Re: WMI filtering question

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance




"Darren Mar-Elia (MVP)" <dmanonymous@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
message news:uLeT48IZGHA.3704@xxxxxxxxxxxxxxxxxxxxxxx
Brian-
If the setting you are creating in the GPO is under Computer
Configuration, then your user-based security group filtering is just going
to be ignored, because its computer that are processing that setting, not
users. This is irrespective of the WMI filter, which by the way, will
apply.


And to add a little more, since by what was said there is no grant
in the security filterig for computers to read/apply the computers
in the subject OU will not process the GPO for computer settings.

Roger

Check out http://www.gpoguy.com -- The Windows Group Policy Information
Hub:
FAQs, Whitepapers and Utilities for all things Group Policy-related
And, the Windows Group Policy Guide is out from Microsoft Press!!! Check
it out at http://www.microsoft.com/mspress/books/8763.asp
GPOGUY Blog: http://blogs.dirteam.com/blogs/gpoguy



"Brian L." <699df88b-2059788708@xxxxxxxxxxxxxx> wrote in message
news:%23521x6IZGHA.3424@xxxxxxxxxxxxxxxxxxxxxxx
Hi all,

I'm hoping someone here has an answer I've been unable to find so far. In
a nutshell (if you don't want to read the background info!) I want to
know whether a WMI filter to determine whether a computer is running
Windows XP will work when the GPO's security is filtered by a group
containing users?


Now the long details for those interested :

I've got a GPO which sets up computers to point to our WSUS server for
automatic updates. At first we had individual computers in a security
group, and the security filtering for the GPO was set to apply only to
that group. It was a lot of work, making sure the right computers were in
the group, since it was a manual process. I wanted to use WMI at the
time, but in order for it to work right we needed XP SP2 on the desktops
(our machines were SP1).

Now all of our desktop machines run XP SP2, so WMI is an option. I went
into the GPO for WSUS settings, and changed the security filtering group
to one that contained the corresponding user accounts rather than their
computers. The benefit is that if one user has two computers, the GPO
still applies. However, I need to make sure that the GPO is only applied
to XP desktops (i.e. not Windows Server 2003 machines). I created a WMI
filter for this purpose:

Select * from Win32_OperatingSystem where Caption = "Microsoft Windows XP
Professional"

So here's my question - this filter is one that is based on a computer,
not a user (that is, XP is a property the computer has, not the user). My
GPO defines computer-based settings for WSUS, not user-based settings.
But the GPO is filtered by a group containing user accounts.

Is this an OK configuration? I'm not sure whether the WMI filter will
work the way I want it to. If anyone has any input or suggestions let me
know! Thanks.







.



Relevant Pages

  • Re: Im having an issue with the "user group loopback processing m
    ... The problem was that i had a GPO with loopback set and security ... filter had authenticate users. ... computers i want to stop the screen saver on and created another GPO. ... Y also had loopback applied and was link to that OU. ...
    (microsoft.public.windows.group_policy)
  • Re: SUS GPO filtering empty
    ... switches to scan just for missing security updates. ... > Filter in the GPMC instead of computer groups. ... >>>I have installed SUS and would like to create a GPO named Client ...
    (microsoft.public.windows.group_policy)
  • Re: Help with Security Filtering
    ... Security Tab for the GPO itself. ... Is there a way to see the ACL in the GPO that they are being applied to ... the computers, besides just noticing the changes live. ... Filtering" tab with 7 of the Security Groups listed, ...
    (microsoft.public.windows.server.active_directory)
  • WMI filtering question
    ... whether a WMI filter to determine whether a computer is running Windows XP ... At first we had individual computers in a security group, ... and the security filtering for the GPO was set to apply only to that group. ...
    (microsoft.public.windows.group_policy)
  • Re: Block Group Policy Settings Based on Group Membership
    ... Perhaps the issue here is that this security filtering means that, ... users and computers who are targeted by a GPO, ... Let's say I have a GPO linked to the ...
    (microsoft.public.win2000.group_policy)