Solved

group policy computer configuration or user configuration

Posted on 2016-09-26
7
42 Views
Last Modified: 2016-11-08
i am trying to figure out the difference between using the settings in computer configuration compared to user configuration.
if you have a setting in the computer configuration, will the settings take place no matter who logs in as long as that computer is in the ou?

some of the settings are the same, computer configuration, windows settings, shortcuts and user configuration, windows settings, shortcuts. what is the difference? when is each applied?
0
Comment
Question by:stevekee65
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 6

Assisted Solution

by:sAMAccountName
sAMAccountName earned 250 total points
ID: 41816648
This is a rich and complex topic with several components that should be considered.

You are correct (at least superficially) that computer settings will be applied regardless of who logs on.  Some policy configuration settings exist in both user and computer simply to provide you the flexibility to choose how you want it applied.  Some exist in both because they have a specific context and though the may look and behave similar, they are configured differently.  There is also loopback policy processing which can further affect how policy is applied.

Theres a ton of really good resources out there and I would urge you to read up on it as much as you can.  Im not sure if a thread like this will ever capture all there is to understand everything (client side polciy processing, configuration, scoping, filtering etc...)

This series is a great place to start
Group policy basics tutorial (MSDN Blog)

Some additional information regarding client side and loopback policy processing
Client Side Processing (technet)
Loopback policy processing (DirTeam blog)
0
 
LVL 13

Accepted Solution

by:
Norm Dickinson earned 125 total points
ID: 41816670
Here is an overview of the precedence in Group Policy: https://emeneye.wordpress.com/2016/02/16/group-policy-order-of-precedence-faq/

Here is a Microsoft article that does a pretty good job of explaining the precedence as well.
https://blogs.technet.microsoft.com/musings_of_a_technical_tam/2012/02/15/group-policy-basics-part-2-understanding-which-gpos-to-apply/

Each update is applied in order. There are options to make sure a particular policy survives the depths of the GPO, and other options to ensure it only works on the layer it is found. (You can get very complex very quickly if you start to use those options for much.)

There is also a tool to help compute the resultant policy which is explained in the Microsoft page. Enjoy!
0
 

Author Comment

by:stevekee65
ID: 41816777
how can i install something on the client so that all of the users will be able to see it and use it?
0
Online Training Solution

Drastically shorten your training time with WalkMe's advanced online training solution that Guides your trainees to action. Forget about retraining and skyrocket knowledge retention rates.

 

Author Comment

by:stevekee65
ID: 41816811
so if i apply a shortcut to the computer configuration, will it be seen by everyone who uses the computer?
0
 
LVL 6

Assisted Solution

by:sAMAccountName
sAMAccountName earned 250 total points
ID: 41816865
It should unless another policy configures the same setting differently and overrides it.
0
 
LVL 11

Assisted Solution

by:Maclean
Maclean earned 125 total points
ID: 41816880
I think you need to read the above articles, which explain what you can or cannot do. Not much point for anyone re-writing the book on it :)
Or if you merely wish to know how to do a particular tasks, perhaps ask us to tell you what you need to do, by describing the work scope.

Based on what you are asking here, I would suggest that  if you wish to push out a shortcut to all users, that you follow this Microsoft blog which shows you how to, including pics etc. Good luck!.

Adding Desktop Shortcuts via GPO
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently, Microsoft released a best-practice guide for securing Active Directory. It's a whopping 300+ pages long. Those of us tasked with securing our company’s databases and systems would, ideally, have time to devote to learning the ins and outs…
After seeing many questions for JRNL_WRAP_ERROR for replication failure, I thought it would be useful to write this article.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

695 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question