Users in a GPO - wAlber47/Tech-Journal GitHub Wiki

This SYS255-desktop Group Policy should only apply to those users in this OU who are members of the custom-desktop security group. You set this using the security filters section of the group policy. By default, All Authenticated Users have access to apply and read group policy, we will restrict this through the following steps.

  1. Add the custom-desktop group created earlier to the Security Filter, remove Authenticated users and add Domain Computers.
  2. Then head to 'Delegation' -> 'Advanced' and uncheck Apply Group Policy, select 'Deny'.
  3. From this point, we have defined who the policy will apply to. We can now move forward and assign what the policy is doing.