I am part of an IT team who was recently assigned to GPO related tasks. I am pretty new to GPO and still getting a grasp about it.<\/p>\n
I recently received a request related to certain GPO user configuration that needs to be enabled however the catch is , it is related to an existing GPO loopback policy which i am still unfamiliar of. Can someone help me understand what needs to be done in order fulfill this task. Badly need some insights.<\/p>\n
Here is the situation:<\/p>\n
The customer wants this particular configuration to be enabled on his end alone . I found out that there is currently an existing GPO where the user’s workstation is linked into. This GPO is currently setup in loopback policy and that specific user configuration is disabled and linked to Laptop OU where the user’s workstation is located into (basically from what i understand, this GPO is currently being applied to all Laptop OUs and this specific user configuration is disabled).<\/p>\n
Domain > Windows 10 > Laptop (this is the OU where the GPO is currently applied into)<\/p>\n
The customer now wants to create a specific security group created and have all users who wants to have that user configuration enabled there, the problem is it is located in different OU.<\/p>\n
Domain > Users > Location User (this is the OU where the customer wants that specific group to be created)<\/p>\n
My question is how will i configure the GPO (user configuration set to enabled) and link it to the “Users OU” when there is an existing GPO in the Workstation OU (user configuration set to disabled and loopback policy - merge is enabled) without having any conflicting issue.<\/p>","upvoteCount":5,"answerCount":9,"datePublished":"2025-02-12T14:02:49.110Z","author":{"@type":"Person","name":"knowledge-heavy006","url":"https://community.spiceworks.com/u/knowledge-heavy006"},"suggestedAnswer":[{"@type":"Answer","text":"
I am part of an IT team who was recently assigned to GPO related tasks. I am pretty new to GPO and still getting a grasp about it.<\/p>\n
I recently received a request related to certain GPO user configuration that needs to be enabled however the catch is , it is related to an existing GPO loopback policy which i am still unfamiliar of. Can someone help me understand what needs to be done in order fulfill this task. Badly need some insights.<\/p>\n
Here is the situation:<\/p>\n
The customer wants this particular configuration to be enabled on his end alone . I found out that there is currently an existing GPO where the user’s workstation is linked into. This GPO is currently setup in loopback policy and that specific user configuration is disabled and linked to Laptop OU where the user’s workstation is located into (basically from what i understand, this GPO is currently being applied to all Laptop OUs and this specific user configuration is disabled).<\/p>\n
Domain > Windows 10 > Laptop (this is the OU where the GPO is currently applied into)<\/p>\n
The customer now wants to create a specific security group created and have all users who wants to have that user configuration enabled there, the problem is it is located in different OU.<\/p>\n
Domain > Users > Location User (this is the OU where the customer wants that specific group to be created)<\/p>\n
My question is how will i configure the GPO (user configuration set to enabled) and link it to the “Users OU” when there is an existing GPO in the Workstation OU (user configuration set to disabled and loopback policy - merge is enabled) without having any conflicting issue.<\/p>","upvoteCount":5,"datePublished":"2025-02-12T14:02:49.174Z","url":"https://community.spiceworks.com/t/gpo-loopback-policy-for-user-configuration-question/1174420/1","author":{"@type":"Person","name":"knowledge-heavy006","url":"https://community.spiceworks.com/u/knowledge-heavy006"}},{"@type":"Answer","text":"
Would it be easier to create a new GPO with security targeting. Make those users a part of the group and they will get the GPO settings<\/p>","upvoteCount":1,"datePublished":"2025-02-12T16:12:17.913Z","url":"https://community.spiceworks.com/t/gpo-loopback-policy-for-user-configuration-question/1174420/2","author":{"@type":"Person","name":"titusovermyer","url":"https://community.spiceworks.com/u/titusovermyer"}},{"@type":"Answer","text":"
there is an existing GPO (configured as loopback enable - merge) that is applied in laptop OU - from what i can understand the organization originally wants that specific user config to be disabled in all laptops but this time, the request is to have an exemption for specific users and have that user configuration enabled however they want us to create a specific security group created in the users OU instead.<\/p>\n
the problem that i am struggling right now is that, when i created a new GPO that enables that user config and link it to the USERS OU, what will take effect?<\/p>\n
OR<\/p>\n
Sorry i am getting confused as well in what will take effect…<\/p>","upvoteCount":1,"datePublished":"2025-02-12T16:32:45.750Z","url":"https://community.spiceworks.com/t/gpo-loopback-policy-for-user-configuration-question/1174420/4","author":{"@type":"Person","name":"knowledge-heavy006","url":"https://community.spiceworks.com/u/knowledge-heavy006"}},{"@type":"Answer","text":"
User Configuration settings only effect users, and computer configuration settings only effect computers. If you make a GPO that only has user settings in it, and link it to an OU that only has computers in it, nothing will happen.<\/p>\n
Also, you cannot apply GPOs to the “Users” container.<\/p>\n
If the Workstation GPO has loopback - merge, then whenever a user logs in to a computer that is in that OU it will merge whatever user settings you may have applied in that OU with the settings of the OU the user is in as well.<\/p>\n
Create the new GPO, edit it to your liking, in the security filtering section, remove authenticated users, and add your created group. Link it to all OUs that contain the users you want the policy applied to, and that should do it.<\/p>","upvoteCount":1,"datePublished":"2025-02-12T23:11:24.870Z","url":"https://community.spiceworks.com/t/gpo-loopback-policy-for-user-configuration-question/1174420/5","author":{"@type":"Person","name":"Farva06","url":"https://community.spiceworks.com/u/Farva06"}},{"@type":"Answer","text":"
“If the Workstation GPO has loopback - merge, then whenever a user logs in to a computer that is in that OU it will merge whatever user settings you may have applied in that OU with the settings of the OU the user is in as well”<\/p>\n
this is the problem i am thinking of, there is an existing GPO (configured as loopback enable - merge) that is applied in laptop OU which disables that user config (the requestor confirmed that the features is disabled).<\/p>\n
If a created a GPO that links to the OU of the user and enables that user config, what will take effect, is it the GPO link in the workstation OU or GPO link to the user OU?<\/p>","upvoteCount":0,"datePublished":"2025-02-13T12:41:44.376Z","url":"https://community.spiceworks.com/t/gpo-loopback-policy-for-user-configuration-question/1174420/6","author":{"@type":"Person","name":"knowledge-heavy006","url":"https://community.spiceworks.com/u/knowledge-heavy006"}},{"@type":"Answer","text":"
Have you tried creating a security group and filtering based on that security group?<\/p>\n
GPO’s run based on being attached to OU’s. But you can filter what accounts in that OU are included using security groups.<\/p>\n
I might add a few security groups to include or deny.<\/p>\n
To deny a security group you’d want to go to the final tab, and click on the button on the bottom right and add the security group you want to deny and assign it that property. Then it will be like that policy doesn’t exist for those groups.<\/p>\n
GPO’s apply best when you focus on either users or devices when setting them up.<\/p>","upvoteCount":0,"datePublished":"2025-02-14T14:20:26.252Z","url":"https://community.spiceworks.com/t/gpo-loopback-policy-for-user-configuration-question/1174420/7","author":{"@type":"Person","name":"microsoftfanboy","url":"https://community.spiceworks.com/u/microsoftfanboy"}},{"@type":"Answer","text":"
It might be the explanation of what is required but loopback does not sound the correct method.<\/p>\n