While more than 80 percent of Windows users in North America have deployed Active Directory, according to market research firm IDC, Microsoft officials say only 50 to 60 percent are using its Group Policy technology. If you manage Windows computers, Group Policy can reduce IT costs, improve security and increase uptime by giving you centralized control of your client and server computers.
Though there are some limitations in its capabilities, here’s how to deploy and benefit from Group Policy. For administrators already using Group Policy, here’s an opportunity to review its capabilities and verify that you are getting the most out of your infrastructure.
Group Policy is a way to manage settings and software on multiple Windows computers. Some of the settings you can define include:
Additionally, administrators or software vendors can add custom Group Policy settings by using Administrative Templates [5]. To familiarize yourself with Group Policy settings, follow these steps [6] to browse Group Policy settings on your local computer, or review the Group Policy Settings Reference [7].
All Windows computers have a local Group Policy object that defines settings for that computer. However, the real benefit of Group Policy is the ability to configure multiple computers. For that, you need an Active Directory domain. If you’re not familiar with Active Directory [8], it is a Microsoft directory service that requires Windows Server 2003 [9]. Active Directory can scale to any size enterprise and provides many other benefits besides Group Policy, including centralized user management, simplified DNS management and software distribution.
When deployed in an Active Directory environment, Group Policy gives you the flexibility to apply settings to computers in a way that mirrors your organization’s structure. Figure 1 shows a simple Group Policy organizational hierarchy. In this hierarchy, a Group Policy object applied at the Domain level would apply to every user and computer in the organization. However, you could overwrite some or all of those settings for the Marketing, IT or Accounting departments by applying Group Policy to those organizational units. For example, if developers need Visual Studio and local Administrator rights, no problem—just specify those settings in a Group Policy object and add the Group Policy object to the Developers organizational unit.
In addition to custom organizational units, you can assign Group Policy objects based on location (known as Sites in Active Directory), operating system and a variety of other factors. Ultimately, this gives you total control over how you configure the computers in your organization. You can even delegate management over parts of your organization, enabling regional and departmental IT groups to make their own decisions about the computers they are responsible for.
There are several tools you can use to configure, apply, and audit Group Policy settings:
[Figure 2 [12]] The GPMC is a requirement for all administrators managing Group Policy objects in an Active Directory domain.
Additional tools are available from both Microsoft [17] and third-parties [18].
Group Policy is a necessity for any organization managing more than a handful of Windows computers. It’s not perfect, however. First, Group Policy has only very limited abilities to manage non-Windows computers, so you may need to purchase third-party software such as the LANDesk Management Suite or Symantec’s LiveState Client Management if you manage UNIX, Linus or Apple clients or servers.
Second, it’s difficult to use Group Policy to manage computers not in an Active Directory domain. Consumer versions of Windows, including Windows XP Home Edition, Windows ME, and Windows 98, cannot join a domain. Therefore, you may need to upgrade some client computers to realize all the benefits of Group Policy.
Finally, the Group Policy and Active Directory infrastructure are included with Windows Server 2003, but that doesn’t mean it comes free. Depending on the size of your organization, you may need anywhere from two to dozens of Windows Server 2003 computers for the Active Directory infrastructure. You’ll also have to train your IT staff to use Group Policy and manage the deployment of your organization’s computers.
Group Policy will almost certainly save you time and money if you manage more than a handful of Windows computers. If you want to deploy Group Policy, start by deploying an Active Directory. Then, design a Group Policy hierarchy that will enable you to efficiently manage your environment with the fewest number of Group Policy objects possible. For information about how to design and deploy a Group Policy infrastructure, a good place to start is Chapters 1 through 4 of the Windows Server 2003 Deployment Kit: Designing a Managed Environment [19].
Links:
[1] http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/TechRef/1f52744d-02d1-421d-bc85-af90cc0ddb26.mspx
[2] http://support.microsoft.com/default.aspx?scid=kb;en-us;324036
[3] http://www.microsoft.com/windowsserversystem/updateservices/default.mspx
[4] http://www.microsoft.com/smserver/default.mspx
[5] http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/TechRef/8f0daf74-1eac-4d47-ac8a-bcbe23c67352.mspx
[6] http://support.microsoft.com/default.aspx?scid=kb;en-us;307882&sd=tech
[7] http://www.microsoft.com/downloads/details.aspx?FamilyID=7821C32F-DA15-438D-8E48-45915CD2BC14&displaylang=en
[8] http://www.microsoft.com/windowsserver2003/technologies/directory/activedirectory/default.mspx
[9] http://www.microsoft.com/windowsserver2003/default.mspx
[10] http://www.microsoft.com/downloads/details.aspx?FamilyID=0A6D4C24-8CBD-4B35-9272-DD3CBFC81887&displaylang=en
[11] http://www.microsoft.com/downloads/details.aspx?FamilyID=c06516f2-86fd-48ba-8502-970f2dec0c5a&DisplayLang=en
[12] http://www.biztechmagazine.com/sites/default/files/legacy/items/2006/v2n2/images/wx1_f2.jpg
[13] http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/ServerHelp/5b388f78-b2a0-4ae6-898e-e06a91020899.mspx
[14] http://support.microsoft.com/default.aspx?scid=kb;en-us;816585
[15] http://support.microsoft.com/default.aspx?scid=kb;en-us;323276
[16] http://www.microsoft.com/downloads/details.aspx?FamilyID=1D24563D-CAC9-4017-AF14-8DD686A96540&displaylang=en
[17] http://www.microsoft.com/downloads/results.aspx?freetext=group%20policy&productID=&categoryId=12&period=&sortCriteria=popularity&nr=50&DisplayLang=en&type=a
[18] http://www.microsoft.com/windowsserver2003/technologies/management/grouppolicy/gptools.mspx
[19] http://www.microsoft.com/downloads/details.aspx?FamilyID=b671967b-ef65-4ccf-9d00-89d6ae428edc&DisplayLang=en