Software Restriction - how to allow specific users to use a specific application


i want use software restriction block specific application users except few of them.

lets have ou name - "company", under ou bunch of sub-ou - name "hr", "marketing", "it", etc.

in order block specific application users. create policy path rule set disallowed , link ou - "company". in security filtering, add "domain users" 

this application allow few hr staff use. create policy path rule set unrestricted , link ou - "hr". in security filtering, add custom group name "hr-special-users". username of hr staff need use application add group.

now, problem policy in ou - "company" work. users in group - "hr-special-users" can't open application.

how can make policy rule allow specific users use specific application while other users blocked ?

> application allow few hr staff use. create another
> policy path rule set unrestricted , link ou -
 
this second path rule has "more specific" elected.
 
if both rules identical, deny rule win.
 
alternatively, block gpo "general" deny rule
members of group - gpmc, delegation, advanced -> "apply gpo - deny".
 


Windows Server  >  Group Policy



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Windows 2016 RDS event 1306 Connection Broker Client failed to redirect the user... Error: NULL