Home > Ask the Windows Experts > From the Archives: Group Policy Questions & Answers > How can I restrict rights for a group of users on a specific OU of computers, but not on any computers outside of that OU?
Ask The Win IT Expert: Questions & Answers
EMAIL THIS

How can I restrict rights for a group of users on a specific OU of computers, but not on any computers outside of that OU?

Jeremy Moskowitz EXPERT RESPONSE FROM: Jeremy Moskowitz

Pose a Question
Other Win IT Categories
Meet all Win IT Experts
Become an Expert for this site


Expert advice on Active Directory and Group Policy
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


>
QUESTION POSED ON: 25 September 2006
How can I restrict rights for a group of users on a specific OU of computers, but not on any computers outside of that OU?

In other words, I don't want this set of users to see the floppy drive, be able to right click, open calculator, etc., when they are using any of the machines within the OU, BUT have full access rights when they are using machines outside of the OU in Group Policy. All the machines and users are in the same domain. Essentially, is it possible to have a GPO that restricts user rights extensively) apply to a group/OU of users only when they login to a specific group/OU of machines?


>
EXPERT RESPONSE

This sounds like a classic case for using loopback policy processing. As you know, the users are getting the policies which apply to their user accounts based on where they are in Active Directory, and likewise for machines. Loopback means that you can get a machine to process policies which have user settings and apply these to users which log on to them, even though that user policy may not be linked to where the real user account is. This is perfect for things like internet kiosk machines or terminal servers which typically need very specific settings that you don't want to apply to your users normally.

So how do you set it up?

Create and link a policy to the OU where the machines are and edit it. Under Administrative TemplatesSystemGroup Policy, you want to configure the setting for "User Group Policy loopback processing mode." You need to choose a mode -- "replace" will ignore all the user's own settings and only use those settings which are in scope for the machine (so linked to your special OU), whereas "merge" will use both, and the machine's looped-back user settings will take precedence in the case of any conflict.

So here we are setting a group policy to tell Group Policy how to function. You can set the user settings you want in this same policy to keep it all together, or link specific user policies to the OU in the normal way.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice

HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT DownloadsBlogs
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 1999 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts