Wednesday, 21 January 2009

SBS 2008 and Group Policy Preferences

The Microsoft document download:

Here is a Group Policy Object with the GP Preferences expanded for both computer and user configurations:


SBS 2008 Group Policy Preferences

With the exception of any Windows Vista SP1 workstations that have the RSAT (download site) installed, all workstations and servers will need to be updated to accept the GP Preference settings pushed out to them.

For those using WSUS, the update should have come and gone a while back: Microsoft Knowledgebase KB943729: Information about new Group Policy preferences in Windows Server 2008. If not using WSUS, then a file for each OS and architecture (x86 or x64) will need to be applied. The above search results link contains links to each file needed as does the KB article.

Group Policy Preferences are just that: Preferences. They enable us to provide the user with a set of allowed configurations on their desktops that they can choose. If they don't like something in one of the GP Preferences, they can disable it, change the setting to something they prefer, or just ignore it altogether.

They also give us the ability to fine tune a user's experience as well as connected network resources without the use of complicated logon scripts. We can create and link a GPO to an OU or Security Group to limit the scope of the preferences.

Or, we can use GP Preferences to set up and push a local admin account (using a limited domain account created in ADUC) on all Windows Vista and XP Pro workstations that we can change the password for in a snap after say a run of software updates. Thus, once the password has been changed, it is possible to have a little more control over what is happening on the SBS network.

This feature is one big plus to migrating existing SBS 2003 domains to SBS 2008.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.

3 comments:

Philip Fuesser said...

I use Preferences to roll out printers, instead of dealing with that pushprinters.exe stuff for XP.

Seems to work well.

Drive mapping is pretty nice too.

-philip

Philip Elder SBS MVP said...

We use Group Policy to push printers on Win2K8 via the GP Publish feature built into the OS.

Group Policy is a set in stone situation that leaves little room for problematic user support calls in the future.

My understanding of Group Policy Preferences, as far as it is only a "preference", has lead us to this policy.

Philip

Gustavo Peterson said...

We were using group policy preferences a while ago but now we switched to desktop authority which was able to overcome all group policy preferences limitations.

This desktop management solution provides a special technology called "validation logic" that is much more granular in applying settings and can configure a wide range of desktop management areas that are not limited with a "Preferences" section like in group policy preferences.