Group Policy - Part 2 of 3 Rick Claus IT Pro Advisor Microsoft Canada [email protected].

25
Group Policy - Part 2 of 3 Rick Claus Rick Claus IT Pro Advisor IT Pro Advisor Microsoft Canada Microsoft Canada [email protected] [email protected] http://blogs.technet.com/rclaus http://blogs.technet.com/rclaus

Transcript of Group Policy - Part 2 of 3 Rick Claus IT Pro Advisor Microsoft Canada [email protected].

Page 1: Group Policy - Part 2 of 3 Rick Claus IT Pro Advisor Microsoft Canada rick.claus@microsoft.com.

Group Policy - Part 2 of 3

Rick ClausRick ClausIT Pro AdvisorIT Pro Advisor

Microsoft CanadaMicrosoft Canada

[email protected]@microsoft.comhttp://blogs.technet.com/rclaushttp://blogs.technet.com/rclaus

Page 2: Group Policy - Part 2 of 3 Rick Claus IT Pro Advisor Microsoft Canada rick.claus@microsoft.com.

What Will We Cover?

• Advanced Group Policy management

• Deploying software with Group Policy

• Group Policy troubleshooting

Page 3: Group Policy - Part 2 of 3 Rick Claus IT Pro Advisor Microsoft Canada rick.claus@microsoft.com.

Agenda

• Implementing Group Policy

• Deploying Software

• Troubleshooting Group Policy

Page 4: Group Policy - Part 2 of 3 Rick Claus IT Pro Advisor Microsoft Canada rick.claus@microsoft.com.

Domain-Level Security Settings

Account Policies

Local Policies

IP Security Policies

File and Registry ACLs

Software Restriction Policies

Account Policies

Local Policies

IP Security Policies

File and Registry ACLs

Software Restriction Policies

Page 5: Group Policy - Part 2 of 3 Rick Claus IT Pro Advisor Microsoft Canada rick.claus@microsoft.com.

Demo

Configuring Domain Policies

demonstration

Page 6: Group Policy - Part 2 of 3 Rick Claus IT Pro Advisor Microsoft Canada rick.claus@microsoft.com.

Software Restriction Policies

Software Restriction Policies

Application started

Hash Rule

Certificate Rule

Path Rule

Internet Zone Rule

Page 7: Group Policy - Part 2 of 3 Rick Claus IT Pro Advisor Microsoft Canada rick.claus@microsoft.com.

Using Software Restriction PoliciesUnrestricted

C:\WINDOWS\SYSTEM32\eventquery.vbsC:\WINDOWS\SYSTEM32\eventquery.vbsC:\WINDOWS\SYSTEM32\pagefileconfig.vbsC:\WINDOWS\SYSTEM32\pagefileconfig.vbs\\LOGIN_SRV\Scripts\CustomerScript1.vbs\\LOGIN_SRV\Scripts\CustomerScript1.vbsC:\Documents and Settings\ILUVU.txt.vbsC:\Documents and Settings\ILUVU.txt.vbs

Page 8: Group Policy - Part 2 of 3 Rick Claus IT Pro Advisor Microsoft Canada rick.claus@microsoft.com.

Demo

Software Restriction Policies

demonstration

Page 9: Group Policy - Part 2 of 3 Rick Claus IT Pro Advisor Microsoft Canada rick.claus@microsoft.com.

Managing Desktops

Local Folder

Shared Network Folder

Elevated privileges

Page 10: Group Policy - Part 2 of 3 Rick Claus IT Pro Advisor Microsoft Canada rick.claus@microsoft.com.

Demo

Managing Desktops

demonstration

Page 11: Group Policy - Part 2 of 3 Rick Claus IT Pro Advisor Microsoft Canada rick.claus@microsoft.com.

Group Policy Filtering

• Security filtering

Refines which users and computers process GPO

• WMI filtering

Filter based on attributes of target computer

Best practice: If you deny GPOs to certain users, disable Read access as well.Best practice: If you deny GPOs to certain users, disable Read access as well.

Page 12: Group Policy - Part 2 of 3 Rick Claus IT Pro Advisor Microsoft Canada rick.claus@microsoft.com.

Group Policy Inheritance

• Link order

• Block inheritance

• Enforcement

• Link status

www.microsoft.com/windowsserver2003/gpmc/gpmcwp.mspx

Page 13: Group Policy - Part 2 of 3 Rick Claus IT Pro Advisor Microsoft Canada rick.claus@microsoft.com.

Demo

Group Policy Filtering and Inheritance

demonstration

Page 14: Group Policy - Part 2 of 3 Rick Claus IT Pro Advisor Microsoft Canada rick.claus@microsoft.com.

Agenda

• Implementing Group Policy

• Deploying Software

• Troubleshooting Group Policy

Page 15: Group Policy - Part 2 of 3 Rick Claus IT Pro Advisor Microsoft Canada rick.claus@microsoft.com.

Software Deployment Options

SMS

WSUSGroup Policy

Rich, granular software distributionRich, granular software distribution

Approve and distribute critical updatesApprove and distribute critical updatesTargeted software deploymentTargeted software deployment

Page 16: Group Policy - Part 2 of 3 Rick Claus IT Pro Advisor Microsoft Canada rick.claus@microsoft.com.

Group Policy Software Deployment

Page 17: Group Policy - Part 2 of 3 Rick Claus IT Pro Advisor Microsoft Canada rick.claus@microsoft.com.

Demo

Deploying Software with Group Policy

demonstration

Page 18: Group Policy - Part 2 of 3 Rick Claus IT Pro Advisor Microsoft Canada rick.claus@microsoft.com.

Session Recap

• Domain-level security settings

• Software restriction policies

• Group Policy filtering and inheritance

• Software deployment with Group Policy

Page 19: Group Policy - Part 2 of 3 Rick Claus IT Pro Advisor Microsoft Canada rick.claus@microsoft.com.

Agenda

• Implementing Group Policy

• Deploying Software

• Troubleshooting Group Policy

Page 20: Group Policy - Part 2 of 3 Rick Claus IT Pro Advisor Microsoft Canada rick.claus@microsoft.com.

Use the Troubleshooting Flowchart

Does Group Policy Results lists the

policy as applied?

Yes NoIs the setting listed?

Is the GPO in the

Denied list?

1. Inheritance2. Asynchronous3. Loopback

1. Replication2. GP Refresh3. Slow Link

1. Security Filtering2. Disabled GPO3. WMI Filter

1. SOM2. GP Refresh3. Network

Yes No Yes

No

Page 21: Group Policy - Part 2 of 3 Rick Claus IT Pro Advisor Microsoft Canada rick.claus@microsoft.com.

Network and Replication Issues

Intersite ReplicationSlow Link Connections

DNS

SMB and LDAP

Page 22: Group Policy - Part 2 of 3 Rick Claus IT Pro Advisor Microsoft Canada rick.claus@microsoft.com.

Group Policy Troubleshooting Tools

> GPResult.exe

> GPMonitor.exe

> GPOTool.exe

> ADDiag.exe

Page 23: Group Policy - Part 2 of 3 Rick Claus IT Pro Advisor Microsoft Canada rick.claus@microsoft.com.

Demo

Troubleshooting Group Policy

demonstration

Page 24: Group Policy - Part 2 of 3 Rick Claus IT Pro Advisor Microsoft Canada rick.claus@microsoft.com.

Session Summary• Group Policy is a powerful tool

• Deploy software through Group Policy

• Several tools are available for troubleshooting Group Policy

Page 25: Group Policy - Part 2 of 3 Rick Claus IT Pro Advisor Microsoft Canada rick.claus@microsoft.com.

For More Information

Visit TechNet at

www.microsoft.ca/technet

Rick ClausRick ClausIT Pro AdvisorIT Pro Advisor

Microsoft CanadaMicrosoft Canada

[email protected]@microsoft.comhttp://blogs.technet.com/rclaushttp://blogs.technet.com/rclaus