Simply Stated GPOs with user settings in them must targeted at (or filtered to subsets of) user accounts. GPOs with computer settings in them must targeted at (or filtered to subsets of) machine accounts.
Filtering with Security Groups: They can reside in any OU anywhere in Active Directotry. Targeting a GPO at an OU that contains only a security doesn't get you there as there are no user or machine accounts in that OU to be targeted. When you use security group as filters, the machine accounts in the security group only apply to the computer settings and the user accounts in the security group apply only to the user settings.
========================================
Your Stated Situation
========================================
Not quite clear. There are GPO based settings available for Computer Startup or Shutdown scripts and User Logon or Logoff scripts.
Without special GPO processing parameters involving Loopback Policy processing being engaged, it is impossible to target a User Logon script at an OU containing only machine accounts and expect them to run (e.g. no user account targets). The reverse applies as well in that you cannot target Computer Startup scripts at OUs containing only user accounts (e.g. no machine account targets).
You statedAre you sure it is a User Logon script or is it really a Computer Startup script? To figure out what is applying to your devices and where it is coming from, run the RSoP.msc command.The logon script is ... linked to sub-OUs which contain only desktops & laptops - I don't want this script running on servers. The Security Filtering is set to include only myself & a couple of other admins for now to (attempt to) limit the scope of the object.


LinkBack URL
About LinkBacks
Reply With Quote