1 00:00:03,060 --> 00:00:03,600 Okay. 2 00:00:03,630 --> 00:00:09,270 And now let's let's look at this concept of targeting of computers and user users on a real system. 3 00:00:10,140 --> 00:00:14,880 So I'm back on my server box and I'm an Active Directory users and computers. 4 00:00:15,800 --> 00:00:18,560 I've got this little voice structure called sales. 5 00:00:19,470 --> 00:00:20,540 Underneath sales. 6 00:00:20,550 --> 00:00:27,150 I have a client, so you and the users owe you and they contain a computer account and a user account 7 00:00:27,150 --> 00:00:28,110 respectively. 8 00:00:29,000 --> 00:00:33,110 So if I come back to AMC, you'll see that same structure. 9 00:00:33,980 --> 00:00:38,120 And what I want to do is I want to create a GPO and link it to that client. 10 00:00:38,120 --> 00:00:45,710 So you and I'm going to call it sales computer policy, and I'm going to create one called Sales User 11 00:00:45,710 --> 00:00:48,250 Policy and I'm going to link that to the users. 12 00:00:48,260 --> 00:00:49,640 Oh, you under sales. 13 00:00:50,570 --> 00:00:57,500 So now if I go in and edit this GPO because I'm on the client, so you the only stuff that I can really 14 00:00:57,500 --> 00:01:00,280 configure that is going to affect the objects within this. 15 00:01:00,280 --> 00:01:04,940 So you are the stuff under computer configuration, remember? 16 00:01:05,860 --> 00:01:08,700 In the clients view, I only have computer objects. 17 00:01:08,710 --> 00:01:11,590 I don't have any users object user objects. 18 00:01:11,590 --> 00:01:13,300 And that's that's on purpose. 19 00:01:13,480 --> 00:01:15,820 That's how I broken up my ADD structure. 20 00:01:16,760 --> 00:01:22,730 So if I come back under the policy, the computer configuration policy section, anything I define here 21 00:01:22,730 --> 00:01:27,650 will be essentially applied to the pole dash, to the computer objects. 22 00:01:28,520 --> 00:01:31,970 And so what I'm going to do is just pick any policy here. 23 00:01:32,840 --> 00:01:37,160 Unwilling to enable to display highly detailed status messages policy. 24 00:01:38,020 --> 00:01:42,520 And that policy will then apply to all of the computer objects in the client's O.U. 25 00:01:43,360 --> 00:01:49,270 Now, if I come in here under sales user policy and I create, let's say I want to create a drive mapping 26 00:01:49,270 --> 00:01:50,530 for the users in sales. 27 00:01:51,460 --> 00:01:56,440 So if I'm going to come up here to drive maps and I'm going to say create a new map drive. 28 00:01:57,320 --> 00:02:01,190 And I'm going to just pointed at a share where the sales organization has. 29 00:02:02,100 --> 00:02:06,210 A public drive, so to speak, and I am going to call it the yes drive for sales. 30 00:02:07,090 --> 00:02:09,010 And I am going to go ahead and click. 31 00:02:09,010 --> 00:02:09,580 Okay. 32 00:02:10,480 --> 00:02:15,190 So now I've got an S drive being mapped to the sales share on the Sd1 server. 33 00:02:16,070 --> 00:02:21,710 And that means that any users within the users o you under sales will process this policy because it's 34 00:02:21,710 --> 00:02:23,570 on the user configuration side. 35 00:02:24,440 --> 00:02:27,770 And they will successfully map that s drive to that share. 36 00:02:28,690 --> 00:02:33,730 So that's kind of the key point here is you've got an ad structure and in that ad structure, you've 37 00:02:33,730 --> 00:02:41,320 got users in some containers and computers in other containers, and you have to target your GPOs accordingly. 38 00:02:42,190 --> 00:02:47,650 Now, you might have a situation where you have an O u that contains both users and computers and that 39 00:02:47,650 --> 00:02:49,270 can get a little bit complicated. 40 00:02:49,270 --> 00:02:54,040 But the point there is that anything you define under computer configuration will be processed by the 41 00:02:54,040 --> 00:02:59,140 computer objects and that, oh, you and anything you define under user configuration will be processed 42 00:02:59,140 --> 00:03:00,280 by the user objects. 43 00:03:00,280 --> 00:03:01,060 And that O.U. 44 00:03:01,930 --> 00:03:07,150 Hopefully that brings the point home around this kind of bifurcated existence of the group policy object 45 00:03:07,150 --> 00:03:09,550 and how it applies each to computers and users.