question

CCTCN-8858 avatar image
0 Votes"
CCTCN-8858 asked FanFan-MSFT commented

Folder Redirection - Do not apply to user on specific PC

I have a GPO for folder redirection set up on a user GPO. This is applied to authentication users on the whole domain. I need User A to have his folder redirections on Computer A but Not on Laptop A. How can I acheive this?

windows-serverwindows-group-policy
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

FanFan-MSFT avatar image
0 Votes"
FanFan-MSFT answered FanFan-MSFT edited

Hi,

This can be achieved by the security filter.
Remove the authenticated users from the delegation tab on the GPO.
Add users will apply the policy ,and grant **"read" and "apply group policy "**permission.
Add computer A ,grant read permission.
80416-3232.jpg
Then only users log onto the computer A, the group policy will apply.

Best Regards,



3232.jpg (67.7 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

CCTCN-8858 avatar image
0 Votes"
CCTCN-8858 answered

Hi

My GPO is a user configuration for folder redirection.


Could I just deny group policy to a specific computer? would this work?

I dont fancy having to add users and computers to a GPO whenever we get a new one.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

CCTCN-8858 avatar image
0 Votes"
CCTCN-8858 answered

So, i've created a new OU and put my computer in there.

I've created 2 policies:

Computer Policy which turns on loopback in REPLACE

User Policy which specifies to ues localprofile for desktop and documents folder

When I do GPRESULT I can see the loopback policy has applied and my new policy for folder redirection has applied but the existing folder redirection is also still applying.

What have I done wrong?

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

FanFan-MSFT avatar image
0 Votes"
FanFan-MSFT answered FanFan-MSFT commented

Hi,

We don't need to enable the loopback policy , it will make the situation more complicated.
When i said add or remove users it is just to set the gpo permissions.
It will be simple and easier to manage .

If you want to use the deny permission.
You can tried to deny the read permission for the SPECIFIC computers on the GPO.

Best Regards,

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi,
 
Just want to confirm the current situations.
If there's anything you'd like to know, don't hesitate to ask.

Best Regards,

0 Votes 0 ·