General GP Concepts Policy Exceptions Reference |
The Group Policy Object Editor (gpedit) allows you to edit security settings for users or computers. You configure security settings policies in Computer Configuration\Windows Settings\Security Settings. With Security Settings, you can require minimum password complexity, control the ability to log on to computers remotely, enable software restriction policies, set IP security, and much more. The following sections explain the security areas that can be configured. Account Policies (SCE) These are computer security settings for password policy, lockout policy, and Kerberos policy in domains on Windows 2000 and Windows Server 2003. Local Policies (SCE) These include security settings for audit policy, user rights assignment, and security options. Local policy allows you to configure who has local or network access to the computer and whether or how local events are audited. Event Log (SCE) This controls security settings for the Application, Security, and System event logs. You can access these logs using the Event Viewer. Restricted Groups (SCE) This allows you to control who should and should not belong to a restricted group, as well as which groups a restricted group should belong to. This allows administrators to enforce security policy settings regarding sensitive groups, such as Administrators or Payroll. For example, it may be decided that only Joe and Mary should be members of the Administrators group. Restricted groups can be used to enforce that policy. If a third user is added to the group (for example, to accomplish some task in an emergency situation), the next time policy is enforced, that third user is automatically removed from the Administrators group. System Services (SCE) These control startup mode and security options (security descriptors) for system services such as network services, file and print services, telephone and fax services, Internet and intranet services, and so on. Registry (SCE) This is used to configure security settings for registry keys including access control, audit, and ownership. When you apply security on registry keys, the Security Settings extension follows the same inheritance model as that used for all tree-structured hierarchies in Windows 2000 and Windows Server 2003 (such as Active Directory and NTFS). Microsoft recommends that you use the inheritance capabilities to specify security only at top-level objects, and redefine security only for those child objects that require it. This approach greatly simplifies your security structure and reduces the administrative overhead that results from a needlessly complex access-control structure. File System (SCE) This is used to configure security settings for file-system objects, including access control, audit, and ownership. Public Key Policies You use these settings to: IP Security Policies on Active Directory IP Security (IPSec) policy can be applied to the GPO of an Active Directory object. This propagates that IPSec policy to any computer accounts affected by that GPO. Wireless Networking This lets you configure wireless network settings that are part of Group Policy for Computer Configuration. Wireless network settings include the list of preferred networks, WEP settings, and IEEE 802.1X settings. These settings are downloaded to targeted domain members, making it much easier to deploy a specific configuration for secure wireless connections to wireless client computers. Software Restriction Policies This lets you protect your computer environment from untrusted code by identifying and specifying which applications are allowed to run. With software restriction policies, you can: Note: Software restriction policy settings should not be used as a replacement for antivirus software. Last Modified 3/1/05 4:41 PM |