Active Directory: OU Administration December 17th, 2008 1-4pm Daniels 407.

Slides:



Advertisements
Similar presentations
Auditing Microsoft Active Directory
Advertisements

Establishing an OU Hierarchy for Managing and Securing Clients Base design on business and IT needs Split hierarchy Separate user and computer OUs Simplifies.
Clyde G. Johnson.  Preference?  Overview  Targeting  Settings  Things to know  GPP Scenarios.
Microsoft Server 2008 R2 Group Policies & AD. Group Policies-Refresher  Policies are “all or nothing”  You cannot selectively choose within a policy.
Sandia is a multiprogram laboratory operated by Sandia Corporation, a Lockheed Martin Company, for the United States Department of Energy’s National Nuclear.
NREL is a national laboratory of the U.S. Department of Energy Office of Energy Efficiency and Renewable Energy operated by the Alliance for Sustainable.
Module 5: Creating and Configuring Group Policy
Managing User Settings with Group Policy
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
Group Policies (the day after) Group Policy Preferences Powershell.
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
MIS Chapter 91 Ch. 9 – Implement and Use Group Policy MIS 431 – created Spring 2006.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 9: Implementing and Using Group Policy.
Clyde G. Johnson.  Test Environment  Tools of the trade  Demo  Central Store  Show  Group Policy Spreadsheets  Demo  Planning and Deployment.
Lesson 16: Creating Group Policy Objects
Guide to MCSE , Enhanced 1 Activity 9-1: Creating a Group Policy Object Using the MMC Objective: To create a GPO using the Group Policy Object Editor.
OIT's Unity Labs Active Directory Windows Environment.
Module 8: Implementing Administrative Templates and Audit Policy.
Group Policy in Microsoft Windows Active Directory.
Understanding Group Policy on Windows Server 2003 John Howard, IT Pro Evangelist, Microsoft UK
Introduction to Active Directory December 10th, pm Daniels 407.
9.1 © 2004 Pearson Education, Inc. Lesson 9: Implementing Group Policy in Windows 2000 Server Exam Microsoft® Windows® 2000 Directory Services Infrastructure.
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
GROUP POLICY An overview of Microsoft Windows Group Policy.
Why use Group Policy? GROUP POLICIES ON SBS: WHY BOTHER? -Save yourself a lot of time - need to install a printer on 20-some computers? - adding a file.
Introduction to Group Policy
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
WolfTech Active Directory: OU Administration June 30th, pm Daniels 407.
Section 2: Using Group Policy Management Tools Local vs. Domain Policies Editing Local Policies Managing Domain Policies Understanding Group Policy Refresh.
Module 15: Manage the Windows ® Small Business Server 2008 Environment Using Group Policy.
Section 1: Introducing Group Policy What Is Group Policy? Group Policy Scenarios New Group Policy Features Introduced with Windows Server 2008 and Windows.
70-411: Administering Windows Server 2012
Managing User Desktops with Group Policy
More GPO’s & GPP Chapter 7. Agenda Group Policies (the day after) Group Policy Preferences.
CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
Module 6: Implementing Group Policy. Overview Implementing Group Policy Objects Implementing GPOs in a Domain Managing the Deployment of Group Policy.
Module 6: Configuring User Environments Using Group Policy.
Module 7: Managing the User Environment by Using Group Policy.
Module 7 Configure User and Computer Environments By Using Group Policy.
Planning a Group Policy Management and Implementation Strategy Lesson 10.
GPO - WINDOWS SERVER AGENDA: Introduction Group Policy Overview Types of Group Policies/Objects Associated Technologies How to implement.
4. Managing the Desktop Thomas Lee Chief Technologist – QA plc.
Labs. Lab Session 1: Administering Windows Server 2008 Exercise 1: Install the DNS Server Role Exercise 2: Configuring Remote Desktop for Administration.
Section 11: Implementing Software Restriction Policies and AppLocker What Is a Software Restriction Policy? Creating a Software Restriction Policy Using.
Module 5: Implementing Group Policy
Section 4: Understanding the Architecture of Group Policy Processing Group Policy Components in AD DS Understanding the Group Policy Processing Sequence.
Active Directory Group Policy. Group Policy Overview  Successor to NT policies Much more flexible  Only applies to 2000 workstations Use old style policies.
CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
Module 5: Creating and Configuring Group Policies.
Module 4 Planning for Group Policy. Module Overview Planning Group Policy Application Planning Group Policy Processing Planning the Management of Group.
How to implement GPOs and secure a MS Windows Environment with little to NO user awareness!?!?
Administering Group Policy Chapter Eleven. Exam Objectives in this Chapter  Plan a Group Policy strategy using Resultant Set of Policy Planning mode.
Company Confidential 1 A Course on Planning A Group Policy Management And Implementation Strategy Prepared for: *Stars* New Horizons Certified Professional.
Implementing Group Policy
11 PLANNING A GROUP POLICY MANAGEMENT AND IMPLEMENTATION STRATEGY Chapter 10.
Week 4 Objectives Overview of Group Policy Group Policy Processing Implementing a Central Store for Administrative Templates.
Implementing a Group Policy Infrastructure
Module 10: Implementing Administrative Templates and Audit Policy.
Module 6 Creating and Configuring Group Policy. Module Overview Overview of Group Policy Configuring the Scope of Group Policy Objects Evaluating the.
Chapter 7: Managing and Troubleshooting Group Policy.
11 DESIGNING AN ADMINISTRATIVE SECURITY STRUCTURE Chapter 7.
GROUP POLICY. Group Policy is a hierarchical infrastructure which allows systems administrators to configure computer and user settings from a central.
1.1 Microsoft® Windows® 2003 Server Group Policy Management Prof. Abdul Hameed.
Module 8: Implementing Group Policy. Overview Multimedia: Introduction to Group Policy Implementing Group Policy Objects Implementing GPOs on a Domain.
Introduction to Group Policy Lesson 7. Group Policy Group Policy is a method of controlling settings across your network. – Group Policy consists of user.
Windows Enterprise Services.  Introductions  UNM Directory Services  RSAT  Organizational Units (OU)  Active Directory Groups  Naming Convention.
Managing User Desktops with Group Policy
Windows Server 2008 Administration
Introduction to Group Policy
Planning a Group Policy Management and Implementation Strategy
Presentation transcript:

Active Directory: OU Administration December 17th, pm Daniels 407

Workflow 1.Get your house in order: o DNS needs to be accurate o asset tracking needs to be accurate 2.Create or Join a domain? o How are you going to handle Account creation? Do you need student accounts? o Do you need to access campus resources? Wolfcopy? ACS Q: drive? 3.Design OU Layout o Types of Users o Types of computers o Logical Units 4.Implement Management Policies o Who can login where? o What level of permissions should they have on each type of machine? o Do you need to deploy Mapped Drives, Scripts, or Printers? 5.Setup Software Deployment Strategy o Who can install their own software on what machines? o What software packages need to be automated? 6.Migrate Current Machines o Reinstall or Join? o Pre-Staging Computer Objects o Do you include Mac/Linux machines? 7.New Machine/Reinstallation strategy o WDS 8.What other services will you need to provide?

Tools Remote Server Administration Tools (RSAT) o Vista SP1 / 2008 version of AdminPak o Only way to access Group Policy Preferences o Includes all added functionality from 2003 R2 ShellRunas - Run as different Domain User for Vista o Do not do administration with normal unity account GPMC - Included in Vista o VBScripts in XP version for doing GPO Scripting SpecOps GPUpdate - Extension for ADUC Scripting: VBScript/PowerShell

OU Layout Single User o Faculty - Individual login, local admin o Staff - Individual or group login, no local admin o Grad Students - Group login, no student admin, Faculty admin Labs o Teaching Labs - college or class login, user rights o Public Labs - any account login (or college), user rights o Research Labs - Group login, user rights Stand Alone o Kiosks - no login, extremely locked down o Conference Rooms - any account login o Loaner machines Servers Macs? Linux boxes?

OU Layout (continued) Favor an overly-hierarchical layout rather than a flat layout Allows for easier targeting of GPO's Follows a more logical structure for support Its harder to move from Flat->Hierarchical than vise-versa College \Department \Machine Type \Group1 \Group2 Examples!

Grouping Creating lots of groups up front will ease administration when change requests are needed. It is better to have a group and not use it, than need a group and not have one. Always use groups for delegating permissions. Groups by User Directory Info: Faculty/Staff/Student Group by Machine Use: Public Lab/Teaching Lab/Kiosk/Server Group by Machine type: Laptop/Desktop Group by administrative access: Server Admins/Lab Admins Groups for Application Deployment Groups for printer deployment

Group Policy Creating: How to copy a GPO GPO Permissions Starter GPO's Filtering: Linking Groups WMI Deny permission? Enforced vs. Blocking Inheritance Loopback - Replace vs. Merge GPO's are applied to an object starting at the root of the domain and overlaid as you get closer to the object. GPMC: Group Policy Results/Group Policy Modelling

Group Policy (continued) Some "best practices": Naming Conventions are a must Be descriptive GPO's that provide access to a resource should be linked at the highest level that is administratively feasible. "Deny" permissions on GPO's should be used with care WMI filtering on specific versions of software usually doesn't get updated. Use WMI filters for OS, and Item-Level targeting in GPP for everything else you can. If you find yourself creating alot of GPO's to solve a single problem, you are doing something wrong. Always do a "gpupdate" rather than relying on reboots when doing testing of new GPO settings.

Policies/Preferences Policies: Software Deployment Scripts Security Settings o Restricted Groups o User Rights assignment o Machine Permissions (Filesystem, Registry, Services) o Software restriction Administrative Templates o Firewall - no spaces in comma separated lists! o Windows Update, IE, desktop environment, etc. Preferences: Mapped Drives Power Settings Distributing individual files, registry keys, shortcuts Item-Level Targeting

Print Setup with GPOs Using group policies, you can deploy, change, and remove printers from computers grouped together into an OU You will need administrative rights over the OU, and a workstation with the GPMC and print management plugins installed. workstation with the GPMC and print management plugins installed

Deploying the printers DO NOT use the Group Policy Management Console to deploy printers. Printers can be successfully delivered when set up from GPMC, but they will not be successfully removed from workstations when they are disassociated from the policy. Instead, you should FIRST create and link an empty policy to the OU where you wish the printer deployed, then associate it with the "Printer Management Console"

Installing printers with scripts Traditionally (prior to R2) printers are installed with scripts. Tons of VB and Powershell (and Perl) examples on the web. The "rundll32.exe" allows you to call functions in a DLL from the command line. All GUI print tasks can be performed with rundll32. For on-line reference, rundll32 printui.dll,PrintUIEntry /?

Scenarios What are some problems that you need to solve?

Q & A