Skip to content

Group Policy

Centrally managing the configuration of Windows users and computers across a domain.

Why It Matters

Group Policy is how a domain enforces settings at scale, from security baselines to drive mappings. It is one of the most powerful administration tools in a Windows environment, and because it controls so much, it is also a target worth monitoring.

Reference

Concepts

Term Meaning
GPO Group Policy Object: a collection of settings
Link A GPO is applied by linking it to a site, domain, or OU
Scope Which users and computers a GPO affects, refined by security filtering and WMI filters
Precedence Processing order: Local, Site, Domain, OU (LSDOU); later wins unless enforced or blocked

Common Tools

Tool Purpose
gpmc.msc Group Policy Management Console: create, link, and manage GPOs
gpedit.msc Local Group Policy editor
gpupdate /force Reapply policy on a host
gpresult /h report.html Resultant Set of Policy report for a host or user

PowerShell (GroupPolicy module)

Get-GPO -All                         # list GPOs
Get-GPOReport -All -ReportType Html -Path .\GPOs.html
New-GPO -Name "Baseline"
Backup-GPO -All -Path .\GPO-Backups

How I Use It

I keep GPOs focused and well-named, document what each one does, and back them up regularly, which the Get-GPOReports script in this toolkit automates. Security baselines go in dedicated GPOs so they are easy to review. Unexpected GPO changes are worth alerting on, since a malicious GPO can push changes to every host at once.

Resources