msaario Posted November 23, 2014 Posted November 23, 2014 Hi, Just landed myself a new role as MOE\SOE engineer for a university for somewhere around 600 student machines across 3 sites, and working on building a new image for the student environment. There current image\setup uses Deep freeze, and once the student has finished using the machine, it reboots and restores itself. Not the best user experience hence why we want to create a new student image. They have just implemented Microsoft SCCM 2012 R2 which is a relief!, however we had a heated discussion the other day with the sysadmin/domain admin guy who flatly refused to use Domain GPO's - even though his moto and catch phrase is "KISS - Keep It Simple Stupid" and hates Best Practices. He said that we can use SCCM to deploy the reg key's with the values set in them instead of using GPO's. My plan was to put them into the 'Master' image but the SysPrep step strips out the all these settings, so I'm going to have to export all the individual Local GPO's to Local Policy files\pack (using Microsoft's Security Compliance Manager) and then restore them back when the Task sequence is run at image deployment time. Can anyone recommend any other way to do it?, or problems that I might face? I'm not looking forward to managing possibly hundreds of Local Policy files because of he's KISS principle. Thanks in advance.
blu4 Posted November 23, 2014 Posted November 23, 2014 Why did they do it the long winded way? What was the MAJOR reason for not using domain GPOs? They save so much time. Sorry for the lack of contribution-I am curious why he set it up this way.
3s-gtech Posted November 23, 2014 Posted November 23, 2014 Domain based Group Policy will give you the same settings but with greater flexibility and more control. There is no reason to use Local Policies - if he wants to keep it simple, that's the opposite of his mantra.
msaario Posted November 23, 2014 Author Posted November 23, 2014 Hey thanks for the replies, All he said was "NO", he didn't give reasons why. He seems to do this when he knows his idea is wrong and has no solid footings to stand on, but no one is willing to stand up to him. His manager wasn't impressed with his attitude in the meeting and is happy for us (me) to investigate. Having little experience with GPO's, hence why I'm gathering evidence to no reasons why he shouldn't implement Domain GPO's and not LGPO's.
synaesthesia Posted November 23, 2014 Posted November 23, 2014 Evidence is quite an easy one ; industry standards. Sounds like this guy is an imbecile who either doesn't have enough knowledge to warrant being in the job he has and is trying to cover his own backs. Domain group policy gives you easy, simple, central control over everything and I dare say is probably more secure.
sonofsanta Posted November 24, 2014 Posted November 24, 2014 Sounds like he a) doesn't know how to use domain GPOs b) only knows how to use reg keys, so he wants to force everyone down this route so he remains the expert and invaluable to the team, when everyone must approach him as a supplicant, begging for scraps of his great wisdom and knowledge, feeble before his intellectual might. I know nothing of the man and may well be wrong, but you do get types like that in IT. Domain GPO works through the registry, so mechanically it's doing the same thing, except it's much more intuitive, easier to troubleshoot, self-documenting and designed for the job. If you find an exploit that you need to close down immediately, make a GPO change and it will have rolled out in 90 minutes; his method requires every PC to reboot first. Has he got any MS certification? As GPO management is a major part of any MCSA/MCSE course.
sted Posted November 24, 2014 Posted November 24, 2014 if he really wants to use reg keys you could use gpp to deploy them not ideal but better than doing it on each pc
msaario Posted November 24, 2014 Author Posted November 24, 2014 Thanks for the reply. I think you hit the nail on the head, he remains the expert and the invaluable to the our team. There is him and his work buddy (whom belong to the same team) who seem to think they are invaluable, and we should do what they say no matter what because in the past all the other IT teams have bowed to them as they owned the keys to the kingdom and held the knowledge. I've (and my team) only joined the organization through a merger (take-over) and from what I understand he has been in that role for the past 15-20+ years as in most of the other IT guys in the team there, and I'm only guessing that he doesn't have any MS certs...
win Posted November 24, 2014 Posted November 24, 2014 I recommend and use GP, but if i try and think the way he does i can see the logic. GP's won't be all that effective with deep freeze, it might not pick up the policies when it starts so you need to put the policy into the actual computer. That way you 100% know it will work, as opposed to it may work if the client picks up the settings - not fun with 600 machines. I bet he used norton ghost back in the days and always used images rather than group policies.
Norphy Posted November 24, 2014 Posted November 24, 2014 One major advantage to using GPOs over registry files is that if somehow, someone does manage to change the key it's only a matter of waiting until the next group policy refresh before they get put back again. How exactly is he planning to push out registry scripts with ConfigMgr? DCM? Packages? Both would work but, frankly, if someone suggested changing from group policies to one of those, my response would be "Don't be so ****ing stupid".
synaesthesia Posted November 24, 2014 Posted November 24, 2014 The fact he's looking at SCCM when he clearly isn't too happy with GPO would scare the hell out of me; SCCM can break SO much if it's not done properly. Let's have a sweepstake run by @msaario on how long before he accidentally reimages every machine?
msaario Posted November 25, 2014 Author Posted November 25, 2014 I don't think he has a clear understanding of what SCCM does and doesn't do. @synaesthesia will keep you posted and you'll be on the my list of people to let know the moment it happens!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now