Jump to content

Recommended Posts

Posted

Hi folks,

 

Just double checking my understanding of GPOs, specifically one I'm trying to apply to a group of computers.

 

Said computers are in an AD group, and I've set the scope of the GPO to this group. Is this sufficient for the GPO to apply, or do the computers have to be in an OU as well?

 

Thanks

Posted

They don't need to be in an OU as such, but the GPO needs to be applied to something. Even if it's top level domain etc (not best practice)

 

Steve

  • Thanks 1
Posted

Does setting a scope apply it though? Specifically, setting something in the Security Filtering.

 

I naively assumed it must, because these GPOs seem to have worked for years.

Posted
Pretty much. So for example if you have a Workstations OU, you'd typically put computer level GPO's in there. They would apply to anything in the scope, so computer names, security groups etc as you correctly say. Just make sure that "Authenticated Users" is set in delegation if it's not in the scope otherwise they won't apply.
  • Thanks 1
Posted

What I've done with some GPOs though is created them, not linked them to an OU, but set them with a scope for the relevant PCs. They all seem to be working e.g. we have a WSUS GPO that is definitely pointing the machines at the WSUS server.

 

So is having them linked to an OU essential, and if it is then why are they working?! *confused*

Posted

What's showing in location is the domain, and I can see that if I create a GPO in the root of the domain it is automatically linking it to the entire domain. My guess is that when these were setup they were just created in the root here, hence apply to the whole domain. I'm guessing that scope/security filtering then just restricts to the particular AD group.

 

Does that sound right?

Posted

Thats right then yes, that's not an ideal scenario as it means every single machine whether it's workstation or server will be querying it, which isn't ideal. It won't apply but it's a little more work for it all to handle. You'd usually put GPO's in as deep into the structure as is required, then work back. So for example, if you have school.internal as the domain, an OU called "school", then workstations>ict suite you'd put GPO's that are needed for all workstations in school.internal\school\workstations, and those that only apply to the ICT suites under school.internal\school\workstations>ict suites.

The only policy under the whole domain location should really be "Default domain policy"

  • Thanks 1
Posted
Thanks. I'm working with an inherited system, so have been creating the newer GPOs within OUs. I did just doubt though how these root GPOs were working!
Posted

If you're setting a scope "and" removing authenticated users (from security), you must re-add authenticated users to the delegation tab since an update last year else it won't apply

 

Steve

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...