Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


toyonut

1508 posts

Uber Geek


#142550 17-Mar-2014 09:29
Send private message

It is better to have one big GPO or multiple granular ones?
I would lean to multiple tightly defined ones, but interested to know if that is the best way to go.
For example, I would have a firewall GPO, a WSUS GPO, a certificate GPO etc, rather than rolling it all into one big domain policy.




Try Vultr using this link and get us both some credit:

 

http://www.vultr.com/?ref=7033587-3B


Create new topic
Zeon
3916 posts

Uber Geek

Trusted

  #1007061 17-Mar-2014 09:41
Send private message

Yea would highly recommend breaking it up as different workstations/servers need different things generally. I would suggest creating them as standalone entities and then apply to containers as necessary.




Speedtest 2019-10-14




Inphinity
2780 posts

Uber Geek


  #1007073 17-Mar-2014 09:53
Send private message

I would make it logically granular, so that the necessary policies can be applied to the necessary OUs correctly.

Lias
5589 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #1007081 17-Mar-2014 10:03
Send private message

For anything other than a lab/home environment, you do not want one big policy. The degree of granularity you aim for should depend to a large extent on the size and complexity of the environment. For a smaller environment, it's generally still fine to clump lots of things together, but for larger/complex environments you generally want even better granularity. The hard part in those environments is finding the balance between functionality through granularity and an administrative nightmare of GPO maintenance :-)




I'm a geek, a gamer, a dad, a Quic user, and an IT Professional. I have a full rack home lab, size 15 feet, an epic beard and Asperger's. I'm a bit of a Cypherpunk, who believes information wants to be free and the Net interprets censorship as damage and routes around it. If you use my Quic signup you can also use the code R570394EKGIZ8 for free setup.




raytaylor
4014 posts

Uber Geek

Trusted

  #1008136 18-Mar-2014 15:04
Send private message

I mostly use group policy to set limits on who can shutdown a terminal server, or install apps / block the control panel etc.

To do this I just have three use groups
Santa Claus
Mrs Claus
Elves

So Santa has full access to the entire system and is the owner(s) of the company
Mrs Claus works in the payroll office and has full access, and also access to the admin shared drives
Elves are locked down and only have access to the everyday shared drive.

This way when I set up a server, I have a standard setup where at each site there is a owners drive, a standard admin drive and then a staff drive, with associated environment restrictions.

Each user on the system is placed into one of the three groups and the correct group policy object will be applied to them at logon.

On the terminal server, each printer is setup as a local network printer - no mappings to shared printers.
When a user logs on, the kixtart script will look at the group they are in and map the applicable shared drives, as well as look for a file \\tsclient\c\printer-x.txt
If the printer-x.txt file exists then the script knows the user is logging in from a specific machine and will set the nearest printer to that machine as the default.
If there is a txt file called printer-y.txt then it uses a different printer as default for the session.

Sorry if this all doesnt really apply to you - I mostly set up small terminal services environments.




Ray Taylor

There is no place like localhost

Spreadsheet for Comparing Electricity Plans Here


toyonut

1508 posts

Uber Geek


  #1008525 18-Mar-2014 22:37
Send private message

Nice, thanks very much. We are currently in process of simplifying down a hugely overcomplicated network. I am working on a set of group policies as I have time. Simple and reasonably granular works well for me and means I can have some leeway where I don't have to create OU's with inheritance blocked in order to stop some GP's overstepping their boundaries.




Try Vultr using this link and get us both some credit:

 

http://www.vultr.com/?ref=7033587-3B


Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.