GPO/GPP Flashcards
Explain the principals of GPO/GPP
*GPO (Group Policy Object) Definition
- Set of config settings applied by a group policy admin to on or more objects in the AD store
- Admin defines the state of a user’s work environment and can rely on the local oper system or AD to enforce GP settings.
- GP Settings can be applied accross an entire org or to specific groups of users and computers
*GPO Benefits
- Reduce user error => disabling unessential features
- Enable admin to create personalized desktop
- Enable admin to increase sec (ex:prevention of installation of software)
- Improve user’s environment
*GPP (Group Policy Preferences)
- Set of extensions that increase functionality of GPOs
- These include advanced settings for folders, mapped drives and printers and are optional for the user or computer
- With GPP, admin can deploy and manage apps on client computers with configs for specific users
Benefit of Group Policy
(TCO)Reduce user error by disabling unessential features for users.
Enable an administrator to create personalized desktop
Enable an administrator to Increase security (ex: by preventing installation of software)
Enable to improve user’s environment
Group Policy Objects’ Scope
Group Policies are processed in the following order:
LOCAL computer Group Policy
Group Policy objects linked to the SITE
Group Policy objects linked to the DOMAIN
Group Policy objects linked to the OU
SCOPE: Group Policies can only be applied to sites, domains and OU
Domain-Based GPOs
Created in Active Directory, stored on domain controllers
Two default GPOs
Default Domain Policy:
-Affects all users and computers in the domain
-Define Account policies for the domain:
Password,
account lockout
and Kerberos policies
Defaul DCs - Policy
- Affects only domain controllers
- Define auditing policies for domain controllers and Active Directory
Block Policy inheritance
- when the administrator of an organizational unit must control all GPOs for that container
- Block Policy inheritance does not block the inheritance of a GPO linked to a parent container if the link is configured with the Enforced option