Group Policy¶
Centrally managing the configuration of Windows users and computers across a domain.
Why It Matters¶
Group Policy is how a domain enforces settings at scale, from security baselines to drive mappings. It is one of the most powerful administration tools in a Windows environment, and because it controls so much, it is also a target worth monitoring.
Reference¶
Concepts¶
| Term | Meaning |
|---|---|
| GPO | Group Policy Object: a collection of settings |
| Link | A GPO is applied by linking it to a site, domain, or OU |
| Scope | Which users and computers a GPO affects, refined by security filtering and WMI filters |
| Precedence | Processing order: Local, Site, Domain, OU (LSDOU); later wins unless enforced or blocked |
Common Tools¶
| Tool | Purpose |
|---|---|
gpmc.msc |
Group Policy Management Console: create, link, and manage GPOs |
gpedit.msc |
Local Group Policy editor |
gpupdate /force |
Reapply policy on a host |
gpresult /h report.html |
Resultant Set of Policy report for a host or user |
PowerShell (GroupPolicy module)¶
Get-GPO -All # list GPOs
Get-GPOReport -All -ReportType Html -Path .\GPOs.html
New-GPO -Name "Baseline"
Backup-GPO -All -Path .\GPO-Backups
How I Use It¶
I keep GPOs focused and well-named, document what each one does, and back them up regularly, which the Get-GPOReports script in this toolkit automates. Security baselines go in dedicated GPOs so they are easy to review. Unexpected GPO changes are worth alerting on, since a malicious GPO can push changes to every host at once.