If you have any intention of excluding your CEO or anyone else from any other policies you should probably better scope your GPOs. Don't make the changes in the domain policy, in fact I rarely recommend anyone change things in that policy except for the things that they absolutely have to. Put the policies down on the OU(s) where the users/computers are. Then place the users and computers in the OU specific to the policy they should have.
 
BTW, why shouldn't the CEO have a machine configured like everyone else?
 
  joe


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Jason B
Sent: Tuesday, February 08, 2005 10:52 AM
To: [email protected]
Subject: [ActiveDir] Exclude a specific user (or group) from a GPO (WMI Filter?)

In this example, I want to exclude our CEO from having a forced IE start page through GPO, while the remainder of our domain keeps a forced homepage.  Is the best way to go about this, to write a WMI filter to exclude that specific user, or is there some better way to do it, as we have this set in our Default Domain Policy?
 
If so, can anyone point me to a good tutorial for writing such a WMI script?
 
Thanks.

Reply via email to