Jump to content

Recommended Posts

Posted

I'm starting down the road of Windows 8 and doing some testing etc.

 

Servers are still 2008R2.

 

Our Default Domain Policy has a WMI filter set for windows 7 we only have windows 7 PC's on our domain now, the last XP machines went off-site a few months back and with them the Default Domain Policy that had a WMI filter set for XP.

 

I'm wondering if it is actually necessary to have split Default Domain Policies?

 

Would appreciate someone taking a look at our current default policy in case there is anything amiss?

 

Cheers.DefaultDomainPol.pdf

Posted
This don't look like the Default Domain Pol more a copy I hope, and my heart did stop when I read the title Default Domain Policy! Never touch the Default Domain Policy if you need to Policy add new (Microsoft do have a tool to recreate the Default Domain Policy). Also WMI filtering on polices is prone to being a tad slow, I would disband that and organize your Directory so that you an apply settings to win 8 and win 7 workstations that way.
Posted
This don't look like the Default Domain Pol more a copy I hope, and my heart did stop when I read the title Default Domain Policy! Never touch the Default Domain Policy if you need to Policy add new (Microsoft do have a tool to recreate the Default Domain Policy). Also WMI filtering on polices is prone to being a tad slow, I would disband that and organize your Directory so that you an apply settings to win 8 and win 7 workstations that way.

 

Thanks for your reply.

 

I can probably remove the WMI filtering on the policies that apply to the workstations, but I'm wondering wont I need to retain WMI filtering for policies applying at the user level if I have a mixture of Windows 7 and Windows 8 PC's.

Posted
I believe good practice is just to put the password security settings in and nothing else. Create new GPO's for this.

 

i wouldnt go quite that far but there should be very little you change on default domain/domain controllers policy things like password policies depending on windows version need to be done in default domain policy iirc

Posted

Best practice is to leave the default domain and default domain controllers policies alone, both policies have special GUIDs that active directory knows to look for so if you break one you could be in trouble(depends what gets broken).

They can also be used as a fail safe if somethings goes wrong, as you could unlink your custom settings knowing the default settings should work.

 

Your current password polices settings in that policy will only affect local accounts on your windows 7 machines, you may not have noticed this if all your polices have the same settings configured i.e. Default Domain,XP,7,8

If your Forrest/Domain functionality level is at 2008 or higher you should be looking to use Active Directory Password Polices if you require different settings.

 

If i were you i would migrate all your custom settings to separate polices but link them at the same level if needed, I would consider linking some of your settings at lower levels if possible as setting them at the top of the domain isn't good practice either.

Then use the Microsoft tool to recreate the default domain policy so you know its in a good state

  • 2 weeks later...
Posted
I have edited the default domain policy numerous times and never had a problem :/

 

Is it really that bad to do?

 

i think it depends what you do to it but it is plausable that you could lock yourself out of the domain by badly editing the default domain policies but i wouldnt do much on them

Posted
I'm starting down the road of Windows 8 and doing some testing etc.

 

Servers are still 2008R2.

 

Our Default Domain Policy has a WMI filter set for windows 7 we only have windows 7 PC's on our domain now, the last XP machines went off-site a few months back and with them the Default Domain Policy that had a WMI filter set for XP.

 

I'm wondering if it is actually necessary to have split Default Domain Policies?

 

Would appreciate someone taking a look at our current default policy in case there is anything amiss?

 

Cheers.[ATTACH=CONFIG]24586[/ATTACH]

 

I'd advise you leave the Default Domain Policy 'as is' and create, then link a new GPO below the Default Domain Policy. Something like the WMI filter should be within its own GPO. It's easier to unlink a GPO creating problems, rather than having to tinker with the Default Domain Policy itself :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...