Day-9&10-Group Policy

Download as pptx, pdf, or txt
Download as pptx, pdf, or txt
You are on page 1of 16

Group Policy

• Group policy is a collection of settings which can be applied on


computers and users.
• With group policy administrator can centrally manage the computers
and users.
• Eases administration using group policy.
Group Policy

Computer Icon
Desktop Settings Recycle Bin Icon
Internet Explorer
Allow or Deny

Help Hide or Show


Start Menu Settings Search
Run Menu
Group Policy

Remove Run Menu


Remove Computer Icon
Remove Internet Explorer
Remove Recycle Bin
Before Group Policy
After Group Policy
After Group Policy
Scopes of Group Policy

Domain
OU
Domain
GPO
Site Site GPO
OU OU

Organizational
Unit GPO

Organizational
Unit GPO
Hierarchy of Group Policy

GPO
GPO 11

T Site
O
P
GPO
GPO 22
TO GPO
GPO 33
Domain
B
O
T GPO
GPO 44
T OU
O
M
OU
OU OU
OU
Site Group Policy

Hide Computer
Icon
MS.com

Hide Computer Hide Computer


Hide Computer Icon Icon
Mcitp.MS.com Ccna.MS.com
Icon

INDIA
Site Group Policy
Domain Group Policy

DC ADC
Hide Internet Explorer Icon

Hide Internet Explorer Icon

Clients
MS.COM
Domain Group Policy
OU Group Policy

Sys1 Sys2

Hide Recycle Bin Icon


Hide Recycle Bin Icon

OU Group Policy
Blocking the Inheritance of a GPO

Domain

PRODUCTION
GPOs

IT-STAFF

No
No GPO
GPO
settings
settings apply
apply
Software Deployment

• It is to deploy software (Applications) on all the computers in the


domain from one central location by applying the Group Policies.
• Supports the deployment of “.MSI” but not “.EXE” applications.
Folder Redirection

• Redirection of folders on the local computer or on a Shared folder.

• Folders on a server appear as if they are located on the local drive.

• Fastens the User logon process in case if the profile is large.


Auditing

• Audit policy configures a system to audit categories of activities. If


audit policy is not enabled, a server will not audit those activities
• Audit events categories are as below :
– Access to NTFS files and folders
– Account or object changes in AD DS
– Logon
– Assignment of use of user rights

You might also like