ImplementingGroupPolicyOverviewIntroductiontoGroupPolicyGroupPolicyStructureWorkingwithGroupPolicyObjectsHowGroupPolicySettingsAreAppliedinActiveDirectoryModifyingGroupPolicyInheritanceDelegatingAdministrativeControlofGroupPolicyMonitoringandTroubleshootingGroupPolicyBestPracticesIntroductiontoGroupPolicyGroupPolicyEnablesYouto:SetcentralizedanddecentralizedpoliciesEnsureusershavetheirrequiredenvironmentsLowertotalcostofownershipbycontrollinguserandcomputerenvironmentsEnforcecorporatepoliciesSiteDomainOUWindows2000AppliesContinuallyUsersComputersAdministratorSetsGroupPolicyOnceGroupPolicyGroupPolicyStructureTypesofGroupPolicySettingsGroupPolicyObjectsGroupPolicySettingsforComputersandUsersGroupPolicyObjectsandActiveDirectoryContainersTypesofGroupPolicySettingsTypesofGroupPolicySettingsAdministrativeTemplatesRegistry-basedGroupPolicysettingsSecuritySettingsforlocal,domain,andnetworksecuritySoftwareInstallationSettingsforcentralmanagementofsoftwareinstallationScriptsStartup,shutdown,logon,andlogoffscriptsRemoteInstallationServicesSettingsthatcontroltheoptionsavailabletouserswhenrunningtheClientInstallationwizardusedbyRISInternetExplorerMaintenanceSettingstoadministerandcustomizeMicrosoftInternetExploreronWindows2000–basedcomputersFolderRedirectionSettingsforstoringofusers’foldersonanetworkserverGroupPolicyObjectsGroupPolicyObjectContainsGroupPolicysettingsContentstoredintwolocationsLocatedindomaincontrollersharedSysvolfolderProvidesGroupPolicysettingsthatcomputersrunningWindows2000obtainandapplyLocatedinActiveDirectoryProvidesversioninformationusedbydomaincontrollersGroupPolicyTemplate(GPT)GroupPolicyContainer(GPC)GroupPolicySettingsforComputersandUsersGroupPolicySettingsforComputers:Specifyoperatingsystembehavior,desktopbehavior,securitysettings,computerstartupandshutdownscripts,computer-assignedapplicationoptions,andapplicationsettingsApplywhentheoperatingsysteminitializesandduringtheperiodicrefreshcycleGroupPolicySettingsforUsers:Specifyoperatingsystembehavior,desktopsettings,securitysettings,assignedandpublishedapplicationoptions,applicationsettings,folderredirectionoptions,anduserlogonandlogoffscriptsApplywhenuserslogontothecomputerandduringtheperiodicrefreshcycleUsersComputersGroupPolicyObjectsandActiveDirectoryContainersGPOSettingsAffectUserandComputerObjectsWithinSites,Domains,andOUstoWhichaGPOIsLinkedYoucanlinkoneGPOtomultiplesites,domains,orOUsYoucanlinkmultipleGPOstoonesite,domain,orOUYouCannotLinkGPOstoDefaultActiveDirectoryContainersSiteDomainOUOUOUOUGPOOUGPOSiteGPODomainGPOWorkingwithGroupPolicyObjectsCreatingLinkedGroupPolicyObjectsCreatingUnlinkedGroupPolicyObjectsLinkinganExistingGroupPolicyObjectSpecifyingaDomainControllerforManagingGroupPolicyObjectsCreatingLinkedGroupPolicyObjectsToApplyGroupPolicytoaContainer,CreateaGPOLinkedtotheContainer:CreateGPOslinkedtodomainsandOUsbyusingActiveDirectoryUsersandComputersCreateGPOslinkedtositesbyusingActiveDirectorySitesandServicescontoso.msftPropertiesGeneralManagedByObjectSecurityGroupPolicyCurrentGroupPolicyObjectLinksforcontoso.msftGroupPolicyObjectLinksNoOverrideDisabledDefaultDomainPolicyAccountLockoutPolicyPasswordsPolicyGroupPolicyObjectshigherinthelisthavethehighestpriority.Thislistobtainedfrom:London.contoso.msftNewOptions...Add...Delete...EditPropertiesUpDownBlockPolicyinheritanceCloseCancelApplyTocreateaGPONameoflinkedGPOCreatingUnlinkedGroupPolicyObjectsSelectGroupPolicyObjectLocalComputerBrowse…AllowthefocusoftheGroupPolicySnap-intobechangedwhenlaunchingfromthecommandline.Thisonlyappliesifyousavetheconsole.ViewArrangeIconsLineupIconsRefreshNewTocreateanunlinkedGPOBrowseforaGroupPolicyObjectDomains/OUsSitesComputersAllLookin:contoso.msftAllGroupPolicyObjectsstoredinthisdomain:NameApplicationDeploymentDefaultDomainControllersPolicyDefaultDomainPolicyNewGroupPolicyObjectNewGroupPolicyObjectNewGroupPolicyObjectNewGroupPolicyObjectTestLinkinganExistingGroupPolicyObjectcontoso.msftPropertiesGeneralManagedByObjectSecurityGroupPolicyCurrentGroupPolicyObjectLinksforcontoso.msftGroupPolicyObjectLinksNoOverrideDisabledDefaultDomainPolicyAccountLockoutPolicyPasswordsPolicyGroupPolicyObjectshigherinthelisthavethehighestpriority.Thislistobtainedfrom:London.contoso.msftNewOptions...Add...Delete...EditPropertiesUpDownTolinkanexistingGPOAddaGroupPolicyObjectLinkDomains/OUsSitesAllLookin:GroupPolicyObjectslinkedtothiscontainer:NameDomainDomainControllers.nwtraders.msftAccounting.nwtraders.msftHumanResources.nwtraders.msftDefaultDomainPolicyRedirectMyDocumentPolicyLogonAttemptsPolicyPasswordsPolicyStartMenuPolicyOKCancelcontoso.msftSelectcontainerinwhichGPOresidesSelectGPOtolinkSelectappropriatetabSpecifyingaDomainControllerforManagingGroupPolicyObjectsWhenYouCreateaNewGPOorEditanExistingGPO,byDefault,theDomainControllerThatHoldsthePDCEmulatorRolePerformstheOperationTheOptionsAvailabletoSpecifyaDomainControllerforManagingGPOsInclude:TheonewiththeOperationsMastertokenforthePDCemulatorTheoneusedbytheActiveDirectory