Logo
programming4us
programming4us
programming4us
programming4us
Home
programming4us
XP
programming4us
Windows Vista
programming4us
Windows 7
programming4us
Windows Azure
programming4us
Windows Server
programming4us
Windows Phone
 
Windows Server

Windows Server 2012 Group Policies and Policy Management : Understanding Group Policy (part 2) - Group Policy Link Enforcement, Group Policy Inheritance, Group Policy Block Inheritance

7/5/2013 5:19:22 PM

8. Group Policy Link Enforcement

Microsoft provides administrators with many ways to manage their infrastructure, including forcing configurations down from the top. GPO link “enforcement,” historically known as No Override, is an option of a GPO link that can be set to ensure that the settings in a particular policy will be applied and maintained even if another GPO has the same setting configured with a different value. GPO link enforcement is shown in Figure 2.

Image

Figure 2. Group policy link enforcement.

Because this might result in undesired functionality or a different level of security than what is required to run a particular service or application or manage a system, exercise caution when using this function. Before enabling GPO enforcement on any policy, carefully research and test to ensure that this will not break any functionality or violate an organization’s IT or regulatory policy.

9. Group Policy Inheritance

GPOs can be linked at the site, domain, and multiple OU levels. When an Active Directory infrastructure contains GPOs linked at the domain level, for example, every container and OU beneath the domain root container inherits any linked policies. As a default example, the Domain Controllers OU inherits the default domain policy from the domain.

GPO inheritance enables administrators to set a common base policy across an Active Directory infrastructure while allowing other administrators to apply more granular policies at a lower level that apply to subsets of users or computers. As an example of this, a GPO can be created and linked at the domain level that restricts all users from running Windows Update, while an OU representing a branch office in the domain can have a GPO linked that enables the branch office desktop administrators security group to run Windows Update.

GPO links inherited from parent containers are processed before GPO links at the container itself, and the last applied policy setting value is the resulting value, if multiple GPOs have the same configured setting with different values. This Group Policy inheritance is also known as GPO precedence, and is shown in Figure 3.

Image

Figure 3. Group Policy inheritance.

One important point to note: Group Policy processing will start with the highest number in the precedence order and the policy with the precedence of 1 will be processed last to ensure that the settings in that policy are applied and not overwritten. In the example shown in Figure 3, the enforced policy from the domain is processed last.

10. Group Policy Block Inheritance

Just as GPOs can be inherited, Active Directory also provides the option to block inheritance, as shown in Figure 4, of all GPOs from parent containers. Figure 4 should be compared to Figure 3 to show which policies are no longer blocked, but the parent policy that is enforced is still allowed. So, administrators who are granted the rights to manage group policy links on particular organizational units may decide to block inheritance, but if policies are enforced at a parent organizational unit or the domain, they will still be applied.

Image

Figure 5. Group Policy Block Inheritance.

Block Inheritance is actually an option applied to an Active Directory domain or organizational unit within the Group Policy Management Console and not on an actual policy. The Block Inheritance option can be useful if the container contains users/computer objects that are very security sensitive or business critical. As an example of this option in use, an OU can be created to contain the Remote Desktop Services host systems, which would not function correctly if domain-level GPOs were applied. The OU can be configured to block inheritance to ensure that only the policies linked to the particular OU were applied. If GPOs need to be applied to this container, links would need to be created at that particular container level, or the GPO link from the parent container would need to be enforced, which would override the Block Inheritance setting, as shown in Figure 4.

Other -----------------
- Windows Server 2012 Group Policies and Policy Management : Local Group Policies, Domain-Based Group Policies
- Windows Server 2012 Group Policies and Policy Management - Group Policy Processing: How Does It Work?
- BizTalk Server 2010 : Installation of WCF SAP Adapter (part 4) - IDOC Deep Dive, Building a BizTalk application — Sending IDOC
- BizTalk Server 2010 : Installation of WCF SAP Adapter (part 3) - IDOC schema generation
- BizTalk Server 2010 : Installation of WCF SAP Adapter (part 2) - WCF-SAP Adapter vs WCF Customer Adapter with SAP binding
- BizTalk Server 2010 : Installation of WCF SAP Adapter (part 1) - SAP Prerequisite DLLs
- Exchange Server 2007 : Leveraging the Capabilities of the Outlook Web Access Client - Getting to Know the Look and Feel of OWA 2007
- Exchange Server 2007 : Leveraging the Capabilities of the Outlook Web Access Client - Logging On to OWA 2007
- Exchange Server 2007 : Leveraging the Capabilities of the Outlook Web Access Client - What’s New in OWA 2007?
- SQL Server 2012 : Data Architecture (part 2) - Smart Database Design
 
 
Top 10 video Game
-   Minecraft Mods - MAD PACK #10 'NETHER DOOM!' with Vikkstar & Pete (Minecraft Mod - Mad Pack 2)
-   Minecraft Mods - MAD PACK #9 'KING SLIME!' with Vikkstar & Pete (Minecraft Mod - Mad Pack 2)
-   Minecraft Mods - MAD PACK #2 'LAVA LOBBERS!' with Vikkstar & Pete (Minecraft Mod - Mad Pack 2)
-   Minecraft Mods - MAD PACK #3 'OBSIDIAN LONGSWORD!' with Vikkstar & Pete (Minecraft Mod - Mad Pack 2)
-   Total War: Warhammer [PC] Demigryph Trailer
-   Minecraft | MINIONS MOVIE MOD! (Despicable Me, Minions Movie)
-   Minecraft | Crazy Craft 3.0 - Ep 3! "TITANS ATTACK"
-   Minecraft | Crazy Craft 3.0 - Ep 2! "THIEVING FROM THE CRAZIES"
-   Minecraft | MORPH HIDE AND SEEK - Minions Despicable Me Mod
-   Minecraft | Dream Craft - Star Wars Modded Survival Ep 92 "IS JOE DEAD?!"
-   Minecraft | Dream Craft - Star Wars Modded Survival Ep 93 "JEDI STRIKE BACK"
-   Minecraft | Dream Craft - Star Wars Modded Survival Ep 94 "TATOOINE PLANET DESTRUCTION"
-   Minecraft | Dream Craft - Star Wars Modded Survival Ep 95 "TATOOINE CAPTIVES"
-   Hitman [PS4/XOne/PC] Alpha Gameplay Trailer
-   Satellite Reign [PC] Release Date Trailer
Popular tags
Microsoft Access Microsoft Excel Microsoft OneNote Microsoft PowerPoint Microsoft Project Microsoft Visio Microsoft Word Active Directory Biztalk Exchange Server Microsoft LynC Server Microsoft Dynamic Sharepoint Sql Server Windows Server 2008 Windows Server 2012 Windows 7 Windows 8 windows Phone 7 windows Phone 8
programming4us programming4us
 
Popular keywords
HOW TO Swimlane in Visio Visio sort key Pen and Touch Creating groups in Windows Server Raid in Windows Server Exchange 2010 maintenance Exchange server mail enabled groups Debugging Tools Collaborating
programming4us programming4us
PS4 game trailer XBox One game trailer
WiiU game trailer 3ds game trailer
Trailer game
 
programming4us
Natural Miscarriage
programming4us
Windows Vista
programming4us
Windows 7
programming4us
Windows Azure
programming4us
Windows Server
programming4us
Game Trailer