Apply Your Knowledge


Exercises

9.1. Filtering Group Policy

In this exercise, you will create a GPO and then filter it to apply only to the Managers Group. This exercise uses the Group Policy Management Console.

Estimated Time: 20 minutes

1.

From the Start menu, click Start, Control Panel, Administrative Tools, Group Policy Management.

2.

In the left pane, expand the domain, and then expand the Kansas City\Users container. Right-click the Users OU and select Create and Link a GPO Here.

3.

When prompted, name the GPO Desktop Background.

4.

In the GPO container, right-click the new GPO and select Edit from the pop-up menu.

5.

This opens the Group Policy Object Editor. Select User configuration, Administrative Templates, Desktop, Active Desktop. In the right pane, double-click the Active Desktop Wallpaper entry.

6.

This opens the Active Desktop Wallpaper Properties dialog box. Select the Enable button, and then enter c:\windows\greenstone.bmp in the Wallpaper Name field. Click OK to save.

7.

In the right pane, double-click the Enable Active Desktop entry.

8.

This opens the Active Desktop Properties dialog box. Select the Enable button, and then click OK to save.

9.

Close the Group Policy Object Editor.

10.

Back in the GPMC, with the Desktop Background GPO selected, click the Delegation tab.

11.

Highlight the Authenticated Users entry and click the Remove button.

12.

Click the Add button, add the Managers group, and give them Read permissions.

13.

On your test server or workstation, log on using any user account.

14.

Open a command window and run the gpupdate command. Close the command window.

15.

Log off the test machine.

16.

Log on the test machine using an account that is a member of the Managers group. You should see the Greenstone desktop background.

17.

Log off the test machine.

18.

Log on the test machine using an account that is not a member of the Managers group. You should see the default desktop background.

Exam Questions

1.

You are the network administrator for FlyByNight Airlines. The network consists of a single Active Directory domain. The functional level of the domain is Windows 2000 native. All network servers run Windows Server 2003, and all client computers run Windows XP Professional.

Some of your users are complaining that because you implemented a set of new group policies, it's taking noticeably longer for them to log on to their computers. You check your GPOs and notice that the affected users are having 10 GPOs applied5 with users settings and 5 with computer settings. What can you do to speed up their logon times?

A.

Change the order of the GPOs.

B.

Raise the functional level of the domain to Windows Server 2003.

C.

Disable the Computer section in the GPOs with User settings.

D.

Disable the User section in the GPOs with Computer settings.


2.

You are the network administrator for FlyByNight Airlines. The network consists of a single Active Directory domain. The functional level of the domain is Windows 2000 native. All network servers run Windows Server 2003, and all client computers run Windows XP Professional.

You assign one of your junior administrators to create a GPO that changes the desktop on all the PCs in the Maintenance OU. He will need to link it to that GPO when it's completed.

Which of the following default groups must he be assigned to?

A.

Domain Admins

B.

GPO Admins

C.

Group Policy Creator Owners

D.

Maintenance Admins


3.

You are the network administrator for FlyByNight Airlines. The network consists of a single Active Directory domain. The functional level of the domain is Windows 2000 native. All network servers run Windows Server 2003, and all client computers run Windows XP Professional.

You assign one of your junior administrators to create a GPO that changes the desktop on all the PCs in the Kansas City Site. He will need to link it to that GPO when it's completed.

Which of the following default groups must he be assigned to?

A.

Domain Admins

B.

GPO Admins

C.

Group Policy Creator Owners

D.

Enterprise Admins


4.

You are the network administrator for CheapRides.com. The network consists of a single Active Directory domain, with a mixture of Windows XP Professional and Windows NT clients.

The general manager calls and says that he wants all users to have a standard desktop background with the company logo.

What would you do to accomplish this task?

A.

Edit the Default Domain GPO to load the standard desktop background on all computers.

B.

Create a new GPO and call it Desktop Background. Edit this GPO to load the standard desktop background on all computers. Link the GPO to the domain container.

C.

Create a new GPO and call it Desktop Background. Edit this GPO to load the standard desktop background on all computers.

D.

None of the above are correct.


5.

You are the network administrator for CheapRides.com. The network consists of a single Active Directory domain. All network servers run Windows Server 2003, and all client computers run Windows XP Professional.

The general manager of the Kansas City location wants his users to have their own custom desktop settings. There is already a Corporate GPO in place with the corporate settings. The Kansas City users and computers are located in a separate OU named Kansas City.

Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

A.

Create a Kansas City GPO and add the requested settings to it. Link it to the Kansas City OU.

B.

Create a Kansas City GPO and add the requested settings to it. Link it to the domain.

C.

Configure the properties of the Kansas City OU to block inheritance.

D.

Configure the properties of the Corporate GPO to block inheritance.

E.

Configure the properties of the domain to block inheritance.


Answers to Exam Questions

1.

D. Because the computer section of the GPO is applied at machine startup, and the user section is applied at user logon, the best solution is to disable the user section in the GPOs that contain only computer settings. This would keep the system from trying to process them, and cut down on the logon overhead. Changing the order of the GPOs wouldn't help because everything still needs to be processed. The functional level of the domain is not the cause of the problem. See "Group Policy Overview."

2.

A. By default, only members of the Enterprise or Domain Admins groups can link GPOs to a domain or OU, and only Enterprise Admins can link GPOs to sites. Members of the Group Policy Creator Owners group can create GPOs; however, they cannot link them to an object. The other groups are not default groups. See "Linking GPOs."

3.

D. By default, only members of the Enterprise or Domain Admins groups can link GPOs to a domain or OU, and only Enterprise Admins can link GPOs to sites. Members of the Group Policy Creator Owners group can create GPOs; however, they cannot link them to an object. The other group is not a default group. "See Linking GPOs."

4.

D. Group Policy is not supported on pre-Windows 2000 clients, so the task cannot be accomplished with the listed options. See "Group Policy Overview."

5.

A and C. To accomplish this task, you will need to configure a new GPO, link it to the Kansas City OU, and block GPO inheritance on the properties page of the OU. See "Blocking Group Policy Inheritance."

Suggested Readings and Resources

1. Group Policy Management Console Step-by-Step Guide. Microsoft Corporation. http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/directory/activedirectory/stepbystep/gpmcinad.mspx.

2. Group Policy Operations Guide. Microsoft Corporation. http://technet2.microsoft.com/WindowsServer/en/Library/ed6131df-efca-4337-9594-583e19ca3b761033.mspx?mfr=true.

3. Group Policy Resource Center. http://www.gpanswers.com/.

4. Morimoto, Rand, et. al. Microsoft Windows Server 2003 Unleashed R2 Edition. Sams Publishing, 2006. ISBN 0672328984.

5. Windows Server 2003 Deployment Guide. http://technet2.microsoft.com/WindowsServer/en/Library/c283b699-6124-4c3a-87ef-865443d7ea4b1033.mspx?mfr=true Microsoft Corporation.

6. Windows Server 2003 Resource Kit. Microsoft Press, 2005. ISBN 0735614717.




MCSA. MCSE 70-290 Exam Prep. Managing and Maintaining a MicrosoftR Windows ServerT 2003 Environment
MCSA/MCSE 70-290 Exam Prep: Managing and Maintaining a Microsoft Windows Server 2003 Environment (2nd Edition)
ISBN: 0789736489
EAN: 2147483647
Year: 2006
Pages: 219
Authors: Lee Scales

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net