Network+ CompTIA Define Restrictions and Objectives on administrative template

Group Policy in general, however, can still read and use legacy ADM ?les. These ?les are Unicode-based and store what is recorded in the system registry. It should be noted, however, that ADM ?les do not affect actual policy processing through administrative tem- plate client-side extensions. For the certification exam, it’s likely you won?t be asked about ADM ?les, because Microsoft is trying to get administrators adapted to the idea of using central store?based ADMX ?les. Just remember that they are still supported.

One of the most common situations administrators used to encounter before mcitp enterprise administrator was having to repeatedly create extraordinarily similar Group Policy objects and then apply those objects to various OUs throughout the infrastructure. Ultimately, this could become a bit tedious. So, with Windows Server 2008, Microsoft created what are called starter GPOs.

Starter GPOs are GPOs that can be created based on administrative template settings that can be de?ned in the GPMC and then applied to a newly created GPO with that starter as a base. As an example, a common task administrators may use Group Policy for is to make users unable to change the desktop background of their machines. Now, administrators can make a starter GPO that contains the desktop restriction setting by default. Then, when an administrator desires, they can create a new GPO with the default settings of the starter GPO, plus any additional Group Policy settings they care to make.

Who made the GPO? Who edited this GPO at a later date?What’s the general purpose of this GPO?With Windows Server 2008, Microsoft introduced a nifty new feature called comment-ing. Commenting allows Microsoft administrators to place notes on Group Policy objects on the Comment tab within the Group Policy Management Editor. As you can see in Figure 6.7, the comments show the purpose of this GPO, as well as the author and date mcse certification it was created. This way, within a few seconds whoever is using this GPO can know all about the creator of the GPO and any other information you want to leave.

However, if the situation arises that for some reason the default domain policy has been altered, the best solution for resolving it is to use the dcgpofix.exe tool. This tool can restore the default domain policy. However, it’s not designed as a disaster recovery tool. It restores only the default domain policy and nothing else.

Processing your request, Please wait....

Leave a Reply