Group policy is
A collection of configuration settings used to define what a system
will look like and how it will behave for a defined group of users or
computer
Group policy is
Supported on all Windows client running Windows 2000 and later.
Group policy is
used to centrally manage and control users and computer
settings.
Benefits of using group policy
Apply security settings
* Manage desktop and
application settings
* Deploy application
* Configure network
settings
Benefits of
Using Group
Policy
Minimize administration as it can be used to
enforce settings to many users and computers
centrally
* Provide a consistent method to enforce standards
in the work environment.
GPO
A container containing a collection of Group Policy
settings that can be applied to a user, computer or both
Tools to manage GPO
Group Policy Management Console
* Group Policy Management Editor
* PowerShell
Administrative
Templates
Used to configure registry based policy settings.
Group Policy settings
Enforce policy settings by
writing the settings to areas of
the registry that standard users
cannot modify
Group Policy settings
Disable the user interface for
settings that Group Policy is
managing
Group Policy settings
Settings are removed when
GPO is not applied
Group Policy Preference
Are written to the normal locations
in the registry that the application
or operating system feature uses
to store the setting
Group Policy Preferences
Do not cause the application or
operating system feature to
disable the user interface for the
settings they configure
Group Policy Preferences
Settings are not removed when
GPO is no longer applied ( by
default)
Default Domain Policy
Linked to the domain
* Affects all security principles in the domain.
Default Domain Controllers Policy
Linked to the Domain Controllers OU,
* Only affect domain controllers
Computer Configuration
policy settings are applied at system startup
* every 90 minutes (+ 30 min variable)
User Configuration
Security settings
refresh at least every 16 hours
Perform Policies refresh manually by using
The Gpupdate command
* The Windows PowerShell cmdlet
GPO Scope
is the collection of users and
computers that will be applied with the settings in
the GPO
Methods to scope a GPO
Link the GPO to container, such as an OU
* Filter by using security settings
Precedence
LocalSiteDomainOU
GPO FILTERING
is used to apply the settings to specific users or
computer