340 likes | 458 Views
Group Policy in Windows Vista. What Will We Cover?. Group Policy Administration Group Policy with Windows Vista QoS Policies. Helpful Experience. Understanding of Group Policy Administering Windows. Level 200. Agenda. Understanding Group Policy Reviewing New Infrastructure Features
E N D
What Will We Cover? • Group Policy Administration • Group Policy with Windows Vista • QoS Policies
Helpful Experience • Understanding of Group Policy • Administering Windows Level 200
Agenda • Understanding Group Policy • Reviewing New Infrastructure Features • Using Policy Settings
File Format Policy Definition Policy Enforcement Policy Troubleshooting • Network Traffic • End-to-end performance • WAN performance • ADM file format and languages • Storage • Difficult to locate settings • Lack of best practice knowledge • Ping issues • VPN scenarios • Error messages • Complicated diagnostic log Group Policy Pain Points What and Where is GPMC?
demonstration • Preparing Active Directory • Install Group Policy Management Console • Copy AdPrep Folder • Run ForestPrep
Agenda • Understanding Group Policy • Reviewing New Infrastructure Features • Using Policy Settings
Hello Hola SYSVOL Windows Vista Improvements Reliable and Efficient Application of Policy Extended Coverage Ease of Use
Group Policy Service Winlogon • More efficient • Service has been hardened
Group Policy Client Network Awareness Ping Connecting over VPN Ping Ping
Customer Request: Set different configurations for different users with local GPOs Multiple Local GPOs
userenv.log Admin Events Multiple Logs Operational Events Cryptic Error Messages Events and Logging
Demo demonstration • Using Group Policy Features • Run DomainPrep • Access the Vista GPMC • Use Internet Explorer 7.0 Group Policy • Use Events and Logging
%windir%\policydefinitions • Printing.admx • inetres.admx • … • %windir%\policydefinitions \en-us • Printing.adml • inetres.adml Windows Vista Administrative Computer (English) <sysvol>\policies\policydefinitions Printing.admx inetres.admx .. \en-us Printing.adml inetres.adml \fr Printing.adml inetres.adml \ .. Windows Vista Administrative Computer (French) • %windir%\policydefinitions • Printing.admx • inetres.admx • … • %windir%\policydefinitions \fr • Printing.adml • inetres.adml Administrative Template Files
Demo demonstration • Editing Domain-based GPOs Using ADMX Files • Create ADMX Central Store
ADM File ADMX File DFS Replication and SYSVOL SYSVOL
Agenda • Understanding Group Policy • Reviewing New Infrastructure Features • Using Policy Settings
Choosing the Right Settings • Examples of Expanded Policy Settings: Client Help BITS Disk Failure Diagnostics DVD Video Burning Shell Application Management MMTP Network Quarantine Security Protection UAC
Security Pain Points • Users over-privileged • Spyware and viruses • Lost productivity • Administrative cost • Secure by default
IPSec Windows Firewall and IPSec
Windows Defender Wireless and Wired Configuration Version 7.0 Network Access Protection Public Key Policy Configuration Integrated IE 7.0 Policy Settings Security Enhancements
Power Management Printer Management Windows Shell Management Desktop Management
Device Driver Device Driver Device Installation Policy Settings • Device Identification Strings • Device Setup Classes
Demo demonstration • Installing Devices with Group Policy • Block the Installation of a USB Device
A/V Traffic QoS Policies • Source IPv4/IPv6 addresses • Destination IPv4/IPv6 addresses • Protocol • Source or destination ports
Demo demonstration • Configuring QoS Policy • Create a QOS Policy for Web Traffic • Create a QOS Policy for VoIP Traffic
Session Summary • Better Group Policy administration • Restricting device installation • Managing network traffic
Microsoft Press Publications www.microsoft.com/learning/books/itpro/
These books can be found and purchased at all major book stores and online retailers Non-Microsoft Publications
What else does TechNet give you? • FREE TechNet Newsletter” • FREE Events and Webcasts • FREE quarterly “TechNet” magazine • FREE comprehensive technical website • FREE TechNet Radio, Security Centre, Learning Paths and Virtual Labs • TechNet Plus Subscription DVD A range of tools and resources for IT professionals that let you plan, manage ,deploy To subscribe to the newsletter or just to find out more, please visit www.microsoft.com/uk/technet
Thank you for attending this TechNet Event • For my blog go to http://blogs.technet.com/jamesone http://www.microsoft.com/uk/technet PS The evaluation form is now sent out electronically with your thank you e-mail. This can take up to 5 working days. Please do feedback as we read all the comments and use them to shape future event content