Group Policy Presentation

Embed Size (px)

Citation preview

  • 8/6/2019 Group Policy Presentation

    1/31

    Group Policy Presentation

    This document is classified as Public.

  • 8/6/2019 Group Policy Presentation

    2/31

    9 aot 2011 - Group Policy

    Objects - This document is

    classified as Public

    2

    Presentation Plan

    Overview of Group Policies.

    Configuring the Scope of Group Policies Objects.

    Evaluating the Application of Group Policies

    Objects.

    Managing Group Policies Objects.

    Delegating Administrative Control of Group

    Policies

    Summary:

    Group Policy Presentation

  • 8/6/2019 Group Policy Presentation

    3/31

    9 aot 2011 - Group Policy

    Objects - This document is

    classified as Public

    3

    Overview of Group Policy

    Group Policy Presentation

  • 8/6/2019 Group Policy Presentation

    4/31

    9 aot 2011 - Group Policy

    Objects - This document is

    classified as Public

    4

    Preview

    What Are Group Policies?

    Group Policy Settings

    HowGroup Policies Are Applied

    Group Policy Processing and Exceptions

    Group Policy Components

    What Are ADM and ADMX files?

    Here are the different parts:

    Overview of Group Policies

  • 8/6/2019 Group Policy Presentation

    5/31

    9 aot 2011 - Group Policy

    Objects - This document is

    classified as Public

    5

    What Are Group Policies?

    Overview of Group Policies

    Group Policies enable IT administrators to automate one-to-many

    management ofusers and computers

    Local grouppolicies are always in effect for local users and local

    computersettings..

    UseGroup Policies to : Apply standard configurations

    Deploy software

    Enforce security settings

    Enforce a consistent desktop environment

  • 8/6/2019 Group Policy Presentation

    6/31

    9 aot 2011 - Group Policy

    Objects - This document is

    classified as Public

    6

    Group Policy Settings

    Group Policy settings forusers

    Software Settings

    Windows Settings

    SecuritySettings

    DesktopSettings

    Group Policy settings forcomputers

    Software Settings

    Windows Settings

    SecuritySettings

    Operating systems Settings

    Overview of Group Policies

  • 8/6/2019 Group Policy Presentation

    7/31

    9 aot 2011 - Group Policy

    Objects - This document is

    classified as Public

    7

    HowGroup Policies Are Applied

    Computersettings

    applied

    Startup scripts run

    Refresh Interval

    User settings applied

    Logon scripts run

    Refresh IntervalComputer

    starts

    User

    logs on

    Every 90 minutes

    Every 90 minutes

    Overview of Group Policies

  • 8/6/2019 Group Policy Presentation

    8/31

    9 aot 2011 - Group Policy

    Objects - This document is

    classified as Public

    8

    Group Policy Processing and Exeptions

    Slow Links

    500 Kbps bydefault

    Certain client side extensions are not processed

    CachedCredential

    Priorto Vista, ICMP is used to detect a slow link

    Vistauses Network Location Awareness

    Windows XP and Vistause cached credential for

    fasterlogons

    Many GPO settings take two logons to take effect

    Group PolicyProcessing

    Local PolicyMachine/User

    Site PolicyMachine/User

    Domain PolicyMachine/User

    OUtop OUbottom PolicyMachine/User

    Overview of Group Policies

  • 8/6/2019 Group Policy Presentation

    9/31

    9 aot 2011 - Group Policy

    Objects - This document is

    classified as Public

    9

    Group Policy Components

    Group PolicyContainer

    Group Policy Template

    Stored in Active Directory

    Provides version information

    Status information

    List of components

    Stored in shared SYSVOL folder

    Provides Group Policy settings

    Supports both ADM and ADMX templates

    Group Policy Object

    ContainsGroup Policy settings

    Stores content in two locations

    Overview of Group Policies

  • 8/6/2019 Group Policy Presentation

    10/31

    9 aot 2011 - Group Policy

    Objects - This document is

    classified as Public

    10

    What Are ADM and ADMX Files?

    ADMX files are:

    Language neutral

    Not stored in the GPO Extensible through XML

    ADM files are:

    Copied into every GPO in SYSVOL

    Difficult to customize

    Overview of Group Policies

  • 8/6/2019 Group Policy Presentation

    11/31

    9 aot 2011 - Group Policy

    Objects - This document is

    classified as Public

    11

    Configuring the Scope of

    Group Policy Objects

    Group Policy Presentation

  • 8/6/2019 Group Policy Presentation

    12/31

    9 aot 2011 - Group Policy

    Objects - This document is

    classified as Public

    12

    Preview

    Group Policy Processing Order

    What Are Multiple Local Group Policies?

    Options for Modifying Group Policy Processing

    How Does Loopback ProcessingWork?

    Here are the different parts:

    Configuring the Scope of Group Policy Objects

  • 8/6/2019 Group Policy Presentation

    13/31

    9 aot 2011 - Group Policy

    Objects - This document is

    classified as Public

    13

    Group Policy Processing Order

    Configuring the Scope of Group Policy Objects

    OU

    OUOU

    Local Group Policy

    Domain

    GPO1

    GPO2

    GPO3

    GPO4

    GPO5

    Site

  • 8/6/2019 Group Policy Presentation

    14/31

    9 aot 2011 - Group Policy

    Objects - This document is

    classified as Public

    14

    What are Multiple Local Group Policies?

    Configuring the Scope of Group Policy Objects

    One layerof computerconfigurations that applies to

    all users

    Layers apply only to individual users, not to groups

    There are three layers ofuserconfigurations:

    - Administrator

    - Non-Administrator

    - User-specific

  • 8/6/2019 Group Policy Presentation

    15/31

    9 aot 2011 - Group Policy

    Objects - This document is

    classified as Public

    15

    Options for Modifying Group Policy Processing

    Configuring the Scope of Group Policy Objects

    Block inheritance

    Five methods to modify GPO default processing:

    Enforcement

    Filteringusing securitygroups orWMI filters

    Disabling GPOs

    Loopback processing

  • 8/6/2019 Group Policy Presentation

    16/31

    9 aot 2011 - Group Policy

    Objects - This document is

    classified as Public

    16

    How Does Loopback ProcessingWork?

    Configuring the Scope of Group Policy Objects

  • 8/6/2019 Group Policy Presentation

    17/31

    9 aot 2011 - Group Policy

    Objects - This document is

    classified as Public

    17

    Evaluating the Application of Group

    Policy Objects

    Group Policy Presentation

  • 8/6/2019 Group Policy Presentation

    18/31

    9 aot 2011 - Group Policy

    Objects - This document is

    classified as Public

    18

    Preview

    What Is Group Policy Reporting?

    What Is Group Policy Modeling?

    Here are the different parts:

    Evaluating the Application of Group Policy Objects

  • 8/6/2019 Group Policy Presentation

    19/31

    9 aot 2011 - Group Policy

    Objects - This document is

    classified as Public

    19

    Evaluating the Application of Group Policy Objects

    What Is Group Policy Reporting?

    Grouppolicyreporting is amethod ofplanningand troubleshootinggroup

    policy

    Group Policy results are provided by the GPMC

    GPResult is a command line utility

  • 8/6/2019 Group Policy Presentation

    20/31

    9 aot 2011 - Group Policy

    Objects - This document is

    classified as Public

    20

    Evaluating the Application of Group Policy Objects

    What Is Group Policy Modeling?

    The Group PolicyModeling Wizard calculates the simulated net effect of

    GPOs

    The Group Policy ModelingWizard simulates:

    Site membership

    Security group membership

    WMI filters

    Slow links

    Loopback processing

    The effects of moving user or computer objects to a

    different Active Directory container

  • 8/6/2019 Group Policy Presentation

    21/31

    9 aot 2011 - Group Policy

    Objects - This document is

    classified as Public

    21

    Managing Group Policy

    Objects

    Group Policy Presentation

  • 8/6/2019 Group Policy Presentation

    22/31

    9 aot 2011 - Group Policy

    Objects - This document is

    classified as Public

    22

    Preview

    What Is a Copy Operation?

    What Is a Backup Operation?

    What Is a Restore Operation?

    What Is an Import Operation?

    What Is a StarterGPO?

    MigratingGroup Policy Objects

    Here are the different parts:

    Managing Group Policy Objects

  • 8/6/2019 Group Policy Presentation

    23/31

    9 aot 2011 - Group Policy

    Objects - This document is

    classified as Public

    23

    Managing Group Policy Objects

    What Is a Copy Operation?

    DACLDACL

    User1GPO1

    ReadFullControl

    DACLDACL

    User1GPO2

    ReadFullControl

    Acopyof a GPO transfers onlythe settings within a GPO

    The new GPO is createdunlinked

  • 8/6/2019 Group Policy Presentation

    24/31

    9 aot 2011 - Group Policy

    Objects - This document is

    classified as Public

    24

    Managing Group Policy Objects

    What Is a Backup Operation?

    In a backupoperation, Group PolicyManagement export all data in the GPO

    to the selected file and saves the GPTfiles

    Backupof a

    GPO

    GPO1

    GPO1

  • 8/6/2019 Group Policy Presentation

    25/31

    9 aot 2011 - Group Policy

    Objects - This document is

    classified as Public

    25

    Managing Group Policy Objects

    What Is a Restore Operation?

    In a restore operation, the contents of the GPO are returned to exactlythe

    same state

    Backed-up GPO

    GPO1

    GPO1

  • 8/6/2019 Group Policy Presentation

    26/31

    9 aot 2011 - Group Policy

    Objects - This document isclassified as Public

    26

    Managing Group Policy Objects

    What Is an Import Operation?

    GPO1 GPO2

    GPO

    Settings

    GPO

    Settings

    In an importoperation, all GPO settings are copied from the source to the

    target GPO

  • 8/6/2019 Group Policy Presentation

    27/31

    9 aot 2011 - Group Policy

    Objects - This document isclassified as Public

    27

    Managing Group Policy Objects

    What Is a Starter GPO?

    Stores administrative template settings on which the new GPOs

    will be based

    Can be exported to .cab files

    Can be imported into other areas of the enterprise

    Exported toCAB file Imported to GPMC

    Starter GPO CAB file LoadCabinetfile

  • 8/6/2019 Group Policy Presentation

    28/31

    9 aot 2011 - Group Policy

    Objects - This document isclassified as Public

    28

    Managing Group Policy Objects

    MigratingGroup Policy Objects

    The ADMX Migrator utility :

    Can be used to convert custom ADM files to ADMX

    Is GUI based and can be downloaded from

    the Microsoft download site utility

  • 8/6/2019 Group Policy Presentation

    29/31

    9 aot 2011 - Group Policy

    Objects - This document isclassified as Public

    29

    Delegating Administrative Control of

    Group Policies

    Group Policy Presentation

  • 8/6/2019 Group Policy Presentation

    30/31

    9 aot 2011 - Group Policy

    Objects - This document isclassified as Public

    30

    Delegating Administrative Control of Group Policies

    Options for Delegating Control ofGPOs

    Methods to

    delegate control

    of GPOs

    Create

    GPOs in

    the domain

    Membership in Group

    Policy Creator Ownersgroup or explicit

    permission to create

    GPOs

    Delegate the right to

    use group policy

    reporting tools

    Assign Edit rights to

    individual policies

    Delegate the right to

    link GPOs to containers

    Edit or

    delete

    GPOs

    Link GPOs

    to

    containers

    Use

    reporting

    tools

    X X X

    XX

    X

    X

    XXX

    XX

  • 8/6/2019 Group Policy Presentation

    31/31

    9 aot 2011 - Group Policy

    Objects - This document isclassified as Public

    31

    Do you have any questions ?

    Group Policy Presentation