Jump to content

Recommended Posts

Posted

Looking at redoing the network from scratch and wondered how people setup up their GPO settings.

 

I'm thinking of the following

 

Main GPOs containing multiple settings

-------------------------------------------

All User GPO (Global Settings for all users)

All Computers GPO (Global computer settings)

Staff GPO

Student GPO

 

Followed by

 

Individual GPOs containing single settings

-----------------------------------------------

Admin Drives (for admin staff)

Software Deployment

Etc, Etc......

 

 

Any advice/warnings/pit falls to avoid are welcomed

Posted

I'd be interested to see what others are doing - I'm planning on starting from scratch with Windows 8.1 machines + Server 2012 R2

 

If anybody is willing to share there GPO Reports Exports for Staff/Students/Computers etc it be very much appreciated!

 

Thanks

Posted

One thing to consider is separating groups of settings you may want to disable for different users or computers.

 

I once needed to remove restrictions from a set of users but because these were in the same gpo as essential settings I had to split everything up. I now have a gpo for settings and one for restrictions.

Posted

Sounds very much like our approach.

 

We have a general Windows 7 computer policy and a general Windows 7 user policy that applies to everyone.

We then also break out separate applications...eg we have a general Windows 7 office policy both computer and user part (making settings only user part when it can be either)

 

On top of this we then apply specific policies to groups of computers\users as it becomes necessary.

 

We have started using GPP to group a lot of these options together rather then have lots of policies

 

For example we have 2 different IE 9 requirements, but we have these in the same IE policy but then through GPP deployed to certain groups

 

If configuring anything like terminal services for certain applications, we then create a separate policy for that application which has both computer and user part enabled with loopback policy processing turned on. This ensures that a user gets a different feel when logging onto a server as opposed to all their normal user settings being downloaded (if that makes sense)

Posted

Very similar to the above, we've just done a fresh AD as well. I've built what I call "Base" settings for computers and users then layered on the specific settings a level below e.g. Staff, Students and so on.

 

Loopback is something I try to avoid if I can help it but has been required for some specific areas where we need to override power management, screensavers and so on.

Posted

I think this is how it goes down with us now...

 

default domain policy with very little in it - basically just password requirements.

computer policy, office (has wsus and power settings in)

computer policy, staff (has wsus and power settings in)

computer policy, staff laptop (has wsus and power settings in)

computer policy, student desktop (has wsus and power settings in)

computer policy, student laptop (has wsus and power settings in)

computer policy, servers (has wsus and power settings in)

computer policy, software install, staff

computer policy, software install, students

computer policy, direct access client settings

computer policy, direct access server settings

computer policy, windows 8.1 start screen layout (linked to WMI filter)

computer policy, RM certificate install

user policy, user environment staff (has gui restrictions, folder redirects and proxy details in)

user policy, user environment students (has gui restrictions, folder redirects and proxy details in)

user policy, start menu, staff

user policy, start menu, students

user policy, software restriction policies, staff

user policy, software restrictions policies, students

user policy, printer settings staff

user policy, printer settings students

user policy, application settings staff (contains office and chrome info plus random reg hacks for software)

user policy, application settings students (contains office and chrome info plus random reg hacks for software)

 

and a couple of random test policies

Posted

Effectively the same as everyone else.

 

Default Domain Policy

 

Device Default

Staff Devices

Student Devices

Staff Shortcuts

Student Shortcuts

 

User Defaults

Student

Yx (per year settings for redirected folders)

Staff

Teaching

Support

 

& then some random ones, so one area of the school may have specific requirements so the GPO is created and security filtered to that group.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...