Get the App
SLTechnology News&Howtos  ›  Servers  › 

How to set local group policy so that it does not take effect for specific users

Shulou Source: shulou.com Published: 2022-06-01 05:57:10 10月02日 Update

This article mainly shows you "how to set local group policy so that it does not take effect on specific users". It is easy to understand and well-organized, hoping to help you solve your doubts. Let me lead you to study and learn the article "how to set local group policy so that it does not work for specific users".

Scope: the user configuration section of the local group policy.

The user configuration section of the local group policy is stored in the C:\ WINDOWS\ system32\ GroupPolicy\ User\ Registry.pol file.

You only need to set the appropriate NTFS permissions on the file to set the local group policy (user configuration section) that does not take effect for certain users.

For example, enable the "disable registry editing tool" policy entry in the group policy → user configuration → administrative template → system, and now you want to be able to open the registry editing tool when Test users log on to the system (that is, the "disable registry editing tool" policy is not valid for Test users).

You can take the following steps:

1. Open the my computer window and go to the C:\ WINDOWS\ system32\ GroupPolicy\ User folder.

two。 Open the properties dialog box for the Registry.pol file under this folder.

3. Switch to the Security tab, click the add button, add the Test user, and then check the deny check box to the right of the read permission.

4. Click the OK button to save your settings.

Because most of the user configuration settings for Group Policy are loaded into the registry after the user logs in, the system cannot read the C:\ WINDOWS\ system32\ GroupPolicy\ User\ Registry.pol file, so the corresponding Group Policy settings cannot be applied.

Note that the "computer configuration" section of Group Policy is loaded into the registry (under HKLM) before the user logs in, so we cannot customize it by modifying NTFS permissions at this time.

We want to make the group policy restrictions do not apply to specific users, usually referring to the administrator group.

The above is all the content of the article "how to set Local Group Policy so that it does not take effect on specific users". Thank you for reading! I believe we all have a certain understanding, hope to share the content to help you, if you want to learn more knowledge, welcome to follow the industry information channel!

Tags: Users policies files configuration no registry sections content tools permissions articles systems logins buttons folders learning help administration fit security Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno macOS NVidia Xiaomi Apple Huawei