I used to just have users or computers in a group and would use GPO Security Filtering to only apply that GPO to users/computers in that group.<\/p>\n
Since the security change, now I add ‘Domain Computers’ and the group I want - which seems to be fine. I don’t feel like this is the best way. Is there a better way to do this?<\/p>\n
Typically doing this on Server 2012 R2 and above.<\/p>","upvoteCount":6,"answerCount":7,"datePublished":"2019-06-04T14:00:11.000Z","author":{"@type":"Person","name":"mvalpreda","url":"https://community.spiceworks.com/u/mvalpreda"},"suggestedAnswer":[{"@type":"Answer","text":"
I used to just have users or computers in a group and would use GPO Security Filtering to only apply that GPO to users/computers in that group.<\/p>\n
Since the security change, now I add ‘Domain Computers’ and the group I want - which seems to be fine. I don’t feel like this is the best way. Is there a better way to do this?<\/p>\n
Typically doing this on Server 2012 R2 and above.<\/p>","upvoteCount":6,"datePublished":"2019-06-04T14:00:11.000Z","url":"https://community.spiceworks.com/t/best-way-to-apply-gpo-to-certain-groups/714849/1","author":{"@type":"Person","name":"mvalpreda","url":"https://community.spiceworks.com/u/mvalpreda"}},{"@type":"Answer","text":"
I believe that this still needs to be done if any other group other than authenticated users is listed under Security Filtering.<\/p>","upvoteCount":0,"datePublished":"2019-06-04T14:13:17.000Z","url":"https://community.spiceworks.com/t/best-way-to-apply-gpo-to-certain-groups/714849/2","author":{"@type":"Person","name":"capef3ar","url":"https://community.spiceworks.com/u/capef3ar"}},{"@type":"Answer","text":"
You just have to list authenticated users with a read delegation on the security tab.<\/p>\n
This is because of a security change. User GPOs are now read by the computer object.<\/p>\n
There is nothing wrong with this. Other ways of filtering GPOs would be by OU management and organization. ILT on GPP GPOs. WMI filters, to name a few.<\/p>","upvoteCount":1,"datePublished":"2019-06-04T14:57:23.000Z","url":"https://community.spiceworks.com/t/best-way-to-apply-gpo-to-certain-groups/714849/3","author":{"@type":"Person","name":"justin1250","url":"https://community.spiceworks.com/u/justin1250"}},{"@type":"Answer","text":"
So how I am doing it is fine after removing ‘Authenticated Users’?<\/p>","upvoteCount":2,"datePublished":"2019-06-04T16:06:44.000Z","url":"https://community.spiceworks.com/t/best-way-to-apply-gpo-to-certain-groups/714849/4","author":{"@type":"Person","name":"mvalpreda","url":"https://community.spiceworks.com/u/mvalpreda"}},{"@type":"Answer","text":"