Windows® Group Policy Resource Kit: Windows Server® 2008 and Windows Vista®

Windows® Group Policy Resource Kit: Windows Server® 2008 and Windows Vista®

Read it now on the O’Reilly learning platform with a 10-day free trial.

O’Reilly members get unlimited access to books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.

Book description

Get the in-depth information you need to use Group Policy to administer Windows Server 2008 and Windows Vista—direct from a leading Group Policy MVP and the Microsoft Group Policy team. With Group Policy and Active Directory directory service, administrators can take advantage of policy-based management to streamline the administration of users and computers throughout the enterprise—from servers running Windows Server 2008, Windows Server 2003 or Windows 2000 Server, to workstations running Windows Vista, Windows XP Professional, or Windows 2000 Professional. This essential resource provides in-depth technical information and expert insights for simplifying and automating administrative tasks, including policy enforcement, system updates, and software installations, as well as how to centralize the management of network resources. The CD provides essential utilities, job aids, and more. It’s everything you need to help increase your efficiency while bolstering user productivity, security services, and system reliability.

For customers who purchase an ebook version of this title, instructions for downloading the CD files can be found in the ebook.

Show and hide more Table of contents Product information

Table of contents

  1. Dedication
  2. Acknowledgments
    1. List of Reviewers from the Group Policy Team
    1. Overview of the Book
      1. Part I: Introducing Group Policy
      2. Part II: Group Policy Structure
      3. Part III: Administering Group Policy
      4. Part IV: Implementing Security
      5. Part V: Using Registry-Based Policy Settings
      6. Part VI: Group Policy Settings
      7. Part VII: Advanced Topics
      8. Part VIII: Appendices
      1. Reader Aids
      2. Sidebars
      3. Command-Line Examples
      1. Elevation Tools
      2. Management scripts
      3. eBook
      4. Chapter-Related Materials
      1. 1. Why Group Policy?
        1. The Past, Present, and Future of Group Policy
          1. Group Policy’s Past
          2. Group Policy’s Present
            1. Group Policy Requires Active Directory
            2. Group Policy Includes Security Settings
            3. Group Policy Includes Software Distribution
            4. Group Policy Helps Eliminate Tattooing
            5. Group Policy Can Modify System Settings
            6. Group Policy Is Extensible
            7. Group Policy Is Dynamic
            8. Much, Much More
            1. Troubleshooting Tools
            2. Enterprise Administration
            3. Disaster Recovery
            4. Reporting
            5. Instant Configuration
            6. Is the Future Already Here?
            1. More Efficient Management
            2. More Powerful Management
            3. Reliability
            4. Extensibility
            5. Security
            6. Diversity
            7. Consistency
            8. Stability
            9. Group Policy Negatives
              1. Limited Troubleshooting Tools
              2. Limited Testing Environment and Tools
              3. Limited Inter-Domain and Inter-Forest Support
              1. Remember When
              2. New and Now
                1. New Group Policy Features in Windows Vista
                  1. Multiple Local GPOs
                    1. Local Computer Policy Object
                    2. Administrators and Non-Administrators Local GPOs
                    3. User-Specific Local GPO
                    4. Precedence and Application
                    1. Filters
                    2. Starter GPOs
                    3. Commenting
                    1. Group Policy Preferences
                    2. Advanced Group Policy Management (GPOVault)
                    1. Group Policy Defined
                    2. Structural Overview of a GPO
                      1. Computer Configuration
                      2. User Configuration
                      1. Local Policy Object
                      2. Administrators and Non-Administrators Local GPOs
                        1. User-Specific Local GPOs
                        2. Precedence
                        1. Default Domain Policy
                          1. Account Policies in the Default Domain Policy
                          2. Other Policy Settings in the Default Domain Policy
                          1. Privileges for Creating New GPOs
                          2. Creating GPOs Correctly
                          1. 4. Architecture of Group Policy
                            1. Group Policy Dependencies
                              1. Active Directory and Group Policy
                              2. Domain Name System
                              3. Replication
                              4. DFS
                              1. Using the PDC Emulator
                              2. Selecting the Domain Controller for GPO Editing
                              1. Group Policy Template
                              2. Group Policy Container
                              1. Group Policy Template and SYSVOL Replication
                              2. Active Directory Replication
                              1. Scope of Management
                              2. Group Policy Processing
                                1. GPO Precedence for GPOs Linked to Different Nodes
                                2. GPO Precedence for GPOs Linked to the Same Node
                                1. Background GPO Policy Processing
                                2. Foreground Group Policy Processing
                                  1. Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options
                                  2. Computer Configuration\Policies\Administrative Templates\Windows Components
                                  3. Computer Configuration\Policies\Administrative Templates\System
                                  4. User Configuration\Policies\Administrative Templates\Windows Components
                                  5. User Configuration\Policies\Administrative Templates\System
                                  1. GPO Version Numbers on the Client
                                  2. GPO Version Numbers on the Domain Controller
                                  1. Block Policy Inheritance
                                  2. Enforce
                                  3. Security Filtering
                                  4. WMI Filters
                                  5. Group Policy Preferences
                                  1. 6. Using the GPMC
                                    1. Getting Around in the GPMC
                                      1. Launching the GPMC from Windows Server 2008
                                      2. Launching the GPMC from Windows Vista
                                      3. Domain Views in the GPMC
                                      4. Forest Views in the GPMC
                                      5. Site Views in the GPMC
                                      6. GPMC Management Limitations
                                      7. Selecting Domain Controllers for Administration of GPOs
                                      1. Creating GPOs
                                      2. Linking GPOs
                                      3. Managing GPO Configurations
                                        1. Enabling and Disabling GPOs
                                        2. Renaming GPOs
                                        3. Enabling and Disabling a GPO Link
                                        1. Backing Up GPOs
                                        2. Restoring GPOs
                                          1. Restoring an Existing GPO
                                          2. Restoring a Deleted GPO
                                          3. Viewing the GPO Settings of a Backed-Up GPO
                                          1. Creating Starter GPOs
                                          2. Editing Starter GPOs
                                          3. Backing Up Starter GPOs
                                          4. Working with Starter GPO Cabinet Files
                                          1. Working with GPOs
                                            1. Searching GPOs
                                            2. Filtering Administrative Templates in the GPME
                                              1. Filter Options
                                              2. Filter Option Operators
                                              1. Results Pane for Group Policy Results
                                                1. Summary
                                                2. Settings
                                                3. Policy Events
                                                1. Advanced View
                                                2. Rerun Query
                                                3. Save Report
                                                1. Results Pane for Group Policy Modeling
                                                  1. Summary
                                                  2. Settings
                                                  3. Query
                                                  1. Advanced View
                                                  2. Rerun Query
                                                  3. Create New Query From This One
                                                  4. Save Report
                                                  1. Starter GPO Comments
                                                  2. Production GPO Comments
                                                  3. Comments for Administrative Template Settings
                                                  1. Reasons for Migrating GPOs
                                                  2. Requirements for Migrating GPOs Between Domains
                                                  3. Settings in a GPO That Require Translation
                                                  4. Migrating GPOs Across Domains
                                                    1. Migrating a GPO Using Copy and Paste
                                                    2. Migrating a GPO Using Backup and Import
                                                    1. GPMC Scripts
                                                      1. Backing Up and Restoring GPOs
                                                        1. BackupGPO.wsf
                                                          1. Syntax
                                                          2. Example & Output
                                                          1. Syntax
                                                          2. Example & Output
                                                          1. Syntax
                                                          2. Example & Output
                                                          1. Syntax
                                                          2. Example & Output
                                                          1. Syntax
                                                          2. Example #1 & Output
                                                          3. Example #2 & Output
                                                          1. CopyGPO.wsf
                                                            1. Syntax
                                                            2. Example
                                                            1. Syntax
                                                            2. Example
                                                            1. Syntax
                                                            2. Example
                                                            1. CreateGPO.wsf
                                                              1. Syntax
                                                              2. Example & Output
                                                              1. Syntax
                                                              2. Example & Output
                                                              1. Syntax
                                                              2. Example & Output
                                                              1. Syntax
                                                              2. Example & Output
                                                              1. DeleteGPO.wsf
                                                                1. Syntax
                                                                2. Example & Output
                                                                1. DumpGPOInfo.wsf
                                                                  1. Syntax
                                                                  2. Example & Output
                                                                  1. Syntax
                                                                  2. Example & Output
                                                                  1. Syntax
                                                                  2. Example & Output
                                                                  1. Syntax
                                                                  2. Example & Output
                                                                  1. Syntax
                                                                  2. Example & Output
                                                                  3. Example #2 & Output
                                                                  1. Syntax
                                                                  2. Example & Output
                                                                  1. FindDisabledGPOs.wsf
                                                                    1. Syntax
                                                                    2. Example & Output
                                                                    1. Syntax
                                                                    2. Example & Output
                                                                    1. Syntax
                                                                    2. Example & Output
                                                                    1. Syntax
                                                                    2. Example & Output
                                                                    1. Syntax
                                                                    2. Example & Output
                                                                    1. Syntax
                                                                    2. Example
                                                                    1. Syntax
                                                                    1. Syntax
                                                                    2. Example & Output
                                                                    1. GrantPermissionOnAllGPOs.wsf
                                                                      1. Syntax
                                                                      2. Example & Output
                                                                      1. Syntax
                                                                      2. Example & Output
                                                                      1. Syntax
                                                                      2. Example & Output
                                                                      1. Syntax
                                                                      2. Example & Output
                                                                      1. Syntax
                                                                      2. Example #1 & Output
                                                                      3. Example #2 & Output
                                                                      1. 9. Security Delegation for Administration of GPOs
                                                                        1. Default Security Environment
                                                                          1. Default Security of the GPMC
                                                                          2. Default Security of AGPM
                                                                          1. Creating GPOs
                                                                          2. Linking GPOs
                                                                          3. Managing GPOs
                                                                          4. Editing GPOs
                                                                          5. Modeling GPOs
                                                                          6. RSoP of GPOs
                                                                          1. Full Control
                                                                          2. Editing
                                                                          3. Approving
                                                                          4. Reviewing
                                                                          1. Creating GPOs
                                                                            1. Creating GPOs without AGPM
                                                                            2. Creating GPOs with AGPM
                                                                            3. Segregation of Group Policy Creation from Other Duties without AGPM
                                                                            1. Editing GPOs without AGPM
                                                                            2. Editing GPOs with AGPM
                                                                            1. Testing GPOs without AGPM with a Production Organizational Unit
                                                                            2. Testing GPOs without AGPM with a Test Domain
                                                                            3. Testing GPOs with AGPM with a Production Organizational Unit
                                                                            1. 10. ADM Templates, ADMX Files, and the ADMX Central Store
                                                                              1. Administrative (.adm) Templates
                                                                                1. Default .adm Templates
                                                                                2. Working with .adm Templates
                                                                                3. Default Installed .adm Templates
                                                                                4. Importing .adm Templates
                                                                                5. Adding .adm Templates
                                                                                6. Removing .adm Templates
                                                                                7. Managing .adm Templates
                                                                                  1. Controlling Updated Versions of .adm Templates
                                                                                    1. Turn Off Automatic Updates Of ADM Files
                                                                                    2. Always Use Local ADM Files For Group Policy Editor
                                                                                    1. Scenario 1: Administration of GPO with Windows Vista
                                                                                    2. Scenario 2: Administration of GPO with a Windows Server 2008 Domain Controller
                                                                                    3. Scenario 3: Administration of GPO from a Windows XP Workstation
                                                                                    1. File Syntax Conversion for .adm Template to ADMX Files
                                                                                    2. ADMX Migrator
                                                                                    1. Creating the Central Store
                                                                                    2. Copying ADMX and ADML Files to the Central Store
                                                                                    1. Creating Custom .adm Templates
                                                                                      1. A Simple .adm Template
                                                                                      1. Structure of an .adm Template
                                                                                      2. #if version
                                                                                      3. Syntax for Updating the Registry
                                                                                        1. CLASS
                                                                                        2. KEYNAME
                                                                                        3. VALUENAME
                                                                                        4. VALUEOFF/VALUEON
                                                                                        1. STRINGS
                                                                                        2. CATEGORY
                                                                                        3. POLICY
                                                                                        4. PART
                                                                                          1. CHECKBOX
                                                                                          2. CLIENTTEXT
                                                                                          3. COMBOBOX
                                                                                          4. DROPDOWNLIST
                                                                                          5. EDITTEXT
                                                                                          6. LISTBOX
                                                                                          7. NUMERIC
                                                                                          8. TEXT
                                                                                          1. Comments
                                                                                          2. REQUIRED
                                                                                          3. MAXLEN
                                                                                          4. EXPLAIN
                                                                                          5. SUPPORTED
                                                                                          1. ADMX Schema
                                                                                          2. ADMX File Structure
                                                                                          3. ADML File Structure
                                                                                          4. Core ADMX File Concepts
                                                                                            1. Referencing the Windows Base ADMX File
                                                                                            2. Referencing Category Elements from the Windows Base ADMX File
                                                                                            3. Referencing Category Elements from the Windows Base ADMX File
                                                                                            1. 12. Group Policy Preferences
                                                                                              1. Benefits of Group Policy Preferences
                                                                                                1. User-Friendly Interface
                                                                                                2. Thousands More Settings
                                                                                                3. Practical and Valuable Settings
                                                                                                4. Reduced Desktop Images
                                                                                                5. Reduced Need for Log-on Scripts
                                                                                                6. Working with Any Organizational Unit Design
                                                                                                1. Managing Group Policy Preferences Using the GPME
                                                                                                  1. Windows Server 2008
                                                                                                  2. Windows Vista
                                                                                                  1. Windows Server 2008
                                                                                                  2. Windows Vista, Windows Server 2003 SP1, and Windows XP SP2
                                                                                                  1. Group Policy Preferences: Windows Settings
                                                                                                    1. Applications
                                                                                                    2. Drive Maps
                                                                                                    3. Environment
                                                                                                    4. Files
                                                                                                    5. Folders
                                                                                                    6. Ini Files
                                                                                                    7. Network Shares
                                                                                                    8. Registry
                                                                                                    9. Shortcuts
                                                                                                    1. Data Sources
                                                                                                    2. Devices
                                                                                                    3. Folder Options
                                                                                                    4. Internet Settings
                                                                                                    5. Local Users and Groups
                                                                                                    6. Network Options
                                                                                                    7. Power Options
                                                                                                    8. Printers
                                                                                                    9. Regional Options
                                                                                                    10. Scheduled Tasks
                                                                                                    11. Services
                                                                                                    12. Start Menu
                                                                                                    1. Action Modes
                                                                                                    2. Common Tab
                                                                                                    3. Item-Level Targeting
                                                                                                      1. Item-Level Targeting Items
                                                                                                        1. Battery Present
                                                                                                        2. Computer Name
                                                                                                        3. CPU Speed
                                                                                                        4. Date Match
                                                                                                        5. Dial-Up Connection
                                                                                                        6. Disk Space
                                                                                                        7. Domain
                                                                                                        8. Environment Variable
                                                                                                        9. File Match
                                                                                                        10. IP Address Range
                                                                                                        11. Language
                                                                                                        12. LDAP Query
                                                                                                        13. MAC Address Range
                                                                                                        14. MSI Query
                                                                                                        15. Operating System
                                                                                                        16. Organizational Unit
                                                                                                        17. PCMCIA Present
                                                                                                        18. Portable Computer
                                                                                                        19. Processing Mode
                                                                                                        20. RAM
                                                                                                        21. Registry Match
                                                                                                        22. Security Group
                                                                                                        23. Site
                                                                                                        24. Terminal Session
                                                                                                        25. Time Range
                                                                                                        26. User
                                                                                                        27. WMI Query
                                                                                                        1. Desktop vs. Laptop
                                                                                                        2. Computer Performance
                                                                                                        3. Operating System Targeting
                                                                                                        4. Drive Mapping Security
                                                                                                        1. Overall GPO Structure
                                                                                                        2. Policies
                                                                                                          1. Software Settings
                                                                                                          2. Windows Settings
                                                                                                            1. Remote Installation Services (User Configuration Only)
                                                                                                            2. Scripts
                                                                                                            3. Security Settings
                                                                                                              1. Account Policies (Computer Configuration Only)
                                                                                                              2. Local Policies (Computer Configuration Only)
                                                                                                              3. Restricted Groups (Computer Configuration Only)
                                                                                                              4. System Services (Computer Configuration Only)
                                                                                                              5. Registry (Computer Configuration Only)
                                                                                                              6. File System (Computer Configuration Only)
                                                                                                              7. Wired Network (IEEE 802.3) Policies (Computer Configuration Only)
                                                                                                              8. Windows Firewall with Advanced Security (Computer Configuration Only)
                                                                                                              9. Wireless Network (IEEE 802.11) Policies (Computer Configuration Only)
                                                                                                              10. Public Key Policies
                                                                                                              11. Software Restriction Policies
                                                                                                              12. Network Access Protection (Computer Configuration Only)
                                                                                                              13. IP Security Policies on Active Directory (Computer Configuration Only)
                                                                                                              14. Folder Redirection (User Configuration Only)
                                                                                                              15. Policy-Based QoS
                                                                                                              16. Internet Explorer Maintenance (User Configuration Only)
                                                                                                              1. Terminal Services
                                                                                                              2. User Account Control
                                                                                                              3. Log-on Scripts
                                                                                                              4. Servers
                                                                                                              5. Hardware Components
                                                                                                              6. Network Security
                                                                                                              1. 14. Advanced Group Policy Management
                                                                                                                1. Architecture of AGPM
                                                                                                                  1. Operating System Support
                                                                                                                  2. GPMC Requirements
                                                                                                                  3. Server Installation
                                                                                                                  4. Client Installation
                                                                                                                  1. When the Changes Were Made
                                                                                                                  2. Who Made the Changes
                                                                                                                  3. What Changes Were Made
                                                                                                                  1. E-Mail Configuration
                                                                                                                  2. Pending Tab
                                                                                                                  3. Creating GPOs
                                                                                                                    1. Creating a GPO (with Create Permissions)
                                                                                                                    2. Creating a GPO (without Create Permissions)
                                                                                                                    3. Withdrawing a GPO That Is Pending Creation
                                                                                                                    4. Approving or Rejecting a Pending GPO
                                                                                                                    1. Deploying a GPO That Was Created Offline (with Deploy Permissions)
                                                                                                                    2. Deploying a GPO That Was Created Offline (without Deploy Permissions)
                                                                                                                    3. Deploying a GPO from the Archive (with Deploy Permissions)
                                                                                                                    4. Deploying a GPO from the Archive (without Deploy Permissions)
                                                                                                                    1. Settings Reports
                                                                                                                    2. Difference Reports
                                                                                                                      1. Difference Report between Two Versions of the Same GPO
                                                                                                                      2. Difference Report between Two GPOs
                                                                                                                      3. Difference Report between a GPO and an AGPM Template
                                                                                                                      1. Group Policy Troubleshooting Essentials
                                                                                                                        1. Common Problems with GPOs
                                                                                                                          1. DNS-Related Problems
                                                                                                                          2. Asynchronous Group Policy Processing
                                                                                                                          1. Group Policy Operational Log
                                                                                                                          2. Event Viewer Troubleshooting Procedure
                                                                                                                            1. Evaluate the System Event Log
                                                                                                                            2. Evaluate the Group Policy Operational Log: Determine the ActivityID of Group Policy Processing
                                                                                                                            3. Evaluate the Group Policy Operational Log: Create a Custom View of a Group Policy Instance
                                                                                                                            4. Divide the Custom View of the Log into Three Phases: Preprocessing
                                                                                                                              1. Start Policy Processing
                                                                                                                              2. Retrieve Account Information
                                                                                                                              3. Domain Controller Discovery
                                                                                                                              4. Computer Role Discovery
                                                                                                                              5. Security Principal Discovery
                                                                                                                              6. Loopback Processing Mode Discovery
                                                                                                                              7. GPO Discovery
                                                                                                                              8. Slow Link Detection
                                                                                                                              9. Nonsystem GP Extension Discovery
                                                                                                                              1. GPLogView
                                                                                                                                1. Export All Group Policy Events
                                                                                                                                2. Export Group Policy Events with a Specific ActivityID
                                                                                                                                3. Run in Monitor Mode
                                                                                                                                4. Use an External Event Log for Input
                                                                                                                                1. A. Third-Party Group Policy Tools
                                                                                                                                  1. BeyondTrust: Privilege Manager
                                                                                                                                  2. FullArmor: Workflow Studio
                                                                                                                                  3. Moskowitz, Inc.
                                                                                                                                    1. PolicyPak for Applications
                                                                                                                                    2. PolicyPak Group Policy Design Studio
                                                                                                                                    1. Group Policy Administrator
                                                                                                                                    2. Change Guardian
                                                                                                                                    1. GPExpert Troubleshooting Pak
                                                                                                                                    2. GPExpert™ Scripting Toolkit for PowerShell
                                                                                                                                    3. GPExpert™ Backup Manager for Group Policy
                                                                                                                                    4. GPMC PowerShell Cmdlets
                                                                                                                                    1. Specops Deploy
                                                                                                                                    2. Specops Inventory
                                                                                                                                    3. Specops Command
                                                                                                                                    4. Specops Password Policy
                                                                                                                                    5. Specops Gpupdate
                                                                                                                                    1. PolMan
                                                                                                                                    2. ADM Template Editor
                                                                                                                                    3. Policy Reporter
                                                                                                                                    1. Group Policy Wiki
                                                                                                                                    2. Microsoft Group Policy Web Site
                                                                                                                                    3. Windows Server 2003 Web Site
                                                                                                                                    4. Microsoft Group Policy Team Blog
                                                                                                                                    5. Group Policy Webcast Web Site
                                                                                                                                    6. Group Policy Script Repository
                                                                                                                                    7. Microsoft TechNet
                                                                                                                                    8. TeamGPExpert.com
                                                                                                                                    9. BrainCore.net
                                                                                                                                    10. GPOGuy.com
                                                                                                                                    11. GPAnswers.com
                                                                                                                                    12. Summary
                                                                                                                                    1. Additional Resources for IT Professionals
                                                                                                                                    1. Also available as single volumes
                                                                                                                                    Show and hide more

                                                                                                                                    Product information

                                                                                                                                    • Title: Windows® Group Policy Resource Kit: Windows Server® 2008 and Windows Vista®
                                                                                                                                    • Author(s): Derek Melber
                                                                                                                                    • Release date: March 2008
                                                                                                                                    • Publisher(s): Microsoft Press
                                                                                                                                    • ISBN: 9780735625143