1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Excluding a single PC from GP

Discussion in 'Windows Server System' started by griffmaster, 2007/07/24.

  1. 2007/07/24
    griffmaster

    griffmaster Inactive Thread Starter

    Joined:
    2006/09/12
    Messages:
    88
    Likes Received:
    0
    Is there any way to exclude a single PC from Group Policy?

    I have GP settings for all computers on network for restrictions to Internet Explorer but dont want these settings applied to the server, just the clients. At the moment even though I configured the GPO "Small Business Server Client Computer" it is still being applied to the server.

    Any ideas?

    Thanks
     
  2. 2007/07/24
    Bursley

    Bursley Well-Known Member Alumni

    Joined:
    2001/12/29
    Messages:
    462
    Likes Received:
    2
    In active directory, create a new organization unit, and place that server in that organization unit. Apply a group policy object block inheritance. Block inheritance
     

  3. to hide this advert.

  4. 2007/07/25
    griffmaster

    griffmaster Inactive Thread Starter

    Joined:
    2006/09/12
    Messages:
    88
    Likes Received:
    0
    I have created a new organization unit called Server so i presume i should just drag the Small Business Server Client Computer from Group Policy into the new Server organization unit? Or should I create a new object in Server and restore the values in Small Business Server Client Computer from Group Policy back to default?

    Thanks
     
  5. 2007/07/25
    Bursley

    Bursley Well-Known Member Alumni

    Joined:
    2001/12/29
    Messages:
    462
    Likes Received:
    2
    did you create domain level group policies, or organizational level? If you have the group policy at the organizational level, moving the system from one OU to the other OU, should remove the policy and apply any new policies. Provided of course the 2nd OU is not a child of the first OU.
    If you created a domain level group policy, you will need to create a group policy within the new OU that blocks inheritance from the domain policy.
     
  6. 2007/07/26
    griffmaster

    griffmaster Inactive Thread Starter

    Joined:
    2006/09/12
    Messages:
    88
    Likes Received:
    0
    I am embarassed to say that I am a little confused as not really got much experience messing about with GP, so I stuck a screen shot here, hopefully this will help you to help me.

    Thanks for you help so far.
     
  7. 2007/07/27
    Bursley

    Bursley Well-Known Member Alumni

    Joined:
    2001/12/29
    Messages:
    462
    Likes Received:
    2
    I typically handle GPO in Active Directory Users and Computers MMC Plugin.
    Right click on the OU you want to modify, and go to the Group Policy tab.
    Add in the group policy you want to block.
    check the box that says, "Block Policy inheritance "
    Apply the setting.
    You can then reboot that server, or force an update by using gpoupdate /force to push out the new GPO.
     
  8. 2007/08/10
    SkyWalkrMT

    SkyWalkrMT Inactive

    Joined:
    2007/08/09
    Messages:
    3
    Likes Received:
    0
    GPO application

    HI :)

    One alternative way of going about this would be to leave the computer in an OU with other computers, but then in the Security filtering for the GPO, add only the computers or security groups (which can contain computer accounts), for which the GPO can be applied. this way you can still select which accounts (both users or computers) will receive the GPO settings.

    hope this helps.

    Best regz\

    Sky




     
  9. 2007/08/15
    tiwang

    tiwang Inactive

    Joined:
    2005/01/14
    Messages:
    53
    Likes Received:
    0
    several simple ways to solve this problem - either define multiple OU's in a tree strcuture and put your computeres in them in a way so that they inherit for the overlying level - and just put the IE blok GPO in the bottom level OU with the PC's
    Or ACL filtering as suggested and deny the server
    or ...
    well - just keep it simple...
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.