Hi All<\/p>\n
I’m having a bit of trouble with a Group Policy Preference and I’m hoping you can help.<\/p>\n
I have a GPO that maps network drives based on the security group(s) the user belongs to using item level targeting. (E.G. Drive M: will only map if the user is a member of the “Staff” group.) The GPO is applied to the Users OU, and works perfectly.<\/p>\n
I want to be a bit more restrictive and only allow certain drives to map if the user logs onto certain machines. I have added the machines I want to allow to their own security group, “Office_Computers”, and changed the item level targeting rules. (E.G. Drive M will only map if the user is a member of the “Staff” group AND the computer is a member of the “Office_Computers” group.<\/p>\n
Using my test account I have found that the drive still maps even when I log onto a computer NOT in the “Office_Computers” group.<\/p>\n
I have tried switching the order of the rules and of course using gpupdate /force and restarting the computer every time I make a change to the GPO.<\/p>\n
Is there something I am missing?<\/p>\n
Mark<\/p>","upvoteCount":11,"answerCount":28,"datePublished":"2018-11-20T11:34:16.000Z","author":{"@type":"Person","name":"mark-theitguy","url":"https://community.spiceworks.com/u/mark-theitguy"},"suggestedAnswer":[{"@type":"Answer","text":"
Hi All<\/p>\n
I’m having a bit of trouble with a Group Policy Preference and I’m hoping you can help.<\/p>\n
I have a GPO that maps network drives based on the security group(s) the user belongs to using item level targeting. (E.G. Drive M: will only map if the user is a member of the “Staff” group.) The GPO is applied to the Users OU, and works perfectly.<\/p>\n
I want to be a bit more restrictive and only allow certain drives to map if the user logs onto certain machines. I have added the machines I want to allow to their own security group, “Office_Computers”, and changed the item level targeting rules. (E.G. Drive M will only map if the user is a member of the “Staff” group AND the computer is a member of the “Office_Computers” group.<\/p>\n
Using my test account I have found that the drive still maps even when I log onto a computer NOT in the “Office_Computers” group.<\/p>\n
I have tried switching the order of the rules and of course using gpupdate /force and restarting the computer every time I make a change to the GPO.<\/p>\n
Is there something I am missing?<\/p>\n
Mark<\/p>","upvoteCount":11,"datePublished":"2018-11-20T11:34:16.000Z","url":"https://community.spiceworks.com/t/apply-mapped-drive-only-on-certain-computers/684709/1","author":{"@type":"Person","name":"mark-theitguy","url":"https://community.spiceworks.com/u/mark-theitguy"}},{"@type":"Answer","text":"
You could try a WMI filter to do the same (just another way of doing the same thing) or you could change the security on the GPO so only the specific computers have access to read the GPO<\/p>","upvoteCount":1,"datePublished":"2018-11-20T12:05:15.000Z","url":"https://community.spiceworks.com/t/apply-mapped-drive-only-on-certain-computers/684709/2","author":{"@type":"Person","name":"Carl-Holzhauer","url":"https://community.spiceworks.com/u/Carl-Holzhauer"}},{"@type":"Answer","text":"
Did you use the reconnect option, if you had already the drive map on that computer,<\/p>\n
you can try with the “remove if not applied”<\/p>\n
or you go the other way around, do a deny on the other computer groups, ( I use that on a few gpo)<\/p>","upvoteCount":1,"datePublished":"2018-11-20T12:08:49.000Z","url":"https://community.spiceworks.com/t/apply-mapped-drive-only-on-certain-computers/684709/3","author":{"@type":"Person","name":"patricegagnon2","url":"https://community.spiceworks.com/u/patricegagnon2"}},{"@type":"Answer","text":"
you need to create an OU if you want it that way. this OU must be out of the way of other mappings you don’t want.<\/p>","upvoteCount":1,"datePublished":"2018-11-20T12:37:20.000Z","url":"https://community.spiceworks.com/t/apply-mapped-drive-only-on-certain-computers/684709/4","author":{"@type":"Person","name":"rinomardo2","url":"https://community.spiceworks.com/u/rinomardo2"}},{"@type":"Answer","text":"
or use Security Filtering on the GPO to apply it only to those computers in the group<\/p>","upvoteCount":2,"datePublished":"2018-11-20T12:51:35.000Z","url":"https://community.spiceworks.com/t/apply-mapped-drive-only-on-certain-computers/684709/5","author":{"@type":"Person","name":"GDaddy","url":"https://community.spiceworks.com/u/GDaddy"}},{"@type":"Answer","text":"
Group Policy Preferences and Item Level Targeting. Configure it to map only if the computer is in the ‘Office_Computers’ group AND if the user is a member of the ‘Staff’ group.<\/p>","upvoteCount":3,"datePublished":"2018-11-20T13:12:25.000Z","url":"https://community.spiceworks.com/t/apply-mapped-drive-only-on-certain-computers/684709/6","author":{"@type":"Person","name":"Rob-Dunn","url":"https://community.spiceworks.com/u/Rob-Dunn"}},{"@type":"Answer","text":"