Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add support for targeting policies to specific users and groups #46

Open
tcvall86 opened this issue Jun 2, 2020 · 11 comments
Open

Add support for targeting policies to specific users and groups #46

tcvall86 opened this issue Jun 2, 2020 · 11 comments
Assignees
Labels
enhancement New feature or request pinned

Comments

@tcvall86
Copy link

tcvall86 commented Jun 2, 2020

Hello,

First of all I like this tool a lot and we are probably implementing this in our domain.
One thing I could not get to work is applying this to a specific group or user. It only seems to work as a domain wide policy.

Potentially this is a duplicate of #32 but since that is closed I am unsure if this has been fixed or not. Maybe I am just missing something obvious

I have tried "removing" authenticated users by removing delegation on Apply group policy - Allow for Authenticated users and adding a seperate group with it allowed. But as soon as I do that, all requests seems to go through even though the filter is being called on. (Which can be seen in Event Viewer)

Is it / Will it be possible to include / exclude specific users from the filter?
It would help for example in testing scenarios or with specific service accounts that are used in conjunction with programs that can't handle certain passwords

Thanks again

@ryannewington
Copy link
Member

Hey @tcvall86

The group policy affects domain controllers, not individual users or groups.

So I'm afraid it's all or nothing as far as being enabled for all users in any given domain.

V2 will have the fine grained policies that you are after, but I'm afraid I haven't yet finished that version.

@tcvall86
Copy link
Author

tcvall86 commented Jun 3, 2020

Hello Ryan,

Thanks for the quick response.
I kind of figured but great to have it confirmed.

Thanks for all your hard work on this project. Looking forward to the next release!

@tcvall86 tcvall86 closed this as completed Jun 3, 2020
@ryannewington ryannewington reopened this Jun 3, 2020
@ryannewington
Copy link
Member

Let's leave this open to track the feature request

@ryannewington ryannewington added enhancement New feature or request pinned labels Jun 3, 2020
@ryannewington ryannewington self-assigned this Jun 3, 2020
@ryannewington ryannewington changed the title GPO for specific group and/or users Add support for targeting policies to specific users and groups Jun 3, 2020
@Techie4Life83
Copy link

@ryannewington yeah this one looks like it is almost the same as #48 and that FGPPs would be the answer. I posted in that request before reading this one :).

@rooso
Copy link

rooso commented Dec 2, 2021

Thanks a lot Ryan, for this amazing tool! We're planning to implement it in our enviroment. After some testing, i stumbled over the need for specific excludes of users. As we have 802.1x Network Authentication in place, therefore we need some MAB objects in AD with very bad passwords.

So I'll wait until you release Version 2, hope it's not too far away 😃

Again thank you very much,
Oliver

@LMApplications
Copy link

Excellent piece of kit! Just dropping a comment about the application of specific users / groups. Also hoping as @rooso that it isn't so far away.

@GobNobber
Copy link

Frustrated that this basically prevents us from using your fine product. No user filtering is a deal break for administration apparently.

@kaloueche
Copy link

bonjour
j'ai installer cette application lithnet ad-password-protection , j'ai fait Add-CompromisedPassword -Value "monmot" mais je peux toujours modifier le mot de passe que j'ai rajouter via la console AD
je comprend pas ou est le problème
merci de m'aider svp

@manulalath
Copy link

manulalath commented Sep 16, 2022

Hi @ryannewington ,

I know this is very old topic, however just want get the confirmation. We do have some have MAB accounts with bad passwords hence is there a way we can exclude a particular OU (where all MAB accounts are sitting) from the password protection GPO?

@neverinfront
Copy link

Great product and thank you for all your effort, but just wanted to bring to your attention that FGP are useful in many environments. For example, in education, there are 5 year old kids who don't know what a symbol is yet and have not taken keyboarding, so they need to have a simpler password.

@JES-OPS
Copy link

JES-OPS commented May 7, 2024

I know this is the most awful question for a dev but do you have a target for releasing your v2 product?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request pinned
Projects
None yet
Development

No branches or pull requests

10 participants