20
Mark and Aaron’s $.02 Group Policy for Laptops and Printers

Group Policy for Laptops and Printers. Order of Operations Computer Policies Things that apply to the hardware or all users Firewall Settings Disable

Embed Size (px)

Citation preview

Page 1: Group Policy for Laptops and Printers. Order of Operations Computer Policies Things that apply to the hardware or all users Firewall Settings Disable

Mark and Aaron’s $.02

Group Policy for Laptops and Printers

Page 2: Group Policy for Laptops and Printers. Order of Operations Computer Policies Things that apply to the hardware or all users Firewall Settings Disable

Policy Processing• Order of Operations•Computer Policies• Things that apply to the hardware or all

users• Firewall Settings• Disable CTRL-ALT-Del at login

•User Policies• Things that follow the user• Profile Settings• Drive Mappings

Page 3: Group Policy for Laptops and Printers. Order of Operations Computer Policies Things that apply to the hardware or all users Firewall Settings Disable

So here is the issue, you want to redirect the user Desktop and My Docs (Libraries) to the server so it will travel

with the user and also be backed up.

• Solutions•Folder Synchronization•Redirected Folders

Page 4: Group Policy for Laptops and Printers. Order of Operations Computer Policies Things that apply to the hardware or all users Firewall Settings Disable

Folder Synchronization• The users folders are cached in a hidden spot so

they are available when they leave the network. Any changes are synched back up upon their return to the Domain

Problem, each user that logs in on a shared device leaves a cache of their entire home drive behind – Quickly filling the hard drive.

Page 5: Group Policy for Laptops and Printers. Order of Operations Computer Policies Things that apply to the hardware or all users Firewall Settings Disable

Redirected Folders• Folders such as home drives etc. are relocated to

a server location thus safe and available on any domain connected computer! Yahoo!

• Problem – Laptops!!! Once they leave the network documents and desktop files cease to exist.

Page 6: Group Policy for Laptops and Printers. Order of Operations Computer Policies Things that apply to the hardware or all users Firewall Settings Disable

Solution – Loopback Policy

• Loopbacks are the exception to the rule processing order• Computer Policy• User Policy• Loopback policy against

subgroup.• In this case we will undo

something we did!

Page 7: Group Policy for Laptops and Printers. Order of Operations Computer Policies Things that apply to the hardware or all users Firewall Settings Disable

So in our case….

• Define the subgroup•We placed all laptops in a separate OU

• Target the Loopback policy at the subgroup•Default Computer Policy runs – Fixes Stuff•Default user policy sets to Profile locations•Loopback policy unsets the Profiles, but only if it is a laptop.

Page 8: Group Policy for Laptops and Printers. Order of Operations Computer Policies Things that apply to the hardware or all users Firewall Settings Disable

Process

• Create a Policy Called Laptop Loopback•Define the following:•Computer Config/Policies/Admin Templates/System/Group Policy: User Group Policy Loopback Mode: Enabled•Next undo the folder redirections you set in the User Policy•Associate the policy with the laptop group!

Page 9: Group Policy for Laptops and Printers. Order of Operations Computer Policies Things that apply to the hardware or all users Firewall Settings Disable

Pushing Printers

Page 10: Group Policy for Laptops and Printers. Order of Operations Computer Policies Things that apply to the hardware or all users Firewall Settings Disable

Pushing Printers

• We define printers by computer location and also who you are.

• Simplifies driver updates• Controls access to copiers and color

printers etc.• Simplifies the imaging process

Page 11: Group Policy for Laptops and Printers. Order of Operations Computer Policies Things that apply to the hardware or all users Firewall Settings Disable

Steps

• You can do this in 4 easy steps•Create the printers and drivers•Define printer install groups that match computer locations•Define printer user access security.•Create the Push Printer policy

Page 12: Group Policy for Laptops and Printers. Order of Operations Computer Policies Things that apply to the hardware or all users Firewall Settings Disable

Create the printers on the server and load the appropriate drivers

• 32 bit drivers are not on Server 2008R2, you will need to push them up if you need them.

• If you log into the workstation machine with an account that has admin privileges for both workstation and print server, you can get into the 'view remote printers' section (used to be called 'printers and faxes'). From here you can pull up properties and install the 'additional drivers’.

• If the workstation doesn't currently have drivers for this printer, or you can't get to the additional drivers section, first install the printer by IP (temporarily) so you have all the proper driver files.

Page 13: Group Policy for Laptops and Printers. Order of Operations Computer Policies Things that apply to the hardware or all users Firewall Settings Disable

Where to install printers

• Divide your work areas up by printer locations.•Main Building Copiers (Available on all Machines)• Departmental Printers (Create a Math Wing Printer Group)• Don’t worry, a computer can belong to multiple groups (Main Office Copiers plus departmental)• Include all printers a staff member may need even in Labs, we will sort the kids off the color printers later!

Page 14: Group Policy for Laptops and Printers. Order of Operations Computer Policies Things that apply to the hardware or all users Firewall Settings Disable

Who gets what!

• Set the security for the printers to users or groups of users that should have access to them.•These can be existing groups

• If a user does not have access to the printer it will not install. AWESOME!

Page 15: Group Policy for Laptops and Printers. Order of Operations Computer Policies Things that apply to the hardware or all users Firewall Settings Disable

Create the Push Policy

• This is where it gets strange•Even though it is hardware and set by computer you push to printer to a user.•Makes sense if you consider that printers are user profile specific

Page 16: Group Policy for Laptops and Printers. Order of Operations Computer Policies Things that apply to the hardware or all users Firewall Settings Disable

New Policy – Push Printers• User Config/Prefs/Control Panel/Printers

Page 17: Group Policy for Laptops and Printers. Order of Operations Computer Policies Things that apply to the hardware or all users Firewall Settings Disable

Here are the details

• Action – Create• Set Printer Path• Decide if it should be

a default

Page 18: Group Policy for Laptops and Printers. Order of Operations Computer Policies Things that apply to the hardware or all users Firewall Settings Disable

Step 2

• Must Click “Run in Logged-on users security context

• Also must select Item-Level Targeting

Page 19: Group Policy for Laptops and Printers. Order of Operations Computer Policies Things that apply to the hardware or all users Firewall Settings Disable

Final Step• Remember that set of computer groups we

created, here is where you use them.

Page 20: Group Policy for Laptops and Printers. Order of Operations Computer Policies Things that apply to the hardware or all users Firewall Settings Disable

Simple!

• Any Questions - Aaron will be available for a small fee after todays session!!!