Administering Group Policy Chapter Eleven. Exam Objectives in this Chapter  Plan a Group Policy strategy using Resultant Set of Policy Planning mode.

Slides:



Advertisements
Similar presentations
Module 5: Creating and Configuring Group Policy
Advertisements

Khan Rashid Lesson 11-The Best Policy: Managing Computers and Users Through Group Policy.
Managing User Settings with Group Policy
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
11.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
Hands-On Microsoft Windows Server 2003 Administration Chapter 4 Managing Group Policy.
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
MIS Chapter 91 Ch. 9 – Implement and Use Group Policy MIS 431 – created Spring 2006.
10.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 9: Implementing and Using Group Policy.
Chapter 6: Configuring Security. Group Policy and LGPO Setting Options Software Installation not available with LGPOs Remote Installation Services Scripts.
Lesson 16: Creating Group Policy Objects
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
Guide to MCSE , Enhanced 1 Activity 9-1: Creating a Group Policy Object Using the MMC Objective: To create a GPO using the Group Policy Object Editor.
1 Chapter Overview Creating User and Computer Objects Maintaining User Accounts Creating User Profiles.
Understanding Group Policy on Windows Server 2003 John Howard, IT Pro Evangelist, Microsoft UK
9.1 © 2004 Pearson Education, Inc. Lesson 9: Implementing Group Policy in Windows 2000 Server Exam Microsoft® Windows® 2000 Directory Services Infrastructure.
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
1 Chapter Overview Understanding Group Policies Implementing Group Policies Using Security Policies Troubleshooting Group Policy Problems.
Corso referenti S.I.R.A. – Modulo 2 07 – Group Policy 20/11 – 27/11 – 05/12 11/12 – 13/12 (gruppo 1) 12/12 – 15/12 (gruppo 2) Cristiano Gentili, Massimiliano.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
Using Group Policy to Manage User Environments. Overview Introduction to Managing User Environments Introduction to Administrative Templates Assigning.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory Chapter 12: Deploying and Managing Software with Group Policy.
Module 15: Manage the Windows ® Small Business Server 2008 Environment Using Group Policy.
70-411: Administering Windows Server 2012
11 MANAGING AND DISTRIBUTING SOFTWARE BY USING GROUP POLICY Chapter 5.
Managing User Desktops with Group Policy
Chapter 13 Users, Groups Profiles and Policies. Learning Objectives Understand Windows XP Professional user accounts Understand the different types of.
CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
Overview Introduction to Managing User Environments Introduction to Administrative Templates Using Administrative Templates in Group Policy Assigning Scripts.
Introduction to Microsoft Management Console (MMC) MMC is a common console framework for management applications. MMC provides a common environment for.
11.1 © 2004 Pearson Education, Inc. Exam Designing a Microsoft ® Windows ® Server 2003 Active Directory and Network Infrastructure Lesson 11: Planning.
1 Chapter Overview Publishing Resources in Active Directory Service Redirecting Folders Using Group Policies Deploying Applications Using Group Policies.
Module 6: Configuring User Environments Using Group Policy.
Module 7: Managing the User Environment by Using Group Policy.
Module 7 Configure User and Computer Environments By Using Group Policy.
Planning a Group Policy Management and Implementation Strategy Lesson 10.
Implementing Group Policy. Overview What is Group Policy Introduction to Group Policy Group Policy Structure How Group Policy Settings Are Applied in.
4. Managing the Desktop Thomas Lee Chief Technologist – QA plc.
Module 5: Implementing Group Policy
Module 11: Troubleshooting Group Policy Issues. Module Overview Introduction to Group Policy Troubleshooting Troubleshooting Group Policy Application.
CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 11: Group Policy for Corporate Policy.
Module 5: Creating and Configuring Group Policies.
Module 4 Planning for Group Policy. Module Overview Planning Group Policy Application Planning Group Policy Processing Planning the Management of Group.
Module 9: Managing the User Environment by Using Group Policy.
1 Group Policies (Week 11, Monday 3/19/2007) © Abdou Illia, Spring 2007.
NetTech Solutions Supporting Local Users and Groups Lesson Three.
Company Confidential 1 A Course on Planning A Group Policy Management And Implementation Strategy Prepared for: *Stars* New Horizons Certified Professional.
Implementing Group Policy
© Wiley Inc All Rights Reserved. MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition.
11 PLANNING A GROUP POLICY MANAGEMENT AND IMPLEMENTATION STRATEGY Chapter 10.
Implementing a Group Policy Infrastructure
11 INTRODUCTION TO GROUP POLICY Chapter 7. Chapter 7: INTRODUCTION TO GROUP POLICY2 WHAT CAN YOU DO WITH GROUP POLICY?  Control the user environment.
Module 6: Configuring User Environments Using Group Policies.
Module 6 Creating and Configuring Group Policy. Module Overview Overview of Group Policy Configuring the Scope of Group Policy Objects Evaluating the.
Module 11: Troubleshooting Group Policy Issues. Module Overview Introduction to Group Policy Troubleshooting Troubleshooting Group Policy Application.
GROUP POLICY. Group Policy is a hierarchical infrastructure which allows systems administrators to configure computer and user settings from a central.
Unit 8 NT1330 Client-Server Networking II Date: 2?10/2016
1.1 Microsoft® Windows® 2003 Server Group Policy Management Prof. Abdul Hameed.
Configuring the User and Computer Environment Using Group Policy Lesson 8.
Introduction to Group Policy Lesson 7. Group Policy Group Policy is a method of controlling settings across your network. – Group Policy consists of user.
11 CONFIGURING THE USER AND COMPUTER ENVIRONMENT USING GROUP POLICY Chapter 8.
Managing User Desktops with Group Policy
Windows Server 2003 群組原則設定與管理
Unit 8 NT1330 Client-Server Networking II Date: 8/2/2016
Planning a Group Policy Management and Implementation Strategy
Windows Server 2003 群組原則設定與管理
Introduction to Group Policy
Planning a Group Policy Management and Implementation Strategy
Presentation transcript:

Administering Group Policy Chapter Eleven

Exam Objectives in this Chapter  Plan a Group Policy strategy using Resultant Set of Policy Planning mode  Troubleshoot Group Policy application deployment issues  Troubleshoot the application of Group Policy security settings  Redirect folders using Group Policy

In this Chapter:  Managing Group Policy with RSoP  Managing Special Folders with Group Policy  Troubleshooting Group Policy

To Complete this Chapter:  As outlined on pate 11-2

Understanding RSoP  Resultant Set of Policy (RSoP)  RSoP is the sum of the group policies applied to a user or computer.  RSoP is the sum of the policies applied to a user or computer, including the application of filters, such as through security groups and Windows Management Instrumentation (WMI), and exceptions, such as No Override and Block Policy Inheritance.

Generating RSoP Queries  The Resultant Set Of Policy Wizard uses existing GPO settings to report the effects of GPOs on users and computers.  Resultant Set Of Policy Wizard uses two modes : Logging mode Planning mode

Logging Mode  RSoP Logging mode enables you to review existing GPO settings, software installation applications, and security for a computer account or a user account Use Logging mode to  Find failed or overwritten policy settings  See how security groups affect policy settings  Find out how local policy is affecting group policies

Planning Mode  Using RSoP Planning mode, you can poll existing GPOs for policy settings, software installation applications, and security, and you can use WMI filter queries to read hardware and software properties.

Planning mode  Use Planning mode in the following situations: You want to test policy precedence in cases where…  The user and the computer are in different security groups  The user and the computer are in different OUs  The user or the computer is moving to a new location. You want to simulate a slow link You want to simulate loopback.

RSoP Planning Mode Options  Slow-network connection This option simulates a slow connection.  Loopback processing This option simulates enabling of the GPO setting User Group Policy Loopback Processing Mode, located in Computer Configuration, Administrative Templates, System, Group Policy.  can be set to Merge or Replace

RSoP Planning Mode Options  Site name This option simulates the application of alternate subnets for startup or logging on, enabling you to predict the RSoP if the subnet is changed.  Alternate user and computer locations This option simulates the application of alternate locations for both users and computers, enabling you to predict the RSoP if the user and/or computer is moved.

RSoP Planning Mode Options  Alternate user and computer security groups This option simulates the application of alternate security groups to both computer and user configurations, enabling you to predict the RSoP using security groups to filter GPO scope.

RSoP Planning Mode Options  WMI filters for users and computers This option simulates the use of WMI filters to help define the policy settings that are applied, enabling you to predict the RSoP using WMI queries to filter GPO scope.

Exam Tip  Make sure you understand the differences between using RSoP in Logging mode and in Planning mode.

Creating RSoP Queries  Mode Selection: Logging mode Planning mode

Creating RSoP Queries  Computer Selection: This computer Another computer

Creating RSoP Queries  User Selection: Current user Select a specific user

Creating RSoP Queries  Summary of Selections

RSoP Wizard  User and Computer Selection:

RSoP Wizard  Advanced Simulations Options:

RSoP Wizard  Alternate Active Directory Paths:

RSoP Wizard  User Security Groups:  Computer Security:

RSoP Wizard  WMI Filters for Users: All linked filters Only these filters

RSoP Wizard  Summary of Selections

Saving and Viewing RSoP Queries  Steps on pages 14 – 15.

Administrative Templates Results  Computer Configuration Properties filtering status  Displaying filtering status

Administrative Templates Results  Computer Configuration Properties Scope management  Displaying Scope management

Administrative Templates Results  Computer Configuration Properties Revision information  Displaying Revision information

Gpresult Command-Line Tool  Gpresult provides general information about the operating system, user, and computer.

Gpresult Command-Line Tool  Gpresult provides the following information about Group Policy: The last time Group Policy was applied and the domain controller that applied policy—for the user and for the computer The complete list of applied GPOs and their details, including a summary of the extensions that each GPO contains Registry settings that are applied and their details Folders that are redirected and their details Software management information, including details about assigned and published applications Disk quota information Internet Protocol (IP) security settings Scripts

Gpresult Command Parameters  Gpresult has the following syntax: gpresult [/s computer [/u domain\user /p password]] [/user username] [/scope {user|computer}] [/v] [/z]  Note table 11-4  Examples on page 11-21

Advanced System Information–Policy Tool  The Advanced System Information–Policy tool enables you to create an RSoP query and view the results in an HTML report that appears in the Help And Support Center window.  This report can be printed, and it can be saved to an.htm file.

Advanced System Information–Policy Tool  The report generated displays policy-related information for the following categories: Computer name, associated domain, and current site User name and associated domain Applied GPOs for the computer and user Security group memberships for the computer and user Microsoft Internet Explorer settings Scripts: logon, logoff, startup, shutdown Security settings Programs installed Folder redirection Registry settings

Advance System Information

Delegating Control of RSoP  Permission for generating an RSoP query is set for the domain or OU by selecting one of the Generate Resultant Set Of Policy Planning options in the Delegation Of Authority Wizard.  You must be a member of the Enterprise Administrators group to delegate RSoP control at the domain and site level

Practice:  Generating RSoP Queries Exercise 1: Creating an RSoP Query with the Resultant Set Of Policy Wizard Logging Mode  Page Exercise 2: Creating an RSoP Query with the Gpresult Command-Line Tool Exercise 3: Creating an RSoP Query with the Advanced System Information– Policy Tool  Page 11-25

Managing Special Folders with Group Policy  Two ways to set up folder redirection: 1. One location for everyone in the site, domain, or OU 2. A location according to security group membership  Folder Redirection  Offline Folder

Folder Redirection  You redirect users’ folders to provide a centralized location for key Microsoft Windows XP Professional folders on a server or servers.

Special Folders To Be Redirected:  Application Data  Desktop  My Documents  My Pictures  Start Menu

Advantages of Redirecting Folders  Documents are always available  When roaming user profiles are used, only the network path to the My Documents folder is part of the roaming user profile, not the My Documents folder itself.  Offline File technology provides users with access to My Documents even when they are not connected to the network

Advantages of Redirecting Folders  Data stored on a shared network server can be backed up as part of routine system administration  The system administrator can use Group Policy to set disk quotas, limiting the amount of space taken up by users’ special folders  Data specific to a user can be redirected to a different hard disk on the user’s local computer from the hard disk holding the operating system files.

Redirecting My Documents to Home Folders  When you redirect My Documents to a user’s home folder, the system assumes that the administrator has set the following items correctly: Security Ownership Home directory property on the user object

Default Special Folder Locations  Note table 11-5

Setting Up Folder Redirection  Two ways to set up folder redirection: Redirect special folders to one location for everyone in the site, domain, or OU. Redirect special folders to a location according to security group membership. Follow the steps on pages 30 – 37

Exam Tip  Be sure you know the two ways to set up folder redirection.

Policy Removal Considerations  Note table 11-6 page 11-38

Folder Redirection and Offline Files  The Offline Files feature provides users with access to redirected folders even when they are not connected to the network.  Offline Files caches files accessed through folder redirection onto the hard drive of the local computer.  When a user accesses a file in a redirected folder, the file is accessed and modified locally.  When a user has finished working with the file and has logged off, only then does the file traverse the network for storage on the server.

Folder Redirection Best Practices Allow the system to create the folders Use fully qualified UNC paths, for example: \\servername\sharename Accept defaults Place the My Pictures folder in the My Documents folder Consider what will happen if the policy is removed Do not redirect My Documents to the home folder unless you have already deployed home directories in your organization Enable Offline Files

Practice:  Managing Special Folders Exercise 1: Setting Up Folder Redirection Exercise 2: Setting Up Offline Files  Page 11-47

Troubleshooting Group Policy  Troubleshooting Group Policy involves using the Resultant Set Of Policy Wizard, the Gpresult and Gpupdate command-line tools, the Event Viewer, and log files to solve policy-related problems.

Tools include:  Resultant Set Of Policy Wizard and Gpresult  Gpupdate  Event Viewer To enable verbose logging for the event log, complete the steps on page  Log Files

Group Policy Troubleshooting Scenarios  Pages

Summary  Case Scenario Exercise Pages 59 – 60.  Troubleshooting Lab Pages  Exam Highlights Key points Key terms  Page 65