And yet ANOTHER installment in the “school network” series…
We have office computers, computer lab computers, student lounge computers, and teacher lounge computers. My goal is to set certain policies that will apply on different sets of computers which will give them their own settings. The problem is that we have four groups of users (students, teachers, office, and sysadmins) and four more of computers (students, teachers, office, and shared.) I am completely confused on how to create effective group policies for them. What I have done so far is created organizational units for them. There is a “Users” unit and a “Computers” unit, and each contains about four sub-units which then contain the given users or computers.
This seems to be a bit much … there must be a simpler way to accomplish my goal without having to use eight separate group policies … students should only be allowed to access STUDENT computers – not the ones in the teacher lounge or the office. Nobody except the office staff should be able to log into the office computers. But the office staff should also be log into the student computers (but not into the teacher computers.)
I would set the computer and user configuration for each user group, but the problem is that I want different computer configuration to apply when a certain user logs onto a different computer … is this possible?
The other dilema was that I want certain aspects of the computer configuration to last permanently on allcomputers. For example, I ALWAYS want people to have to use CTRL+ALT+DEL when the login … I NEVER want people to be able to shut down without logging in, and I’ll be damned if I ever see that “Welcome to Windows” screen again. How can I set these up without them conflicting with the varying computer configurations of the users signing on different computers?