How to apply "user configuration" of GPO of specific OU when they login on specific computers?

For example:
Only users belong to OU1 cannot access control panel when he log on to computer1 which belongs to OUA, how to do that with GPO?
The users in OU1 CAN access control panel when they log on the computers which NOT in OUA, and users who are not belong to OU1 CAN access control panel when log on  computer1.
 thanks.

It sounds like you need loopback enabled. Loopback allows you to apply user side settings to a computer.
http://deployhappiness.com/loopback-policy-how-a-computer-gets-a-transgender-operation/
http://deployhappiness.com/questions-about-loopback-policy-processing/
If my answer helped you, check out my blog:
Deploy Happiness

Similar Messages

  • How does one get open applications to reappear on desktop when they have disappeared?

    How does one get open applications to reappear on desktop when they have disappeared? They disappeared by something I did but don't know what.

    Try clicking on their Dock icon. Or you can use the task bar: COMMAND-TAB.

  • How can I stop receiving email automatically from the community when they have issues with there problems regarding the apple products.

    How can I stop receiving email automatically from the community when they have issues with there problems regarding the apple products.

    Click here for the instructions on stopping the emails.
    (85713)

  • How to stop users configuring mail in iphone

    Hi
    My company want to restrict users configuring official mails in mobile phone without getting proper approval. I disabled active sync for the users, but still the user able to configure mail in iphone devices..
    Anybody tell me how to restrict this..

    see if this helps u
    http://blogs.technet.com/b/exchange/archive/2010/11/15/3411539.aspx
    Blog: http://theinfraguys.com
    Follow me at Facebook
    The Infra Guys Facebook Page
    Please remember to click Mark as Answer on the answer if it helps you in anyway

  • How to prevent users configuring outlook in personal laptops

    Hi 
    we are having exchange server 2010 and my company don't want to allow users to configure outlook in there personal laptops(system which is not in domain).
    FYI we cant disable outlook anywhere since people using official laptop outside.
    Outlook anywhere, webaccess hosted through ISA 2006.
    Is there any way to do it..

    Hi
    Thank you for response.
    Please correct me if iam wrong, by enabling this option i can configure outlook only in my domain laptops right.
    Also please tell me is it possible to configure mail in mobile right, because only i have to restrict user configuring outlook in there personal laptops.
    Also after doing this i am not able to login OWA(Web access).
    Hi,
    Yes, there are some restrictions if you limit the computer name in AD for user accessing. This would limit users only log on the Windows machine and Outlook on the specific computer. If the user wants to access his account or Outlook in another domain-joined
    computer which is not in the Log On To list, it can’t be succeed either.
    If that is not what you needed, I think we need to disable Outlook Anywhere and use VPN for the remote official laptop. Here is a similar thread for this requirement:
    https://social.technet.microsoft.com/Forums/en-US/66396999-c859-43c2-abc6-430a926fe0a0/restrict-outlook-access-only-to-domain-joined-pcs?forum=exchange2010
    Regards,
    Winnie Liang
    TechNet Community Support

  • Some users are having access to all mailboxes when they configure thier outlook

    for 7 users the get access to all mailboxes so when they configure their outlook profile they get about 700 mailbox so outlook hangs this happens with new created users the same 7 users will get access to them as will 
    i tired this
    Get-Mailbox | Remove-MailboxPermission -User Administrator -AccessRights Fullaccess -InheritanceType all
    nut then i got this
    An inherited access control entry has been specified CreateChild ControlType Allow
    then o tried removing from the DB level
    Remove-Adpermission "DB" -user "jobs" -extendedrights Receive-As
    Remove-Adpermission "DB" -user "jobs" -extendedrights send-as
    Remove-Adpermission "DB" -user "jobs" -extendedright ms-Exch-Store-Admin
    but stilll the same

    hi thank you, looks i need some more detail on how to do this
    i saved the lines on a .ps1 file tried to run it on exchange and i got the below , can you illustrate more how to do this
    The operation couldn't be performed because object 'sharedmailbox' couldn't be found on 'DC.mydomain.com'.
        + CategoryInfo          : InvalidData: (:) [Get-MailboxPermission], ManagementObjectNotFoundException
        + FullyQualifiedErrorId : E61E2EBE,Microsoft.Exchange.Management.RecipientTasks.GetMailboxPermission
    Cannot bind argument to parameter 'Instance' because it is null.
        + CategoryInfo          : InvalidData: (:) [Remove-MailboxPermission], ParameterBindingValidationException
        + FullyQualifiedErrorId : ParameterArgumentValidationErrorNullNotAllowed,Remove-MailboxPermission
    Cannot bind argument to parameter 'Identity' because it is null.
        + CategoryInfo          : InvalidData: (:) [Add-MailboxPermission], ParameterBindingValidationException
        + FullyQualifiedErrorId : ParameterArgumentValidationErrorNullNotAllowed,Add-MailboxPermission

  • Chat App: how to store the user IP in database when they login.

    hello,
    i am working on chat application. first i made a login GUI form. after login when we run the Chat program, it ask the ip address of the server to whom it want to connect. and if u enter the ip address, it will connect to the server and chat will begin, thats working perfect.
    but i want to show the list of users who r logged on and when i simply click on the user name, chat should begin.
    i have the logic that when any user log in, then its IP address will be stored in the database. this ip address will shown to the online users.
    but i dont know how to store the user information in database when they log in. can any body suggest me wht lines of code i should use.
    thanks.

    palakk wrote:
    i have the logic that when any user log in, then its IP address will be stored in the database. Bad approach. That will only work if this chat is only intended for use on a LAN. If it's used on the internet, then your users' IP addresses will almost always be either a) those of their routers, or b) private IP addresses, and in both cases, multiple users can have the same IP address.
    this ip address will shown to the online users. Why would you want to do that? I want to chat with "Bill", not with "1.2.3.4".
    but i dont know how to store the user information in database when they log in.Do the same thing that you're currently doing to store the IP address, but with the other information you want to store.
    can any body suggest me wht lines of code i should use. This is not a code writing service.

  • Users are being prompted for Admin credentials when they attempt to print.

    Hello!  I am a Tech assistant at a public school and we have run into an issue with our students and their MacBooks & MacBook Pros.
    Whenever our students attempt to print to any printer in their school building they are prompted for administrator credentials.  I have attached examples of the message they are getting:
    We are not sure how to go about tackling this issue.  We are getting this message on both MacBooks and MacBook Pros.  They are all running Mountain Lion.  Last year they were all on Lion and we never had this issue.  Could this possibly be a known issue with Mountain Lion???  Once we type in the administrator credentials for the students they are able to print from then on.  Many of the students are also seeing this message when they try to print at their homes.  It seems to have something to do with printing permissions but we're just not sure.  Any help would be very much appreciated!
    Thanks!

    You used Workgroup Manager, Profile Manager, or Parental Controls to restrict users from printing or adding a print queue. Remove or modify those restrictions the same way.

  • How do I delete names from the drop down list when I login to gmail and facebook?

    When I login to gmail and facebook several login names used in the past show up in a drop down list. I want to remove some of these names. How do I do that?

    On Mac you need to use Shift+Delete
    *http://kb.mozillazine.org/Deleting_autocomplete_entries
    *Click the (empty) input field on the web page to open the drop down list
    *Highlight an entry in the drop down list
    *Press the Delete key (on Mac: Shift+Delete) to remove it.
    *Firefox > Preferences > Security: Passwords: "Saved Passwords" > "Show Passwords"
    *https://support.mozilla.com/kb/make-firefox-remember-usernames-and-passwords

  • How to apply Computer Configuration to users with Security Filtering?

    I have a gpo that contains both user and computer settings.  In order to test it, I want to link it to an OU that contains users and their computers, but I want to use Security Filtering to apply it only to certain users (I don't have their computer
    names).
    Is there a way to filter it to only certain users without losing the computer settings?

    > Is there a way to filter it to only certain users without losing the
    > computer settings?
     Computers look for computer settings in a GPO they have access to.
    Users look for user settings in a GPO they have access to.
    SO you might simply remove "Authenticated Users" (which includes both
    computers and users) from security filtering. Then add "Domain
    computers" which gives all computers access to computer settings, and
    add the users in question, which gives THESE users access to user settings.
    Don't enable loopback and play around with it unless you are sure you
    fully understand what it is doing!
    http://evilgpo.blogspot.de/2012/02/loopback-demystified.html
    http://blogs.technet.com/b/askds/archive/2013/02/08/circle-back-to-loopback.aspx
    Martin
    Mal ein
    GUTES Buch über GPOs lesen?
    NO THEY ARE NOT EVIL, if you know what you are doing:
    Good or bad GPOs?
    And if IT bothers me - coke bottle design refreshment :))

  • How to apply an InDesign Paragraph Rule above, but not when first in column

    How do I apply a paragraph rule "above" but not when first in a column. In other words, the rule above will only run if it isn't the first paragraph in the column (even if it appears in a multi-column text frame).
    Before you jump the gun: Rule below will not solve that, for various reasons.
    Thanks much in advance.

    Aha! Apparently totally!
    Here a similar way to yours with an anchored block. Copy it and launch this simple regex. Easy with no headache! 

  • In iPlanet Web Proxy Server 3.6 on Win2000, how do I turn on authentication?  I want to force users to enter an id and pw when they go thru the proxy to websites out on the net. Thanks

     

    Mal,
    You'll need to point to some user database, either the local db on Proxy or an ldap server. The ldap server is the best choice as the local db just stores users in a flat file and becomes unreliable after 1000 entries.
    To enable authentication, manage the proxy server instance and navigate to Restrict Access.
    From there, turn on access control, and click on the Permissions button. This will open up a new window to allow you to setup your access control rules and restrictions. When you're done, click on Done, apply your changes and restart the proxy server and you should be on your way.

  • How can pine users access their iPlanet account without identifying first to login, and then when they run pine?

    At University we have just completed migration to iPlanet Messaging Server 5.2. Users of UNIX and pine now have to identify twice to get email. As stated in the question, they have to login to their shell, and then pine forces another login. Each additional time they run pine to check email it requires a new login.
    Is there any way to get rid of the additional authorizations required to read email after someone is successfully authenticated to our own student/faculty servers? Perhaps adding some sort of Kerberos ticket system?
    Thank You

    At University we have just completed migration to iPlanet Messaging Server 5.2. Users of UNIX and pine now have to identify twice to get email. As stated in the question, they have to login to their shell, and then pine forces another login. Each additional time they run pine to check email it requires a new login.
    Is there any way to get rid of the additional authorizations required to read email after someone is successfully authenticated to our own student/faculty servers? Perhaps adding some sort of Kerberos ticket system?
    Thank You

  • How can another user on my system share their document if they cannot access a public drop box, do not have an email account setup on the system and we don't want to use iwork?

    Please help. My DS created a document under his login on my PowerBook and now, I cannot seem to access it. He doesn't have an email account of his own, I can't seem to save it as a public document in a drop box like I can from my own login and we do not want to use iwork. Is there a way to save it so that I can access it from my login to email to his teacher. I don't want to have to retype it into Pages under my login.

    Save the document from his account to an external drive or thumb drive.
    Set the permissions (using Finder > Get Info) for "Everyone" to Read and Write.
    Your DS will likely be the owner of the file, so you may need his login password to change the permissions.
    Regards,
    Barry

  • How can i let people make adjustings in my app when they use it

    I want people to adjust their wishes in my app. 
    So if I would set 4 website links to 4 random websites. Then people that download my app should be able to adjust the website to any of their favourites. This way it works best for them.
    Can anyone please explain how it's possible to do this with Dreamweaver CS6
    Thanks in advance

    It's a little clearer, but not 100%. The application needs to allow the user to store their favorites in a database table on your server. For example, the database might have two tables - one to store the user's credentials and other related data, and another table to store their favorite url's. DW has some built in server behaviours for inserting, deleting and displaying data from a database that can help with this, but you really need to be familar with programming in the server side language you are using as well as SQL.
    But I'm still confused as to how you are building this. This forum is for server side appliation development, but you mentioned that people would download your app? What are they downloading? Have you started building this? What server side scripting language are you using?

Maybe you are looking for