Jump to content

Group policy


dennis99
 Share

Recommended Posts

Force users to do windows update ?

Hey Dennis, you can use SUS (Software Update Server) from Microsoft and install it on any Server that you have. And then you can create a new GPO that linked to your domain.

Locate to :

Computer Configuration > Administrative Templates > Windows Components > Windows Update

Then you have to :

- Enable Configure Automatic Updates for the specific time

- Specify the full URL of your SUS Server

- Schedule the automatic installation

- etc

And make sure that you can synchronize your SUS Server to Microsoft Update Website.

Cheers....

Link to comment
Share on other sites

I'll have to check when I get home Dennis. I'm helping someone with come PC problems after work, so if I don't get to it tonight, I'll try tomorrow. I want to give you a step-by-step, and all I have access to right now are 2000 Servers.

In the mean time, Microsoft's site has some very good free tutorials like this one: Applying security settings that may help. You could try searching Microsoft's site, or searching for what you're trying to do on Google and picking the applicable Microsft site too.

Link to comment
Share on other sites

Please use extreme caution doing this! Do some learning and implement things in a small test environment first. If you make the wrong change using a domain-wide group policy you could, for example, lock yourself out of all PC's on your network!

I liken what we're doing here to joining a mechanic's forum and saying how do I change a piston in eight easy steps. Step 1, Learn a lot more about engines!

[edit]I don't mean to be condescending or demeaning in any way here Dennis. I'm trying to impress upon you how much trouble can ensue if you don't do quite a bit of background reading and testing before implementing policies.

Here's an example from the Windows 2003 Help Files for setting an audit policy:

For a domain or organizational unit, when you are on a member server or on a workstation that is joined to a domain

Open Microsoft Management Console (MMC).

[edit]Click on Start, Run and type in mmc then hit Enter

In the File menu, click Add/Remove Snap-in, and then click Add.

Click Group Policy Object Editor, and then click Add.

On the Select Group Policy Object page in the Group Policy Wizard, click Browse.

In Browse for a Group Policy Object, select a Group Policy object (GPO) in the appropriate domain, site, or organizational unit—or create a new one, click OK, and then click Finish.

Click Close, and then click OK.

In the console tree, click Audit Policy.

Computer Configuration

Windows Settings

Security Settings

Local Policies

Audit Policy

In the details pane, double-click an event category that you want to change the auditing policy settings for.

If you are defining auditing policy settings for this event category for the first time, select the Define these policy settings check box.

Do one or both of the following, and then click OK.

To audit successful attempts, select the Success check box.

To audit unsuccessful attempts, select the Failure check box.

To perform this procedure, you must be a member of the Domain Admins group or the Enterprise Admins group in Active Directory, or you must have been delegated the appropriate authority. As a security best practice, consider using Run as to perform this procedure.

To open Microsoft Management Console, click Start, click Run, type mmc, and then click OK.

To audit object accesses, enable auditing of the object access event category by following the steps above. Then, enable auditing on the specific object. For information about how to enable auditing on an object, see "Apply or modify auditing policy settings for a local file or folder" or "Apply or modify auditing policy settings for an object using Group Policy" in Related Topics.

After your audit policy is configured, events will be recorded in the security log. Open the security log to view these events. For information about the security log, see "Use the security log" in Related Topics.

The default auditing policy setting for domain controllers is No Auditing. This means that even if auditing is enabled in the domain, the domain controllers do not inherit auditing policy locally. If you want domain auditing policy to apply to domain controllers, you must modify this policy setting.

Here's another help message about modifying default domain policies. Don't do it!

Best practices

Do not modify the default domain policy.

If you do not edit the default domain policy, you always have the option of reapplying the default domain policy if something goes wrong with your customized domain policy.

Create a separate Group Policy object for software restriction policies.

If you create a separate Group Policy object (GPO) for software restriction policies, you can disable software restriction policies in an emergency without disabling the rest of your domain policy.

For more information, see Group Policy.

If you experience problems with applied policy settings, restart Windows in Safe Mode.

Software restriction policies do not apply when Windows is started in Safe Mode. If you accidentally lock down a workstation with software restriction policies, restart the computer in Safe Mode, log on as a local administrator, modify the policy, run gpupdate, restart the computer, and then log on normally.

For more information about restarting the computer in Safe Mode, see To start the computer in Safe Mode. For more information about gpupdate, see Gpupdate.

Use caution when defining a default setting of Disallowed.

When you define a default setting of Disallowed, all software is disallowed except for software that has been explicitly allowed. Any file that you want to open has to have a software restriction policies rule that allows it to open.

To protect administrators from locking themselves out of the system, when the default security level is set to Disallowed, four registry path rules are automatically created. You can delete or modify these registry path rules; however, this is not recommended.

For more information, see Setting the default security level to Disallowed.

For best security, use access control lists in conjunction with software restriction policies.

Users might try to circumvent software restriction policies by renaming or moving disallowed files or by overwriting unrestricted files. As a result, it is recommended that you use access control lists (ACLs) to deny users the access necessary to perform these tasks. For information about access control, see Access control.

Test new policy settings thoroughly in test environments before applying the policy settings to your domain.

New policy settings might act differently than originally expected. Testing diminishes the chance of encountering a problem when you deploy policy settings across your network.

You can set up a test domain, separate from your organization's domain, in which to test new policy settings. You can also test the policy settings by creating a test GPO and linking it to a test organizational unit. When you have thoroughly tested the policy settings with test users, you can link the test GPO to your domain.

Do not set programs or files to Disallowed without testing to see what the effect may be. Restrictions on certain files can seriously affect the operation of your computer or network.

Information that is entered incorrectly or typing mistakes can result in a policy setting that does not perform as expected. Testing new policy settings before applying them can prevent unexpected behavior.

Filter user policy settings based on membership in security groups.

You can specify users or groups for which you do not want a policy setting to apply by clearing the Apply Group Policy and Read check boxes, which are located on the Security tab of the properties dialog box for the GPO.

When the Read permission is denied, the policy setting is not downloaded by the computer. As a result, less bandwidth is consumed by downloading unnecessary policy settings, which enables the network to function more quickly. To deny the Read permission, select Deny for the Read check box, which is located on the Security tab of the properties dialog box for the GPO.

For more information, see Group Policy.

Do not link to a GPO in another domain or site.

Linking to a GPO in another domain or site can result in poor performance.

Link to comment
Share on other sites

Thanks!

What I have done so far is create a new organizational unit, then I created a new user group inside of it, and I added myself to this group. then I created a Group Policy object for this OU, and i put two things in this GPO: I disabled the ability for users to change thier home page and I remove the help menu from start/ programs. All of this was quite easy, and I liked felt good because I didn't have to mess with the entire domain, I can disable the GPO if I want, and I only affect myself. there's just one little problem, it doesn't work. :blink:

I dont know why yet. It all seems right. I'm not sure if I have to re-log in, or wait a while, or what??? I am a system admin, so maybe that overrides it. I will keep you posted if I figure it out.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy