Re: Planning A Group Policy Deployment

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Edward,

I get the impression that you are so-to-speak being blinded by the
trees and failing to view the forest from overlooks in the terrain.

GP usage aims to facilitate management of computers and of
users when using those computers.

So, first one needs to decide what aspects one wants to manage,
and rank these as to their importance. Think functionally. Do not
at this point think about what is available in the thousand and a half
odd some policies that can be set. The 900 you mention is a pre-
Vista number and also is only the policy settings available in the
administrative templates.

For examples: make machines accessible to only valid users,
make machines silent on the network, have login scripts for
users based on their user category, make sure all machines are
using correct DNS servers, etc. List out what are you major and
minor management objectives. Then see what GPOs have that
let you accomplish those objectives.

Now, granted, there is a chicken/egg aspect, and while I am saying
to emphasize a functional use case specification first, as one does
get more familiar with GP capabilities and shortfalls those will also
come into the picture early on, influencing what you spec as the major
and minor management objectives. However, starting at the other end,
the individual policy settings, is not the way to approach the issue.

Roger


"Edward" <Edward@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:4F53B770-C8A2-4C24-B50E-2CF26C48A13D@xxxxxxxxxxxxxxxx
I'd like to start a thread concerning the high level planning for Group
Policy deployment. In my particular situation I have been given the
responsibility for deploying Group Policy (and AD) at a high school.
While
there is a blizzard of information about GP, it is all referential - what
does this do, what does it effect, etc. I'm looking for a level 200 or
300
discussion about the process.

For example - there are over 900 group policies in the W2k3 excel
spreadsheet reference. Trying to deploy all or most all at once is
obviously
silly. There must be some kind of rational, phased process for deploying
these. Such a process, I would think, always, or nearly always, should be
begin with some particular subset of policies, ie, Internet Explorer or
Desktop or Restricted Software. Another subset would almost always be
second, and third, and so on.

I've never seen the process covered by any of the documentation provided
by
Microsoft, except in the most general way (Design AD, Design OU's, Create
the
test environment, etc.). This is not what I'm refering to.

Anyone have a step 1 though n for the policies themselves?


.



Relevant Pages

  • RE: protect MS Windows 95/98/Me
    ... Just remember, when using poledit.exe, the System Policy MUST be created ... on the OS in which you want to run policy settings. ... settings affected by group policies. ... Incoming mail is certified Virus Free. ...
    (Security-Basics)
  • Analysing and configuring IPS/IDS Policies
    ... I am currently in the process of implementing an IPS at a client site. ... There are various approaches to deploying policies from ground up and ... We analyse alerts observed on the allowed protocols and create ... alerts and deploying policies. ...
    (Focus-IDS)
  • Re: Domain logon without network connection + group policies
    ... Information Security Analyst ... This provides false security when deploying policies that restrict ... not the intended recipient, you are hereby notified that any review, retransmission, dissemination, ...
    (Focus-Microsoft)
  • Re: Behaviour of Existing Passwords After Policy Changes
    ... the policy settings are only evaluated when a password is written into the ADDB ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... Always test ANY suggestion in a test environment before implementing! ... What happens to users when password policies are made more complex and their ...
    (microsoft.public.windows.server.active_directory)
  • Domain logon without network connection + group policies
    ... network connection and bypass the group policies. ... This provides false security when deploying policies that restrict ...
    (Focus-Microsoft)