Most popular Group Policies for organization

Donate Us : Most popular group policies for organization 1. Prepare - DC31 : Domain Controller() | DC32 : Domain Member | WIN101, WIN102 : Clients 2. Step by step : Settings most popular group policies for organization via GPO ### -------------******************** ********************-------------------- ### - DC31 : Settings most popular group policies for organization via GPO Create and sharing a picture with path \\DC31\IM\ Server Manager - Tools - Group Policy Management - : For ’Default Domain Policy’ - Right-Click ’Default Domain Policy’ - Edit ... : 1.1 Set Password Policy Computer Configuration - Polices - Windows Settings - Security Settings - Account Policies - Password Policy : Set depend your Organizarion 1.2 Settings account lockout policy Computer Configuration - Policies - Windows Settings - Security Settings - Account Policies - Account lockout policy : Account lockout duration : 30 minutes Account lockout threshold : 3 invalid logon attempts Reset account lockout counter affter : 30 minutes (depend your Organizarion) 1.3 Settings machine will locked after inactive time Computer Configuration - Policies - Windows Settings - Security Settings - Local Policies - Security Options - Interactive logon : Machine inactivity limit : Tick “Define this policy settings“ Machine will be locked after : 900 seconds (depend your Organizarion) 2.2 Disable Forced System Restart Right-click ’Group Policy Objects’ - New : ’Disable Forced System Restarts’ - Right-click ’Disable Forced System Restarts’ - Edit... - Computer Configuration - Policies - Administrative Templates - Windows Component - Windows Update - Double-click ’No auto-restart with logged on users for scheduled automatic updates installations’ : Enable - OK 2.3 Restrict Software Installations Right-click ’Group Policy Objects’ - New : ’Restrict Software Installations’ - Double-click ’Restrict Software Installations’ - Edit... - Computer Configuration - Policies - Administrative Templates - Windows Component - Windows Installer - Double-click ’Prohibit User Install’ : Enable - OK 2.5 Prevent USB Right-click ’Group Policy Objects’ - New ’Prevent USB’ - Right-Click ’Prevent USB’ - Edit... - Computer Configuration - Policies - Administrative Templates - System - Removeable Storage Access - All Removeable Storage class : Deny all access - Enable 2.6 Add member to local Administrators group Right-click ’Group Policy Objects’ - New : Add to Local Administrators - Right-click ’Add to Local Administrators’ : Edit... - Computer Configuration - Polices - Windows Setting - Security Settings - Right-click “Restricted Groups“ - Add Group... - Administrators : Members of this group - Add... - Browse... - HiepIT;Domain admins - OK 2.7 Set Proxy for Browsers Right-click ’Group Policy Objects’ - New ’Site01 Proxy’ - Right-click ’Site01 Proxy’ - Edit... - User Configuration - Preferences - Control Panel settings - Right-click Internet Settings - New - Internet Explorer 10 - Connections - LAN settings... : Select “Use a proxy server for your LAN (These settings will not apply to dial-up or VPN connections)“ Address : ( press F6 to green) (IP of Proxy Server) Port : 8080 Select : Bypass proxy server for local addresses ( press F6 to green) Policies - Administrative Templates - Windows components - Internet Explorer - Prevent changing proxy settings : Enable 2.8 Set Wallpaper for client Right-click ’Group Policy Objects’ - New ’Wallpaper Clients’ - Right-Click ’Wallpaper Clients’ - Edit... - User Configuration - Policies - Administrative Templates - Desktop - Desktop - Desktop Wallpaper : Enable Wallpaper name : \\DC31\IM\ Wallpaper stype : Center - OK Linked to OUs that you want Link (2.2, 2.5, 2.6) to Servers OU Link (2.3, 2.5, 2.6, 2.7, 2.8) to Clients OU Link (2.1, 2.3, 2.5, 2.6, 2.8) to Guests OU Start - run - cmd, type : gpupdate /force - DC32(belong Servers OU), WIN101(belong Clients OU), WIN102(belong Guests OU) : Update policies and check
Back to Top