I created a new GPO that I want applied to a certain security group. I created an OU, created the security group in that OU, and I am now creating a GPO that is linked to that OU. I only want the GPO to apply to the users inside the security group.

On security filtering I added the security group and removed authenticated users. I know that it is now necessary to add the computers that I want it to apply to. If I add Domain Computers to the security filtering, will it only apply to users that are in that security group, or will it apply to all domain computers regardless of whether or not the user is in that security group?

2 Spice ups
  1. Create Security Group

  2. Add users to Security Group

  3. Create group policy

  4. Configure security filtering to include the Security Group

  5. Grant Authenticated Users ‘Read’ of group policy under Delegation tab

  6. Drink coffee/Profit

3 Spice ups

Is there no need to add Domain Computers to the security filtering? I thought that Windows update KB3163622 made it so you had to include Domain Computers in order for the policy to apply?

Is this a GPP? If so you can use Item Level Targeting to control it.

1 Spice up

Group policy doesn’t apply to groups.

You have to link your policy to either an OU with Computers or and OU with users.

As for using security filtering, this depends on if this is a user GPO or a Computer GPO. You can use security filtering to restrict user GPO settings to groups of users or Computer GPO settings to groups of computers.

If your policy is a Computer GPO and you add Domain computers it will apply to Every machine that is in that OU. Note if the OU does not have any user or computer objects in it the GPO will have nothing to apply to.

He said:

 "I created an OU, created the security group in that OU, and I am now creating a GPO that is linked to that OU."

Just making sure there is more than just the new group in that OU.

Yeah, I reread what you said and what OP said and realized what you meant. I deleted my post, but it was too late, you’d already quoted me :slight_smile:

1 Spice up

Yes, you will have to add the read permission not the apply permission.

Not to the Filter, no. You add them to the Delegation tab.

1 Spice up