filtering specific computers from policy

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Ilya (anonymous_at_discussions.microsoft.com)
Date: 06/30/04


Date: Wed, 30 Jun 2004 00:52:55 -0700

Hi all,

I have a lot of sites and several domains. It is purely
Windows 2000 environment.

I am going to set up Group Policy at site level. It will
manage site-related software installation, drive mapping,
and other site-related options.

I don't want to make geographically based OUs, because
it's easer to use natural existing object like site.

I need to exclude servers from computer policy part of
site GPO. I think that I can do it by placing all servers
in security group and use GPO's permissions to denying
this group from apply policy.

Is this solution correct? I've searched the Internet but
could not manage to find if someone did the same thing.

Thank you,
Ilya.



Relevant Pages

  • Re: filtering specific computers from policy
    ... >> I am going to set up Group Policy at site level. ... >> site GPO. ... >> in security group and use GPO's permissions to denying ...
    (microsoft.public.win2000.group_policy)
  • Re: Windows 2003 relation trust with 2 DC
    ... The policy to apply must be applied from where the user exists. ... Are these DCs at Different Domains or Different Forests? ... If DCs are in the Same Forest you might need to apply it at Site level. ... Also be aware that if site policies are being applied through slow links ...
    (microsoft.public.windows.server.active_directory)
  • Re: Restricting the Site Group Policy for a single computer
    ... I have a group policy that is configured at the Site level. ... policy to override the offending policy. ...
    (microsoft.public.windows.server.active_directory)