understanding group policy part 1

80
Understanding Group Policy Part 1

Upload: others

Post on 03-Feb-2022

3 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Understanding Group Policy Part 1

Understanding Group Policy Part 1

Page 2: Understanding Group Policy Part 1

What Will We Cover?

• Group Policy concepts

• Creating test and staging environments

• Group Policy tools

Page 3: Understanding Group Policy Part 1

Helpful Experience

Level 200

• Experience supporting Windows servers

• Experience supporting Microsoft networks

• Familiarity with Active Directory

www.microsoft.com/technet/ADD-07www.microsoft.com/technet/ADD-08

Page 4: Understanding Group Policy Part 1

Agenda

• Preparing the Environment

• Creating a Staging Environment

• Managing Group Policy

Page 5: Understanding Group Policy Part 1

Designing an OU Structure

Page 6: Understanding Group Policy Part 1

Designing an OU Structure

Page 7: Understanding Group Policy Part 1

Designing an OU Structure

Page 8: Understanding Group Policy Part 1

Designing an OU Structure

Page 9: Understanding Group Policy Part 1

Demo

Organizing OUs

demonstration

Page 10: Understanding Group Policy Part 1

What Is Group Policy?

Page 11: Understanding Group Policy Part 1

What Is Group Policy?

• Manage user and computer environments• Manage user and computer environments

Page 12: Understanding Group Policy Part 1

What Is Group Policy?

• Manage user and computer environments• Manage user and computer environments• Enforce IT policies• Enforce IT policies

Page 13: Understanding Group Policy Part 1

What Is Group Policy?

• Manage user and computer environments• Manage user and computer environments• Enforce IT policies• Enforce IT policies• Simplify administrative tasks• Simplify administrative tasks

Page 14: Understanding Group Policy Part 1

What Is Group Policy?

• Manage user and computer environments• Manage user and computer environments• Enforce IT policies• Enforce IT policies• Simplify administrative tasks• Simplify administrative tasks• Implement security settings• Implement security settings

Page 15: Understanding Group Policy Part 1

Group Policy Terms

Group Policy Object

Computer Configuration

User Configuration

Page 16: Understanding Group Policy Part 1

Group Policy Terms

Scope of Management

Group Policy Object

Site

Domain OU

Computer Configuration

User Configuration

Page 17: Understanding Group Policy Part 1

Group Policy Terms

Scope of Management

Group Policy Object

Computer Configuration

User Configuration

Page 18: Understanding Group Policy Part 1

Group Policy Terms

Scope of Management

Group Policy Object

Computer Configuration

User Configuration

Page 19: Understanding Group Policy Part 1

Common Desktop Scenarios

• Lightly managed• Mobile

• Multiuser

• AppStation

• TaskStation• Kiosk

Page 20: Understanding Group Policy Part 1

Usage Scenarios – Lightly Managed

• For power users or developers

• Least restricted

• Free-seating

• Core set of applicationswww.microsoft.com/downloads/details.aspx?FamilyID=354b9f45-8aa6-4775-9208-c681a7043292&displaylang=en (Search for Group Policy Scenarios)

Page 21: Understanding Group Policy Part 1

Usage Scenarios – Mobile

• Aimed at mobile users

• Data available at all times

• Partial free-seating

• Log off without disconnecting

Page 22: Understanding Group Policy Part 1

Usage Scenarios – Multiuser

• Basic customization

• Free-seating

• Restricted write access

• Security-enhanced

• Assigned and published applications

Page 23: Understanding Group Policy Part 1

Usage Scenarios – AppStation

• Minimal customization

• Few applications

• Free-seating

• Restricted write access

• Security-enhanced

Page 24: Understanding Group Policy Part 1

Usage Scenarios – TaskStation

• For order entry or call centers

• Runs a single application

• No desktop or Start menu

Page 25: Understanding Group Policy Part 1

Usage Scenarios – Kiosk

• Unattended public workstation

• Single application and user

• Security-enhanced

• No user changes or write access

• Always on

Page 26: Understanding Group Policy Part 1

Agenda

• Preparing the Environment

• Creating a Staging Environment

• Managing Group Policy

Page 27: Understanding Group Policy Part 1

Build staging environmentBuild staging environment11

Implementing a Staging Environment

Production Staging

Page 28: Understanding Group Policy Part 1

Synchronize with productionSynchronize with production22

Implementing a Staging Environment

Production Staging

CreateXMLFromEnvironment.wsf CreateEnvironmentFromXML.wsf

Page 29: Understanding Group Policy Part 1

Test GPOsTest GPOs33

Implementing a Staging Environment

Staging

Group Policy Modeling

Page 30: Understanding Group Policy Part 1

Test GPOsTest GPOs33

Implementing a Staging Environment

Staging

Group Policy ModelingGroup Policy Results

Page 31: Understanding Group Policy Part 1

Test GPOsTest GPOs33

Implementing a Staging Environment

Group Policy Results Group Policy Results

Page 32: Understanding Group Policy Part 1

GPO Backups

Prepare for deploymentPrepare for deployment44

Implementing a Staging Environment

Staging

Page 33: Understanding Group Policy Part 1

GPO Backups

Prepare for deploymentPrepare for deployment44

Implementing a Staging Environment

Staging

Migration Tables

Page 34: Understanding Group Policy Part 1

Deploy to productionDeploy to production55

Implementing a Staging Environment

Production Staging

GPO Backups

Migration Tables

Page 35: Understanding Group Policy Part 1

Demo

Creating a Staging Environment

demonstration

Page 36: Understanding Group Policy Part 1

Agenda

• Preparing the Environment

• Creating a Staging Environment

• Managing Group Policy

Page 37: Understanding Group Policy Part 1

Group Policy Management Console

• MMC snap-in

• Includes Group Policy Object Editor

• Reporting and modeling

• Supports cross-forest trusts

Page 38: Understanding Group Policy Part 1

GPMC Service Pack 1

• Various bug fixes

• New languages

• Updated GPMC EULA

• Updated MSXML4http://www.microsoft.com/downloads/details.aspx?FamilyId=0A6D4C24-8CBD-4B35-9272-DD3CBFC81887&displaylang=en

Page 39: Understanding Group Policy Part 1

Demo

Reviewing the GPMC

demonstration

Page 40: Understanding Group Policy Part 1

User and Computer Configuration

Page 41: Understanding Group Policy Part 1

User and Computer Configuration

Page 42: Understanding Group Policy Part 1

User and Computer Configuration

Page 43: Understanding Group Policy Part 1

User and Computer Configuration

Lab Computers settings

Page 44: Understanding Group Policy Part 1

User and Computer Configuration

Page 45: Understanding Group Policy Part 1

User and Computer Configuration

Page 46: Understanding Group Policy Part 1

User and Computer Configuration

Sales Users settings

Page 47: Understanding Group Policy Part 1

User and Computer Configuration

Page 48: Understanding Group Policy Part 1

Sales Users settings

User and Computer Configuration

Lab Computers settings

Page 49: Understanding Group Policy Part 1

Group Policy Order of Precedence

Page 50: Understanding Group Policy Part 1

Local Security Policy

Group Policy Order of Precedence

Page 51: Understanding Group Policy Part 1

Local Security Policy

Site Policy

Group Policy Order of Precedence

Page 52: Understanding Group Policy Part 1

Local Security Policy

Site Policy

Domain Policy

Group Policy Order of Precedence

Page 53: Understanding Group Policy Part 1

Local Security Policy

Site Policy

Domain Policy

Parent OU Policy

Group Policy Order of Precedence

Page 54: Understanding Group Policy Part 1

Local Security Policy

Site Policy

Domain Policy

Parent OU Policy

Child OU Policy

Group Policy Order of Precedence

Page 55: Understanding Group Policy Part 1

When is Group Policy Applied?

Startup and shutdown

Page 56: Understanding Group Policy Part 1

When is Group Policy Applied?

Startup and shutdown

Logon and logoff

Page 57: Understanding Group Policy Part 1

When is Group Policy Applied?

Startup and shutdown

Logon and logoff

Defined intervals

Page 58: Understanding Group Policy Part 1

When is Group Policy Applied?

Startup and shutdown

Logon and logoff

Defined intervals

Forced with GPUpdate.exe

Page 59: Understanding Group Policy Part 1

Group Policy ProcessingSynchronous Initial Processing

Page 60: Understanding Group Policy Part 1

Group Policy ProcessingSynchronous Initial Processing

Page 61: Understanding Group Policy Part 1

Group Policy ProcessingSynchronous Initial Processing

Asynchronous Initial Processing

Page 62: Understanding Group Policy Part 1

Group Policy ProcessingSynchronous Initial Processing

Asynchronous Initial Processing

Page 63: Understanding Group Policy Part 1

Demo

Modifying Group Policy Objects

demonstration

Page 64: Understanding Group Policy Part 1

Group Policy Modeling and Results

• Group Policy Modeling

Simulates GPOs on user or computer

• Group Policy Results

Reports actual policy settings

Page 65: Understanding Group Policy Part 1

Demo

Group Policy Modeling and Results• Using Group Policy Modeling• Using Group Policy Results

demonstration

Page 66: Understanding Group Policy Part 1

Backing Up and Restoring GPOs

Page 67: Understanding Group Policy Part 1

Backing Up and Restoring GPOs

Page 68: Understanding Group Policy Part 1

Backing Up and Restoring GPOs

Page 69: Understanding Group Policy Part 1

Backing Up and Restoring GPOs

Page 70: Understanding Group Policy Part 1

Demo

Backing up and Restoring GPOs

demonstration

Page 71: Understanding Group Policy Part 1

Session Summary

• Manage and control your environment more easily with Group Policy

• Use a staging environment to test Group Policy before production deployment

• Use the GPMC to manage Group Policy

Page 72: Understanding Group Policy Part 1

For More Information

www.microsoft.com/technet/ADD-06

Visit TechNet atwww.microsoft.com/technet

Visit the following URL for additional information

Page 73: Understanding Group Policy Part 1

Microsoft Press Publications

For the latest titles, visitwww.microsoft.com/learning/books/itpro/

Page 75: Understanding Group Policy Part 1

Course ID Title

2274 Managing a Microsoft Windows Server 2003 Environment

For training information and availability www.microsoft.com/learning

Training Resources

Page 76: Understanding Group Policy Part 1

Readiness with Skills Assessment• Self-study learning tool free to anyone• Determines skills gaps• Provides learning plans• Post your score; see how you stack up

Visitwww.microsoft.com/assessment

Page 77: Understanding Group Policy Part 1

Become a Microsoft Certified Professional• What are MCP certifications?

Validation in performing critical IT functions• Why Certify?

Worldwide recognition of skills gained through experienceMore effective deployments with reduced costs for your organizations

• What Certifications are there for IT pros?MCP, MCSE, MCSA, MCDST, MCDBA.

www.microsoft.com/learning/mcp

Page 78: Understanding Group Policy Part 1

www.microsoft.com/technet/subscriptions

Heard the News about TechNet?

• Software without time limits

• Complimentary technical support

• The most current resources on hand

Page 79: Understanding Group Policy Part 1

Find all these support options at www.microsoft.com/technet/supportMicrosoft offers a progressive series of support options starting with no-charge online support and developing through subscription, incident, and contract support.

1. No-Charge Online Support

Knowledge BaseSearch a vast database of articles to pinpoint the information you need.

NewsgroupsAccess over 20,000 active newsgroups on scores of topics.

Product Support CentersGet answers to frequently asked questions, plus how-to articles and step-by-step instructions organized by product.

DLL Help Database Search here to identify the software used to install a specific DLL version.

Events and Errors Message CenterResolve event and error messages fast with explanations, recommendations, and links to support and resources.

Support WebcastsTune in to live technical presentations by Microsoft experts and take part in real-time Q&A.

ChatsChat online with Microsoft specialists or search the transcript archives.

User Group ProgramAccess information and support for IT and other interest-specific user groups.

TechNet Security Resource CenterGet ahead of security risks with resources that keep you current, including security newsletters and the Microsoft notification service.

2. Subscription-Based Support

TechNet SubscriptionSubscribe to TechNet for a personal library of articles, service packs, how-tos, resource kits, tools, utilities, and more. Your subscription includes monthly updates delivered on CD or DVD, so you always have the latest information, straight from the source.

Upgrade to a TechNet Plus subscription and add all this:

1. Full-version evaluation software, including Microsoft Office System and Windows Server System™ products, without time restrictions.

2. Free support — two complimentary incidents, plus a discount on other support calls.

3. Unlimited, next-business-day access to reliable answers from the IT community and Microsoft Support Professionals through Managed Newsgroups (English only).

3. Assisted Incident Support

E-mail SupportGet online incident help via e-mail from a Microsoft Support Professional.

Phone SupportGet incident help over the phone from a Microsoft Support Professional.

Phone Support ContractSave with a discounted 5-Pack Phone Support contract.

Advisory ServicesAdd remotely delivered consultation options from Microsoft Advisory Services for proactive support that goes far beyond routine product maintenance.

4. Contract-Based Support

Premier SupportGet the flexibility to match support options to your organization and enjoy direct access to Microsoft technical experts at any time, day or night. Premier Support delivers customized options for businesses with complex needs, including dedicated technical professionals to overseeyour support, 24x7 problem resolution, and training and workshops that keep your IT staff up to date.

Essential SupportEssential Support offers prepackaged options specifically designed to meet the fundamental support requirements of any business, large or small. Includes account management, problem resolution, and information services.

Page 80: Understanding Group Policy Part 1

• Free chats and webcasts• List of newsgroups• Microsoft community sites• Community events and columns

Where Else Can I Get Help?

www.microsoft.com/technet/community