Corso referenti S.I.R.A. – Modulo 2 07 – Group Policy 20/11 – 27/11 – 05/12 11/12 – 13/12 (gruppo 1) 12/12 – 15/12 (gruppo 2) Cristiano Gentili, Massimiliano.

Slides:



Advertisements
Similar presentations
Module 5: Creating and Configuring Group Policy
Advertisements

Khan Rashid Lesson 11-The Best Policy: Managing Computers and Users Through Group Policy.
Managing User Settings with Group Policy
Chapter 8 Configuring Group Policies
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
Hands-On Microsoft Windows Server 2003 Administration Chapter 4 Managing Group Policy.
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
MIS Chapter 91 Ch. 9 – Implement and Use Group Policy MIS 431 – created Spring 2006.
10.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 9: Implementing and Using Group Policy.
Administering Active Directory
Chapter 6: Configuring Security. Group Policy and LGPO Setting Options Software Installation not available with LGPOs Remote Installation Services Scripts.
Hands-On Microsoft Windows Server 2003 Administration Chapter 3 Administering Active Directory.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 10: Server Administration.
Lesson 16: Creating Group Policy Objects
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
Guide to MCSE , Enhanced 1 Activity 9-1: Creating a Group Policy Object Using the MMC Objective: To create a GPO using the Group Policy Object Editor.
1 Chapter Overview Creating User and Computer Objects Maintaining User Accounts Creating User Profiles.
Corso referenti S.I.R.A. – Modulo 2 Local Security 20/11 – 27/11 – 05/12 11/12 – 13/12 (gruppo 1) 12/12 – 15/12 (gruppo 2) Cristiano Gentili, Massimiliano.
9.1 © 2004 Pearson Education, Inc. Lesson 9: Implementing Group Policy in Windows 2000 Server Exam Microsoft® Windows® 2000 Directory Services Infrastructure.
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 3: Introducing Active Directory.
1 Chapter Overview Understanding Group Policies Implementing Group Policies Using Security Policies Troubleshooting Group Policy Problems.
Introduction to Group Policy
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
Using Group Policy to Manage User Environments. Overview Introduction to Managing User Environments Introduction to Administrative Templates Assigning.
70-411: Administering Windows Server 2012
11 MANAGING AND DISTRIBUTING SOFTWARE BY USING GROUP POLICY Chapter 5.
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
Managing User Desktops with Group Policy
Overview Introduction to Managing User Environments Introduction to Administrative Templates Using Administrative Templates in Group Policy Assigning Scripts.
Module 6: Implementing Group Policy. Overview Implementing Group Policy Objects Implementing GPOs in a Domain Managing the Deployment of Group Policy.
Introduction to Microsoft Management Console (MMC) MMC is a common console framework for management applications. MMC provides a common environment for.
11.1 © 2004 Pearson Education, Inc. Exam Designing a Microsoft ® Windows ® Server 2003 Active Directory and Network Infrastructure Lesson 11: Planning.
1 Chapter Overview Publishing Resources in Active Directory Service Redirecting Folders Using Group Policies Deploying Applications Using Group Policies.
Module 6: Configuring User Environments Using Group Policy.
Module 7 Configure User and Computer Environments By Using Group Policy.
Implementing Group Policy. Overview What is Group Policy Introduction to Group Policy Group Policy Structure How Group Policy Settings Are Applied in.
Module 4: Administration in Active Directory. Overview  Designing Active Directory to Delegate Administrative Authority Identifying Business Needs Identifying.
1 Administering Shared Folders Understanding Shared Folders Planning Shared Folders Sharing Folders Combining Shared Folder Permissions and NTFS Permissions.
GPO - WINDOWS SERVER AGENDA: Introduction Group Policy Overview Types of Group Policies/Objects Associated Technologies How to implement.
Section 11: Implementing Software Restriction Policies and AppLocker What Is a Software Restriction Policy? Creating a Software Restriction Policy Using.
Module 5: Implementing Group Policy
Module 11: Troubleshooting Group Policy Issues. Module Overview Introduction to Group Policy Troubleshooting Troubleshooting Group Policy Application.
Page 1 System and Group Policies Lecture 7 Hassan Shuja 11/02/2004.
Active Directory Group Policy. Group Policy Overview  Successor to NT policies Much more flexible  Only applies to 2000 workstations Use old style policies.
CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 11: Group Policy for Corporate Policy.
Module 5: Creating and Configuring Group Policies.
Module 4 Planning for Group Policy. Module Overview Planning Group Policy Application Planning Group Policy Processing Planning the Management of Group.
1 Group Policies (Week 11, Monday 3/19/2007) © Abdou Illia, Spring 2007.
1 Chapter Overview Managing Object and Container Permissions Locating and Moving Active Directory Objects Delegating Control Troubleshooting Active Directory.
Administering Group Policy Chapter Eleven. Exam Objectives in this Chapter  Plan a Group Policy strategy using Resultant Set of Policy Planning mode.
Implementing Group Policy
© Wiley Inc All Rights Reserved. MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition.
Week 4 Objectives Overview of Group Policy Group Policy Processing Implementing a Central Store for Administrative Templates.
Implementing a Group Policy Infrastructure
11 INTRODUCTION TO GROUP POLICY Chapter 7. Chapter 7: INTRODUCTION TO GROUP POLICY2 WHAT CAN YOU DO WITH GROUP POLICY?  Control the user environment.
Module 6 Creating and Configuring Group Policy. Module Overview Overview of Group Policy Configuring the Scope of Group Policy Objects Evaluating the.
10.1 © 2004 Pearson Education, Inc. Lesson 10: Specifying Group Policy Settings Exam Microsoft® Windows® 2000 Directory Services Infrastructure.
Windows Server 2003 群組原則設定與管理 林寶森
Unit 8 NT1330 Client-Server Networking II Date: 2?10/2016
1.1 Microsoft® Windows® 2003 Server Group Policy Management Prof. Abdul Hameed.
Module 8: Implementing Group Policy. Overview Multimedia: Introduction to Group Policy Implementing Group Policy Objects Implementing GPOs on a Domain.
Introduction to Group Policy Lesson 7. Group Policy Group Policy is a method of controlling settings across your network. – Group Policy consists of user.
Windows Server 2003 群組原則設定與管理
Utilize Group Policy Terminal Server Settings
Windows Server 2003 群組原則設定與管理
Introduction to Group Policy
Module 8: Implementing Group Policy
Presentation transcript:

Corso referenti S.I.R.A. – Modulo 2 07 – Group Policy 20/11 – 27/11 – 05/12 11/12 – 13/12 (gruppo 1) 12/12 – 15/12 (gruppo 2) Cristiano Gentili, Massimiliano Viola (CSIA)

Overview Introduction to Group Policy Group Policy Structure Working with Group Policy Objects How Group Policy Settings Are Applied in Active Directory Modifying Group Policy Inheritance Delegating Administrative Control of Group Policy Monitoring and Troubleshooting Group Policy Best Practices

Introduction to Group Policy Group Policy Enables You to: Set centralized and decentralized policies Ensure users have their required environments Lower total cost of ownership by controlling user and computer environments Enforce corporate policies Site Domain OU Windows 2000 Applies Continually Users Computers Administrator Sets Group Policy Once Group Policy

Group Policy Structure Group Policy Structure Types of Group Policy Settings Group Policy Objects Group Policy Settings for Computers and Users Group Policy Objects and Active Directory Containers

Types of Group Policy Settings Administrative Templates Administrative Templates Registry-based Group Policy settings Security Settings for local, domain, and network security Software Installation Settings for central management of software installation Scripts Startup, shutdown, logon, and logoff scripts Remote Installation Services Settings that control the options available to users when running the Client Installation wizard used by RIS Internet Explorer Maintenance Settings to administer and customize Microsoft Internet Explorer on Windows 2000–based computers Folder Redirection Settings for storing of users’ folders on a network server

Group Policy Objects Group Policy Object Contains Group Policy settings Content stored in two locations Located in domain controller shared Sysvol folder Provides Group Policy settings that computers running Windows 2000 obtain and apply Located in Active Directory Provides version information used by domain controllers Group Policy Template (GPT) Group Policy Container (GPC)

Group Policy Settings for Computers and Users Group Policy Settings for Computers: Specify operating system behavior, desktop behavior, security settings, computer startup and shutdown scripts, computer-assigned application options, and application settings Apply when the operating system initializes and during the periodic refresh cycle Group Policy Settings for Users: Specify operating system behavior, desktop settings, security settings, assigned and published application options, application settings, folder redirection options, and user logon and logoff scripts Apply when users log on to the computer and during the periodic refresh cycle Users Computers

Group Policy Objects and Active Directory Containers GPO Settings Affect User and Computer Objects Within Sites, Domains, and OUs to Which a GPO Is Linked You can link one GPO to multiple sites, domains, or OUs You can link multiple GPOs to one site, domain, or OU You Cannot Link GPOs to Default Active Directory Containers Site Domain OU OU GPO Site GPO Domain GPO

Working with Group Policy Objects Creating Linked Group Policy Objects Creating Unlinked Group Policy Objects Linking an Existing Group Policy Object Specifying a Domain Controller for Managing Group Policy Objects

Creating Linked Group Policy Objects To Apply Group Policy to a Container, Create a GPO Linked to the Container: Create GPOs linked to domains and OUs by using Active Directory Users and Computers Create GPOs linked to sites by using Active Directory Sites and Services contoso.msft Properties GeneralManaged ByObjectSecurity Group Policy Current Group Policy Object Links for contoso.msft Group Policy Object LinksNo OverrideDisabled Default Domain Policy Account Lockout Policy Passwords Policy Group Policy Objects higher in the list have the highest priority. This list obtained from: London.contoso.msft New Options... Add... Delete... Edit Properties Up Down Block Policy inheritance Close Cancel Apply Name of linked GPO Name of linked GPO

Creating Unlinked Group Policy Objects Select Group Policy Object Local Computer Browse… Allow the focus of the Group Policy Snap-in to be changed when launching from the command line. This only applies if you save the console. View Arrange Icons Line up Icons Refresh New To create an unlinked GPO Browse for a Group Policy Object Domains/OUsSitesComputersAll Look in:contoso.msft All Group Policy Objects stored in this domain: Name Application Deployment Default Domain Controllers Policy Default Domain Policy New Group Policy Object Test

Linking an Existing Group Policy Object contoso.msft Properties GeneralManaged ByObjectSecurity Group Policy Current Group Policy Object Links for contoso.msft Group Policy Object LinksNo OverrideDisabled Default Domain Policy Account Lockout Policy Passwords Policy Group Policy Objects higher in the list have the highest priority. This list obtained from: London.contoso.msft New Options... Add... Delete... Edit Properties Up Down To link an existing GPO To link an existing GPO Add a Group Policy Object Link Domains/OUs SitesAll Look in: Group Policy Objects linked to this container: Name Domain Domain Controllers.nwtraders.msft Accounting.nwtraders.msft Human Resources.nwtraders.msft Default Domain Policy Redirect My Document Policy Logon Attempts Policy Passwords Policy Start Menu Policy OK Cancel contoso.msft Select container in which GPO resides Select GPO to link Select appropriate tab

How Group Policy Settings Are Applied in Active Directory Group Policy Inheritance How Group Policy Settings Are Processed Controlling the Processing of Group Policy Resolving Conflicts Between Group Policy Settings

Group Policy Inheritance Windows 2000 Applies GPO Settings in a Specific Order Windows 2000 Applies GPO Settings in a Specific Order Site Domain OU Child Containers Inherit GPO Settings from Parent Containers Child Containers Inherit GPO Settings from Parent Containers Computers Users Payroll Domain Domain GPO

How Group Policy Settings Are Processed Computer starts User logs on Computer settings applied Startup scripts run User settings applied Logon scripts run The GetGPOList Function Executes on the Client Computer During: Computer startup to determine which GPOs contain computer configurations settings to be applied User logon to determine which GPOs contain user configurations settings to be applied

Controlling the Processing of Group Policy Synchronous and Asynchronous Processing By default, the processing of Group Policy is synchronous You can change the processing of Group Policy to asynchronous by using a Group Policy setting for both computers and users Refreshing Group Policy at Established Intervals of: 90 minutes for computers running Windows 2000 Professional and for member servers running Windows 2000 Server 5 minutes for domain controllers Processing Unchanged Group Policy Settings You can configure each client-side extension to process all applicable Group Policy settings

Resolving Conflicts Between Group Policy Settings All Group Policy Settings Apply Unless There Are Conflicts The Last Setting Processed Applies When settings from different GPOs in the Active Directory hierarchy conflict, the child container GPO settings apply When settings from GPOs linked to the same container conflict, the settings for the GPO highest in the GPO list apply A Computer Setting Applies When It Conflicts with a User Setting

Modifying Group Policy Inheritance Enabling Block Inheritance Enabling No Override Filtering Group Policy Settings

Enabling Block Inheritance Block Inheritance: Stops inheritance of all GPOs from all parent containers Cannot selectively choose which GPOs are blocked Cannot stop No Override GPOs Sales Production Domain No GPO settings apply

Enabling No Override No Override: Overrides Block Inheritance and GPO conflicts Should be set high in the Active Directory tree Is applicable to links and not to GPOs Enforces corporate- wide rules Sales Production Domain Domain GPO settings apply Conflicting GPO Settings No Override GPO Settings

Filtering Group Policy Settings Domain Sales Mengph Kimyo Group Deny Apply Group Policy Deny Apply Group Policy Allow Read and Apply Group Policy Allow Read and Apply Group Policy Filter Group Policy Settings by: Explicitly denying the Apply Group Policy permission Omitting an explicit Apply Group Policy permission

Delegating Administrative Control of Group Policy Enable a User to Manage Group Policy Links for a Site, Domain, or OU by: Assigning the user read and write permissions to the gPLink and gPOptions attributes of the site, domain, or OU Using the Delegation of Control wizard Enable a User or Group to Create GPOs by: Adding the user or group to the Group Policy Creator Owners group Adding the user or group to the Group Policy Creator Owners group Enable a User to Edit GPOs by: Assigning the user read and write permissions to the GPO Making the user a member of either Domain Admins, Enterprise Admins, or GPO Creator Owners groups Granting the user access to the GPO by using the Security tab in the GPO Properties dialog box