Group Policy Objects Applied to Organizational Units Containing Only Groups Are Not Applied to Members of Those Groups (220822)



The information in this article applies to:

  • Microsoft Windows 2000 Server
  • Microsoft Windows 2000 Advanced Server
  • Microsoft Windows 2000 Datacenter Server

This article was previously published under Q220822

SUMMARY

Group Policy Objects (GPOs) are applied only to the users or computers that are members of the Organizational Unit (OU) to which the GPO is linked. Groups that are placed in the OU have no effect during the processing of a group policy.

MORE INFORMATION

There are alternative mechanisms that you can use to filter GPOs on the basis of security group membership:
  • Filter by using an access control entry (ACE) placed directly on the GPO named Apply Group Policy.
  • Group policy filtering can be accomplished only by using membership in Security groups. Distribution groups, such as Universal groups, cannot be used to filter the application of group policies.
  • Access control entries can be applied to the group policy from the Security tab of its Properties dialog box.

Modification Type:MajorLast Reviewed:11/13/2003
Keywords:kbenv kbinfo KB220822