AD Groups, Service Accounts & GPO
The Day I Learned About Proper Group Strategy
Active Directory Groups: The Foundation of Access Control
Group Types
Security Groups
# Create security group
New-ADGroup -Name "Finance-FullAccess" `
-GroupScope Global `
-GroupCategory Security `
-Path "OU=Security Groups,OU=Groups,DC=company,DC=com" `
-Description "Full access to Finance file shares"Distribution Groups
Group Scopes: Understanding the Differences
Domain Local Groups
Global Groups
Universal Groups
The AGDLP Strategy (My Standard Approach)
Real-World AGDLP Example
Group Nesting Best Practices
Group Management Scripts
Service Accounts: The Right Way
Types of Service Accounts I Use
1. Standard Domain User Accounts (Legacy Method)
2. Managed Service Accounts (MSA)
3. Group Managed Service Accounts (gMSA) – My Preferred Method
Creating gMSA Step-by-Step
Service Account Best Practices
Migrating from Standard to gMSA
Group Policy Objects (GPO): Centralized Configuration Management
GPO Architecture
GPO Processing Order (LSDOU)
Creating and Linking GPOs
GPO Structure: Computer vs User Configuration
Common GPOs I Deploy
1. Security Baseline GPO
2. Workstation Hardening GPO
3. Software Deployment GPO
4. Drive Mapping GPO
GPO Filtering and Targeting
Security Filtering
WMI Filtering
Item-Level Targeting (Preferences)
GPO Troubleshooting
Check Applied GPOs
Force GPO Update
GPO Processing Logs
Check GPO Replication
GPO Backup and Restore
GPO Reporting
Real-World Scenarios
Scenario 1: Deploying Administrative Tools
Scenario 2: Desktop Lockdown for Kiosk Computers
Scenario 3: Time-Based Access Control
Best Practices Summary
Groups
Service Accounts
Group Policy
Conclusion
Further Reading
Last updated