Advanced understanding of MMC, LGPOs, Snap-ins, and when/how to use overlapping settings.
I am trying to understand the standard winXP MMC snap-ins, specifically understanding where and why they have overlap and how to use each in combination. I think I have a fairly good understanding of how they can be used individually, but as a group of snapins I am not sure. e.g.Computer management snap in has a section called local users and groups and the snap in "local users and groups" is identical.e.g.Security templates snapin has similar settings as the group policy snap in.Here is the situation. We have 300 computers operting without a domain, without active directory. They have never been properly configured for security. Now I have to apply security settings, LGPOs, define my groups and users, and other areas to each of these devices individually. I need a way to sit here in the office and design these settings, then apply them in the field in a semi automated way such as a batch file. I cannot manually assign all these settings to each device over and over again in the field. Installing domain controllers is not an option in the near term.So, what snap-ins do I need?Explain the overlap of settings.Explain how I can define my settings in a lab, then roll them out in a semi automated way to each device. I don't need anyone to design the security settings, my group, users, etc for me. I pretty much need to know why snap-ins have overlapping settings, how do I get a complete and concise MMC console with all the security settings and user/group sections without repeating settings or an explaination of why settings are repeated and how/when to use each, and basic methodology of implementing LGPOs in a semi-automated fassion and how to design them in a lab environment. Why does the "security templates" snap-in under "account policies" have a section called "Kerberos Policy" while the "local computer policy" snap in does not? Should it not be identical? The exact same situation seems to be present in the sections titled "event log", "system services", and more. I suppose that each of these snap-ins operates on different parts of the same data set, overlapping at times. Is this accurate? If so, how do I get a complete list without repeating?
October 7th, 2009 5:39pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics