Rsop Security Has Requested to Process Its Policy Settings Again

This chapter is from the volume

Resultant Fix of Policy (RSoP)

As you become more familiar with Grouping Policy, both at the local and Active Directory levels, you volition quickly see that they can be very complex. The complexity results not merely from the numerous settings that are available within a single Group Policy, but also from the fact that many policies can exist applied, and at many unlike areas within the enterprise. When these settings finally apply to the computer and user on a Windows XP Professional computer, it can be very difficult, because of the array of settings from all the GPOs, to make up one's mind the final policies that are practical. Microsoft has gone to great lengths with Windows XP Professional to assist decipher the complexity of GPOs and security settings that are possible. Microsoft has done this with 3 fantastic tools: Group Policy Result (gpresult), Group Policy Update (gpupdate), and the RSoP snap-in.

Group Policy Result

The kickoff tool, Group Policy Outcome, is a command-line tool. This tool gives you lot the Resulting Set of Policy (RSoP) that applies to your computer and user accounts. The tool is extremely uncomplicated to run and is easy to read when it spits the results back to you. All you need to do is start a command prompt and type gpresult, equally shown in Figure 3.iv.

Figure 3.5

Figure 3.4 Grouping Policy Result output for the RSoP.

Group Policy Update

It is well known that Grouping Policies automatically refresh past default. And so, when you configure any new setting in the Local or Agile Directory Group Policies, the settings will automatically refresh for both the computer and user. For some situations, this is not sufficient, though. You might exist testing out new policies and want to run across the results immediately, or desire to force a new security policy to a department of users immediately. If you lot demand to forcefulness a policy immediately, y'all need only to run the Group Policy Update command-line tool, gpupdate. This tool will investigate the Local and Active Directory–based Grouping Policies and utilize them immediately to both the reckoner and user accounts. You exercise non demand to run whatsoever switches with the tool, but if y'all want better command, you can employ the chief switches listed next:

  • U: (Reckoner, User)—Allows explicit refreshing of either the reckoner or user portions of the policies that need to be applied.

  • /forcefulness—Reapplies all settings in the policies, whereas if no switches are used, only the changed policies apply.

  • /logoff—Some user-based Group Policy settings exist (such as Folder Redirection) that do not apply until the user logs off and back on. With this switch, the user will exist logged off automatically afterward the other policies refresh.

  • /kicking—Like the user settings, some figurer settings require a reboot (such equally software deployment). With this switch, the computer will automatically reboot subsequently the other policies refresh.

RSoP Snap-in

The final tool for determining the RSoP is the new RSoP snap-in. This tool enables you to investigate the policies in a GUI interface, which tin then be saved to a file or website for archiving. To open this tool, open up a new MMC and add the RSoP snap-in. When you open the tool, you volition have the following options for your Windows XP Professional person computer:

  • Calculator Telescopic—You have the choice of selecting either your computer or some other reckoner on the network (as long every bit you have administrative credentials on the remote computer). You are also able to eliminate the figurer portion of the RSoP, if you lot want to run across merely user-based settings.

  • User Scope—You can select the currently logged on user or another user who can access the local computer. Again, y'all must accept the right privileges to view another user'south RSoP. You tin can also eliminate the user portion of the RSoP, if you want to see only the reckoner-based settings.

When the tool is run and finishes, it gives you the results in the MMC that yous initially opened. Figure iii.5 shows the resulting RSoP format, which is the same format every bit the original Grouping Policy Editor.

Figure 3.5

Figure three.five RSoP snap-in results for both the local computer and currently logged-on user.

mauldintiong1970.blogspot.com

Source: https://www.pearsonitcertification.com/articles/article.aspx?p=402458&seqNum=4

0 Response to "Rsop Security Has Requested to Process Its Policy Settings Again"

Post a Comment

Iklan Atas Artikel

Iklan Tengah Artikel 1

Iklan Tengah Artikel 2

Iklan Bawah Artikel