Active Directry 101 Create and Manage Grup Plicy Sander Berkuwer CTO at SCCT 10-fld Micrsft MVP Active Directry aficinad Daniel Gater Systems Engineer Netwrix
Active Directry 101 Micrsft exam 70-742 Identity with Windws Server 2016 Active Directry 101 vs. Exam 70-742 Implement and manage a certificate authrity (CA) hierarchy with AD CS Deply and manage certificates Implement and administer Active Directry Federatin Services (AD FS) Implement and administer Active Directry Rights Management Services (AD RMS) Implement synchrnizatin between AD DS and Azure AD Mnitr, trublesht, and establish business cntinuity fr AD DS services Secure AD DS and user accunts Manage user settings by using GPOs Implement and manage Grup Plicy Cnfigure and manage replicatin Implement AD DS sites Implement AD DS in cmplex envirnments Manage bjects in AD DS Install and cnfigure Dmain Cntrllers
Agenda Implementing Grup Plicy Managing User settings with Grup Plicy Grup Plicy Best Practices Hw t deliver cmplete visibility int all security and cnfiguratin changes in Grup Plicy
Implementing Grup Plicy
Intrductin t Grup Plicy Centralized apprach t applying ne r mre changes t mre than ne user r cmputer Very pwerful tl, in the right hands, t Apply security settings Manage the Windws (Server) experience Deply sftware Cnfigure netwrking Grup Plicy Objects, Settings and Links Apply settings t Dmains, OUs, Sites and/r lcal cmputers Despite its name, yu can t apply Grup Plicies t individual users r grups
Tls fr managing Grup Plicy Graphical Tls Grup Plicy Management Cnsle (gpmc) Grup Plicy Editr (gpedit) Cmmand-line Tls GPUpdate.exe GPResult.exe PwerShell Invke-gpupdate Advanced Grup Plicy Management (AGPM) tl Part f Sftware Assurance Allws versining, etc.
Hw Grup Plicy settings are applied Grup Plicy Objects are linked Enabled vs. Disabled GPOs Grup Plicy Prcessing Order and Precedence Lcal Grup Plicies, Site, Dmain, OUs Last setting t be applied wins Precedence when multiple links n Site, Dmain r OU: lwest number last Blck Inheritance vs. Enfrced Lpback prcessing Replace mde vs. Merge mde Ideal fr Remte Desktp Sessin Hsts, public-use cmputers Security Filtering and WMI Filtering
Grup Plicy Refresh Plicy settings apply every 90-120 minutes, when clients retrieve the grup plicy settings t update their cached settings By default, nly when Grup Plicy settings have changed Grup Plicy refresh can be Changed thrugh Grup Plicies Initiated using gpupdate.exe n per dmain-jined device Initiated in the GPMC frm a Dmain Cntrller, t
Administrative Templates Cntrl the envirnment f the OS and UI OS features like Cntrl Panel, netwrk and printers UI features like Desktp, netwrk, Start Menu and taskbar Tw file types: *.adm Cpied int every GPO in the System Vlume (SYSVOL) *.admx and *.adml Nt stred in the GPO Language Neutral Administrative Templates make Grup Plicy expandable
The Grup Plicy Central Stre Central repsitry fr *.admx and *.adml in SYSVOL Must be created manually and files must be cpied manually Frm C:\Windws\PlicyDefinitins, and dwnlads T \\dmain.tld\sysvol\dmain.tld\plicies\plicydefinitins
Grup Plicy Preferences Extensins t Grup Plicy Settings Manage settings previusly unavailable Map drives Create shrtcuts Cnfigure pwer ptins Schedule tasks Cnfigure Internet Explrer D nt cause the UI fr these settings t grey ut Use Grup Plicy Refresh by default, but can be cnfigured t nly run nce
Trubleshting Grup Plicy When d Grup Plicy settings apply? Cmputer settings in a GPO apply at startup f device User settings in a GPO apply at lgn f user Grup Plicy Refresh interval (Security Settings at least every 16 hurs) Manual Grup Plicy Refresh Hw d I knw what GPO applies certain settings? Why is a device taking lng Applying Grup Plicy settings? Use the Grup Plicy Results Wizard in GPMC Use GPResults.exe Use Get-GPResultantSetOfPlicy
Delegating Grup Plicy Management Yu can delegate Grup Plicy Management t nn-dmain Admins: Create Edit Manage links Perfrm Mdeling Reading Grup Plicy results data Creating WMI Filters But nt: Backup and Restre Cpy and Imprt Manage Starter GPOs
Managing user settings with Grup Plicy
Flder Redirectin Flder Redirectin allws flders t be lcated n a netwrk server, but appear as if they are lcated n a lcal drive Basic Flder Redirectin: All users save t the same lcatin Advanced Flder Redirectin: Grup membership-based lcatins By default, Administratrs have n permissins n user flders
Distributing sftware and running scripts Yes, yu can install sftware using Grup Plicy Assign sftware: install at next startup/lgn Publish sftware Manual install frm Cntrl Panel Autmatically install based n file extensins Yes, yu can run scripts with Grup Plicy autmatically Fur available triggers fr scripts: Cmputer: startup scripts and shutdwn scripts User: lgn scripts and lgff scripts Asynchrnus (default) and synchrnus script prcessing
Grup Plicy best practices
Grup Plicy Best Practices Implement the Grup Plicy Central Stre D nt use the Grup Plicy functinality t set passwrds Avid using Enfrce and Blck Inheritance Avid linking GPOs t Sites Avid elabrate WMI Filters Replace scripts with Grup Plicy Preferences D nt place Grup Plicy Settings and Grup Plicy Preferences in the same GPO
Netwrix Auditr fr Active Directry
Abut Netwrix Crpratin Year f fundatin: 2006 Headquarters lcatin: Irvine, Califrnia Custmer supprt: glbal 24/5 supprt with 97% custmer satisfactin Glbal custmer base: ver 9,000 Recgnitin: Amng the fastest grwing sftware cmpanies in the US with 140 industry awards frm Redmnd Magazine, SC Magazine, Windws IT Pr and thers
Netwrix Auditr Unified Platfrm Netwrix Auditr fr Active Directry Netwrix Auditr fr Exchange Netwrix Auditr fr Windws Server Free Add-Ons Netwrix Auditr fr Windws File Servers Netwrix Auditr fr EMC Netwrix Auditr fr NetApp Netwrix Auditr fr Azure AD Netwrix Auditr fr Office 365 Netwrix Auditr fr SharePint Linux Unix Netwrix Auditr fr SQL Server Netwrix Auditr fr Oracle Database Netwrix Auditr fr VMware
Netwrix Auditr Demnstratin
Next Steps Experiment with Grup Plicy in yur testlab Cntact Sales t btain mre infrmatin netwrix.cm/cntactsales Live One-t-One Dem: prduct tur with Netwrix expert netwrix.cm/livedem Upcming and On-Demand Netwrix Webinars: jin upcming webinars r watch previusly recrded sessins netwrix.cm/webinars netwrix.cm/webinars#featured Visit: dirteam.cm fr mre Active Directry infrmatin
Questins? Thank yu! Sander Berkuwer CTO at SCCT 10-fld Micrsft MVP Active Directry aficinad Daniel Gater Systems Engineer Netwrix