+ Reply to Thread
Results 1 to 3 of 3

Thread: Group Policy advice needed (GPOs & ADM files)

  1. #1
    mrsh is offline 10+ Helpful Posts Happy to be helping others
    Join Date
    Mar 2010
    Posts
    10

    Question Group Policy advice needed (GPOs & ADM files)

    Hi all

    We're in the midst of a desktop rebuild project and will shortly migrate 1500+ machines from XPSP2/Office2003/IE6 to XPSP3/Office2007/IE8. We need to amend our Group Policy structure to accommodate the 'new build' environment alongside the existing environment. We have considered 3 different approaches:-

    1. Create a brand new O.U. structure altogether then move users and computers across as and when they are migrated. [Unnecessary duplication of O.U.s.]
    2. Retain the existing O.U. structure and add the Office 2007 ADM files to the existing Group Policy Object (GPO) with the 2003 ADM files. [This will increase the size of the GPOs to be processed, hence increase logon times. Also it is unknown whether applying the 2003 and 2007 ADM files in unison will cause conflicts]
    3. Create 2 new GPOs (one for Office2007/IE and the other for site-specific re-directed folders). Then add the 2 new GPOs to each UK site within the existing O.U. structure and filter processing of both the existing and new GPOs based on security group membership. We understand this approach follows Microsoft best practice and moves away from the security compromises posed when using the Authenticated Users group, as in the case of our existing GPOs. This is our preferred option but we thought of the following issues:-

    Q1. We have found user group membership inconsistencies so we cannot rely on altering the existing GPOs by replacing Authenicated Users with office-based groups in the Security Filtering. And surely adding all domains users individually is not practical.

    Q2. The existing computers are not a member of any office-based groups so we see no easy way to move away from Authenicated Users and apply the appropriate Security Filtering.

    Unless the necessary housekeeping is done for all users and computers (time is against us!) these 2 issues may be the show-stoppers that mean we may have to implement a brand new O.U. structure after all.

    Can anyone offer any help or an alternative solution that we may have overlooked please?

    Thanks
    Scott

  2. #2
    captcomputer is offline Getting Started on GPanswers.com
    Join Date
    Feb 2010
    Posts
    1

    Default WMI Filtering

    Scott, are all of your machines Windows XP based? If so then you could target using WMI filters.
    If your environment only consist of XP SP2(Old and Busted) and XP SP3(New and Hotness) then use WMI filtering to target the Win32_OperatingSystem class.

  3. #3
    mrsh is offline 10+ Helpful Posts Happy to be helping others
    Join Date
    Mar 2010
    Posts
    10

    Smile

    Quote Originally Posted by captcomputer View Post
    Scott, are all of your machines Windows XP based? If so then you could target using WMI filters.
    If your environment only consist of XP SP2(Old and Busted) and XP SP3(New and Hotness) then use WMI filtering to target the Win32_OperatingSystem class.
    Great suggestion but we've eventually decided to create a new O.U. structure and move the users and computers as and when they are migrated.

    Having said that, I'll be testing your suggestion and will put my recommendations forward.

    Many thanks for your reply and advice.

    Scott

+ Reply to Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts

Search Engine Friendly URLs by vBSEO