How to Exclude Users or Devices from Windows Screen Lock Policies?

0
21
Asked By TechieTornado42 On

I'm trying to figure out how to handle exclusion requests for the corporate screen lock policy. Some customers want certain users and computers to be exempt from this policy, but I'm running into issues. When I set the policy based on users, it's hard to exclude specific computers, and if I set it based on computers, it's tough to exclude users. How are others managing this? Please don't tell me you never exclude anyone!

5 Answers

Answered By AdminWiseguy23 On

For managing this, we've successfully used security group filtering instead of jumping between user and computer GPOs. It allows for including all users while excluding specific groups when necessary. It’s a little clunky, but it’s proven to be the least painful method for handling these edge cases.

FeedbackFreak22 -

Sounds like a solid approach and maybe the best balance between flexibility and control!

Answered By PolicyNinja88 On

You might want to consider using a loopback GPO for this. It allows you to apply a user policy that disables the lock screen for all users on specific machines. Just keep in mind it can get a bit messy, and you need to remember you've set it up like that.

ExpertAdmin70 -

Yeah, that sounds like the way to go for sure!

SystemSleuth23 -

Alternatively, you could avoid the loopback by creating specific computer groups. We did something similar and excluded certain machines by placing them in a dedicated security group, which worked well.

Answered By CuriousTechie99 On

I'm intrigued but I'm not sure I'm catching the full picture of your issue. Are you aiming to exclude specific user accounts from the overall GPOs?

TechieTornado42 -

Yes! Right now, the screen lock applies to all users through a user-based GPO, and we occasionally receive requests to exclude certain users or computers. Users are easier to manage, but excluding computers tied to any user has me puzzled.

Answered By CynicalDev77 On

Honestly, I can't see why they're asking for this setup unless there's some office politics at play. But honestly, I guess there could be valid reasons. For instance, some jobs require constant monitoring and they need to avoid being interrupted by a lock screen every few minutes.

LogicGiant54 -

I can definitely think of some logical reasons. Like, if someone is monitoring security systems, they shouldn't have to deal with lock screens after a few minutes.

OfficeJester99 -

I had the same thought! But there are practical reasons behind these requests, like specific work duties requiring constant attention.

Answered By HospitalSysAdmin12 On

I handle this setup in the hospitals I work for, especially with our autologon systems. We have one computer group and two policies – one for filtering display sleep settings and the other for managing screensaver and lock preferences. This setups ensures that all users on those machines follow the established settings without any hassle.

GPOGuru11 -

Keep in mind that the 'enforced' setting in GPO can get tricky. It's meant to override inheritance, but overusing it can lead to complications down the line.

TechGuru247 -

Yeah, 'enforced' can be a slippery slope! Always better to keep it simple and clear in your GPO arrangement.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.