How To Create A Group Policy In Windows Server 2012
This article explains what Group Policies are and shows how to configure Windows Server 2012 Active Directory Grouping Policies. Our next article will embrace how to properly enforce Group Policies (Group Policy Link Enforcement, Inheritance and Cake Inheritance) on computers and users that a role of the company's Active Directory.
FREE Hyper-Five & VMware Backup: Like shooting fish in a barrel to utilize - Powerful features - Simply works, no hassle: It's Free for Firewall.cx readers! Download Now!
Before nosotros swoop into Grouping Policy configuration, let'south explain what exactly Group Policies are and how they tin assistance an administrator control its users and computers.
A Grouping Policy is a calculator or user setting that can be configured by administrators to use various figurer specific or user specific registry settings to computers that have joined the domain (active directory). A elementary example of a group policy is the user password expiration policy which forces users to alter their countersign on a regular basis. Some other instance of a group policy would exist the enforcement of a specific desktop background pic on every workstation or restricting users from accessing their Local Network Connection properties then they cannot change their IP address.
A Group Policy Object (GPO) contains 1 or more group policy settings that can exist practical to domain computers, users, or both. GPO objects are stored in active directory. You lot tin can open and configure GPO objects by using the GPMC (Group Policy Management Panel) in Windows Server 2012:
Effigy i. GPO Objects
Grouping Policy Settings are the bodily configuration settings that can be applied to a domain computer or user. Most of the settings have three states, Enabled, Disabled and Not Configured. Group Policy Direction Editor provides admission to hundreds of computer and user settings that tin be applied to brand many arrangement changes to the desktop and server surroundings.
Grouping Policy Settings
Group Policy Settings are divided into Computer Settings and User Settings. Figurer Settings are applied to computer when the system starts and this modifies the HKEY Local Automobile hive of registry. User Settings are applied when the users log in to the computer and this modifies the HKEY Local Machine hive.
Figure two. Group Policy Settings
Computer Settings and User Settings both have policies and preferences.
These policies are:
Software Settings: Software can be deployed to users or reckoner past the administrator. The software deployed to users volition exist available only to those specific users whereas software deployed to a computer will be available to whatever user that on the specific calculator where the GPO is applied.
Windows Settings: Windows settings tin exist applied to a user or a computer in order to modify the windows environment. Examples are: countersign policies, firewall policy, account lockout policy, scripts and so on.
Administrative Templates: Contains a number of user and computer settings that tin can be applied to control the windows environment of users or computers. For example, specifying the desktop wallpaper, disabling admission to non-essential areas of the computers (due east.yard Network desktop icon, control panel etc), binder redirection and many more.
Preferences are a group policy extension that does the work which would otherwise require scripts. Preferences are used for both users and computers. You can use preferences to map network drives for users, map printers, configure net options and more.
Next, let'southward take a await at how we tin create and apply a Group Policy.
FREE Hyper-V & VMware Backup: Like shooting fish in a barrel to use - Powerful features - Just works, no hassle: It's FREE for Firewall.cx readers! Download Now!
Creating and Applying Group Policy Objects
By default, GPOs can exist created and applied by Domain Admins, Enterprise Admins and Group Policy Creator Owner user groups. Subsequently creating the GPO, you can apply or link the GPOs to sites, domains or Organizational Units (OUs), all the same you cannot apply GPO to users, groups, or computers. GPOs are candy in following top to bottom order:
- Local Group Policy: Every windows operating organization has local group policy installed by default. So this local group policy of the calculator is applied at first.
- Site GPO: The GPOs linked to the Site is and so candy. By default, there is no site level group policy configured.
- Domain GPO: Next, the GPO configured at domain level is processed. Past default, GPO named default domain policy is practical at the domain level. This applies to all the objects of the domain. If there is policy disharmonize between domain and site level GPOs, then GPO applied to domain level takes the precedence.
- Organizational Unit GPO: - In the finish, GPO configured at OU is practical. If there is any conflict betwixt previously applied GPOs, the GPO applied to OU takes the almost precedence over Domain, Site and Local Group Policy.
Permit's now take a look at a scenario to utilise a grouping policy to domain joined computers to alter the desktop background. We have a domain controller named FW-DC01 and ii clients FW-CL1 and FW-CL2 as shown in the diagram below. The goal here is to set the desktop wallpaper for these two clients from a group policy:
Figure iii. GPO Scenario
In our earlier articles we showed how Windows 8 / Windows eight.1 join an Agile Directory domain, FW-CL1 and FW-CL2 are workstations that have previously joined our domain – Active Directory. We accept 2 users MJackson and PWall in the FW Users OU.
Open up the Group Policy Direction Console (GPMC) past going into Server Manager>Tools and select Group Policy Management as shown below:
Figure 4. Open GPMC
Every bit the GPMC opens up, you will encounter the tree hierarchy of the domain. Now aggrandize the domain, firewall.local in our case, and you volition encounter the FW Users OU which is where our users reside. From hither, right-click this OU and select the outset option Create a GPO in this domain and Link it here:
Figure 5. Select FW Users and Create a GPO
Now type the Name for this GPO object and click the OK button. We selected WallPaper GPO:
Effigy half-dozen. Creating our Wallpaper Group Policy Object
Next, right-click the GPO object and click edit:
Effigy 7. Editing a Group Policy Object
At this point nosotros get to meet and configure the policy that deals with the Desktop Wallpaper, however observe the number of different policies that let u.s. to configure and tweak various aspects of our domain users.
To discover the Desktop Wallpaper, go to Expand User Configuration> Policies> Administrative Templates> Desktop> Desktop. At this point we should exist able to see the setting in right window. Right-click the Desktop Wallpaper setting and select Edit:
Effigy 8. Selecting and editing Desktop Wallpaper policy
The settings of Desktop Wallpaper will now open. Beginning we demand to activate the policy by selecting the Enabled choice on the left. Next, type the UNC path of shared wallpaper. Remember that nosotros must share the folder that contains the wallpaper \\FW-DC1\WallPaper\ and configure the share permission so that users can admission it. Notice that we can even select to eye our wallpaper (Wallpaper Style). When set up click Utilise then OK:
Figure nine. Configure Desktop Wallpaper
At present that we've configured our GPO, we need to apply it. To practise so, nosotros tin can just log off and log back in the client reckoner or type post-obit command in domain controller's command prompt to use the settings immediately:
C:\>gpupdate /force
In one case our domain user logs in to their calculator (FW-CL1), the new wallpaper policy will be applied and loaded on to the computer's desktop.
Figure x. User Login
As nosotros tin encounter below, our user's desktop now has the background epitome configured in the group policy nosotros created:
Figure xi. Estimator Desktop Wallpaper Changed
This example shows how 1 pocket-size configuration setting tin can be applied to all computers within an organization. The ability and flexibility of Grouping Policy Objects is truly unbelievable and as nosotros've shown, it'due south fifty-fifty easier to configure and apply them with just a few clicks on the domain controller!
Free Hyper-V & VMware Backup: Easy to utilise - Powerful features - Just works, no hassle: It's Gratuitous for Firewall.cx readers! Download Now!
This article explained what Group Policies Objects are and showed how to Configure Windows 2012 Active Directory Group Policies to control our Active Directory users and computers. We also highly recommend our article on Group Policy Enforcement, Inheritance throughout the Active Directory structure. More articles on Windows 2012 & Hyper-V tin be found at our Windows 2012 Server section.
Back to Windows 2012 Server Section
Source: https://www.firewall.cx/microsoft-knowledgebase/windows-2012/1055-windows-2012-group-policies.html
Posted by: williamswaregs.blogspot.com
0 Response to "How To Create A Group Policy In Windows Server 2012"
Post a Comment