GPO newbie, some questions.

Zucarita9000

Golden Member
Aug 24, 2001
1,590
0
0
Post - GPOs Newbie

So I just started with Group Policy. I’ve enabled a company wide policy, which I applied to the Default Domain Policy GPO.
It’s pretty basic stuff, a company wallpaper, company screensaver, some IE and Start Menu configurations, Windows Update interval and options, etc.
The screensaver and wallpaper setting were a bit tricky. I used a batch file at logon to copy the .scr from the server into the System32 directory, otherwise it wouldn’t work with the UNC path. For the wallpaper, I didn’t want to use Active Desktop, so instead I used a batch file to import a reg key into the Registry key “HKEY_CURRENT_USER\Control Panel\Desktop” and set the wallpaper bitmap.

Users cannot change the wallpaper or the screensaver.
However, I’ve noticed that even if I log in as an administrator, I can’t either. I’m also locked from making changes. So my question is, how can I exclude domain admins from the Default Domain Policy? Or am I doing something wrong to begin with?

Another inquiry is this. I have a few problem users who spent too much time on Windows Live Messenger and some other crap I don’t like. Some of them need to be local admin because of some idiotic business applications we have to run, which won’t run otherwise. So I was planning on creating an user group in AD called “Problem Users”. I would add those users (just 8 or 10) to that group. Then, I’d create a GPO for that user group alone, and apply all the restrictions there. I believe that will keep the domain admins out, right? Even if the user is a local admin, the GPO should override their privileges, am I correct?

I’ve been reading a lot aboutG Group Policy lately, but I appreciate all the help I can get.

Thanks!
 

RebateMonger

Elite Member
Dec 24, 2005
11,588
0
0
I haven't had to look in-depth at your GPO question. But I can offer a piece of advice that will save you time and trouble.

DO NOT modify default GPOs. Create a NEW Policy that only addresses the new feature you want to apply. Then apply it where it's needed.

If you screw up a GPO, it's a LOT easier to simply disable the new GPO, fix it, and re-enable it. And when you come back a year from now, you can look down your list of the various GPOs you created and easily see what each does, rather than trying to figure out what you changed in the Default Domain GPO.
 

Zucarita9000

Golden Member
Aug 24, 2001
1,590
0
0
I haven't had to look in-depth at your GPO question. But I can offer a piece of advice that will save you time and trouble.

DO NOT modify default GPOs. Create a NEW Policy that only addresses the new feature you want to apply. Then apply it where it's needed.

If you screw up a GPO, it's a LOT easier to simply disable the new GPO, fix it, and re-enable it. And when you come back a year from now, you can look down your list of the various GPOs you created and easily see what each does, rather than trying to figure out what you changed in the Default Domain GPO.

Exactly what I was thinking. That's why I didn't do a lot of tweaking to the default GPO, just minor esthetic changes to the OS, stuff that I want applied company wide. Heavier restrictions such as prohibited apps, etc. will have to go into their own GPO. I was just asking if this was the best practice to use.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |