MDOP 系列之二: Microsoft 進階群組原則管理

Slides:



Advertisements
Similar presentations
Web Role 的每台虚机运行有 IIS ,用于处理 Web 请求 Worker Role 用于运行后台进程 Cloud Service 是什么? 支持多层架构的应用容器 由多个 Windows 虚拟机集群构成 集群有两种类型: Web 和 Worker Cloud Service 做什么 进行应用的自动化部署.
Advertisements

应用技术 陕西华辉科技有限公司.
泛舆情管理平台 ——助力媒体业务创新 新模式 新格局 创新盈利增长点 2/26/2017 1:59 AM 屈伟: 创始人,总裁
中国银行业前置端操作系统移植研究.
3/3/ :01 PM © 2007 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
请点击以下链接下载WinHEC的演讲材料
借助公有云实现游戏的弹性运营 Shaun Fang (方兴) Azure开发技术顾问
Windows Hyper-V与集群共享卷
Customer Service & Support
请点击以下链接下载WinHEC的演讲材料
1. 设定愿景,确定业务场景 Microsoft Corporation
广东省广州市花都区教育局教研室 汤少冰 优化评估方式, 促进中学英语的教与学 广东省广州市花都区教育局教研室 汤少冰
張書源 Microsoft MVP MCT 趨勢科技 技術經理 網酷科技 資深顧問 集英信誠 資深顧問
Office 2013 全新功能介紹 台灣微軟 Office 大使 楊承恩 Marcus Microsoft Office
講師姓名:黃信嘉、黃振宇 職稱:微軟技術支援副理 公司名稱:台灣微軟 課程代碼:WCL305
四川省集体林权流转平台 中国西部林权交易网
全国信息技术标准化技术委员会 (SAC/TC28)工作交流
Windows 10 混合现实 Mingfei Yan 高级项目经理
Benjamin Armstrong 高级项目经理 微软
W371 如何使网络设备更好的和Windows Vista工作
MBL 340 Tablet PC SDK:在您的应用程序中使用数字墨水
資料檔案的安全性管理 羅英嘉 2007年4月.
今天很高兴能够利用Web Cast和大家讲解嵌入式XP的新增功能。
什麼是電子軟體下載 Electronic Software Download (ESD).
OFC 302 InfoPath2007新特性及解决方案.
最新 Windows Server 徽标 要求和计划
Windows Mobile 轻松接轨GPS
Microsoft Office SharePoint Server 2007 事件追蹤與專案管理
SOLUTIONACCELERATORS Windows Vista Hardware Assessment 1
MSG 321 统一消息架构和PBX集成.
朝雲端專業DBA邁進: 深入剖析 Windows Azure SQL Database 完整資料庫管理、雲端報表建立、建置分散式雲端資料庫
利用最新Hyper-V Replica 功能達成Hyper-V 災難備援機制
Windows Server 2008 NAP整合802.1x網路安全控管
互聯網安全資訊 助您達至更安全的網上體驗.
服務啟用、導入流程、 郵件移轉步驟簡介 Microsoft Office 12/2/2018
MBL 325 开发跨平台的 Windows Mobile应用程序
MBL 327 Windows Mobile开发中的异构系统集成
Cameron Brodeur Program Manager US-Device & Storage PM
David Edfeldt Senior Program Manager Windows Logo Program
构建 Windows TV Tuner 产业 生态环境的重要观点
微软新一代云计算 面向企业的 Office 365 客户培训大纲
1/2/ :39 PM 讀經 以弗所書 4:31-32 © 2007 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may.
1/2/ :38 PM 耶利米書 33:1-3 約翰福音 14:12-14 © 2007 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names.
使徒行傳 21:17-23章「保羅的見證(一)」 引言 預言保羅為主的名受許多的苦難的實現
2/24/2019 5:40 AM © 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
Exchange 2007 系統部署 -- 儲存預測與測試
教师课堂教学能力提升培训 ---“互联网+教育”考勤小测验 Plickers 洛阳理工学院
Microsoft SQL Server 2008 報表服務_設計
利用 ASP.NET MVC 提升您的 Web 應用程式


橫跨電腦、手機與軟體的全方位端點管控解決方案
请点击以下链接下载WinHEC的演讲材料
呂政周 精誠恆逸教育訓練處 資深講師 Windows PowerShell 呂政周 精誠恆逸教育訓練處 資深講師
Windows Server 2008 遠端管理 - Windows Remote Management
使用WPF创建Windows应用和Web应用
4/30/2019 7:40 AM 約翰福音 15:9;17:20-23 加拉太書 6:1-2 © 2007 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product.
DEV 343 VS2005超快速开发方案/EEP2006控件包.
5/4/2019 4:42 PM © 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
使徒行傳 24-26章 [ 保羅的見證(二)] 徒9:15 “  主 對 亞 拿 尼 亞 說 、 你 只 管 去 . 他 是 我 所 揀 選 的 器 皿 、 要 在 外 邦 人 和 君 王 並 以 色 列 人 面 前 、 宣 揚 我 的 名 。 ”]
TechEd /6/ :36 PM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks.
Windows 徽标计划工具:综述与发展趋势
5/5/2019 7:06 PM 两跨框架梁截面配筋图的绘制 © 2007 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may.
百万亿次超级计算机诞生记 姓名 Xiangyu Ye 职务 微软中国技术中心资深HPC顾问 公司 微软中国
5/15/2019 姓名: 公司名称: 云赛空间BP模板 Now let’s take a look at who we are, what we’re doing and why we’re doing it in China... This is an image of a technology.
DEV 343 VS2005超快速开发方案/EEP2006控件包.
MGT 213 System Management Server的昨天,今天和明天
Bob Combs Lead Program Manager Microsoft Corporation
Ron Jacobs 高级技术专员 Microsoft
Windows Workflow Foundation CON 230
Presentation transcript:

MDOP 系列之二: Microsoft 進階群組原則管理 加速部署與管理桌上型電腦 簡志偉 大型企業業務暨經銷事業群 台灣微軟

提昇企業桌上型電腦管理能力 動態資料串流軟體作為中央管理服務 將軟體清單轉換成商務智慧 可加速桌上型電腦修復的強大工具 Microsoft Desktop Optimization 可加速部署與提升管理能力 動態資料串流軟體作為中央管理服務 Microsoft SoftGrid Application Virtualization* 將軟體清單轉換成商務智慧 Microsoft Asset Inventory Service 可加速桌上型電腦修復的強大工具 Microsoft Diagnostics and Recovery Toolset 經由變更管理增強群組原則 Microsoft Advanced Group Policy Management 主動管理應用程式與作業系統失敗 System Center Desktop Error Monitoring *終端機服務的 SoftGrid Application Virtualization CAL 已發行,且與 MDOP 分開銷售 2 2

Microsoft Management Summit 2007 March 26-30, 2007 | San Diego, CA 1/3/2019 3:49 AM 簡介 2006年10月從 Desktop Standard 取得 在群組原則的延伸投資 GPOVault – Advanced Group Policy Management (AGPM, 進階群組原則管理) 群組原則的變更管理 建立在 Group Policy Management Console (GPMC) 的基礎上 © 2006 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Microsoft 進階群組原則管理 (AGPM) 經由變更管理增強群組原則 提供有效率的群組原則變更管理 以角色為基礎的系統管理與範本 有彈性的委派模組 版本、歷程及復原 運用精細的系統管理控制權加強管理 降低失敗擴散的風險 PC 管理能力 診斷與支援工程師

Microsoft 進階群組原則管理 (AGPM) 案例研究 – Forsyth County 建立與管理群組原則,將整個企業的桌上型電腦組態保持在最新狀態 挑戰: 以即時、有效率及安全的方式管理 1,650 部 PC 上的群組原則 結果: 輕鬆且安全地建置群組原則物件 視需要復原群組原則變更,而不再需要等待 PC 汰換 可在最短的停機情況下,滿足即時群組原則建立需求 順暢且自動化的群組原則變更管理

Microsoft 進階群組原則管理 (AGPM) MMC 延伸到 GPMC 針對群組原則架構提供完整的異動管理 以角色為基礎的委派 離線編輯 Check-out/Check-in 透過歷史紀錄追蹤改變 部署流程 Roll-back and Roll-forward

Microsoft Management Summit 2007 March 26-30, 2007 | San Diego, CA 1/3/2019 3:49 AM AGPM 架構 Copy of GPO 1 Copy of GPO 2 GPO 1 GPO 2 AGPM 伺服器元件 AGPM 伺服器端 網域控制站 AGPM 管理元件 AGPM 用戶端 © 2006 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

安裝進階群組原則管理伺服器 安裝伺服器元件: gpovents.msi 應該安裝在網域伺服器上 安裝特別注意 建立一個負責與 AD 溝通的 AGPM 服務帳戶 License 檔案 建立一個擁有 AGPM 完整權限的管理員

安裝進階群組原則管理用戶端 安裝用戶端元件: gpoventc.msi 必須與 GPMC 一起安裝在電腦上 可以透過群組原則安裝 Windows Vista Windows Server 2003 可以透過群組原則安裝

進階管理群組原則物件的檔案紀錄 GPO 更新紀錄 時間標籤 GPO 狀態 擁有者 設定與差異報告 復原舊的 GPO 套用新的 GPO

檔案紀錄位址 檔案位置標籤 必須指定主機名稱 (FQDN 或 IP 位址) 為每一個用戶端設定執行AGPM 可以透過 AGPM 的 ADM 檔案進行管理

進階群組原則管理 SMTP 設定 設定使用者接收委派管理的 email 建立新的 GPOs 發佈或更新 GPOs 其他委派任務

進階群組原則管理委派 樹系層級委派 網域層級委派 GPO 層級委派角色 完全控制 批准者 (Approver) 編輯者 (Editor) 檢閱者 (Reviewer)

設定與AGPM伺服器連結 設定email通知 委派管理 demo 設定與AGPM伺服器連結 設定email通知 委派管理 © 2006 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Microsoft Management Summit 2007 March 26-30, 2007 | San Diego, CA 1/3/2019 3:49 AM 工作流程 Check-out 編輯 檢閱 Check in 請求部署 批准/拒絕 Check-out/Check-in 提出請求 建立 GPOs 部署 GPOs 刪除已部署的 GPOs 請求會被送到事先定義的批准者 範本 支援 GPO 建立 允與比較 GPOs 版本之間的差異 © 2006 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

控制 GPOs Uncontrolled GPOs 只用在實際環境上

demo 管理 Uncontrolled GPOs © 2006 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

建立與使用範本 建立新 GPOs 設定的基準 建立範本 從範本建立 GPO 滑鼠右鍵建立 GPO 滑鼠右鍵點擊 Change Control 選擇 “New Controlled GPO”

編輯 Controlled GPOs 必須“check-out” GPO 進行編輯 Controlled GPOs 使用 GPOE 來編輯 當 GPO 被更新, 就要“checked-in”

demo 建立/編輯 GPOs © 2006 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Microsoft Management Summit 2007 March 26-30, 2007 | San Diego, CA 1/3/2019 3:49 AM 報告 報告比較在歷史紀錄內的不同時間點 Report 比較不同的 GPOs Report 比較範本 設定報告 顯示設定 差異性報告 © 2006 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

demo 差異性報告 © 2006 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

從 AGPM 部署 GPO 具有編輯權限的使用者可以選擇 “Deploy” 寄送 email 給批准者 (會在 SMTP 設定中被提到) 將 GPO 放入 “Pending” 模式 被授權的使用者可以針對 ”Pending” GPO 選擇 ”Deploy” 或 “Reject” Full Control (完全控制) – 這個角色具有權力部署 “Approver” (批准者) – 這個腳色具有權力部署

透過 AGPM 刪除 GPO 從檔案紀錄管理刪除 ‘un-controls’ GPO 一旦被放在回收桶 破壞 回復

demo 部署/刪除 GPOs © 2006 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

資源 Microsoft Desktop Optimization Pack for Software Assurance 的網站: http://www.microsoft.com/taiwan/windows/products/windowsvista/buyorupgrade/optimizeddesktop.mspx 可用資源 取得Microsoft 進階群組原則管理規格書:

Q & A

© 2007 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

Microsoft makes no warranties, express or implied, in this summary. © 2007 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only and is subject to change. Microsoft makes no warranties, express or implied, in this summary.