How to Manage Group Policy Objects in Windows Server 2003
User-Submitted Article
In order to create a GPO we must first make sure that our network has AD enabled so that Security Policies can be deployed, leaving us with the configuration of security specifications that we must manually configure when assigning GPO's to a computer.
Our first steps in order to create a GPO, is to create a custom MM Console to manage Security Policy for our new GPO. Follow these steps indicated below to add a new GPO.
Our first steps in order to create a GPO, is to create a custom MM Console to manage Security Policy for our new GPO. Follow these steps indicated below to add a new GPO.
Difficulty: Moderate
Instructions
Things You'll Need:
- Computer access, Windows Server 2003 properly installed and configured correctly, network access, Ehow guide for easy to follow instructions, and patience.
- 1Select Start--> Run, type MMC in the run dialog box and choose OK to open the MMC.
- 2From the Main Menu of the MMC, select File--> Add/Remove Snap-In.
- 3In the Add/Remove Snap-In dialog box, choose Add. The Add Standalone Snap-In is displayed.
- 4Highlight the Group Policy Object Editor Snap-In and choose Add. The Group Policy Wizard is displayed.
- 5The Group Policy Object specifies Local Computer by default. Choose Browse to browse for a Group Policy Object.
- 6The Domains/OU tab is the default showing the current domain. Notice that you can choose the default Domain Policy here and that you have a Create New Policy Object button to the right of the drop-down list of domains. In the Domains/OU tab, click the create New Group Policy Object button. Name the GPO Security Policy GPO. Choose Ok and then choose finish to return to the Add Standalone Snap-In window.
- 7Highlight the Event Viewer in the snap-in and choose Add.
- 8The select computer dialog box appears and Local Computer selected by default. Choose the Another Computer radio button and type the name of the domain controller computer from which you are doing this exercise.
- 9Click Finish then click Close.
- 10In the Add/Remove Snap-In dialog box, notice that the new GPO we created is now listed along with the Event Viewer.
- 11Choose Ok to return to the main console window.
- 12Select File--> Save As.. Save the console as Security Policy GPO in all Users\StartMenu\Programs\Administrative Tools folder and choose Save.
- 13Now you can access this console by selecting Startà Administrative Toolsà Security Policy GPO.
Now that we have installed our new GPO we need to set the appropriate permissions so that our users have ideal settings to certain information that may only be available to his or her department. In order to change the user permissions, we can easily set our settings in order to accommodate for our Security Policy that fits along with the GPO we created. In order set the proper settings please follow the sequence as indicated below to achieve this task. - 14To access the Security Policy settings we have created for our GPO we need to access the Account Security Policies folder. Click Start--> Administrative Tools--> Security Policy GPO and the MMC Snap-In dialog appears.
- 15Expand Security Policy GPO--> Computer Configurationà Windows Settings--> Security Settings--> Account Policies.
- 16Under the Account Policy GPO Object we can control the settings for passwords, lockouts, local and user audits along with security options that can accessed and edited right from the MMC Console we created above.
No comments:
Post a Comment