Jump to content

Recommended Posts

Posted
Hi, I've just joined a Special School that has 106 Group Policy Objects on their Server 2012 R2 system. I have not come across that many GPO's at other schools I have worked at. Is 106 a normal number of GPO's for a small (100 pupil) Special School ?
Posted

I don't think there's one true "normal number" of GPOs. It rather depends on what they're trying to do and the philosophy of the people implementing it.

 

If they're creating lots of "thin" GPOs with just one or two settings in each because they need flexibility to apply different combinations of settings to different situations that's quite ok.

 

If someone didn't realise that you could apply the same GPO at different places in the GPO tree and there are therefore lots of repeated settings that need to be changed in more than one place,then yeah that's a problem... but with how things are being done rather than the specific number of GPOs.

Posted

I have about 60 GPOs but only 5 to 7 get applied. Some legacy (for reference), some for the future and the current ones. I have separate GPOs for windows 7,8 and 10 machines and pupils. (each with their wmi filter) it adds up..

 

 

I can't remember the think on GPO schemas, a few fat ones or lots of thin ones.

  • Thanks 1
Posted

We have 224 (ish) GPOs. (1500 pupil secondary)

Mostly due to a combination of using "thin" policies, and having a bunch of legacy stuff that's there for reference.

Posted
Gold star to @chazzy2501 for being the first to admit to a number. I counted 80 "active" ones at this site with a few disabled but kept for reference (could probably get rid of most of them). Could probably shave a few off the total if I tried.
Posted

150 total in Group Policy Objects. A lot of legacy and unused stuff there though.

 

About 25-40 in use depending on the user and Computer OU.

 

Normally each 'thing' will get it's own GPO - so Roaming Profiles is one, Office 2013 default settings another, Power Settings separate (one each for Win 10 and Win 7 and Servers), separate ones for each WSUS targeting group (but global settings applied at a higher level to all machines) etc.

 

I've found that it can make finding each individual setting more difficult, especially on GPO's that were around before I started, but the actual troubleshooting during GPO creation is much easier. There doesn't seem to be much (or any, but I'm not tempting fate by saying it) duplication of each setting unless it's specifically overridden further down the OU tree.

 

ETA: Not a school. A <100 user business with a lot of legacy technology, and things that were upgraded over the years.

Posted

44 here......and they say that RM has a lot of crud?

 

Well we have 1200 accounts as a middle sized secondary....

 

All I can say is not bad RM......

Posted

Over 200! Quite a few are just MSI deployments (separate GPO for each app) or room-by-room settings for things like Veyon (we're still on WDS for deployment). Quite a bit of legacy stuff that's not applied and could go at some point. Like @Bedders we have separate GPOs for each 'thing' we're wanting to achieve, and some of that is Win7 or Win10 specific as well. With a half decent naming convention it's not a problem to manage what's where.

Since the vast majority are either computer or user settings, we disable whichever half of a GPO we're not using. Can't say we've ever noticed a problem doing things this way.

Posted

180 GPO's.

 

~50 are software deploying policies

 

~60 are user polices - mixture of Windows 7 and 10

 

~70 are computer/server policies - mixture of mainly 7 and 10 again.

Posted

We've about 80, across four secondaries.

 

We generally have some for standardised settings across the MAT (~20) which are applied everywhere (both user and computer), and then each school will have further "localised" GPOs applied for school specific setups. We don't deploy software via GPO.

Posted
I wouldn't be too worried about the number of them.Just try to ensure that they are as thin as possible and that they are applied as close to the objects that you wish to apply them to.
  • Thanks 1
Posted (edited)

350 here, mainly because we have one GPO per room (lots of rooms!) for Deployed Printers. Also got some LanSchool per-room GPOs that can be deleted now we've moved to Impero so that will reduce the number to under 200.

 

Generally it's about 5 GPOs that apply to any given machine; a Base plus some specific ones for WSUS (per site), BitLocker etc.

Similar for per-user, a Base policy plus some specific ones for Staff \ Students, Folder Redirection and so on.

 

As per above making sure it's lean and mean is better than just number of objects.

Edited by gshaw
Posted
We're running about 114 GPOs here (some of which are legacy and kept for reference) for about 7500 users. To be honest, we probably need to do some tidying up here as I don't think they're as efficient as they could be - which is a comment about some of the legacy stuff we're still using, not about the number we have. But priorities being what they are, that's a problem for tomorrow (or more likely 2019) Roberto.
Posted

Around 100 here with a number of unlinked ones. I prefer to split our policy's into manageable chunks - I find it much easier to troubleshoot when something goes wrong. There is some consolidation that could be done on our existing ones though.

 

We also have a naming structure to help identify what type of policies are applied, for example :-

 

Computer Policies -

© Classic Shell

© Delprof2

© File Associations

© Firewall

 

User policies

(U) IE - Students

(U) IE - Staff

(U) Library Redirection

(U) Microsoft office 16

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...