Jump to content

Recommended Posts

Posted

Hi All

 

I'm going to be rebuilding my network over the holidays, this is the first time I've done this with out being under an overlord. I just wanted to ask if there was a list of GPO's that everyone should have on their network, I've got a pretty good idea of most of the things I'll need to do, so I'm thinking something a little bit more obscure, something might be over looked.

 

I've already got in mind currently -

 

password policy

folder redirection for start menu, desktop, home area and profile

set preferences for printers and shared drives

block control panel / settings

block command prompt

block software installation

hide system drive

Disable right click and external media

SSO for One drive / sharepoint

 

I'm sure I'm missing quite a lot though.

Posted
I wouldn't block right clicking or the command prompt. Students wouldn't be able to do anything via those routes that they wouldn't otherwise - if things are locked down (i.e. NTFS permissions, FSRM policies, etc.) properly then there's no need.
  • Thanks 1
Posted
True, command prompt I'd just want to take the temptation to fiddle away completely, they don't need to access it. Right click I was erring on the side of caution, but on the other hand it is also useful.
Posted
True, command prompt I'd just want to take the temptation to fiddle away completely, they don't need to access it. Right click I was erring on the side of caution, but on the other hand it is also useful.

Indeed - there's also the concern that we should be teaching students how to use IT properly rather than simply locking everything up.

 

Regarding command prompt, I take your point that they typically won't need it - however be aware that if you're a secondary they may need it for Computing classes (obviously that'll depend on your curriculum).

Posted
Good shout, yes, that was a bit of a pain to setup last time, I think I'd blanked it from my memory! I used software restriction policies last time, but with that and FSRM we should make it pretty tight!
Posted
They way I think about it, is there something you do on each and every PC that needs to be done en mass, certain settings that have to be changed then it needs to be in a policy and applied that way rather than been done manually.
  • Thanks 1
Posted

A good naming policy for your GPO's!

 

We prefix.

 

C-* policies applied at that the Computer Level

U-* policies applied at the User level

SD-* polices that install software

  • Thanks 3
Posted
Yes I've done something similar to you Fishcustard, with settings:, Software:, Config: etc etc then normally initials and date it was last updated
Posted
That's a good idea - we have prefixes for various things (e.g. "Software: BlahProduct XP 2000", "Branding: College", "Config: XYZ bug workaround").

 

Similar here, too. I'd say that's particularly useful for someone building stuff up from scratch. A lot of the time that helps you to 'read' things in GPMC just from the AD structure and names of linked GPOs, without needing to actually open up and inspect any policies.

  • Thanks 1
Posted
We used to have a baseline user and baseline computer policies then say staff user and office user type thing. Tried to keep policies as few as possible as the more you have I was told the more issues it could cause.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...