troubleshooting Question

GPOs, Security filtering and Linked enabled

Avatar of sysnimda
sysnimda asked on
SecurityWindows OSActive DirectoryWindows 10Azure
2 Comments1 Solution66 ViewsLast Modified:
Hello -

I am running Windows Server 2016 and I have an OU (Member Servers) and inside this OU it holds computer objects, one Sub OUs called testing  and two Security groups called WSUS Anytime and WSUS Afterhours. Weird thing is that there is a GPO and it's 'Linked to Member Server OUs and set with a 'security filter' AD security group that is one of the security groups assign to Member Server OU.

Now, this GPO configured to push updates and should only be applied to one of the security groups which is set correctly within security filtering called WSUS Afterhours. However, since it is linked to Member server OU and remember that OU has another security group called WSUS Anytime, which I do not want to have updates pushed to. In addition, it also has computer accounts within root of that OU, so doesn't those systems actually get GPO applied to them?

What I want to do is create a OU called PM - After hours and PM - Anytime and 'only' assign the computers to root of OU. From my understanding, GPOs are only applied to users and computers contained directly within the OU-Domain-Site hierarchy.
Jeff Glover
Sr. Systems Administrator

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Join our community to see this answer!
Unlock 1 Answer and 2 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 2 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros