320 likes | 534 Views
Understanding Group Policy Part 3 of 3. Rick Claus IT Pro Advisor Microsoft Canada rick.claus@microsoft.com http://blogs.technet.com/rclaus. What Will We Cover?. Group Policy Management Advanced Group Policy Security Scripting Group Policy Group Policy Modeling. Agenda.
E N D
Understanding Group Policy Part 3 of 3 Rick Claus IT Pro Advisor Microsoft Canada rick.claus@microsoft.com http://blogs.technet.com/rclaus
What Will We Cover? • Group Policy Management • Advanced Group Policy Security • Scripting Group Policy • Group Policy Modeling
Agenda • Managing .ADM Files • Scripting Group Policy • Implementing Advanced Security • Using WMI Filters • Migrating GPOs across Domains • Using Advanced Group Policy Modeling
Administrative Template Extension • Simple way to configure policy • Largest Group Policy extension • .ADM files enable user interface
Using ADM Template Extensions Modify Group Policy 1 Stored on domain controller 2 Policy applied to client 3 Domain Controller SYSVOL Active Directory Database
demonstration Demo Reviewing .ADM Files
Custom ADM Templates Use to Do not use to • Increase security • Disable interface options • Disable confusing items • Control data • Configure all settings • Create unsupported policy
Registry Policies HKEY_LOCAL_MACHINE\SOFTWARE\policies HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\policies HKEY_CURRENT_USER\SOFTWARE\policies HKEY_CURRENT_USER \SOFTWARE\Microsoft\Windows\CurrentVersion\policies
demonstration Demo • Customizing .ADM Templates
Agenda • Managing .ADM Files • Scripting Group Policy • Implementing Advanced Security • Using WMI Filters • Migrating GPOs across Domains • Using Advanced Group Policy Modeling
Scripting Group Policy Backing up GPOs Creating a new GPO Sample Scripts Creating environment using XML Importing a GPO Listing disabled GPOs Listing GPO information GPMC COM Interfaces
demonstration Demo • Scripting Group Policy • Using GPMC Scripts • Changing the Script Host Engine • Using Scripts to Back up GPOs
Agenda • Managing .ADM Files • Scripting Group Policy • Implementing Advanced Security • Using WMI Filters • Migrating GPOs across Domains • Using Advanced Group Policy Modeling
Exclude Accounts from Group Policy Domain Controller Administrator
demonstration Demo • Configuring Group Policy ACLs • Protect Administrator from Group Policy
Delegating Control of GPOs Delegate Domain Controller Delegate Administrator
demonstration Demo • Delegating Administration • Delegating “create GPOs” to ITGroup • Delegating Sales User GPO
Security Configuration and Analysis Does the hard work Enables quick review Ensures policies are enforced Allows local security configuration
Security Configuration Wizard Security Configuration Wizard Administrator download.microsoft.com/download/f/7/1/f71adf6e-dbab-48a2-9a29-9e481110fd55/SCWQuickStartDoc.doc
demonstration Demo • Applying Security Templates
Agenda • Managing .ADM Files • Scripting Group Policy • Implementing Advanced Security • Using WMI Filters • Migrating GPOs across Domains • Using Advanced Group Policy Modeling
WMI Filtering Windows XP Windows XP WMI Filter Domain Controller Windows 2000 XP Professional only
demonstration Demo • Using WMI Filters • Creating WMI Filters • Applying WMI Filters • Modeling WMI Filters
Agenda • Managing .ADM Files • Scripting Group Policy • Implementing Advanced Security • Using WMI Filters • Migrating GPOs across Domains • Using Advanced Group Policy Modeling
Copying GPOs between Domains GPO Backup GPO Import GPO Copy uk.contoso.com us.contoso.com us.contoso.com us.fabrikam.com
demonstration Demo • Migrating GPOs across Domains
Agenda • Managing .ADM Files • Scripting Group Policy • Implementing Advanced Security • Using WMI Filters • Migrating GPOs across Domains • Using Advanced Group Policy Modeling
Group Policy Modeling Overview • Group Policy Modeling Wizard • Group Policy Results Wizard • HTML Reports www.microsoft.com/technet/prodtechnol/windowsserver2003/library/DepKit/b8af2303-dac9-4fd5-9717-c3a7f553c627.mspx
Loopback Processing • Changes GPO processing order • Process only computer settings • Merge user and computer settings
demonstration Demo • Modeling GPO Loopback
Session Summary • Manage and control your environment more easily • Enhance security in your environment • Group Policy Modeling predicts behavior of GPOs before implementing them
For More Information Visit TechNet atwww.microsoft.ca/technet Rick Claus IT Pro Advisor Microsoft Canada rick.claus@microsoft.com http://blogs.technet.com/rclaus