Active directory, apply GPO to one group, only on a specific computer

i got a group called, specialGroup.
that should have no acccess to task manager only one computer called computer1.

how can i use GPO, to disable that.

i created the GPO.
i created a new OU, and put computer1 in in it.
i used filtering to apply it only on Specialgroup.

that did not work.
it only works when i put the GPO on the entire domain, instead of the OU it self !!

any ideas ?
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Disable Task Manager is a policy under the "User Configuration" tree of Group Policy, and hence does not apply directly to computer objects.

You will need to enable loopback processing mode to have user configuration policies apply in a computer context. More details on that here:

Be sure to understand precisely how this works (the above link describes in more detail), and to do this in your policy itself, so its scope is limited. You should also make a decision between "Replace" and "Merge" options; if you don't want any other policies which would normally apply to the user, then replace works (often relevant in a kiosk example), otherwise it is often good to err on the side of caution and select "merge".

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Da_Ch0senAuthor Commented:
i tried merge, and i tried replace, both ways, the policy was not applied

when i check group policy result for that user on that computer.
i noticed some that are denied and some that are applied.

but the GPO in question is not listed as any, not denied nor applied, it is  not even there
Da_Ch0senAuthor Commented:
donno what happen, but after few refreshes and gpupdate s it worked lol
thanks that was helpful
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Active Directory

From novice to tech pro — start learning today.