    Windows 2003 Server. AD domain. Created an OU so that I can apply a Group
    Policy to a collection of users. As per Msoft instructions, I created a
    Local Group, and put that local group inside the OU. Created a Global
    Group, added users to the Global Group, and then added the Global Group to
    this local group. I then created a Group Policy - User Config, and set up
    the restrictions. I applied the GP to the OU, and did a GPUPDATE / FORCE.

    The result is that this GP doesn't affect the pc where the user above logs
    in. If I take the local group out of the OU, and just put the individual
    user account into the OU (instead of the local group), the GP works fine
    when that user logs into a PC.

    Any ideas why this won't work when I use groups to add users to the OU, and
    thus to the Global Policy world?

    CS, Jan 27, 2009
    Group Policies only apply to USER ACCOUNTS and COMPUTER ACCOUNTS ! They
    don't apply to Group Accounts!
    So your experinece was to be expected ;)

    You can only filter GPO scope through its DACL to a group (or any individual

    Claus Greck
    Claus Greck, Jan 27, 2009
  3. Meinolf Weber [MVP-DS], Jan 27, 2009
    Thanks Everyone. That makes sense.

    CS, Jan 30, 2009
