<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>RO Windows Administrators Weblog &#187; Group Policy</title>
	<atom:link href="http://www.winadmin.ro/tag/group-policy/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.winadmin.ro</link>
	<description>Weblogul adminilor de Windows din Romania.</description>
	<lastBuildDate>Wed, 28 Jul 2010 15:34:54 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Group Policy Search Tool</title>
		<link>http://www.winadmin.ro/2010/05/26/group-policy-search-tool/</link>
		<comments>http://www.winadmin.ro/2010/05/26/group-policy-search-tool/#comments</comments>
		<pubDate>Wed, 26 May 2010 04:00:00 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Group Policy]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/?p=1612</guid>
		<description><![CDATA[Iata o aplicatie in nor destul de interesanta: http://gps.cloudapp.net Poate fi folosita ca si referinta pentru majoritatea seterilor din GPO. Si merge adaugata ca si search provider in Internet Explorer. Un must have pentru orice GPO admin.]]></description>
			<content:encoded><![CDATA[<p>Iata o aplicatie in nor destul de interesanta: <a title="http://gps.cloudapp.net" href="http://gps.cloudapp.net">http://gps.cloudapp.net</a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image118.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb115.png" width="625" height="484" /></a></p>
<p>Poate fi folosita ca si referinta pentru majoritatea seterilor din GPO.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image119.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb116.png" width="633" height="484" /></a></p>
<p>Si merge adaugata ca si search provider in Internet Explorer.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image120.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb117.png" width="306" height="484" /></a></p>
<p>Un must have pentru orice GPO admin.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/05/26/group-policy-search-tool/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>How to change active network profile name and icon.</title>
		<link>http://www.winadmin.ro/2010/02/08/how-to-change-active-network-profile-name-and-icon/</link>
		<comments>http://www.winadmin.ro/2010/02/08/how-to-change-active-network-profile-name-and-icon/#comments</comments>
		<pubDate>Mon, 08 Feb 2010 05:00:00 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Windows Client]]></category>
		<category><![CDATA[Windows Server]]></category>
		<category><![CDATA[Group Policy]]></category>
		<category><![CDATA[Network Icon]]></category>
		<category><![CDATA[Network Name]]></category>
		<category><![CDATA[Useless Features]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/?p=665</guid>
		<description><![CDATA[&#160; Recunosc ca ma rodea sa aflu cum se face de vreo saptamana si am tot cautat sa vad cum se face. Mai exact sa obtii ceva de genul asta pe statiile utilizatorilor din domeniu: Pentru cine nu observa, apare un logo customizat + nume pentru profilul de retea activ. &#160; Se face din Group [...]]]></description>
			<content:encoded><![CDATA[<p>&#160;</p>
<p>Recunosc ca ma rodea sa aflu cum se face de vreo saptamana si am tot cautat sa vad cum se face. Mai exact sa obtii ceva de genul asta pe statiile utilizatorilor din domeniu:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/02/image4.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/02/image_thumb4.png" width="319" height="214" /></a></p>
<p>Pentru cine nu observa, apare un logo customizat + nume pentru profilul de retea activ. </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/02/image5.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/02/image_thumb5.png" width="642" height="484" /></a></p>
<p>&#160;</p>
<p>Se face din Group Policy – Computer Configuration\Policies\Windows Settings\Security Settings\Network List Manager Policies</p>
<p>&#160;</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/02/image1.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/02/image_thumb1.png" width="644" height="457" /></a></p>
<p>&#160;</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/02/image2.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/02/image_thumb2.png" width="408" height="450" /></a></p>
<p>&#160;</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/02/image3.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/02/image_thumb3.png" width="408" height="450" /></a>&#160;</p>
<p> Bineinteles ca e nevoie de Windows 7 sau Vista pe statiile userilor.</p>
<p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/02/image5.png"></a></p></p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/02/08/how-to-change-active-network-profile-name-and-icon/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ce trebuie sa stim despre Group Policy.</title>
		<link>http://www.winadmin.ro/2010/02/04/ce-trebuie-sa-stim-despre-group-policy/</link>
		<comments>http://www.winadmin.ro/2010/02/04/ce-trebuie-sa-stim-despre-group-policy/#comments</comments>
		<pubDate>Thu, 04 Feb 2010 07:24:21 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Windows Server]]></category>
		<category><![CDATA[Group Policy]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2010/02/04/ce-trebuie-sa-stim-despre-group-policy/</guid>
		<description><![CDATA[&#160; Nota: Post preluat de pe ITBoard (m-am gandit ca trebuie sa-l am si aici). &#160; Cateva lucruri fundamentale care trebuie retinute despre GPO: 1. GPO-urile sunt stocate in SYSVOL (replicat pe fiecare DC). In AD exista doar un link catre GPO. Toate setarile se afla in adm-ul din SYSVOL. 2. GPO-urile nu sunt impinse [...]]]></description>
			<content:encoded><![CDATA[<p>&#160;</p>
<p><em>Nota: Post preluat de pe ITBoard (m-am gandit ca trebuie sa-l am si aici).</em></p>
<h3>&#160;</h3>
<p>Cateva lucruri fundamentale care trebuie retinute despre GPO:</p>
<p>1. GPO-urile sunt stocate in SYSVOL (replicat pe fiecare DC). In AD exista doar un link catre GPO. Toate setarile se afla in adm-ul din SYSVOL.</p>
<p>2. GPO-urile nu sunt impinse de catre domain controller. Clientul citeste si aplica GPO-urile stocate in AD (aici revenim la problema cu Adminul local pe statii – daca e admin pe statie gaseste el ceva sa fenteze GPO-ul).</p>
<p>3. Ordinea de aplicare este urmatoarea:</p>
<p>- Local Policy</p>
<p>- Site Policy</p>
<p>- Domain Policy</p>
<p>- OUs Policy (in functie de ierarhia de OU-uri din AD, GPO-ul de pe ultimul OU din ierarhie si aplica ultimul; probabil OU-ul in care se afla userul sau computer accountul). Exista ceva metode de a influenta putin ordinea dar vorbim mai tarziu.</p>
<p>In caz de conflict de setari intre GPO-uri se aplica setarile din ultimul GPO aplicat (adica suprascrie ce s-a aplicat inainte)</p>
<p>4. GPO-urile nu se aplica pe grupuri.</p>
<p>5. La nivel de OU se poate seta optiunea Block Policy Inheritance. E utila atunci cand vrem sa blocam aplicarea GPO-urilor legate la nivelele de mai sus (OU, domeniu, site).</p>
<p>6. La nivel de GPO putem seta No Override (e acelasi lucru cu Enforced in toolurile mai noi). Mai exact setarile din GPO-ul cu aceasta optiune, nu vor fi suprascrise de setarile din GPO-urile de la nivelele de mai jos. Tehnic mi se pare ca GPO-ul cu No Override se aplica ultimul.</p>
<p>7. Cand cele doua optiuni de mai sus intra in conflict are prioritate No Override.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/02/04/ce-trebuie-sa-stim-despre-group-policy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cum restaurez un GPO care a fost modificat?</title>
		<link>http://www.winadmin.ro/2010/01/19/cum-restaurez-un-gpo-care-a-fost-modificat/</link>
		<comments>http://www.winadmin.ro/2010/01/19/cum-restaurez-un-gpo-care-a-fost-modificat/#comments</comments>
		<pubDate>Tue, 19 Jan 2010 11:09:01 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[GPO]]></category>
		<category><![CDATA[GPO Rollback]]></category>
		<category><![CDATA[Group Policy]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2010/01/19/cum-restaurez-un-gpo-care-a-fost-modificat/</guid>
		<description><![CDATA[&#160; Cum restauram un GPO (Group Policy Object)? Considerand cazul in care GPO-ul nu mai poate fi citit sau setarile lui au fost modificate si sunt eronate. Simplu. Din backup,nu? Ei, dar nu e chiar asa de simplu. Hai sa vedem mai intai ce optiuni avem. &#160; 1. GPO-ul era documentat, asa ca il pot [...]]]></description>
			<content:encoded><![CDATA[<p>&#160;</p>
<p>Cum restauram un GPO (Group Policy Object)? Considerand cazul in care GPO-ul nu mai poate fi citit sau setarile lui au fost modificate si sunt eronate. Simplu. Din backup,nu?    <br /> Ei, dar nu e chiar asa de simplu. Hai sa vedem mai intai ce optiuni avem.</p>
<p>&#160;</p>
<p>1. GPO-ul era documentat, asa ca il pot sterge si reface de la zero folosind setarile din documentatie (care documentatie? <img src='http://www.winadmin.ro/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  )</p>
<p>2. Incepand cu Windows 2003, Group Policy Management Console are si optiune de a face backup la GPO-uri. Restauram folosind backup-ul facut cu GPMC.</p>
<p>3. Restauram folosind un system state backup de pe un domain controller.</p>
<p>&#160;</p>
<p>Si acum e partea interesanta. Cazul numarul 3. Sa restaurez tot system state-ul pentru un GPO? Nu. Doar GPO-ul. Pasii sunt urmatorii:</p>
<p>- restore de system state; dar in alternate location. Adica intr-un folder temporar, undeva pe server (de preferat DC; nu e recomandat ca informatiile din system state sa plece de pe domain controller)</p>
<p>- cu GPMC aflam GUID-ul GPO-ului</p>
<p>- in locatia in care am facut restore la system state cautam folderul policies din sysvol. Atentie ca aici nu mai are exact structura care o stim de pe domain controller. E posibil ca locatia sa fie de forma d:\temp\sysvol\c_\windows\sysvol\domain\policies\. Copiem continutul politicii din folderul cu GUID-ul gasit mai sus.</p>
<p>- acum ca am localizat politica dupa GUID, tot ce trebuie sa mai facem este sa stergem continutul folderului din SYSVOL si sa copiem continutul din backup (un simplu paste la ce am copiat mai sus).</p>
<p>Si cam atat … nu restart de DC-uri sau alte avioane cum am vazut prin alte articole pe net.</p>
<p>PS: cred ca un titlu bun era si GPO Rollback.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/01/19/cum-restaurez-un-gpo-care-a-fost-modificat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Group Policy Preferences</title>
		<link>http://www.winadmin.ro/2009/12/09/group-policy-preferences/</link>
		<comments>http://www.winadmin.ro/2009/12/09/group-policy-preferences/#comments</comments>
		<pubDate>Wed, 09 Dec 2009 06:00:19 +0000</pubDate>
		<dc:creator>Sebi22</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Windows Server]]></category>
		<category><![CDATA[Group Policy]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/?p=288</guid>
		<description><![CDATA[Group Policy Preferences reprezinta un feature introdus in Windows Server o data cu aparitia versiunii 2008. Sunt incluse, atat pentru computere, cat si pentru useri, extensii care ne permit sa configuram anumite setari pentru care obisnuiam (de fapt eram nevoiti) sa folosim scripturi. De exemplu, folosind Group Policy Preferences, putem seta parola userului local Administrator [...]]]></description>
			<content:encoded><![CDATA[<p>Group Policy Preferences reprezinta un feature introdus in Windows Server o data cu aparitia versiunii 2008.</p>
<p>Sunt incluse, atat pentru computere, cat si pentru useri, extensii care ne permit sa configuram anumite setari pentru care obisnuiam (de fapt eram nevoiti) sa folosim scripturi. De exemplu, folosind Group Policy Preferences, putem seta parola userului local Administrator sau adauga un user in grupul de administratori locali pe toate computerele sau pe o parte din ele, putem mapa Network Drives, putem face deploy de imprimante, putem configura Power Options, Folder Options, Registry settings si multe altele.</p>
<p> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/12/clip_image001.jpg"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" src="http://www.winadmin.ro/wp-content/uploads/2009/12/clip_image001_thumb.jpg" border="0" alt="clip_image001" width="843" height="633" /></a></p>
<p> </p>
<p>Toate aceste setari se pot aplica pe toate computerele, pe toti userii sau in functie de filtrele pe care le aplicam folosind Item-Level Targeting. Putem filtra aplicarea politicii dupa numele computerului sau al userului, dupa apartenenta la un grup sau OU, dupa sistemul de operare si multe alte criterii.</p>
<p> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/12/clip_image003.jpg"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" src="http://www.winadmin.ro/wp-content/uploads/2009/12/clip_image003_thumb.jpg" border="0" alt="clip_image003" width="850" height="529" /></a></p>
<p> </p>
<p>Pentru a putea folosi Group Policy Preferences, avem nevoie de urmatoarele:</p>
<p>- Pe computerele din domeniu trebuie instalat KB943729 – Group Policy Client-Side Extensions, disponibil pentru Windows XP minim SP2, Windows Server 2003 minim SP1, Windows Vista; XMLLite pe statiile cu Windows XP (KB915865) si Windows 2003 ( KB914783).</p>
<p>- Un server/statie de lucru cu Windows Server 2008/2008 R2 sau Windows Vista/7 cu RSAT.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2009/12/09/group-policy-preferences/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Group Policy Security Filtering (I)</title>
		<link>http://www.winadmin.ro/2009/11/10/group-policy-security-filtering-i/</link>
		<comments>http://www.winadmin.ro/2009/11/10/group-policy-security-filtering-i/#comments</comments>
		<pubDate>Tue, 10 Nov 2009 02:24:36 +0000</pubDate>
		<dc:creator>Bogdan Morosan</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Group Policy]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2009/11/10/group-policy-security-filtering-i/</guid>
		<description><![CDATA[&#160; In ciuda numelui, Group Policy nu se aplica grupurilor ci utilizatorilor si calculatoarelor in functie de containerul (OU), domeniul sau site-ul in care se afla. Si totusi cum putem controla aplicarea Group Policy in functie de un grup de securitate? Raspunsul este prin intermediul “security filtering”. Obiectele de tip Group Policy au, ca orice [...]]]></description>
			<content:encoded><![CDATA[<p>&#160;</p>
<p>In ciuda numelui, Group Policy nu se aplica grupurilor ci utilizatorilor si calculatoarelor in functie de containerul (OU), domeniul sau site-ul in care se afla. Si totusi cum putem controla aplicarea Group Policy in functie de un grup de securitate? Raspunsul este prin intermediul “security filtering”. </p>
<p>Obiectele de tip Group Policy au, ca orice alt obiect din Active Directory, un set de liste de control al accesului (ACL) care determina permisiunile. Prin intermediul acestor ACLs putem filtra accesul pentru anumite grupuri sau conturi de utilizator/computer. Care sunt ACL-urile implicite ale unui GPO?</p>
<p>Deschideti consola Group Policy Management:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/11/GPMgmt.jpg"><img style="border-top-width: 0px;border-left-width: 0px;border-bottom-width: 0px;border-right-width: 0px" height="384" alt="GPMgmt" src="http://www.winadmin.ro/wp-content/uploads/2009/11/GPMgmt_thumb.jpg" width="644" border="0" /></a>&#160;</p>
<p>Click pe politica dorita in partea stanga a ferestrei de browsing si selectati tab-ul Delegation:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/11/Delegation.jpg"><img style="border-top-width: 0px;border-left-width: 0px;border-bottom-width: 0px;border-right-width: 0px" height="384" alt="Delegation" src="http://www.winadmin.ro/wp-content/uploads/2009/11/Delegation_thumb.jpg" width="644" border="0" /></a> </p>
<p>Pentru o afisare mai familiara a permisiunilor click pe butonul Advanced:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/11/ACLs.jpg"><img style="border-top-width: 0px;border-left-width: 0px;border-bottom-width: 0px;border-right-width: 0px" height="484" alt="ACLs" src="http://www.winadmin.ro/wp-content/uploads/2009/11/ACLs_thumb.jpg" width="433" border="0" /></a> </p>
<p>Pentru ca un GPO sa se aplice unui cont de utilizator/computer trebuie ca acest cont, sau grupul din care face parte, sa aiba cel putin permisiunea “Allow” pentru “Read” <strong>si</strong> “Apply group policy”. Aceasta inseamna ca implicit pentru toti membrii grupului “Authenticated Users” se va aplica politica respectiva. Membrii acestui grup sunt toate conturile de utilizator sau computer care au fost autentificate de catre un Domain Controller. Desi membrii “Domain Admins” nu au permisiunea “Allow” “Apply group policy”, politica li se va aplica prin intermediul apartenentei implicite la grupul “Authenticated Users”.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/11/DomAdm.jpg"><img style="border-top-width: 0px;border-left-width: 0px;border-bottom-width: 0px;border-right-width: 0px" height="484" alt="DomAdm" src="http://www.winadmin.ro/wp-content/uploads/2009/11/DomAdm_thumb.jpg" width="433" border="0" /></a> </p>
<p>In cazul in care doriti sa aplicati o politica noua pentru toti utilizatorii din domeniu, dar sa nu si pentru administratorii de domeniu (Domain Admins) aveti doua variante la dispozitie:</p>
<p>1. Scoateti grupul “Authenticated Users” din lista si folositi in locul lui un grup specific.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/11/Filt1.jpg"><img style="border-top-width: 0px;border-left-width: 0px;border-bottom-width: 0px;border-right-width: 0px" height="484" alt="Filt1" src="http://www.winadmin.ro/wp-content/uploads/2009/11/Filt1_thumb.jpg" width="433" border="0" /></a> </p>
<p>Atentie! In cazul folosirii grupului “Domain Users” contul “Administrator” nu va fi exceptat de la aplicarea politicii pentru ca face parte si din acest grup.</p>
<p>2. Pentru grupul “Domain Admins” activati permisiunea “Deny” “Apply Group Policy”.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/11/Filt2.jpg"><img style="border-top-width: 0px;border-left-width: 0px;border-bottom-width: 0px;border-right-width: 0px" height="484" alt="Filt2" src="http://www.winadmin.ro/wp-content/uploads/2009/11/Filt2_thumb.jpg" width="434" border="0" /></a> </p>
<p>&#160;</p>
<p>In partea a doua a articolului va voi prezenta un scenariu mai complex de filtrare a Group Policy.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2009/11/10/group-policy-security-filtering-i/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Din seria Group Policy Tattooing</title>
		<link>http://www.winadmin.ro/2009/11/05/din-seria-group-policy-tattooing/</link>
		<comments>http://www.winadmin.ro/2009/11/05/din-seria-group-policy-tattooing/#comments</comments>
		<pubDate>Thu, 05 Nov 2009 06:00:00 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Group Policy]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2009/11/05/din-seria-group-policy-tattooing/</guid>
		<description><![CDATA[&#160; Tattooing??? What is that? Termenul e cunoscut pentru cei ce citesc gpoguy.com; eu il stiu tot de acolo ca nu stiam cum sa denumesc “fenomenul”. Sa incep sa explic: ai policy aplicat peste un user sau computer, trebuie sa-l stergi, il stergi, dar setarile raman in continuare. Cum asa? Pai probabil ca acele registry [...]]]></description>
			<content:encoded><![CDATA[<p>&#160;</p>
<p>Tattooing??? What is that?</p>
<p>Termenul e cunoscut pentru cei ce citesc gpoguy.com; eu il stiu tot de acolo ca nu stiam cum sa denumesc “fenomenul”. Sa incep sa explic: ai policy aplicat peste un user sau computer, trebuie sa-l stergi, il stergi, dar setarile raman in continuare.</p>
<p>Cum asa? Pai probabil ca acele registry settings aplicate prin GPO nu se incadreaza in zonele din registry care sunt sterse cand policy-ul se modifica. Ceva detalii despre asta gasiti pe <a href="http://www.gpoguy.com/FAQs/Whitepapers/tabid/63/articleType/ArticleView/articleId/5/Understanding-Policy-Tattooing.aspx">GPOGUY</a>.</p>
<p>Azi m-am intalnit din nou cu fenomenul asta, insa fiind patit de multe ori am testat inainte si bine am facut. Exista setari chiar si in Administrative Templates care sufera de problema asta (in scenariul meu foloseam W2K3 si XP pe client):</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/11/image5.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2009/11/image_thumb5.png" width="644" height="448" /></a> </p>
<p>Deci, simpla stergere sau dezactivare a policy-ului nu o sa-mi scoata setarile de proxy din IE de pe statii. E nevoie sa las policy-ul aplicat si sa fac Uncheck la optiunea “Enable proxy settings”.</p>
<p>Concluzia: testati de fiecare data setarile aplicate prin GPO; si la add si la remove.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2009/11/05/din-seria-group-policy-tattooing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Shutdown Event Tracker &#238;n Windows Server 2003 și 2008</title>
		<link>http://www.winadmin.ro/2009/10/31/shutdown-event-tracker-in-windows-server-2003-si-2008/</link>
		<comments>http://www.winadmin.ro/2009/10/31/shutdown-event-tracker-in-windows-server-2003-si-2008/#comments</comments>
		<pubDate>Sat, 31 Oct 2009 06:23:00 +0000</pubDate>
		<dc:creator>Vitalie Ciobanu</dc:creator>
				<category><![CDATA[Windows Server]]></category>
		<category><![CDATA[Group Policy]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2009/10/31/shutdown-event-tracker-n-windows-server-2003-%c8%99i-2008/</guid>
		<description><![CDATA[Primul lucru pe care îl fac după ce instalez un server, este să-i scot Shut Down Event Tracker-ul. Adică: Da, recunosc că poate fi folositor uneori, dar pe mine personal mă enervează Am avut probleme cu shutdown-ul în Server 2008, când primul buton era setat să facă shutdown. Dar din 2008 R2 butonul de Shut [...]]]></description>
			<content:encoded><![CDATA[<p>Primul lucru pe care îl fac după ce instalez un server, este să-i scot Shut Down Event Tracker-ul. Adică:</p>
<p><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="Shut Down Windows" src="http://www.winadmin.ro/wp-content/uploads/2009/10/image102.png" width="350" height="415" /></p>
<p>Da, recunosc că poate fi folositor uneori, dar pe mine personal mă enervează <img src='http://www.winadmin.ro/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  Am avut <em>probleme</em> cu shutdown-ul în Server 2008, când primul buton era setat să facă shutdown. Dar din 2008 R2 butonul de Shut Down a fost schimbat cu Log Off. Cred că prea mulți au dat shut down la servere întâmplător <img src='http://www.winadmin.ro/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p>Bun, să revin la ce vreau să spun. După ce am instalat un server, îi scot traker-ul respectiv, ca să nu mă mai întrebe ce vreau să fac când apăs butonul Shut Down. Cum fac asta? Simplu:</p>
<ol>
<li>Dau un Windows+R (Run) și scriu <strong>gpedit.msc</strong>. </li>
<li>În <strong>Computer Configuration</strong>, <strong>Administrative Templates</strong>, <strong>System</strong>, fac dublu click pe <strong>Display Shutdown Event Tracker</strong>.<a href="http://www.winadmin.ro/wp-content/uploads/2009/10/image103.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="gpedit.msc" src="http://www.winadmin.ro/wp-content/uploads/2009/10/image_thumb101.png" width="640" height="318" /></a> </li>
<li>Selectez <strong>Disabled</strong> și dau <strong>OK</strong>.
<p><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="Shutdown Event Tracker" src="http://www.winadmin.ro/wp-content/uploads/2009/10/image104.png" width="405" height="449" /> </li>
<li>Închid GPO Editor. Gata. </li>
</ol>
<p>Data viitoare când o să dau Shutdown la un Server 2008, o să facă Shutdown fără să mă mai întrebe nimic. Serverul 2003 însă o să-mi mai dea o fereastră, dar măcar nu va fi nevoie să spun de ce vreau shutdown sau restart…</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2009/10/31/shutdown-event-tracker-in-windows-server-2003-si-2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Run Powershell Scripts from GPO</title>
		<link>http://www.winadmin.ro/2009/10/27/run-powershell-scripts-from-gpo/</link>
		<comments>http://www.winadmin.ro/2009/10/27/run-powershell-scripts-from-gpo/#comments</comments>
		<pubDate>Tue, 27 Oct 2009 08:00:00 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Scripting]]></category>
		<category><![CDATA[Group Policy]]></category>
		<category><![CDATA[Powershell]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2009/10/27/run-powershell-scripts-from-gpo/</guid>
		<description><![CDATA[Nou in Windows 2008R2 &#38; 7 putem face deployment la scripturi Powershell (startup sau logon): Scriptul cu extensia ps1 se copiaza in folderul scripts asociat cu politica si se adauga cu Add, fara powershell.exe in fata. Pe sistemul meu de test am avut setat deja Set-ExecutionPolicy Unrestricted. Dupa asta am setat sistemul si pe AllSigned [...]]]></description>
			<content:encoded><![CDATA[<p>Nou in Windows 2008R2 &amp; 7 putem face deployment la scripturi Powershell (startup sau logon):</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/10/image82.png"><img style="border-bottom: 0px;border-left: 0px;float: none;margin-left: auto;border-top: 0px;margin-right: auto;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2009/10/image_thumb81.png" width="624" height="484" /></a></p>
<p>Scriptul cu extensia ps1 se copiaza in folderul scripts asociat cu politica si se adauga cu Add, fara powershell.exe in fata.</p>
<p>Pe sistemul meu de test am avut setat deja Set-ExecutionPolicy Unrestricted. Dupa asta am setat sistemul si pe AllSigned si scriptul ruleaza fara probleme <img src='http://www.winadmin.ro/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2009/10/27/run-powershell-scripts-from-gpo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Simplu scenariu de utilizare GPO</title>
		<link>http://www.winadmin.ro/2009/10/12/simplu-scenariu-de-utilizare-gpo/</link>
		<comments>http://www.winadmin.ro/2009/10/12/simplu-scenariu-de-utilizare-gpo/#comments</comments>
		<pubDate>Mon, 12 Oct 2009 15:35:15 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Group Policy]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2009/10/12/simplu-scenariu-de-utilizare-gpo/</guid>
		<description><![CDATA[Articolul asta ar cam trebui sa fie continuarea celui scris pe ITBoard si sper sa fie pe placul lui Alin Prima data ar trebui sa pomenesc cate ceva despre modul in care organizam informatiile in AD. Si aici intervin Organizational Unit-urile care sunt containere in care grupam obiectele din AD. Iar modul in care proiectam [...]]]></description>
			<content:encoded><![CDATA[<p>Articolul asta ar cam trebui sa fie continuarea celui scris pe <a href="http://itboard.ro/blogs/andrei_ungureanus_blog/archive/2009/09/14/ce-trebuie-sa-stim-despre-group-policy.aspx">ITBoard</a> si sper sa fie pe placul lui Alin <img src='http://www.winadmin.ro/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Prima data ar trebui sa pomenesc cate ceva despre modul in care organizam informatiile in AD. Si aici intervin Organizational Unit-urile care sunt containere in care grupam obiectele din AD. Iar modul in care proiectam structura de Organizational Unit-uri poate fi orientat catre delegarea administrarii sau catre aplicarea de Group Policy. Nu exista nici un design batut in cuie, fiecare companie isi poate face structura de Organizational Unit-uri dupa bunul plac, insa e de retinut: nu ghidati acest design dupa departamentele din firma, sedii, functii etc, ci dupa modul in care va administrati infrastructura. Cu cat mai simpla structura cu atat mai bine. Nu vorbim de OU design acum, ci de GPOs.</p>
<p>In exemplu de azi am ales varianta cu OU pentru fiecare locatie (ex: Bucuresti), impartit in doua – Users si Computers. Scopul este de a activa setarea care spune userului daca s-a logat folosind cached credentials in cazul in care DC-ul nu e disponibil.</p>
<p>&#160;</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/10/DCR220091011113433.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;margin-left: 0px;border-left-width: 0px;margin-right: 0px" border="0" alt="DC R2-2009-10-11-11-34-33" src="http://www.winadmin.ro/wp-content/uploads/2009/10/DCR220091011113433_thumb.png" width="644" height="484" /></a></p>
<p>Dar ca exemplu o sa pun un screenshot cu o structura de OU-uri facuta dupa tipul resurselor nu dupa locatie ca sa se poate face diferenta (in continuare o sa mergem tot pe modelul geografic).</p>
<p>&#160;<a href="http://www.winadmin.ro/wp-content/uploads/2009/10/DCR220091012112050.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="DC R2-2009-10-12-11-20-50" src="http://www.winadmin.ro/wp-content/uploads/2009/10/DCR220091012112050_thumb.png" width="644" height="484" /></a></p>
<p>Acum, pentru a lucra cu GPO objects pe containerele nou create e necesar sa deschidem GPMC:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/10/DCR2200910121016371.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="DC R2-2009-10-12-10-16-37" src="http://www.winadmin.ro/wp-content/uploads/2009/10/DCR220091012101637_thumb1.png" width="644" height="484" /></a></p>
<p>Si sa facem un GPO nou sau link la unul deja existent:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/10/DCR2200910121017231.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="DC R2-2009-10-12-10-17-23" src="http://www.winadmin.ro/wp-content/uploads/2009/10/DCR220091012101723_thumb1.png" width="644" height="484" /></a></p>
<p>Odata creeat, GPO-ul poate fi gasit in containerul Group Policy Objects si tot de acolo poate fi dezactivat sau numai anumite portiuni User sau Computer settings (in cazul in care o parte din setari nu sunt folosite intr-un GPO – gen GPO care contine numai setari legate de Computer Settings – user configuration settings pot fi dezactivate pentru a grabi procesul de aplicare a politicilor).</p>
<p>&#160;</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/10/DCR2200910121019281.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="DC R2-2009-10-12-10-19-28" src="http://www.winadmin.ro/wp-content/uploads/2009/10/DCR220091012101928_thumb1.png" width="644" height="484" /></a></p>
<p>Sa ne uitam putin si in detaliile acestui GPO. Nu uitati sa le si documentati pentru ca si ceilalti administratori sa stie la ce foloseste si pentru a evita GPO-uri redundante.</p>
<p>&#160;</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/10/DCR2200910121021211.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="DC R2-2009-10-12-10-21-21" src="http://www.winadmin.ro/wp-content/uploads/2009/10/DCR220091012102121_thumb1.png" width="644" height="484" /></a></p>
<p>De remarcat acel Unique ID dupa care putem localiza policy-ul in folderul SYSVOL. User version si Computer version reprezinta numarul modificarii – eu am facut doar una in computer settings (utile atunci cand sunt probleme de replicare a politicilor intre site-uri).</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/10/DCR2200910121024141.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="DC R2-2009-10-12-10-24-14" src="http://www.winadmin.ro/wp-content/uploads/2009/10/DCR220091012102414_thumb1.png" width="644" height="484" /></a></p>
<p>&#160;</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/10/DCR2200910121024491.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="DC R2-2009-10-12-10-24-49" src="http://www.winadmin.ro/wp-content/uploads/2009/10/DCR220091012102449_thumb1.png" width="644" height="484" /></a></p>
<p>In settings vedem exact ce contine politica:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/10/DCR2200910121021491.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="DC R2-2009-10-12-10-21-49" src="http://www.winadmin.ro/wp-content/uploads/2009/10/DCR220091012102149_thumb1.png" width="644" height="484" /></a></p>
<p>&#160;</p>
<p>Acuma o sa fac o scurta pauza, asta pentru ca am pomenit de SYSVOL. Asta e locul unde sunt stocate politicile si sursa multor probleme pana la Windows 2008. Asta pentru ca mecanismul de replicare al SYSVOL in W2K/W2K3 e FRS care nu merge foarte bine. Fiecare politica nou creata mai adauga cativa MB la acel folder; deoarece fisierele ADM sunt stocate cu fiecare politica in parte pentru a permite editarea politicii de pe orice sistem cu orice OS si localizat in orice limba. Incepand cu Windows 2008 si Vista a fost introdus concepul de <a href="http://support.microsoft.com/kb/929841">ADMX Central Store</a> in care sunt stocate toate fisierele ADMX, acestea fiind disponibile pentru toate GPO-urile si nemaifacand parte din fiecare GPO separat. Chiar si cand DC-ul e 2008, daca editam GPO-ul de la o masina cu XP, acesta o sa adauge fisierele ADM la politica. Asa ca atentie mare la numarul de politici si dimensiunea folderului SYSVOL.</p>
<p>ADMX-urile pentru a incepe cu central Store la gasiti in %windir%\PolicyDefinitions</p>
<p>&#160;</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/10/DCR2200910121029051.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="DC R2-2009-10-12-10-29-05" src="http://www.winadmin.ro/wp-content/uploads/2009/10/DCR220091012102905_thumb1.png" width="644" height="484" /></a></p>
<p>&#160;</p>
<p>Ok, mergem mai departe. Am facut un GPO numit “Setari computere Bucuresti” si ne-am dat seama ca de aceleasi setari avem nevoie sa fie aplicate si peste OU-ul Ilfov. Avem 2 optiuni – mai facem un GPO, sau putem face un link catre acelasi GPO &#8211; “Setari computere Bucuresti” (eh, in cazul asta am putea sa-l redenumim si sa scoatem numele Bucuresti).</p>
<p>&#160;</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/10/DCR220091012103209.jpg"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="DC R2-2009-10-12-10-32-09" src="http://www.winadmin.ro/wp-content/uploads/2009/10/DCR220091012103209_thumb.jpg" width="644" height="484" /></a></p>
<p>&#160;</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/10/DCR220091012103226.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="DC R2-2009-10-12-10-32-26" src="http://www.winadmin.ro/wp-content/uploads/2009/10/DCR220091012103226_thumb.png" width="644" height="484" /></a></p>
<p>&#160;</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/10/DCR220091012103235.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="DC R2-2009-10-12-10-32-35" src="http://www.winadmin.ro/wp-content/uploads/2009/10/DCR220091012103235_thumb.png" width="644" height="484" /></a></p>
<p>Si am vazut ca nu e nevoie sa facem GPO-uri pentru fiecare OU nou, ci putem face link-uri catre unele deja existente (si putem avea politici generice pentru toti userii, sau politici care isi au rolul numai intr-un anumit site).</p>
<p>&#160;</p>
<p>Acum ca am vazut cum facem un GPO si cum il legam de un OU, hai sa vedem si ce setari ar trebui sa i se aplice unui user din domeniu. Pentru ca am avut la dispozitie doar un DC pe care eram logat cu userul administrator nu am avut multe optiuni. Putem obtine aceste informatii folosing Grpup Policy Results din consola, specificand userul si sistemul pe care se logheaza:</p>
<p>&#160;</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/10/DCR220091012103440.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="DC R2-2009-10-12-10-34-40" src="http://www.winadmin.ro/wp-content/uploads/2009/10/DCR220091012103440_thumb.png" width="644" height="484" /></a></p>
<p>Sau daca vrem sa vedem exact ce s-a aplicat pe acel user (nu ce <strong>ar trebui</strong> ca in cazul de mai sus) folosind GPRESULT /R (valabil in Vista, 7, 2008; pe celelalte nu e nevoie de /R, mai putin Windows 2000 unde se face cu secedit) de pe statia unde userul e logat:</p>
<p>Microsoft (R) Windows (R) Operating System Group Policy Result tool v2.0    <br />Copyright (C) Microsoft Corp. 1981-2001</p>
<p>Created On 10/12/2009 at 12:36:32 AM</p>
<p>RSOP data for ITBOARD\Administrator on DC1 : Logging Mode    <br />&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>OS Configuration:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; Primary Domain Controller    <br />OS Version:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; 6.1.7600     <br />Site Name:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; Default-First-Site-Name     <br />Roaming Profile:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; N/A     <br />Local Profile:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; C:\Users\Administrator     <br />Connected over a slow link?: No</p>
<p>COMPUTER SETTINGS    <br />&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;     <br />&#160;&#160;&#160; CN=DC1,OU=Domain Controllers,DC=itboard,DC=net     <br />&#160;&#160;&#160; Last time Group Policy was applied: 10/12/2009 at 12:33:49 AM     <br />&#160;&#160;&#160; Group Policy was applied from:&#160;&#160;&#160;&#160;&#160; DC1.itboard.net     <br />&#160;&#160;&#160; Group Policy slow link threshold:&#160;&#160; 500 kbps     <br />&#160;&#160;&#160; Domain Name:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; ITBOARD     <br />&#160;&#160;&#160; Domain Type:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; Windows 2000</p>
<p>&#160;&#160;&#160; Applied Group Policy Objects    <br />&#160;&#160;&#160; &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; Default Domain Controllers Policy     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; Default Domain Policy</p>
<p>&#160;&#160;&#160; The following GPOs were not applied because they were filtered out    <br />&#160;&#160;&#160; &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; Local Group Policy     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; Filtering:&#160; Not Applied (Empty)</p>
<p>&#160;&#160;&#160; The computer is a part of the following security groups    <br />&#160;&#160;&#160; &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; BUILTIN\Administrators     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; Everyone     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; BUILTIN\Pre-Windows 2000 Compatible Access     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; BUILTIN\Users     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; Windows Authorization Access Group     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; NT AUTHORITY\NETWORK     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; NT AUTHORITY\Authenticated Users     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; This Organization     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; DC1$     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; Domain Controllers     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; Denied RODC Password Replication Group     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; System Mandatory Level</p>
<p>USER SETTINGS    <br />&#8212;&#8212;&#8212;&#8212;&#8211;     <br />&#160;&#160;&#160; CN=Administrator,CN=Users,DC=itboard,DC=net     <br />&#160;&#160;&#160; Last time Group Policy was applied: 10/11/2009 at 11:40:43 AM     <br />&#160;&#160;&#160; Group Policy was applied from:&#160;&#160;&#160;&#160;&#160; DC1.itboard.net     <br />&#160;&#160;&#160; Group Policy slow link threshold:&#160;&#160; 500 kbps     <br />&#160;&#160;&#160; Domain Name:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; ITBOARD     <br />&#160;&#160;&#160; Domain Type:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; Windows 2000     <br />&#160;&#160;&#160; Applied Group Policy Objects     <br />&#160;&#160;&#160; &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; N/A</p>
<p>&#160;&#160;&#160; The following GPOs were not applied because they were filtered out    <br />&#160;&#160;&#160; &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; Default Domain Policy     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; Filtering:&#160; Not Applied (Empty)</p>
<p>&#160;&#160;&#160;&#160;&#160;&#160;&#160; Local Group Policy    <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; Filtering:&#160; Not Applied (Empty)</p>
<p>&#160;&#160;&#160; The user is a part of the following security groups    <br />&#160;&#160;&#160; &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; Domain Users     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; Everyone     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; BUILTIN\Administrators     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; BUILTIN\Users     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; BUILTIN\Pre-Windows 2000 Compatible Access     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; NT AUTHORITY\INTERACTIVE     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; CONSOLE LOGON     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; NT AUTHORITY\Authenticated Users     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; This Organization     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; LOCAL     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; Domain Admins     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; Group Policy Creator Owners     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; Schema Admins     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; Organization Management     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; Enterprise Admins     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; Denied RODC Password Replication Group     <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; High Mandatory Level</p>
<p>&#160;</p>
<p>In cazul de mai sus se poate vedea ca in cazul Computerului au fost aplicate 2 GPO-uri – Default Domain Policy si Default Domain Controllers Policy. In cazul Userului acestea nu au fost aplicate pentru ca nu contineau nici o setare. </p>
<p>GPRESULT e utila si pentru a vedea din ce grupuri face parte utilizatorul dupa logon.</p>
<p>&#160;</p>
<p>Cam atat in acest post insa nu ne oprim aici cu politicile …</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2009/10/12/simplu-scenariu-de-utilizare-gpo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
