+ Reply to Thread
Results 1 to 13 of 13
  1. #1
    Member
    Join Date
    Sep 2004
    Location
    Your living room...
    Posts
    427

    Active Directory, Managing Group Policies, etc. . .?

     
    Hi All,

    I'm having a bit of a problem wrapping my head around group policies and such in Active Directory. Currently I have a test setup with a Win 2k3 Standard Server and a Win 2k Pro workstation. I've already added the Win 2k workstation to the "home.local" domain and all is well.

    Now, i need to begin administering permissions, etc. Can someone point me to a quality tutorial regarding specific items. Say I only want to allow specific applications to run, etc. I need a tutorial that instructs on that.

    As I've basically said, AD is running with full DNS. I simply need to know how to do what comes next; managing it. FYI, this is strictly a learning setup so I'm not averse to trying wildly experimental things.

    Regards
    I reserve the right to contradict myself. . .

  2. #2
    Ultimate Member cadetstimp's Avatar
    Join Date
    Oct 2001
    Location
    Oceanside CA
    Posts
    1,804
    Active Directory is very flexable in allowing you to create whatever groups you need..... the trick is in applying specific properties and tools to each group you create.

    Don't worry how to create the group - just do it and use long names if you need to describe its function. The trick is paying close attention to where the group is and what properties you attach to it (i.e. a subgroup 'virus' under 'Win2kSP2' could apply virus software to Win2k clients listed in the group that have received/are running SP2)

    I would start by thinking of the tasks you want to do and in which order.... think of how you want to group your clients based on the functions you need to apply. Create a group for each function and then put them in the correct oder/heirarchy.

    As far as how to apply functions and policies to each group - start by right clicking the group that's been created and play with the policy settings. Drag clients into the new group and then see if the policy setting works on the clients in the group.

    i.e. Create a group called 'PasswordComplexityHigh' and then go into the policy settigns of that new group and set a policy that requires a password complexity (8 charaters /alpha numeric / etc.) Once saved - any clients dragged into that group will require a complex password when the client tries to change their password.

    (Making sure the name of the group is very descriptive of it's function really helps when you start to get a lot of groups going)

    Advanced functions would involve client scripts that could be attached to a group to allow the scripts to run on the clients that are a part of the group.

    Scripting is a whole subject by itself, but I would search for an example 'Login scripts' to get started


    In any case - think of a function / create the group using a name that describes the funtion well / drag the group to the correct location in AD if not root / alter the group properties to carry out the policy you require / drag the correct clients into the group you wish to affect / check that the clients in the group are receiving the policy (that it works)

    For education purposes - you could start by creating a number of groups in the root of your AD with different functions. Then you could drag your one client into one group at a time to see if each function works. Then have fun dragging one group into another as a subgroup to see if the client obtains the functions of both groups. You'll quickly see the advantage of AD when you start to drag one group into another!
    Last edited by cadetstimp; August 12th, 2007 at 09:06 PM.

  3. #3
    Member
    Join Date
    Sep 2004
    Location
    Your living room...
    Posts
    427
    Well, let's pick one item. How would I add a policy that says "They can only use IE". . .or a policy that says "They can use everything EXCEPT IE". . .Can you give me a short walk-through?
    I reserve the right to contradict myself. . .

  4. #4
    Member
    Join Date
    Sep 2004
    Location
    Your living room...
    Posts
    427
    . . .and, is there any chance of having a domain without ".local" appended? it seems that when I don't use ".local" bad things happen.
    I reserve the right to contradict myself. . .

  5. #5
    Ultimate Member cadetstimp's Avatar
    Join Date
    Oct 2001
    Location
    Oceanside CA
    Posts
    1,804
    You'll want to explore and use the Software Restriction Policies

  6. #6
    Member
    Join Date
    Sep 2004
    Location
    Your living room...
    Posts
    427
    Understood. Another issue: How do I actually add a "client" machine without first logging into that machine as a "domain user"? Can I not simply "claim" an existing machine as long as it's on the domain?
    I reserve the right to contradict myself. . .

  7. #7
    Member
    Join Date
    Sep 2004
    Location
    Your living room...
    Posts
    427
    . . .also, what would suddenly make data transfer slow? Before the Active Directory and DNS setup was in place, the machines could transfer files and such at a blinding speeds. Now, it seems that they're all connected via a 9600 baud modem or something. It's unbelievable.
    I reserve the right to contradict myself. . .

  8. #8
    Goverment property now GroundZero3's Avatar
    Join Date
    Oct 2001
    Location
    NOVA
    Posts
    33,778
    Blog Entries
    46
    You can add a computer account into AD but you will still need to join the computer to the domain

    Data transfers such as internet or file sharing?

  9. #9
    Member
    Join Date
    Sep 2004
    Location
    Your living room...
    Posts
    427
    Well the computers are currently on a closed network, so there's no internet access. But their file transfer has become unbelievably slow since setting up AD.
    I reserve the right to contradict myself. . .

  10. #10
    Goverment property now GroundZero3's Avatar
    Join Date
    Oct 2001
    Location
    NOVA
    Posts
    33,778
    Blog Entries
    46
    Network details?

    Are you copying over to mapped drives that you mapped out with AD?

    Are you trying to save to the network or just copy data over?

    Do you have all the latest updates installed for windows 2003 server?

  11. #11
    Member
    Join Date
    Sep 2004
    Location
    Your living room...
    Posts
    427
    Sorry. Yes, Server 2003 Standard R2 with all the latest updates. The server is running on a dual 3GHz Xeon with 2GB ram, and the client currently being worked with is some tiny 2GHz machine running 2K Pro.

    Basically the drives were mapped with the OS natively, not through AD so to speak. We're just running data tests right now. It seems for some reason that a SYNC between SQL servers runs fine, but actual drag-and-drop file transfer is amazingly slow. Could this have anything to do with bad DNS setup? Is it even remotely possible that it's doing redundant address resolution checks or something of that nature? I'm really lost at this point.
    I reserve the right to contradict myself. . .

  12. #12
    Member
    Join Date
    Sep 2004
    Location
    Your living room...
    Posts
    427
    Could it potentially have something to do with "LMHOSTS" or "NetBIOS over TCP/IP"?
    I reserve the right to contradict myself. . .

  13. #13
    Goverment property now GroundZero3's Avatar
    Join Date
    Oct 2001
    Location
    NOVA
    Posts
    33,778
    Blog Entries
    46
    lmhost and netbios are used for older operating systems (win9x) so if you are running a pure win2k/xp/vista network you can turn it off.

    i don't think thats the problem. Did you setup a primary zone, secondary zone, or stub zone in DNS?

    What happens when you remove the mapped drives, flush the dns cache on the computer then remap the drives? I assume these machines are logging into the domain?

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Active directory - Help
    By Samshen in forum Applications and Operating Systems
    Replies: 3
    Last Post: October 28th, 2005, 12:01 PM
  2. Group policies in Windows
    By lost-and-found in forum Applications and Operating Systems
    Replies: 0
    Last Post: June 23rd, 2005, 02:47 PM
  3. Group Policies...
    By gyoung in forum Applications and Operating Systems
    Replies: 5
    Last Post: May 19th, 2003, 04:26 PM
  4. group policies using gpedit.msc - trying to restrict guest account
    By maxxialfacilary in forum Applications and Operating Systems
    Replies: 4
    Last Post: September 22nd, 2002, 11:48 AM
  5. Windows 2000 Pro (Group Policies) / Novell...
    By Agent_Embryo in forum Applications and Operating Systems
    Replies: 4
    Last Post: August 6th, 2002, 08:50 AM

Tags for this Thread

Posting Permissions

  • You may post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Recommended Sites: ResellerRatings Store Reviews