Best way to deploy Group Policy Objects...

Posted on 2009-12-17
Medium Priority
Last Modified: 2012-05-08
I'm asking this question to get some feed back on how you guys deploy GPO's. I'm a heavy user of GP, but never had one or a group of people say this is the way they do it because... My question is, do you deploy a GP for a specific task such as mapping drives and that's it or do you deploy a lot of actions into one GP, such as printers, drives, shortcuts and other items. I can see the win-win for doing it both ways, but just wanted to ask you guys and see the way you do it and maybe a reason for it. I really do not think there is a bad way to do it, but wanted to get some feedback on it. Thanks for the discussion guys, it is greatly appreciated.
Question by:ChiBot
LVL 70

Expert Comment

ID: 26072663
Its always a compromise between having a small number of GPOs with lots of settings (that get applied quickly but are more of a problem to manage), and having lots of GPOs each doing a specific thing (which takes longer to apply but is easier to manage).
LVL 13

Expert Comment

ID: 26072704
I do a lot of stuffs through GP. I don't put a lot of actions in one GP and i don't think that's the best way to do.

Author Comment

ID: 26072740
It is something that I have always thought over. I'm not in a large organization by any means, so it is easy to break them off into single GPO's and not have 100s. I posted this because I'm really rethinking my GP because of the new preferences they added with the release of 7/2008. Just so much more to control and wanted to get a feel of what other people are doing. Thanks for your quick responses.
LVL 35

Accepted Solution

Joseph Daly earned 1000 total points
ID: 26072753
This is definitely open for alot of discussion. We have some gpos that are configured both ways. Our default domain policy has many settings in it that we use to get the computer to the baseline we would like. We also have other single gpos that do specific modifications or updates for systems when necessary.

I kind of like the idea of having individual GPOs for each options you would like to configure. In my mind it is just easier to track down an issue or conflict if you know exactly what each GPO does and there arent a million settings in them.
LVL 57

Assisted Solution

by:Mike Kline
Mike Kline earned 1000 total points
ID: 26073571
Yeah I agree with everyone else, it depends.  I just wanted to post a great article by top GP MVP Darren Mar-Elia.  From Technet Magazine last year...very well written article.  That is where I learned that disabling the computer or user section of a GPO did nothing...I was wrong on that for so many years :)
Optimizing Group Policy Performance

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Group policies can be applied selectively to specific devices with the help of groups. Utilising this, it is possible to phase-in group policies, over a period of time, by randomly adding non-members user or computers at a set interval, to a group f…
Wouldn't it be nice if objects in Active Directory automatically moved into the correct Organizational Units? This is what AutoAD aims to do and as a plus, it automatically creates Sites, Subnets, and Organizational Units.
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Suggested Courses

850 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question