mdrabble Posted January 3, 2015 Posted January 3, 2015 Looking at redoing the network from scratch and wondered how people setup up their GPO settings. I'm thinking of the following Main GPOs containing multiple settings ------------------------------------------- All User GPO (Global Settings for all users) All Computers GPO (Global computer settings) Staff GPO Student GPO Followed by Individual GPOs containing single settings ----------------------------------------------- Admin Drives (for admin staff) Software Deployment Etc, Etc...... Any advice/warnings/pit falls to avoid are welcomed
mattpant Posted January 3, 2015 Posted January 3, 2015 I'd be interested to see what others are doing - I'm planning on starting from scratch with Windows 8.1 machines + Server 2012 R2 If anybody is willing to share there GPO Reports Exports for Staff/Students/Computers etc it be very much appreciated! Thanks
DarrenM Posted January 3, 2015 Posted January 3, 2015 One thing to consider is separating groups of settings you may want to disable for different users or computers. I once needed to remove restrictions from a set of users but because these were in the same gpo as essential settings I had to split everything up. I now have a gpo for settings and one for restrictions.
Firefox Posted January 5, 2015 Posted January 5, 2015 Sounds very much like our approach. We have a general Windows 7 computer policy and a general Windows 7 user policy that applies to everyone. We then also break out separate applications...eg we have a general Windows 7 office policy both computer and user part (making settings only user part when it can be either) On top of this we then apply specific policies to groups of computers\users as it becomes necessary. We have started using GPP to group a lot of these options together rather then have lots of policies For example we have 2 different IE 9 requirements, but we have these in the same IE policy but then through GPP deployed to certain groups If configuring anything like terminal services for certain applications, we then create a separate policy for that application which has both computer and user part enabled with loopback policy processing turned on. This ensures that a user gets a different feel when logging onto a server as opposed to all their normal user settings being downloaded (if that makes sense)
gshaw Posted January 7, 2015 Posted January 7, 2015 Very similar to the above, we've just done a fresh AD as well. I've built what I call "Base" settings for computers and users then layered on the specific settings a level below e.g. Staff, Students and so on. Loopback is something I try to avoid if I can help it but has been required for some specific areas where we need to override power management, screensavers and so on.
mdrabble Posted January 7, 2015 Author Posted January 7, 2015 Happy to see others do it in a way I am currently planning.... make me all warm and fuzzy inside
Oaktech Posted January 7, 2015 Posted January 7, 2015 I think this is how it goes down with us now... default domain policy with very little in it - basically just password requirements. computer policy, office (has wsus and power settings in) computer policy, staff (has wsus and power settings in) computer policy, staff laptop (has wsus and power settings in) computer policy, student desktop (has wsus and power settings in) computer policy, student laptop (has wsus and power settings in) computer policy, servers (has wsus and power settings in) computer policy, software install, staff computer policy, software install, students computer policy, direct access client settings computer policy, direct access server settings computer policy, windows 8.1 start screen layout (linked to WMI filter) computer policy, RM certificate install user policy, user environment staff (has gui restrictions, folder redirects and proxy details in) user policy, user environment students (has gui restrictions, folder redirects and proxy details in) user policy, start menu, staff user policy, start menu, students user policy, software restriction policies, staff user policy, software restrictions policies, students user policy, printer settings staff user policy, printer settings students user policy, application settings staff (contains office and chrome info plus random reg hacks for software) user policy, application settings students (contains office and chrome info plus random reg hacks for software) and a couple of random test policies
TechMonkey Posted January 7, 2015 Posted January 7, 2015 Effectively the same as everyone else. Default Domain Policy Device Default Staff Devices Student Devices Staff Shortcuts Student Shortcuts User Defaults Student Yx (per year settings for redirected folders) Staff Teaching Support & then some random ones, so one area of the school may have specific requirements so the GPO is created and security filtered to that group.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now