I have heard that you can disable either the computer or the user side of a GPO. Are there any advantages to this?


Not Really. Although you may speed up the performance by a hair, it isn’t worth the hassle that it introduces down the road of troubleshooting the GPO when you or someone else doesn’t know that half the GPO is disabled. A well designed OU and GPO structure will only need to utilize one side at a time anyway as user accounts and computer accounts should be separated.