Difference between revisions of "Information Systems:2021 GPO Rework"
Jump to navigation
Jump to search
m |
m |
||
| Line 1: | Line 1: | ||
==Overview== |
==Overview== |
||
| − | Review and reconfigure GPOs to erase outstanding technical debt |
+ | Review and reconfigure GPOs to erase outstanding technical debt. These are the main issues with GPOs currently: |
| + | |||
| + | * Monolithic objects |
||
| + | * Related to the previous - non-separation of computer and user settings |
||
| + | * Upgrade of Windows OS since initial GPO design (outdated settings) |
||
| + | * Overly strict (read: Machiavellian) policies |
||
==Changes== |
==Changes== |
||
Revision as of 12:06, 3 February 2021
Overview
Review and reconfigure GPOs to erase outstanding technical debt. These are the main issues with GPOs currently:
- Monolithic objects
- Related to the previous - non-separation of computer and user settings
- Upgrade of Windows OS since initial GPO design (outdated settings)
- Overly strict (read: Machiavellian) policies
Changes
- Machine account password policy - delete 1-day machine account passwords setting to revert to 30-day default
- Printer deployment - delete old printers, add new printers
- General unlinked GPOs - delete
- "Standard" GPOs - this used to be the primary, monolithic object where GPOs were stored. Now we break them out. There are 7 of these related to Windows 7. They will be compared to the "Standard Windows 10" GPO. This one will then be reduced and genericized to apply to all desktops and users, and selectively applied settings will be broken out