• Home
  • About 404TS
  • Contact

404 Tech Support

Where IT Help is Found

  • Articles
    • Code
    • Entertainment
    • Going Green
    • Hardware, Gadgets, and Products
    • Management
    • Network
    • News
    • Operating Systems
    • Security and Privacy
    • Software
    • System Administration
    • Talking Points
    • Tech Solutions
    • Web
    • Webmaster
  • Reviews
  • Media
    • Infographics
    • Videos
  • Tech Events
  • Tools
    • How do I find my IP address?
    • Browser and plugin tests
  • Get a Technical Consultation
You are here: Home / Articles / System Administration / Group Policy Advanced Info

Group Policy Advanced Info

2008-03-06 by Jason

Post-class GPO knowledge:

Make a console for your convenience from the Microsoft Management Console.
Go to Start, Run… and enter mmc.
Go to File, Add/Remove snap-ins.
Click the ‘Add…’ button
Browse the list (you might have to install the AdminPack.msi to get these snap-ins) and choose Active Directory Users and Computers, ADSI, Resultant Set of Policy, and anything else that looks interesting and might be useful for your environment.
Add these snap-ins and save the console to your desktop or other convenient location.

Install the Group Policy Management Console from the Windows Server 2003 Resource kit for the best interface. .NET 1.1 is required for the GPMC.

Get to the GPMC by browsing through the Active Directory Users and Computers console. Right-click on an OU (Organization Unit) and select Properties. The far-right tab is labeled Group Policy and under it will have a button to “Launch Group Policy Management Console” if you have installed that component.

When creating GPO’s, it would be best-practice to disable the links first while editing them and then re-link when done. You should also have a separate OU created to use for testing as policies are edited live and would take effect the next time a machine refreshes their Group policy (default: every 90 minutes) and logs off for user policies or restarts for computer policies. Enable the links when you’re ready for the Group Policy to take effect.

The hierarchy of application of policies resolves any conflicts that might arise with contradicting policies. One policy at the domain level might say to disable something, while the policy at the OU level says to enable it. The more specific policy will win out.
Local/Machine Domain -> Site -> Domain -> OU
(ascending in specificity)

Permissions on computers in the Group Policy must allow read access to the policy, and allow “Apply Group Policy” permissions for the policy to take effect on that machine. The security permissions on the group policies can be used to filter access to those that can use the GPO by enabling or disabling permissions to security groups.

Loopback processing must be enabled to apply GPOs to users not in your OU. The setting can be found under Computer Config, Admin Templates, System, Group Policy.

Monitor the Application event log for an event from SceCli which will give information that the security policy was successfully applied to see that the group policy has refreshed.

See the group policy that applied to a machine with the command gpresult /z
Write this to a file for easier analysis with: gpresult /z > c:\gp.txt
Through the MMC, with the snap-in for Resultant Set of Policy, you can also view what policies were applied or under the command prompt type RSoP.

Under the command prompt, type set to see what system variables are named and available.

Filed Under: System Administration, Tech Solutions

Trending

  • Apple builds up privacy policy and releases OS X El Capitan
    In Operating Systems, Security and Privacy
  • 5 Crucial Tips on How Bypass Geo-Blocking with Your Android
    In Security and Privacy
  • Stop 0x50 BSoDs for Windows 7 and Server 2008 R2 following August updates
    In System Administration, Tech Solutions

Latest Media Posts

Find Out Where To Download SNES ROMs

Find Out Where To Download SNES ROMs

Multifunctional Video Conversion Tools – Wondershare Video Converter

Multifunctional Video Conversion Tools – Wondershare Video Converter

  • Popular
  • Latest
  • Today Week Month All
  • How to ‘Unblock’ multiple files at a time with PowerShell How to 'Unblock' multiple files at a time with PowerShell
  • Increase IIS Private Memory Limit to improve WSUS availability Increase IIS Private Memory Limit to improve WSUS availability
  • Command line to take ownership and change permissions Command line to take ownership and change permissions
  • Creating and editing views in phpMyAdmin Creating and editing views in phpMyAdmin
  • Read the Event Logs on Windows Server Core Read the Event Logs on Windows Server Core
  • How to Purchase Cryptocurrencies? How to Purchase Cryptocurrencies?
  • Top 6 necessary aspects to consider when hiring Angular developers Top 6 necessary aspects to consider when hiring Angular developers
  • Full guide on drawbacks and benefits of Node.js for making the perfect choice for your business Full guide on drawbacks and benefits of Node.js for making the perfect choice for your business
  • Benefits of End-To-End Testing That Will Match Company Expectations Benefits of End-To-End Testing That Will Match Company Expectations
  • 3 Key Features of Pets Health Monitoring Systems 3 Key Features of Pets Health Monitoring Systems
Ajax spinner

Elevator Pitch

404 Tech Support documents solutions to IT problems, shares worthwhile software and websites, and reviews hardware, consumer electronics, and technology-related books.

Subscribe to 404TS articles by email.

Recent Posts

  • How to Purchase Cryptocurrencies?
  • Top 6 necessary aspects to consider when hiring Angular developers
  • Full guide on drawbacks and benefits of Node.js for making the perfect choice for your business

Search

FTC Disclaimer

404TechSupport is an Amazon.com affiliate; when you click on an Amazon link from 404TS, the site gets a cut of the proceeds from whatever you buy. This site also uses Skimlinks for smart monetization of other affiliate links.
Use of this site requires displaying and viewing ads as they are presented.

Copyright © 2023 · Magazine Pro Theme on Genesis Framework · WordPress · Log in