Solved

Applications of Group Policy

Posted on 2004-03-28
7
203 Views
Last Modified: 2013-12-04
Can any smart person there solve this question for me? Thanks..


"You are the administrator of your company’s network. The network consists of 1 Windows 2000 domain. The domain consists of 4 OU (Organisation Unit) as shown. All OUs contain users for their department. The Network Administrators are in the IT OU. You want to centralize security policy for your domain. You create the following 3 Group Policies. How should you apply the Group Policy?


    -Main OU
          -IT OU
          -HR OU
          -Sales OU
          -Finance OU


I.      Group Policy 1 defines Password, Audit and User Rights policies
II.      Group Policy 2 defines User Desktop policy
III.      Group Policy 3 defines a high security User Desktop policy for network administrators."



Anyone Can Give Me the DETAILS STEPS to solve the above question and the 800 Points will be yours!!!
THANKS IN ADVANCE........ =)
0
Comment
Question by:pika83
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 6

Accepted Solution

by:
DanniF earned 500 total points
ID: 10702092
Hmmmm I hope this isn't your homework :).

I. You should apply this policy on Domain level as this should affect ALL users. (password and security policy)

II. This one goes to the 3 user OU's (HR, Sales and Finance).

III. This one goes to the IT OU as this is only for network administrators.

Hope this helps and good luck,

Daniel F.
0
 
LVL 6

Expert Comment

by:Joseph_Moore
ID: 10702905
Actually, I would put Group Policy 1 on Main OU, since GP is inherited by all child OUs (unless the inheritance is denied). That way, all OUs would get GP1, and you don't need to mess with the Domain-level GP.
Other then that, I agree with DanniF on GP2 and GP3.
0
 
LVL 7

Expert Comment

by:Isigow
ID: 10703263
Actually, just put Group Policy I and II on the Domain level (Main OU)
Then put GPIII on the IT OU.
Inheritance level will override the Previous User Desktop created via GPII when you are in the IT OU, thus allowing only GPIII to affect users in the IT OU, but letting GPII still affect users in the other OU's

Isi
0
Three Reasons Why Backup is Strategic

Backup is strategic to your business because your data is strategic to your business. Without backup, your business will fail. This white paper explains why it is vital for you to design and immediately execute a backup strategy to protect 100 percent of your data.

 

Expert Comment

by:Antowh76
ID: 10709848
-Password policies must be set at domain level to take effect, so
I. must be applied at domain level

II. and III, I agree with Isigow.

Regards, Antonio
0
 
LVL 7

Expert Comment

by:Isigow
ID: 10709976
yeah I think I said that :)

Isi
0
 
LVL 6

Expert Comment

by:DanniF
ID: 10712417
But why would you want to be:

A) Setting Domain level policies when you don't need to ?

B) Having policies override each other when you don't need to ??

I'd rather do it this way than counting on the fact that the policies override each other correctly.


In fact, If this was MY domain I would create an OU called Users where I would place all normal user OU's (HR, Sales and Finance in this case) and then I would place the IT OU outside the Users OU as I have completely different policies for the two.

So mine would be like this:

   
-DOMAIN-
     -IT OU
     -Users OU
           -HR OU
           -Sales OU
           -Finance OU

Anyways, I don't think you can do this as you have a question you need to answer. Just running off a bit there :)

Good luck,

Daniel F.
0
 

Author Comment

by:pika83
ID: 10756862

Hey guys..

Thanks a million! Really appreciate it ;)


Take care =)
0

Featured Post

2017 Webroot Threat Report

MSPs: Get the facts you need to protect your clients.
The 2017 Webroot Threat Report provides a uniquely insightful global view into the analysis and discoveries made by the Webroot® Threat Intelligence Platform to provide insights on key trends and risks as seen by our users.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This is a guide to the following problem (not exclusive but here) on Windows: Users need our support and we supporters often use global administrative accounts to do this. Using these accounts safely is a real challenge. Any admin who takes se…
Container Orchestration platforms empower organizations to scale their apps at an exceptional rate. This is the reason numerous innovation-driven companies are moving apps to an appropriated datacenter wide platform that empowers them to scale at a …
In this video you will find out how to export Office 365 mailboxes using the built in eDiscovery tool. Bear in mind that although this method might be useful in some cases, using PST files as Office 365 backup is troublesome in a long run (more on t…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
Suggested Courses

624 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question