Group Policy Objects Applied to Organizational Units Containing Only Groups Are Not Applied to Members of Those Groups

ID: Q220822


The information in this article applies to:
  • Microsoft Windows 2000 Server
  • Microsoft Windows 2000 Advanced Server
  • Microsoft Windows 2000 Datacenter Server


SUMMARY

Group Policy Objects (GPOs) are applied only to the users or computers that are members of the Organizational Unit (OU) to which the GPO is linked. Groups that are placed in the OU have no effect during the processing of a group policy.


MORE INFORMATION

There are alternative mechanisms that you can use to filter GPOs on the basis of security group membership:

  • Filter by using an access control entry (ACE) placed directly on the GPO named Apply Group Policy.


  • Group policy filtering can be accomplished only by using membership in Security groups. Distribution groups, such as Universal groups, cannot be used to filter the application of group policies.


  • Access control entries can be applied to the group policy from the Security tab of its Properties dialog box.


Additional query words:

Keywords : kbenv
Version : WINDOWS:2000
Platform : WINDOWS
Issue type : kbinfo


Last Reviewed: December 29, 1999
© 2000 Microsoft Corporation. All rights reserved. Terms of Use.