1 00:00:00,360 --> 00:00:02,720 So what are the main based GP roles. 2 00:00:02,750 --> 00:00:09,700 The main based GP use our energy bills created in 83 years and start on the main controller. 3 00:00:09,720 --> 00:00:15,150 You can use them to Manage Configuration centrally for the main users and computers. 4 00:00:15,210 --> 00:00:21,120 When you install HDD and create a domain to GP those are created automatically. 5 00:00:21,120 --> 00:00:29,220 They are default domain policy and default domain controller is policy default domain policy is linked 6 00:00:29,280 --> 00:00:36,870 to the domain and has no security group or w are my filters therefore it affects all users of sound 7 00:00:36,870 --> 00:00:44,070 computers in the domain including computers that are domain controllers but are only sentence in the 8 00:00:44,070 --> 00:00:46,050 computer configuration section. 9 00:00:46,140 --> 00:00:53,160 This GPO default domain policy contains policies settings that specify a password account lock out and 10 00:00:53,160 --> 00:00:55,860 Canberra's version 5 protocol policies. 11 00:00:55,860 --> 00:01:02,900 You shouldn't add unrelated policies sentence in this GPL if you need to configure other broad sadness 12 00:01:02,910 --> 00:01:03,790 in your domain. 13 00:01:03,840 --> 00:01:11,370 Great additional GP shows that link to the domain and other important policy is default domain controllers 14 00:01:11,430 --> 00:01:12,280 policy. 15 00:01:12,300 --> 00:01:19,540 This GPO is linked to the O of the domain controllers because computers accounts for domain controllers 16 00:01:19,560 --> 00:01:26,490 are capped exclusively in the domain controllers or you and other computer accounts shouldn't be captain 17 00:01:26,750 --> 00:01:27,100 this. 18 00:01:27,100 --> 00:01:32,880 Oh yeah they should be capped in either or use this GPO effects only domain controllers. 19 00:01:32,880 --> 00:01:40,650 You should only modify the default domain controller GPO to implement your audit and policies and to 20 00:01:40,650 --> 00:01:44,660 assign the user rights required on domain controllers. 21 00:01:44,730 --> 00:01:52,440 Many administrators prefer not to modify either of the default GP roles and instead rely on the process 22 00:01:52,440 --> 00:01:57,440 of create an additional GP always and linking them to the same container objects. 23 00:01:57,450 --> 00:02:04,290 If some incident a cure sounds you need to restore the default due bills to their out of the box settings. 24 00:02:04,350 --> 00:02:08,820 All your changes would be lost if you made changes to the default Jubilee. 25 00:02:08,850 --> 00:02:15,870 Also know that computers run on Windows operating systems also have local GP shows which are typically 26 00:02:16,140 --> 00:02:20,130 overwritten by higher precedence domain based GP shows. 27 00:02:20,250 --> 00:02:28,010 However when your computers are not connected to a domain it is only the local GP those that apply. 28 00:02:28,020 --> 00:02:35,810 Windows Vista and later and Windows 2000 eight and later support the notion of multiple local GP shows 29 00:02:36,000 --> 00:02:42,860 the local computer GPO is the same as the GPO in previous versions of Windows operating systems in the 30 00:02:42,870 --> 00:02:49,460 computer configuration note you can configure all computer related settings in the user configuration 31 00:02:49,460 --> 00:02:55,980 nodes you can configure settings that you want to apply to all users of the computer you can modify 32 00:02:55,980 --> 00:03:04,440 the user sets in the local computer GPO by using the user resurgence in two new local GPO administrators 33 00:03:04,530 --> 00:03:06,390 and not administrators. 34 00:03:06,400 --> 00:03:09,760 Sorry non administrator these two bills apply. 35 00:03:09,770 --> 00:03:17,040 User Settings to signed in users according to whether they are members of the local administrator or 36 00:03:17,040 --> 00:03:24,840 groups in which case they would use the administrators GPO or not members of the administrators group 37 00:03:25,080 --> 00:03:29,390 and therefore they use the known administrators GPO. 38 00:03:29,430 --> 00:03:35,430 You can refine the user resurgence further with a local GPO that applies to a specific user account 39 00:03:35,660 --> 00:03:42,500 user a specific local GP those are associated with local not domain user accounts. 40 00:03:42,510 --> 00:03:49,950 It is important to understand that domain based GPO settings combined with those supplied by using local 41 00:03:49,950 --> 00:03:50,520 GPO. 42 00:03:50,640 --> 00:03:57,660 However because demand based GPO was applied last May take precedence over a local GPO settings. 43 00:03:57,720 --> 00:04:04,650 You can disable the local GP bills by configuring the turnoff local group policy objects process and 44 00:04:04,730 --> 00:04:07,430 certain in a domain based GPO. 45 00:04:07,440 --> 00:04:14,100 Be aware that the local GPO contains many important settings including security settings that you need 46 00:04:14,100 --> 00:04:16,710 to configure in a domain based GPO.