Solved

AD OU doesn't show up in Group Policy

Posted on 2013-06-18
1
854 Views
Last Modified: 2013-06-18
Domain Functional Level: Win Server 2003

I'm trying to exclude my servers from my (very simple) Windows Update GPO.  (I don't want them to auto-restart at 3am.)  The easiest solution seems to be to assign the GPO to specific Organizational Units, as I do with all my other GPOs.  However, I am now realizing that not all my OUs available in Active Directory show up in Group Policy.  Specifically, my "Computers" OU is not there.  

Can I rectify this? ...if not, any suggestions for how to separate my servers from my workstations so that I can assign my Windows Update GPO accordingly?
Thanks!
0
Comment
Question by:cuiinc
1 Comment
 
LVL 15

Accepted Solution

by:
Rob Stone earned 500 total points
ID: 39257242
It's because it's not an OU, but a container, as is Users.

You'll need to create an OU and move the computers/users to respective OU's.

I would look to move the servers into a Servers OU, otherwise you will need to look at a WMI filter or deny access to the computer accounts for that policy (I'd advise against this last option though!).
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A safe way to clean winsxs folder from your windows server 2008 R2 editions
Is your Office 365 signature not working the way you want it to? Are signature updates taking up too much of your time? Let's run through the most common problems that an IT administrator can encounter when dealing with Office 365 email signatures.
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

930 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now