I am running Windows Server 2016 and I have an OU (Member Servers) and inside this OU it holds computer objects, one Sub OUs called testing and two Security groups called WSUS Anytime and WSUS Afterhours. Weird thing is that there is a GPO and it's 'Linked to Member Server OUs and set with a 'security filter' AD security group that is one of the security groups assign to Member Server OU.
Now, this GPO configured to push updates and should only be applied to one of the security groups which is set correctly within security filtering called WSUS Afterhours. However, since it is linked to Member server OU and remember that OU has another security group called WSUS Anytime, which I do not want to have updates pushed to. In addition, it also has computer accounts within root of that OU, so doesn't those systems actually get GPO applied to them?
What I want to do is create a OU called PM - After hours and PM - Anytime and 'only' assign the computers to root of OU. From my understanding, GPOs are only applied to users and computers contained directly within the OU-Domain-Site hierarchy.