Link to home
Start Free TrialLog in
Avatar of Tim Phillips
Tim PhillipsFlag for United States of America

asked on

How do I apply a group policy to an OU with computers?

I'm sure this is easy, but I can't figure it out.  I have a GPO called "_DevAuditLogging" with settings for logging.  (i.e. audit object access, security log size)

I have one server in an OU called "Dev Servers"

When I link the GPO to the Dev Servers it doesn't apply.  I tried the "Group Policy Results" report and it doesn't show up for the computer.  Also, I try "gpupdate /force" on the machine and it doesn't get the changes.  What gives?
Avatar of Aard Vark
Aard Vark
Flag of Australia image

Have a look in Event Viewer. It will tell you why the GPO did not apply.

Eventvwr > Applications and Services Logs > Microsoft > Windows > Group Policy > Operational
ASKER CERTIFIED SOLUTION
Avatar of Sushil Sonawane
Sushil Sonawane
Flag of India image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Tim Phillips

ASKER

@Learnctx I didn't see anything in the event log at the location you specified.

@Sushil using those links I can verify that the GPO is not being applied to the computer, but I already know that.

I'm thinking that my configuration is wrong somehow.  The GPO doesn't have anything in the "security filtering" portion of the scope.  Is that a problem?  I figured that would just narrow down which computers it applies to, but I want it to apply to the whole group.
I figured it out.  I had removed "Authenticated Users" from the scope filtering section and I think that removed "Authenticated Users" from the Delegation Tab.  When I was in the Delegation Tab there was no mention of the anything containing the server in question.  I added a group that the server was in and added the permission "Apply Group Policy" and then it worked!