none
Apply GPO on a PC in another OU

    Question

  • Hi!

    We need to apply a GPO to a Computer which is in a different OU than the main OU where the GPO is applied. We created a Security Group in the main OU and added that pc in that OU but still the GPO is not applying as the PC is in a different OU. We don't want to move the pc to the main OU.

    Any Suggestions?

    Thanks.

    Wednesday, January 27, 2016 10:52 AM

Answers

  • > We need to apply a GPO to a Computer which is in a different OU than the
    > main OU where the GPO is applied.
     
    Then link your GPO to the different OU, too.
     
     
    Wednesday, January 27, 2016 11:12 AM
  • Hi,

    Fist of all GPO does not apply into Security Group. It only applicable for user account and Computer account.

    As per the mentioned scenario there are 2 solutions for you :-

    Solution-1 :-

    1. Link the GPO into another OU where the computer object is located.

    In that solution all computer into that OU will get the policy. If you don't want to apply this policy to all computer located into that OU. Then go for 2nd Solution

    Solution -2 :-

    1. Link the GPO into another OU where the computer object is located.

    2. As you have created one security group and added the computer object into that OU. So you can do security group filtering into that GPO and mention the security group.

    Once you do security group filtering into that OU and mentioned the group which contain the computer account, then only the mentioned computer will get the policy. No other computer will get it.

    -----------------------------------------------

    Please remember to mark the replies as answers if they help .

    • Proposed as answer by Prips Thursday, January 28, 2016 6:18 AM
    • Marked as answer by Steven_Lee0510Moderator Monday, February 15, 2016 9:48 AM
    Thursday, January 28, 2016 6:18 AM

All replies

  • > We need to apply a GPO to a Computer which is in a different OU than the
    > main OU where the GPO is applied.
     
    Then link your GPO to the different OU, too.
     
     
    Wednesday, January 27, 2016 11:12 AM
  • Hi,

    Fist of all GPO does not apply into Security Group. It only applicable for user account and Computer account.

    As per the mentioned scenario there are 2 solutions for you :-

    Solution-1 :-

    1. Link the GPO into another OU where the computer object is located.

    In that solution all computer into that OU will get the policy. If you don't want to apply this policy to all computer located into that OU. Then go for 2nd Solution

    Solution -2 :-

    1. Link the GPO into another OU where the computer object is located.

    2. As you have created one security group and added the computer object into that OU. So you can do security group filtering into that GPO and mention the security group.

    Once you do security group filtering into that OU and mentioned the group which contain the computer account, then only the mentioned computer will get the policy. No other computer will get it.

    -----------------------------------------------

    Please remember to mark the replies as answers if they help .

    • Proposed as answer by Prips Thursday, January 28, 2016 6:18 AM
    • Marked as answer by Steven_Lee0510Moderator Monday, February 15, 2016 9:48 AM
    Thursday, January 28, 2016 6:18 AM
  • Hi,

    Are there any updates?

    Best Regards,

    Jay


    Please remember to mark the replies as answers if they help and un-mark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Thursday, February 11, 2016 9:21 AM
    Moderator
  • I moved the PC to the OU where the GPO is applied.

    Thanks.

    Sunday, February 21, 2016 7:35 AM