nicholab Posted June 8, 2007 Posted June 8, 2007 To help people who what to set up a new vanilla network can we creat a list of Group Policey Objects that you need to make an eductioan network? Admins Could this Become a sticky?
rlculver Posted June 8, 2007 Posted June 8, 2007 Hi, I will be interested in this as well Any pre-defined GPO's would be great
andyrite Posted June 9, 2007 Posted June 9, 2007 I'd be very intrested as well. I'm in the process of removing ranger from the network.
john Posted June 10, 2007 Posted June 10, 2007 I would say over 50% of them are needed to make a good secure network.
srochford Posted June 10, 2007 Posted June 10, 2007 That might be a bit over the top - there are over 800 in system.adm alone! http://www.microsoft.com/downloads/details.aspx?FamilyID=7821C32F-DA15-438D-8E48-45915CD2BC14&displaylang=en lists all the settings so you can have a look at what's availble (really useful when you think it ought to be possible to do "X" but can't find it in the console! Sharing is always good but one of the things I've found over the years is that some of the things I think are absolutely essential to run a decent network others will look at and think "uuhhh??? - why??" and vice versa :-)
GrumbleDook Posted June 10, 2007 Posted June 10, 2007 You mean you don't have the perfect setup? Damn ... I've been following the wrong messiah!
ConTheITGuy Posted June 11, 2007 Posted June 11, 2007 Sounds ideal for the Wiki doesn;t it? (once it becomes unlocked!) Andy
starscream Posted June 11, 2007 Posted June 11, 2007 I have been wondering this for a long time and wouldn't need to buy Ranger if there was some place to get the GPOs. That's all I am buying ranger for really, to make like easier and so that no area is left open.
PiqueABoo Posted June 11, 2007 Posted June 11, 2007 Gosh, you can't move in here for people volunteering to actually make these things. Could have sworn I seen the anti-CC3 et al people say it's only a five minute job as well ;b I'm not volunteering either because I know it's big/hard, but if someone does have the energy to work on this then I'd aim to make pre-configured registry.pol files and obviously with any ADMs you might need (more or less self documenting once you get them in GPMC and turn off unconfigured settings).
ZeroHour Posted June 11, 2007 Posted June 11, 2007 sounds good but seems like it could lead to a "too many cooks" thread lol. My GPO rocks anyway so there
bossman Posted June 11, 2007 Posted June 11, 2007 PiqueABoo: careful "big/hard" ohh err missus you no what i mean hehe!
boomam Posted April 8, 2008 Posted April 8, 2008 I have a vanilla network here. Ive got the domain level GPO specifying things like login text. A gpo per user group for settings for those users. A gpo per computer room to allocate specific printers. GPOs over all the computers for specific software installs, one per software. And the same again for settings.
Michael Posted April 8, 2008 Posted April 8, 2008 It is a very good question, however because there are hundreds of policies I'm not going to go through each one. Initially though, you need to have Active Directory installed. In here you can create multiple OUs and this is where your user and computer objects live, but also, where you apply policies. Fortunately Microsoft have included descriptions of what each policy does. Myself like other Network Managers have gone through each one and familiarised ourselves with what each policy does and whether it's needed. In practice it can take years to fully appreciate how powerful policies are. Windows Server 2008 has even more for me to learn and discover! There is no easy way around this, but I think that with guidance you'll learn Active Directory properly over time if you take the time to learn about policies.
Jose Posted April 8, 2008 Posted April 8, 2008 We have a Windows 2003 network, 2 cc3 servers, we have created a vanilla OU structure that has blocked all the viruses and cc3 policies from getting through. This is the restricted user policy for students and some staff. restricted users settings Data collected on: 4/8/2008 11:50:47 AM General Details Domainwallington.internal OwnerWALLINGTON\Domain Admins Created12/27/2007 2:01:24 PM Modified3/14/2008 10:18:06 AM User Revisions122 (AD), 122 (sysvol) Computer Revisions3 (AD), 3 (sysvol) Unique ID{B0F74196-D34C-4DA9-8436-B233A9B020F8} GPO StatusEnabled Links LocationEnforcedLink StatusPath WHSGNoEnabledwallington.internal/WHSG This list only includes links in the domain of the GPO. Security Filtering The settings in this GPO can only apply to the following groups, users, and computers:Name NT AUTHORITY\Authenticated Users WMI Filtering WMI Filter NameNone DescriptionNot applicable Delegation These groups and users have the specified permission for this GPONameAllowed PermissionsInherited NT AUTHORITY\Authenticated UsersRead (from Security Filtering)No NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSReadNo NT AUTHORITY\SYSTEMEdit settings, delete, modify securityNo WALLINGTON\disCustomNo WALLINGTON\Domain AdminsCustomNo WALLINGTON\Enterprise AdminsEdit settings, delete, modify securityNo WALLINGTON\SAVECustomNo WALLINGTON\Staff {UT}CustomNo WALLINGTON\WHS Teaching StaffCustomNo Computer Configuration (Enabled) Administrative Templates System/Group Policy PolicySetting User Group Policy loopback processing modeEnabled Mode:Replace User Configuration (Enabled) Windows Settings Security Settings Software Restriction Policies Enforcement PolicySetting Apply software restriction policies toAll software files except libraries (such as DLLs) Apply software restriction policies to the following usersAll users Designated File Types File ExtensionFile Type ADEMicrosoft Office Access Project Extension ADPMicrosoft Office Access Project BASBAS File BATMS-DOS Batch File CHMCompiled HTML Help file CMDWindows NT Command Script COMMS-DOS Application CPLControl Panel extension CRTSecurity Certificate EXEApplication HLPHelp File HTAHTML Application INFSetup Information INSInternet Communication Settings ISPInternet Communication Settings LNKShortcut MDBMicrosoft Office Access Application MDEMicrosoft Office Access MDE Database MSCMicrosoft Common Console Document MSIWindows Installer Package MSPWindows Installer Patch MSTMST File OCXActiveX Control PCDPhotoCD Image PIFShortcut to MS-DOS Program REGRegistration Entries SCRScreen Saver SHSScrap object URLInternet Shortcut VBVB File WSCWindows Script Component Trusted Publishers Allow the following users to select trusted publishersEnd users Before trusting a publisher, check the following to determine if the certificate is revokedNone
Jose Posted April 8, 2008 Posted April 8, 2008 continued from above Software Restriction Policies/Security Levels PolicySetting Default Security LevelUnrestricted Software Restriction Policies/Additional Rules Hash Rules Entertainment Pack FreeCell Game; Microsoft® Windows® Operating System; Microsoft Corporation; freecell (5.1.2600.0) File hash4D9B5E540158BF8E9B1BCAC1AEDD8C60:55296:32771 Security levelDisallowed Description Date last modified3/14/2008 10:02:02 AM Entertainment Pack FreeCell Game; Microsoft® Windows® Operating System; Microsoft Corporation; freecell (5.1.2600.0) File hash4D9B5E540158BF8E9B1BCAC1AEDD8C60:55296:32771 Security levelDisallowed DescriptionFREECELLCARD GAME Date last modified3/14/2008 9:30:47 AM Entertainment Pack Minesweeper Game; Microsoft® Windows® Operating System; Microsoft Corporation; WINMINE.EXE (5.1.2600.0) File hash9C45D38B74634C9DED60BEC640C5C3CA:119808:32771 Security levelDisallowed Description Date last modified3/14/2008 10:02:47 AM Entertainment Pack Minesweeper Game; Microsoft® Windows® Operating System; Microsoft Corporation; WINMINE.EXE (5.1.2600.0) File hash9C45D38B74634C9DED60BEC640C5C3CA:119808:32771 Security levelDisallowed DescriptionMINE SWEEPER Date last modified3/14/2008 9:35:41 AM Solitaire Game Applet; Microsoft® Windows® Operating System; Microsoft Corporation; sol.exe (5.1.2600.0) File hash373E7A863A1A345C60EDB9E20EC32311:56832:32771 Security levelDisallowed Description Date last modified3/14/2008 10:02:32 AM Solitaire Game Applet; Microsoft® Windows® Operating System; Microsoft Corporation; sol.exe (5.1.2600.0) File hash373E7A863A1A345C60EDB9E20EC32311:56832:32771 Security levelDisallowed DescriptionSOLITAIRE Date last modified3/14/2008 9:36:19 AM Spider; Microsoft® Windows® Operating System; Microsoft Corporation; Spider (5.1.2600.2180) File hash4749198C70F4162D622F24601B527645:538624:32771 Security levelDisallowed Description Date last modified3/14/2008 10:02:39 AM Spider; Microsoft® Windows® Operating System; Microsoft Corporation; Spider (5.1.2600.3264) File hashAE506917A742177864DC3F9231CF765C:538624:32771 Security levelDisallowed DescriptionSPIDER Date last modified3/14/2008 9:53:54 AM The Microsoft Hearts Network; Microsoft® Windows® Operating System; Microsoft Corporation; MSHEARTS.EXE (5.1.2600.0) File hashBE1B85306352E0AC901EC08506792B6B:126976:32771 Security levelDisallowed Description Date last modified3/14/2008 10:02:24 AM The Microsoft Hearts Network; Microsoft® Windows® Operating System; Microsoft Corporation; MSHEARTS.EXE (5.1.2600.0) File hashBE1B85306352E0AC901EC08506792B6B:126976:32771 Security levelDisallowed DescriptionHEARTS CARDS Date last modified3/14/2008 9:32:11 AM Path Rules %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% Security LevelUnrestricted Description Date last modified3/14/2008 9:04:16 AM %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%*.exe Security LevelUnrestricted Description Date last modified3/14/2008 9:04:16 AM %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%System32\*.exe Security LevelUnrestricted Description Date last modified3/14/2008 9:04:16 AM %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% Security LevelUnrestricted Description Date last modified3/14/2008 9:04:16 AM C:\Program Files\MSN Gaming Zone\Windows Security LevelDisallowed Description Date last modified3/14/2008 9:06:34 AM Administrative Templates Control Panel PolicySetting Prohibit access to the Control PanelEnabled Control Panel/Add or Remove Programs PolicySetting Hide Add New Programs pageEnabled Hide Add/Remove Windows Components pageEnabled Hide Change or Remove Programs pageEnabled Hide the Set Program Access and Defaults pageEnabled Remove Add or Remove ProgramsEnabled Control Panel/Display PolicySetting Hide Desktop tabEnabled Hide Settings tabEnabled Prevent changing wallpaperEnabled Remove Display in Control PanelEnabled Control Panel/Printers PolicySetting Browse the network to find printersDisabled Prevent deletion of printersEnabled Desktop PolicySetting Do not add shares of recently opened documents to My Network PlacesEnabled Don't save settings at exitEnabled Hide My Network Places icon on desktopEnabled Prevent adding, dragging, dropping and closing the Taskbar's toolbarsEnabled Prohibit adjusting desktop toolbarsEnabled Prohibit user from changing My Documents pathEnabled Remove My Computer icon on the desktopEnabled Remove Properties from the My Computer context menuEnabled Remove Properties from the My Documents context menuEnabled Remove the Desktop Cleanup WizardEnabled Desktop/Active Directory PolicySetting Hide Active Directory folderEnabled Network/Offline Files PolicySetting Prevent use of Offline Files folderEnabled Prohibit user configuration of Offline FilesEnabled Prevents users from changing any cache configuration settings. Start Menu and Taskbar PolicySetting Clear history of recently opened documents on exitEnabled Do not keep history of recently opened documentsEnabled Force classic Start MenuEnabled Lock the TaskbarEnabled Prevent changes to Taskbar and Start Menu SettingsEnabled Remove access to the context menus for the taskbarEnabled Remove Balloon Tips on Start Menu itemsEnabled Remove Drag-and-drop context menus on the Start MenuEnabled Remove Help menu from Start MenuEnabled Remove links and access to Windows UpdateEnabled Remove Logoff on the Start MenuEnabled Remove My Network Places icon from Start MenuEnabled Remove Network Connections from Start MenuEnabled Remove programs on Settings menuEnabled Remove Run menu from Start MenuEnabled Remove Search menu from Start MenuEnabled Remove Set Program Access and Defaults from Start menuEnabled Turn off personalized menusEnabled Turn off user trackingEnabled System/Ctrl+Alt+Del Options PolicySetting Remove Lock ComputerEnabled Remove LogoffEnabled Remove Task ManagerEnabled Windows Components/Internet Explorer PolicySetting Disable changing Advanced page settingsEnabled Disable changing connection settingsEnabled Disable changing home page settingsEnabled Disable Internet Connection wizardEnabled Do not allow AutoComplete to save passwordsEnabled Windows Components/Internet Explorer/Browser menus PolicySetting Help menu: Remove 'Send Feedback' menu optionEnabled Tools menu: Disable Internet Options... menu optionEnabled Windows Components/Internet Explorer/Internet Control Panel PolicySetting Disable the Advanced pageEnabled Disable the Connections pageEnabled Disable the Content pageEnabled Disable the General pageEnabled Disable the Privacy pageEnabled Disable the Programs pageEnabled Disable the Security pageEnabled Windows Components/Microsoft Management Console PolicySetting Restrict the user from entering author modeEnabled Restrict users to the explicitly permitted list of snap-insEnabled Windows Components/Task Scheduler PolicySetting Prohibit New Task CreationEnabled Windows Components/Windows Explorer PolicySetting Hide these specified drives in My ComputerEnabled Pick one of the following combinationsRestrict C, M, P and S only PolicySetting Hides the Manage item on the Windows Explorer context menuEnabled No "Computers Near Me" in My Network PlacesEnabled No "Entire Network" in My Network PlacesEnabled Remove "Map Network Drive" and "Disconnect Network Drive"Enabled Remove DFS tabEnabled Remove Hardware tabEnabled Remove Search button from Windows ExplorerEnabled Remove Security tabEnabled Windows Components/Windows Installer PolicySetting Prevent removable media source for any installEnabled Windows Components/Windows Media Player PolicySetting Prevent Radio Station Preset RetrievalEnabled Windows Components/Windows Media Player/Networking PolicySetting Hide Network TabEnabled Windows Components/Windows Messenger PolicySetting Do not allow Windows Messenger to be runEnabled Windows Components/Windows Update PolicySetting Do not display 'Install Updates and Shut Down' option in Shut Down Windows dialog boxEnabled Remove access to use all Windows Update featuresEnabled
Jose Posted April 8, 2008 Posted April 8, 2008 this is a gpo we apply to all vanilla machines, this forces the machine to only allow local profiles, plus other settings User settings Loopback processing General Details Domainwallington.internal OwnerWALLINGTON\Domain Admins User Revisions16 (AD), 16 (sysvol) Computer Revisions6 (AD), 6 (sysvol) Unique ID{371B6EFC-3B55-452E-B223-3AB4DDE52948} GPO StatusEnabled Links LocationEnforcedLink StatusPath WHSGYesEnabledwallington.internal/WHSG This list only includes links in the domain of the GPO. Security Filtering The settings in this GPO can only apply to the following groups, users, and computers:Name NT AUTHORITY\Authenticated Users WALLINGTON\Domain Computers WMI Filtering WMI Filter NameNone DescriptionNot applicable Delegation These groups and users have the specified permission for this GPONameAllowed PermissionsInherited NT AUTHORITY\Authenticated UsersRead (from Security Filtering)No NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSReadNo NT AUTHORITY\SYSTEMEdit settings, delete, modify securityNo WALLINGTON\Domain AdminsEdit settings, delete, modify securityNo WALLINGTON\Domain ComputersEdit settings, delete, modify securityNo WALLINGTON\Enterprise AdminsEdit settings, delete, modify securityNo Computer Configuration (Enabled) Administrative Templates System/Group Policy PolicySetting User Group Policy loopback processing modeEnabled Mode:Replace System/User Profiles PolicySetting Log users off when roaming profile failsDisabled Only allow local user profilesEnabled User Configuration (Enabled) Windows Settings Folder Redirection My Documents Setting: Basic (Redirect everyone's folder to the same location) Path: \\%HOMESHARE%%HOMEPATH% Options Grant user exclusive rights to My DocumentsEnabled Move the contents of My Documents to the new locationDisabled Policy Removal BehaviorLeave contents Internet Explorer Maintenance Browser User Interface/Customized Title Bar Title Bar Text WALLINGTON HIGH SCHOOL FOR GIRLS URLs/Important URLs NameURL Home page URLhttp://www.wallingtongirls.sutton.sch.uk/ Search bar URLNot configured Online support page URLNot configured URLs/Favorites and Links PolicySetting Place favorites and links at the top of the list in the order specified belowNot configured Delete existing Favorites and Links, if presentNot configured Delete existing channels, if presentNot configured Favorites NameURL School Emailhttp://www.webmail.suttonlea.org SNAB ONLINEhttp://www.snabonline.com Sutton LEA Intranethttp://www.intra.suttonlea.org GOOGLE UKhttp://www.google.co.uk Security/Security Zones and Content Ratings Security Zones and Privacy These settings will not apply to users that log on to computers that have the Internet Explorer Enhanced Security Configuration (ESC) enabled. To create settings for users on computers that have ESC enabled, create a new GPO and edit that GPO on a computer where ESC is enabled.Internet (Security Level: Custom) .NET Framework-reliant componentsRun components not signed with AuthenticodeEnable Run components signed with AuthenticodeEnable ActiveX controls and plug-insDownload signed ActiveX controlsPrompt Download unsigned ActiveX controlsDisable Initialize and script ActiveX controls not marked as safeDisable Run ActiveX controls and plug-insEnable Script ActiveX controls marked safe for scriptingEnable DownloadsFile downloadEnable Font downloadEnable Microsoft VMJava permissionsHigh safety MiscellaneousAccess data sources across domainsDisable Allow META REFRESHEnable Display mixed contentPrompt Don't prompt for client certificate selection when no certificates or only one certificate existsDisable Drag and drop or copy and paste filesEnable Installation of desktop itemsPrompt Launching applications and unsafe filesPrompt Launching programs and files in an IFRAMEPrompt Navigate sub-frames across different domainsEnable Software channel permissionsMedium safety Submit nonencrypted form dataPrompt Userdata persistenceEnable ScriptingActive scriptingEnable Allow paste operations via scriptEnable Scripting of Java appletsEnable User AuthenticationLogonAutomatic logon only in Intranet zone Local intranet (Security Level: Custom) .NET Framework-reliant componentsRun components not signed with AuthenticodeEnable Run components signed with AuthenticodeEnable ActiveX controls and plug-insDownload signed ActiveX controlsEnable Download unsigned ActiveX controlsPrompt Initialize and script ActiveX controls not marked as safePrompt Run ActiveX controls and plug-insEnable Script ActiveX controls marked safe for scriptingEnable DownloadsFile downloadEnable Font downloadEnable Microsoft VMJava permissionsLow safety MiscellaneousAccess data sources across domainsEnable Allow META REFRESHEnable Display mixed contentPrompt Don't prompt for client certificate selection when no certificates or only one certificate existsEnable Drag and drop or copy and paste filesEnable Installation of desktop itemsEnable Launching applications and unsafe filesEnable Launching programs and files in an IFRAMEEnable Navigate sub-frames across different domainsEnable Software channel permissionsLow safety Submit nonencrypted form dataEnable Userdata persistenceEnable ScriptingActive scriptingEnable Allow paste operations via scriptEnable Scripting of Java appletsEnable User AuthenticationLogonAutomatic logon with current username and password SitesRequire server verification (https:) for all sites in this zoneDisabled Include all local (intranet) sites not listed in other zonesEnabled Include all sites that bypass the proxy serverEnabled Include all network paths (UNCs)Enabled Sites in this zone None Trusted sites (Security Level: Custom) .NET Framework-reliant componentsRun components not signed with AuthenticodeEnable Run components signed with AuthenticodeEnable ActiveX controls and plug-insDownload signed ActiveX controlsEnable Download unsigned ActiveX controlsPrompt Initialize and script ActiveX controls not marked as safePrompt Run ActiveX controls and plug-insEnable Script ActiveX controls marked safe for scriptingEnable DownloadsFile downloadEnable Font downloadEnable Microsoft VMJava permissionsLow safety MiscellaneousAccess data sources across domainsEnable Allow META REFRESHEnable Display mixed contentPrompt Don't prompt for client certificate selection when no certificates or only one certificate existsEnable Drag and drop or copy and paste filesEnable Installation of desktop itemsEnable Launching applications and unsafe filesEnable Launching programs and files in an IFRAMEEnable Navigate sub-frames across different domainsEnable Software channel permissionsLow safety Submit nonencrypted form dataEnable Userdata persistenceEnable ScriptingActive scriptingEnable Allow paste operations via scriptEnable Scripting of Java appletsEnable User AuthenticationLogonAutomatic logon with current username and password SitesRequire server verification (https:) for all sites in this zoneEnabled Sites in this zone None Restricted sites (Security Level: Custom) .NET Framework-reliant componentsRun components not signed with AuthenticodeDisable Run components signed with AuthenticodeDisable ActiveX controls and plug-insDownload signed ActiveX controlsDisable Download unsigned ActiveX controlsDisable Initialize and script ActiveX controls not marked as safeDisable Run ActiveX controls and plug-insDisable Script ActiveX controls marked safe for scriptingDisable DownloadsFile downloadDisable Font downloadPrompt Microsoft VMJava permissionsDisable Java MiscellaneousAccess data sources across domainsDisable Allow META REFRESHDisable Display mixed contentPrompt Don't prompt for client certificate selection when no certificates or only one certificate existsDisable Drag and drop or copy and paste filesPrompt Installation of desktop itemsDisable Launching applications and unsafe filesDisable Launching programs and files in an IFRAMEDisable Navigate sub-frames across different domainsDisable Software channel permissionsHigh safety Submit nonencrypted form dataPrompt Userdata persistenceDisable ScriptingActive scriptingDisable Allow paste operations via scriptDisable Scripting of Java appletsDisable User AuthenticationLogonPrompt for user name and password SitesSites in this zone None Privacy Privacy LevelMedium Web Sites Always allowNone Always blockNone Administrative Templates Control Panel/Display/Desktop Themes PolicySetting Load a specific visual style file or force Windows ClassicEnabled Path to Visual Style: To select Luna type: %windir%\resources\Themes\Luna\Luna.msstyles To select a different visual style, type: ie: \\\share\Corp.msstyles To select Windows Classic, leave the box above blank and enable this setting
Netman Posted April 8, 2008 Posted April 8, 2008 To help people who what to set up a new vanilla network can we creat a list of Group Policey Objects that you need to make an eductioan network? Admins Could this Become a sticky? I'd be willing to run this as a project - I agree it would be very worthwhile having some example GPOs that Edugeeks could just download and then customise for themselves. I'd need some examples of existing GPOs that are in use (in backup or report form) then I could take the best settings from them all and roll them into maybe three exemplar GPOs, i.e Strict, Medium and Lenient... and stick it all on the Wiki. More than happy to do this if you think it's a good idea. If so, post here and if there is enough interest, I'll start a new thread asking for examples of edugeeker's GPOs... 1
Freedom Posted April 23, 2008 Posted April 23, 2008 I aquired Server 2008 for one fo the schools I work at and something very nice was the ability to Import, Export and Create things called Starter GPO's. If anyone else has any Starter GPOs that they have configured I would very much appreciate them, otherwise I have got to spend the rest of eternity configuring all of the settings Don't worry though, if I get no volunteers, I will submit my starter GPO once it is finished for perusal, modification and mayby reimplemntation into my network. BTW: Planning to dump Ranger and go Vanilla with proper settings and GPO structure - first time doing that
Domino Posted April 23, 2008 Posted April 23, 2008 so....like this http://www.microsoft.com/Downloads/details.aspx?familyid=AE3DDBA7-AF7A-4274-9D34-1AD96576E823&displaylang=en 1
shoggie Posted December 15, 2010 Posted December 15, 2010 Having some basic GPO's would be great for use to us i.e Strict, Medium and Lenient. Server 2008 r2 / windows 7
Domino Posted December 15, 2010 Posted December 15, 2010 Having some basic GPO's would be great for use to us i.e Strict, Medium and Lenient. Server 2008 r2 / windows 7 *ahem* so....like this Download details: Starter Group Policy Objects (GPOs)
edutech4schools Posted December 15, 2010 Posted December 15, 2010 Hay rather than typing in all that info (above posts) you can open gpmc click on the group police from the list, in the right box click something like display all (not in front of server at the mo) and click save as html. It will then generate a report for that selected group policy for your convenience. (2003 works not done this in 2008)
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now