Professional Documents
Culture Documents
Module7:ManagingUserDesktopwithGroupPolicy
Contents: Lesson1: LabA: Lesson2: LabB: Lesson3: LabC: ImplementAdministrativeTemplates ManageAdministrativeTemplatesandCentralStore ConfigureGroupPolicyPreferences ManageGroupPolicyPreferences ManageSoftwarewithGPSI ManageSoftwarewithGPSI
Module Overview
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
1/83
07/06/13
InanenvironmentmanagedbyawellimplementedGroupPolicyinfrastructure,little ornoconfigurationneedstobemadebydirectlytouchingadesktop.Theentire configurationisdefined,enforced,andupdatedbyusingthesettingsinGroupPolicy objects(GPOs)thataffectaportionoftheenterpriseasbroadasanentiresiteora domain,orasnarrowasasingleorganizationalunit(OU)oragroup.Inthismodule, youwilllearnwhatGroupPolicyis,howitworks,andhowbesttoimplementitin yourorganization.Inthismodule,youwilllearnhowtoconfiguredesktop environmentsbyusingAdministrativetemplatesandGroupPolicyPreferences.You willalsoseehowtoproperlyscopeGroupPolicy.Inaddition,youwilllearnhowto deploysoftwarebyusingGroupPolicy.
Objectives
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe 2/83
07/06/13
AdministrativeTemplatesallowyoutocontroltheenvironmentoftheoperating
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe 3/83
07/06/13
Objectives
Aftercompletingthislesson,youwillbeableto: DescribeAdministrativeTemplatesandhowtheywork. Describemanagedsettings,unmanagedsettings,andpreferences. DescribeCentralStore.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
4/83
07/06/13
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
5/83
07/06/13
Thefactthatthesettingexistsandthatitprovidesadropdownlistwithwhichto disableRegedit.exefromrunningsilentlyisdeterminedinanadministrativetemplate. Theregistrysettingthatismadebasedonhowyouconfigurethepolicyisalso definedintheadministrativetemplate. Somesoftwarevendorsprovideadministrativetemplatesasamechanismtomanage theconfigurationoftheirapplicationcentrally.Forexample,youcanobtain administrativetemplatesforallrecentversionsofMicrosoft Officefromthe MicrosoftDownloadsCenter.Youcanalsocreateyourowncustomadministrative templates.Atutorialoncreatingcustomadministrativetemplatesisbeyondthescope ofthiscourse.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
6/83
07/06/13
AdministrativeTemplateshavethefollowingcharacteristics: Theyareorganizedintosubfoldersthatdealwithspecificareasoftheenvironment, suchasnetwork,system,andWindows components. ThesettingsinthecomputersectionedittheHKEY_LOCAL_MACHINEhiveinthe registry,andsettingsintheusersectionedittheHKEY_CURRENT_USERhiveinthe registry. Somesettingsexistforbothuserandcomputer.Forexample,thereisasettingto preventWindowsMessengerfromrunninginboththeuserandthecomputer templates.Incaseofconflictingsettings,thecomputersettingprevails. SomesettingsareavailableonlytocertainversionsofWindowsoperatingsystems, suchasanumberofnewsettingscanbeappliedonlytotheWindows7family ofoperatingsystems.Doubleclickingthesettingswilldisplaythesupported versionsforthatsetting.
.ADM Files
InversionsofWindowspriortoWindowsVista ,anadministrativetemplatehadan .ADMextension..ADMfileshaveseveraldrawbacks.First,alllocalizationmustbe performedwithinthe.ADMfile.Thatis,ifyouwanttocreatean.ADMfiletohelp deployconfigurationinamultilingualorganization,youwouldneedseparate.ADM filesforeachlanguagetoprovideauserinterfaceforadministratorswhospeakthat
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe 7/83
07/06/13
.ADMX/.ADML Files
InWindowsVista,Windows7,WindowsServer2008,andWindowsServer2008 R2,anadministrativetemplateisapairofXMLfiles,onewithan.ADMXextension thatspecifieschangestobemadetotheregistryandtheotherwithan.ADML extensionthatprovidesalanguagespecificuserinterfaceintheGPME.Whenchanges needtobemadetosettingsmanagedbytheadministrativetemplate,theycanbe madetothesingle.ADMXfile.AnyadministratorwhomodifiesaGPOthatusesthe templateaccessesthesame.ADMXfileandcallstheappropriate.ADMLfileto populatetheuserinterface. Toadd.ADMX/.ADMLadministrativetemplatestotheGPME,copythe.ADMXfileinto the%SystemRoot%\PolicyDefinitionsfolderonyourclientorinthecentralstore.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe 8/83
07/06/13
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
9/83
07/06/13
07/06/13
H K C U \ S o f t w a r e \ M i c r o s o f t \ W i n d o w s \ C u r r e n t V e r s i o n \ P o l i c i e s \ S y s t e m \ D i s a b l e R e g e d i t M o d e
IfyouchoosetorestrictRegeditfromrunningsilently,thatvalueissetto2.Ifyou choosetorestrictonlytheRegistryEditorUItool,thevalueissetto1.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
11/83
07/06/13
07/06/13
settings: HKLM\Software\Policies(computersettings) HKCU\Software\Policies(usersettings) HKLM\Software\Microsoft\Windows\CurrentVersion\Policies(computersettings) HKCU\Software\Microsoft\Windows\CurrentVersion\Policies(usersettings) Thesekeysaresecuredsothatonlyadministratorscanmakeachange.Together withUIlockout,thismeansthatnonadministrativeuserswillreceivethechange specifiedbythepolicysettingandcannotmodifythesettingontheircomputer. ChangesmadebyaGroupPolicysettingandtheUIlockoutarereleasediftheuser orcomputerfallsoutofscopeoftheGPO.Forexample,ifyoudeleteaGPO, managedpolicysettingsthathadappliedtoauserwillbereleased.Thismeans that,generally,thesettingresetstoitspreviousstate. Additionally,theUIinterfaceforthesettingisenabled.
07/06/13
Incontrast,anunmanagedpolicysettingmakesachangethatispersistentinthe registry.IftheGPOnolongerapplies,thesettingremains.Thisisoftencalled "tattooing"theregistry,inotherwords,makingapermanentchange.Toreversethe effectofthepolicysetting,youmustdeployachangethatrevertstheconfiguration tothedesiredstate.Additionally,anunmanagedpolicysettingdoesnotlocktheUI forthatsetting. Bydefault,theGPMEhidesunmanagedpolicysettingstodiscourageyoufrom implementingaconfigurationthatisdifficulttorevert.However,youcanmakemany usefulchangeswithunmanagedpolicysettings,particularlyforcustomadministrative templatestomanageconfigurationforapplications. Tocontrolwhichpolicysettingsarevisible,rightclickAdministrativeTemplates andclickFilterOptions,andthenselectfromtheManageddropdownlist. Laterinthismodule,youwillworkwithGroupPolicyPreferences.Whenachangeis madebyapreference,thechangeisnotforced,butratherrecommended.
Central Store
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
14/83
07/06/13
Aswaspreviouslystated,.ADMfilesarestoredaspartoftheGPOitselfintheGPT. WhenyoueditaGPOthatusesadministrativetemplatesinthe.ADMformat,the GPMEloadsthe.ADMfromtheGPTtoproducetheuserinterface.When .ADMX/.ADMLfilesareusedasadministrativetemplates,theGPOcontainsonlythe datathattheclientneedsforprocessingGroupPolicy,andwhenyouedittheGPO, theGPMEpullsthe.ADMXand.ADMLfilesfromthelocalworkstation. Thisworkswellforsmallerorganizations,butforcomplexenvironmentsthatinclude customadministrativetemplatesorthatrequiremorecentralizedcontrol,Windows Server2008introducesCentralStore.CentralStoreisasinglefolderinSYSVOLthat holdsallthe.ADMXand.ADMLfilesthatarerequired.AfteryouhavesetupCentral Store,theGPMErecognizesitandloadsalladministrativetemplatesfromCentral
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe 15/83
07/06/13
\ \ c o n t o s o . c o m \ S Y S V O L \ c o n t o s o . c o m \ P o l i c i e s \ P o l i c y D e f i n i t i o n s
Ifyoulogontoadomaincontroller,locallyorbyusingRemoteDesktop,thelocal pathtothePolicyDefinitionsfolderis.
% S y s t e m R o o t % \ S Y S V O L \ d o m a i n \ P o l i c i e s \ P o l i c y D e f i n i t i o n s
2.
Copyall.ADMXfilesfromthe%SystemRoot%\PolicyDefinitionsfolderofa WindowsServer2008systemtothenewSYSVOLPolicyDefinitionsfolder.
3.
Copythe.ADMLfilesfromtheappropriatelanguagespecificsubfolderof %SystemRoot%\PolicyDefinitionsintothelanguagespecificsubfolderofthe
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
16/83
07/06/13
workwiththeCentralStore.TheGPOsyoucreatecanbeappliedtopreviousversions ofWindows.
07/06/13
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
18/83
07/06/13
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
19/83
07/06/13
07/06/13
Comments
Youcanalsosearchandfilterbasedonpolicysettingcomments.WindowsServer 2008enablesyoutoaddcommentstopolicysettingsintheAdministrativeTemplates node.Todoso,doubleclickapolicysettingandclicktheCommenttab. Itisabestpracticetoaddcommentstoconfiguredpolicysettingstodocumentthe justificationforasettinganditsintendedeffect.Youshouldalsoaddcommentsto theGPOitself.WindowsServer2008enablesyoutoattachcommentstoaGPO.In theGPME,rightclicktherootnodeintheconsoletree,clickProperties,andthen clicktheCommenttab.
Starter GPOs
AnothernewGroupPolicyfeatureinWindowsServer2008isstarterGPOs.Astarter GPOcontainsAdministrativeTemplatesettings.YoucancreateanewGPOfroma starterGPO,inwhichcasethenewGPOisprepopulatedwithacopyofthesettingsin thestarterGPO.AstarterGPOis,ineffect,atemplate.WhenyoucreateanewGPO, youcanstillchoosetobeginwithablankGPO,oryoucanselectoneofthe preexistingstarterGPOsoracustomstarterGPO.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe 21/83
07/06/13
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
22/83
07/06/13
Lab Setup
Forthislab,youwillusetheavailablevirtualmachineenvironment.Beforeyoubegin thelab,youmustcompletethefollowingsteps: 1. Onthehostcomputer,clickStart,pointtoAdministrativeTools,andthen clickHyperVManager. 2. InHyperVManager,click6425CNYCDC1,andintheActionspane,click Start. 3. IntheActionspane,clickConnect.Waituntilthevirtualmachinestarts.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
23/83
07/06/13
4.
Lab Scenario
YouwererecentlyhiredasthedomainadministratorforContoso,Ltd,replacingthe previousadministrator,whoretired.Youarenotcertainwhatpolicysettingshave beenconfigured,soyoudecidetolocateanddocumentGPOsandpolicysettings. Youalsodiscoverthatthecompanyhasnotleveragedeitherthefunctionalityorthe manageabilityofadministrativetemplates.
07/06/13
1.
2. 3. 4.
5. 6.
SelectNotepadandclickOK. ClicktheFormatmenuandselectWordwrap.
25/83
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
07/06/13
7.
SearchforthetextScreenSaverIsSecure. ThisisadefinitionofastringvariablecalledScreenSaverIsSecure.
8. 9.
10. Closethefile. 11. GotothePolicyDefinitionsfolder. 12. DoubleclickControlPanelDisplay.admx. 13. ChoosetheSelectaprogramfromalistofinstalledprogramsoptionand clickOK. 14. SelectNotepadandclickOK. 15. Searchforthetext,ScreenSaverIsSecure. 16. Examinethecodeinthefile,alsoshownbelow:
< p o l i c yn a m e = " S c r e e n S a v e r I s S e c u r e "c l a s s = " U s e r " d i s p l a y N a m e = " $ ( s t r i n g . S c r e e n S a v e r I s S e c u r e ) " e x p l a i n T e x t = " $ ( s t r i n g . S c r e e n S a v e r I s S e c u r e _ H e l p ) " k e y = " S o f t w a r e \ P o l i c i e s \ M i c r o s o f t \ W i n d o w s \ C o n t r o l
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe 26/83
07/06/13
P a n e l \ D e s k t o p "v a l u e N a m e = " S c r e e n S a v e r I s S e c u r e " > < p a r e n t C a t e g o r yr e f = " P e r s o n a l i z a t i o n "/ >< s u p p o r t e d O n r e f = " w i n d o w s : S U P P O R T E D _ W i n 2 k S P 1 "/ >< e n a b l e d V a l u e > < s t r i n g > 1 < / s t r i n g >< / e n a b l e d V a l u e >< d i s a b l e d V a l u e > < s t r i n g > 0 < / s t r i n g >< / d i s a b l e d V a l u e >< / p o l i c y >
1.
OnNYCDC1,openGroupPolicyManagementconsoleas Pat.Coleman_Admin
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
27/83
07/06/13
2. 3. 4.
RightclickDefaultDomainPolicyobjectandselectEdit ExpandUserConfiguration\Policies\AdministrativeTemplatesfolder, Addtheoffice12.admtemplatefromD:\Labfiles\Lab07b\Office2007 AdministrativeTemplates. Classicadministrativetemplates(.ADMfiles)areprovidedprimarilyfor enterprisesthatdonotmanageGroupPolicywithWindowsVistaorWindows Server2008orneweroperatingsystems. YoushoulduseacomputerrunningthemostrecentversionofWindowsto manageGroupPolicy.Bydoingso,youwillbeabletoviewandmodifyall availablepolicysettings,includingthosethatapplytopreviousversionsof Windows.IfyouhaveatleastonecomputerrunningWindowsVista,Windows Server2008,orlater,youshouldusethatcomputertomanageGroupPolicy, andthenyouwillnotneedclassicadministrativetemplates(.ADMfiles)when .ADMX/.ADMLfilesareavailable. NotethatthetemplateformataffectsonlythemanagementofGroupPolicy. SettingswillapplytoversionsofWindowsasdescribedintheSupportedonor Requirementssectionofthepolicysettingproperties.
5. 6.
Examinethesettingsinthisadministrativetemplate. Removethetemplate.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
28/83
07/06/13
1.
2.
1.
2. 3.
4.
Copyall.ADMLfilesfrom%systemroot%\PolicyDefinitions\enus(orthe appropriatefolderforyourlanguageandregion)to
29/83
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
07/06/13
Results:Inthisexercise,youcreatedacentralstoreofadministrativetemplates andaddedtheMicrosoftOffice2007templates.
NoteDonotshutdownthevirtualmachinesafteryoufinishthislabbecause thesettingsyouhaveconfiguredherewillbeusedinsubsequentlabs.
07/06/13
07/06/13
Objectives
Aftercompletingthislesson,youwillbeableto: DescribeGroupPolicyPreferences. DescribethedifferencesbetweenGroupPolicysettingsandGroupPolicy Preferences. ConfigureanddeployGroupPolicyPreferences.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
32/83
07/06/13
07/06/13
performedbylogonscriptsareinstallingprinters,mappingnetworkdrives, configuringregistrysettings,andcopyingfilesandfolders.Youcanaccomplish thesetasksbyusingpreferences. Limitsconfigurationerrors.Configurationerrorsduringandafterdeploymentare oftenthereasonforsupportcallsandescalationsthatleadtohigherdeployment costs.GroupPolicypreferencessignificantlyhelpreducethesecosts. Minimizesimagemaintenance.UsingGroupPolicypreferences,youcansignificantly reducethetimeandcostofmaintainingdiskimages.Insteadofupdatingimages toreflectconfigurationchanges,youcandeployagenericimageandupdateGroup Policypreferences.
07/06/13
07/06/13
Update.Modifyanexistingitemonthetargetedcomputer.
Option
Stopprocessing itemsinthis extensionifan erroroccurs Runinloggedon user'ssecurity context
Description
Bydefault,errorsdonotpreventGroupPolicyPreferencesfromprocessingthe remainingpreferenceitemsinthesameextension.Ifyouwantpreferencestostop processingadditionalitemsifanerroroccurs,enablethisoption.
Itemlevel
Targetingdeterminestowhichusersandcomputersapreferenceitemapplies.Enable
36/83
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
07/06/13
targeting
thisoption,andthenclicktheTargetingbuttontoconfiguretargetingitems forthepreferenceitem.
Targeting Control
ItemleveltargetingdeterminestheusersandcomputerstowhichGroupPolicy appliesindividualpreferenceitemswithinaGPO.Youcantargetdifferentpreference itemswithinasingleGPOatcomputersbasedondifferentcriteria.Youcanuselogical operatorstojoincriteria.Forexample,youcanapplyapreferenceifthecomputer matchesaspecificIPAddressrangeandoperatingsystemversion.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
37/83
07/06/13
Preferences
Preferencesarenotenforced.
Policies
Settingsareenforced.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
38/83
07/06/13
Userinterfaceisnotdisabled. Importindividualregistrysettingsor entireregistrybranchesfromalocalora remotecomputer. NotavailableinlocalGroupPolicy. SupportsnonGroupPolicyaware applications. Originalsettingsareoverwritten. Removingthepreferenceitemdoesnot restoretheoriginalsetting. Targetingisgranularwithauser interfaceforeachtypeoftargetingitem. Supportstargetingattheindividual preferenceitemlevel.
Userinterfaceisdisabled. Cannotcreatepolicysettingstomanagefiles,folders,andsoon.
AvailableinlocalGroupPolicy. RequiresGroupPolicyawareapplications.
Originalsettingsarenotchanged. Removingthepolicysettingrestorestheoriginalsettings.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
39/83
07/06/13
Inthisdemonstration,yourinstructorwillshowyouhowtoconfiguresomeGroup PolicyPreferences.
Demonstration Steps
AddashortcuttoNotepadforNYCCL1. AddafoldernamedReportstoallcomputersrunningWindowsServer2008R2.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
40/83
07/06/13
Lab Setup
Forthislab,youwillusetheavailablevirtualmachineenvironment.Beforeyoubegin thelab,youmustcompletethefollowingsteps: 1. Onthehostcomputer,clickStart,pointtoAdministrativeTools,andthen clickHyperVManager. 2. InHyperVManager,click6425CNYCDC1,andintheActionspane,click Start.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe 41/83
07/06/13
3. 4.
Lab Scenario
YouwererecentlyhiredasthedomainadministratorforContoso,Ltd.Tosimplify GroupPolicymanagement,whichincludeseliminatingtheneedforlogonscriptsto mapdrives,youneedtodeployseveralGroupPolicyPreferencessettingsthatwill allowformoreflexibilityforcorporateusers.
07/06/13
3.
Configuredrivemapping.
1.
2.
LeavetheGroupPolicyManagementEditorwindowopenforthenexttask.
Task 2: Create a new folder named Reports on drive C of all computers running Windows Server 2008. 1. IntheGroupPolicyManagementEditorwindow,underWindowsSettings, rightclickFolders,pointtoNew,andthenclickFolder.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
43/83
07/06/13
2. 3.
4.
LeavetheGroupPolicyManagementEditorwindowopenforthenexttask.
1.
2.
CreateanewmappeddrivelabeledDatafor\\NYCDC1\Databyusingthe driveletterPandselecttheReconnectoption.
07/06/13
1. 2. 3.
NoteItmaytakeafewmomentsforthisfoldertoappear.
Result:Inthisexercise,youconfiguredandtestedGroupPolicyPreferencesand verifiedtheirapplication.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
45/83
07/06/13
Youmightbeawareofseveraltoolsthatcanbeusedtodeploysoftwarewithinan
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe 46/83
07/06/13
Objectives
Aftercompletingthislesson,youwillbeableto: DeploysoftwarebyusingGPSI. Describesoftwaredeploymentoptions. RemovesoftwareoriginallyinstalledwithGPSI.
Understand GPSI
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
47/83
07/06/13
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
48/83
07/06/13
07/06/13
NoteYoucannotdeploy.mstor.mspfilesalone.Theymustbeappliedto anexistingWindowsInstallerpackage.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
50/83
07/06/13
The.msifile,transforms,andotherfilesrequiredtoinstallanapplicationarestored inasharedsoftwaredistributionpoint(SDP).
Assigning Applications
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe 51/83
07/06/13
Publishing Applications
Whenyoupublishanapplicationtousers,theapplicationdoesnotappearasifitis installedontheuserscomputers.NoshortcutsarevisibleonthedesktoporStart menu.Instead,theapplicationappearsasanavailableapplicationfortheuserto installusingAddOrRemoveProgramsinControlPanelonaWindowsXPsystemor inprogramsandfeaturesonaWindowsServer2008,WindowsVista,orWindows7 system.Additionally,theapplicationcanbeinstalledwhenauseropensafiletype associatedwiththeapplication.Forexample,ifAcrobatReaderisadvertisedtousers, itwillbeinstalledifauseropensafilewitha.pdfextension. Giventhatapplicationscanbeeitherassignedorpublishedandtargetedtousersor computers,youcanestablishaworkablecombinationtomeetyoursoftware managementgoals.Thefollowingtabledetailsthedifferentsoftwaredeployment options.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe 52/83
07/06/13
Assign (User)
Thenexttimea userlogson.
Assign(Computer)
Thenexttimethecomputerstarts.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
53/83
07/06/13
Supported installationfiles:
WindowsInstallerpackages(.msifiles).
NowthatyouunderstandGPSIatahighlevel,youcanpreparetheSDP.TheSDPis
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe 54/83
07/06/13
Demonstration Steps
1. Start6425CNYCDC1andlogonasPat.Colemanwiththepassword, Pa$$w0rd. 2. 3. 4. Start6425CNYCSVR1,butdonotlogon. SwitchtoNYCDC1. RunActiveDirectoryUsersandComputerswithadministrativecredentials. UsetheaccountPat.Coleman_AdminwiththepasswordPa$$w0rd. 5. Intheconsoletree,expandthecontoso.comdomainandtheGroupsOU,and thenclicktheApplicationOU. 6. 7. 8. RightclicktheApplicationOU,pointtoNew,andthenclickGroup. TypeAPP_XMLNotepad,andthenpressEnter. Intheconsoletree,expandthecontoso.comdomainandtheServersOU,and
55/83
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
07/06/13
thenclicktheFileOU. 9. Inthedetailspane,rightclickNYCSVR1,andthenclickManage. TheComputerManagementconsoleopens,focusedonNYCSVR1. 10. Intheconsoletree,expandSystemToolsandSharedFolders,andthenclick Shares. 11. RightclickShares,andthenclickNewShare.TheCreateaSharedFolder Wizardappears. 12. ClickNext. 13. IntheFolderPathbox,typeC:\Software,andthenclickNext. Amessageappearsaskingifyouwanttocreatethefolder. 14. ClickYes. 15. AcceptthedefaultSharename,Software,andthenclickNext. 16. ClickCustomizepermissions,andthenclickCustom. 17. ClickSecurity. 18. ClickAdvanced. TheAdvancedSecuritySettingsdialogboxappears. 19. ClickChangePermissions.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe 56/83
07/06/13
20. CleartheIncludeinheritablepermissionsfromthisobject'sparent option. AdialogboxappearsaskingifyouwanttoAddorRemoveinherited permissions. 21. ClickAdd. 22. SelectthefirstpermissionassignedtotheUsersgroup,andthenclickRemove. 23. SelecttheremainingpermissionassignedtotheUsersgroup,andthenclick Remove. 24. SelectthepermissionassignedtoCreatorOwner,andthenclickRemove. 25. ClickOKtwotimestoclosetheAdvancedSecuritySettingsdialogboxes. 26. IntheCustomizePermissionsdialogbox,clicktheSharePermissionstab. 27. SelecttheFullControlcheckbox. Thesecuritymanagementbestpracticeistoconfigureleastprivilegepermissions intheACLoftheresource,whichwillapplytousers,regardlessofhowusers connecttotheresource,atwhichpointyoucanusetheFullControlpermission ontheSMBsharedfolder.Theresultantaccesslevelwillbethemorerestrictive permissionsdefinedintheACLofthefolder. 28. ClickOK.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
57/83
07/06/13
29. ClickFinish. 30. ClickFinishtoclosethewizard. 31. ClickStart,clickRun,type\\NYCSVR1\c$,andthenpressEnter. TheConnecttoNYCSVR1dialogboxappears. 32. IntheUsernamebox,typeCONTOSO\Pat.Coleman_Admin. 33. InthePasswordbox,typePa$$w0rd,andthenpressEnter. AWindowsExplorerwindowopens,focusedontherootofthedriveConNYC SVR1. 34. OpentheSoftwarefolder. 35. ClickNewfolder. Anewfolderiscreatedandisin"renamemode." 36. TypeXMLNotepad,andthenpressEnter. 37. RightclicktheXMLNotepadfolder,andthenclickProperties. 38. ClickSecurity. 39. ClickEdit. 40. ClickAdd.TheSelectUsers,Computers,ServiceAccounts,orGroups dialogboxappears.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe 58/83
07/06/13
41. TypeAPP_XMLNotepad,andthenpressEnter. Thegroupisgiventhedefault,Read&Executepermission. 42. ClickOKtwicetocloseallopendialogboxes. 43. OpentheXMLNotepadfolder. 44. OpentheD:\Labfiles\Lab07cfolderinanewwindow. 45. RightclickXMLNotepad.msi,andthenclickCopy. 46. SwitchtotheWindowsExplorerwindow,displaying\\NYC SVR1\c$\Software\XMLNotepad. 47. Rightclickintheemptydetailspane,andthenclickPaste. XMLNotepadiscopiedintothefolderonNYCSVR1. 48. CloseallopenWindowsExplorerwindows. 49. ClosetheComputerManagementconsole.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
59/83
07/06/13
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
60/83
07/06/13
5.
Browsetolocatethe.msifilefortheapplication.ClickOpen. TheDeploySoftwaredialogboxappears,showninthefollowingscreenshot:
6.
SelectPublished,Assigned,orAdvanced. Youcannotpublishanapplicationtocomputers,sotheoptionwillnotbe availableifyouarecreatingthepackageintheSoftwareInstallationnodein ComputerConfiguration. TheAdvancedoptionenablesyoutospecifywhethertheapplicationispublished orassignedandgivesyoutheopportunitytoconfigureadvancedpropertiesof thesoftwarepackage.Therefore,selectAdvanced.Thepackagepropertiesdialog boxthenappears.Amongthemoreimportantpropertiesthatyoucanconfigure arethefollowingchoices: DeploymentType:OntheDeploymenttab,configurePublishedorAssigned.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
61/83
07/06/13
DeploymentOptions:Basedontheselecteddeploymenttype,different choicesappearintheDeploymentOptionssection.Theseoptions,alongwith othersettingsontheDeploymenttab,managethebehavioroftheapplication installation. UninstallThisApplicationWhenItFallsOutOftheScopeOfManagement:If thisoptionisselected,theapplicationwillbeautomaticallyremovedwhenthe GPOnolongerappliestotheuserorcomputer. Upgrades:OntheUpgradestab,youcanspecifythesoftwarethatthis packagewillupgrade.UpgradesarediscussedintheMaintainSoftware DeployedwithGPSIsectionlaterinthislesson. Categories:TheCategoriestabenablesyoutoassociatethepackagewith oneormorecategories.Categoriesareusedwhenanapplicationispublished toauser.WhentheuseropenstheControlPaneltoinstallaprogram, applicationspublishedbyusingGPSIarepresentedingroupsbasedonthese categories. Tocreatecategoriesthatareavailabletoassociatewithpackages,rightclick SoftwareInstallationandclickProperties.Then,clicktheCategoriestab. Modifications:Ifyouhaveatransform(.mstfile)thatcustomizesthepackage, clicktheAddbuttontoassociatethetransformwiththepackage.Mosttabsin thepackagePropertiesdialogboxareavailableforyoutochangesettingsat anytime.However,theModificationstabisavailableonlywhenyoucreate thenewpackageandselecttheAdvancedoption.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe 62/83
07/06/13
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
63/83
07/06/13
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
64/83
07/06/13
4.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
65/83
07/06/13
5. 6.
7.
ClickOK.
YoucanalsoremoveanapplicationthatwasdeployedwithGPSIbyperformingthe followingsteps: 1. 2. Rightclickthepackage,clickAllTasks,andthenselectRemove. IntheRemoveSoftwaredialogbox,chooseoneofthefollowingtwooptions: Immediatelyuninstallthesoftwarefromusersandcomputers.This option,knownasforcedremoval,causescomputerstoremovetheapplication. Thesoftwareinstallationextensionwillremoveanapplicationwhenthe computerrestartsiftheapplicationwasdeployedwithapackageinthe ComputerConfigurationportionoftheGPO.IfthepackageisintheUser Configurationportion,theapplicationisuninstalledthenexttimetheuserlogs on. AllowsUsersToContinueToUseTheSoftware,ButPreventsNew
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe 66/83
07/06/13
IfyouuseoneofthesetwooptionstoremovesoftwarebyusingGPSI,itis importantthatyouallowthesettingsintheGPOtopropagatetoallcomputerswithin thescopeoftheGPObeforeyoudelete,disable,orunlinktheGPO.Clientsneedto receivethissetting,whichspecifiesforcedoroptionalremoval.IftheGPOisdeleted ornolongerappliedbeforeallclientshavereceivedthissetting,thesoftwareisnot removedaccordingtoyourinstructions.Thisisparticularlyimportantinenvironments withmobileusersonlaptopcomputersthatmightnotconnecttothenetworkona regularbasis. If,whencreatingthesoftwarepackage,youchosetheUninstallthisapplication whenitfallsoutofthescopeofmanagementoption,youcansimplydelete, disable,orunlinktheGPO,andtheapplicationwillbeforciblyremovedbyallclients thathaveinstalledthepackagewiththatsetting.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
67/83
07/06/13
07/06/13
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
69/83
07/06/13
Lab Setup
Forthislab,youwillusethesamevirtualmachineenvironmentusedinpreviouslabs. Ifrequired,youmustcompletethefollowingsteps: 1. Onthehostcomputer,clickStart,pointtoAdministrativeTools,andthen clickHyperVManager. 2. InHyperVManager,click6425CNYCDC1,andintheActionspane,click Start. 3. IntheActionspane,clickConnect.Waituntilthevirtualmachinestarts.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
70/83
07/06/13
4.
5.
Repeatsteps2and3for6425CNYCSVR1.Donotlogontothemachineuntil directedtodoso.
Lab Scenario
YouareanadministratoratContoso,Ltd.YourdevelopersrequireXMLNotepadto editXMLfiles,andyouwanttoautomatethedeploymentandlifecyclemanagement oftheapplication.YoudecidetouseGroupPolicySoftwareInstallation.Most applicationsarelicensedpercomputer,soyouwilldeployXMLNotepadtothe developers'computers,ratherthanassociatingtheapplicationwiththeiruser accounts.
07/06/13
1. 2. 3. 4.
1.
2.
IntheGroups\ApplicationOU,createanewglobalsecuritygroupnamed APP_XMLNotepad.
3. 4.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
72/83
07/06/13
Then,configuretheSharepermissionsuchthattheEveryonegroupisallowedFull Control.
5.
OpentheadministrativesharefordriveConNYCSVR1(\\NYCSVR1\c$)as Pat.Coleman_AdminwiththepasswordPa$$w0rd.
6.
InsidetheSoftwarefolderonNYCSVR1,createafoldercalledXML Notepad.
7.
AddpermissiontotheXMLNotepadfoldersothattheAPP_XMLNotepad groupisallowedRead&Executepermission.
8.
CopyXMLNotepad.msifromD:\Labfiles\Lab07cto\\NYC SVR1\c$\Software\XMLNotepad.
9.
CloseanyopenWindowsExplorerwindows.
10. ClosetheComputerManagementconsole.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
73/83
07/06/13
1.
RunGroupPolicyManagementasanadministrator,withtheusername Pat.Coleman_AdminandthepasswordPa$$w0rd.
2.
IntheGroupPolicyObjectscontainer,createanewGPOcalledXML Notepad.EditthatGPO.
3.
ExpandComputerConfiguration,Policies,SoftwareSettings,andthen clickSoftwareInstallation.
4. 5.
6.
SelecttheWindowsInstallerpackage,XmlNotepad.msiandthenclickOpen. Afterafewmoments,theDeploySoftwaredialogboxappears.
7. 8.
9.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
74/83
07/06/13
theapplicationtousers. 10. SelectUninstallThisApplicationWhenItFallsOutOfTheScopeOf Management. 11. ClickOK. 12. ClosetheGroupPolicyManagementEditor. 13. ScopetheGPOtoapplyonlytomembersofAPP_XMLNotepad,andnotto AuthenticatedUsers. 14. LinktheGPOtotheClientComputersOU.
1. 2.
AddNYCCL1totheAPP_XMLNotepadgroup. Start6425CNYCCL1,butdonotlogon.
1. 2.
LogontoNYCCL1asPat.ColemanwiththepasswordPa$$w0rd. ConfirmthatXMLNotepadinstalledsuccessfully.
75/83
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
07/06/13
Results:Inthisexercise,youdeployedXMLNotepadtoNYCCL1.
1. 2.
SwitchtoNYCDC1. IntheGroupPolicyManagementconsoletree,rightclicktheXMLNotepad
76/83
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
07/06/13
GPOintheGroupPolicyObjectscontainer,andthenclickEdit. TheGroupPolicyManagementEditoropens. 3. Intheconsoletree,expandComputerConfiguration,Policies,Software Settings,andthenclickSoftwareInstallation. 4. 5. RightclickSoftwareInstallation,pointtoNew,andthenclickPackage. IntheFilenametextbox,typethenetworkpathtothesoftwaredistribution folder,\\NYCSVR1\software\XMLNotepad,andthenpressEnter. ThisexercisewillusetheexistingXmlNotepad.msifileasifitisanupdated versionofXMLNotepad. 6. SelecttheWindowsInstallerpackage,XmlNotepad.msi,andthenclickOpen. TheDeploySoftwaredialogboxappears. 7. 8. ClickAdvanced,andthenclickOK. OntheGeneraltab,changethenameofthepackagetosuggestthatitisthe nextversionoftheapplication.TypeXMLNotepad2011. 9. ClicktheDeploymenttab.Becauseyouaredeployingtheapplicationto computers,Assignedistheonlydeploymenttypeoption. 10. ClickUpgrades. 11. ClickAdd.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe 77/83
07/06/13
12. ClicktheCurrentGroupPolicyObject(GPO)option. 13. InthePackagetoupgradelist,selectthepackageforthesimulatedearlier version,XMLNotepad2007. 14. SelecttheUninstalltheexistingpackageandthenselecttheninstallthe upgradepackageoption. 15. ClickOK. 16. ClickOK. Ifthiswereanactualupgrade,thenewpackagewouldupgradetheprevious versionoftheapplicationasclientsappliedtheXMLNotepadGPO.Becausethis isonlyasimulationofanupgrade,youcanremovethesimulatedupgrade package. 17. RightclickXMLNotepad2011,whichyoujustcreatedtosimulateanupgrade, pointtoAllTasks,andthenselectRemove. 18. IntheRemoveSoftwaredialogbox,clickImmediatelyuninstallthe softwarefromusersandcomputers,andthenclickOK.
Results:Inthisexercise,yousimulatedanupgradeofXMLNotepadbyusing GPSI.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
78/83
07/06/13
Whenyoufinishthelab,revertthevirtualmachinestotheirinitialstate.Todothis, completethefollowingsteps:
1. 2.
3. 4.
IntheRevertVirtualMachinedialogbox,clickRevert. Repeatthesestepsfor6425CNYCCL1.
defaultpermissions.
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe 79/83
07/06/13
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
80/83
07/06/13
Review Questions
1. 2. WhatisthebenefitofhavingCentralStore? WhatisthemaindifferencebetweenGroupPolicySettingsandGroupPolicy Preferences? 3. WhatisthedifferencebetweenpublishingandassigningsoftwarethroughGPSI?
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
07/06/13
Tools
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe 82/83
07/06/13
Tool
Grouppolicyreporting RSoP
Usefor
Reportinginformationaboutthe currentpoliciesbeingdelivered toclients.
Wheretofindit
GroupPolicyManagementConsole
GPResult
Acommandlineutilitythat displaysRSoPinformation.
Commandlineutility
GPUpdate
RefreshinglocalandADDS basedGroupPolicysettings.
Commandlineutility
Dcgpofix
Commandlineutility
GPOLogView
Commandlineutility
https://skillpipe.courseware-marketplace.com/reader/Print/be1aba64-6bbe-4ff5-82e5-4d7e5b9d8ee0?ChapterNumber=9&FontSize=3&FontType=segoe
83/83