#WindowsServer
gpmc.msc to reach it
gpedit.msc to edit local files
DDL : for password policies like 7 characters minimum etc
Groups are Organizational Units.
L.S.D.OU : Local Site Domain OU
TP
block Panneau de config - Control Panel block CMD block Regedit block Powershell
Adding GPO to our server
![[Pasted image 20240313154353.png]]
CTRL + M and we choose the GPO manager
From the GPO manager panel we'll be doing the restrictions.
to access: choose edit on the policy
![[Pasted image 20240313163948.png]]
block control panel
![[Pasted image 20240313155020.png]]
blocking CMD
![[Pasted image 20240313155057.png]]
blocking regedit
![[Pasted image 20240313155212.png]]
and we can do many other things....
with this code we force update the Group Policy
gpupdate /force /wait:0
![[Pasted image 20240313160001.png]]
Restrcting users to change their Desktop and Documents
![[Pasted image 20240313163507.png]]
second step is : on decoche le premier option
![[Pasted image 20240313163523.png]]
What are the three fases of GPO ?
- Local
- Site
- Domain
- OU
In short LSDOU
GPO - Default Domain Policy
Applies to all of the domain from one place, mostly used for Password policies.
on CMD
gpupdate /force /wait:0
gpresult /r
On the client side
run > gpedit.msc to view GP Manager in the client device
run > compmgmnt.msc to view Computer Manager in the client device