Rechercher dans ce blog

Affichage des articles dont le libellé est GPO. Afficher tous les articles
Affichage des articles dont le libellé est GPO. Afficher tous les articles

dimanche 13 octobre 2013

Afficher / Masquer les éléments du Bureau Windows 2008 R2 / Windows 7 par l'intermédiaire de registre et des préférences de stratégie de groupe Microsoft

 

Voici les emplacements de registre pour cacher les objets Microsoft Windows Desktop:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\
HideDesktopIcons\ClassicStartMenu]

“{20D04FE0-3AEA-1069-A2D8-08002B30309D}”=dword:00000000      (<= Computer)
“{59031a47-3f72-44a7-89c5-5595fe6b30ee}”=dword:00000000            (<= User Files)
“{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}”=dword:00000000   (<= Control Panel)
”{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}”=dword:00000000     (<= Network)
“{645FF040-5081-101B-9F08-00AA002F954E}”=dword:00000001         (<= Recycle Bin)

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\
HideDesktopIcons\NewStartPanel]

“{20D04FE0-3AEA-1069-A2D8-08002B30309D}”=dword:00000000      (<= Computer)
“{59031a47-3f72-44a7-89c5-5595fe6b30ee}”=dword:00000000            (<= User Files)
“{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}”=dword:00000000   (<= Control Panel)
”{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}”=dword:00000000     (<= Network)
“{645FF040-5081-101B-9F08-00AA002F954E}”=dword:00000001         (<= Recycle Bin)

Dans l'exemple ci-dessus, tout est indiqué sur le bureau à l'exception de la Corbeille que vous remarquerez une valeur de 1 (Hide = activée). J'ai, bien sur suis conscient que la corbeille n'a pas besoin d'être contrôlé par l'intermédiaire d'un registre peaufiner car il peut être éliminé par des stratégies de groupe. C'est juste là pour le tableau d'ensemble.

La meilleure façon d'adapter ces éléments dans Préférences côté client de stratégie de groupe Microsoft est de se connecter sur un Windows Server 2008 ou machine de référence Windows 7 qui a l'outil de gestion des stratégies de groupe installé.

Bien entendu, vous n'avez pas à utiliser les Préférences du côté client de stratégie de groupe Microsoft, cela peut aussi être KIX script ou tout autre outil que vous préférez comme AppSense Environment Manager de RES Workspace Manager.

Étape 1. Permettre à tous les articles de bureau dans la personnalisation (clic droit bureau, personnalisation), de sorte qu'ils sont affichés sur le bureau.

image

Étape 2. Ouvrez Microsoft Management Policy Group, ouvrez la stratégie de groupe que vous souhaitez utiliser.


Étape 3. Aller à Configuration utilisateur, Préférences, Paramètres Windows, Registre, cliquez droit sur Assistant Nouvelle greffe

image

Étape 4. Accédez à l'article (de travail, Panneau de configuration, les fichiers de l'utilisateur et / ou corbeille) que vous souhaitez afficher (ou masquer explicitement), n'oubliez pas de marquer le point deux fois, sous ClassicStartMenu et une fois sous NewStartPanel;

image

image

Étape 5. Activer ou désactiver l'élément que vous souhaitez afficher ou masquer. Voir l'image ci-dessous, lorsque la valeur des données indique 0, elle est affichée, si elle est 1, alors l'objet sera caché.

image

Étape 6. Je sais Corbeille peut être contrôlé à l'aide des stratégies de groupe, donc ce point est vraiment pas nécessaire. Comme l'image ci-dessous montrent J'ai désactivé cet ouvrage. Avec ce client particulier j'ai désactivé cachant ordinateur (valeur = 0) et a permis le Panneau de configuration de la clandestinité et de fichiers utilisateur (valeur = 1).

image

SOURCE : http://hlouwers.wordpress.com/2010/07/24/show-hide-desktop-items-windows-2008-r2-windows-7-by-means-of-registry-and-microsoft-group-policy-preferences/

vendredi 24 septembre 2010

GPO – WSUS - SBS2008

Comment recréer les GPO WSUS pour SBS 2008.

http://blogs.technet.com/b/sbs/archive/2009/09/03/how-to-manually-create-the-sbs-2008-and-wsus-group-policies-objects.aspx

Certain Group Policy Objects (GPOs) are created and configured by default during the installation of SBS 2008. This blog post will cover how to create these GPOs manually in the event that they are missing or have been accidentally deleted without a backup. Note: If one or more of these GPOs are missing as the result of a failed install, you should not follow this procedure. We recommend that you call Microsoft Product Support as other components are likely to be broken. The steps have been broken down into two types of Group Policies:

Update Services Policies:

  • Update Services Client Computers Policy
  • Update Services Common Settings Policy
  • Update Services Server Computers Policy

Windows SBS Policies:

  • Windows SBS Client – Windows Vista Policy
  • Windows SBS Client – Windows XP Policy
  • Windows SBS Client Policy
  • Windows SBS CSE Policy
  • Windows SBS Users Policy
  • Small Business Server Folder Redirection Policy (Optional)

We do not cover the steps to create the Default Domain Controllers Policy or the Default Domain Policy in this post. Either restore these policies from backup or contact Microsoft Product Support Services for assistance.

Create the three Update Services Policies
  1. Open Start > Run and enter gpmc.msc to open the Group Policy Management Console.
  2. Expand Forest: <SBS Forest>\Domains\<SBS Domain>\Group Policy Objects

  3. image

 

 

 

 

 

 

  1. Right-click the Group Policy Objects key and choose New
  2. Enter Update Services Client Computers Policy as the name
  3. Select OK
    image
    ***The name must be entered exactly as shown, DOUBLE CHECK your spelling before selecting OK
  4. Create the two remaining WSUS policies in this way
    • Update Services Common Settings Policy
    • Update Services Server Computers Policy
Configure the Update Services Client Computers Policy
  1. Right-click Update Services Client Computers Policy and choose Edit. On the Group Policy Management Editor, open Computer Configuration\Policies\Administrative Templates\Windows Components\Windows Update
  2. Configure the settings as shown in the report below

image

Configure the Update Services Common Settings Policy
  1. Right-click Update Services Common Settings Policy and choose Edit. On the Group Policy Management Editor, open Computer Configuration\Policies\Administrative Templates\Windows Components\Windows Update
  2. Configure the settings as shown in the report below

image

Important: The Set the intranet update service for detecting updates and Set the intranet statistics server policies are specific to your server and must be configured with http://<YourServerName>:8530

Note: The above report for this GPO shows the “enabled” and “disabled” policy settings only. Any policy that does not appear in the above report should be set to “Not configured” on your server.

Configure the Update Services Server Computers Policy
  1. Right-click Update Services Server Computers Policy and choose Edit. On the Group Policy Management Editor, open Computer Configuration\Policies\Administrative Templates\Windows Components\Windows Update
  2. Configure the settings as shown in the report below

image

Configure the scope of the new Update Services Policies

The configuration on the Scope tab for each new Update Services GPO needs to be as follows:

  1. Update Services Client Computers Policy
    • Leave “Links” empty
    • Remove any object under “Security Filtering”
    • Set “WMI Filtering” to <none>
  2. Update Services Server Computers Policy
    • Leave “Links” empty
    • Remove any object under “Security Filtering”
    • Set “WMI Filtering” to <none>
  3. Update Services Common Settings Policy
    • Leave “Links” empty
    • “Authenticated Users” must be listed under “Security Filtering”
    • Set “WMI Filtering” to <none>
Link the new Update Services Policies
  1. In the Group Policy Management Console, right-click on your SBS domain and select Link an Existing GPO
    image
  2. Select the following 3 policies
    • Update Services Client Computer Policy
    • Update Services Common Settings Policy
    • Update Services Server Computer Policy
  3. Click OK

Once the WSUS policies have been updated and applied, Security Filtering on the Client Computers and Server Computers GPOs will begin populating with the machine accounts of your domain joined clients and servers. This is done automatically by SBS.

Create the Windows SBS Policies

Create the Small Business Server Folder Redirection Policy (Optional):

This is an optional GPO. Follow these steps only if you wish to use folder redirection

  1. On the SBS 2008 Console, select the Shared Folders and Web Sites tab
  2. On the Right hand side, under “Tasks” select Redirect folders for user accounts to the server
  3. Complete the wizard

image

Create the remaining SBS GPOs

These steps will create the following GPOs:

  • Windows SBS Client – Windows Vista Policy
  • Windows SBS Client – Windows XP Policy
  • Windows SBS Client Policy
  • Windows SBS CSE Policy
  • Windows SBS Users Policy
  1. Copy the following file and save it to an easily accessible path, such as c:\windows\temp, on the SBS 2008 server:
    http://cid-d5fe25afb6c3615f.skydrive.live.com/self.aspx/.Public/gpofix.txt
  2. Right-click on the Command Prompt and select Run as Administrator
    image
  3. Run the following command from the Administrator Command prompt, substitute the path to the gpofix.txt file as needed (We recommend that you DO NOT copy & paste the command directly from the blog post):

    “C:\Program Files\Windows Small Business Server\Bin\GPOTask.exe” /config:c:\windows\temp\gpofix.txt
  4. The task will take a few moments to complete, after which it will return to the command prompt
    image
  5. Verify that the GPOs have been created in the Group Policy Management Console
  6. Run and complete the Internet Address Management Wizard from the SBS 2008 Console to complete the configuration.