Can Only See All Settings Into Gpo Editor Under Administrative Templates
Using the Grouping Policy Direction Editor
The Group Policy Management Editor allows you to directly edit a group policy and configure the settings that will affect computers and users. You can open up the GPME by right-clicking whatsoever of the group policies within the GPMC and selecting Edit. The group policy that yous selected will appear within a new window. Effigy 8.17 shows a grouping policy open and ready to be edited. We have already talked about the sections you tin can piece of work with—Computer Configuration and User Configuration—and so nosotros will motion on to some of the settings that you tin can manipulate.
Figure 8.17
GPO open up for editing
Figure 8.17
GPO open up for editing
Managing Settings
The settings you can manipulate come in a few flavors. Depending on what a setting does, you lot will be presented with dissimilar configuration options. The most basic of the settings merely enable or disable an option. More advanced settings allow yous to configure the values that will exist used. Effigy 8.18 shows a elementary policy particular that can be either enabled or disabled. Figure 8.19 displays a setting that has more than data that you lot can enter when enforcing a policy.
Calculation Administrative Templates
Every fourth dimension the GPO is evaluated, all of the settings inside the GPO are evaluated to make up one's mind how they affect the user or computer. As yous tin probably imagine, the more settings there are to evaluate, the longer it takes for the figurer to beginning and the user to receive the logon dialog. That is why Microsoft made the decision to non add together all of the available administrative templates into the group policy architecture. Instead, you can add together only the authoritative templates you need inside your environment.
By right-clicking on the Administrative Templates node, you tin can add together an administrative template past selecting the Add/Remove Templates option. Once the Add/Remove Templates window appears, you can click the Add push and navigate to the location of the template. Templates tin can normally be downloaded from the provider of the software you are trying to manage. Additionally, Microsoft provides several templates to control its operating-system features and applications. In one case y'all have added a template, you volition see the new settings announced inside the Administrative Templates container.
Effigy 8.18
Simple enable and disable settings
Figure 8.xix
Setting with more than options to configure
Filtering Administrative Templates
Those who have worked with group policies know that one of the hardest things to do is find the correct group policy setting to use when managing systems. Because there are hundreds of configurable settings, it can be overwhelming to find the one setting you need to configure. Microsoft has ever offered the Group Policy Settings Reference, which is a spreadsheet you lot tin use to detect the settings y'all want to work with. The spreadsheet was configured with easy search options that permit you to filter out whatsoever nonmatching options. Just this required y'all to exit the Group Policy Object Editor and open up the spreadsheet to notice the setting, and then become back to the Grouping Policy Object Editor and follow the path to the setting. Included in the GPME is an administrative template filter. Y'all tin substantially hide any of the settings that practise not come across the filter criteria, making it easier to find settings directly within the editor.
Right-clicking any of the containers within Authoritative Templates under either Computer Configuration or User Configuration displays two options on the context menu: Filter On and Filter Options, as seen in Figure 8.twenty. Selecting Filter On applies the current filter settings to the administrative templates. Immigration Filter On returns the view to the default, which displays all of the authoritative template settings. Figure 8.21 shows that the Administrative Templates container has been filtered, and only a subset of the available options appears.
To configure the filter to meet your requirements, you need to select Filter Options from the context carte. Y'all will see a window that looks similar Effigy 8.22. The iii sections help you create the filter that you will use to view the configuration settings. The first department allows you to search for settings that meet just basic criteria: Managed, Configured, and/or Commented. Managed settings make changes to registry settings. Configured settings are those that are set to either Enabled or Disabled. Commented settings are those that have entries within the Comments section.
The second section allows yous to search for keywords within the settings. Once y'all enable this department, you tin type in keywords to search for and the search parameters. You tin can select to search in the championship, in the explicate text, and/or in the Annotate sections of the settings. Using keyword filters, you tin perform a very powerful search through the settings.
The final section allows y'all to limit the operating-system and application criteria through which you are searching. If yous are looking for settings that apply to only Windows XP systems, you can simply select the Microsoft Windows XP Family selection, and settings that utilise to any version of Windows XP will announced. The drop-down card shown in Effigy 8.23 allows you to control whether to display settings that apply to any of the operating systems that you lot select from the listing, or if the setting has to apply to all of the selections that you have made.
Real World Scenario
Don't Overdo It
Administrative templates are a nifty manner to extend your control over the applications and services within your network. Just make sure that you don't add unnecessary ones. Every bit you add administrative templates, you are creating more than settings that need to exist reviewed every time a reckoner or user account evaluates the group policy.
Case in point: an organization that had implemented Active Directory became caught upwards in its quest to manage the arrangement. Staff establish several administrative templates they thought looked interesting, and imported each of the ADM files into every 1 of their group policies. They theorized that they needed to give all of their group policies standardized settings.
The trouble with this theory is that when you add together administrative templates, you are increasing the number of settings that have to be checked. Whenever a reckoner started upwards or a user logged on, the additional settings were evaluated, whether the template applied or non. The organization found that its users were not happy with the new startup and logon times. Afterwards beingness informed of what was happening, the staff reviewed the requirements for each of the GPOs they had, and removed the unnecessary authoritative templates.
Figure S.2G
Filter options
J| Group Policy Management Editor
File Action View Assist
Boston Binder Redirection [ZygortL El |j$) Computer Configuration □ □ Polides
El Q Software Settings IB WindowsSettings
0 Hi] Control Pane El Q Network Q Printers El □ Arrangement El IB Windows Cor All Settings El E3 Preferences B ^ User Configuration B □ Polides
El Q Software Settings El thirteen WindowsSettings □ CL Administrative Templat El C3 Command Panel El Ë Desktop El Q Network C3 Shared Folders [3 Start Menu and Tai El Q Arrangement El Hi Windows Compone All Settings El Q] Preferences
Add/Remove Templates.., Filter On Filter Options..,
Re-Apply Filter
Help
¡Manage authoritative templates
Setting jrces beyond domains [ÏÏ1 Access information sources across domains [ÏÏ1 Access data sources aaoss domains Access data sources aaoss domains Access data sources aaoss domains [ill Access information sources aaoss domains [lil Admission information sources aaoss domains [li| Access data sources aaoss domains [ÏÏ1 Access information sources aaoss domains Access data sources aaoss domains |i=1 Action on server disconnect
|i;1 Activate Shutdown Result Tracker System State Information feature [li] Add a specific listing of search providers to the user's search pro vid,.. [lil Add together Printer wizard - Network scan page (Managed network) [li| Add together Printer wizard - Network browse page (Unmanaged network) |:zj Add the Administrators security group to roaming user profiles [i£ Add together-on List
|i:| Admin-approved behaviors [li] Administratively assigned offline files [ÏÏ1 All Processes jjAII Jjill
Figure S.21
Administrative Templates container filtered
Boston Fokfef Rfitiediwi PygortE - Reckoner Configuration
+ . Software Settings + Windows Settings j Authoritative Templat
+ ^ Endows Compone
+ . Preferences
In Effigy eight.24 we are creating a filter that volition display only the settings that have a keyword of offline and apply to Windows Server 2003 or Windows XP systems. Afterwards nosotros configure the filter, we have turned on the filter setting, and as y'all tin can encounter in Effigy viii.25, the policy settings that see our requirements are shown. In dissimilarity, if we remove the operating-system requirement in the filter, the list changes to what is seen in Figure eight.26. Because there are several more options available in Windows Vista and Windows Server 2008, you will see more than settings appear when you remove the operating organization criteria from the filter.
Having the filter functionality built into the Group Policy Management Editor lets you lot search through all of the administrative templates, whether they were provided by Microsoft or another company. When using the Group Policy Settings Reference that Microsoft provides, you have only the settings that apply to Microsoft products.
The drawback to the filter is that information technology applies only to administrative templates. The settings in all other areas of group policy are non affected and cannot be filtered. However, those settings practice not become updated and changed every bit frequently every bit the administrative templates.
Policies and Preferences
Earlier we discussed the fact that an administrative template is made up of policies and preferences. Policies take ever been bachelor in Active Directory. Preferences were originally added through a production called PolicyMaker, which Microsoft acquired. Yous can at present manage preferences natively within the Group Policy Management Console included with Windows Server 2008, or the with Remote Server Administration Tools. Using both of these constructs allows you to manage your organization'southward resource better than if you had only the policies in place.
The principal difference between policies and preferences is the mode that they are practical. Policies are mandated settings that users are not allowed to change. This is achieved past writing the settings for the policy in the Policy branches of the registry. These branches are protected by permissions that exercise not allow standard users to access them. Once the settings are applied in the registry, applications that are group policy-aware will review the Policy branches of the registry for enforcement settings. If a given setting is not configured past a GPO, the application volition await to the standard registry branches for awarding-specific settings.
Preferences are not written to the Policy branches, yet. Policy settings are written to the same registry locations that the applications and operating organization use. Because these branches are not locked downwards by permissions, users tin can make changes to the settings through the operating-organization management tools, through the applications themselves, or even through some registry tweaks. As an added bonus, applications do not take to be group policy-aware to have advantage of preferences, because they don't demand to empathize how to access the Policy branches of the registry.
Effigy 8.22
Filter configuration settings
Figure eight.23
Specifying the matching-operating-system criteria
W Brable Rfiqcwemeiits Filters
Select Ihe desired platfixm and applies Men fil1ef(sj
Indude settings ttiatmateh any of the selected i^atforms.
Indude settings that match whatsoever of the selected platforms.
■0Microsoft Windows Server 2003 family unit
Microsoft Windows XP family □NetMeeting 3.0 □Windows Installer v2,0 □Windows Installer v3,0 •□Windows Installer v4,0
Figure 8.24
Configuring a filter
Effigy eight.25
Viewing the results of the filter
Figure eight.25
Viewing the results of the filter
Both policy and preference settings are refreshed according to the refresh interval, but y'all take the power to specify that a preference setting will not refresh. This way you can let users to make changes to their systems, and the settings will not be overwritten when the refresh occurs. If you lot look at Figure 8.27, you will come across the setting for Employ One time and Do Not Reapply that tin can be configured within the Common tab.
Effigy 8.26
Viewing the filter without operating-system limitations
Effigy eight.27
Setting a preference so that it is non reapplied
Equally shown in Figure 8.27, there is as well a bank check box labeled Item-Level Targeting. When you select this selection, the Targeting push button becomes available. Clicking the push volition actuate a window, seen in Effigy eight.28, that allows you to create a filter. This filter is used to identify the computer business relationship or user account to which the preference volition utilise. This is quite different from policies. Windows Management Instrumentation (WMI) filters can be created for policies, merely the WMI filter specifies whether the entire GPO is applied against a computer or user. Y'all don't accept the ability to create a different WMI filter for each policy particular. With preferences, each preference item you create can have a unlike filter.
As seen in Figure 8.29, you tin can specify exactly which object blazon the filter will be evaluated against. Choosing one of the objects will create the targeting item options equally seen in Effigy 8.30. You tin select the options that you want to use, and add boosted target items as necessary. In Figure eight.31, y'all tin see that a target query has been created that determines if the notebook computer is docked and, if it is, that it has a bombardment present, that the CPU is at least a 1GHz processor, and that it is running any version of Windows XP.
Figure 8.28
Creating a target filter
Effigy 8.29
Objects for which y'all can create a filter
| T Targeting Editor _ | | |
| New Item - Add Collection | Particular Options - | 4j- * | jfc -¡à _ X Delete | to; Help | |
| F Docked | |
| Five Undocked | |
| V Unknown | |
| A Portable Reckoner targeting item allows a preference particular to be applied to computers or users merely if the processing reckoner is identified as a portable computer in the current hardware profile on the processing computer or if the processing reckoner is identified as a portable computer with the docking state specified in the targeting detail. Boosted information... | |
| OK Cancel | |
In Figure viii.32, the Detail Options drop-downward displays the options that you can use when defining the logical evaluation of the query items. The And pick evaluates two options to be true; the Or pick evaluates whether at least one of the options is true; the Is option sets a comparison between items to evaluate to Truthful; Is Not sets a comparison between items so that at least one detail is False. And using the Label pick, y'all can create friendly text for one of the query items so that it is easier to empathise how the options are evaluated.
Figure eight.xxx
Inbound an object query item
Effigy viii.31
Query to be practical to systems
Figure viii.32
Logical evaluators l+50 I_I H
El User Configuration El Q Policies El Q Preferences
El [3 Windows Settings iS) Applications Drive Maps ffi Files Folders flni Files Registry H Shortcuts □ (jw) Control Console Settir "3J Data Sources Sa Devices L-j" Folder Options westward Internet Setönc gj Local Users and Bn Network Option ^¡A Ability Options & Printers (jp Regional Optior QT| Scheduled Task & Start Carte du jour ~
The other options on the Common tab include the following:
Stop Processing Items In This Extension If an Mistake Occurs Selecting this option allows you to stop the processing of all of the preferences within the container so that you practise non inject several errors into the consequence log and cause the system to attempt to apply the settings when the customer-side extension may have a processing trouble.
Run in Logged-On User's Security Context (User Policy Option) When a preference is configured within the User Configuration settings, the user'southward credentials volition exist used to process the preference.
Remove This Particular when It Is No Longer Practical When the preference item is deleted from the GPO, the Preferences settings volition be removed from the registry settings.
As you lot tin can see in Figure 8.33, you can configure several containers within the Preferences container. The best way to get to understand them all is to start working with them. The following is a cursory summary of what each container is used for:
Figure viii.33
Preferences containers
Windows Settings The following settings can be found within the Windows Settings container. Some are available on the Computer Configuration settings, some are available in the User Configuration settings, and some are in both.
Applications User Configuration option used to configure settings for applications that include a preference plug-in.
Bulldoze Maps User Configuration option used to create, supersede, update, or delete mapped drives on a system. Tin also be used to show or hibernate mapped drives on the system.
Environment Computer Configuration and User Configuration option used to create, replace, update, or delete surround variables on systems.
Files Calculator Configuration and User Configuration option that can be used to create, replace, update, or delete files on systems.
Folders Figurer Configuration and User Configuration selection that can be used to create, supercede, update, or delete folders on systems.
Ini Files Figurer Configuration and User Configuration choice that can exist used to create, replace, update, or delete configuration .ini files on systems.
Registry Computer Configuration and User Configuration pick that tin be used to create, supplant, update, or delete registry values on systems.
Network Shares Computer Configuration selection that can be used to create, supercede, update or delete shares on systems.
Shortcuts Reckoner Configuration and User Configuration choice that can be used to create, supplant, update, or delete shortcuts on systems.
Control Panel Settings The following settings can be found within the Command Panel Settings container. Some are available on the Computer Configuration settings, some are bachelor in the User Configuration settings, and some are in both.
Data Sources Figurer Configuration and User Configuration selection that tin can be used to create, supervene upon, update, or delete database data source name (DSN) values on systems.
Devices Computer Configuration and User Configuration choice that tin exist used to enable or disable devices on systems.
Binder Options Computer Configuration and User Configuration option that can be used to create, supersede, update, or set file associations on systems, equally well equally to manage how the binder information is displayed to the user.
Net Settings User Configuration option that can be used to manage Net Explorer configuration settings.
Local Users and Groups Figurer Configuration and User Configuration option that can be used to create, replace, update, or delete local user and group accounts on systems.
Network Options Calculator Configuration and User Configuration options that can be used to create, replace, update, or delete virtual private network or dial-up networking settings.
Power Options Computer Configuration and User Configuration options that can be used to manage the power configuration settings on systems.
Printers Computer Configuration and User Configuration options that can be used to create, replace, update, or delete printer settings on systems.
Regional Options User Configuration choice that can be used to manage the formatting that is used for currency, numbers, date, and time for the user.
Scheduled Tasks Estimator Configuration and User Configuration options that can be used to create, supplant, update, or delete scheduled tasks on a system.
Services Computer Configuration selection that can be used to manage how services start and how they function on a arrangement.
Kickoff Menu User Configuration choice that tin can be used to manage how the Start Carte appears in a user's profile.
Continue reading here: Bankroll Up and Restoring Group Policies
Was this article helpful?
Can Only See All Settings Into Gpo Editor Under Administrative Templates,
Source: https://www.serverbrain.org/active-directory-planning-008/using-the-group-policy-management-editor.html
Posted by: lopesleou1984.blogspot.com

0 Response to "Can Only See All Settings Into Gpo Editor Under Administrative Templates"
Post a Comment