Solved

Server 2012 R2 GPO

Posted on 2015-02-05
3
526 Views
Last Modified: 2015-02-05
Hi,
I have set up a new physical server (Server 2012 R2) as a Hyper-V host and have created several VMs also running Server 2012 R2.
I have been playing with group policy and thought it would be fun (and a good way to learn a bit more about how to use GPO) to personalise each of the servers a bit. I have discovered that I can change the Lock Screen using GPO in the Default Domain Policy with:
Computer Configuration> Policies> Administrative Templates Policy> Control Panel> Personalization, and enabling "Force a specific default lock screen image". ...and it works!
I set it to a specific file that suited the name of the DC (i.e. I have named the DC 'Zeus', and have used a picture of Disney's Zeus character as the lock screen.)
It is all very cool...except I thought ... 'I wonder how I would set the lock screen on the other servers?' ... and while I was pondering this, the next day I had Zeus grinning at me from the lock screen of ALL the servers! Doh! (slaps forehead).

So, I understand what I did wrong, but I can't work out how to set a different lock screen for each server. Is there a way to add a computer (i.e. server) to an OU? I can create a GPO and link it to an OU. If I can somehow put the server in the OU it will work.
Or can I use Item-level Targeting? I've used that for Drive Mapping in Preferences, but I don't think I can do it with Policies.

Any thoughts?
Cheers,
Greg
0
Comment
Question by:gregmiller4it
  • 2
3 Comments
 
LVL 53

Accepted Solution

by:
Will Szymkowski earned 500 total points
ID: 40592727
The quickest way to get account this is using the Security Filtering for this policy. By default Authenticated Users is used (this includeds both users and computers). Remove this and add the computer account to the security filtering for "Zeus". Once you have done this you can do to one of your servers and from gpupdate /force and the screen lock should be removed.

It is a computer based policy and most require to be at least logged off and or reboot. In this case it might not.

Will.
0
 

Author Comment

by:gregmiller4it
ID: 40592743
Excellent...and it was simple too! Thanks heaps. The only extra trick was that I had to tick 'Computer' in the object type list before it found 'Zeus'. So now I have Zeus and Apollo with different lock screens (now I just need to find suitable images for Hermes, Atlas and Kronos). Works a charm, thanks.
Cheers,
Greg
0
 

Author Comment

by:gregmiller4it
ID: 40592745
By the way... 'gpupdate /force' required a logoff
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This script can help you clean up your user profile database by comparing profiles to Active Directory users in a particular OU, and removing the profiles that don't match.
This article runs through the process of deploying a single EXE application selectively to a group of user.
In this Micro Tutorial viewers will learn how to restore single file or folder from Bare Metal backup image of their system. Tutorial shows how to restore files and folders from system backup. Often it is not needed to restore entire system when onl…
This tutorial will walk an individual through the process of configuring basic necessities in order to use the 2010 version of Data Protection Manager. These include storage, agents, and protection jobs. Launch Data Protection Manager from the deskt…

778 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question