Re: Applying user object policy (filtering based on computer location)



Roger,
Thank you very much for your response - Not sure why I did not think of
using Loopback mode.

Ok. So I have tried it but am running into some challenges.

I have a OU called "NY DESKTOPS" - I created a new policy and enabled
Loopback processing mode (Merge). In the same policy, I enabled Active
Desktop and set the path for the HTML page. I have this policy set to only
apply to users from LA - i.e. LA Employees.
In the "NY DESKTOPS" OU there is another policy linked that applies to
'AUTHENTICATED USERS" This is the standard gpo for my NY desktops.
So in total, there are two gpo's linked to this OU.
So when I log into a computer (i'm in the LA employee group), i do not get
the settings.... Any idea why?

Thanks again.


"Roger Abell [MVP]" <mvpNoSpam@xxxxxxx> wrote in message
news:uD6Z0qGEIHA.1208@xxxxxxxxxxxxxxxxxxxxxxx
"jm" <jm@GMAIL> wrote in message
news:53E28875-24FE-4EDF-B051-D15C6CCB140B@xxxxxxxxxxxxxxxx
Hello Everyone.

I am trying to set a standard desktop background for certain users. I
have the part working....

What I can't see to get around is that I don't want this to happen to all
my users. Just to users how are visiting from a different branch office.
Do I need to use a WMI filter? If so, can anyone help me with Query
design?

Basically, I do not want the policy to apply if IP Address begins with
172.22. -- make sense?


No, I cannot really follow your statements.

If you want certain user policies to apply for a specific set of
user accounts but only when they are logging onto a particular
set of computers, then you would use a GPO set for loopback
processing. Such a GPO is linked so that the set of computers
is within its scope, and the security group filtering needs to be
such that only those computers and only the users you desire to
impact have read/apply of the GPO.
Search on GPO loopback

Roger




.



Relevant Pages

  • Re: Complex GPO Configuration Issue
    ... I have read a lot of posts and articles on loopback processing and have used ... If you enforce a policy then it will override all other polices in the path ... to the user/computer unless another GPO closer to the user/computer is also ... What I'm getting for user configuration is ...
    (microsoft.public.windows.group_policy)
  • Re: Applying user object policy (filtering based on computer location)
    ... leave "authenticated users" with read and apply group policy permissions and set deny on NY employees. ... should have the GPO applied via loopback when logging into ...
    (microsoft.public.win2000.group_policy)
  • Re: Applying user object policy (filtering based on computer location)
    ... should have the GPO applied via loopback when logging into ... the computers in NY Desktops OU, ... I have a OU called "NY DESKTOPS" - I created a new policy and enabled Loopback processing mode. ...
    (microsoft.public.win2000.group_policy)
  • Re: Mulitiple Loopback GPOs and one OU
    ... I tested what you've indicated..interesting...it reads from my first policy, ... that loopback is implemented and then it ends up applying the ... explicitly apply computer settings in a GPO via a security filter...they seem ... loopback policy is even read on the GPO that has an explicit Deny on it? ...
    (microsoft.public.windows.group_policy)
  • Re: Controlling User Policy via Computer account
    ... > (1 and 2 are adding grants of read/apply in the GPO security) ... > 4 place the machines in the OU to which this GPO is linked ... Even with the Loopback policy, ...
    (microsoft.public.windows.group_policy)