You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Server 2003环境下用VBScript设置GPO权限:拒绝TestGroup应用组策略

VBScript to Configure GPO Permissions for Targeted Policy Application

Got it, here's a tailored VBScript solution that fits your Server 2003 environment and exact requirements. Let's recap your scenario first to make sure we're aligned:

Your Scenario: You need SettingA (delivered via TestGPO) to apply to all users except TestGroup. Since you can't create an "all users except TestGroup" group and everyone's in the same OU, the correct approach is to keep Authenticated Users' default Read/Apply permissions, then add a Deny "Apply Group Policy" permission for TestGroup.


The VBScript Code

' VBScript to set Deny "Apply Group Policy" permission for TestGroup on a specified GPO
Option Explicit

Dim objGPO, objSD, objACE, objTrustee
Dim strGPODisplayName, strTestGroupDN

' --------------------------
' Configuration Variables - UPDATE THESE!
' --------------------------
strGPODisplayName = "TestGPO" ' Replace with your actual GPO display name
strTestGroupDN = "CN=TestGroup,OU=YourUsersOU,DC=yourdomain,DC=local" ' Replace with TestGroup's full Distinguished Name

' Bind to the GPO using its GUID (retrieved via helper function)
Set objGPO = GetObject("LDAP://cn={" & GetGPOGUID(strGPODisplayName) & "},cn=policies,cn=system,DC=yourdomain,DC=local")
If Err.Number <> 0 Then
    WScript.Echo "Error binding to GPO: " & Err.Description
    WScript.Quit 1
End If

' Fetch the GPO's current security descriptor
Set objSD = objGPO.Get("nTSecurityDescriptor")

' Create a trustee object for the TestGroup
Set objTrustee = CreateObject("ADSI.ADSTrustee")
objTrustee.trustee = strTestGroupDN

' Build the Deny ACE for "Apply Group Policy"
Set objACE = CreateObject("ADSI.ADAccessControlEntry")
objACE.AccessMask = 16777216 ' Fixed mask for "Apply Group Policy" permission
objACE.AceType = 1 ' Deny type (takes precedence over Allow)
objACE.AceFlags = 0 ' No inheritance needed here
objACE.Trustee = objTrustee

' Add the new Deny ACE to the GPO's DACL
objSD.DiscretionaryAcl.AddAce objACE

' Save the updated security descriptor back to the GPO
objGPO.Put "nTSecurityDescriptor", Array(objSD)
objGPO.SetInfo

WScript.Echo "Success! Deny 'Apply Group Policy' has been set for TestGroup on GPO: " & strGPODisplayName

' Helper function to get a GPO's GUID from its display name
Function GetGPOGUID(strGPOName)
    Dim objGPOContainer, objGPO
    Set objGPOContainer = GetObject("LDAP://cn=policies,cn=system,DC=yourdomain,DC=local")
    objGPOContainer.Filter = Array("groupPolicyContainer")
    
    For Each objGPO In objGPOContainer
        If UCase(objGPO.Get("displayName")) = UCase(strGPOName) Then
            ' Extract GUID from the GPO's file system path
            GetGPOGUID = Split(objGPO.Get("gpcfilesyspath"), "\\")(2)
            Exit Function
        End If
    Next
    
    WScript.Echo "GPO named '" & strGPOName & "' was not found in the domain."
    WScript.Quit 1
End Function

What You Need to Do First

  1. Update Configuration Variables:

    • Replace strGPODisplayName with your actual TestGPO name (case-insensitive, but match it exactly to avoid issues).
    • Replace strTestGroupDN with the full Distinguished Name of your TestGroup. You can get this in Active Directory Users and Computers: open the group's properties > go to the Attribute Editor tab > find distinguishedName and copy its value.
    • Update all DC/domain references in the LDAP paths to match your domain (e.g., DC=yourdomain,DC=local).
  2. Run with Elevated Permissions: You must execute this script as a Domain Administrator—modifying GPO security requires this level of access.


Key Details for Server 2003 Compatibility

  • This script uses ADSI, which is fully supported on Server 2003. No additional tools or updates are needed.
  • The AccessMask value 16777216 is the standard, fixed constant for the "Apply Group Policy" permission in Active Directory.
  • The Deny ACE takes precedence over the default Allow permission for Authenticated Users, which ensures TestGroup members won't get the GPO applied.
  • The script leaves Authenticated Users' default permissions untouched—we're only adding the Deny rule for TestGroup.

Verification

After running the script, open the TestGPO's properties in Group Policy Management Console:

  1. Go to the Security tab.
  2. Find TestGroup in the list of principals.
  3. Confirm that "Apply Group Policy" is set to Deny.

内容的提问来源于stack exchange,提问作者Badger

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 10:23:12