Jump to content

Group Policy User settings based on Security Group?


Recommended Posts

Posted (edited)

It's getting to the point now where we're having to tweak certain policies for certain kids depending on what subjects they take at GCSE. More storage, removable device access, etc. Rather than keep nesting more OU's and fracturing our user accounts, I'm thinking would it be possible to create Security Groups for subjects with special permissions and have those apply policies as needed..

 

For example, the Photography students need access to their phones because we don't have the money to be buying cameras, so I create a GPO that enables Read permissions on WPD Devices. I want to have that apply if pupils are part of the 'GCSE Photography' security group, but if I put the Security Group in an OU and apply the policy to that OU, it doesn't apply to members of the Security Group.

 

This article documents a similar approach, rather than applying the GPO to the OU containing the Security Group, apply it to all users but only allow users of the Security Group to process it by removing Authenticated Users permissions. I've tried that and it doesn't work either, even if the Security Group is in the same OU as the user.

 

Kinda stumped now. Is what I'm after even possible, or am I just completely barking up the wrong tree?

 

DERP! I'm an idiot. I completely removed Authenticated Users' permissions rather than just unchecking 'Apply group policy'. Once Authenticated Users had Read permissions again, it worked as intended.

Edited by Garacesh
  • 2 weeks later...
Posted
Yeah, when doing GPO security filtering one should always give authenticated users read access, even if you do not want to apply it to them. Otherwise stuff won't work since a MS update in the past.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...