AJB123 Posted November 1, 2018 Posted November 1, 2018 Hi, I've just joined a Special School that has 106 Group Policy Objects on their Server 2012 R2 system. I have not come across that many GPO's at other schools I have worked at. Is 106 a normal number of GPO's for a small (100 pupil) Special School ?
Roberto Posted November 1, 2018 Posted November 1, 2018 I don't think there's one true "normal number" of GPOs. It rather depends on what they're trying to do and the philosophy of the people implementing it. If they're creating lots of "thin" GPOs with just one or two settings in each because they need flexibility to apply different combinations of settings to different situations that's quite ok. If someone didn't realise that you could apply the same GPO at different places in the GPO tree and there are therefore lots of repeated settings that need to be changed in more than one place,then yeah that's a problem... but with how things are being done rather than the specific number of GPOs.
chazzy2501 Posted November 1, 2018 Posted November 1, 2018 I have about 60 GPOs but only 5 to 7 get applied. Some legacy (for reference), some for the future and the current ones. I have separate GPOs for windows 7,8 and 10 machines and pupils. (each with their wmi filter) it adds up.. I can't remember the think on GPO schemas, a few fat ones or lots of thin ones. 1
Rob_D Posted November 1, 2018 Posted November 1, 2018 We have 224 (ish) GPOs. (1500 pupil secondary) Mostly due to a combination of using "thin" policies, and having a bunch of legacy stuff that's there for reference.
LeMarchand Posted November 1, 2018 Posted November 1, 2018 Gold star to @chazzy2501 for being the first to admit to a number. I counted 80 "active" ones at this site with a few disabled but kept for reference (could probably get rid of most of them). Could probably shave a few off the total if I tried.
Bedders Posted November 1, 2018 Posted November 1, 2018 150 total in Group Policy Objects. A lot of legacy and unused stuff there though. About 25-40 in use depending on the user and Computer OU. Normally each 'thing' will get it's own GPO - so Roaming Profiles is one, Office 2013 default settings another, Power Settings separate (one each for Win 10 and Win 7 and Servers), separate ones for each WSUS targeting group (but global settings applied at a higher level to all machines) etc. I've found that it can make finding each individual setting more difficult, especially on GPO's that were around before I started, but the actual troubleshooting during GPO creation is much easier. There doesn't seem to be much (or any, but I'm not tempting fate by saying it) duplication of each setting unless it's specifically overridden further down the OU tree. ETA: Not a school. A <100 user business with a lot of legacy technology, and things that were upgraded over the years.
bossman Posted November 1, 2018 Posted November 1, 2018 44 here......and they say that RM has a lot of crud? Well we have 1200 accounts as a middle sized secondary.... All I can say is not bad RM......
jthompson Posted November 1, 2018 Posted November 1, 2018 Over 200! Quite a few are just MSI deployments (separate GPO for each app) or room-by-room settings for things like Veyon (we're still on WDS for deployment). Quite a bit of legacy stuff that's not applied and could go at some point. Like @Bedders we have separate GPOs for each 'thing' we're wanting to achieve, and some of that is Win7 or Win10 specific as well. With a half decent naming convention it's not a problem to manage what's where. Since the vast majority are either computer or user settings, we disable whichever half of a GPO we're not using. Can't say we've ever noticed a problem doing things this way.
itwasntme Posted November 1, 2018 Posted November 1, 2018 @AJB123 safe to say we're all different and 106 gpos not obscene/unheard of. 17 GPOs for about 1000 pupils - could easily reduce in quantity but even easier to increase
kennysarmy Posted November 1, 2018 Posted November 1, 2018 180 GPO's. ~50 are software deploying policies ~60 are user polices - mixture of Windows 7 and 10 ~70 are computer/server policies - mixture of mainly 7 and 10 again.
Jonah Posted November 1, 2018 Posted November 1, 2018 We've about 80, across four secondaries. We generally have some for standardised settings across the MAT (~20) which are applied everywhere (both user and computer), and then each school will have further "localised" GPOs applied for school specific setups. We don't deploy software via GPO.
Bob_the_Goon Posted November 3, 2018 Posted November 3, 2018 I wouldn't be too worried about the number of them.Just try to ensure that they are as thin as possible and that they are applied as close to the objects that you wish to apply them to. 1
gshaw Posted November 5, 2018 Posted November 5, 2018 (edited) 350 here, mainly because we have one GPO per room (lots of rooms!) for Deployed Printers. Also got some LanSchool per-room GPOs that can be deleted now we've moved to Impero so that will reduce the number to under 200. Generally it's about 5 GPOs that apply to any given machine; a Base plus some specific ones for WSUS (per site), BitLocker etc. Similar for per-user, a Base policy plus some specific ones for Staff \ Students, Folder Redirection and so on. As per above making sure it's lean and mean is better than just number of objects. Edited November 5, 2018 by gshaw
Roberto Posted November 8, 2018 Posted November 8, 2018 We're running about 114 GPOs here (some of which are legacy and kept for reference) for about 7500 users. To be honest, we probably need to do some tidying up here as I don't think they're as efficient as they could be - which is a comment about some of the legacy stuff we're still using, not about the number we have. But priorities being what they are, that's a problem for tomorrow (or more likely 2019) Roberto.
ataylor Posted November 9, 2018 Posted November 9, 2018 Around 100 here with a number of unlinked ones. I prefer to split our policy's into manageable chunks - I find it much easier to troubleshoot when something goes wrong. There is some consolidation that could be done on our existing ones though. We also have a naming structure to help identify what type of policies are applied, for example :- Computer Policies - © Classic Shell © Delprof2 © File Associations © Firewall User policies (U) IE - Students (U) IE - Staff (U) Library Redirection (U) Microsoft office 16
k-strider Posted November 9, 2018 Posted November 9, 2018 184 but their are probably loads that could go as they have been in place since windows xp and 2000
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now