none
Security Filtering for Apply and Deny in single policy

    Question

  • Hi Team,

    Is it possible to apply security Filtering for Apply and Deny in single policy? Recently I have applied computer policy at domain level and I want to exclude this policy for certain computers?

    Is it achievable by security filtering?

    Regards,

    Karthikeyan R

    Wednesday, June 29, 2016 7:21 AM

Answers

  • Hi Karthikeyan,

    Thanks for your post.

    To achieve your goal, you could try to perform these actions below.

    1. Add those computers, which need apply the GPO, to a computer group
    2. Then you need remove the Authenticated Users from Security filtering
    3. Add the computer group to Security filtering

    Or

    You could add those computers, which do not wat to apply the GPO, to a computer group.

    Then delegate the computer group with deny apply group policy in delegation tab.

    Best Regards,

    Jay


    Please remember to mark the replies as answers if they help and un-mark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Thursday, June 30, 2016 1:18 AM
    Moderator

All replies

  • Deny has precedence over Apply, so it should work

    Gleb.

    Wednesday, June 29, 2016 9:02 AM
  • Hi Karthikeyan,

    Thanks for your post.

    To achieve your goal, you could try to perform these actions below.

    1. Add those computers, which need apply the GPO, to a computer group
    2. Then you need remove the Authenticated Users from Security filtering
    3. Add the computer group to Security filtering

    Or

    You could add those computers, which do not wat to apply the GPO, to a computer group.

    Then delegate the computer group with deny apply group policy in delegation tab.

    Best Regards,

    Jay


    Please remember to mark the replies as answers if they help and un-mark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Thursday, June 30, 2016 1:18 AM
    Moderator