Separate GPO's for computer groups?

Ok, here's my situation.  We have 2 groups I'm trying to work with, normal desktop computers, and then computers in our conference rooms.
For the desktop machines, the users don't have admin rights to install anything, have their printers and network drives mapped and have other settings I want
For the conference rooms I am pretty much setting a common desktop wallpaper that shows our logo, and these machines allow users to install software they want.
I had a problem yesterday when a user told me his mapped drives showed up when he logged into the conference room computer, but he couldn't access the drives, he was denied.
This morning I changed the conference room policy to add a link to the users OU as well as computers, shown here:
It had been linked to just the computers.
My concern is that it appears some of the rules are combining.  Here is the way the desktop policy looks:
When I added the users to the conference room policy users reported that wallpaper they had set on their personal machines was blanked out........ and I don't think that's just by chance.
What can I do to keep these 2 policies separate.  I thought the security filtering would assist with that, but it doesn't appear to be set up correctly.
Can anyone help???
Thanks!
Steve

Hi wingut144,
Based on my understanding, thers are two tyoes of PCs that you want to manage differently: desktop computers and conference room PCs. According to the screenshorts, the GPO COM-Conference Room PC is linked to the OUs Computers and Users,
and the GPO COM-User Computer Second Policy is linked to the OUs Computers, Service Accounts and Users. However, you said the first GPO should only be linke to the OU Computers. Please check if it is right.
As Charlie said, the tool GPResult can help to display which GPOs are applied to the client and which GPO wins. In addition, you can also to set the priority of the two GPOs to decide the applying order if the two GPOs have
configured the same settings.
You can tell us what the settings you want to configure to the different OUs to get more help.
Regards,
Lany Zhang 

Similar Messages

  • Managed (mcx) preferences ONLY works for Computer Groups (Lists)

    AD Server 2008 R2 with extended schema.
    Macs (ML 10.8.5) bound to AD, mcx settings were created for Computer Groups , User Groups (AD security groups), Users
    but ONLY Computer Lists settings apply on the local machine (ANY, not just one)
    I can see it with mcxquery
    Anybody has an idea why that could be & how to sort it, so it DOES apply to user, user groups as well?
    Seb

    Turned out that my user existed as LOCAL user (same name/pass as AD)
    In that way ONLY Machine MCX applies
    Renaming local user & login with AD user applies Preferences correctly
    Seb

  • How to disconnect a network drive filtered to a computer group

    I have a Group of computers that needs to get a specific network drive disconnected. There is a user setting for this but the problem is when i need to filter this against a computer Group. If i have user settings i need to filter against users/user Groups.
    I cant do this on computer configuration, even With script, computer configuration is loaded before the network drive is mapped up. Is there any way i can apply a user configuration filtered towards a computer Group?

    > How is targeting a security group any different than having the GPO
    > filtered towards a security group?
    You can target a computer group in user GPOs. You cannot security filter
    for computer groups in user GPOs.
    > to remove a network drive for a group of computers. There is no setting
    Did you map these drives in a startup script in system context? Or are
    these drives mapped to users logging on to these computers?
    Martin
    Mal ein
    GUTES Buch über GPOs lesen?
    NO THEY ARE NOT EVIL, if you know what you are doing:
    Good or bad GPOs?
    And if IT bothers me - coke bottle design refreshment :))

  • How to export and import "Computer Groups" and "Patch approvals" in WSUS 4.0 ?

    Hi,
    I have a query regarding the export and import options for "Computer Groups" and "Patch Approvals" in WSUS 4.0.
    In WSUS 3.2 once we install WSUS 3.0 API Samples and Tools, we get "WSUSMigrationExport" and "WSUSMigrationImport" tools under
    C:\Program Files\Update Services 3.0 API Samples and Tools\WsusMigrate\ folder. 
    Using the 'WSUSMigrationExport' tool we can export the Computer Groups and the Patch Approvals in a XML file. And using the 'WSUSMigrationImport' tool we can import the 'Computer Groups' and the 'Patch Approvals' from that XML file into a different WSUS
    3.2 server. We can run the import tool as below:
    a. Run command prompt as administrator.
    b. In the command prompt, go to C:\Program Files (x86)\Update Services 3.0 API Samples ans Tools\ WsusMigrate\WsusMigrationImport
    c. Type WsusMigrationImport filename.xml TargetGroups None. Press enter; this will import Computer Groups to the WSUS 3.2 server.
       Type WsusMigrationImport filename.xml Approvals None. Press enter; this will import "Patch Approvals" to the WSUS 3.2 server.
    This is easy and useful.
    Now, for WSUS 4.0 I did not find  "WSUS
    4.0 API Samples and Tools". So I installed "WSUS 3.0 API Samples and Tools" in my WSUS 4.0 server. And tried to import a valid XML file in the above mentioned process. But the command returned an error.
    The error says the "Microsoft.UpdateService.Administration.dll" file was not found.
    I further searched in the internet about this issue and I found that the "WSUS 3.0 API Samples and Tools" is not supported in WSUS 4.0 as the .net framework used in "WSUS 3.0 API Samples and Tools" is 2.0 and WSUS 4.0 uses .net Framework
    4.5.
    So, Here are my questions.
    1. Is it correct that "WSUS 3.0 API Samples and Tools" is not supported in WSUS 4.0?
    2. Is "WSUS 4.0 API Samples and Tools" available?
    3. Is there any alternative way in WSUS 4.0 to export and import XML file consisting "Computer Groups" and "Patch Approvals" configurations?
    I need an urgent reply. Thank you in advance.

    Hi Tapojyoti,
    >>1. Is it correct that "WSUS 3.0 API Samples and Tools" is not supported in WSUS 4.0?
    Yes, WSUS 3.0 API Samples and Tools is not supported in Windows Server 2012R2 by default. We may try to rebuild it in Windows Server 2012R2. For detailed information about how the rebuiled, please refer to the readme document of the WSUS 3.0 API Samples
    and Tools.
    >>2. Is "WSUS 4.0 API Samples and Tools" available?
    No, I can't find the WSUS API Samples and Tools for 2012R2.
    >>3. Is there any alternative way in WSUS 4.0 to export and import XML file consisting "Computer Groups" and "Patch Approvals" configurations?
    As I have mentioned above, due to WSUS 3.0 API Samples and Tools is released with source code, we can try to rebuild it in the Windows Server 2012R2.
    If it doesn't work, as a workaround, we can configure the new WSUS server as the replica server of the existing WSUS server. After the synchronization, change the server mode to stand alone.
    Best Regards.
    Steven Lee
    TechNet Community Support

  • We have 2 itouchs, we a separate itunes account for each one. We have one home computer to use them both on for syc and icloud, the icloud will not accept the 2 accounts?

    we have 2 itouchs, we a separate itunes account for each one. We have one home computer to use them both on for sync and icloud, the icloud will not accept the 2 accounts?

    Do you know what happens if you delete the icloud account from an iphone 4s?  Will it delete the pictures, documents, etc. from the phone, or just unlink the icloud from the phone?  I want to associate a different icloud account to the phone.

  • Approving WSUS updates for one computer group at a time

    We have a WSUS server, and four computer groups (Alpha, Beta, Production, Workstations). Our patching process has us approve all "Not Approved" patches for the Alpha group, right after they're released by Microsoft. One week later, we approve all
    of the updates from the previous week, for the Beta group. One week later, we do the same for Production. 
    I'm writing a script (which I can't test until next week), and wonder if there's a better way to get the list of updates that are approved for Alpha. Here is the code: 
    $updateScope = New-Object Microsoft.UpdateServices.Administration.UpdateScope
    $updateScope.ApprovedStates = [Microsoft.UpdateServices.Administration.ApprovedStates]::LatestRevisionApproved
    $updateScope.FromArrivalDAte = (Get-Date).AddMonths(-1)
    $wsusGroup = $wsus.GetComputerTargetGroups() | Where {$_.Name -eq "$PatchingGroup"}
    $updateScope
    $updateScope.getType()
    $updateScope.count
    $updateScope.ApprovedComputerTargetGroups.add($wsusGroup)
    $wsus.GetUpdates($updateScope)
    $Updates = $wsus.GetUpdates($updateScope)
    I assume I can take the $Updates variable and do the following for the Beta and Production groups: 
    Foreach ($update in $updates) {
    $update.Approve(“Install”,$PatchingGroup)
    Is this going to work, and is there a better way?

    For WSUS Scripts see this: http://poshwsus.codeplex.com/
    ¯\_(ツ)_/¯

  • Separate Header, Main, Trailer for each group of date

    Hi,
    I have report built-in Oracle Reports10g R2, with Header, Main, Trailer sections, I am running report for different date parameters, for instance date between 29-30 Dec, 11.
    But when i get output of the report it do format as I expect, mean output comes in this way Header(29, 30 Dec), Main(29, 30 Dec), Trailer(29, 30). I made separate repeating frame for all of 3 sections which is based on DATE parameter. I want output to be Header(29 Dec), Main(29 Dec), Trailer(29) and same for 30th Dec.
    Somebody will guide me please what is wrong with my report.
    Thanks and Regards,
    Syed Khawar
    Edited by: S.Khawar on Jan 4, 2012 11:44 AM

    Hi bombocha,
    According to your description, you want to export each group to separate Excel File. As tested in my environment, we can use filter and subscription to achieve your goal. Please refer to the following steps:
    Supposing we have a table grouping on SalesTerritoryGroup field, we can create another dataset Dataset2 using the simple queries "Select distinct SalesTerritoryGroup from ...".
    Add a parameter @SalesTerritoryGroup to the report, then get Available Values from Dataset2 SalesTerritoryGroup field.
    Create a filter on the dataset used to extract report data, set Expression: SalesTerritoryGroup, Operator: =, Value: [@SalesTerritoryGroup].
    Deploy the report to report manager and create a data-driven subscription with Windows File Share delivery extension.
    In step 3 of creating the subscription, specify the query as "Select distinct  SalesTerritoryGroup  from ..." and click on Validate button.
    In step 4, set file name as Get the value from the database: SalesTerritoryGroup, and set Render Format to Excel.
    In step 5, as to the SalesTerritoryGroup parameter values, select SalesTerritoryGroup from Get the value from the database drop down list.
    Create a schedule for the subscription, then click Finish.
    For more information about Data-driven Subscriptions, please refer to the following article:
    Data-driven Subscriptions in SSRS
    If you have any more questions, please feel free to ask.
    Thanks,
    Wendy Fu

  • Computer Groups Adding Computers in Bulk

    I have two questions here:
    1.We use a separate tool to patch our systems. Would like to know if we can we use WSUS only for scanning the environment to ensure the systems are patched. If yes, can you point me to some resources that speak about such a configuration.
    2.We intend to create some computer groups in our Windows 2012 WSUS. Is there a way to bulk add computer objects into these newly created group using powershell or other means.
    Thanks

    2.We intend to create some computer groups in our Windows 2012 WSUS. Is there a way to bulk add computer objects into these newly created group using powershell or other means.
    Sort of... maybe. :-) We (SolarWinds) have a
    free tool that's designed to extract groups/computers from a WSUS server to be imported into another WSUS server. The tool was designed for dealing with DR/replica scenarios where server-side targeting is being used, thus avoiding the need to reassign
    all of the computers to groups again.
    The export function produces an XML file which contains all of the groups and computers contained in the WSUS database. This XML file can be edited (e.g. if you wanted to move some computers from one group to another, or add them to another group) prior
    to import).
    As such... it's possible to run the "export" of your WSUS server to build the shell of existing computer groups, and then populate the file with the necessary computer records and re-import the file, effectively creating the computers
    in the database. However, it may not actually be worth the effort, because you'll need to create structured XML records for the computers, including GUIDs, but that's the only way I know of to "push" non-existent computers into a WSUS database, except by having
    the client actually talk to the WSUS server.
    The other option to consider... since you're going to need to create a GPO to configure the clients to talk to WSUS anyway... consider using Client-Side Targeting, and assign the group memberships using Group Policy.
    Lawrence Garvin, M.S., MCSA, MCITP:EA, MCDBA
    SolarWinds Head Geek
    Microsoft MVP - Software Packaging, Deployment & Servicing (2005-2014)
    My MVP Profile: http://mvp.microsoft.com/en-us/mvp/Lawrence%20R%20Garvin-32101
    http://www.solarwinds.com/gotmicrosoft
    The views expressed on this post are mine and do not necessarily reflect the views of SolarWinds.

  • My family has multiple iOS devices, all with 1 Apple ID. With iCloud coming, should I create separate Apple IDs for each member of my family?

    Hello,
    Between my family, we have 2 iPhones, multiple computers, iPads, and an Apple TV ALL tied in to the same Apple ID (the one I created when I got my first device). With iCloud coming, I wanted to know if I need to create separate Apple IDs for each family member (for emails, contacts, calendars, etc.). For instance, I would like to share certain contacts and a calendar with only my wife, all media between all family members, and have home sharing so that I can play/stream content on my Apple TV. Will there be a way to have multiple and distinct me.com accounts and yet share the same Apple ID?
    Apologies for being verbose — just wanted to give ample info/background.
    Thanks,
    Jay.

    I happened to stop at the Apple store yesterday for a separate issue and had a discussion about iCloud. Seems like this is how iCloud works (also, there's another thread on this forum that explains it well).
    Each member of the family can have their own iCloud ID, which will be used for Mail, Calendar, Contacts, Apps, Bookmarks, Media, Photos, etc. and having this content synced automatically with a Mac (computer). The iCloud IDs work in tandem with the associated Apple ID — so while you cannot have multiple Apple IDs, you can certainly have multiple iCloud IDs tagged with a certain Apple ID.
    While all this makes sense from the iOS device standpoint, I'm unclear on how things will sync with a Mac computer, especially if the family uses a single iMac with multiple login IDs for various members. For instance, I currently have an iMac and iTunes content resides in my Public folder, which my wife can still access when she logs in with her login ID. I'm guessing that I'll be able to set up her iCloud ID using her login, set up my iCloud ID using my login, while both our iMac logins will retain the same Apple ID. This would take care of syncing Photos, Contacts, Calendars, etc.
    Another (not sure if unique) problem I face is our Address Book — right now, we have one GIANT address book with different groups set up. Certain groups sync to her iPhone, while others to mine. Some contacts are common between both of us. I'm hoping that if she/I updates a common contact, then the change will be reflected in both our groups of contacts. I hope this makes sense — for instance, I update a contact named Joe, and he's on my group of contacts in my iPhone. Hope iCloud updates the master contact card for Joe on the iMac, which would then automatically trigger the update on my wife's group of contacts—that Joe also belongs to— leading to an update on her iOS device as well.
    Apologies for the lengthy response..

  • How to Separate Management Servers for Ease of Administration?

    Hello,
    I am fairly new to SCOM, though have been charged with creating a monitoring solution for a particular group of customers and integrating it as far as possible into our existing corporate SCOM implementation, so any help, tips and so on would be greatly
    appreciated. 
    The customer monitoring requirements will be very different to those of our fairly standard corporate environment - we will need to monitor very different technologies, with some systems sat in different domains or a DMZ. Our central servicedesk will still
    need to monitor and action alerts and events for both environments as seamlessly as possible. 
    At the same time, I would like to separate the environments as the configuration of the management servers for the customer environment will be quite different from our corporate one, and I want to avoid having to make changes to all our corporate servers
    every time I need to change something on the customer environment - so things like management pack installs, certificate admin, static DNS config and so on. 
    How would I go about this please? Would it be better to create a separate management group, with servers dedicated to the customer environment, then connect this to the corporate management group so that the servicedesk can still monitor it, or is there
    another way of doing it? Perhaps using resource pools? Time will be a factor here, though ultimately the goal is ease of administration going forward. 
    Thanks

    Using resource pools will not allow you to separate configuration such as MP installs, security, etc. as they are all part of the same management group.  From Technet, "A resource pool is a collection of management servers used to distribute
    work amongst themselves and take over work from a failed member."  If configuration needs to be completely separate from the base configuration perspective, you could use separate connected management groups. 
    Another option is to separate the configuration within the management group.  For example, if you need to monitor SQL computers in your corp environment but not the customer environment, simply create a group containing customer computers and override
    the SQL discovery.  This applies to other technologies as well.  You can even group computers by environment (corp/customer) by using reg key attributes like Kevin Holman describes here: (While my account is being verified
    I can't post links but you can search "Creating custom dynamic computer groups based on registry keys on agents").  If you are familiar with MP authoring, you could create a new MP with a new Windows Computer based class instead of extending
    the Windows Computer class.  From a capabilities perspective, you can certainly monitor corporate, customer, DMZ, and other domains in the same management group.  If the domain is untrusted or in the case of the DMZ, workgroups computers, you can
    utilize gateway servers with certificate authentication which will be configured for each domain/dmz gateway.
    Ease of administration is a tricky concept here...if you utilize separate management groups, administration will have to be handled completely separate in 2 separate consoles.  If there are separate SCOM admins per management group, this is
    of no issue, but if 1 team/person is managing both, this can be difficult.  Alternatively, there will be some up front work to using groups to separate the environments using groups, discoveries, etc.
     

  • Clearing historical WSUS approvals for computers groups

    Hi there,
    I have inherited a messy WSUS environment that I have to use until 2015.
    We patch in quarterly cycles Jan/Apr/Jul/Oct and split out systems out into Computer Computer Group then sub-group Dev/Prod/QA.
    I have updates that have been missed over the past year that I'd like to get installed on the handful of servers that missed it in previous quarter patching
    for whatever reason. However, when I approve the update, it also installs on any needed server in previously approved Computer Groups.
    I have approved an update for BI Production Servers and BI QA Servers earlier in the year. I now wish to approve the same update to BI Test Servers. In
    the mean time, an additional server has been added to BI Production Servers that does not have this update, but as being production I do not wish to install it, just yet.
    I approve the update for BI Test Servers. The GPO sets patches to install on Sundays at 0300. This time comes
    around and both the server in BI Test Servers and BI Prod Servers have received the update.
    My assumption, as mentioned earlier, is that because BI Productions Servers had had approval for this update at an earlier time, it applied to the server in this group and installed automatically.
    I had thought deleting any old Update Views would have mitigated this, but I guess they are just views.
    What I would like to do, is to clear all previous approvals in WSUS, so the system thinks no updates have never been approved. Is such a thing possible?We're
    running the system on SQL so a query that can amend this would also be an option.
    The system is also running a downstream server, so any changes would need to propogate downwards. Unsure if SQL would cope with this.
    Sorry for such a long post!
    Any help gratefully received!
    Lewis

    What I would like to do, is to clear all previous approvals in WSUS, so the system thinks no updates have never been approved. Is such a thing possible?
    Sure! Open the All Updates View. Ctrl-A. Right-Click. Select NotApproved for "All Computers" and inherit to all groups. If you're lucky, the UI won't timeout trying to complete the task.
    Kinda radical, though, if you ask me.
    It might be more productive to back up a step and make sure that you fully understand the association between approvals, groups, and members, and what behaviors will occur as a result, and simply set the approvals the way they should be, and remove the approvals
    from updates that shouldn't be.
    In the mean time, an additional server has been added to BI Production Servers that does not have this update, but as being production I do not wish to install it, just yet.
    If you put a machine in a group that has approved updates, that machine is going to get ALL of the approved updates that are not yet installed -- particularly if it is *configured* to do that. Part of the challenge here seems to be confusing the concept
    of *Approval* (permission/authorization) with the actual *Deployment* (action) of the updates. A second part of the challenge here is that your servers should not be able to *automatically* install updates if you wish to expressly control when they do that.
    My assumption, as mentioned earlier, is that because BI Productions Servers had had approval for this update at an earlier time, it applied to the server in this group and installed automatically.
    This is absolutely correct.
    I had thought deleting any old Update Views would have mitigated this, but I guess they are just views.
    Also correct. Views are views -- just a collection of updates with common attributes.
    Approvals are approvals.
    The system is also running a downstream server, so any changes would need to propogate downwards.
    Important point! All changes WILL propgate downwards, but removing the approvals from hundreds (if not thousands) of updates will functionally break the downstream server. This forum is replete with conversations about people who have declined hundreds of
    updates in one pass. The server-to-server synchronization task is just not equipped for that volume of event transactions.
    If you truly feel the need to remove all of the approvals, it would likely take less time to build a new downstream server and sync after the approvals have been removed.
    For that matter, it would likely take less time to rebuild the UPSTREAM server, than to try to remove every approval in the system!
    Lawrence Garvin, M.S., MCSA, MCITP:EA, MCDBA
    SolarWinds Head Geek
    Microsoft MVP - Software Packaging, Deployment & Servicing (2005-2014)
    My MVP Profile: http://mvp.microsoft.com/en-us/mvp/Lawrence%20R%20Garvin-32101
    http://www.solarwinds.com/gotmicrosoft
    The views expressed on this post are mine and do not necessarily reflect the views of SolarWinds.

  • HT201272 If I create separate Apple IDs for my children, will they still be able to access content I have purchased on their iPhones and iPads?

    If I create separate Apple IDs for my children, will they still be able to access content I have purchased on their iPhones and iPads?

    I happened to stop at the Apple store yesterday for a separate issue and had a discussion about iCloud. Seems like this is how iCloud works (also, there's another thread on this forum that explains it well).
    Each member of the family can have their own iCloud ID, which will be used for Mail, Calendar, Contacts, Apps, Bookmarks, Media, Photos, etc. and having this content synced automatically with a Mac (computer). The iCloud IDs work in tandem with the associated Apple ID — so while you cannot have multiple Apple IDs, you can certainly have multiple iCloud IDs tagged with a certain Apple ID.
    While all this makes sense from the iOS device standpoint, I'm unclear on how things will sync with a Mac computer, especially if the family uses a single iMac with multiple login IDs for various members. For instance, I currently have an iMac and iTunes content resides in my Public folder, which my wife can still access when she logs in with her login ID. I'm guessing that I'll be able to set up her iCloud ID using her login, set up my iCloud ID using my login, while both our iMac logins will retain the same Apple ID. This would take care of syncing Photos, Contacts, Calendars, etc.
    Another (not sure if unique) problem I face is our Address Book — right now, we have one GIANT address book with different groups set up. Certain groups sync to her iPhone, while others to mine. Some contacts are common between both of us. I'm hoping that if she/I updates a common contact, then the change will be reflected in both our groups of contacts. I hope this makes sense — for instance, I update a contact named Joe, and he's on my group of contacts in my iPhone. Hope iCloud updates the master contact card for Joe on the iMac, which would then automatically trigger the update on my wife's group of contacts—that Joe also belongs to— leading to an update on her iOS device as well.
    Apologies for the lengthy response..

  • Page break for a group and sub group based on page length

    Hi
    I have a requirement where in I need to develop a report which has the following requirement. I am attaching the sample xml and rtf files for reference:
    1) There are 3 groups in the Data Model. G1, G2 and G3. G1 contains G2 and G2 contains G3. I need to display that data in that order in the rtf template. Pretty straight forward.
    2) The tricky part, however, is that the report needs to have a page break on the following conditions:
        a) When the value of col1 changes which is in G1
        b) On col3 (in G2), but only when there is not enough space on the page to accommodate the values present in G3, ie col5 and col6 alongwith the values in G2. This means when the value of col3, which is present in G2, changes and if there is not enough space to accommodate G2 and G3 on the same page, it should break and start on a new page. The table which should come together is marked in grey color in the RTF template.
    What I have done till now to achieve this?
    I have created a parent table with two rows. In the second row I have made sure that the row doesn't break across pages. This is true for all the subsequent tables in the report. Now, in that second row, I have col1 in a nested table within a repeating group G1. Inside G1 there is a nested table for G2 and within G2 I have another table for the group G3. The row is not breaking across pages for all the tables that have been created.
    I have tried all the permutations and combinations of nested tables, keeping G1, G2 and G3 in the same table but different rows, having G1 in one table and nesting G2 and G3 in another, keeping G2 and G3 in a separate table altogether, Keeping G1, G2 and G3 all of them in the separate table. All of them are apparently not working.
    Is there anyway where we can either get hold of the current position of the cursor and the total number of rows on that page? Or any other solution that is possible? Or if I can have to make changes in the data model?
    Thanks a lot in advance
    Sid

    Hello Sid,
    I have checked your report and XML Sample and you haven't linked the fields from XML Sample to your .rtf report.
    You can use <?for-each?> syntax for your groups to print the content.
    I recommend you to review our "Creating RTF templates" manual:
    http://docs.oracle.com/cd/E28280_01/bi.1111/e22254/create_rtf_tmpl.htm#BIPRD2354
    Regards,
    Liviu

  • How to create a group policy for a group not to logout from rdp

    there is already a global policy for all users in OU which will disconnect a rdp session after 15 min of inactivity and log user out in another 15 min, (logout 30minutes)
    how do I create another policy  for a group in that OU so that group user will not be logged out ( executives are asking for this)?

    Hi,
    In addition to Martin’s suggestions, we can also choose to change the scope of the existing GPO with Security Filtering.
    Regarding Security Filtering, the following article can be referred to for more information.
    Security filtering using GPMC
    http://technet.microsoft.com/en-us/library/cc781988(v=WS.10).aspx
    Filter Using Security Groups
    http://technet.microsoft.com/en-us/library/cc752992.aspx
    Best regards,
    Frank Shen

  • HT204053 I have three IOS devices and would like to have separate iCloud IDs for each device, but I would to keep one Apple ID for iTunes that share with my spouse for purchasing.  Please help

    How do I create separate iCloud id for three of my IOS devices?
    1.  Iphone
    2.  Ipad
    3.  Macbook air

    If she doesn't have an iCloud account on her iPhone or iPad now, you can just go to Settings>iCloud and sign in with a different Apple ID to set up the new account, then turn on the data that you want to sync with iCloud.  She can continue to use the same ID for the App and iTunes store; it doesn't need to be the same as the the ID she uses for iCloud.
    If she is already sharing your iCloud account on her devices, you should go to Settings>iCloud on her phone, tap Delete Account (which only deletes the account from her phone, not from iCloud), when prompted choose Keep on My iPhone, then set up a new account by signing back in with a different Apple ID.  Then turn on the data she wants to sync with iCloud, and when prompted, choose Merge to upload her data to the new account.  After doing this on her phone, go to Settings>iCloud on her iPad, tap Delete Account, when prompted choose Delete from my iPad, then sign into the new account just created on her phone using the new ID and turn on her data syncing to sync the iCloud data in the new account to her iPad.  Finally, if you have any merged data in your accounts from sharing the original account, you'll need to go to icloud.com on your computer, sign into each iCloud account separately and delete the data you don't want from each account.

Maybe you are looking for

  • C++ Runtime error while executing

    I have the problem that an application file  application.exe starts with the following error message on my target device (Windows XP SP2).. The application continues to run and does not show any malfunction. I have been creating LV8.6 builds on my de

  • Exit or BAdi for Validating GR posting date Greater than PO creation date.

    Hi all , Is there any Exit or BAdi for restricting users to post GR date greater than PO creation date. Regards Gibi Philip

  • General Preferences

    Hi, I have been looking around the forum for a solution to a problem that may have already been answered but I cannot find it. Is there a way to export the 'General Preferences' of a project and import them into a new project? I have approx 20 projec

  • MacBook Pro (late 2009) running slow after Mavericks install - EtreCheck printout included

    Any advice appreciated! Restarted my computer and ran EtreCheck prior to opening any programs. EtreCheck version: 1.9.11 (43) - report generated June 7, 2014 at 4:32:12 PM CDT Hardware Information:           MacBook Pro (13-inch, Mid 2009)           

  • Opening Excel XLS files in Numbers

    I have Mac OS 10.6.2 on my MacBook using Numbers '09. A windows excel pc user sent a xls file. When I try to open this file on my MacBook with Numbers is get message "The document is encrypted and can't be opened." The windows user says the file is n