Re: Access Denied (Security Filtering)



Hi Peter,

If I understand you correctly, I need to apply this to some users also? The
problem I have is that since the PCs I need to apply this to are lab PCs,
when the users go to their office PCs, I dont want that GPO to apply to them
as users there also.

If I put the authenticated users in the same group, is there a way to say
that if you are using this PC that you will get this policy, but if you are
not using this PC, you will not get the policy?

Thank you for your help.

Scott

"Peter Dickason, MCSE, CCA, CNE" wrote:

Hi Scott,

I think I see the issue. Even though the computer accounts are in the
group, the user will not be able to read the GPO even though you have
loopback enabled because you have no permissions applied to any users. If
you have no user accounts in the same OU as your workstations, and no other
loopbacks, you can give authenticated users the read and apply group policy,
otherwise you may need to put these in an OU of their own and apply the GPO
there. Let me know if that works.

Pete



.