Re: GPO Security Filtering VS OU Specific GPOs

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



My opinion is you have hit the edge of functionality trying to use AD for
software distribution; you need SMS.

If you can't afford that, then ACL's on GPO's is my bet.

As is said, an object can only be in 1 OU.

JamesR.

"Jim Willson" <JimWillson@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:1C4143CF-4AA2-4A91-857C-DF329FD9EDDD@xxxxxxxxxxxxxxxx
> Then how would you handle GPO's for software installations, for example?
> You
> certainly can't put a machine in multiple OUs so it gets Office, Acrobat
> Writer, and Pagemaker - so then what?
>
> Our AD structure is very simple at the moment. Looking forward though, I'd
> like to make the best decisions now for future expansion and utilization
> of
> AD. What I'd really like is a MS writeup about best practices for Enforce
> and
> Filtering. To be honest, I've seen the exact opposite advice posted online
> (Windows IT Pro, I think). The advice there was to keep your OU usage
> sparing, but use security filtering/no enfore to apply/not apply GPOs.
>
>
>
> "Wong Tuck Wah" wrote:
>
>> Guidelines from MS are always to minimise the use of Inheritance, Enforce
>> (no
>> overwrite) and Filtering.
>>
>> Extensive use of these methods will make troubleshooting GP problems
>> complicated and time consuming. It is always easier to create a new GPO
>> for
>> specific needs, if possible.
>>
>> In your case, create 2 OUs instead - one for laptop and the other for
>> desktop. Create another 2 GPOs, each for the specific OU. This will make
>> your
>> design lean and manageable.
>>
>> HTH.
>>


.



Relevant Pages

  • Re: GPO not working (yes, another post)
    ... What is not present in the screenshot is the individual property settings for the actual preference, which would be necessary to rule out problems such as item-level-targetting or user context problems. ... you undo a WMI filter that the wizard set, you may cause harm to your server as a setting is now getting applied to a server that never should be. ... Don't use WMI filters unless there is no other way to achieve the filtering you want. ... Since I work mostly with non-SBS servers, I don't completely agree with the way SBS links all of the default GPOs at the domain level and uses filtering to apply the objects. ...
    (microsoft.public.windows.server.sbs)
  • Re: Applying to Multiple Computers
    ... in the computer list to install it. ... "Security Groups" but I can't ever seem to see the group within Group Policy ... Using filtering creates additional overhead on each GPO - the ... GPOs the more overhead. ...
    (microsoft.public.windows.group_policy)
  • Re: ADM not pushed to OU
    ... The following GPOs were not applied because they were filtered out ... Filtering: Not Applied ... It is not an error message but an info that the GPO does not contain "interesting" settings for the object. ... It is still so that you have your ADM template file as a "CLASS MACHINE" and that dictates that it needs to be linked to a OU where machine accounts are in. ...
    (microsoft.public.windows.group_policy)
  • Re: Applying GPOs in a mixed 2000/XP desktop environment
    ... you don't have to have different GPOs to manage both platforms. ... WMI filtering does not work or apply to Windows 2000. ...
    (microsoft.public.windows.group_policy)