Denied group policy for a group, but not working

muser 21 Reputation points

I have a group policy , and need to deny that for a group of people. I created a universal security group and added to delegation- advanced - and allowed read and denied apply group policy. But it not working and the the group policy is still applied to that group of people. It works when I deny it for an individual user .Please help.

Please see my GPO settings:

The GPO is applied to entire users and computers, 'Only Authenticated users ' to security filtering. GPO is applied in user configuration .


A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
3,093 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Fan Fan 15,231 Reputation points


    Based on your description , the GPO configuration seem no problem.
    Only the group delegation were not working.
    One situation can be considered that the user didn't recognize the new membership .
    So i would suggest :

    Log on the user and run the command : klist purge and then :gpupdate /force and check if it works.
    If not , try to log off and log on again to refresh the group membership.
    Best Regards,