Showing posts with label Group Policy FAQ. Show all posts
Showing posts with label Group Policy FAQ. Show all posts

Group Policy FAQ -5

5. What settings are not updated during a Background Group Policy Refresh?

Most Group Policy extensions are processed during a background refresh, however two are not:

  • Folder Redirection
  • Software Installation Policies


Both of these extensions are only processed during computer start-up and user logon, application of these policies during a users logon session may produce undesired results. For example, should a Software Installation Policy apply whilst a user is logged on, it is possible that a user could be using an application that this policy will try to upgrade or uninstall. This is not great for the user should their application stop working while they’re still using it!

Some additional information on configuring Folder Redirection processing on Windows XP can be found on this page.

Tags: Group policy, Group policy Editor, Group policy object, group policy object editor, group policy management console, Group policy commands, Group policy in windows 2003, Group policy in vista, Group policy in windows vista, Group policy settings, Group policy tools, Group policy in windows xp, Group policy viewer, Group policy view, Group policy software, Group policy monitoring, Group policy chaning, group policy change homepage, group policy settings not applying

Group Policy FAQ -4

4. How can I configure Group Policy Refresh?

Group Policy Objects apply at Computer Start-up and User Logon (known as foreground Refresh). In addition to this, Group Policy Client Site Extension (CSEs) also applies in the background at default intervals, so in most cases there is no need to wait for reboots or user logoffs to apply new settings.

Group Policy Refresh is configurable using the Group Policy Management Console/Group Policy Editor. The Group Policy settings are stored in Computer Configuration/Administrative Templates/System/Group Policy. You can adjust the interval in which clients apply GPO and what is applied during the refresh.

The Group Policy refresh interval is fully configurable for Computers and Domain Controllers, a default value is set to 90 minutes for Computers and 5 minutes for Domain Controllers.

  • To adjust this setting on computers (anything other than Domain Controllers) open the GPMC and edit the Group Policy Object that will be applied to all client objects. Open the path mentioned above and change the Group Policy refresh interval for computers.
  • To adjust this setting on Domain Controllers open the GPMC and edit the Default Domain Controllers Policy (this is a standard GPO). Open the path mentioned above and change the Group Policy refresh interval for Domain Controllers.


You should take into consideration the overhead this will have on the network and other infrastructure by reducing this refresh interval. For example reducing the refresh interval to every few minutes will have an impact on your infrastructure as the client has to contact a domain controller each time a Group Policy Refresh is triggered. So far, we found no reason to alter the default settings.

You can also turn off background processing altogether using the Turn off background refresh of Group Policy. This could be helpful in situations where enforcing settings in the background may interrupt or affect a running application, in this case you might only want to enforce policy settings when the computer restarts and the user logs on.

Tags: Group policy, Group policy Editor, Group policy object, group policy object editor, group policy management console, Group policy commands, Group policy in windows 2003, Group policy in vista, Group policy in windows vista, Group policy settings, Group policy tools, Group policy in windows xp, Group policy viewer, Group policy view, Group policy software, Group policy monitoring, Group policy chaning, group policy change homepage, group policy settings not applying

Group Policy FAQ -3

3. What should I consider when deploying Group Policy?

This will vary depending on your delegation and organisation requirements, however some common pointers are

  • Use the Default Domain Policy solely for Domain Account Policy settings, remember all settings in this policy are applied to all Users and Computers in the domain so you should limit the amount settings made in this GPO
  • Use OUs to group computer objects that will share the same configuration, an example would be to separate Clients from Servers
  • Use OUs to group user objects that will share the same configuration, an example would be to separate Admins from Standard Users
  • Make sure you allow for exceptions to the standard configurations you are applying
  • Think about how you will implement group based filtering to further define the scope of a GPO
  • Think about how you will implement WMI based filtering to further define the scope
  • Take care in your design to reduce or eliminate altogether the use of ‘No Override’ and ‘Block Inheritance’
  • Define a standard and descriptive Naming Convention for your GPOs

The following white paper will assist you further in your planning your deployment:

http://www.microsoft.com/downloads/details.aspx?familyid=3ada804c-ba20-479d-9014-8f29427f3d96&displaylang=en


Tags: Group policy, Group policy Editor, Group policy object, group policy object editor, group policy management console, Group policy commands, Group policy in windows 2003, Group policy in vista, Group policy in windows vista, Group policy settings, Group policy tools, Group policy in windows xp, Group policy viewer, Group policy view, Group policy software, Group policy monitoring, Group policy chaning, group policy change homepage, group policy settings not applying

Group Policy FAQ -2

2. What tools can I use to manage Group Policy?

With the original release of Windows 2000 Active Directory Microsoft provided us with the Group Policy Editor and ADUC, this did not fullfill the requirements, especially in medium to large enterprise environments where GPO soon became to difficult to manage using the provided tools.

So Microsoft (and other third parties) produced tools to help manage GPO. Some of the better known tools include:


Tags: Group policy, Group policy Editor, Group policy object, group policy object editor, group policy management console, Group policy commands, Group policy in windows 2003, Group policy in vista, Group policy in windows vista, Group policy settings, Group policy tools, Group policy in windows xp, Group policy viewer, Group policy view, Group policy software, Group policy monitoring, Group policy chaning, group policy change homepage, group policy settings not applying

Group Policy FAQ -1

1. What is Group Policy?

Group Policy is an important and powerful feature included with Windows 2000 Active Directory. If you are familiar with System Policies in Windows NT you know that they had limitations, settings applied in the registry were sometimes difficult to reverse (known commonly as tattooing the registry) and it was near impossible to limit the scope of System Policies from applying to the entire domain (including Administrators and Servers).

Group Policy has very few of the limitations that System Policy had. Functionality has been provided for registry-based policy settings, security settings, software installation, scripts (computer start-up and shutdown, user logon and logoff), folder redirection, Software Distribution and can be extended to include more. Group Policy includes hundreds of settings that can be defined centrally by an administrator.

Group Policy is now much more scaleable using a variety of different methods to control the Group Policies that are applied and to which objects they are applied to, this is commonly known as Scope of Management (SOM). Group Policy Objects can be linked (applied) to groups of users or computers based on the Organisation Structure, all members of an OU for example would have the same GPO(s) applied. Group Policy Objects can also be applied based on the computers network location, for example all Computers in the same AD Site (a group of IP subnets) or from the Domain level.

As well as applying Group Policies at the Domain, AD Site and OU level, each Group Policy Object has an ACL so you can Apply or Deny Group Policy Objects based on a Users or Computers Group Membership, this is known as Group Filtering.

In addition to Group filtering, Microsoft introduced WMI filters in Windows 2003/Windows XP (See working with WMI Filters for more detail). WMI was made an integral part of the Windows 2000 (and then XP/2003) operating system and provides access to nearly every hardware and software object in the computing environment such as free disk space, total physical memory, network card configuration, hardware chassis type etc. Using a WMI Filter an Admin can ensure that only computers matching a specific criteria (for example “All computers running Windows XP”) will have a GPO applied.

As you can see, Group Policy is a very powerful and scaleable tool that can be used to help manage your clients, users and server environments from a central location.

Tags: Group policy, Group policy Editor, Group policy object, group policy object editor, group policy management console, Group policy commands, Group policy in windows 2003, Group policy in vista, Group policy in windows vista, Group policy settings, Group policy tools, Group policy in windows xp, Group policy viewer, Group policy view, Group policy software, Group policy monitoring, Group policy chaning, group policy change homepage, group policy settings not applying