Solved

Best practice for creating share drives via GPO in server 2008 R2

Posted on 2012-04-07
3
1,857 Views
Last Modified: 2012-04-21
I want to create a few shared drives in server 2008 R2 and have them linked to GPO. I want is so that when users log in they have shared drives appear as network drives and everyone should have there own personal shared drive on the server. What would be a "best practice" configuration method. Any help or suggestions please.

Thanks
0
Comment
Question by:vmagan
3 Comments
 
LVL 26

Accepted Solution

by:
MidnightOne earned 250 total points
ID: 37821124
Window s 2008 has the basics of these already defined in the starter GPOs.

My method is thus:
A GPO for common multiple drive mappings (Everyone gets S: for shared storage, P: for company policy documents, etc.)
A GPO for specific role-based drive mappings (L: for legal documentation, T: for templates, I: for IT department, etc.)
A GPO for user or one-off mappings (Oddball mapping needed for specific users)

As far as each user's personal storage, that can be done by mapping to \\SERVER\SHARE\%username% - the %username% variable fills in with the user's SAM.

If you're feeling adventurous, you can use Kixtart and scripting logic to create one logon script that parses the user's groups and assign drive mappings based on that. For large companies I've seen it used preferentially due to the enormous upkeep required for having dozens of logon scripts otherwise.
0
 
LVL 6

Assisted Solution

by:jaredr80
jaredr80 earned 250 total points
ID: 37821603
Going off of what MidnightOne states, there is no real need to have different GPOs anymore with server 2008R2.

The current best practice is to map drives based on Group Membership. The link below shows directly how M$ recommends implementing this policy. From here you can map whatever is needed, and under the common tab, under Item-Level Targeting, you can use any sort of variable for having only specific groups of users, receive mapped drives. Regarding the scope and security filtering, depending on your AD structure, I usually have it at the top of the Domain/Forest/OU and keep the security filtering default. This is because all specific mapping is done in Item-Level targeting and therefore no need to change the scope.

http://blogs.technet.com/b/askds/archive/2009/01/07/using-group-policy-preferences-to-map-drives-based-on-group-membership.aspx

Logon scripts unless specifically needed in your environment (haven't found a reason for them yet) bog down the system and create slow logon times. Group policy is clean, easy, and efficient and is considered the current best practice.

-Jared
0
 
LVL 6

Author Closing Comment

by:vmagan
ID: 37871318
Thank you guys for the great advice. I have more than enough info now.
0

Featured Post

NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

New Windows 7 Installations take days for Windows-Updates to show up and install. This can easily be fixed. I have finally decided to write an article because this seems to get asked several times a day lately. This Article and the Links apply to…
This article explains how to install and use the NTBackup utility that comes with Windows Server.
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

785 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question