Unit 9 ITT TECHNICAL INSTITUTE NT1330 Client-Server Networking II Date: 2/17/2016 Instructor: Williams Obinkyereh.

Slides:



Advertisements
Similar presentations
Lesson 17: Configuring Security Policies
Advertisements

Understanding Group Policy on Windows Server 2003 Michael J. Murphy TechNet Presenter
Module 5: Creating and Configuring Group Policy
Khan Rashid Lesson 11-The Best Policy: Managing Computers and Users Through Group Policy.
Managing User Settings with Group Policy
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
11.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
10.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 9: Implementing and Using Group Policy.
Lesson 18: Configuring Application Restriction Policies
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
Performing Software Installation with Group Policy
Guide to MCSE , Enhanced 1 Activity 9-1: Creating a Group Policy Object Using the MMC Objective: To create a GPO using the Group Policy Object Editor.
Deploying and Managing Software by Using Group Policy.
9.1 © 2004 Pearson Education, Inc. Lesson 9: Implementing Group Policy in Windows 2000 Server Exam Microsoft® Windows® 2000 Directory Services Infrastructure.
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 3: Introducing Active Directory.
Week 6 - Implement Group Policy
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory Chapter 12: Deploying and Managing Software with Group Policy.
Section 2: Using Group Policy Management Tools Local vs. Domain Policies Editing Local Policies Managing Domain Policies Understanding Group Policy Refresh.
Section 10: Assigning and Publishing Software Packages Using MSI Packages to Distribute Software Using Group Policy as a Software Deployment Method Deploying.
Module 15: Manage the Windows ® Small Business Server 2008 Environment Using Group Policy.
70-411: Administering Windows Server 2012
11 MANAGING AND DISTRIBUTING SOFTWARE BY USING GROUP POLICY Chapter 5.
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
Managing User Desktops with Group Policy
CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
Module 6: Implementing Group Policy. Overview Implementing Group Policy Objects Implementing GPOs in a Domain Managing the Deployment of Group Policy.
Introduction to Microsoft Management Console (MMC) MMC is a common console framework for management applications. MMC provides a common environment for.
Performing Software Installation with Group Policy Lesson 9.
1 Chapter Overview Publishing Resources in Active Directory Service Redirecting Folders Using Group Policies Deploying Applications Using Group Policies.
Module 6: Configuring User Environments Using Group Policy.
Module 7: Managing the User Environment by Using Group Policy.
Module 7 Configure User and Computer Environments By Using Group Policy.
Performing Software Installation with Group Policy BAI516.
Planning a Group Policy Management and Implementation Strategy Lesson 10.
Section 11: Implementing Software Restriction Policies and AppLocker What Is a Software Restriction Policy? Creating a Software Restriction Policy Using.
Module 5: Implementing Group Policy
Troubleshooting Security Issues Lesson 6. Skills Matrix Technology SkillObjective Domain SkillDomain # Monitoring and Troubleshooting with Event Viewer.
Module 6: Deploying and Managing Software by Using Group Policy.
Section 4: Understanding the Architecture of Group Policy Processing Group Policy Components in AD DS Understanding the Group Policy Processing Sequence.
Module 4 Planning for Group Policy. Module Overview Planning Group Policy Application Planning Group Policy Processing Planning the Management of Group.
1 Group Policies (Week 11, Monday 3/19/2007) © Abdou Illia, Spring 2007.
1 Chapter Overview Managing Object and Container Permissions Locating and Moving Active Directory Objects Delegating Control Troubleshooting Active Directory.
Administering Group Policy Chapter Eleven. Exam Objectives in this Chapter  Plan a Group Policy strategy using Resultant Set of Policy Planning mode.
Deploying Software with Group Policy Chapter Twelve.
Company Confidential 1 A Course on Planning A Group Policy Management And Implementation Strategy Prepared for: *Stars* New Horizons Certified Professional.
11 PLANNING A GROUP POLICY MANAGEMENT AND IMPLEMENTATION STRATEGY Chapter 10.
Module 6: Configuring User Environments Using Group Policies.
Lesson 6: Controlling Access to Local Hardware and Applications
10.1 © 2004 Pearson Education, Inc. Lesson 10: Specifying Group Policy Settings Exam Microsoft® Windows® 2000 Directory Services Infrastructure.
Unit 7 ITT TECHNICAL INSTITUTE NT1330 Client-Server Networking II Date: 2/3/2016 Instructor: Williams Obinkyereh.
Module 9: Using Group Policy to Manage Software. Overview Introduction to Managing Software Deployment Windows Installer Deploying Software Configuring.
GROUP POLICY. Group Policy is a hierarchical infrastructure which allows systems administrators to configure computer and user settings from a central.
Unit 10 ITT TECHNICAL INSTITUTE NT1330 Client-Server Networking II Date: 2/24/2016 Instructor: Williams Obinkyereh.
Unit 8 NT1330 Client-Server Networking II Date: 2?10/2016
1.1 Microsoft® Windows® 2003 Server Group Policy Management Prof. Abdul Hameed.
Managing User Desktops with Group Policy
MANAGING SOFTWARE Chapter 9
Unit 10 NT1330 Client-Server Networking II Date: 8/16/2016
Unit 8 NT1330 Client-Server Networking II Date: 8/2/2016
Unit 7 NT1330 Client-Server Networking II Date: 7/26/2016
Planning a Group Policy Management and Implementation Strategy
Chapter 9 MANAGING SOFTWARE.
Chapter 10: Supporting and Maintaining Desktop Applications
Unit 9 NT1330 Client-Server Networking II Date: 8/9/2016
Planning a Group Policy Management and Implementation Strategy
Unit 6 NT1330 Client-Server Networking II Date: 7/19/2016
Presentation transcript:

Unit 9 ITT TECHNICAL INSTITUTE NT1330 Client-Server Networking II Date: 2/17/2016 Instructor: Williams Obinkyereh

Class Agenda 1 Learning Objectives Lesson Presentation, Discussions and video. Assignments and Lab Activities. Break Times as per School regulation Note: Submit all Assignment and labs due today.

Class Agenda 2 Theory : Unit 8:00pm-8:00pm) Lab : (8:15pm to 11:00pm) Text book for Unit 9: Windows Server 2008 Active Directory Configuration MOAC Lesson 9 and 10

Performing Software Installation with Group Policy, Planning Group Policy Lesson 9 and 10

Objectives Manage Software through Group Policy. Install Software with Group Policy. Manage Group Policy. Filter Group Policy Scope. Determine information needed to develop an implementation scenario. Recommend an approach for installing software.

Managing Software through Group Policy Group Policy can be used to install, upgrade, patch, or remove software applications. Group Policy can be used to fix problems associated with applications. For example, if a user inadvertently deletes a file from an application, Group Policy can be used to launch a repair process that will fix the application.

.MSI File Microsoft Windows Server 2008 uses the Windows Installer with Group Policy to install and manage software that is packaged into an.msi file. –The Windows Installer Service, responsible for automating the installation and configuration of the designated software. –The Windows Installer Service requires a package file (.msi file) that contains all of the pertinent information about the software.

MSI File The.msi file: –Is a relational database file that is copied to the target computer system with the program files it deploys. –Assists in the self-healing process for damaged applications and clean application removal. –Consists of external source files that may be required for the installation or removal of software. –Includes summary information about the software and the package. –Includes reference point to the path where the installation files are located.

.MST File You may need to modify Windows Installer files to better suit the needs of your corporate network. Modifications to.msi files require transform files, which have an.mst extension.

Patch file (.msp) Windows Installer files with the.msp extension serve as patch files. Patch files are used to apply service packs and hot fixes to installed software. For this reason,.msp files should be located in the same folder as the original.msi file when you want the patch to be applied as part of the Group Policy software installation. This allows the patch file to be applied to the original package or.msi file.

ZAP File When repackaging an application is not an option and a Windows Installer file is not available, you can use a.zap file to publish an application. A.zap file is a non–Windows Installer package that can be created in a text editor. The disadvantages of creating.zap files are as follows: –They can be published, but not assigned. –Deployments require user intervention, instead of being fully unattended. –Local administrator permissions might be required to perform the installation. –They do not support custom installations or automatic repair. –They do not support the removal of applications that are no longer needed or applications that failed to install properly.

Software Distribution Point Before deploying software using Group Policy, you must create a distribution share/Software distribution point. Users who are affected by the Group Policy assignment should be assigned NTFS Read permission to the folder containing the application and package files.

Assigning and Publishing Software Assigning Software –If you assign the program to a user, it is installed when the user logs on to the computer. –If you assign the program to a computer, it is installed when the computer starts, and it is available to all users who log on to the computer. –When a user first runs the program, the installation is finalized. Publishing Software –You can publish a program distribution to users. –When the user logs on to the computer, the published program is displayed in the Add or Remove Programs dialog box, and it can be installed from there.

Assigning and Publishing Software

Software Restrictions Policies Provide organizations greater control in preventing potentially dangerous applications from running. Software restriction policies are designed to identify software and control its execution. Administrators can control who will be affected by the policies.

Software Restrictions Policies

When considering the use of software restriction policies, you must determine your approach to enforcing restrictions. The three basic strategies for enforcing restrictions are: –Unrestricted. This allows all applications to run except those that are specifically excluded. –Disallowed. This prevents all applications from running except those that are specifically allowed. –Basic User. This prevents any application from running that requires administrative rights, but allows programs to run that only require resources that are accessible by normal users. By default, the Software Restriction Policies area has an Unrestricted value in the Default Security Level setting.

Software Restrictions Policies Four types of software restriction rules can be used to govern which programs can or cannot run on your network: –Hash rule –Certificate rule –Path rule –Network zone rule

Group Policy Management Console The Group Policy Management MMC snap-in is a tool for managing Windows Server 2008, Windows Server 2003, and Windows 2000 Active Directory domains..

Group Policy Management Console Group Policy Management Console is used to: Import and copy GPO settings to and from the file system. Backup and restoration of GPOs is available in Group Policy Management. Search for GPOs based on name, permissions, Search for individual settings within a GPO by keyword

Group Policy Management Console

Managing an Individual GPO The following features are available when a GPO is selected in the Group Policy Management interface: –Scope –Details –Settings –Delegation

Management interface Scope: Allows administrators to view the locations to which the policy is linked. Detail: Allows the GPO to be enabled or disabled. Setting: When activated, an HTML report is generated that allows administrators to view GPO settings that do not have the original default values. Delegation: Is used to delegate security in ACL

Scope

Detail

Settings When this tab is activated, an HTML report is generated that allows administrators to view GPO settings that do not have the original default values. Links on the right side of the report allow detailed information to be displayed or hidden. Right-clicking within this view allows administrators to print or save the report.

Settings

Windows Management Instrumentation (WMI) A component of the Microsoft Windows operating system that provides management information and control in an enterprise environment. It allows administrators to create queries based on hardware, software, operating systems, and services. These queries can be used to gather data or to determine where items, such as GPOs, will be applied. WMI filters can be used to control which users or computers will be affected by a GPO based on defined criteria.

Unit 8 Assignments and Labs Unit 9. Assignment 1. GPO Planning Scenario Unit 9. Lab 1. Software Distribution and Controlling Group Policy Unit 9. Exercise 1. Research Software Deployment Options