Management of GPO with security filtering ?


hello,

the staff of our principal domain wants limit number of ou in our ad.

because of that, staff wants create 1 ou "workstations" , apply specific gpos depending on security filtering applied it.

so, example, several gpos linked ou "workstations".

one of them "gpo-restrictedgroups" , applied security group contain computers.

the problem see kind of filtering local administrators not have ad management experience.

indeed, in our ad, specify in front of each computer name of user associated in description field.

in configuration, if want know computers in scope of gpo, have open security group associated, , see name , location of computer object, , nothing else (so not see description field).

for me, gpo security filtering isnt fitted larges companies.

what think ? 

is there way improve gpo configuration without creating many ou ? 

thank you

as general question, i'm not big fan of having large flat ous , trying filter gpos based strictly on security group. there's number of downsides that. you've noted administrative unfriendliness of this, i've seen bigger consequences. have pretty darn sure security filtering right, because 1 missed group filter or 1 overly locked down gpo linked big ou admin forgets remove authenticated users ace , can have major disaster. prefer using kind of more granular segregation of machine accounts, such server vs. workstation @ least, , beyond that, i've used form factor segregation (e.g. laptop, desktop, kiosk/ts, vdi, etc.). caution if using security group filtering, don't overdo it. think why need segregate particular policy , try avoid if can. policy great tool coarse-grained configuration control starts break down if try fine-grained.

darren


darren mar-elia ms-mvp, group policy
www.gpoguy.com
www.sdmsoftware.com - "the group policy experts"



Windows Server  >  Group Policy



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group