Emergency server help: get in touch

Group Policy Security Filtering: 6 Ways to Target or Exclude

Target a GPO at specific users, computers or groups, exclude others with Deny Apply, keep the Authenticated Users Read entry that MS16-072 requires, and audit every filter in the domain with Get-GPPermission.

Published Updated 13 min read

Group Policy security filtering decides which users and computers inside a linked OU actually apply a GPO, based on two permissions on the GPO itself: Read and Apply group policy. Linking controls where a GPO can apply; security filtering narrows that scope to the accounts and groups you choose, and Deny entries carve out exceptions. This guide covers how the permissions work, the Read requirement introduced by MS16-072, filtering by user and computer groups, exclusions, PowerShell management and how to fix a GPO that gpresult reports as Denied (Security).

Short answer: In GPMC, select the GPO, and on the Scope tab remove Authenticated Users from Security Filtering and add your group. Then open the Delegation tab and add Authenticated Users back with Read only. Restart the target computers (or sign users out and in) so their new group membership is in the Kerberos ticket, and run gpresult /r to confirm.

How security filtering works

A computer or user applies a GPO only when both conditions are true: the account can read the GPO, and it has the Apply group policy permission, either directly or through a group. By default every new GPO grants Authenticated Users both permissions, so it applies to everything in the linked containers. Group Policy security filtering changes who holds the Apply permission.

GoalWhat to configureWhereNotes
Apply to one group onlyRemove Authenticated Users from Security Filtering, add the groupScope tabAdd Authenticated Users back with Read on the Delegation tab
Apply to everyone except one groupDeny Apply group policy for the exception groupDelegation » AdvancedDeny wins over Allow; invisible on the Scope tab
Apply to specific computersAdd a computer security group (or computer accounts)Scope tabMembership changes need a restart or a ticket purge
Apply to specific usersAdd a user security groupScope tabMembership changes need a new sign-in
Apply by OS, hardware or modelWMI filterScope tab, WMI FilteringEvaluated on the client every refresh
Target single preference itemsItem-level targetingGPP item, Common tabPreferences only, not Administrative Templates

Only security groups work. Distribution groups have no SID in the token and are ignored. Nested security groups are evaluated normally, because Windows checks the full token.

Prerequisites

  • Domain-joined Windows 11 Pro, Enterprise or Education, or Windows Server 2016 to 2025.
  • Group Policy Management Console (RSAT on Windows 11) and the GroupPolicy PowerShell module.
  • Rights to edit security on the GPO: Domain Admins, Group Policy Creator Owners for GPOs they created, or delegated Edit settings, delete, modify security.
  • A security group per target, for example GPO-Apply-Kiosk-PCs (computers) or GPO-Apply-Finance-Users (users). A naming convention makes later audits much easier.

The Authenticated Users Read requirement (MS16-072)

Before June 2016, a client read user GPOs in the user’s security context. Security update MS16-072 (KB3163622) changed that: user policies are now retrieved in the computer’s security context. The computer account therefore needs Read on every GPO that holds user settings, even if the GPO only targets users.

The typical failure looks like this: an administrator removes Authenticated Users from Group Policy security filtering, adds Finance Users, and the user settings silently stop applying, because the computer account can no longer read the GPO. The fix Microsoft recommends is to add Authenticated Users with Read only. Computer accounts are members of Authenticated Users, so they can read the GPO, but only members of your filter group hold Apply. If your policy forbids Authenticated Users on GPOs, grant Read to Domain Computers instead.

Keep this rule whenever you change Group Policy security filtering, including on GPOs that only contain computer settings. It costs nothing and removes a whole class of surprises when someone later adds a user setting to the same GPO.

Filter a GPO to a group in GPMC

  1. Create the security group in Active Directory Users and Computers and add the users, computers or nested groups.
  2. Open Group Policy Management (gpmc.msc), expand Group Policy Objects and select the GPO.
  3. On the Scope tab, under Security Filtering, select Authenticated Users and click Remove, then confirm.
  4. Click Add…, type the group name, click Check Names and OK. For computer accounts, click Object Types… and tick Computers first.
  5. Open the Delegation tab, click Add…, enter Authenticated Users and choose Read as the permission.
  6. Check that the GPO is linked to the OU that contains the objects: security filtering only narrows the scope of a link, it never extends it.

Adding an entry on the Scope tab grants both Read and Apply. Adding one on the Delegation tab with Read grants Read only. That difference is the whole mechanism behind Group Policy security filtering.

Computer groups vs user groups

Each half of a GPO is filtered against a different account:

  • Computer Configuration applies when the computer account has Apply. Filter with computer groups.
  • User Configuration applies when the user account has Apply. Filter with user groups.

A GPO linked to a computer OU and filtered to a computer group will never apply its user settings, because no user is a member of that group. With loopback processing enabled on those computers, user settings from the computer OU’s GPOs do apply to users, but the user must still hold Apply. In that case keep a user group (or Authenticated Users) with Apply next to the computer group. Our loopback processing guide covers the merge and replace modes.

Exclude a group with Deny Apply

To apply a GPO to everyone in the OU except one group, keep Authenticated Users on the Scope tab and deny Apply for the exception group. A Deny entry overrides any Allow the account gets through other groups.

  1. Select the GPO and open the Delegation tab, then click Advanced… at the bottom.
  2. Click Add… and enter the exception group, for example GPO-Exclude-IT-Admins.
  3. With the group selected, tick Deny for Apply group policy. Leave Read allowed.
  4. Click OK and accept the warning that Deny entries take precedence.

Two points to keep in mind:

  • The Scope tab does not show Deny entries, and the Delegation tab only shows Custom. Name the group clearly and write the exclusion in the GPO comment (right-click the GPO, Properties » Comment) so the next administrator can find it.
  • Set-GPPermission can only grant GpoRead, GpoApply, GpoEdit, GpoEditDeleteModifySecurity or None. It cannot create a Deny entry, so exclusions are a GPMC task. Get-GPPermission does report them through its Denied property.

Use Deny for small, stable exceptions such as admin workstations or service accounts. For larger groups, an allow-list with a dedicated Apply group is easier to read and audit.

Refresh group membership without waiting

Group Policy security filtering is evaluated against the group SIDs in the account’s Kerberos ticket, not live against Active Directory. Adding a computer to a group therefore has no effect until the computer gets a new ticket.

  • Computers: restart, or purge the computer account’s tickets from an elevated prompt and refresh policy:
    klist -li 0x3e7 purge
    gpupdate /target:computer /force

    0x3e7 is the logon session of the local SYSTEM account, which holds the computer’s tickets.
  • Users: sign out and back in. A running session keeps the token it received at sign-in, so gpupdate alone does not pick up a new user group.

Check the membership the machine currently sees with gpresult /r /scope computer (section The computer is a part of the following security groups) or whoami /groups for the user.

Manage security filtering with PowerShell

The GroupPolicy module handles allow entries well. The pattern below turns a default GPO into a filtered one: grant Apply to the group, then downgrade Authenticated Users to Read.

Import-Module GroupPolicy
$gpo = 'SEC - Kiosk Lockdown'
Set-GPPermission -Name $gpo -TargetName 'GPO-Apply-Kiosk-PCs' -TargetType Group -PermissionLevel GpoApply
Set-GPPermission -Name $gpo -TargetName 'Authenticated Users' -TargetType Group -PermissionLevel GpoRead -Replace

-Replace matters on the second line. Without it, Set-GPPermission leaves a higher existing permission in place, so Authenticated Users would keep Apply. To remove a trustee completely, set -PermissionLevel None.

To add the MS16-072 Read entry to every GPO in the domain in one pass (safe to run on GPOs that already have it; -Replace is omitted so existing Apply entries are not downgraded):

Get-GPO -All | Set-GPPermission -PermissionLevel GpoRead -TargetType Group -TargetName 'Authenticated Users'

For a new GPO created by script, apply the filter at creation time:

$gpo = New-GPO -Name 'USR - Finance Drive Maps' -Comment 'Filtered to GPO-Apply-Finance-Users'
$gpo | Set-GPPermission -TargetName 'GPO-Apply-Finance-Users' -TargetType Group -PermissionLevel GpoApply
$gpo | Set-GPPermission -TargetName 'Authenticated Users' -TargetType Group -PermissionLevel GpoRead -Replace
New-GPLink -Name $gpo.DisplayName -Target 'OU=Finance,OU=Users,DC=contoso,DC=com'

Audit filters with Get-GPPermission

Group Policy security filtering drifts as groups are renamed, emptied or deleted. A domain with years of history usually has GPOs filtered to empty groups, deleted groups (shown as unresolved SIDs) or missing the Read entry. These three reports find them.

Who holds Apply on every GPO

Get-GPO -All | ForEach-Object {
    $g = $_
    Get-GPPermission -Guid $g.Id -All |
        Where-Object Permission -eq 'GpoApply' |
        Select-Object @{n='GPO';e={$g.DisplayName}},
                      @{n='Trustee';e={$_.Trustee.Name}},
                      @{n='Type';e={$_.Trustee.SidType}},
                      Denied
} | Sort-Object GPO | Export-Csv C:\Reports\GPO-SecurityFiltering.csv -NoTypeInformation

Rows with Denied set to True are your exclusions. Rows with an empty trustee name point to a deleted group whose SID is still on the GPO.

GPOs where Authenticated Users has no entry

Get-GPO -All | Where-Object {
    -not (Get-GPPermission -Guid $_.Id -TargetName 'Authenticated Users' -TargetType Group -ErrorAction SilentlyContinue)
} | Select-Object DisplayName, Id

For each GPO in this list, confirm that Domain Computers has Read instead. If neither does, user settings in that GPO are not applying anywhere.

Filter groups that are empty

Get-GPO -All | ForEach-Object {
    Get-GPPermission -Guid $_.Id -All | Where-Object { $_.Permission -eq 'GpoApply' -and $_.Trustee.SidType -eq 'Group' }
} | ForEach-Object { $_.Trustee.Name } | Sort-Object -Unique | ForEach-Object {
    $n = (Get-ADGroupMember -Identity $_ -ErrorAction SilentlyContinue | Measure-Object).Count
    if ($n -eq 0) { "$_ has no members" }
}

Built-in groups such as Authenticated Users are well-known SIDs, not AD groups, so they do not appear in the last report.

Verify it works

  1. On a target computer, run gpresult /r /scope computer (or /scope user in the user’s session). The GPO should appear under Applied Group Policy Objects.
  2. On an excluded machine, the same command lists it under The following GPOs were not applied because they were filtered out with Filtering: Denied (Security).
  3. For a full report with the winning GPO per setting, run gpresult /h C:\Temp\rsop.html from an elevated prompt.
  4. In Event Viewer, open Applications and Services Logs » Microsoft » Windows » GroupPolicy » Operational. Event 5312 lists the GPOs that apply; event 5313 lists the GPOs filtered out.
  5. From an admin workstation, use GPMC Group Policy Modeling to test a planned group change before you make it, or Group Policy Results to read a remote machine’s last result.

Troubleshooting

SymptomLikely causeFix
gpresult shows Denied (Security) for an account that should apply the GPOAccount is not in the filter group, or its ticket predates the changeCheck gpresult /r group list; restart or run klist -li 0x3e7 purge
Excluded group still receives the settingsDeny set on the wrong GPO, or settings come from another GPOCheck the Winning GPO column in gpresult /h
User settings do not apply after filtering; GPO missing from the user’s gpresultComputer account lacks Read (MS16-072)Add Authenticated Users or Domain Computers with Read
User settings in a computer-filtered GPO never applyUsers do not hold ApplyMove user settings to a user-linked GPO, or add a user group when using loopback
Computer settings do not apply after adding the PC to the groupOld Kerberos ticketRestart, or purge SYSTEM tickets and run gpupdate /force
Denied (WMI Filter) instead of SecurityThe linked WMI filter returned no resultTest the query with Get-CimInstance on that machine
Unresolved SID on the Scope tabFilter group was deletedRemove the entry and add the replacement group

If the GPO does not appear in gpresult at all, check the link, link order and Block Inheritance before looking at filters; our Group Policy not applying guide walks through that order.

Roll back or undo

To return a GPO to the default scope, grant Apply to Authenticated Users again and remove the filter group:

Set-GPPermission -Name 'SEC - Kiosk Lockdown' -TargetName 'Authenticated Users' -TargetType Group -PermissionLevel GpoApply
Set-GPPermission -Name 'SEC - Kiosk Lockdown' -TargetName 'GPO-Apply-Kiosk-PCs' -TargetType Group -PermissionLevel None

Remove Deny entries in Delegation » Advanced by clearing the Deny tick or removing the group. Back up the GPO first (Backup-GPO -Name 'SEC - Kiosk Lockdown' -Path \\fs01\GPOBackups): the backup includes the GPO’s permissions, so a restore also brings back the previous Group Policy security filtering.

Design rules that keep filters manageable

  • Link first, filter second. Put objects in the right OU and link the GPO there. Use Group Policy security filtering to narrow a link, not to replace a sensible OU design.
  • One Apply group per GPO. Name it after the GPO (GPO-Apply-Kiosk-Lockdown) so membership explains itself and the audit report reads cleanly.
  • Read for Authenticated Users everywhere. Treat it as part of every filtered GPO, not an optional extra.
  • Deny only for documented exceptions. Record each one in the GPO comment and review it with the audit report.
  • Split computer and user settings. A GPO that holds only one half is easier to filter correctly, and you can disable the unused half on the Details tab (GPO Status).
  • Prefer groups over single accounts. Filtering to individual computer or user accounts works, but group changes are easier to delegate to a helpdesk.

With these rules, Group Policy security filtering stays readable even in a domain with hundreds of GPOs, and a monthly run of the audit reports above catches drift early.

Group Policy security filtering at a glance

Group Policy Security Filtering summary card: In GPMC, select the GPO, and on the Scope tab remove Authenticated Users from Security Filtering and add your group.
In short: In GPMC, select the GPO, and on the Scope tab remove Authenticated Users from Security Filtering and add your group.

Official documentation: Set-GPPermission (GroupPolicy module), Get-GPPermission (GroupPolicy module), Deploying Group Policy security update MS16-072.

Related guides: Troubleshoot Group Policy not applying: gpresult, RSoP and Events 1058/1030 · GPO WMI filters with ready-made queries · Group Policy processing order, Enforced and Block Inheritance.

Frequently asked questions

Why do I need Authenticated Users with Read after removing it from security filtering?

Since MS16-072, Windows reads user GPOs in the computer’s security context. The computer account needs Read on the GPO, and Authenticated Users (which includes computers) with Read only provides that without letting everyone apply it.

Can I filter a GPO to a computer group and still apply its user settings?

Not in normal processing, because user settings apply only when the user holds Apply. With loopback processing, keep a user group or Authenticated Users with Apply alongside the computer group.

How do I exclude a group from a GPO?

Open the GPO’s Delegation tab, click Advanced, add the group and tick Deny for Apply group policy. Deny overrides any Allow the account gets from other groups.

Why does a computer ignore the GPO after I added it to the filter group?

The computer’s Kerberos ticket still holds the old group list. Restart it, or run klist -li 0x3e7 purge followed by gpupdate /force from an elevated prompt.

Can Set-GPPermission create a Deny entry?

No. It supports GpoRead, GpoApply, GpoEdit, GpoEditDeleteModifySecurity and None only. Create Deny entries in GPMC under Delegation, Advanced; Get-GPPermission shows them with Denied set to True.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.