Server 2003环境下用VBScript设置GPO权限:拒绝TestGroup应用组策略
Got it, here's a tailored VBScript solution that fits your Server 2003 environment and exact requirements. Let's recap your scenario first to make sure we're aligned:
Your Scenario: You need SettingA (delivered via TestGPO) to apply to all users except TestGroup. Since you can't create an "all users except TestGroup" group and everyone's in the same OU, the correct approach is to keep Authenticated Users' default Read/Apply permissions, then add a Deny "Apply Group Policy" permission for TestGroup.
The VBScript Code
' VBScript to set Deny "Apply Group Policy" permission for TestGroup on a specified GPO Option Explicit Dim objGPO, objSD, objACE, objTrustee Dim strGPODisplayName, strTestGroupDN ' -------------------------- ' Configuration Variables - UPDATE THESE! ' -------------------------- strGPODisplayName = "TestGPO" ' Replace with your actual GPO display name strTestGroupDN = "CN=TestGroup,OU=YourUsersOU,DC=yourdomain,DC=local" ' Replace with TestGroup's full Distinguished Name ' Bind to the GPO using its GUID (retrieved via helper function) Set objGPO = GetObject("LDAP://cn={" & GetGPOGUID(strGPODisplayName) & "},cn=policies,cn=system,DC=yourdomain,DC=local") If Err.Number <> 0 Then WScript.Echo "Error binding to GPO: " & Err.Description WScript.Quit 1 End If ' Fetch the GPO's current security descriptor Set objSD = objGPO.Get("nTSecurityDescriptor") ' Create a trustee object for the TestGroup Set objTrustee = CreateObject("ADSI.ADSTrustee") objTrustee.trustee = strTestGroupDN ' Build the Deny ACE for "Apply Group Policy" Set objACE = CreateObject("ADSI.ADAccessControlEntry") objACE.AccessMask = 16777216 ' Fixed mask for "Apply Group Policy" permission objACE.AceType = 1 ' Deny type (takes precedence over Allow) objACE.AceFlags = 0 ' No inheritance needed here objACE.Trustee = objTrustee ' Add the new Deny ACE to the GPO's DACL objSD.DiscretionaryAcl.AddAce objACE ' Save the updated security descriptor back to the GPO objGPO.Put "nTSecurityDescriptor", Array(objSD) objGPO.SetInfo WScript.Echo "Success! Deny 'Apply Group Policy' has been set for TestGroup on GPO: " & strGPODisplayName ' Helper function to get a GPO's GUID from its display name Function GetGPOGUID(strGPOName) Dim objGPOContainer, objGPO Set objGPOContainer = GetObject("LDAP://cn=policies,cn=system,DC=yourdomain,DC=local") objGPOContainer.Filter = Array("groupPolicyContainer") For Each objGPO In objGPOContainer If UCase(objGPO.Get("displayName")) = UCase(strGPOName) Then ' Extract GUID from the GPO's file system path GetGPOGUID = Split(objGPO.Get("gpcfilesyspath"), "\\")(2) Exit Function End If Next WScript.Echo "GPO named '" & strGPOName & "' was not found in the domain." WScript.Quit 1 End Function
What You Need to Do First
Update Configuration Variables:
- Replace
strGPODisplayNamewith your actual TestGPO name (case-insensitive, but match it exactly to avoid issues). - Replace
strTestGroupDNwith the full Distinguished Name of your TestGroup. You can get this in Active Directory Users and Computers: open the group's properties > go to the Attribute Editor tab > finddistinguishedNameand copy its value. - Update all DC/domain references in the LDAP paths to match your domain (e.g.,
DC=yourdomain,DC=local).
- Replace
Run with Elevated Permissions: You must execute this script as a Domain Administrator—modifying GPO security requires this level of access.
Key Details for Server 2003 Compatibility
- This script uses ADSI, which is fully supported on Server 2003. No additional tools or updates are needed.
- The
AccessMaskvalue16777216is the standard, fixed constant for the "Apply Group Policy" permission in Active Directory. - The Deny ACE takes precedence over the default Allow permission for Authenticated Users, which ensures TestGroup members won't get the GPO applied.
- The script leaves Authenticated Users' default permissions untouched—we're only adding the Deny rule for TestGroup.
Verification
After running the script, open the TestGPO's properties in Group Policy Management Console:
- Go to the Security tab.
- Find TestGroup in the list of principals.
- Confirm that "Apply Group Policy" is set to Deny.
内容的提问来源于stack exchange,提问作者Badger

