Hightower Posted June 21, 2011 Posted June 21, 2011 Our GPO structure looks like this, and it works well - all the software gets allocated to every machine in the ou just like you would expect. However, what would be the best way to allocate the likes of SIMS.net? If I add SOFTWARE SIMS.net to Art then every PC in art will get SIMS, whereas I just want it to be allocated to the teaching machines. Likewise with SmartBoard software. Any ideas?
Hightower Posted June 21, 2011 Author Posted June 21, 2011 One idea I had was to allocate SIMS.net & SmartBoard software at site level, but change the delegation from Authenticated Users to Teaching Computers, and then add all the teaching computers to the Teaching Computers group. I know this should work, but is that best practice or is there another way that is more highly thought of?
box_l Posted June 21, 2011 Posted June 21, 2011 (edited) Make a Sub OU for the teachers pc? Edited June 21, 2011 by box_l
cromertech Posted June 21, 2011 Posted June 21, 2011 Make a Sub OU fot the teachers pc? This is the way I have done it I have a teaching pc's ou and departmental ou's under that. When I need to put software only to a certain department just create the gpo in the corresponding ou
Guest Guest Posted June 21, 2011 Posted June 21, 2011 The 2 options are Sub-OU for teachers in each room/OU. Or using security groups and applying them to the GPO. Obviously both methods require you to add the computer to the correct OU/group on creation. Otherwise a script which reads the computer name...
jamesb Posted June 21, 2011 Posted June 21, 2011 Create a group called SIMS PCs, an appropriate group policy and put security filtering on the policy so it only applies to that particular group?
Hightower Posted June 21, 2011 Author Posted June 21, 2011 Gone with the security group method and seems to work well. Make the computer a member of the group and it allocates, take it out and it deallocates - just what I need EDIT: Also, by using this method I just need to link the GPO once at site level, whereas with OU's within OU's it would require a bit more work I feel.
jamesb Posted June 21, 2011 Posted June 21, 2011 EDIT: Also, by using this method I just need to link the GPO once at site level, whereas with OU's within OU's it would require a bit more work I feel. We used to do this for all GPOs. OUs were purely for organisational structure, and GPOs were filtered by group membership. Group names similar to the GPO name, and Bob's your uncle. Easy to tell at a glance what's going on without having to trawl through hunting down links.
Guest Guest Posted June 21, 2011 Posted June 21, 2011 Gone with the security group method and seems to work well. Make the computer a member of the group and it allocates, take it out and it deallocates - just what I need EDIT: Also, by using this method I just need to link the GPO once at site level, whereas with OU's within OU's it would require a bit more work I feel. Yep, plus it means any teacher specific software can be deployed this way, be it at top level or even if you want to apply IT teachers software only to the IT teachers computers/OU.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now