Jump to content

Recommended Posts

Posted

The AD at my new school is set up in a very flat structure with security filtering in the GPO to target specific AD groups. This means all my student PCs are in a single OU container, which has 30+ policies linked to it such as "Printers - Art", "Printers - Business", "Printers - English", with each policy targeting a corresponding AD group, e.g. "Desktops - Art", "Desktops - Business", "Desktops - English" and so forth. Users and user GPOs are set up in a similar way.

 

To put some numbers around this, a booting computer is checking over 70 computer GPOs of which around 30 are applied; the user logon checks nearly 40 GPOs of which around 10 are applied. Add to this, SCCM is deploying applications based on AD group membership, so an IT Suite PC is member of over 50 groups.

 

This seems cumbersome to manage and - please correct me if I'm wrong here - is dramatically slowing startup and logon times, as the PC enumerates each of these policies, checks its validity against its/the user's own group membership, applies/ignores the Policy, and then moves on.

 

Apparently, the AD had been set out hierarchically with OU-targetted GPOs until my predecessor started, when he changed everything because apparently group membership is the correct way to do things. Before I reinstate a hierarchical structure (as per every other domain I've ever worked with) is there any merit to what I've inherited?

Posted

I don’t know if GP was developed with a degree of flexibility in mind or not but that’s is what it provides. By that I mean I’ve always found people do it differently and to a great extent it all depends on your AD structure and also generally how your network is setup. I don’t think there is a single correct way to do things and that’s perhaps part of the power of group policy.

In context, I certainly wouldn’t do it like your predecessor has. Definitely not the ‘least administrative effort’ and doesn’t look like he leverages the flexibility of group policy at all - in most cases it’s a mix and match of group memberships & OU based policies.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...