PC Review


Reply
Thread Tools Rate Thread

Best way to apply policy to all computers except servers

 
 
Deb H
Guest
Posts: n/a
 
      29th Jul 2008
Trying to decide what the best way to apply certain features such as event
log settings and other computer related GPO settings. Currently I have all
computers in their OUs designed by location. Should I also create a group and
add all computers to the group, then add group to a certain policy affecting
the event logs. Or should I adjust all the OUs?
 
Reply With Quote
 
 
 
 
Florian Frommherz [MVP]
Guest
Posts: n/a
 
      29th Jul 2008
Deb,

Deb H wrote:
> Trying to decide what the best way to apply certain features such as event
> log settings and other computer related GPO settings. Currently I have all
> computers in their OUs designed by location. Should I also create a group and
> add all computers to the group, then add group to a certain policy affecting
> the event logs. Or should I adjust all the OUs?


avoid security filtering (that is tweaking permissions on the Group
Policy) as far as you can. That slows down Group Policy application. If
possible, re-organize the OU structure so that you can create and add
your GPOs more easily or link the policy in question to multiple
locations in the hierachy.

cheers,

Florian
--
Microsoft MVP - Group Policy
eMail: prename [at] frickelsoft [dot] net.
blog: http://www.frickelsoft.net/blog.
Maillist (german): http://frickelsoft.net/cms/index.php?page=mailingliste
 
Reply With Quote
 
Barkley Bees
Guest
Posts: n/a
 
      30th Jul 2008
We have our OU structure setup as follows (simplified):

MAIN OU (Contains our client PC's and users)
--- SERVERS OU (Servers only under the Main OU)

The main OU has server Pollicies applied to it (Default domain policy,
Firewall, WSUS for clients, etc).
The Server OU has only two set for it (Remote Desktop setting and WSUS).

Yet, I can see from GPMC that the parent OU's Group Policies are being
inherited to the Server OU. Can I simply select 'block inheritance' to
prevent these unwanted ones from being applied (ie: Client Firewall, WSUS
for Clients)?


"Florian Frommherz [MVP]" <(E-Mail Removed)> wrote in
message news:%(E-Mail Removed)...
> Deb,
>
> Deb H wrote:
>> Trying to decide what the best way to apply certain features such as
>> event log settings and other computer related GPO settings. Currently I
>> have all computers in their OUs designed by location. Should I also
>> create a group and add all computers to the group, then add group to a
>> certain policy affecting the event logs. Or should I adjust all the OUs?

>
> avoid security filtering (that is tweaking permissions on the Group
> Policy) as far as you can. That slows down Group Policy application. If
> possible, re-organize the OU structure so that you can create and add your
> GPOs more easily or link the policy in question to multiple locations in
> the hierachy.
>
> cheers,
>
> Florian
> --
> Microsoft MVP - Group Policy
> eMail: prename [at] frickelsoft [dot] net.
> blog: http://www.frickelsoft.net/blog.
> Maillist (german): http://frickelsoft.net/cms/index.php?page=mailingliste



 
Reply With Quote
 
Mark Heitbrink [MVP]
Guest
Posts: n/a
 
      30th Jul 2008
Barkley Bees schrieb:
> We have our OU structure setup as follows (simplified):
>
> MAIN OU (Contains our client PC's and users)
> --- SERVERS OU (Servers only under the Main OU)


IMHO, the easiest way to handle it:
MAIN OU
- Link all GPOs that are for both kind of computers
--- SERVERS OU
- link only GPOs with server settings
--- WORKSTATIONS OU
- link only GPOs with special client settings

Mark
--
Mark Heitbrink - MVP Windows Server - Group Policy

Homepage: www.gruppenrichtlinien.de - deutsch
Discuss : www.freelists.org/list/gpupdate
 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Windows Servers 2003 servers can Connect to the internet, but Client computers cannot diamondd Internet / ISP / Networking 0 18th Jul 2011 05:26 PM
GP Don't apply to two computers Angel Massa Microsoft Windows 2000 Group Policy 9 1st Nov 2005 06:36 PM
how to apply w2k security to w2k member servers under w2k3 domain? =?Utf-8?B?YmVu?= Microsoft Windows 2000 Security 6 7th Apr 2005 02:31 AM
Group Policy won't apply to Computers Brian Parker Microsoft Windows 2000 Group Policy 3 25th Nov 2003 09:51 AM
Re: apply group policy logon logoff to computers Sabin Nair[MSFT] Microsoft Windows 2000 Group Policy 4 13th Aug 2003 08:15 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 04:24 AM.