Solved

Group Policy and Authenticated Users

Posted on 2013-02-03
3
617 Views
Last Modified: 2013-02-18
Hi guys,
I want to apply a group policy to one user only.
In the Security filtering section of the group policy, it has the authenticated users there by default.
Should I remove this group, and then add the specific user to that security filtering section, or is it safe to leave the authenticated users group there.
This user is in an OU with 100s of other users.
I just want to make sure that the other users in this OU dont get the gpo.
Thanks.
0
Comment
Question by:Simon336697
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 9

Assisted Solution

by:Zenvenky
Zenvenky earned 140 total points
ID: 38850073
This is bit tricky. However are there any other policies are getting applied on this OU. If your answer is yes, then you have to be very carefull do not change anything "Authenticated Users".
Instead take that single user out of OU and create new policy to give permissions that you want to give.
0
 
LVL 85

Accepted Solution

by:
oBdA earned 200 total points
ID: 38850154
Removing the "Authenticated Users" group from the Security Filtering section and adding a dedicated security group instead is basically the only way to apply a GPO to a user selection inside of an OU.
And even if it's currently only a single user, you should still create a dedicated group "GPO-Apply-<ThatCertainGPO>" or whatever, add the user account to this group, and add this group to the GPO's security filtering. That way, the configuration is basically self-documenting; in addition, the time will come when a second account needs this policy applied as well.
0
 
LVL 13

Assisted Solution

by:Jaihunt
Jaihunt earned 160 total points
ID: 38850810
Hi

You can create a Group and add all users in that group except the one user who requires the group policy.

Go to the policy in GPMC and Delegation --> Advanced -->add the Group -- in Permissions Select Apply group policy check deny.

It will Deny Group policy applying to all the users in the Group. In future if you need any changes you can modify to the Group.

Thanks
Jai
0

Featured Post

Free NetCrunch network monitor licenses!

Only on Experts-Exchange: Sign-up for a free-trial and we'll send you your permanent license!

Here is what you get: 30 Nodes | Unlimited Sensors | No Time Restrictions | Absolutely FREE!

Act now. This offer ends July 14, 2017.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article outlines the process to identify and resolve account lockout in an Active Directory environment.
A company’s centralized system that manages user data, security, and distributed resources is often a focus of criminal attention. Active Directory (AD) is no exception. In truth, it’s even more likely to be targeted due to the number of companies …
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

729 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question