Top Banner
GPO - WINDOWS SERVER 2012
18

GPO - WINDOWS SERVER 2012. AGENDA: Introduction Group Policy Overview Types of Group Policies/Objects Associated Technologies How to implement.

Jan 03, 2016

Download

Documents

Jack Newman
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: GPO - WINDOWS SERVER 2012. AGENDA: Introduction Group Policy Overview Types of Group Policies/Objects Associated Technologies How to implement.

GPO - WINDOWS SERVER 2012

Page 2: GPO - WINDOWS SERVER 2012. AGENDA: Introduction Group Policy Overview Types of Group Policies/Objects Associated Technologies How to implement.

AGENDA:

• Introduction

• Group Policy Overview

• Types of Group Policies/Objects

• Associated Technologies

• How to implement

Page 3: GPO - WINDOWS SERVER 2012. AGENDA: Introduction Group Policy Overview Types of Group Policies/Objects Associated Technologies How to implement.

33CDW — PROPRIETARY AND CONFIDENTIAL. COPYING RESTRICTED. FOR INTERNAL USE ONLY.

GROUP POLICY OVERVIEW

• Group Policy Definition • Preferences• Define Scope of Policy (Site,

Domain, Etc.)• Inheritance/Enforce/Block • Administration/GPMC• Naming Conventions• Security Filtering/WMI Filters• RSOP /Modeling• Login Scripts/Startup Scripts• Fine-grained Password

Policies

• Security Templates (More detail later)

• Machine vs. User Policies• Group Policy Loop-back • Change Control

Page 4: GPO - WINDOWS SERVER 2012. AGENDA: Introduction Group Policy Overview Types of Group Policies/Objects Associated Technologies How to implement.

44CDW — PROPRIETARY AND CONFIDENTIAL. COPYING RESTRICTED. FOR INTERNAL USE ONLY.

USER AND COMPUTER CONFIGURATION SETTINGS

Group Policy settings for users: Desktop settings Software settings Windows settings Security settings

Group Policy settings for computers:

Desktop behavior Software settings Windows settings Security settings

Page 5: GPO - WINDOWS SERVER 2012. AGENDA: Introduction Group Policy Overview Types of Group Policies/Objects Associated Technologies How to implement.

55CDW — PROPRIETARY AND CONFIDENTIAL. COPYING RESTRICTED. FOR INTERNAL USE ONLY.

GPO COMPONENTS

Contains Group Policy settingsStores content in two locations

Group Policy ObjectGroup Policy Object

Stored in shared SYSVOL folder Provides Group Policy settingsStored in shared SYSVOL folder Provides Group Policy settings

Group Policy TemplateGroup Policy Template

Stored in Active DirectoryProvides version informationStored in Active DirectoryProvides version information

Group Policy ContainerGroup Policy Container

Page 6: GPO - WINDOWS SERVER 2012. AGENDA: Introduction Group Policy Overview Types of Group Policies/Objects Associated Technologies How to implement.

66CDW — PROPRIETARY AND CONFIDENTIAL. COPYING RESTRICTED. FOR INTERNAL USE ONLY.

WHEN IS A GPO APPLIED?

Computer startsComputer starts

Computer settings applied

Startup scripts run

Computer settings applied

Startup scripts run

Refresh IntervalRefresh Interval

User logs onUser logs on

User settings applied

Logon scripts run

User settings applied

Logon scripts run

Refresh IntervalRefresh Interval

Page 7: GPO - WINDOWS SERVER 2012. AGENDA: Introduction Group Policy Overview Types of Group Policies/Objects Associated Technologies How to implement.

77CDW — PROPRIETARY AND CONFIDENTIAL. COPYING RESTRICTED. FOR INTERNAL USE ONLY.

GPMC (GROUP POLICY MANAGEMENT CONSOLE)

Page 8: GPO - WINDOWS SERVER 2012. AGENDA: Introduction Group Policy Overview Types of Group Policies/Objects Associated Technologies How to implement.

88CDW — PROPRIETARY AND CONFIDENTIAL. COPYING RESTRICTED. FOR INTERNAL USE ONLY.

WHAT IS A GPO LINK?

Organizational Unit GPOOrganizational Unit GPO

Organizational Unit GPOOrganizational Unit GPO

Site GPOSite GPO

Domain GPODomain GPO

Site

Domain

OUOU

OU

Applied in order: Local Site Domain OU

Page 9: GPO - WINDOWS SERVER 2012. AGENDA: Introduction Group Policy Overview Types of Group Policies/Objects Associated Technologies How to implement.

99CDW — PROPRIETARY AND CONFIDENTIAL. COPYING RESTRICTED. FOR INTERNAL USE ONLY.

GP ENFORCEMENT

Page 10: GPO - WINDOWS SERVER 2012. AGENDA: Introduction Group Policy Overview Types of Group Policies/Objects Associated Technologies How to implement.

1010CDW — PROPRIETARY AND CONFIDENTIAL. COPYING RESTRICTED. FOR INTERNAL USE ONLY.

POLICY FILTERING

Page 11: GPO - WINDOWS SERVER 2012. AGENDA: Introduction Group Policy Overview Types of Group Policies/Objects Associated Technologies How to implement.

1111CDW — PROPRIETARY AND CONFIDENTIAL. COPYING RESTRICTED. FOR INTERNAL USE ONLY.

SITE POLICIES

• Second only to local polices• Conditional Polices depending on Network location (VPN,

DMZ, etc)• Time Zones• Printer location related policies

Page 12: GPO - WINDOWS SERVER 2012. AGENDA: Introduction Group Policy Overview Types of Group Policies/Objects Associated Technologies How to implement.

1212CDW — PROPRIETARY AND CONFIDENTIAL. COPYING RESTRICTED. FOR INTERNAL USE ONLY.

DOMAIN POLICIES

• Password and Account Policies• Security and Auditing Policies• Control Restricted Domain Groups• Do not use the Default Domain Policy

Page 13: GPO - WINDOWS SERVER 2012. AGENDA: Introduction Group Policy Overview Types of Group Policies/Objects Associated Technologies How to implement.

1313CDW — PROPRIETARY AND CONFIDENTIAL. COPYING RESTRICTED. FOR INTERNAL USE ONLY.

DEFAULT DOMAIN POLICIES

• Password Settings• Account Lockout Settings• Allow system to be shutdown without having to log on• Change Administrator account name to: • Change Guest account name to:• Clear pagefile on shutdown• Digitally sign server side communication• Digitally sign client communication

Page 14: GPO - WINDOWS SERVER 2012. AGENDA: Introduction Group Policy Overview Types of Group Policies/Objects Associated Technologies How to implement.

1414CDW — PROPRIETARY AND CONFIDENTIAL. COPYING RESTRICTED. FOR INTERNAL USE ONLY.

FINE GRAINED PASSWORD POLICIES

• New in AD DS 2008• Allows companies to define different password policies for

groups within their organization, without creating separate domains

Page 15: GPO - WINDOWS SERVER 2012. AGENDA: Introduction Group Policy Overview Types of Group Policies/Objects Associated Technologies How to implement.

1515CDW — PROPRIETARY AND CONFIDENTIAL. COPYING RESTRICTED. FOR INTERNAL USE ONLY.

USER POLICIES

• Desktop lockdown discussion » Removal of My Documents folder from

computer/Redirection» Removal of context menus» Remove Add/Remove programs» Password protect screen saver» Standard desktop? – same screen saver, desktop

background, fonts, etc for certain users?» Allow/disallow shared folders» Login/Logout Scripts- SW installation» Loopback processing mode (Kiosks)

Page 16: GPO - WINDOWS SERVER 2012. AGENDA: Introduction Group Policy Overview Types of Group Policies/Objects Associated Technologies How to implement.

1616CDW — PROPRIETARY AND CONFIDENTIAL. COPYING RESTRICTED. FOR INTERNAL USE ONLY.

MACHINE POLICIES

• Roaming profiles – on or off, should they propagate to server• Startup scripts and shutdown scripts – async or sync• Run this at user logon – no matter which user• Disk quotas• Dynamic DNS• Group policy refresh interval• Security policy• EFS policy• (desktops) Remote assistance on/off• (desktops) system restore on/off/settings• (desktops) NTP – time settings

Page 17: GPO - WINDOWS SERVER 2012. AGENDA: Introduction Group Policy Overview Types of Group Policies/Objects Associated Technologies How to implement.

1717CDW — PROPRIETARY AND CONFIDENTIAL. COPYING RESTRICTED. FOR INTERNAL USE ONLY.

GUIDELINES FOR PLANNING GPOS

• Apply GPO settings at the highest level• Reduce the number of GPOs• Create specialized GPOs• Use the Enforced option only when required• Use Block Inheritance sparingly• Use security filtering only when necessary

Page 18: GPO - WINDOWS SERVER 2012. AGENDA: Introduction Group Policy Overview Types of Group Policies/Objects Associated Technologies How to implement.

1818CDW — PROPRIETARY AND CONFIDENTIAL. COPYING RESTRICTED. FOR INTERNAL USE ONLY.

Questions?