I'm aware of that possibility, but this is a GPO for all users if the user logging on is member of a specific group. Our domain isn't in native mode yet, so i can't put domain global groups in domain global groups. So i have to use a domain local group for the GPO, in which i can put domain global groups or users. But, the GPO only works with domain global groups If i attach authenticated users to the GPO and restrict access to that GPO via a WMI filter, it could do the trick ??
_________________________
Kind regards,