MCITP 70-640: Group Policy Processing Order

preview_player
Показать описание
In your domain you are more than likely going to have multiple Group Policies applied at different levels throughout your domain. This videos looks at which order the Group Polices will be applied in when multiple Group Policies are in use.

Processing Order
The order that Group Policy is applied in is: Local, Site, Domain, and OU. A Group Policy has the ability to overwrite any settings that were applied before. For this reason, the local Group Policy is the weakest of the Group Policies since all Group Policies at the site, domain and OU are free to overwrite any settings configured by the local Group Policy. You could also say that the OU's Group Policy is the highest priority or strongest Group Policy as it can over write local, site and domain Group Policy settings. Sub OU's are applied after the parent OU so the child OU has priority over the parent OU.

Demonstration
To edit the local Group Policy on a computer, run "Edit Group Policy" from the start menu.
To edit Group Policy at the domain level run "Group Policy Management". If you are using a client operating system the GPMC will need to be download and installed. It is available from the Microsoft web site.
Using the GPMC you can configured a Group Policy by right clicking on an OU and selecting "Create a GPO in this domain, and link it here". A Group Policy Object can also be created in Group Policy Objects, however it will be essentially inactive until it is linked to an OU.
If want to link a Group Policy Object at the site level, the Group Policy first needs to be created under Group Policy Objects. Once it is created you next need to right click "sites" and select the option "show sites". This will allow you to choose which sites will be visible in the GPMC. Once the site is visible, right click it and select the option "Link an Existing GPO".

Settings used in this video
User Configuration\Polices\Administrative Templates\Desktop\Desktop\Desktop Wallpaper
User Configuration\ Polices\Administrative Templates\Desktop\Remove Recycle Bin icon from desktop
Computer Configuration\Polices\Windows Settings\Internet Explorer Maintenance\connection\Proxy Settings
User Configuration\ Polices\Administrative Templates\Control Panel\Prohibit access to the Control Panel

References
"MCTS 70-640 Configuring Windows Server 2008 Active Directory Second edition" pg 280-282
Рекомендации по теме
Комментарии
Автор

This person is amazing !!! Always love his videos as he makes things very easy to understand. God bless him.🙂

AvirupGhosh
Автор

Thanks for watching. We are working on get the course complete as soon as possible.

itfreetraining
Автор

these are one of the ever best tutorials for Group Policy.

asifzardari
Автор

Thanks!
I appreciate how fast and accurate you are. Night and day from a DVD set I have lol!
Writing my 640 this week.

MattRoadhouse
Автор

Depends what you want to achieve. For a small office it is often just simple to buy some computer and a small NAS for a file share.

itfreetraining
Автор

Extremely CLEAR video!Thank you.With every video from you guys i get closer to exam date!:)

cos
Автор

Great video! This gives a great intro on Group Policy for people that have never worked with it.

Bendezium
Автор

Good clear video. I'm new to AD & GPO and this explains very well.

dileshj
Автор

Thanks very much. Good luck sitting your exam.

itfreetraining
Автор

Thank you sir, I was struggling with the difference between processing order and precedence order. Now I get the difference :P

Remolhunter
Автор

Never fail to impress. Thank you so much.

RanYJ
Автор

Great series, you must have put in lots of time and effort and it shows. Do you know how many more videos you were planning for the 70-640 stream and how many objectives have been covered?

DefyAbility
Автор

Great Video!! you just got yourself a subscriber and I will be letting all my friends know too.

ryanwilson
Автор

I liked your explanation and understood well. Please help me to sort out my issue.I have linked GPO A to user OU and is enforced in this GPO I have enabled prevent proxy change access to users(this gpo scope is authenticated users).I have created another GPO B which is also enforced and I have disabled prevent proxy change access to users(this gpo scope is one AD group in which I have added few users). Now only GPO A is getting applied not B. whatever changes I do in A gets applied but changes in B not at all applying.

surajhegde
Автор

very good tutorial! clear and straight forward! thanks!

notme
Автор

You need to download Remote Server Administration Tools (RSAT). This will allow you to perform administration on remote server from a desktop. We do this, because most administrators will perform remote administration now days rather than using the server. If you search our channel, you will find a video on how to install RSAT.

itfreetraining
Автор

Thanks for the video.., It's very clear and awesome, I have query here., In your explanation you had taken control panel and blocked in site level, for some purpose we need so your providing access only to some users., like wise can we block recycle bin in site level and but we give access only some user..
Thanks in advance

ramprabakaran
Автор

Really good video series mate I have recommended this to my tutor

tombarnsley
Автор

Hi,

These are really great videos and thanks for the taking the time in creating and posting them.

Do you have an ETA when the track will be complete?

Thanks!


brainbrain
Автор

I have one domain and have several sites on it, now I want to configure a GPO to the one particular site and doing so is not an issue but yes however I am not sure that if I configure the GPO to one site then, it would be replicated to another sites as well using inter site replication which I really do not wanted to.
so please suggest "" applying GPO to one site would affect other site or not''""

aixperts