CTU June 2011 - Guided Hands on Lab on GPO - GPP

37
Guided Hands-On Lab on GPO-GPP Presenter Tan Chee Title MVP in GPO Event CTU 2011 June Date 25 th June 2011

description

 

Transcript of CTU June 2011 - Guided Hands on Lab on GPO - GPP

Page 1: CTU June 2011 - Guided Hands on Lab on GPO - GPP

Guided Hands-On Lab on GPO-GPP

Presenter Tan CheeTitle MVP in GPOEvent CTU 2011 JuneDate 25th June 2011

Page 2: CTU June 2011 - Guided Hands on Lab on GPO - GPP

Guided HOL on GPO-GPP

• Getting Familiarize with the HOL Setup

• HOL Session #1 – Restricted Group (GPO & GPP)

• HOL Session #2 – Deployment of TCPIP Printer (GPO & GPP)

• HOL Session #3 – Managing Office 2010 settings (GPO)

• HOL Session #4 – WMI Filter

• HOL Session #5 – Basic Troubleshooting

• Tips and Tricks plus Discussion (Sharing Experience)

Agenda

Page 3: CTU June 2011 - Guided Hands on Lab on GPO - GPP

Getting Familiarize with the HOL Setup

The Setup

Domain Name: ONPREM.LOCAL

Physical Host

Virtual Machines (Hyper-V): Private Network

Page 4: CTU June 2011 - Guided Hands on Lab on GPO - GPP

Quick Walk Through on the HOL Setup

Page 5: CTU June 2011 - Guided Hands on Lab on GPO - GPP

Getting Ready

Under “START” > “Administrative Tools”

• Start “Active Directory Users and Computers” Console– Understand the OU structure– Understand where is the User Objects– Understand where is the Computer Objects

• Start “Group Policy Management” Console

• Start “Active Directory Sites and Services” Console (For manual replication)

DC1.onprem.local (Domain Controller)

Page 6: CTU June 2011 - Guided Hands on Lab on GPO - GPP

OU Structure and Dummy Accounts

Page 7: CTU June 2011 - Guided Hands on Lab on GPO - GPP

GPMCOU that cannot link GPO to

Page 8: CTU June 2011 - Guided Hands on Lab on GPO - GPP

Getting Ready

• Login as Domain Admin

• Open Command Prompt– Get ready to run following commands

•GPUPDATE /FORCE• You may be required to login as CTUUSER01 in later part

Client1.onprem.local (Domain Machine)

Page 9: CTU June 2011 - Guided Hands on Lab on GPO - GPP

HOL Session #1 – Restricted Group (GPO)

Page 10: CTU June 2011 - Guided Hands on Lab on GPO - GPP

HOL Session #1

• Restrict adding of members to local administrators group

• Insertion of Domain Group to be a member of local administrators group

Restricted Group through GPO

Page 11: CTU June 2011 - Guided Hands on Lab on GPO - GPP

HOL #1a - Restrict adding of members to local machine administrators group

Page 12: CTU June 2011 - Guided Hands on Lab on GPO - GPP

HOL Session #1a

On DC1.onprem.local (Domain Controller)

• Start GPMC

• Create and Configure GPO – “CTU_Restricted_Group”

• Link the GPO to the OU containing Computer – “Client1”

On Client1.onprem.local (Client Machine)

• Under “local users and groups” > “Groups”, try adding “CTUUser01” to “Administrators” group.

• Then under command prompt, run “GPUPDATE /FORCE”

Restrict adding of members to local machine administrators group

Page 13: CTU June 2011 - Guided Hands on Lab on GPO - GPP

HOL Session #1a

Expected Result:User able to insert another domain group to the local machine administrators group.User un-able to add another domain account to the local machine administrators group.

Restrict adding of members to local machine administrators group

Page 14: CTU June 2011 - Guided Hands on Lab on GPO - GPP

HOL #1b - Insert Domain Group to be a member of local machine administrators group

Page 15: CTU June 2011 - Guided Hands on Lab on GPO - GPP

HOL Session #1b

On DC1.onprem.local (Domain Controller)

• Start GPMC

• Create and Configure GPO – “CTU_Inject_LocalAdmin”

• Link the GPO to the OU containing Computer – “Client1”

On Client1.onprem.local (Client Machine)

• Under “local users and groups” > “Groups”, try adding “CTUUser01” to “Administrators” group.

• Then under command prompt, run “GPUPDATE /FORCE”

Insert Domain Group to be a member of local machine administrators group

Page 16: CTU June 2011 - Guided Hands on Lab on GPO - GPP

HOL Session #1b

Expected Result:User able to insert another domain group to the local machine administrators group.User able to add another domain account to the local machine administrators group.

Insert Domain Group to be a member of local machine administrators group

Page 17: CTU June 2011 - Guided Hands on Lab on GPO - GPP

HOL #1c – Managing Local Machine Administrators Group using GPP

Page 18: CTU June 2011 - Guided Hands on Lab on GPO - GPP

GPP contain similar settings? Yes!

Page 19: CTU June 2011 - Guided Hands on Lab on GPO - GPP

HOL #1c – Managing Local Machine Administrators Group using GPP

DEMO

Page 20: CTU June 2011 - Guided Hands on Lab on GPO - GPP

HOL Session #2 – Deployment of TCPIP Printer (GPO & GPP)

Page 21: CTU June 2011 - Guided Hands on Lab on GPO - GPP

Getting Ready

On DC1.onprem.local

• Print Service (Add Role)

• Add Printer Drivers (Both x64 and x86)

• Share out the Printer (192.168.1.40 – CTU Printer)

• Create and Configure GPO – “CTU_Deploy_Printer”

• Link the GPO to the OU containing Computer

• On Client machine, under command prompt, run “GPUPDATE /FORCE

Deployment of TCPIP Printer (GPO & GPP)

Page 22: CTU June 2011 - Guided Hands on Lab on GPO - GPP

Deployment of TCPIP Printer (GPO & GPP)

• Printer Driver (32bit and 64bit)

• GPO Setting – Computer Configuration > Administrative Templates > Printers > Point and Print Restrictions: Enabled

• Impact to Boot Up

• Through Computer or User GPP?

Pointers to take note

Page 23: CTU June 2011 - Guided Hands on Lab on GPO - GPP

HOL Session #3 – Managing Office 2011 settings (GPO)

Page 24: CTU June 2011 - Guided Hands on Lab on GPO - GPP

Getting Ready

On DC1.onprem.local

• Create and Configure GPO – “CTU_Office2010”

• Import GPO template files for Office 2010– Note that the settings are under User Configuration

• Link the GPO to the OU containing Users – “CTUUser01”

Managing Office 2011 settings (GPO)

Page 25: CTU June 2011 - Guided Hands on Lab on GPO - GPP

Setting to Try

• Configure as following.

• On Client, Login as CTUUser01 to verify setting is applied.

Default Font Name, Size

Page 26: CTU June 2011 - Guided Hands on Lab on GPO - GPP

HOL Session #4 – WMI Filter

DEMO

Page 27: CTU June 2011 - Guided Hands on Lab on GPO - GPP

WMI Filter (GPO)

• Useful to target GPO for Machine running different OS under same OU.

Demo on how to import and apply WMI Filter

Page 28: CTU June 2011 - Guided Hands on Lab on GPO - GPP

HOL Session #5 – Basic Troubleshooting Relates to GPO

Page 29: CTU June 2011 - Guided Hands on Lab on GPO - GPP

Basic Troubleshooting

On Client machine (Login with Domain account)

• Event Viewer of Client

• Run Command Line – GPRESULT /H <Filename>.html

On Domain Controller

• Use GPMC to generate a Group Policy Result

Page 30: CTU June 2011 - Guided Hands on Lab on GPO - GPP

Requirement for GPMC Group Policy Results Wizard to work

• WMI service on target must be running

• Firewall port must open for WMI (Predefined Program)

Page 31: CTU June 2011 - Guided Hands on Lab on GPO - GPP

Tips and Tricks plus Discussion!!

Page 32: CTU June 2011 - Guided Hands on Lab on GPO - GPP

Tips and Tricks

In Client Machine, Remove the following registry key and run GP update, the GPP that is configured as Apply Once Only will apply again.

HKLM\SOFTWARE\Microsoft\Group Policy\Client\RunOnce

GPP – Apply Once Only?

Page 33: CTU June 2011 - Guided Hands on Lab on GPO - GPP

Tips and TricksGPP – Settings with Red and Green Underline – What does it mean?

Red – [No Go], Will not Deliver

Green – [Go], Will be Delivered

Page 34: CTU June 2011 - Guided Hands on Lab on GPO - GPP

Tips and TricksGPO Settings Supersede GPP Settings

Page 35: CTU June 2011 - Guided Hands on Lab on GPO - GPP

Discussion

Page 36: CTU June 2011 - Guided Hands on Lab on GPO - GPP

Thank You!!

Page 37: CTU June 2011 - Guided Hands on Lab on GPO - GPP