none
Access Denied (Security Filtering) on user link GPO

    Question

  • hi,

      I am trying to apply preference registry settings only for office 2016 users, but i am getting access denied security filtering.

    I link my gpo to users OU.

    Authenicated users has Read and apply GPO check.

    gpo status has Computer Configuration settings disabled.

    WMI Filtering has my custom wmi query call MS OFFICE 2016

    Here is the query:

    Select * from cim_datafile where (Name='C:\\Program Files (x86)\\Microsoft Office\\root\\Office16\\WINWORD.EXE') or (Name='C:\\Program Files\\Microsoft Office\\root\\Office16\\WINWORD.EXE') 

    I want to only Apply who has office 2016 x86 or x64 installed. I ran this query to system has office 2016 and looks fine.

    any help why am I getting Access Denied.


    orion

    Thursday, March 09, 2017 11:57 PM

Answers

  • well I figure it out.

    Under delegation where exception group, I changed to edit settings, works fine now.


    orion

    • Marked as answer by Ultra9.99 Saturday, March 11, 2017 12:32 AM
    Saturday, March 11, 2017 12:32 AM

All replies

  • Hi,

    >>but i am getting access denied security filtering.

    Did all of these users in authenticated users group?

    Please try to add everyone group in the security filtering then try adding again to see if this issue still persists?

    Best regards,

    Andy


    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Friday, March 10, 2017 8:18 AM
    Moderator
  • > Authenicated users has Read and apply GPO check.
     
    Double check the delegation tab of your GPO for entries that have "custom" permissions.
     
    Friday, March 10, 2017 12:48 PM
  • Here what I have so far,

    Autenticated users has read and apply GPO, Added everyone for Read. still gpresult is Access Denied (Security Filtering)


    orion

    Friday, March 10, 2017 6:47 PM
  • I think it is giving me access denied because there is an exception security group is in under Groups OU which above the USERS OU. Since GPO is applied to USERS Group.

          Enterprise ou

                   Groups (exemptions security Groups)

                   Users  (OU)

                   Computers (OU)

    Because as soon I remove Exception Security works fine, add it back access denied.

    There is not there in exception group.

    question: Is this correct that where I am LINKING GPO, it should follow that OU and Under?


    orion

    Saturday, March 11, 2017 12:11 AM
  • well I figure it out.

    Under delegation where exception group, I changed to edit settings, works fine now.


    orion

    • Marked as answer by Ultra9.99 Saturday, March 11, 2017 12:32 AM
    Saturday, March 11, 2017 12:32 AM