GPO Denied (Security Filter) not applying

38,012

You probably removed Authenticated Users from the Group Policy, if so:

Add Authenticated Users back by using the "Delegation" tab and select "Read" on the role (very important). The Authenticated User should NOT be able to "Apply the Group Policy" but just "Read" the group policy (otherwise your filter based on the group membership will not work).

Since June 2016, the group policies are retrieved with the computer account (including users group policies), so you must allow the computers to read the policy settings.

Share:
38,012

Related videos on Youtube

Gustavo Mendes
Author by

Gustavo Mendes

Updated on September 18, 2022

Comments

  • Gustavo Mendes
    Gustavo Mendes over 1 year

    I am having an issue in my company.

    I have a GPO, and one group in security filter, lets name it group X. In my delegation, I set the permissions to X (Allow Read and Allow Apply Group Policy).

    The user is in the group X, and when I log on the computer, this GPO is denied by the security filter. How can I troubleshoot to identify where it is denying this GPO?

    I don't know if this is relevant, but this group X denies another GPO and allows this specific one.