Windows 10 don't lock screen4/3/2024 I find this method more convenient than moving computers around to different OUs. To deny any additional computers all you have to do is add them to the security group. When you check a computer with the gpresult /r command the policy will show as denied The computers in your deny group will need to be rebooted. Make sure Read is set to “Allow” and Apply group policy is to “Deny”. With the security settings windows open click on Addĥ. Go into the group policy management console, select the GPO click the delegation tab then click Advanced. It’s very important to name the group with a descriptive name and use the description box.Ģ. Create a security group and add the computers that you want the lock screen policy disabled on. This is my preferred method as I think it prevents moving computers around between OUs.ġ. Option 2: Create a security group, add the computers, and deny the policy from applying to this group.This works and I’ve used this method for several clients. Option 1: Move the computers into a new OU and not link the GPO to this OU. Let’s say you have the lock screen GPO applied to all computers but now you need to disable it on specific computers. How to Disable the Lock Screen for Specific Computers You can see above the “Computer – Lock Screen” GPO is applied to this computer. You will need to open the Windows command prompt as administrator or it can fail to pull the computer policies. To verify the GPO is applied to a computer you can use the gpresult /r command. How to Verify the Lock Screen GPO is applied So computers in the Accounting, HR, and IT OU will get the lock screen GPO applied. All of the sub-OUs will inherit this policy. You can instantly refresh this by rebooting the computer or running the gpupdate /force command.Ībove is a screenshot showing the GPO linked to my ADPRO Computers OU. So keep in mind it could take up to 90 minutes before this policy gets applied to all computers. The GPO refresh interval is 90 minutes on a computer. Select the GPO you created in step 2 and click OK. In the group policy management console right-click an OU and select “Link an Existing GPO:Ģ. If you apply the GPO to an OU with users only the lock screen will not work.ġ. Since this is a computer policy you must apply the GPO to an OU that contains computer accounts. Now you just need to link the GPO to the correct OU. The GPO is created and the policy settings have been enabled. I set mine to 900 seconds which is 15 minutes. It is the “ Interactive Logon: Machine inactivity limit”īrowse to -> Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security OptionsĬhange the value to whatever you want. There is only one group policy setting that needs to be set. The GPO is created but now we need to set the idle timeout settings. For example, I named my GPO “Computer – Lock Screen”. Right Click “Group Policy Objects” and click new Open the group policy management consoleĢ. It is group policy best practice to not modify the default domain policy and instead create a new one.ġ. Step 2: Create a New GPOĭo not add these settings to the default domain policy. In step 4, I’ll show you how I exclude specific computers from the policy. In this example, I want the policy to apply to all computers so I’m going to link the GPO to my ADPRO Computers OU. These requests should all be approved by upper management.ĭepending on your OU structure you could apply the GPO to the root and let the sub OUs inherit the policy or you could apply the policy to specific OUs. I’ve had requests to exclude conference room computers, computers that are used for 24/7 monitoring, then of course there are always a few users that complain and want it disabled. It’s best to apply this policy to all computers but there will always be exceptions. Later I will show you how to exclude specific computers from the policy. The lock screen policy is a computer policy, this means anyone who logs into the computer will get the lock screen policy applied.
0 Comments
Leave a Reply.AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |