854
|
Chapter 26: Using Group Policy with Windows Vista
Vista resolves conflicts in settings by overwriting any previous setting with the last
read and most current setting. The final setting is the one Windows Vista uses.
Because of this, the processing order is extremely important: it determines which
user settings are actually applied when there are conflicting settings.
Only the enabled or disabled state of a setting matters. If a setting is
set as Not Configured, this has no effect on the state of the setting
from a previous policy application.
To see how setting overwriting works, consider the following examples:
• Jim is a member of the local Administrator account and has a user-specific GPO.
When Jim logs on to his computer, Local Group Policy is applied, then Adminis-
trators Local Group Policy, and then his User-specific Local Group Policy. Thus,
if Local Group Policy disabled a setting, then Administrators Local Group Pol-
icy enabled a setting, and then User-specific Local Group Policy disabled the set-
ting, the setting would be disabled.
• Tina is not a member of the local Administrator account and has a user-specific
GPO. When Tina logs on to her computer, Local Group Policy is applied, then
Non-Administrators Local Group Policy, and then her User-specific Local Group
Policy. Thus, if a setting is disabled in Local Group Policy, then enabled in
Administrators Local Group Policy, and then not configured in User-specific
Local Group Policy, the setting would be enabled.
As you can see, using multiple LGPOs in a standalone configuration allows you to
control precisely how policy settings are applied to users based on their logon
account and group membership. In a domain configuration, however, you might not
want to use multiple LGPOs because in domains, most computers and users already
have multiple GPOs applied to them, and adding multiple LGPOs to this already var-
ied mix can make it confusing to manage Group Policy.
In a domain, computers apply local policy first and then domain policy. Because
domain policy is applied last, domain policy settings overwrite any conflicting set-
tings from local policy. Further, to simplify administration, domain administrators
can disable processing of LGPOs on computers running Windows Vista by enabling
the “Turn off Local Group Policy objects processing” policy setting in a domain
GPO. In Group Policy, this setting is located under Computer Configuration\Adminis-
trative Templates\System\Group Policy.
Creating Multiple Local Group Policy Objects
Using the GPOE, you can easily create and manage multiple LGPOs. By default, the
only local policy object that exists on a computer is the LGPO. You can, however,
create other local objects as necessary. Other objects are created when you access
them in the GPOE.