SlideShare a Scribd company logo
Guided Hands-On Lab on GPO-GPPPresenter	Tan CheeTitle			MVP in GPOEvent		CTU 2011 JuneDate		25th June 2011
Guided HOL on GPO-GPPGetting Familiarize with the HOL SetupHOL Session #1 – Restricted Group (GPO & GPP)HOL Session #2 – Deployment of TCPIP Printer (GPO & GPP)HOL Session #3 – Managing Office 2010 settings (GPO)HOL Session #4 – WMI FilterHOL Session #5 – Basic TroubleshootingTips and Tricks plus Discussion (Sharing Experience)Agenda
Getting Familiarize with the HOL SetupThe SetupVirtual Machines (Hyper-V): Private NetworkDomain Name: ONPREM.LOCALPhysical Host
Quick Walk Through on the HOL Setup
Getting ReadyUnder “START” > “Administrative Tools”Start “Active Directory Users and Computers” ConsoleUnderstand the OU structureUnderstand where is the User ObjectsUnderstand where is the Computer ObjectsStart “Group Policy Management” ConsoleStart “Active Directory Sites and Services” Console (For manual replication)DC1.onprem.local (Domain Controller)
OU Structure and Dummy Accounts
GPMCOU that cannot link GPO to
Getting ReadyLogin as Domain AdminOpen Command PromptGet ready to run following commandsGPUPDATE /FORCEYou may be required to login as CTUUSER01 in later partClient1.onprem.local (Domain Machine)
HOL Session #1 – Restricted Group (GPO)
HOL Session #1Restrict adding of members to local administrators groupInsertion of Domain Group to be a member of local administrators groupRestricted Group through GPO
HOL #1a - Restrict adding of members to local machine administrators group
HOL Session #1aOn DC1.onprem.local (Domain Controller)Start GPMCCreate and Configure GPO – “CTU_Restricted_Group”Link the GPO to the OU containing Computer – “Client1”On Client1.onprem.local (Client Machine)Under “local users and groups” > “Groups”, try adding “CTUUser01” to “Administrators” group.Then under command prompt, run “GPUPDATE /FORCE”Restrict adding of members to local machine administrators group
HOL Session #1aExpected Result:User able to insert another domain group to the local machine administrators group.User un-able to add another domain account to the local machine administrators group.Restrict adding of members to local machine administrators group
HOL #1b - Insert Domain Group to be a member of local machine administrators group
HOL Session #1bOn DC1.onprem.local (Domain Controller)Start GPMCCreate and Configure GPO – “CTU_Inject_LocalAdmin”Link the GPO to the OU containing Computer – “Client1”On Client1.onprem.local (Client Machine)Under “local users and groups” > “Groups”, try adding “CTUUser01” to “Administrators” group.Then under command prompt, run “GPUPDATE /FORCE”Insert Domain Group to be a member of local machine administrators group
HOL Session #1bExpected Result:User able to insert another domain group to the local machine administrators group.User able to add another domain account to the local machine administrators group.Insert Domain Group to be a member of local machine administrators group
HOL #1c – Managing Local Machine Administrators Group using GPP
GPP contain similar settings? Yes!
HOL #1c – Managing Local Machine Administrators Group using GPPDEMO
HOL Session #2 – Deployment of TCPIP Printer (GPO & GPP)
Getting ReadyOn DC1.onprem.localPrint Service (Add Role)Add Printer Drivers (Both x64 and x86)Share out the Printer (192.168.1.40 – CTU Printer)Create and Configure GPO – “CTU_Deploy_Printer”Link the GPO to the OU containing ComputerOn Client machine, under command prompt, run “GPUPDATE /FORCEDeployment of TCPIP Printer (GPO & GPP)
Deployment of TCPIP Printer (GPO & GPP)Printer Driver (32bit and 64bit)GPO Setting – Computer Configuration > Administrative Templates > Printers > Point and Print Restrictions: EnabledImpact to Boot UpThrough Computer or User GPP?Pointers to take note
HOL Session #3 – Managing Office 2011 settings (GPO)
Getting ReadyOn DC1.onprem.localCreate and Configure GPO – “CTU_Office2010”Import GPO template files for Office 2010Note that the settings are under User ConfigurationLink the GPO to the OU containing Users – “CTUUser01”Managing Office 2011 settings (GPO)
Setting to TryConfigure as following.On Client, Login as CTUUser01 to verify setting is applied.Default Font Name, Size
HOL Session #4 – WMI FilterDEMO
WMI Filter (GPO)Useful to target GPO for Machine running different OS under same OU.Demo on how to import and apply WMI Filter
HOL Session #5 – Basic Troubleshooting Relates to GPO
Basic TroubleshootingOn Client machine (Login with Domain account)Event Viewer of ClientRun Command Line – GPRESULT /H <Filename>.htmlOn Domain ControllerUse GPMC to generate a Group Policy Result
Requirement for GPMC Group Policy Results Wizard to work WMI service on target must be runningFirewall port must open for WMI (Predefined Program)
Tips and Tricks plus Discussion!!
Tips and TricksIn Client Machine, Remove the following registry key and run GP update, the GPP that is configured as Apply Once Only will apply again.HKLM\SOFTWARE\Microsoft\Group Policy\Client\RunOnceGPP – Apply Once Only?
Tips and TricksGPP – Settings with Red and Green Underline – What does it mean?Red – [No Go], Will not DeliverGreen – [Go], Will be Delivered
Tips and TricksGPO Settings Supersede GPP Settings
Discussion
Thank You!!
CTU June 2011 - Guided Hands on Lab on GPO - GPP

More Related Content

PPTX
Securing Windows with Group Policy
PDF
1200+ sighs of relief for the IT department at City of Grand Rapids - ADSelfS...
PPTX
Protecting Windows Passwords and Preventing Windows Computer / Password Attacks
PPTX
Decrypting the security mystery with SIEM (Part 2) ​
PDF
Windows Server 2012 R2 Hyper V Component Architecture
PPTX
Microsoft Windows Network Auditing and Reporting Solution
PPTX
Active Directory Auditing and Reporting Tool
PPTX
Securing Windows with Group Policy
1200+ sighs of relief for the IT department at City of Grand Rapids - ADSelfS...
Protecting Windows Passwords and Preventing Windows Computer / Password Attacks
Decrypting the security mystery with SIEM (Part 2) ​
Windows Server 2012 R2 Hyper V Component Architecture
Microsoft Windows Network Auditing and Reporting Solution
Active Directory Auditing and Reporting Tool

Viewers also liked (20)

DOCX
What is active directory
PDF
Active Directory Upgrade
PPT
70 640 Lesson03 Ppt 041009
PPT
70 640 Lesson04 Ppt 041009
PPTX
Microsoft Offical Course 20410C_00
PDF
Checking the health of your active directory enviornment
PPT
70 640 Lesson07 Ppt 041009
PPT
70 640 Lesson05 Ppt 041009
PDF
Windows server 2012 r2 active directory建置實務
PPT
70 640 Lesson02 Ppt 041009
PPTX
What's new in Windows Server 2012 R2
PPTX
Agile in Action - Act 2: Development
PPTX
Microsoft Offical Course 20410C_01
PPTX
Best MCSA - SQL SERVER 2012 Training Institute in Delhi
PPTX
7 tips to simplify Active Directory Management ​
PPTX
Overcoming the challenges of Office 365 user management in hybrid environments​
PDF
Kerberos presentation
PPTX
70-410 Installing and Configuring Windows Server 2012
PPTX
Kerberos protocol
PPTX
Kerberos
What is active directory
Active Directory Upgrade
70 640 Lesson03 Ppt 041009
70 640 Lesson04 Ppt 041009
Microsoft Offical Course 20410C_00
Checking the health of your active directory enviornment
70 640 Lesson07 Ppt 041009
70 640 Lesson05 Ppt 041009
Windows server 2012 r2 active directory建置實務
70 640 Lesson02 Ppt 041009
What's new in Windows Server 2012 R2
Agile in Action - Act 2: Development
Microsoft Offical Course 20410C_01
Best MCSA - SQL SERVER 2012 Training Institute in Delhi
7 tips to simplify Active Directory Management ​
Overcoming the challenges of Office 365 user management in hybrid environments​
Kerberos presentation
70-410 Installing and Configuring Windows Server 2012
Kerberos protocol
Kerberos
Ad

Similar to CTU June 2011 - Guided Hands on Lab on GPO - GPP (16)

PPTX
Group Policy Windows Server 2008
PPTX
Microsoft Offical Course 20410C_11
PPTX
Useful Group Policy Concepts
PPT
Understanding Group Policy Object Windows Server
PPTX
Group policy Best Practices
PPTX
(Ab)Using GPOs for Active Directory Pwnage
PPTX
A.Group Policy and group policy obj.pptx
PPT
Ad group policy1
PDF
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory 1st ...
PPTX
Arcelor Mittal intern
PPT
Chapter09 Implementing And Using Group Policy
PDF
Windows Server 2008 R2 Group Policy Changes
PPTX
Domain wide organisation policy
PDF
Group Policy
PPTX
MCSA Installing & Configuring Windows Server 2012 70-410
PPTX
How To Troubleshoot Group Policy in Windows 10
Group Policy Windows Server 2008
Microsoft Offical Course 20410C_11
Useful Group Policy Concepts
Understanding Group Policy Object Windows Server
Group policy Best Practices
(Ab)Using GPOs for Active Directory Pwnage
A.Group Policy and group policy obj.pptx
Ad group policy1
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory 1st ...
Arcelor Mittal intern
Chapter09 Implementing And Using Group Policy
Windows Server 2008 R2 Group Policy Changes
Domain wide organisation policy
Group Policy
MCSA Installing & Configuring Windows Server 2012 70-410
How To Troubleshoot Group Policy in Windows 10
Ad

More from Spiffy (20)

PDF
01 server manager spiffy
PDF
Agile in Action - Act 3: Testing
PPTX
Agile in Action - Keynote: Becoming and Being Agile - What Does This Mean?
PPTX
Agile in Action - Act 1 (Set Up, Planning, Requirements and Architecture)
PDF
MS TechDays 2011 - WCF Web APis There's a URI for That
PDF
MS TechDays 2011 - NUI, Gooey and Louie
PDF
MS TechDays 2011 - Mango, Mango! Developing for Windows Phone 7
PDF
MS TechDays 2011 - Generate Revenue on Azure
PDF
MS TechDays 2011 - HTML 5 All the Awesome Bits
PDF
MS TechDays 2011 - Cloud Computing with the Windows Azure Platform
PDF
MS TechDays 2011 - Simplified Converged Infrastructure Solutions
PDF
MS TechDays 2011 - SCDPM 2012 The New Feature of Data Protection
PDF
MS TechDays 2011 - Microsoft Exchange Server and Office 365 Hybrid Deployment
PDF
MS TechDays 2011 - How to Run Middleware in the Cloud Story of Windows Azure ...
PDF
MS TechDays 2011 - Cloud Management with System Center Application Controller
PDF
MS TechDays 2011 - Virtualization Solutions to Optimize Performance
PDF
MS TechDays 2011 - Automating Your Infrastructure System Center Orchestrator ...
PDF
MS TechDays 2011 - Self-Service Private Cloud Management through Integrated P...
PDF
MS TechDays 2011 - SCVMM 2012 Building of Private Clouds and Federation to th...
PDF
MS TechDays 2011 - Operation Manager 2012 - New features to Enhance Enterpris...
01 server manager spiffy
Agile in Action - Act 3: Testing
Agile in Action - Keynote: Becoming and Being Agile - What Does This Mean?
Agile in Action - Act 1 (Set Up, Planning, Requirements and Architecture)
MS TechDays 2011 - WCF Web APis There's a URI for That
MS TechDays 2011 - NUI, Gooey and Louie
MS TechDays 2011 - Mango, Mango! Developing for Windows Phone 7
MS TechDays 2011 - Generate Revenue on Azure
MS TechDays 2011 - HTML 5 All the Awesome Bits
MS TechDays 2011 - Cloud Computing with the Windows Azure Platform
MS TechDays 2011 - Simplified Converged Infrastructure Solutions
MS TechDays 2011 - SCDPM 2012 The New Feature of Data Protection
MS TechDays 2011 - Microsoft Exchange Server and Office 365 Hybrid Deployment
MS TechDays 2011 - How to Run Middleware in the Cloud Story of Windows Azure ...
MS TechDays 2011 - Cloud Management with System Center Application Controller
MS TechDays 2011 - Virtualization Solutions to Optimize Performance
MS TechDays 2011 - Automating Your Infrastructure System Center Orchestrator ...
MS TechDays 2011 - Self-Service Private Cloud Management through Integrated P...
MS TechDays 2011 - SCVMM 2012 Building of Private Clouds and Federation to th...
MS TechDays 2011 - Operation Manager 2012 - New features to Enhance Enterpris...

Recently uploaded (20)

PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PPTX
A Presentation on Artificial Intelligence
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Accuracy of neural networks in brain wave diagnosis of schizophrenia
PDF
Network Security Unit 5.pdf for BCA BBA.
PPTX
Spectroscopy.pptx food analysis technology
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
cuic standard and advanced reporting.pdf
PDF
Empathic Computing: Creating Shared Understanding
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Encapsulation theory and applications.pdf
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
Electronic commerce courselecture one. Pdf
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
NewMind AI Weekly Chronicles - August'25-Week II
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
A Presentation on Artificial Intelligence
20250228 LYD VKU AI Blended-Learning.pptx
Accuracy of neural networks in brain wave diagnosis of schizophrenia
Network Security Unit 5.pdf for BCA BBA.
Spectroscopy.pptx food analysis technology
The Rise and Fall of 3GPP – Time for a Sabbatical?
cuic standard and advanced reporting.pdf
Empathic Computing: Creating Shared Understanding
Digital-Transformation-Roadmap-for-Companies.pptx
Encapsulation theory and applications.pdf
MYSQL Presentation for SQL database connectivity
Spectral efficient network and resource selection model in 5G networks
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
Dropbox Q2 2025 Financial Results & Investor Presentation
Electronic commerce courselecture one. Pdf
Per capita expenditure prediction using model stacking based on satellite ima...
NewMind AI Weekly Chronicles - August'25-Week II
“AI and Expert System Decision Support & Business Intelligence Systems”
Reach Out and Touch Someone: Haptics and Empathic Computing

CTU June 2011 - Guided Hands on Lab on GPO - GPP

  • 1. Guided Hands-On Lab on GPO-GPPPresenter Tan CheeTitle MVP in GPOEvent CTU 2011 JuneDate 25th June 2011
  • 2. Guided HOL on GPO-GPPGetting Familiarize with the HOL SetupHOL Session #1 – Restricted Group (GPO & GPP)HOL Session #2 – Deployment of TCPIP Printer (GPO & GPP)HOL Session #3 – Managing Office 2010 settings (GPO)HOL Session #4 – WMI FilterHOL Session #5 – Basic TroubleshootingTips and Tricks plus Discussion (Sharing Experience)Agenda
  • 3. Getting Familiarize with the HOL SetupThe SetupVirtual Machines (Hyper-V): Private NetworkDomain Name: ONPREM.LOCALPhysical Host
  • 4. Quick Walk Through on the HOL Setup
  • 5. Getting ReadyUnder “START” > “Administrative Tools”Start “Active Directory Users and Computers” ConsoleUnderstand the OU structureUnderstand where is the User ObjectsUnderstand where is the Computer ObjectsStart “Group Policy Management” ConsoleStart “Active Directory Sites and Services” Console (For manual replication)DC1.onprem.local (Domain Controller)
  • 6. OU Structure and Dummy Accounts
  • 7. GPMCOU that cannot link GPO to
  • 8. Getting ReadyLogin as Domain AdminOpen Command PromptGet ready to run following commandsGPUPDATE /FORCEYou may be required to login as CTUUSER01 in later partClient1.onprem.local (Domain Machine)
  • 9. HOL Session #1 – Restricted Group (GPO)
  • 10. HOL Session #1Restrict adding of members to local administrators groupInsertion of Domain Group to be a member of local administrators groupRestricted Group through GPO
  • 11. HOL #1a - Restrict adding of members to local machine administrators group
  • 12. HOL Session #1aOn DC1.onprem.local (Domain Controller)Start GPMCCreate and Configure GPO – “CTU_Restricted_Group”Link the GPO to the OU containing Computer – “Client1”On Client1.onprem.local (Client Machine)Under “local users and groups” > “Groups”, try adding “CTUUser01” to “Administrators” group.Then under command prompt, run “GPUPDATE /FORCE”Restrict adding of members to local machine administrators group
  • 13. HOL Session #1aExpected Result:User able to insert another domain group to the local machine administrators group.User un-able to add another domain account to the local machine administrators group.Restrict adding of members to local machine administrators group
  • 14. HOL #1b - Insert Domain Group to be a member of local machine administrators group
  • 15. HOL Session #1bOn DC1.onprem.local (Domain Controller)Start GPMCCreate and Configure GPO – “CTU_Inject_LocalAdmin”Link the GPO to the OU containing Computer – “Client1”On Client1.onprem.local (Client Machine)Under “local users and groups” > “Groups”, try adding “CTUUser01” to “Administrators” group.Then under command prompt, run “GPUPDATE /FORCE”Insert Domain Group to be a member of local machine administrators group
  • 16. HOL Session #1bExpected Result:User able to insert another domain group to the local machine administrators group.User able to add another domain account to the local machine administrators group.Insert Domain Group to be a member of local machine administrators group
  • 17. HOL #1c – Managing Local Machine Administrators Group using GPP
  • 18. GPP contain similar settings? Yes!
  • 19. HOL #1c – Managing Local Machine Administrators Group using GPPDEMO
  • 20. HOL Session #2 – Deployment of TCPIP Printer (GPO & GPP)
  • 21. Getting ReadyOn DC1.onprem.localPrint Service (Add Role)Add Printer Drivers (Both x64 and x86)Share out the Printer (192.168.1.40 – CTU Printer)Create and Configure GPO – “CTU_Deploy_Printer”Link the GPO to the OU containing ComputerOn Client machine, under command prompt, run “GPUPDATE /FORCEDeployment of TCPIP Printer (GPO & GPP)
  • 22. Deployment of TCPIP Printer (GPO & GPP)Printer Driver (32bit and 64bit)GPO Setting – Computer Configuration > Administrative Templates > Printers > Point and Print Restrictions: EnabledImpact to Boot UpThrough Computer or User GPP?Pointers to take note
  • 23. HOL Session #3 – Managing Office 2011 settings (GPO)
  • 24. Getting ReadyOn DC1.onprem.localCreate and Configure GPO – “CTU_Office2010”Import GPO template files for Office 2010Note that the settings are under User ConfigurationLink the GPO to the OU containing Users – “CTUUser01”Managing Office 2011 settings (GPO)
  • 25. Setting to TryConfigure as following.On Client, Login as CTUUser01 to verify setting is applied.Default Font Name, Size
  • 26. HOL Session #4 – WMI FilterDEMO
  • 27. WMI Filter (GPO)Useful to target GPO for Machine running different OS under same OU.Demo on how to import and apply WMI Filter
  • 28. HOL Session #5 – Basic Troubleshooting Relates to GPO
  • 29. Basic TroubleshootingOn Client machine (Login with Domain account)Event Viewer of ClientRun Command Line – GPRESULT /H <Filename>.htmlOn Domain ControllerUse GPMC to generate a Group Policy Result
  • 30. Requirement for GPMC Group Policy Results Wizard to work WMI service on target must be runningFirewall port must open for WMI (Predefined Program)
  • 31. Tips and Tricks plus Discussion!!
  • 32. Tips and TricksIn Client Machine, Remove the following registry key and run GP update, the GPP that is configured as Apply Once Only will apply again.HKLM\SOFTWARE\Microsoft\Group Policy\Client\RunOnceGPP – Apply Once Only?
  • 33. Tips and TricksGPP – Settings with Red and Green Underline – What does it mean?Red – [No Go], Will not DeliverGreen – [Go], Will be Delivered
  • 34. Tips and TricksGPO Settings Supersede GPP Settings

Editor's Notes

  • #5: Guide class to login to Physical Host and launch Hyper-VAccessing to the Hyper-V VMsLogin to the VM using the Domain Admin AccountsDomain Admin: AdministratorDomain Account: CTUUser01CTUUser02Domain Groups:CTU_LocalAdminCTU_Users
  • #8: To show that for certain OU, one cannot link GPO to it.
  • #12: Work together with class on how to configure this GPO and apply.And show what is the end resultExpected Result:User able to insert another domain group to the local machine administrators group.User un-able to add another domain account to the local machine administrators group.
  • #15: Work together with class on how to configure this GPO and apply.And show what is the end resultExpected Result:User able to insert another domain group to the local machine administrators group.User able to add another domain account to the local machine administrators group.
  • #18: Work together with class on how to configure this GPO and apply.And show what is the end resultExpected Result:User able to insert another domain group to the local machine administrators group.User able to add another domain account to the local machine administrators group.
  • #20: Work together with class on how to configure this GPO and apply.And show what is the end resultExpected Result:User able to insert another domain group to the local machine administrators group.User able to add another domain account to the local machine administrators group.
  • #21: Work together with class on how to configure this GPO and apply.And show what is the end resultExpected Result:User able to insert another domain group to the local machine administrators group.User able to add another domain account to the local machine administrators group.
  • #24: Work together with class on how to configure this GPO and apply.And show what is the end resultExpected Result:User able to insert another domain group to the local machine administrators group.User able to add another domain account to the local machine administrators group.
  • #27: Work together with class on how to configure this GPO and apply.And show what is the end resultExpected Result:User able to insert another domain group to the local machine administrators group.User able to add another domain account to the local machine administrators group.
  • #29: Work together with class on how to configure this GPO and apply.And show what is the end resultExpected Result:User able to insert another domain group to the local machine administrators group.User able to add another domain account to the local machine administrators group.
  • #31: Mention that DNS must be able to resolve properly too!But DNS is very critical for GPO to function properly
  • #32: Work together with class on how to configure this GPO and apply.And show what is the end resultExpected Result:User able to insert another domain group to the local machine administrators group.User able to add another domain account to the local machine administrators group.
  • #33: Create Batch file containing following line to perform the action to remove the registry keyREG DELETE &quot;HKLM\\SOFTWARE\\Microsoft\\Group Policy\\Client\\RunOnce&quot; /va