Configuring GPOs
Creating and Configuring GPOs¶
Group Policy Objects (GPOs) are central to enforcing security policies across Windows domains. By creating and configuring GPOs via the Group Policy Management Console (GPMC), administrators can standardize settings for password complexity, account lockout, audit policies, and more. This section outlines the process of creating a GPO and configuring foundational security settings.
Creating a GPO via GPMC¶
-
Open GPMC:
Launch the Group Policy Management Console by runninggpmc.mscfrom the Start menu or PowerShell. -
Create a New GPO:
- Right-click the target Organizational Unit (OU) in the GPMC console.
- Select Group Policy > New.
-
Enter a name (e.g.,
Security Policy) and click OK. -
Link the GPO to an OU:
- Right-click the newly created GPO.
- Select Edit to open the Group Policy Management Editor.
- Alternatively, use the Link option to associate the GPO with an OU without editing immediately.
PowerShell Alternative:
Configuring Basic Security Settings¶
After creating a GPO, use the Group Policy Management Editor to configure critical security settings.
1. Password and Account Policies¶
- Navigate to:
Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Password Policy - Set parameters like:
- Minimum password length (e.g., 12 characters).
- Enforce password history (e.g., 24 passwords).
- Password must meet complexity requirements (enabled).
2. Account Lockout Policy¶
- Go to:
Computer Configuration > Policies > Windows Settings > Security Settings > Account Lockout Policy - Configure:
- Account lockout threshold (e.g., 5 failed attempts).
- Account lockout duration (e.g., 30 minutes).
- Reset account lockout counter after (e.g., 30 minutes).
3. Audit Policies¶
- Access:
Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Audit Policy - Enable auditing for:
- Logon/logoff
- Object access
- Process tracking
4. Software Restriction Policies¶
- Navigate to:
Computer Configuration > Policies > Windows Settings > Security Settings > Software Restriction Policies - Create a new policy and define rules to block unsigned executables or specific file paths.
Linking GPOs to OUs and Managing Inheritance¶
- Linking:
Right-click the GPO in GPMC > Link > Select the OU to apply the policy. - Enforcing Policies:
Check the Enforced checkbox in the GPO properties to prevent child OUs from overriding settings. - Order of Processing:
GPOs are applied in the order of their links. Use the GPO Link Order tool to prioritize policies.
Troubleshooting and Validation¶
- Check Policy Application:
Rungpresult /Rfrom an admin command prompt to verify which GPOs apply to a user or computer. - Audit Logs:
Review Event Viewer (Security log) for events related to policy changes or failed lockout attempts.
Key takeaways¶
- Use GPMC to create and link GPOs to OUs for centralized policy management.
- Configure password, account lockout, and audit policies to enforce security standards.
- Leverage PowerShell (
New-GPO,Set-GPPermission) for automation and advanced configuration. - Validate GPO application with
gpresultand audit logs to ensure compliance. - Enforce critical policies to prevent unintended overrides from child OUs.