SBS 2003 Administration

Figure 8.43: Selecting WMI filters for users to be linked to the GPO 9. A WMI filter can also be selected for computers. This selection functions in exactly the same way as described in the previous step.

Then click Next. 10. A summary of the selections is displayed.

After you have completed the modeling wizard, a new entry is added in the Group Policy Modeling node. The Content tab of the node for all existing objects displays information about the domain controller used, the selected users and computers, and the execution date. Select any of the available objects to get the summary for this object (see the following figure).

The Summary tab displays an HTML report of the user and computer configuration for group memberships, GPOs, and WMI filters. The Settings tab displays an HTML report of the simulated policy settings. The Query tab contains the parameters that were given to generate the simulation.

Figure 8.44: Group policy modeling in the GPMC Via the context menu of the modeled object, you can run the same query again, run a new query based on the existing query, or generate a report. Open the Resultant Set of Policy (RSoP) MMC by selecting Advanced View from the context menu. This MMC contains the same data as that contained in the HTML report.

However, the HTML report only shows the current value of a policy and the GPO that sets this value. If multiple GPOs are allocated, only the list of all the GPOs and their processing sequence will be displayed in the Group Policy Results MMC..

Group Policy Results The group policy results are not only displayed for users and computers for whom group policy modeling has been carried out, but also for real users and computers. One is dealing here with real data that has been collected from an existing computer. No simulation is carried out on a domain controller.

For this, the destination computer must have Windows XP or Windows Server 2003/SBS2003 installed on it. No group policy results can be obtained from computers running Windows 2000 Professional/Server. In order to get the group policy results from a destination computer, the user must have local administrative rights for this computer.

However, it is essential for the delegation of group policy result data that the Windows 2003 schema be available in the forest. Use the ADPREP program for this purpose. A domain controller under Windows Server 2003 environment is not essential.

Take the following steps to display the group policy results: 1. Select Group Policy Result Wizard from the context menu of the Group Policy Results node. 2.

Click Next when the welcome message is displayed. Then select the computer for which the group policy results are to be displayed. Either the current computer or any other computer can be selected.

If you do not want to display any policy results for the computer, enable the Do Not Show the Policy Setting Results for the Selected Computer checkbox. Then click Next. 3.

Select a user. You can either select the current user or any other user. If you do not want to display any policy results for the user, enable the do not show the user policy results checkbox.

Then click Next. 4. A summary of the settings is generated.

Click Next and then Finish. The newly created policy result set is available as a new node under Group Policy Results. By default, the name of this set is in the format username/computer name.

It has three tabs: Summary, Settings, and Policy Events. The Summary and Settings tabs contain the same information as they did under group policy modeling. The Policy Events tab (see Figure 8.

45) contains all the securityrelated events (information, warnings, and error messages) of the event log from the destination computer. For this the user must have permission to read the event log via remote access. All users have this permission in the Windows XP environment, but not in the SBS 2003 and Windows Server 2003 environments.

