GPO on certain users

I want to apply a GPO to restrict them from downloading and running any files. they can browse the internet but not download nor run any files.

I have a total of 10 users, only two will be exclude from that policy.

Should I create a new OU and move the users to that OU and create that policy, or what is the best way to accomplish that?

windows 2008 r2 .
LVL 1
alonig1Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Sekar ChinnakannuSr Infra Security AdministratorCommented:
Create a group and add all the users to AD group.
You can create a policy and add the user group to Security Filtering in GPO and it will work for group of users.
alonig1Author Commented:
Do you know which option should I use to prevent the users of running / downloading programs?
Sekar ChinnakannuSr Infra Security AdministratorCommented:
In GPO -> User Configuration -> Policies -> Administrative Templates -> Windows Components -> Internet Explorer -> Internet Control Panel -> Security Page -> Internet Zone
CEOs need to know what they should worry about

Nearly every week during the past few years has featured a headline about the latest data breach, malware attack, ransomware demand, or unrecoverable corporate data loss. Those stories are frequently followed by news that the CEOs at those companies were forced to resign.

alonig1Author Commented:
Where does it say not to allow in downloads?
Sekar ChinnakannuSr Infra Security AdministratorCommented:
Goto allow file downloads and read the content.
alonig1Author Commented:
"Create a group and add all the users to AD group.
You can create a policy and add the user group to Security Filtering in GPO and it will work for group of users."

I've created a group where do I apply the gpo on it. on the GPO management window I can see the security group I've created
Sekar ChinnakannuSr Infra Security AdministratorCommented:
- Create AD group and add the users
- Create a new policy with settings as I mentioned ID: 42070899 and under security filtering add the group of users to apply the policy.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
alonig1Author Commented:
Where do I do the second part?
alonig1Author Commented:
found it.

let me see if it work.s
alonig1Author Commented:
do you know the gpupdate command?
Sekar ChinnakannuSr Infra Security AdministratorCommented:
Yes you can....
alonig1Author Commented:
I set everything, and I can still download.
alonig1Author Commented:
gpo.JPG
Sekar ChinnakannuSr Infra Security AdministratorCommented:
which browser you tried, hope its IE...
alonig1Author Commented:
yes.
alonig1Author Commented:
I just set a homepage through GPO the see it the changes apply . and it did.

but still can download from IE.
masnrockCommented:
Did you force the update on the server?

gpupdate /force
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Active Directory

From novice to tech pro — start learning today.