dennis99 Posted March 14, 2005 Report Share Posted March 14, 2005 I created a new group policy object, and I want to do something with it. I need ideas on things that might be useful and that would not be risking disruption to my domain. For instance it would be nice to force users to do windows update. Thx Quote Link to comment Share on other sites More sharing options...
bu6z Posted March 15, 2005 Report Share Posted March 15, 2005 Force users to do windows update ?Hey Dennis, you can use SUS (Software Update Server) from Microsoft and install it on any Server that you have. And then you can create a new GPO that linked to your domain.Locate to :Computer Configuration > Administrative Templates > Windows Components > Windows UpdateThen you have to :- Enable Configure Automatic Updates for the specific time- Specify the full URL of your SUS Server- Schedule the automatic installation- etcAnd make sure that you can synchronize your SUS Server to Microsoft Update Website.Cheers.... Quote Link to comment Share on other sites More sharing options...
homecomputeraid Posted March 18, 2005 Report Share Posted March 18, 2005 I think the replacement for Software Update Service is Windows Update Services which is still in Beta. You could download SUS Server, or WUS Server Beta and give them a try. Quote Link to comment Share on other sites More sharing options...
dennis99 Posted March 21, 2005 Author Report Share Posted March 21, 2005 I have created a group policy object. How do I apply it to just one user or group of users? thanksI've brought your post to this thread dennis99 to keep them together. Makes it easier for those trying to help. :) Quote Link to comment Share on other sites More sharing options...
homecomputeraid Posted March 22, 2005 Report Share Posted March 22, 2005 Windows 2000 or 2003? Quote Link to comment Share on other sites More sharing options...
dennis99 Posted March 22, 2005 Author Report Share Posted March 22, 2005 2003, sorry. Quote Link to comment Share on other sites More sharing options...
homecomputeraid Posted March 22, 2005 Report Share Posted March 22, 2005 I'll have to check when I get home Dennis. I'm helping someone with come PC problems after work, so if I don't get to it tonight, I'll try tomorrow. I want to give you a step-by-step, and all I have access to right now are 2000 Servers.In the mean time, Microsoft's site has some very good free tutorials like this one: Applying security settings that may help. You could try searching Microsoft's site, or searching for what you're trying to do on Google and picking the applicable Microsft site too. Quote Link to comment Share on other sites More sharing options...
dennis99 Posted March 24, 2005 Author Report Share Posted March 24, 2005 Any luck Ted? Quote Link to comment Share on other sites More sharing options...
homecomputeraid Posted March 24, 2005 Report Share Posted March 24, 2005 Sorry,No time for a step-by-step right now. I worked on someone's PC that's down last night, and I'm working tonight and tomorrow and probably 1/2 day Saturday.Have you tried the M$ article? Quote Link to comment Share on other sites More sharing options...
dennis99 Posted March 28, 2005 Author Report Share Posted March 28, 2005 yea, i don't see the answer in there. Quote Link to comment Share on other sites More sharing options...
homecomputeraid Posted March 28, 2005 Report Share Posted March 28, 2005 I'll try to post something tonight Dennis. Anything in particular you're trying to accomplish with the policy? Quote Link to comment Share on other sites More sharing options...
homecomputeraid Posted March 29, 2005 Report Share Posted March 29, 2005 Dennis,I'll post a generic group policy and application of that policy tonight. Windows 2003 has some excellent help built into it too which might give you specifics about what you're trying to do. Quote Link to comment Share on other sites More sharing options...
nellie2 Posted March 29, 2005 Report Share Posted March 29, 2005 I think dennis99 hit the wrong button when he last posted .... we all do it! :blush: This was the report I gotthanks! :) Quote Link to comment Share on other sites More sharing options...
homecomputeraid Posted March 30, 2005 Report Share Posted March 30, 2005 Please use extreme caution doing this! Do some learning and implement things in a small test environment first. If you make the wrong change using a domain-wide group policy you could, for example, lock yourself out of all PC's on your network!I liken what we're doing here to joining a mechanic's forum and saying how do I change a piston in eight easy steps. Step 1, Learn a lot more about engines![edit]I don't mean to be condescending or demeaning in any way here Dennis. I'm trying to impress upon you how much trouble can ensue if you don't do quite a bit of background reading and testing before implementing policies.Here's an example from the Windows 2003 Help Files for setting an audit policy:For a domain or organizational unit, when you are on a member server or on a workstation that is joined to a domain Open Microsoft Management Console (MMC). [edit]Click on Start, Run and type in mmc then hit EnterIn the File menu, click Add/Remove Snap-in, and then click Add. Click Group Policy Object Editor, and then click Add. On the Select Group Policy Object page in the Group Policy Wizard, click Browse. In Browse for a Group Policy Object, select a Group Policy object (GPO) in the appropriate domain, site, or organizational unit—or create a new one, click OK, and then click Finish. Click Close, and then click OK. In the console tree, click Audit Policy. Computer Configuration Windows Settings Security Settings Local Policies Audit Policy In the details pane, double-click an event category that you want to change the auditing policy settings for. If you are defining auditing policy settings for this event category for the first time, select the Define these policy settings check box. Do one or both of the following, and then click OK. To audit successful attempts, select the Success check box. To audit unsuccessful attempts, select the Failure check box.To perform this procedure, you must be a member of the Domain Admins group or the Enterprise Admins group in Active Directory, or you must have been delegated the appropriate authority. As a security best practice, consider using Run as to perform this procedure. To open Microsoft Management Console, click Start, click Run, type mmc, and then click OK. To audit object accesses, enable auditing of the object access event category by following the steps above. Then, enable auditing on the specific object. For information about how to enable auditing on an object, see "Apply or modify auditing policy settings for a local file or folder" or "Apply or modify auditing policy settings for an object using Group Policy" in Related Topics. After your audit policy is configured, events will be recorded in the security log. Open the security log to view these events. For information about the security log, see "Use the security log" in Related Topics. The default auditing policy setting for domain controllers is No Auditing. This means that even if auditing is enabled in the domain, the domain controllers do not inherit auditing policy locally. If you want domain auditing policy to apply to domain controllers, you must modify this policy setting. Here's another help message about modifying default domain policies. Don't do it!Best practicesDo not modify the default domain policy.If you do not edit the default domain policy, you always have the option of reapplying the default domain policy if something goes wrong with your customized domain policy. Create a separate Group Policy object for software restriction policies.If you create a separate Group Policy object (GPO) for software restriction policies, you can disable software restriction policies in an emergency without disabling the rest of your domain policy. For more information, see Group Policy.If you experience problems with applied policy settings, restart Windows in Safe Mode.Software restriction policies do not apply when Windows is started in Safe Mode. If you accidentally lock down a workstation with software restriction policies, restart the computer in Safe Mode, log on as a local administrator, modify the policy, run gpupdate, restart the computer, and then log on normally. For more information about restarting the computer in Safe Mode, see To start the computer in Safe Mode. For more information about gpupdate, see Gpupdate.Use caution when defining a default setting of Disallowed.When you define a default setting of Disallowed, all software is disallowed except for software that has been explicitly allowed. Any file that you want to open has to have a software restriction policies rule that allows it to open. To protect administrators from locking themselves out of the system, when the default security level is set to Disallowed, four registry path rules are automatically created. You can delete or modify these registry path rules; however, this is not recommended. For more information, see Setting the default security level to Disallowed.For best security, use access control lists in conjunction with software restriction policies.Users might try to circumvent software restriction policies by renaming or moving disallowed files or by overwriting unrestricted files. As a result, it is recommended that you use access control lists (ACLs) to deny users the access necessary to perform these tasks. For information about access control, see Access control. Test new policy settings thoroughly in test environments before applying the policy settings to your domain.New policy settings might act differently than originally expected. Testing diminishes the chance of encountering a problem when you deploy policy settings across your network. You can set up a test domain, separate from your organization's domain, in which to test new policy settings. You can also test the policy settings by creating a test GPO and linking it to a test organizational unit. When you have thoroughly tested the policy settings with test users, you can link the test GPO to your domain. Do not set programs or files to Disallowed without testing to see what the effect may be. Restrictions on certain files can seriously affect the operation of your computer or network. Information that is entered incorrectly or typing mistakes can result in a policy setting that does not perform as expected. Testing new policy settings before applying them can prevent unexpected behavior. Filter user policy settings based on membership in security groups.You can specify users or groups for which you do not want a policy setting to apply by clearing the Apply Group Policy and Read check boxes, which are located on the Security tab of the properties dialog box for the GPO. When the Read permission is denied, the policy setting is not downloaded by the computer. As a result, less bandwidth is consumed by downloading unnecessary policy settings, which enables the network to function more quickly. To deny the Read permission, select Deny for the Read check box, which is located on the Security tab of the properties dialog box for the GPO. For more information, see Group Policy.Do not link to a GPO in another domain or site.Linking to a GPO in another domain or site can result in poor performance. Quote Link to comment Share on other sites More sharing options...
dennis99 Posted March 30, 2005 Author Report Share Posted March 30, 2005 Thanks!What I have done so far is create a new organizational unit, then I created a new user group inside of it, and I added myself to this group. then I created a Group Policy object for this OU, and i put two things in this GPO: I disabled the ability for users to change thier home page and I remove the help menu from start/ programs. All of this was quite easy, and I liked felt good because I didn't have to mess with the entire domain, I can disable the GPO if I want, and I only affect myself. there's just one little problem, it doesn't work. :blink: I dont know why yet. It all seems right. I'm not sure if I have to re-log in, or wait a while, or what??? I am a system admin, so maybe that overrides it. I will keep you posted if I figure it out. Quote Link to comment Share on other sites More sharing options...
homecomputeraid Posted March 30, 2005 Report Share Posted March 30, 2005 It sounds like you're going down the right path Dennis. You might make a simple test user account with no special rights in the domain an dput that in your group to see whether it performs as you want it to. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.