GPO not applying computer configuration

mginster 11 Reputation points
2022-11-04T18:17:53.987+00:00

I setup a GPO to apply some user and computer settings. I do want to restrict these user settings to only a specific group so am using security filtering.

GPO:
Security filtering has only the AD group to apply permissions
Delegation -Authenticated users has Read only. AD group to apply has Read / Apply rights.

User policies are applying, but computer policies are not.

I added "Domain Computers" to delegation with "Read" only and it still wont apply.

How do I apply GPO's for only a specific group? I read all the documentation online and it did say to add the group with (Read/Apply) and set Auth users to (Read). This does not work.

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
5,060 questions
0 comments No comments
{count} vote

5 answers

Sort by: Most helpful
  1. mginster 11 Reputation points
    2022-11-07T15:50:18.793+00:00

    1 OU with the computers added.

    GPO has both user and computer settings.

    When set to Auth users read only, targeted group read/apply, it works for user settings. Computer settings do not apply. After adding "Domain Computers" with read/apply to security filtering its working now.

    1 person found this answer helpful.

  2. Daisy Zhou 21,046 Reputation points Microsoft Vendor
    2022-11-07T06:07:23.493+00:00

    Hello mginster-0346,

    Thank you for posting in our Q&A forum.

    Based on the description,

    1.Did you put users and computers on the same OU or different OU?
    2.Did you configure user settings and computer settings within the same GPO?
    3. Or did you configure user settings in one GPO and configure computer settings in the other GPO?

    Usually, I assume the case is like this:

    For user group policy configuration
    1.Put user objects in OU1.
    2.GPO1 with user settings and linked GPO1 to OU1.
    3.We can make Authenticated Users have "Read" permissions.
    4.Then add user group and make this user group have "Read" and "Apply group policy" permissions.
    5.Users in OU1 should apply user settings within GPO1.

    For computer group policy configuration
    1.Put computer objects in OU2.
    2.GPO2 with computer settings and linked GPO2 to OU2.
    3.We can make Authenticated Users have "Read" permissions.
    4.Then add computer group and make this computer group have "Read" and "Apply group policy" permissions.
    5.Computers in OU2 should apply computer settings within GPO2.

    Hope the information above is helpful.

    Best Regards,
    Daisy Zhou

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments

  3. Xavier GAILLARD 21 Reputation points
    2023-01-20T17:25:26.7166667+00:00

    Bonjour, j'ai exactement le même problème pouvez-vous m'en dire plus car je recherche le paramètre en question je ne vois pas bien ou effectuer le paramétrage que vous avez fait pour résoudre le problème merci par avance de votre réponse

    0 comments No comments

  4. Namakkal Kandasamy, Prasaanth 0 Reputation points
    2023-07-19T08:49:58.3833333+00:00

    I have similar type of problem I have created two GPO one with computer configuration and other with User configuration. while testing GPO with Computer configuration is applied and GPO with user configuration is not applied to the user

    It is not listed with this cmd : Gpresult /r / Scope:user

    Welcome for your suggestions

    0 comments No comments

  5. Duran, Erwin 0 Reputation points
    2024-07-08T09:56:15.66+00:00

    Need Help: I just created a GPO for under user configuration. the GPO will aims to install SSL certificate for a website using a batch file and is stored in the logon script.

    i tested the script multiple times and it is working. when I log into the test machine an run gpresult /r

    I can see that the policy I have created is being rolled out to the test machine and the script is also showing when running rsop. but the cert is not installed on the test machines when i run the MMC

    I hope someone can assist me on this

    0 comments No comments