Denied GPO

Maor Zohar
Occasional Visitor

Hi,

We have an OU called "Stations" with all the computer accounts, and they resides in a several OUs under the "Stations" OU. 

I linked a new GPO to the "Stations" OU, and all Sub-OUs should get the policy.

I created a group under out "Groups" OU, that is not under "Stations" OU.

I added to that group two computer accounts.

For some reason, on the gpresult i'm getting "Filtering:  Denied (Security)" on this policy.

I even tried to move the group to the "Stations" OU but no change.

it's working only if i put in the GPO scope specifically the two computers account, and not in a group.

I want to work with a group.

 

How can i make it work? where is the problem?

 

Thanks.