Simon_Sion Posted July 5, 2019 Posted July 5, 2019 Hi All I'm going to be rebuilding my network over the holidays, this is the first time I've done this with out being under an overlord. I just wanted to ask if there was a list of GPO's that everyone should have on their network, I've got a pretty good idea of most of the things I'll need to do, so I'm thinking something a little bit more obscure, something might be over looked. I've already got in mind currently - password policy folder redirection for start menu, desktop, home area and profile set preferences for printers and shared drives block control panel / settings block command prompt block software installation hide system drive Disable right click and external media SSO for One drive / sharepoint I'm sure I'm missing quite a lot though.
FishCustard Posted July 5, 2019 Posted July 5, 2019 I wouldn't block right clicking or the command prompt. Students wouldn't be able to do anything via those routes that they wouldn't otherwise - if things are locked down (i.e. NTFS permissions, FSRM policies, etc.) properly then there's no need. 1
TriggerHappyUK Posted July 5, 2019 Posted July 5, 2019 I asked similar. Here's the link... Must Have GPO Settings 2
Simon_Sion Posted July 5, 2019 Author Posted July 5, 2019 True, command prompt I'd just want to take the temptation to fiddle away completely, they don't need to access it. Right click I was erring on the side of caution, but on the other hand it is also useful.
FishCustard Posted July 5, 2019 Posted July 5, 2019 True, command prompt I'd just want to take the temptation to fiddle away completely, they don't need to access it. Right click I was erring on the side of caution, but on the other hand it is also useful. Indeed - there's also the concern that we should be teaching students how to use IT properly rather than simply locking everything up. Regarding command prompt, I take your point that they typically won't need it - however be aware that if you're a secondary they may need it for Computing classes (obviously that'll depend on your curriculum).
MartinByard Posted July 5, 2019 Posted July 5, 2019 Look at implementing MS LAPS to control local admin account passwords ? 2
Simon_Sion Posted July 5, 2019 Author Posted July 5, 2019 Thanks, haven't seen that before, looks good!
jthompson Posted July 5, 2019 Posted July 5, 2019 AppLocker or SRP (as a whitelist). I'd say that's a must. 1
Simon_Sion Posted July 5, 2019 Author Posted July 5, 2019 Good shout, yes, that was a bit of a pain to setup last time, I think I'd blanked it from my memory! I used software restriction policies last time, but with that and FSRM we should make it pretty tight!
MatthewL Posted July 5, 2019 Posted July 5, 2019 They way I think about it, is there something you do on each and every PC that needs to be done en mass, certain settings that have to be changed then it needs to be in a policy and applied that way rather than been done manually. 1
Rob_D Posted July 5, 2019 Posted July 5, 2019 I'd suggest power-plan GPOs. Password protected screensaver is a must for data protection IMO. 1
Davit2005 Posted July 5, 2019 Posted July 5, 2019 MS Office ADMX settings is defo on the list for me. 1
Arthur Posted July 5, 2019 Posted July 5, 2019 Look at implementing MS LAPS to control local admin account passwords? +1. The LAPS Web App is also worth mentioning since it allows you to view the passwords from any device with a browser. 1
k-strider Posted July 5, 2019 Posted July 5, 2019 Right click usefull for Previous Versions tab when students delete their work....
kennysarmy Posted July 5, 2019 Posted July 5, 2019 A good naming policy for your GPO's! We prefix. C-* policies applied at that the Computer Level U-* policies applied at the User level SD-* polices that install software 3
FishCustard Posted July 5, 2019 Posted July 5, 2019 That's a good idea - we have prefixes for various things (e.g. "Software: BlahProduct XP 2000", "Branding: College", "Config: XYZ bug workaround").
Simon_Sion Posted July 5, 2019 Author Posted July 5, 2019 Yes I've done something similar to you Fishcustard, with settings:, Software:, Config: etc etc then normally initials and date it was last updated
jthompson Posted July 5, 2019 Posted July 5, 2019 That's a good idea - we have prefixes for various things (e.g. "Software: BlahProduct XP 2000", "Branding: College", "Config: XYZ bug workaround"). Similar here, too. I'd say that's particularly useful for someone building stuff up from scratch. A lot of the time that helps you to 'read' things in GPMC just from the AD structure and names of linked GPOs, without needing to actually open up and inspect any policies. 1
MatthewL Posted July 5, 2019 Posted July 5, 2019 We used to have a baseline user and baseline computer policies then say staff user and office user type thing. Tried to keep policies as few as possible as the more you have I was told the more issues it could cause.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now