# Group Policy Security Filtering: 6 Ways to Target or Exclude

Source: https://srvscripts.com/guides/group-policy-security-filtering/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

Group Policy security filtering decides which users and computers inside a linked OU actually apply a GPO, based on two permissions on the GPO itself: Read and Apply group policy. Linking controls where a GPO can apply; security filtering narrows that scope to the accounts and groups you choose, and Deny entries carve out exceptions. This guide covers how the permissions work, the Read requirement introduced by MS16-072, filtering by user and computer groups, exclusions, PowerShell management and how to fix a GPO that gpresult reports as Denied (Security).

**Short answer:** In GPMC, select the GPO, and on the **Scope** tab remove Authenticated Users from **Security Filtering** and add your group. Then open the **Delegation** tab and add Authenticated Users back with **Read** only. Restart the target computers (or sign users out and in) so their new group membership is in the Kerberos ticket, and run `gpresult /r` to confirm.

In short: In GPMC, select the GPO, and on the Scope tab remove Authenticated Users from Security Filtering and add your group.

## How security filtering works

A computer or user applies a GPO only when both conditions are true: the account can read the GPO, and it has the Apply group policy permission, either directly or through a group. By default every new GPO grants Authenticated Users both permissions, so it applies to everything in the linked containers. Group Policy security filtering changes who holds the Apply permission.

| Goal | What to configure | Where | Notes |
| --- | --- | --- | --- |
| Apply to one group only | Remove Authenticated Users from Security Filtering, add the group | Scope tab | Add Authenticated Users back with Read on the Delegation tab |
| Apply to everyone except one group | Deny Apply group policy for the exception group | Delegation » Advanced | Deny wins over Allow; invisible on the Scope tab |
| Apply to specific computers | Add a computer security group (or computer accounts) | Scope tab | Membership changes need a restart or a ticket purge |
| Apply to specific users | Add a user security group | Scope tab | Membership changes need a new sign-in |
| Apply by OS, hardware or model | WMI filter | Scope tab, WMI Filtering | Evaluated on the client every refresh |
| Target single preference items | Item-level targeting | GPP item, Common tab | Preferences only, not Administrative Templates |

Only security groups work. Distribution groups have no SID in the token and are ignored. Nested security groups are evaluated normally, because Windows checks the full token.

## Prerequisites

- Domain-joined Windows 11 Pro, Enterprise or Education, or Windows Server 2016 to 2025.

- Group Policy Management Console (RSAT on Windows 11) and the `GroupPolicy` PowerShell module.

- Rights to edit security on the GPO: Domain Admins, Group Policy Creator Owners for GPOs they created, or delegated Edit settings, delete, modify security.

- A security group per target, for example GPO-Apply-Kiosk-PCs (computers) or GPO-Apply-Finance-Users (users). A naming convention makes later audits much easier.

## The Authenticated Users Read requirement (MS16-072)

Before June 2016, a client read user GPOs in the user’s security context. Security update MS16-072 (KB3163622) changed that: user policies are now retrieved in the **computer’s** security context. The computer account therefore needs Read on every GPO that holds user settings, even if the GPO only targets users.

The typical failure looks like this: an administrator removes Authenticated Users from Group Policy security filtering, adds Finance Users, and the user settings silently stop applying, because the computer account can no longer read the GPO. The fix Microsoft recommends is to add Authenticated Users with **Read** only. Computer accounts are members of Authenticated Users, so they can read the GPO, but only members of your filter group hold Apply. If your policy forbids Authenticated Users on GPOs, grant Read to Domain Computers instead.

Keep this rule whenever you change Group Policy security filtering, including on GPOs that only contain computer settings. It costs nothing and removes a whole class of surprises when someone later adds a user setting to the same GPO.

## Filter a GPO to a group in GPMC

- Create the security group in Active Directory Users and Computers and add the users, computers or nested groups.

- Open **Group Policy Management** (`gpmc.msc`), expand Group Policy Objects and select the GPO.

- On the **Scope** tab, under **Security Filtering**, select Authenticated Users and click **Remove**, then confirm.

- Click **Add…**, type the group name, click **Check Names** and **OK**. For computer accounts, click **Object Types…** and tick Computers first.

- Open the **Delegation** tab, click **Add…**, enter Authenticated Users and choose **Read** as the permission.

- Check that the GPO is linked to the OU that contains the objects: security filtering only narrows the scope of a link, it never extends it.

Adding an entry on the Scope tab grants both Read and Apply. Adding one on the Delegation tab with Read grants Read only. That difference is the whole mechanism behind Group Policy security filtering.

### Computer groups vs user groups

Each half of a GPO is filtered against a different account:

- **Computer Configuration** applies when the computer account has Apply. Filter with computer groups.

- **User Configuration** applies when the user account has Apply. Filter with user groups.

A GPO linked to a computer OU and filtered to a computer group will never apply its user settings, because no user is a member of that group. With loopback processing enabled on those computers, user settings from the computer OU’s GPOs do apply to users, but the user must still hold Apply. In that case keep a user group (or Authenticated Users) with Apply next to the computer group. Our [loopback processing guide](/guides/group-policy-loopback-processing/) covers the merge and replace modes.

## Exclude a group with Deny Apply

To apply a GPO to everyone in the OU except one group, keep Authenticated Users on the Scope tab and deny Apply for the exception group. A Deny entry overrides any Allow the account gets through other groups.

- Select the GPO and open the **Delegation** tab, then click **Advanced…** at the bottom.

- Click **Add…** and enter the exception group, for example GPO-Exclude-IT-Admins.

- With the group selected, tick **Deny** for **Apply group policy**. Leave Read allowed.

- Click **OK** and accept the warning that Deny entries take precedence.

Two points to keep in mind:

- The Scope tab does not show Deny entries, and the Delegation tab only shows Custom. Name the group clearly and write the exclusion in the GPO comment (right-click the GPO, **Properties » Comment**) so the next administrator can find it.

- `Set-GPPermission` can only grant GpoRead, GpoApply, GpoEdit, GpoEditDeleteModifySecurity or None. It cannot create a Deny entry, so exclusions are a GPMC task. `Get-GPPermission` does report them through its `Denied` property.

Use Deny for small, stable exceptions such as admin workstations or service accounts. For larger groups, an allow-list with a dedicated Apply group is easier to read and audit.

## Refresh group membership without waiting

Group Policy security filtering is evaluated against the group SIDs in the account’s Kerberos ticket, not live against Active Directory. Adding a computer to a group therefore has no effect until the computer gets a new ticket.

- **Computers:** restart, or purge the computer account’s tickets from an elevated prompt and refresh policy:

```
klist -li 0x3e7 purgegpupdate /target:computer /force
```

`0x3e7` is the logon session of the local SYSTEM account, which holds the computer’s tickets.

- **Users:** sign out and back in. A running session keeps the token it received at sign-in, so `gpupdate` alone does not pick up a new user group.

Check the membership the machine currently sees with `gpresult /r /scope computer` (section The computer is a part of the following security groups) or `whoami /groups` for the user.

## Manage security filtering with PowerShell

The `GroupPolicy` module handles allow entries well. The pattern below turns a default GPO into a filtered one: grant Apply to the group, then downgrade Authenticated Users to Read.

```
Import-Module GroupPolicy
$gpo = 'SEC - Kiosk Lockdown'
Set-GPPermission -Name $gpo -TargetName 'GPO-Apply-Kiosk-PCs' -TargetType Group -PermissionLevel GpoApply
Set-GPPermission -Name $gpo -TargetName 'Authenticated Users' -TargetType Group -PermissionLevel GpoRead -Replace
```

`-Replace` matters on the second line. Without it, Set-GPPermission leaves a higher existing permission in place, so Authenticated Users would keep Apply. To remove a trustee completely, set `-PermissionLevel None`.

To add the MS16-072 Read entry to every GPO in the domain in one pass (safe to run on GPOs that already have it; `-Replace` is omitted so existing Apply entries are not downgraded):

```
Get-GPO -All | Set-GPPermission -PermissionLevel GpoRead -TargetType Group -TargetName 'Authenticated Users'
```

For a new GPO created by script, apply the filter at creation time:

```
$gpo = New-GPO -Name 'USR - Finance Drive Maps' -Comment 'Filtered to GPO-Apply-Finance-Users'
$gpo | Set-GPPermission -TargetName 'GPO-Apply-Finance-Users' -TargetType Group -PermissionLevel GpoApply
$gpo | Set-GPPermission -TargetName 'Authenticated Users' -TargetType Group -PermissionLevel GpoRead -Replace
New-GPLink -Name $gpo.DisplayName -Target 'OU=Finance,OU=Users,DC=contoso,DC=com'
```

## Audit filters with Get-GPPermission

Group Policy security filtering drifts as groups are renamed, emptied or deleted. A domain with years of history usually has GPOs filtered to empty groups, deleted groups (shown as unresolved SIDs) or missing the Read entry. These three reports find them.

### Who holds Apply on every GPO

```
Get-GPO -All | ForEach-Object {
    $g = $_
    Get-GPPermission -Guid $g.Id -All |
        Where-Object Permission -eq 'GpoApply' |
        Select-Object @{n='GPO';e={$g.DisplayName}},
                      @{n='Trustee';e={$_.Trustee.Name}},
                      @{n='Type';e={$_.Trustee.SidType}},
                      Denied
} | Sort-Object GPO | Export-Csv C:\Reports\GPO-SecurityFiltering.csv -NoTypeInformation
```

Rows with `Denied` set to `True` are your exclusions. Rows with an empty trustee name point to a deleted group whose SID is still on the GPO.

### GPOs where Authenticated Users has no entry

```
Get-GPO -All | Where-Object {
    -not (Get-GPPermission -Guid $_.Id -TargetName 'Authenticated Users' -TargetType Group -ErrorAction SilentlyContinue)
} | Select-Object DisplayName, Id
```

For each GPO in this list, confirm that Domain Computers has Read instead. If neither does, user settings in that GPO are not applying anywhere.

### Filter groups that are empty

```
Get-GPO -All | ForEach-Object {
    Get-GPPermission -Guid $_.Id -All | Where-Object { $_.Permission -eq 'GpoApply' -and $_.Trustee.SidType -eq 'Group' }
} | ForEach-Object { $_.Trustee.Name } | Sort-Object -Unique | ForEach-Object {
    $n = (Get-ADGroupMember -Identity $_ -ErrorAction SilentlyContinue | Measure-Object).Count
    if ($n -eq 0) { "$_ has no members" }
}
```

Built-in groups such as Authenticated Users are well-known SIDs, not AD groups, so they do not appear in the last report.

## Verify it works

- On a target computer, run `gpresult /r /scope computer` (or `/scope user` in the user’s session). The GPO should appear under Applied Group Policy Objects.

- On an excluded machine, the same command lists it under The following GPOs were not applied because they were filtered out with `Filtering: Denied (Security)`.

- For a full report with the winning GPO per setting, run `gpresult /h C:\Temp\rsop.html` from an elevated prompt.

- In Event Viewer, open Applications and Services Logs » Microsoft » Windows » GroupPolicy » Operational. Event 5312 lists the GPOs that apply; event 5313 lists the GPOs filtered out.

- From an admin workstation, use GPMC **Group Policy Modeling** to test a planned group change before you make it, or **Group Policy Results** to read a remote machine’s last result.

## Troubleshooting

| Symptom | Likely cause | Fix |
| --- | --- | --- |
| gpresult shows Denied (Security) for an account that should apply the GPO | Account is not in the filter group, or its ticket predates the change | Check gpresult /r group list; restart or run klist -li 0x3e7 purge |
| Excluded group still receives the settings | Deny set on the wrong GPO, or settings come from another GPO | Check the Winning GPO column in gpresult /h |
| User settings do not apply after filtering; GPO missing from the user’s gpresult | Computer account lacks Read (MS16-072) | Add Authenticated Users or Domain Computers with Read |
| User settings in a computer-filtered GPO never apply | Users do not hold Apply | Move user settings to a user-linked GPO, or add a user group when using loopback |
| Computer settings do not apply after adding the PC to the group | Old Kerberos ticket | Restart, or purge SYSTEM tickets and run gpupdate /force |
| Denied (WMI Filter) instead of Security | The linked WMI filter returned no result | Test the query with Get-CimInstance on that machine |
| Unresolved SID on the Scope tab | Filter group was deleted | Remove the entry and add the replacement group |

If the GPO does not appear in gpresult at all, check the link, link order and Block Inheritance before looking at filters; our [Group Policy not applying guide](/guides/group-policy-not-applying/) walks through that order.

## Roll back or undo

To return a GPO to the default scope, grant Apply to Authenticated Users again and remove the filter group:

```
Set-GPPermission -Name 'SEC - Kiosk Lockdown' -TargetName 'Authenticated Users' -TargetType Group -PermissionLevel GpoApply
Set-GPPermission -Name 'SEC - Kiosk Lockdown' -TargetName 'GPO-Apply-Kiosk-PCs' -TargetType Group -PermissionLevel None
```

Remove Deny entries in **Delegation » Advanced** by clearing the Deny tick or removing the group. Back up the GPO first (`Backup-GPO -Name 'SEC - Kiosk Lockdown' -Path \\fs01\GPOBackups`): the backup includes the GPO’s permissions, so a restore also brings back the previous Group Policy security filtering.

## Design rules that keep filters manageable

- **Link first, filter second.** Put objects in the right OU and link the GPO there. Use Group Policy security filtering to narrow a link, not to replace a sensible OU design.

- **One Apply group per GPO.** Name it after the GPO (GPO-Apply-Kiosk-Lockdown) so membership explains itself and the audit report reads cleanly.

- **Read for Authenticated Users everywhere.** Treat it as part of every filtered GPO, not an optional extra.

- **Deny only for documented exceptions.** Record each one in the GPO comment and review it with the audit report.

- **Split computer and user settings.** A GPO that holds only one half is easier to filter correctly, and you can disable the unused half on the **Details** tab (GPO Status).

- **Prefer groups over single accounts.** Filtering to individual computer or user accounts works, but group changes are easier to delegate to a helpdesk.

With these rules, Group Policy security filtering stays readable even in a domain with hundreds of GPOs, and a monthly run of the audit reports above catches drift early.

## Group Policy security filtering at a glance

**Official documentation:** [Set-GPPermission (GroupPolicy module)](https://learn.microsoft.com/en-us/powershell/module/grouppolicy/set-gppermission), [Get-GPPermission (GroupPolicy module)](https://learn.microsoft.com/en-us/powershell/module/grouppolicy/get-gppermission), [Deploying Group Policy security update MS16-072](https://learn.microsoft.com/en-us/archive/blogs/askds/deploying-group-policy-security-update-ms16-072-kb3163622).

**Related guides:** [Troubleshoot Group Policy not applying: gpresult, RSoP and Events 1058/1030](/guides/group-policy-not-applying/) · [GPO WMI filters with ready-made queries](/guides/gpo-wmi-filters/) · [Group Policy processing order, Enforced and Block Inheritance](/guides/group-policy-processing-order/).

## Frequently asked questions

### Why do I need Authenticated Users with Read after removing it from security filtering?

Since MS16-072, Windows reads user GPOs in the computer’s security context. The computer account needs Read on the GPO, and Authenticated Users (which includes computers) with Read only provides that without letting everyone apply it.

### Can I filter a GPO to a computer group and still apply its user settings?

Not in normal processing, because user settings apply only when the user holds Apply. With loopback processing, keep a user group or Authenticated Users with Apply alongside the computer group.

### How do I exclude a group from a GPO?

Open the GPO’s Delegation tab, click Advanced, add the group and tick Deny for Apply group policy. Deny overrides any Allow the account gets from other groups.

### Why does a computer ignore the GPO after I added it to the filter group?

The computer’s Kerberos ticket still holds the old group list. Restart it, or run klist -li 0x3e7 purge followed by gpupdate /force from an elevated prompt.

### Can Set-GPPermission create a Deny entry?

No. It supports GpoRead, GpoApply, GpoEdit, GpoEditDeleteModifySecurity and None only. Create Deny entries in GPMC under Delegation, Advanced; Get-GPPermission shows them with Denied set to True.
