I'm might be trying something that cannot be done. I am trying to apply 2 different computer configurations to 2 different security groups. Specifically, I'm trying to get one account to have an "account lockout policy" set to 0. Another account, logging onto the same machine, needs to have the "account lockout policy" set to 5.
My AD Structure is this:
Domain
- My Franchise
| - District Managers
| - Stores
| | · store1
| | · store2
| | · clerk
| | - Computers
| | | · All computer objects here
I have two GPOs applied applied to the STORE OU. They are STORE and CLERK. STORE applies to all the store accounts and the CLERK, which is one account used at all stores, is applied to the clerk account. The Computers OU inherits the two GPOs.
On the CLERK GPO, I have the security setting allowing only the CLERK to read and apply the GPO. On the STORE GPO, I have the security setting allowing only the STORE to read and apply the GPO.
My problem is that I cannot get any of the GPO computer settings to apply to any of the accounts. However, the GPO user settings are applied to the respective accounts according to it's GPO.
The GPO computer settings, however, do apply to the machine if "Authenticated Users" group is in the Security Filter. If I do this, it applies both GPO computer configurations to the machine, which I do not want.
If only I could get the Security Filter to work to only allow a specific group or user to apply the computer configuration, everything would work perfectly. I'm willing to restructure my AD if another structure works better. Any help would be appreciated.
Shon
Network Administrator
My AD Structure is this:
Domain
- My Franchise
| - District Managers
| - Stores
| | · store1
| | · store2
| | · clerk
| | - Computers
| | | · All computer objects here
I have two GPOs applied applied to the STORE OU. They are STORE and CLERK. STORE applies to all the store accounts and the CLERK, which is one account used at all stores, is applied to the clerk account. The Computers OU inherits the two GPOs.
On the CLERK GPO, I have the security setting allowing only the CLERK to read and apply the GPO. On the STORE GPO, I have the security setting allowing only the STORE to read and apply the GPO.
My problem is that I cannot get any of the GPO computer settings to apply to any of the accounts. However, the GPO user settings are applied to the respective accounts according to it's GPO.
The GPO computer settings, however, do apply to the machine if "Authenticated Users" group is in the Security Filter. If I do this, it applies both GPO computer configurations to the machine, which I do not want.
If only I could get the Security Filter to work to only allow a specific group or user to apply the computer configuration, everything would work perfectly. I'm willing to restructure my AD if another structure works better. Any help would be appreciated.
Shon
Network Administrator