question

OchenAo-0382 avatar image
0 Votes"
OchenAo-0382 asked LimitlessTechnology-2700 answered

Group Policy not applying for a Security Group but applies explicitly to a computer

Hi,

I am having a weird issue on my AD environment. I created a GPO (Computer settings) and in Security Filtering i removed Authenticated Users and added a Global Security Group that has a computer nested as a member. The GPO doesn't apply if it is set that way but if i explicitly add the computer account nested in the group, the gpo applies. On delegation, Authenticated Users have only Read permissions, the Group has Read and Apply permissions. There are no other Deny or permission related issues, pretty much straight-forward. The GPO is linked to the OU where the Computer account is, evident by the fact that it applies when the account is added explicitly on Security Filtering.

gpupdate /R /SCOPE COMPUTER shows the GPO as Denied (Security Filtering) for the non-working scenario.

Appreciate some insights on this if anyone has encountered this before? Thanks

Regards,

Ochen

windows-active-directorywindows-group-policy
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

sbairu avatar image
0 Votes"
sbairu answered sbairu edited

Hi @OchenAo-0382 ,

Can you please create a Test OU under your Domain OU, Please Link your computer-based GPO to that test OU and move your machine under Test OU and please verify the GPO with (rsop. msc) from your machine and see if the GPO is working,(This is for testing only)


Go back to your previous and follow below.

if it works please don't remove the Authentication users from the security filter, you make everyone a read-only please refer below. you can add your security based Group to the security filter

https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-firewall/assign-security-group-filters-to-the-gpo

if my suggestion helps, please mark this blog as an acceptable answer. please let me know if you have any questions.

Thanks & Regards,
Sarat

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

cthivierge avatar image
0 Votes"
cthivierge answered OchenAo-0382 commented

You may already did that but, does the computer has rebooted since it has been added to the Global security group ?

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Yep, i already did.

0 Votes 0 ·
OchenAo-0382 avatar image
0 Votes"
OchenAo-0382 answered sbairu commented

Hi, that's my current setup now. A test OU with a single computer, works with Authenticated Users (the default, already tried that). The problem is when i configure security filtering. it works when i add the computer account. The thing here in focus is the Security group.
So, all in all, we have this:

Authenticated Users - Working
Security Group - Not Working
Explicit Computer Account - Working.

Question: Does the Security Group also need to be under the Scope of Management of the GPO?
My answer, at the moment, is a No but I will defer that to the experts.

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

cthivierge avatar image
0 Votes"
cthivierge answered

In the GPO, under delegation tab... validate that the global security group has Allow "Apply Group Policy"... Look the the Advanced Tab

132789-gpo10.png


132833-gpo11.png



gpo10.png (39.2 KiB)
gpo11.png (18.2 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

LimitlessTechnology-2700 avatar image
0 Votes"
LimitlessTechnology-2700 answered

Hello Ochen,

Do Follow up on the thread discussed in the below link, that will definitely help you out with the issue further.

https://docs.microsoft.com/en-us/answers/questions/120736/gpos-not-applied-ad-group-issue.html

Hope this answers all your queries, if not please do repost back.
If an Answer is helpful, please click "Accept Answer" and upvote it : )

Regards,

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.