Tag Archives: group policy troubleshooting

Step-by-Step Guide to exclude user or user group from group policy

After few sick weeks I am back in blogging :). In an active directory infrastructure some time you may need to exclude user or user group from a group policy. It can be due to application setting or system setting. Sometime I seen administrators create separate OU and move users there just to get user exclude from particular group policy. It is not necessary to create new OU to exclude users from GPO. In this post I am going to demonstrate how you can exclude a user or group from a GPO.

1)    Log in to a server with administrator privileges (it can be DC server or a server with group policy management feature installed on). I am using windows server 2016 TP5 DC for the demo.
2)    Open the Group policy mmc with server manager > tools > group policy management

gpe1

3)    Then expand the tree and go to the group policy that you like to exclude users or group. In my demo it’s going to be GP called Test1

gpe2

4)    Click on the selected GPO and in right hand panel it will list the settings. Click on delegation tab.

gpe3

5)    Then click on the Advanced button

gpe4

6)    In window, click on add to add the user or the group that you like to exclude

gpe5

gpe6

7)    Then in the permission list, you can see by default Read permission is allowed. Leave it same and scroll down the list to select permission called Apply group policy. Then click on deny permission.

gpe7

8)    Then click on OK to apply the changes. In warning message click on Yes. Now we successfully exclude user2 from the Test1 GPO.

gpe8

gpe9

Hope this post informative and if you got any questions feel free to contact me on rebeladm@live.com

Group policy Troubleshooting – Part 02

This is the Part 02 of the series of posts which explains about methods, tools which can use for group policy troubleshooting. In Part 01 I explain about tool called “Group Policy Results Wizard” which can use for troubleshooting purpose against group policy issues. If you not read it yet you can find it in http://www.rebeladmin.com/2015/08/group-policy-troubleshooting-part-01/

In this post let’s look in to some of other tools.

GPResult.exe command

This is the command version of “Group Policy Results Wizard”. To run it,
1)    Log in to the server
2)    Open command prompt
3)    Type gpresult /s serverorcomputername /user username /r

In here serverorcomputername should replace with the device host name. username should be replace with the username of the account which will evaluate with group policy.

In the demo I used gpresult /s DCM1 /user canitpro\Administrator /r

gp1

gp2

Group Policy Modelling Wizard

This is the advanced and powerful tool which can use on GP troubleshooting. It also gives greater results. Using this we can perform test upon computer, user account using in more detail level and see the impact of different group policies.

To run the tool,
1)    Log in to the DC as domain admin or enterprise admin
2)    Load server manager > tools > group policy management

gp3

3)    Then expand the tree, go to Group policy modelling and then right click on it and select Group Policy Modelling Wizard

gp4

4)    Then it will open the wizard, click next to continue

gp5

5)    Then it’s ask about the domain controller, in here you even can select different domains, sub domains. Do the selections and click next

gp6

6)    Then it’s ask which OUs should use for test. First one is for users and second one is for computers.  After the selection click next

gp7

7)    Then it gives option to select the site. Also you can select to simulate slow link processing and loopback processing, after selection click next to continue

gp8

8)    Then its list down the security groups for the current use. If you need you can select different groups. Click next to continue.

gp9

9)    In next window it list computer security groups, if you need you can add more, click next to continue

gp10

10)    In next window you can add the WMI filters or just use the all linked WMI filters for the users. It depend on the configuration and troubleshooting process. Click next to continue

gp11

11)    In next window you can add the WMI filters or just use the all linked WMI filters for the computers. Click next to continue.

gp12

12)    In next window it gives the summary of the selection. Click next to continue

gp13

13)    Then in next windows click on finish to complete the wizard.

gp14

14)    Then go to console and click on the new object it created and you can see the detail report

gp15

gp16

gp17

If you have any question about the post feel free to contact me on rebeladm@live.com