Module 6 - Implementing A Group Policy Infrastructure
Module 6 - Implementing A Group Policy Infrastructure
Module6:ImplementingaGroupPolicyInfrastructure
Contents: Lesson1: Lesson2: LabA: Lesson3: LabB: Lesson4: Lesson5: LabC: UnderstandGroupPolicy ImplementGPOs ImplementGroupPolicy ManageGroupPolicyScope ManageGroupPolicyScope GroupPolicyProcessing TroubleshootPolicyApplication TroubleshootPolicyApplication
Module Overview
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
1/135
07/06/13
InModule1,youlearnedthatActiveDirectoryDomainServices(ADDS)provides thefoundationalservicesofanidentityandaccesssolutionforenterprisenetworks runningWindows,andthatADDSalsosupportsthemanagementand configurationofeventhelargest,mostcomplexnetworks.InModules2through5, youlearnedhowtoadministerADDSsecurityprincipals:users,groups,and computers.Now,youwillexaminethemanagementandconfigurationofusersand computersbyusingGroupPolicy.GroupPolicyprovidesaninfrastructurewithinwhich settingscanbedefinedcentrallyanddeployedtousersandcomputersinthe enterprise. InanenvironmentmanagedbyawellimplementedGroupPolicyinfrastructure,little ornoconfigurationneedstobemadebydirectlytouchingadesktop.Theentire
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 2/135
07/06/13
Objectives
Aftercompletingthismodule,youwillbeableto: DescribethecomponentsandtechnologiesthatcomprisetheGroupPolicy framework. ImplementGPOs. Configureandunderstandavarietyofpolicysettingtypes. UnderstandandconfigureGroupPolicypreferences. ScopeGPOsbyusinglinks,securitygroups,WindowsManagement Instrumentationfilters,loopbackprocessing,andpreferencetargeting. DescribehowGPOsareprocessed. LocatetheeventlogscontainingGroupPolicyrelatedeventsandtroubleshoot GroupPolicyapplication.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 3/135
07/06/13
Objectives
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 4/135
07/06/13
Ifyouhaveonlyonecomputerinyourenvironmentathome,forexampleandyou needtomodifythedesktopbackground,thereareseveralwaystodothat.Most
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 5/135
07/06/13
peoplewouldprobablyopenPersonalizationfromControlPanelandmakethechange byusingtheWindowsinterface.Thatworkswellforoneuser,butmaybecome tediousifyouwanttomakethechangeacrossmultipleusers.Say,forexample,that youwantthesamebackgroundforyourselfandyourfamily.Youhavetomakethe changemultipletimes,andthenifyoueverchangeyourmindandwanttochange thebackgroundyetagain,youhavetoreturntoeachuser'sprofileandmakethe change.Implementingthechangeandmaintainingaconsistentenvironmentbecomes evenmoredifficultacrossmultiplecomputers. Configurationmanagementisacentralizedapproachtoapplyingoneormorechanges tooneormoreusersorcomputers.Ifyourememberthat,everythingelsewillbe easiertounderstand.Thekeyelementsofconfigurationmanagementare: Acentralizeddefinitionofachange,whichisknownasasetting.Thesettingbrings auseroracomputertoadesiredstateofconfiguration. Adefinitionoftheuser(s)orcomputer(s)towhomthechangeapplies,whichis knownasthescopeofthechange. Amechanismorprocessthatensuresthatthesettingisappliedtousersand computerswithinthescope,whichisknownastheapplication.
GroupPolicyisaframeworkwithinWindowswithcomponentsthatresideinActive Directory,ondomaincontrollers,andoneachWindowsserverandclientthat
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 6/135
07/06/13
Overview of Policies
07/06/13
torenamethelocalAdministratoraccount.Youcanusethispolicysettingtorename theAdministratoraccountonalluserdesktopsandlaptops. Thesetwoexamplesillustrateanimportantpoint:thatsomepolicysettingsaffecta user,regardlessofthecomputertowhichtheuserlogson,andotherpolicysettings affectacomputer,regardlessofwhichuserlogsontothatcomputer.Policysettings suchasthesettingthatpreventsaccesstoregistryeditingtoolsareoftenreferredto asuserconfigurationsettingsorusersettings.Policysettingssuchastheonethat disablestheAdministratoraccountandsimilarsettingsareoftenreferredtoas computerconfigurationsettingsorcomputersettings.Youwillalsohearthese referredtoasuserpoliciesandcomputerpolicies.Theterminologyusedinthe industryisnotexact. TherearevariouspolicysettingsthatcanbemanagedbyGroupPolicy,andthe frameworkisextensible.So,intheend,youcouldmanagejustaboutanythingwith GroupPolicy. Todefineapolicysetting,doubleclickit. ThepolicysettingPropertiesdialogboxappears. Apolicysettingcanhavethreestates:NotConfigured,Enabled,andDisabled. InanewGPO,everypolicysettingissettoNotConfigured.Thismeansthatthe
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 8/135
07/06/13
GPOwillnotmodifytheexistingconfigurationofthatparticularsettingforauseror computer.Ifyouenableordisableapolicysetting,achangewillbemadetothe configurationofusersandcomputerstowhichtheGPOisapplied. Theeffectofthechangedependsonthepolicysetting.Forexample,ifyouenable thePreventAccessToRegistryEditingToolspolicysetting,userswillbeunable tolaunchtheRegedit.exeRegistryEditor.Ifyoudisablethepolicysetting,youensure thatuserscanlaunchtheRegistryEditor.Noticethedoublenegativeinthispolicy setting:Youdisableapolicythatpreventsanaction,soyouallowtheaction. Somepolicysettingsbundleseveralconfigurationsintoonepolicyandmightrequire additionalparameters.Inthescreenshotabove,youcanseethatbyenablingthe policytorestrictregistryeditingtools,youcanalsodefinewhetherregistryfilescan bemergedintothesystemsilentlybyusingregedit/s. NoteManypolicysettingsarecomplex,andtheeffectofenablingordisabling themmightnotbeimmediatelyclear.Also,somepolicysettingsaffectonly certainversionsofWindows.
07/06/13
settingsbeforedeployingachangeintheproductionenvironment. YouwillexplorepolicysettingsandhowtomanagetheminLesson3.
07/06/13
Deploy Software
GroupPoliciescanalsobeusedtodeploysoftwareforusersorcomputers.All softwarethatisprovidedinthe.msiformatcanbedeployedbyusingGroupPolicy.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 11/135
07/06/13
Youcanenforceautomaticsoftwareinstallationoryoucanletyourusersdecideif theywantthesoftwaretobedeployedtotheirmachinesornot.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
12/135
07/06/13
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
13/135
07/06/13
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
14/135
07/06/13
TheGPMEdisplaysthethousandsofpolicysettingsavailableinaGPOinan organizedhierarchythatbeginswiththedivisionbetweencomputersettingsanduser settings,theComputerConfigurationnodeandtheUserConfigurationnode.The nextlevelsofthehierarchyaretwonodescalledPoliciesandPreferences.Youwill learnaboutthedifferencebetweenthesetwonodesasthislessonprogresses.Drilling deeperintothehierarchy,youwillseethattheGPMEdisplaysfolders,whicharealso callednodesorpolicysettinggroups.Withinthefoldersarethepolicysettings themselves.ThePreventAccessToRegistryEditingToolsoptionisselectedinthe screenshotshownhere. TheGPOmustbeappliedtodomain,site,orOUintheADDShierarchyforthe settingswithintheobjecttotakeeffect.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 15/135
07/06/13
YouwilllearnhowtoimplementandmanageGPOsinLesson2.
GPO Scope
07/06/13
orOUthenbecomesthemaximumscopeoftheGPO.Allcomputersanduserswithin thesite,domain,orOU,includingthoseinchildOUs,willbeaffectedbythe configurationsspecifiedbythepolicysettingsintheGPO.AsingleGPOcanbelinked tomorethanonesiteorOU. YoucanfurthernarrowthescopeoftheGPOwithoneoftwotypesoffilters:security filtersthatspecifyglobalsecuritygroupstowhichtheGPOshouldorshouldnot apply,andWindowsManagementInstrumentation(WMI)filtersthatspecifyascope byusingcharacteristicsofasystem,suchasoperatingsystemversionorfreedisk space.UsesecurityfiltersandWMIfilterstonarroworspecifythescopewithinthe initialscopecreatedbytheGPOlink. WindowsServer2008introducedanewcomponentofGroupPolicy:GroupPolicy Preferences.SettingsthatareconfiguredbyGroupPolicyPreferenceswithinaGPO canbefilteredortargetedbasedonseveralcriteria.Targetedpreferencesallowyouto furtherrefinethescopeofPreferenceswithinasingleGPO.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
17/135
07/06/13
Howexactlyarethepolicysettingsapplied?WhenGroupPolicyrefreshbegins,a servicerunningonallWindowssystems,whichiscalledtheGroupPolicyClientin WindowsVista,Windows7,WindowsServer2008,andWindowsServer2008R2, determineswhichGPOsapplytothecomputeroruser.Thisservicedownloadsany GPOsthatarenotalreadycached.Then,aseriesofprocessescalledclientside extensions(CSEs)interpretthesettingsinaGPOandmakeappropriatechangesto thelocalcomputerortothecurrentlyloggedonuser.ThereareCSEsforeachmajor categoryofpolicysetting.Forexample,thereisasecurityCSEthatappliessecurity changes,aCSEthatexecutesstartupandlogonscripts,aCSEthatinstallssoftware, andaCSEthatmakeschangestoregistrykeysandvalues.EachversionofWindows hasaddedCSEstoextendthefunctionalreachofGroupPolicy.Thereareseveral dozenCSEsnowinWindows.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 18/135
07/06/13
OneofthemoreimportantconceptstorememberaboutGroupPolicyisthatitis reallyclientdriven.TheGroupPolicyclientpullstheGPOsfromthedomain, triggeringtheCSEstoapplysettingslocally.GroupPolicyisnotapushtechnology. Infact,thebehaviorofCSEscanbeconfiguredbyusingGroupPolicy.MostCSEswill applysettingsinaGPOonlyifthatGPOhaschanged.Thisbehaviorimprovesoverall policyprocessingbyeliminatingredundantapplicationsofthesamesettings.Most policiesareappliedinsuchawaythatstandarduserscannotchangethesettingon theirsystemtheywillalwaysbesubjecttotheconfigurationenforcedbyGroup Policy.However,somesettingscanbechangedbystandardusers,andmanycanbe changedifauserisanadministratoronthatsystem.Ifusersinyourenvironmentare administratorsontheircomputers,considerconfiguringCSEstoreapplypolicy settingseveniftheGPOhasnotchanged.Thatway,ifanadministrativeuser changesaconfigurationsothatitisnolongercompliantwithpolicy,theconfiguration willberesettoitscompliantstateatthenextGroupPolicyrefresh. NoteYoucanconfigureCSEstoreapplypolicysettings,eveniftheGPOhas notchanged,atbackgroundrefresh.Todoso,configureaGPOscopedto computersanddefinethesettingsintheComputer Configuration\Policies\AdministrativeTemplates\System\GroupPolicynode. ForeachCSEyouwanttoconfigure,openitspolicyprocessingpolicysetting, suchasRegistryPolicyProcessingfortheRegistryCSE.ClickEnabledand selecttheProcesseveniftheGroupPolicyobjectshavenotchangedcheck box.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
19/135
07/06/13
Animportantexceptiontothedefaultpolicyprocessingsettingsissettingsmanaged bythesecurityCSE.Securitysettingsarereappliedevery16hoursevenifaGPOhas notchanged. NoteEnabletheAlwaysWaitForNetworkAtStartupAndLogonpolicysetting forallWindowsclients.Withoutthissetting,bydefault,WindowsXP,Windows Vista,andWindows7clientsperformonlybackgroundrefreshesaclient mightstartup,andausermightlogonwithoutreceivingthelatestpolicies fromthedomain.ThesettingislocatedinComputer Configuration\Policies\AdministrativeTemplates\System\Logon.Besureto readthepolicysettingsexplanatorytext.Thecontoso.comdomainusedin thiscoursehasbeenpreconfiguredwiththisadditionalGroupPolicysetting.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
20/135
07/06/13
07/06/13
Asdiscussedinprevioustopics,themostimportantcomponentstotakecareofwhen dealingwithGroupPoliciesare: Setting.ThisrepresentsaspecificsettingthatisconfigurableineachGroupPolicy object.InWindowsServer2008R2,therealmost3,000differentsettings.Group PolicysettingsprovidethemeaningandpurposeofGroupPolicy.Settingscanbe enabledordisabled,butbydefault,theyareNotConfigured.Theeffectofenabling ordisablingasettingcansometimesbecomplextoevaluate,sobesuretoread theexplanatorytextandtestallsettingsbeforedeployingtheminproduction. Scope.AfterGroupPolicysettingsareconfigured,youmustdecidewheretoapply theGPO.Thisisdefinedbyscope.AGPOcanbelinkedtoasite,domain,orOU.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 22/135
07/06/13
Withinthelinkscope,aGPOcanbefilteredwithsecuritygroupsorWMIfilters. Application.WhenplanningGroupPolicyapplication,youmustbeawareofrefresh intervalsforvarioustypesofcomputers.Computersettingsareappliedatstartup andevery90120minutesthereafter.Usersettingsareappliedatlogonandevery 90120minutesthereafter. Tools.ThereareseveraltoolsformanagingGPOs.GPOsaremanagedthroughthe GroupPolicyManagementconsole.PolicysettingswithinaGPOareconfiguredby usingtheGPME.GPUpdateallowsyoutomanuallytriggerGroupPolicyrefresh. RSoPtoolsallowyoutoevaluateandmodelthesettingsthatwereappliedby GroupPolicy.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
23/135
07/06/13
07/06/13
07/06/13
Module7.
07/06/13
07/06/13
Templatesnodeisdiscussedindetaillaterinthismodule. Therearethousandsofsuchsettingsavailableforconfiguringtheuserandcomputer environment.Asanadministrator,youmightspendasignificantamountoftime manipulatingthesesettings.Toassistyouwiththesettings,adescriptionofeach policysettingisavailableintwolocations: OntheExplaintabinthePropertiesdialogboxforthesetting.Inaddition,the SettingstabinthePropertiesdialogboxforeachsettingalsoliststherequired operatingsystemorsoftwareforthesetting. OntheExtendedtaboftheGPME.TheExtendedtabappearsonthelowerright ofthedetailspaneandprovidesadescriptionofeachselectedsettinginacolumn betweentheconsoletreeandthesettingspane.Therequiredoperatingsystemor softwareforeachsettingisalsolisted.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
28/135
07/06/13
NowthatyouhaveabroadunderstandingofGroupPolicyanditscomponents,you canlookcloselyateachcomponent.Inthissection,youwillexamineGPOsindetail.
Objectives
Aftercompletingthislesson,youwillbeableto: Create,edit,andlinkGPOs. IdentifychangeandconfigurationmanagementcapabilitiesofGroupPolicy. Configurepolicysettings.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
29/135
07/06/13
ExplainGPOstorage,replication,andversioning.
Local GPOs
07/06/13
GPOexistswhetherornotthecomputerispartofadomain,aworkgroup,oranon networkedenvironment.Itisstoredin%SystemRoot%\System3\GroupPolicy.The policiesinthelocalGPOaffectonlythecomputeronwhichtheGPOisstored.By default,onlytheSecuritySettingspoliciesareconfiguredonasystemslocalGPO.All otherpoliciesaresetatNotConfigured. WhenacomputerdoesnotbelongtoanActiveDirectorydomain,thelocalpolicyis usefultoconfigureandenforceconfigurationonthatcomputer.However,inanActive Directorydomain,settingsinGPOsthatarelinkedtothesite,domain,orOUswill overridelocalGPOsettingsandareeasiertomanagethanGPOsonindividual computers. WindowsVista,Windows7,WindowsServer2008,andlatersystemshavemultiple localGPOs.TheLocalComputerGPOisthesameastheGPOinthepreviousversions ofWindows.IntheComputerConfigurationnode,youcanconfigureallcomputer relatedsettings.IntheUserConfigurationnode,youcanconfiguresettingsyouwant toapplytoallusersonthecomputer.TheusersettingsintheLocalComputerGPO canbemodifiedbytheusersettingsintwonewlocalGPOs:AdministratorsandNon Administrators.ThesetwoGPOsapplyusersettingstologgedonusersaccordingto whethertheyaremembersofthelocalAdministratorsgroupinwhichcasetheywould usetheAdministratorsGPOornotmembersoftheAdministratorsgroup(andusethe NonAdministratorsGPO).YoucanfurtherrefinetheusersettingswithalocalGPO thatappliestoaspecificuseraccount.UserspecificlocalGPOsareassociatedwith local,notdomain,useraccounts.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 31/135
07/06/13
RSoPiseasyforcomputersettings:TheLocalComputerGPOistheonlylocalGPO thatcanapplycomputersettings.UsersettingsinauserspecificGPOoverride conflictingsettingsintheAdministratorsandNonAdministratorsGPOs,which themselvesoverridesettingsintheLocalComputerGPO.Theconceptissimplethe morespecificthelocalGPO,thehighertheprecedenceofitssettings. TocreateandeditlocalGPOs: 1. ClicktheStartbuttonandintheStartSearchbox,typemmc.exe,andthen pressEnter. AnemptyMicrosoftManagementconsole(MMC)opens. 2. 3. ClickFile,andthenclickAdd/RemoveSnapin. SelecttheGroupPolicyObjectEditoroption,andthenclickAdd. Adialogboxappears,promptingyoutoselecttheGPOtoedit. 4. TheLocalComputerGPOisselectedbydefault.Ifyouwanttoeditanother localGPO,clicktheBrowsebutton.OntheUserstab,youwillfindtheNon AdministratorsandAdministratorsGPOsandoneGPOforeachlocaluser. SelecttheGPOandclickOK. 5. ClickFinish,andthenclickOKtocloseeachofthedialogboxes.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
32/135
07/06/13
Domain-Based GPOs
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
33/135
07/06/13
WhenADDSisinstalled,twodefaultGPOsarecreated:DefaultDomainControllers PolicyandDefaultDomainPolicy.
07/06/13
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
35/135
07/06/13
AfteryouhavecreatedaGPO,youcancreatetheinitialscopeoftheGPObylinking ittoasite,domain,orOU. TolinkaGPO,rightclickthesite,domain,orOU,andthenclickLinkAnExisting GPO. YoucanalsocreateandlinkaGPOwithasinglestep:rightclickasite,domain,or OU,andthenclickCreateAGPOInThisDomainAndLinkItHere. NotethatyouwillnotseeyoursitesintheSitesnodeoftheGPMCuntilyouright clickSites,clickShowSites,andthenselectthesitesyouwanttomanage. YoumusthavepermissiontolinkGPOstoasite,domain,orOU.IntheGPMC,select thecontainerintheconsoletree,andthenclicktheDelegationtabintheconsole detailspane.FromthePermissiondropdownlist,clickLinkGPOs.Theusersand groupsdisplayedholdthepermissionfortheselectedOU.ClicktheAddorRemove buttonstomodifythedelegation. ToeditaGPO,rightclicktheGPOintheGroupPolicyObjectscontainerandclick Edit. TheGPOisopenedintheGPME.YoumusthaveatleasttheReadpermissiontoopen theGPOinthisway.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
36/135
07/06/13
TomakechangestoaGPO,youmusthavetheWritepermissiontotheGPO. PermissionsfortheGPOcanbesetbyselectingtheGPOintheGroupPolicyObjects containerandthenclickingtheDelegationtabinthedetailspane. TheGPMEwilldisplaythenameoftheGPOastherootnode.TheGPMEalso displaysthedomaininwhichtheGPOisdefinedandtheserverfromwhichtheGPO wasopenedandtowhichchangeswillbesaved.TherootnodeisintheGPOName [ServerName]format.InthescreenshotoftheGPMEonanearlierpageinthis module,therootnodeisCONTOSOStandards[SERVER01.contoso.com]Policy.The GPOnameisCONTOSOStandards,anditwasopenedfromSERVER01.contoso.com, meaningthattheGPOisdefinedinthecontoso.comdomain. Bydefault,boththeGPMCandtheGPMEconsoleconnecttoaspecificdomain controllerinyourenvironmentwiththedomaincontrolleractingasthePDCEmulator. Inalatermodule,youwilllearntoidentifyandmanagewhichdomaincontrollerhas thisrole. ThisisdonetoreducethepossibilitythatasingleGPOmightbechangedontwo differentdomaincontrollers,atwhichpointduringreplicationtherewouldbenoway toreconcilethechanges,andonlyoneversionoftheentireGPOwouldprevailandbe replicated.Focusingtheadministrativetoolsononedomaincontrollerhelpsensure thatchangesaremadeinoneplace. However,inalarge,distributedenvironment,thePDCEmulatormaybeinadistant
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 37/135
07/06/13
Demonstration Steps
CreateaGPO. OpenaGPOforediting. LinkaGPO. DelegatethemanagementofGPOs. DeletetheGPO. DiscussthedefaultconnectiontoPDCemulator.
GPO Storage
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
38/135
07/06/13
GroupPolicysettingsarepresentedasGPOsinActiveDirectoryuserinterfacetools, butaGPOisactuallytwocomponents:aGroupPolicyContainer(GPC)andaGroup PolicyTemplate(GPT). TheGPCisanActiveDirectoryobjectstoredintheGroupPolicyObjectscontainer withinthedomainnamingcontextofthedirectory.LikeallActiveDirectoryobjects, eachGPCincludesagloballyuniqueidentifier(GUID)attributethatuniquelyidentifies theobjectwithinActiveDirectory.TheGPCdefinesbasicattributesoftheGPO,butit doesnotcontainanyofthesettings.ThesettingsarecontainedintheGPTa collectionoffilesstoredintheSYSVOLofeachdomaincontrollerinthe %SystemRoot%\SYSVOL\Domain\Policies\GPOGUIDpath,whereGPOGUIDisthe GUIDoftheGPC.WhenyoumakechangestothesettingsofaGPO,thechangesare
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 39/135
07/06/13
savedtotheGPToftheserverfromwhichtheGPOwasopened. Bydefault,whenGroupPolicyrefreshoccurs,theCSEsapplysettingsinaGPOonlyif theGPOhasbeenupdated. TheGroupPolicyclientcanidentifyanupdatedGPObyitsversionnumber.EachGPO hasaversionnumberthatisincrementedeachtimeachangeismade.Theversion numberisstoredasanattributeoftheGPCandinatextfile,GPT.ini,intheGPT folder.TheGroupPolicyclientknowstheversionnumberofeachGPOithas previouslyapplied.If,duringGroupPolicyrefresh,theGroupPolicyclientdiscovers thattheversionnumberoftheGPChasbeenchanged,theCSEswillbeinformedthat theGPOisupdated.
GPO Replication
GroupPolicyContainerandGroupPolicyTemplatearebothreplicatedbetweenall domaincontrollersinActiveDirectory.However,differentreplicationmechanismsare usedforthesetwoitems. TheGPCinActiveDirectoryisreplicatedbytheDirectoryReplicationAgent(DRA). TheDRAusesatopologygeneratedbytheKnowledgeConsistencyChecker(KCC) thatcanbedefinedorrefinedmanually.YouwilllearnmoreaboutActiveDirectory ReplicationinModule14.TheresultisthattheGPCisreplicatedwithinsecondstoall domaincontrollersinasiteandisreplicatedbetweensitesbasedonyourintersite replicationconfiguration.ThisprocesswillalsobediscussedinModule14.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 40/135
07/06/13
TheGPTintheSYSVOLisreplicatedbyusingoneofthefollowingtwotechnologies. TheFileReplicationService(FRS)isusedtoreplicateSYSVOLindomainsrunning WindowsServer2008,WindowsServer2008R2,WindowsServer2003,and Windows2000.IfalldomaincontrollersarerunningWindowsServer2008orearlier, youcanconfigureSYSVOLreplicationbyusingDistributedFileSystemReplication (DFSR),whichisamuchmoreefficientandrobustmechanism. BecausetheGPCandGPTarereplicatedseparately,itispossibleforthemtobecome outofsyncforashorttime. Typically,whenthishappens,theGPCwillreplicatetoadomaincontrollerfirst. SystemsthatobtainedtheirorderedlistofGPOsfromthatdomaincontrollerwill identifythenewGPC,willattempttodownloadtheGPT,andwillnoticethatthe versionnumbersarenotthesame.Apolicyprocessingerrorwillberecordedinthe eventlogs.Ifthereversehappens,andtheGPOreplicatestoadomaincontroller beforetheGPC,clientsobtainingtheirorderedlistofGPOsfromthatdomain controllerwillnotbenotifiedofthenewGPOuntiltheGPChasreplicated.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
41/135
07/06/13
WhenyourightclickaGPOintheGPMC,alistofusefulmanagementcommands appears. Copy.YoucancopyaGPOandthenrightclicktheGroupPolicyObjectscontainer andselectPastetocreateacopyoftheGPO.Thisisusefulwhenyouwantto createanewGPOinthesamedomainandtostartwiththesamesettingsasan existingGPO.ItisalsousefultocopyaGPOintoanotherdomain,forexample, betweenatestdomainandaproductiondomain.TocopyaGPObetween domains,addthetargettrusteddomaintotheGPMC.Youmusthavepermissionto createGPOsinthetargetdomain.WhenyoupasteaGPO,youaregiventhe optiontocopytheaccesscontrollist(ACL)fromtheoriginalGPO,whichpreserves thesecurityfiltering,ortousethedefaultACLfornewGPOsinthetargetdomain.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 42/135
07/06/13
BackUp.Aswithanycriticaldata,itisimportanttobackupGPOs.BecauseaGPO consistsofseveralfiles,objects,permissions,andlinks,managingthebackupand restoreofGPOsisquitedifficult.Luckily,theBackUpcommandpullsallofthose piecesintoasingleplaceandmakesrestoreasimpletask. RestorefromBackup.RestoreanentireGPO,includingitsfiles,objects, permissions,andlinksintothesamedomaininwhichtheGPOoriginallyexisted. ImportSettings.ImportonlythesettingsfromabackedupGPO.Althoughthis optiondoesnotimportpermissionsorlinks,itcanbeusefulfortransferringGPOs betweennontrusteddomainsthatcannotusecopyandpaste.IfaGPOincludes potentiallydomainspecificsettings,includingtheUNCpathsornamesofsecurity groups,youwillbepromptedastowhetheryouwanttoimportthosesettings exactlyastheywerebackeduportouseamigrationtablethatmapssourceto destinationnames. SaveReport.UsethistosaveanHTMLreportoftheGPOsettings. Delete.UsethistodeleteaGPO. Rename.UsethistorenameaGPO.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
43/135
07/06/13
Lab Setup
Forthislab,youwillusetheavailablevirtualmachineenvironment.Beforeyoubegin thelab,youmustcompletethefollowingsteps: 1. Onthehostcomputer,clickStart,pointtoAdministrativeTools,andthen clickHyperVManager. 2. InHyperVManager,click6425CNYCDC1,andintheActionspane,click Start. 3. IntheActionspane,clickConnect.Waituntilthevirtualmachinestarts.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
44/135
07/06/13
4.
5.
Start6425CNYCCL1.Donotlogontotheclientcomputeruntildirectedtodo so.
Lab Scenario
YouareresponsibleformanagingchangeandconfigurationatContoso,Ltd.Contoso corporateITsecuritypoliciesspecifythatcomputerscannotbeleftunattendedand loggedontoformorethan10minutes.Youwillthereforeconfigurethescreensaver timeoutandpasswordprotectedscreensaverpolicysettings.Additionally,youwill lockdownaccesstoregistryeditingtools.
07/06/13
1.
OnNYCDC1,runGroupPolicyManagementasanadministrator,withthe usernamePat.Coleman_AdminandthepasswordPa$$w0rd.
2.
CreateaGroupPolicyObjectnamedCONTOSOStandardsintheGroup PolicyObjectscontainer.
1.
EdittheCONTOSOStandardsGPO.
46/135
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
07/06/13
2.
NavigatetotheUserConfiguration,Policies,AdministrativeTemplates, Systemfolder.
3. 4.
5. 6. 7.
LinktheCONTOSOStandardsGPOtothecontoso.comdomain.
1. 2.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
47/135
07/06/13
3.
AttempttorunRegistryEditor.YouarepreventedfromdoingsobyGroup Policy.
OnNYCDC1,edittheCONTOSOStandardsGPOandspendtimeexploringthe settingsthatareavailableinaGPO.Donotmakeanychanges.
NoteDonotshutdownthevirtualmachinesafteryoufinishthislabbecause thesettingsyouhaveconfiguredherewillbeusedinsubsequentlabs.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
48/135
07/06/13
1. 2.
3.
Filtertheviewtoshowonlyconfiguredpolicysettings.Spendafewmoments examiningthosesettings.
4.
TurnoffthefilterfromAdministrativeTemplates.
1.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
49/135
07/06/13
Results:Inthisexercise,youaddedcommentstoyourGroupPolicyobjectand settings.
07/06/13
07/06/13
Objectives
Aftercompletingthislesson,youwillbeableto: ManageGPOlinks. IdentifytherelationshipbetweenOUstructureandGPOapplication. EvaluateGPOinheritanceandprecedence. UnderstandtheBlockInheritanceandEnforcedlinkoptions.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 52/135
07/06/13
GPO Links
AGPOcanbelinkedtooneormoreActiveDirectorysites,domains,orOUs.Aftera policyislinkedtoasite,domain,orOU,theusersorcomputersandusersinthat
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 53/135
07/06/13
containerarewithinthescopeoftheGPO,includingcomputersandusersinchild OUs. AsyoulearnedinLesson1,youcanlinkaGPOtothedomain,siteortoanOU. TolinkaGPO,rightclickthedomainorOUintheGPMCconsoletree,andthenclick LinkasexistingGPO.IfyouhavenotyetcreatedaGPO,clickCreateAGPOIn This{Domain|OU|Site}AndLinkItHere. YoucanchoosethesamecommandstolinkaGPOtoasite,butbydefault,your ActiveDirectorysitesarenotvisibleintheGPMC. ToshowsitesintheGPMC,rightclickSitesintheGPMCconsoletreeandchoose ShowSites. NoteAGPOlinkedtoasiteaffectsallcomputersinthesitewithoutregardto thedomaintowhichthecomputersbelong(aslongasallcomputersbelong tothesameActiveDirectoryforest).Therefore,whenyoulinkaGPOtoasite, thatGPOcanbeappliedtomultipledomainswithinaforest.SitelinkedGPOs arestoredondomaincontrollersinthedomaininwhichtheGPOwascreated. Therefore,domaincontrollersforthatdomainmustbeaccessibleforsite linkedGPOstobeappliedcorrectly.Ifyouimplementsitelinkedpolicies,you mustconsiderpolicyapplicationwhenplanningyournetworkinfrastructure. EitherplaceadomaincontrollerfromtheGPOsdomaininthesitetowhich thepolicyislinked,orensurethatawideareanetwork(WAN)connectivity providesaccessibilitytoadomaincontrollerintheGPOsdomain.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 54/135
07/06/13
07/06/13
07/06/13
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
57/135
07/06/13
1.
Localgrouppolicies.EachcomputerrunningWindows2000orlaterhasat leastonelocalgrouppolicy.Thelocalpoliciesareappliedfirst.
2.
3.
4.
5.
07/06/13
IfyoulinkseveralGPOstoanorganizationalunit,theirprocessingoccursintheorder thattheadministratorspecifiesontheLinkedGroupPolicyObjectstabforthe organizationalunitintheGroupPolicyManagementConsole(GPMC). Bydefault,processingisenabledforallGPOlinks.Youcancompletelyblockthe applicationofaGPOforagivensite,domain,ororganizationalunitbydisablingthat containersGPOlink.NotethatiftheGPOislinkedtoothercontainers,theywill continuetoprocesstheGPOiftheirlinksareenabled. YoucanalsodisabletheuserorcomputerconfigurationofaparticularGPO independentofeithertheuserorcomputer.Ifonesectionofapolicyisknowntobe empty,disablingtheothersidespeedsuppolicyprocessing.Forexample,ifyouhave apolicythatonlydeliversuserdesktopconfiguration,youcoulddisablethecomputer sideofthepolicy.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
59/135
07/06/13
ApolicysettingcanbeconfiguredinmorethanoneGPO,andGPOscanbeinconflict withoneanother.Forexample,apolicysettingcanbeenabledinoneGPO,disabled inanotherGPO,andnotconfiguredinathirdGPO.Inthiscase,theprecedenceof theGPOsdetermineswhichpolicysettingtheclientapplies.AGPOwithhigher precedenceprevailsoveraGPOwithlowerprecedence.Precedenceisshownasa numberintheGPMC.Thesmallerthenumberthatis,thecloserto1thehigherthe precedence,soaGPOwithaprecedenceof1willprevailoverotherGPOs.Selectthe domainorOUandthenclicktheGroupPolicyInheritancetabtoviewthe precedenceofeachGPO. WhenapolicysettingisenabledordisabledinaGPOwithhigherprecedence,the configuredsettingtakeseffect.However,rememberthatpolicysettingsaresettoNot
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 60/135
07/06/13
Configuredbydefault.IfapolicysettingisnotconfiguredinaGPOwithhigher precedence,thepolicysetting(eitherenabledordisabled)inaGPOwithlower precedencewilltakeeffect. Asite,domain,orOUcanhavemorethanoneGPOlinkedtoit.Thelinkorderof GPOsdeterminestheprecedenceofGPOsinsuchascenario.GPOswithahigherlink ordertakeprecedenceoverGPOswithalowerlinkorder.WhenyouselectanOUin theGPMC,theLinkedGroupPolicyObjectstabshowsthelinkorderofGPOslinked tothatOU. ThedefaultbehaviorofGroupPolicyisthatGPOslinkedtoahigherlevelcontainer areinheritedbylowerlevelcontainers.Whenacomputerstartsuporauserlogson, theGroupPolicyClientexaminesthelocationofthecomputeroruserobjectinActive DirectoryandevaluatestheGPOswithscopesthatincludethecomputeroruser. Then,theclientsideextensionsapplypolicysettingsfromtheseGPOs.Policiesare appliedsequentially,beginningwiththepolicieslinkedtothesite,followedbythose linkedtothedomain,followedbythoselinkedtoOUsfromthetoplevelOUdown totheOUinwhichtheuserorcomputerobjectexists.Itisalayeredapplicationof settings,soaGPOthatisappliedlaterintheprocess,becauseithashigher precedence,overridessettingsappliedearlierintheprocess. ThesequentialapplicationofGPOscreatesaneffectcalledpolicyinheritance.Policies areinherited,sotheresultantsetofgrouppoliciesforauserorcomputerwillbethe cumulativeeffectofsite,domain,andOUpolicies.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 61/135
07/06/13
Bydefault,inheritedGPOshavelowerprecedencethanGPOslinkeddirectlytothe container.Forexample,youmightconfigureapolicysettingtodisabletheuseof registryeditingtoolsforallusersinthedomainbyconfiguringthepolicysettingina GPOlinkedtothedomain.ThatGPO,anditspolicysetting,isinheritedbyallusers withinthedomain.However,youprobablywantadministratorstobeabletouse registryeditingtools,soyouwilllinkaGPOtotheOUthatcontainsadministrators accountsandconfigurethepolicysettingtoallowtheuseofregistryeditingtools. BecausetheGPOlinkedtotheadministratorsOUtakeshigherprecedencethanthe inheritedGPO,administratorswillbeabletouseregistryeditingtools.Thefollowing figureillustratesGroupPolicyInheritance:
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
62/135
07/06/13
Block Inheritance
AdomainorOUcanbeconfiguredtopreventtheinheritanceofpolicysettings. Toblockinheritance,rightclickthedomainorOUintheGPMCconsoletreeand selectBlockInheritance. TheBlockInheritanceoptionisapropertyofadomainorOU,soitblocksallGroup PolicysettingsfromGPOslinkedtoparentsintheGroupPolicyhierarchy.Whenyou
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 63/135
07/06/13
blockinheritanceonanOU,forexample,GPOapplicationbeginswithanyGPOs linkeddirectlytothatOUGPOslinkedtohigherlevelOUs,thedomain,orthesite willnotapply. TheBlockInheritanceoptionshouldbeusedsparingly.Blockinginheritancemakesit moredifficulttoevaluateGroupPolicyprecedenceandinheritance.Inalatertopic, youwilllearnhowtoscopeaGPOsothatitappliestoonlyasubsetofobjectsorso thatitispreventedfromapplyingtoasubsetofobjects.Withsecuritygroupfiltering, youcancarefullyscopeaGPOsothatitappliestoonlythecorrectusersand computersinthefirstplace,makingitunnecessarytousetheBlockInheritance option.
07/06/13
set. Inthefigureonthefollowingpage,BlockInheritancehasbeenappliedtothe BusinessOU.Asaresult,GPOD,whichisappliedtothedomain,isblockedanddoes notapplywhenauserfromtheEmployeesOUlogsontoacomputerintheClients OU.However,intheSecurityGPO,GPOslinkedtothedomainwiththeEnforced optiondoesapply.Infact,itisappliedlastintheprocessingorder,meaningits settingswilloverridethoseofGPOsB,C,andE. WhenyouconfigureaGPOthatdefinesconfigurationmandatedbyyourcorporateIT securityandusagepolicies,youwanttoensurethatthosesettingsarenotoverridden byotherGPOs.YoucandothisbyenforcingthelinkoftheGPO.Thefigurehere showsjustthisscenario:
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
65/135
07/06/13
Evaluating Precedence
TofacilitateevaluationofGPOprecedence,youcansimplyselectanOU(ordomain) andclicktheGroupPolicyInheritancetab.Thistabwilldisplaytheresulting precedenceofGPOs,accountingforGPOlink,linkorder,inheritanceblocking,and linkenforcement.Thistabdoesnotaccountforpoliciesthatarelinkedtoasite,nor doesitaccountforGPOsecurityorWMIfiltering.
Bynow,youvelearnedthatyoucanlinkaGPOtoasite,domain,orOU.However, youmightneedtoapplyGPOsonlytocertaingroupsofusersorcomputersrather
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 66/135
07/06/13
thantoallusersorcomputerswithinthescopeoftheGPO.Althoughyoucannot directlylinkaGPOtoasecuritygroup,thereisawaytoapplyGPOstospecific securitygroups.ThepoliciesinaGPOapplyonlytouserswhohaveAllowReadand AllowApplyGroupPolicypermissionstotheGPO. EachGPOhasanACLthatdefinespermissionstotheGPO.Twopermissions,Allow ReadandAllowApplyGroupPolicy,arerequiredforaGPOtoapplytoauseror computer.Forexample,ifaGPOisscopedtoacomputerbyitslinktothecomputers OU,butthecomputerdoesnothaveReadandApplyGroupPolicypermissions,itwill notdownloadandapplytheGPO.Therefore,bysettingtheappropriatepermissions forsecuritygroups,youcanfilteraGPOsothatitssettingsapplyonlytothe computersandusersyouspecify. Bydefault,AuthenticatedUsersaregiventheAllowApplyGroupPolicypermissionon eachnewGPO.Thismeansthatbydefault,allusersandcomputersareaffectedby theGPOssetfortheirdomain,site,orOU,regardlessoftheothergroupsinwhich theymightbemembers.Therefore,therearetwowaysoffilteringGPOscope: RemovetheApplyGroupPolicypermission(currentlysettoAllow)forthe AuthenticatedUsersgroupbutdonotsetthispermissiontoDeny.Then,determine thegroupstowhichtheGPOshouldbeappliedandsettheReadandApplyGroup PolicypermissionsforthesegroupstoAllow. DeterminethegroupstowhichtheGPOshouldnotbeappliedandsettheApply GroupPolicypermissionforthesegroupstoDeny.IfyoudenytheApplyGroup
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 67/135
07/06/13
NoteGPOscanbefilteredonlywithglobalsecuritygroupsnotwith domainlocalsecuritygroups.
3. 4. 5.
TheresultwilllooksimilartothefigureshownheretheAuthenticatedUsersgroupis
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 68/135
07/06/13
notlisted,andthespecificgrouptowhichthepolicyshouldapplyislisted.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
07/06/13
3.
ClicktheAdvancedbutton. TheSecuritySettingsdialogboxappears.
4. 5.
6.
ClickOK. ThegroupyouselectedisgiventheAllowReadpermissionbydefault.
7. 8.
CleartheAllowReadpermissioncheckbox. SelecttheDenyApplyGroupPolicycheckbox.
ThefigurehereshowsanexamplethatdeniestheHelpDeskgrouptheApplygroup policypermissionand,therefore,excludesthegroupfromthescopeoftheGPO.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
70/135
07/06/13
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
71/135
07/06/13
ThisisyetonemorereasontouseDenypermissionssparingly.
WMI Filters
WMIisamanagementinfrastructuretechnologythatenablesadministratorsto monitorandcontrolmanagedobjectsinthenetwork.AWMIqueryiscapableof
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 72/135
07/06/13
filteringsystemsbasedoncharacteristics,includingRAM,processorspeed,disk capacity,IPaddress,operatingsystemversionandservicepacklevel,installed applications,andprinterproperties.BecauseWMIexposesalmosteverypropertyof everyobjectwithinacomputer,thelistofattributesthatcanbeusedinaWMIquery isvirtuallyunlimited.WMIqueriesarewrittenbyusingWMIQueryLanguage(WQL). YoucanuseaWMIquerytocreateaWMIfilter,withwhichaGPOcanbefiltered.A goodwaytounderstandthepurposeofaWMIfilter,bothforthecertificationexams andforrealworldimplementation,isthroughexamples.GroupPolicycanbeusedto deploysoftwareapplicationsandservicepacksacapabilitythatisdiscussedin Module7.YoumightcreateaGPOtodeployanapplicationandthenuseaWMIfilter tospecifythatthepolicyshouldapplyonlytocomputerswithacertainoperating systemandservicepackWindowsXPSP3,forexample.TheWMIquerytoidentify suchsystemsis:
07/06/13
WMIexposesnamespaces,withinwhichareclassesthatcanbequeried.Manyuseful classes,includingWin32_OperatingSystem,arefoundinaclasscalledroot\CIMv2. TocreateaWMIfilter: 1. RightclicktheWMIFiltersnodeintheGPMCconsoletree,andthenclick New. Typeanameanddescriptionforthefilter,andthenclicktheAddbutton. 2. 3. 4. IntheNamespacebox,typethenamespaceforyourquery. IntheQuerybox,enterthequery. ClickOK. TofilteraGPOwithaWMIfilter: 1. 2. 3. SelecttheGPOorGPOlinkintheconsoletree. ClicktheScopetab. ClicktheWMIdropdownlist,andselecttheWMIfilter.
07/06/13
figurehere,displaystheGPOsthatusetheWMIfilter:
07/06/13
YoucanpreventthesettingsintheComputerConfigurationorUserConfiguration
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 76/135
07/06/13
nodesfrombeingprocessedduringpolicyrefreshbychangingtheGPOStatus.
07/06/13
UserConfigurationSettingsDisabled.Duringuserpolicyrefresh,user configurationsettingsintheGPOwillnotbeapplied.
Target Preferences
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
78/135
07/06/13
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
79/135
07/06/13
07/06/13
balancetheconfigurationmanagementbenefitsofitemleveltargetingagainstthe performanceimpactyoudiscoverduringtestinginalab.
07/06/13
importantforvirtualdesktopinfrastructure(VDI)scenarios,includingremotevirtual machinesandRemoteDesktopServices(RDS),knownasTerminalServicesin previousversions. Imagineascenarioinwhichyouwanttoenforceastandardcorporateappearancefor theWindowsdesktoponallcomputersinconferenceroomsandotherpublicareasof youroffice.HowwillyoucentrallymanagethisconfigurationbyusingGroupPolicy? PolicysettingsthatconfiguredesktopappearancearelocatedintheUser ConfigurationnodeofaGPO.Therefore,bydefault,thesettingsapplytousers, regardlessofwhichcomputertheylogonto.Thedefaultpolicyprocessingdoesnot giveyouawaytoscopeusersettingstoapplytocomputers,regardlessofwhichuser logson.Thatswhereloopbackpolicyprocessingcomesin. LoopbackpolicyprocessingaltersthedefaultalgorithmusedbytheGroupPolicy clienttoobtaintheorderedlistofGPOsthatshouldbeappliedtoausers configuration.InsteadofuserconfigurationbeingdeterminedbytheUser ConfigurationnodeofGPOsthatarescopedtotheuserobject,userconfiguration canbedeterminedbytheUserConfigurationnodepoliciesofGPOsthatarescoped tothecomputerobject. TheUserGroupPolicyloopbackprocessingmodepolicy,locatedintheComputer Configuration\Policies\AdministrativeTemplates\System\GroupPolicyfolderinGPME, canbe,likeallpolicysettings,settoNotConfigured,Enabled,orDisabled.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
82/135
07/06/13
Whenenabled,thepolicycanspecifytheReplaceorMergemode. Replace.Inthiscase,theGPOlistfortheuser(obtainedinstep5intheGroup PolicyProcessing,thenextsection)isreplacedentirelybytheGPOlistalready obtainedforthecomputeratcomputerstartup(instep2).ThesettingsinUser ConfigurationpoliciesofthecomputersGPOsareappliedtotheuser.TheReplace modeisusefulinasituationsuchasaclassroomwhereusersshouldreceivea standardconfigurationratherthantheconfigurationappliedtothoseusersinaless managedenvironment. Merge.Inthiscase,theGPOlistobtainedforthecomputeratcomputerstartup (step2intheGroupPolicyProcessingsection)isappendedtotheGPOlist obtainedfortheuserwhenloggingon(step5).BecausetheGPOlistobtainedfor thecomputerisappliedlater,settingsinGPOsonthecomputerslisthave
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 83/135
07/06/13
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
84/135
07/06/13
Lab Setup
Forthislab,youwillusetheavailablevirtualmachineenvironment.Beforeyoubegin thelab,youmustcompletethefollowingsteps: 1. Onthehostcomputer,clickStart,pointtoAdministrativeTools,andthen clickHyperVManager. 2. InHyperVManager,click6425CNYCDC1,andintheActionspane,click Start. 3. IntheActionspane,clickConnect.Waituntilthevirtualmachinestarts.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
85/135
07/06/13
4.
5.
Start6425CNYCCL1.Donotlogontotheclientcomputeruntildirectedtodo so.
Lab Scenario
Youareanadministratorofthecontoso.comdomain.TheContosoStandardsGPO, linkedtothedomain,configuresapolicysettingthatrequiresatenminutescreen savertimeout.Anengineerreportsthatacriticalapplicationthatperformslengthy calculationscrasheswhenthescreenssaverstarts,andtheengineerhasaskedyouto preventthesettingfromapplyingtotheteamofengineersthatusestheapplication everyday.Youhavealsobeenaskedtoconfigureconferenceroomcomputerstouse a45minutetimeoutsothatthescreensaverdoesnotlaunchduringameeting.
07/06/13
Task 1: Create a GPO with a policy setting that takes precedence over a conflicting setting. 1. OnNYCDC1,runActiveDirectoryUsersandComputersasan administrator,withtheusernamePat.Coleman_Adminandthepassword Pa$$w0rd. 2. IntheUserAccounts\EmployeesOU,createasubOUcalledEngineers,and thencloseActiveDirectoryUsersandComputers. 3. RuntheGroupPolicyManagementConsoleasanadministrator,withtheuser namePat.Coleman_AdminandthepasswordPa$$w0rd. 4. CreateanewGPOlinkedtotheEngineersOUcalledEngineering ApplicationOverride.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 87/135
07/06/13
5.
ConfiguretheScreensavertimeoutpolicysettingtobedisabled,andthen closetheGPME.
6.
1.
IntheGPMCconsoletree,selecttheDomainControllersOU,andthenclick theGroupPolicyInheritancetab.
2.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
88/135
07/06/13
1.
IntheGPMCconsole,selecttheEngineersOUandexaminetheprecedence andinheritanceofGPOsontheGroupPolicyInheritancetab.
2.
3.
TurnoffBlockInheritancefromtheEngineersOU.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
89/135
07/06/13
1.
RunActiveDirectoryUsersandComputersasanadministrator,withthe usernamePat.Coleman_AdminandthepasswordPa$$w0rd.
2.
IntheGroups\ConfigurationOU,createaglobalsecuritygroupnamed
90/135
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
07/06/13
1.
RunActiveDirectoryUsersandComputersasanadministratorwiththeuser namePat.Coleman_AdminandthepasswordPa$$w0rd.
2.
IntheGroups\ConfigurationOU,createaglobalsecuritygroupnamed GPO_CONTOSOStandards_Exempt.
3.
4.
ConfiguretheGPOtodenyApplyGroupPolicypermissiontothe GPO_CONTOSOStandards_Exemptgroup.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
91/135
07/06/13
1.
CreateanewGPOnamedConferenceRoomPoliciesandlinkittothe Kiosks\ConferenceRoomsOU.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
92/135
07/06/13
2.
ConfirmthattheConferenceRoomPoliciesGPOisscopedto AuthenticatedUsers.
3.
NoteDonotshutdownthevirtualmachinesafteryoufinishthislabbecause thesettingsyouhaveconfiguredherewillbeusedinsubsequentlabs.
Lab Review Questions Question:Manyorganizationsrelyheavilyonsecuritygroupfilteringtoscope GPOs,ratherthanlinkingGPOstospecificOUs.Intheseorganizations,GPOsare typicallylinkedveryhighintheActiveDirectorylogicalstructuretothedomain itselfortoafirstlevelOU.Whatadvantagesaregainedbyusingsecuritygroup filteringratherthanGPOlinkstomanagethescopeoftheGPO? Question:Whymightitbeusefultocreateanexemptiongroupagroupthat isdeniedtheApplyGroupPolicypermissionforeveryGPOyoucreate?
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 93/135
07/06/13
Nowthatyouhavelearnedmoreabouttheconcepts,components,andscopingof GroupPolicy,youarereadytoexamineGroupPolicyprocessingclosely.
Objectives
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 94/135
07/06/13
07/06/13
precedencetheirsettings,whenapplied,willoverridesettingsappliedearlier.The followingsequencedetailstheprocessthroughwhichsettingsinadomainbasedGPO areappliedtoaffectacomputeroruser. 1. Thecomputerstarts,andthenetworkstarts.RemoteProcedureCallSystem Service(RPCSS)andMultipleUniversalNamingConventionProvider(MUP)are started.TheGroupPolicyClientisstarted. 2. TheGroupPolicyClientobtainsanorderedlistofGPOsscopedtothecomputer. TheorderofthelistdeterminestheorderofGPOprocessing,whichis,by default,local,site,domain,andOU. LocalGPOs.EachcomputerrunningWindowsServer2003,WindowsXP,and Windows2000hasexactlyoneGPOstoredlocally.WindowsVista,Windows Server2008,andWindows7havemultiplelocalGPOs.Theprecedenceof localGPOsisdiscussedintheLocalGPOssectioninLesson2. SiteGPOs.AnyGPOsthathavebeenlinkedtothesiteareaddedtothe orderedlistnext.WhenmultipleGPOsarelinkedtoasite,adomain,oran OU,thelinkorder,configuredontheScopetab,determinestheorderin whichtheyareaddedtothelist.TheGPOthatishighestonthelist,withthe numberclosestto1,hasthehighestprecedence,andisaddedtothelistlast. Itwill,therefore,beappliedlast,anditssettingswilloverridethoseofthe GPOsappliedearlier. DomainGPOs.MultipledomainlinkedGPOsareaddedasspecifiedbythelink
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 96/135
07/06/13
OUGPOs.GPOslinkedtotheOUhighestintheActiveDirectoryhierarchyare addedtotheorderedlist,followedbyGPOslinkedtoitschildOU,andsoon. Finally,theGPOslinkedtotheOUthatcontainsthecomputerareadded.If severalgrouppoliciesarelinkedtoanOU,theyareaddedintheorder specifiedbythelinkorder. EnforcedGPOsareaddedattheendoftheorderedlist,sotheirsettingswill beappliedattheendoftheprocessandwill,therefore,overridesettingsof GPOsearlierinthelistandintheprocess.Asapointoftrivia,enforcedGPOs areaddedtothelistinthereverseorder:OU,domain,andsite.Thisis relevantwhenyouapplycorporatesecuritypoliciesinadomainlinked enforcedGPO.ThatGPOwillbeattheendoftheorderedlistandwillbe appliedlast,soitssettingswilltakeprecedence. 3. TheGPOsareprocessedsynchronouslyintheorderspecifiedbytheorderedlist. ThismeansthatsettingsinthelocalGPOsareprocessedfirst,followedbyGPOs linkedtothesite,thedomain,andtheOUscontainingtheuserorcomputer. GPOslinkedtotheOUofwhichthecomputeroruserisadirectmemberare
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 97/135
07/06/13
processedlast,followedbyenforcedGPOs. AseachGPOisprocessed,thesystemdetermineswhetheritssettingsshould beappliedbasedontheGPOstatusforthecomputernode(enabledor disabled)andwhetherthecomputerhastheAllowGroupPolicypermission.If aWMIfilterisappliedtotheGPO,andifthecomputerisrunningWindowsXP orlater,itperformstheWQLqueryspecifiedinthefilter. 4. IftheGPOshouldbeappliedtothesystem,CSEstriggertoprocesstheGPO settings.PolicysettingsinGPOsoverwritepoliciesofpreviouslyappliedGPOsin thefollowingways: Ifapolicysettingisconfigured(settoEnabledorDisabled)inaGPOlinkedto aparentcontainer(OU,domain,orsite),andthesamepolicysettingisNot ConfiguredinGPOslinkedtoitschildcontainer,theresultantsetofpolicies forusersandcomputersinthechildcontainerwillincludetheparentspolicy setting.IfthechildcontainerisconfiguredwiththeBlockInheritanceoption, theparentsettingisnotinheritedunlesstheGPOlinkisconfiguredwiththe Enforcedoption. Ifapolicysettingisconfigured(settoEnabledorDisabled)foraparent container,andthesamepolicysettingisconfiguredforachild,thechild containerssettingoverridesthesettinginheritedfromtheparent.Ifthe parentGPOlinkisconfiguredwiththeEnforcedoption,theparentsettinghas precedence. IfapolicysettingofGPOslinkedtoparentcontainersisNotConfigured,and
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 98/135
07/06/13
6.
Every90120minutesaftercomputerstartup,computerpolicyrefreshoccurs, andtheprocessisrepeatedforcomputersettings.
7.
Every90120minutesafteruserlogon,userpolicyrefreshoccurs,andthe processisrepeatedforusersettings.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
99/135
07/06/13
07/06/13
ClientSide Extension
Registrypolicyprocessing InternetExplorermaintenance SoftwareInstallationpolicy FolderRedirectionpolicy Scriptspolicy Securitypolicy InternetProtocolSecurity (IPSec)policy
Slowlinkprocessing
Canitbechanged?
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
101/135
07/06/13
Off On Off
Ifauserisworkingwhiledisconnectedfromthenetwork,thesettingspreviously appliedbyGroupPolicycontinuetotakeeffect,soausersexperienceisidentical, irrespectiveofwhetherheorsheisonthenetworkoraway.Thereareexceptionsto thisrule,mostnotablythatstartup,logon,logoff,andshutdownscriptswillnotrunif theuserisdisconnected. Ifaremoteuserconnectstothenetwork,theGroupPolicyclientwakesupand determineswhetheraGroupPolicyrefreshwindowhasbeenmissed.Ifso,it performsaGroupPolicyrefreshtoobtainthelatestGPOsfromthedomain.Again, theCSEsdetermine,basedontheirpolicyprocessingsettings,whethersettingsin thoseGPOsareapplied.ThisprocessdoesnotapplytoWindowsXPorWindows Server2003systems.ItappliesonlytoWindowsVista,WindowsServer2008, Windows7,andneweroperatingsystems.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
102/135
07/06/13
ThereareseveralprocessesthatmustbecompletedbeforeGroupPolicysettingsare actuallyappliedtoauseroracomputer.Wewilldiscusstheseprocessesinthistopic
07/06/13
07/06/13
07/06/13
g p u p d a t e/ f o r c e/ l o g o f f/ b o o t
InWindows2000Server,theSecedit.execommandwasusedtorefreshpolicy,so youmightencounteramentionoftheSecedit.execommandontheexam.
Most CSEs Do Not Reapply Settings if the GPO Has Not Changed
RememberthatmostCSEsapplysettingsinaGPOonlyiftheGPOversionhas changed.Thismeansifausercanchangeasettingthatwasoriginallyspecifiedby GroupPolicy,thesettingwillnotbebroughtbackintocompliancewiththesettings specifiedbytheGPOuntiltheGPOchanges.Luckily,mostpolicysettingscannotbe changedbyanonprivilegeduser.However,ifauserisanadministratoroftheir computer,orifthepolicysettingaffectsapartoftheregistryorofthesystemthat theuserhaspermissionstochange,thiscouldbearealproblem.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
106/135
07/06/13
07/06/13
Objectives
Aftercompletingthislesson,youwillbeableto: AnalyzethesetofGPOsandpolicysettingsthathavebeenappliedtoauseror computer. ProactivelymodeltheimpactofGroupPolicyorActiveDirectorychangesonthe ResultantSetofPolicy(RSOP). LocatetheeventlogscontainingGroupPolicyrelatedevents.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
108/135
07/06/13
07/06/13
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
110/135
07/06/13
TohelpyouanalyzethecumulativeeffectofGPOsandpolicysettingsonauseror computerinyourorganization,theGPMCincludestheGroupPolicyResultsWizard.If youwanttounderstandexactlywhichpolicysettingshaveappliedtoauserora computer,andwhy,theGroupPolicyResultsWizardisthetooltouse. TheGroupPolicyResultsWizardcanreachintotheWMIprovideronalocalor remotecomputerrunningWindowVista,WindowsXP,WindowsServer2003, WindowsServer2008,orWindows7.TheWMIprovidercanreporteverythingthere istoknowaboutthewayGroupPolicywasappliedtothesystem.Itknowswhen processingoccurred,whichGPOswereapplied,whichGPOswerenotappliedand why,errorsthatwereencountered,andtheexactpolicysettingsthattookprecedence andtheirsourceGPO.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 111/135
07/06/13
Afteryouhaveensuredthattherequirementsaremet,youarereadytorunanRSoP analysis.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
112/135
07/06/13
TorunanRSoPreport,rightclickGroupPolicyResultsintheGPMCconsoletree andthenclickGroupPolicyResultsWizard. Thewizardpromptsyoutoselectacomputer.ItthenconnectstotheWMIprovider onthatcomputerandprovidesalistofusersthathaveloggedontoit.Youcanthen selectoneoftheusersoropttoskipRSoPanalysisforuserconfigurationpolicies. ThewizardproducesadetailedRSoPreportinadynamicHTMLformat.IfInternet ExplorerEnhancedSecurityConfigurationisset,youwillbepromptedtoallowthe consoletodisplaythedynamiccontent.Youcanexpandorcollapseeachsectionof thereportbyclickingtheShoworHidelink,orbydoubleclickingtheheadingofthe section. Thereportisdisplayedonthreetabs: Summary.TheSummarytabdisplaysthestatusofGroupPolicyprocessingat thelastrefresh.Youcanidentifyinformationthatwascollectedaboutthesystem, theGPOsthatwereappliedanddenied,securitygroupmembershipthatmight haveaffectedGPOsfilteredwithsecuritygroups,WMIfiltersthatwereanalyzed, andthestatusofCSEs. Settings.TheSettingstabdisplaystheresultantsetofpolicysettingsappliedto thecomputeroruser.Thistabshowsyouexactlywhathashappenedtotheuser throughtheeffectsofyourGroupPolicyimplementation.Atremendousamountof informationcanbegleanedfromtheSettingstab,butsomedataisntreported,
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 113/135
07/06/13
07/06/13
includedinlaterversionsofWindows. WhenyouruntheGPResultcommand,youarelikelytousethefollowingoptions.
/ s c o m p u t e r n a m e
/ s c o p e[ u s e r|c o m p u t e r ]
ThisdisplaysRSoPanalysisforuserorcomputersettings.Ifyouomitthe/scope option,RSoPanalysisincludesbothuserandcomputersettings.
/ u s e r u s e r n a m e
ThisspecifiesthenameoftheuserforwhichRSoPdataistobedisplayed.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
115/135
07/06/13
/ r
ThisoptiondisplaysasummaryofRSoPdata.
/ v
ThisoptiondisplaysverboseRSoPdata,whichpresentsthemostmeaningful information.
/ z
/ u d o m a i n \ u s e r / p p a s s w o r d
ThisprovidescredentialsthatareintheAdministratorsgroupofaremotesystem.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 116/135
07/06/13
Withoutthesecredentials,GPResultrunsbyusingthecredentialswithwhichyouare loggedon.
[ / x|/ h ]f i l e n a m e
ThisoptionsavesthereportsintheXMLorHTMLformat.Theseoptionsareavailable inWindowsVistaSP1andlater,WindowsServer2008andlater,andWindows7.
Troubleshoot Group Policy with the Group Policy Results Wizard and GPResult.exe
Asanadministrator,youwilllikelyencounterscenariosthatrequireGroupPolicy troubleshooting.Youmightneedtodiagnoseandsolveproblems,includingthe following: GPOsarenotbeingappliedatall. Theresultantsetofpoliciesforacomputeroruserisnotwhatwasexpected.
07/06/13
incorrectlyorpolicyprocessingerrorsthatpreventedtheapplicationofGPOsettings.
07/06/13
theRSoPoftheuserorcomputer.TheGroupPolicyResultsWizardcanperformRSoP analysisonlyonwhathasactuallyhappened.Topredictthefutureandtoperform whatifanalyses,youcanusetheGroupPolicyModelingWizard. ToperformGroupPolicyModeling,rightclicktheGroupPolicyModelingnodeinthe GPMCconsoletree,clickGroupPolicyModelingWizard,andthenperformthestepsin thewizard. Modelingisperformedbyconductingasimulationonadomaincontroller,soyouare firstaskedtoselectadomaincontrollerthatisrunningWindowsServer2003orlater. Youdonotneedtobeloggedonlocallytothedomaincontroller,butthemodeling requestwillbeperformedonthedomaincontroller.Youarethenaskedtospecifythe settingsforthesimulation. Selectauserorcomputerobjecttoevaluate,orspecifytheOU,site,ordomainto evaluate. Choosewhetherslowlinkprocessingshouldbesimulated. Specifytosimulateloopbackprocessingand,ifso,chooseReplaceorMergemode. Selectasitetosimulate. Selectsecuritygroupsfortheuserandforthecomputer. ChoosewhichWMIfilterstoapplyinthesimulationofuserandcomputerpolicy
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 119/135
07/06/13
processing.
WindowsVista,WindowsServer2008,andWindows7improveyourabilityto
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 120/135
07/06/13
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
121/135
07/06/13
Lab Setup
Forthislab,youwillusetheavailablevirtualmachineenvironment.Beforeyoubegin thelab,youmustcompletethefollowingsteps: 1. Onthehostcomputer,clickStart,pointtoAdministrativeTools,andthen clickHyperVManager. 2. InHyperVManager,click6425CNYCDC1,andintheActionspane,click Start. 3. IntheActionspane,clickConnect.Waituntilthevirtualmachinestarts.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
122/135
07/06/13
4.
5.
Start6425CNYCCL1.LogontoNYCCL1asPat.Colemanwiththepasswordof Pa$$w0rd.
Lab Scenario
YouareresponsibleforadministeringandtroubleshootingtheGroupPolicy infrastructureatContoso,Ltd.Youwanttoevaluatetheresultantsetofpoliciesfor usersinyourenvironmenttoensurethattheGroupPolicyinfrastructureishealthy, andthatallpoliciesareappliedastheywereintended.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
123/135
07/06/13
1. 2. 3.
1.
OnNYCCL1,runthecommandpromptasanadministrator,withtheusername Pat.Coleman_AdminandthepasswordPa$$w0rd.
2.
3.
RestartNYCCL1andwaitforittorestartbeforeproceedingwiththenexttask.
1.
OnNYCDC1,runtheGroupPolicyManagementconsoleasanadministrator, withtheusernamePat.Coleman_AdminandthepasswordPa$$w0rd.
2.
UsetheGroupPolicyResultsWizardtorunanRSoPreportfor Pat.ColemanonNYCCL1.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
124/135
07/06/13
3.
4.
5.
ClickthePolicyEventstab,andlocatetheeventthatlogsthepolicyrefresh youtriggeredwiththeGPUpdatecommandinTask1.
6.
1. 2. 3.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
125/135
07/06/13
4.
5.
Typegpresult/zandpressEnter. ThemostdetailedRSoPreportisproduced.
6.
Typegpresult/h:"%userprofile%\Desktop\RSOP.html"andpressEnter. AnRSoPreportissavedasanHTMLfiletoyourdesktop.
7. 8.
Results:Inthisexercise,youlearnedhowtodoaresultantsetofpolicyintwo ways,usingawizardandfromthecommandline.
07/06/13
NoteThistaskrequiresgreaterlevelofdetailinthehighlevelsteps comparetoothertasksinthemodule..
1. 2.
3.
4.
ClickNext.
127/135
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
07/06/13
5. 6.
7. 8.
9.
TypeNYCCL1andthenpressEnter.
10. ClickNext. 11. OntheAdvancedSimulationOptionspage,selecttheLoopback Processingcheckbox,andthenclickMerge. EventhoughtheConferenceRoomPolicesGPOspecifiesloopback processing,youmustinstructtheGroupPolicyModelingWizardtoconsider loopbackprocessinginitssimulation. 12. ClickNext. 13. OntheAlternateActiveDirectoryPathspage,clicktheBrowsebuttonnext toComputerlocation.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 128/135
07/06/13
TheChooseComputerContainerdialogboxappears. 14. Expandcontoso.comandKiosks,andthenclickConferenceRooms. YouaresimulatingtheeffectofNYCCL1asaconferenceroomcomputer. 15. ClickOK. 16. ClickNext. 17. OntheUserSecurityGroupspage,clickNext. 18. OntheComputerSecurityGroupspage,clickNext. 19. OntheWMIFiltersforUserspage,clickNext. 20. OntheWMIFiltersforComputerspage,click.Next. 21. ReviewyoursettingsontheSummaryofSelectionspage,andthenclick Next. 22. ClickFinish. 23. OntheSummarytab,scrolltoandexpand,ifnecessary,UserConfiguration, GroupPolicyObjects,andAppliedGPOs. 24. CheckwhethertheConferenceRoomPoliciesGPOapplytoMikeDanseglio asaUserpolicywhenhelogsontoNYCCL1ifNYCCL1isintheConference RoomsOU.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
129/135
07/06/13
Ifnot,checkthescopeoftheConferenceRoomPoliciesGPO.Itshouldbe linkedtotheConferenceRoomsOUwithsecuritygroupfilteringthatapplies theGPOtotheAuthenticatedUsersspecialidentity.Youcanrightclickthe modelingquerytorerunthequery.IftheGPOisstillnotapplying,trydeleting andrebuildingtheGroupPolicyModelingreport,andbeverycarefulto followeachstepprecisely. 25. ClicktheSettingstab. 26. Scrollto,andexpandifnecessary,UserConfiguration,Policies, AdministrativeTemplatesandControlPanel/Personalization. 27. Confirmthatthescreensavertimeoutis2,700seconds(45minutes),thesetting configuredbytheConferenceRoomPoliciesGPOthatoverridesthe10 minutestandardconfiguredbytheCONTOSOStandardsGPO.
07/06/13
1.
OnNYCCL1,whereyouareloggedonasPat.Coleman_Admin,runEvent Viewerasanadministrator.
2. 3.
LocateandreviewGroupPolicyeventsintheSystemlog. LocateandreviewGroupPolicyeventsintheApplicationlog.
NoteDependingonhowlongthevirtualmachinehasbeenrunning,you maynothaveanyGroupPolicyEventsintheapplicationlog.
07/06/13
Results:Inthisexercise,youidentifiedGroupPolicyeventsintheeventlogs.
Whenyoufinishthelab,revertthevirtualmachinestotheirinitialstate.Todothis, completethefollowingsteps:
1. 2.
3. 4.
IntheRevertVirtualMachinedialogbox,clickRevert. Repeatthesestepsfor6425CNYCCL1.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
132/135
07/06/13
Question:HaveyoueverdiagnosedaGroupPolicyapplicationproblembased oneventsinoneoftheeventlogs?
Review Questions
1. YouhaveassignedalogonscripttoanOUviaGroupPolicy.Thescriptislocated inasharednetworkfoldernamedScripts.SomeusersintheOUreceivethe script,whereasothersdonot.Whatmightbethepossiblecauses?
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe 133/135
07/06/13
2. 3.
Troubleshootingtip
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
134/135
07/06/13
Tools
Tool
Grouppolicyreporting RSoP
Usefor
Reportinginformationabout thecurrentpoliciesbeing deliveredtoclients.
Wheretofindit
GroupPolicyManagementConsole
GPResult
Acommandlineutilitythat displaysRSoPinformation.
Commandlineutility
GPUpdate
RefreshinglocalandADDS basedGroupPolicysettings.
Commandlineutility
Dcgpofix
Commandlineutility
GPOLogView
Commandlineutility
GroupPolicy Managementscripts
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=8&FontSize=3&FontType=segoe
135/135