<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Group Policy: Where Do You Want It to Go Tomorrow?</title><link>http://blogs.technet.com/b/grouppolicy/archive/2007/06/28/group-policy-where-do-you-want-it-to-go-tomorrow.aspx</link><description>We often have groups of customers come to Redmond to visit and provide their feedback about the direction in which we are taking our products. Recently, a group of folks joined us for a few days to talk specifically about the desktop and its direction</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: Group Policy: Where Do You Want It to Go Tomorrow?</title><link>http://blogs.technet.com/b/grouppolicy/archive/2007/06/28/group-policy-where-do-you-want-it-to-go-tomorrow.aspx#2736589</link><pubDate>Fri, 11 Jan 2008 18:42:43 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2736589</guid><dc:creator>lee.wilmott</dc:creator><description>&lt;p&gt;I can't believe I didn't spot this earlier...&lt;/p&gt;
&lt;p&gt;Anyway, first let me say that Group Policy is the best thing since sliced bread - I love it. &amp;nbsp;Thank you!&lt;/p&gt;
&lt;p&gt;Secondly, I don't know if it's too late to answer your questions...but here goes...&lt;/p&gt;
&lt;p&gt;1). At the moment I am trying to disable Smart Card Readers via Group Policy and I'm unable to do so. &amp;nbsp;I have used the &amp;quot;Restrict Driver Installation&amp;quot; - but the drivers are already installed. &amp;nbsp;I need to find a solution to two problems...&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; a) ...prevent users from copying data from our network onto Smart Card devices...&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; b) ...the logon script automatically map drives for our users. &amp;nbsp;However, it is errorring because the drive letters that should be mapped to network shares are being used by Smart Card Readers. &amp;nbsp;On our new machines there are 4/5 drive letters that are being used by devices I want disabled (centrally).&lt;/p&gt;
&lt;p&gt;Although the &amp;quot;Prevent Driver Installation&amp;quot; policy is useful, please can we have a new policy that &amp;quot;Disables Hardware Devices...&amp;quot;? &amp;nbsp;Many thanks!&lt;/p&gt;
&lt;p&gt;2). I've never modified a Local Policy - yet! &amp;nbsp;I'm using Group Policy to manage the computers in my environment. &amp;nbsp;By making/creating/modifying the Local Policy then I would be moving away from Central Management - This is the devil as far as I'm concerned. &amp;nbsp;:-)&lt;/p&gt;
&lt;p&gt;3) Purchasing DesktopStandard's Policy Maker is FANTASTIC news for us administrators. &amp;nbsp;The features in this product is AMAZING.&lt;/p&gt;
&lt;p&gt;Is this thread a good place to place any future Group Policy suggestions?&lt;/p&gt;
&lt;p&gt;Lee&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2736589" width="1" height="1"&gt;</description></item><item><title>re: Group Policy: Where Do You Want It to Go Tomorrow?</title><link>http://blogs.technet.com/b/grouppolicy/archive/2007/06/28/group-policy-where-do-you-want-it-to-go-tomorrow.aspx#2687782</link><pubDate>Sat, 29 Dec 2007 04:13:53 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2687782</guid><dc:creator>Charlie B_</dc:creator><description>&lt;p&gt;I could slightly understand MS$ unwillingness to put resources into creating a 64bit version of GPMC if there was no need. The 64bit version exists for Vista and Group Policies should be managed from a desktop. BUT! My network has approx 15,000 desktops and we are using Forefront client security. This requires considerable amounts of constant database communication therefore for a high I/O box with 64bit is in order. We are unable to install the Forefront SQL database on our 64bit SQL 2005 server simply because there is no GMPC installed. This is where i believe MS$ has left users like me in a bind.&lt;/p&gt;
&lt;p&gt;Thanks MS$.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2687782" width="1" height="1"&gt;</description></item><item><title>re: Group Policy: Where Do You Want It to Go Tomorrow?</title><link>http://blogs.technet.com/b/grouppolicy/archive/2007/06/28/group-policy-where-do-you-want-it-to-go-tomorrow.aspx#2362346</link><pubDate>Thu, 08 Nov 2007 04:16:40 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2362346</guid><dc:creator>GRead</dc:creator><description>&lt;p&gt;Setting location of IE History via GP.&lt;/p&gt;
&lt;p&gt;Setting location of ALL logable outputs via GP.&lt;/p&gt;
&lt;p&gt;Setting redirection of desktop, appdata etc per Computer policy, not just user policy.&lt;/p&gt;
&lt;p&gt;Enforcement of a controlled Outlook Disclaimer via Group Policy.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2362346" width="1" height="1"&gt;</description></item><item><title>re: Group Policy: Where Do You Want It to Go Tomorrow?</title><link>http://blogs.technet.com/b/grouppolicy/archive/2007/06/28/group-policy-where-do-you-want-it-to-go-tomorrow.aspx#2236790</link><pubDate>Tue, 23 Oct 2007 22:23:12 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2236790</guid><dc:creator>ecold</dc:creator><description>&lt;p&gt;I second the SUPPORT FOR the GPMC on Server 2003 x64 Edition!! How can this not happen? From what I can tell, MS wants us on the 64 bit bandwagon but yet they don't have basic tools for it? I sold my boss on a 64 bit DC for a brand new domain we are migrating to and have no GPMC to edit from on the server. I can't do an XP machine for each of the three domains I am working on unless of course MS wants to give us one since they don't have a GPMC for 64 bit. :) &amp;nbsp;&lt;/p&gt;
&lt;p&gt;Lots of other good suggestions listed above. I wish I had time to compile a list but I am swamped at the moment.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2236790" width="1" height="1"&gt;</description></item><item><title>re: Group Policy: Where Do You Want It to Go Tomorrow?</title><link>http://blogs.technet.com/b/grouppolicy/archive/2007/06/28/group-policy-where-do-you-want-it-to-go-tomorrow.aspx#1751039</link><pubDate>Tue, 14 Aug 2007 10:50:18 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1751039</guid><dc:creator>Robert Al</dc:creator><description>&lt;p&gt;There are a few things, really &lt;/p&gt;
&lt;p&gt;1. I agree with the &amp;quot;only one active network connection&amp;quot; comment - this is a major security concern for us. We have 150,000 laptops, and want to disable the wireless network card when they're connected to the corporate lan. This is to prevent people pulling up in a car outside our offices and using a connected laptop as a network bridge. We’re in your Vista “TAP”, and had hoped to see this – it would be great to see it for SP1.&lt;/p&gt;
&lt;p&gt;2. Fix the local RSOP tool! Requiring GPMC to be able to read all local RSOP on Vista clients is unrealistic for an enterprise LAN like ours!&lt;/p&gt;
&lt;p&gt;3. These last two really come down to the granularity of control: in Internet Explorer, many settings that are entered are completely unavailable – an example would be the proxy server or autoconfig url (ACURL). If a user is having problems connecting to the internet, and the helpdesk want the user to read the string, all they can see is &lt;a rel="nofollow" target="_new" href="http://acurlconfig.ourcompany.com/"&gt;http://acurlconfig.ourcompany.com/&lt;/a&gt; - nothing useful, as we need to know the specific settings after this which determine how the ACURL script is created dynamically depending on a user’s machine configuration, which is in turn set by site group policy.&lt;/p&gt;
&lt;p&gt;4. In the “Advanced” tab in Internet Explorer, grey out the settings that are set by GP (like when you attempt to edit Local Group Policy, and domain-wide settings override some options – you just can’t edit them). This way, we would be able to leave the tab there so that more advanced users could change the ones that we don’t set (i.e. ones that have little affect on the client, but which they may want to change for their own personal reasons).&lt;/p&gt;
&lt;p&gt;rob&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1751039" width="1" height="1"&gt;</description></item><item><title>re: Group Policy: Where Do You Want It to Go Tomorrow?</title><link>http://blogs.technet.com/b/grouppolicy/archive/2007/06/28/group-policy-where-do-you-want-it-to-go-tomorrow.aspx#1504941</link><pubDate>Thu, 12 Jul 2007 02:09:34 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1504941</guid><dc:creator>esmith69</dc:creator><description>&lt;p&gt;Very basic request: &amp;nbsp;SUPPORT FOR the GPMC on Server 2003 x64 Edition!! &amp;nbsp;It's so frustrating to read the FAQs for the GPMC....they simply say that it's not supported on x64 edition. &amp;nbsp;They don't give any explanation for why this is the case. &amp;nbsp;Even worse, they give no indication that this is ever going to be fixed.&lt;/p&gt;
&lt;p&gt;Their solution: &amp;nbsp;install the GPMC on an XP workstation. &amp;nbsp;Yes, I know I can do that, but I'm an IT consultant and most of the time I'm managing servers and GPOs through a remote desktop connection over the internet. &amp;nbsp;Since many of my clients have small, one-server environments, running the GPMC from another computer on their network is almost always not an option for me.&lt;/p&gt;
&lt;p&gt;Not being able to manage GPOs straight from an x64 domain controller is going to be a HUGE problem.&lt;/p&gt;
&lt;p&gt;Can someone shed some light on this?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1504941" width="1" height="1"&gt;</description></item><item><title>re: Group Policy: Where Do You Want It to Go Tomorrow?</title><link>http://blogs.technet.com/b/grouppolicy/archive/2007/06/28/group-policy-where-do-you-want-it-to-go-tomorrow.aspx#1504689</link><pubDate>Thu, 12 Jul 2007 00:44:47 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1504689</guid><dc:creator>GPTeam</dc:creator><description>&lt;p&gt;Yes, thank you, Kris! Really appreciate the list. &lt;/p&gt;
&lt;p&gt;Anyone else want to jump in here? We don't bite. :)&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1504689" width="1" height="1"&gt;</description></item><item><title>re: Group Policy: Where Do You Want It to Go Tomorrow?</title><link>http://blogs.technet.com/b/grouppolicy/archive/2007/06/28/group-policy-where-do-you-want-it-to-go-tomorrow.aspx#1440150</link><pubDate>Wed, 04 Jul 2007 20:42:09 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1440150</guid><dc:creator>GPTeam</dc:creator><description>&lt;p&gt;Wow, Thanks Kris...&lt;/p&gt;
&lt;p&gt;This is a fantastic list! we really appreciate the thought you put into this.&lt;/p&gt;
&lt;p&gt;Kevin&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1440150" width="1" height="1"&gt;</description></item><item><title>re: Group Policy: Where Do You Want It to Go Tomorrow?</title><link>http://blogs.technet.com/b/grouppolicy/archive/2007/06/28/group-policy-where-do-you-want-it-to-go-tomorrow.aspx#1427699</link><pubDate>Tue, 03 Jul 2007 10:47:47 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1427699</guid><dc:creator>kurakuraninja</dc:creator><description>&lt;p&gt;Hi, I have a few remarks on group policies:&lt;/p&gt;
&lt;p&gt;1) Policies we would like to see, but are unavailable today:&lt;/p&gt;
&lt;p&gt;-&amp;gt; The ability to manage scheduled tasks via Group Policies&lt;/p&gt;
&lt;p&gt;-&amp;gt; The ability to enforce that only one network is active (prohibit that user is wired connected to the corporate LAN and wireless to a hotspot)&lt;/p&gt;
&lt;p&gt;-&amp;gt; The ability to manage system restore in Windows Vista (we've lost control over that. be able to determine a maximum percentage of diskspace it can consume)&lt;/p&gt;
&lt;p&gt;-&amp;gt; The ability to manage the shadow copying service (set a maximum percentage of diskspace it can consume, define a number of versions to keep, ...)&lt;/p&gt;
&lt;p&gt;-&amp;gt; The ability to manage the schedule of the build-in defragger&lt;/p&gt;
&lt;p&gt;-&amp;gt; The ability to set a maximum size for the Internet Explorer Cache&lt;/p&gt;
&lt;p&gt;-&amp;gt; The ability to set the default network profile (private/work, public) + the ability to predefine some networks that should be considered as private.&lt;/p&gt;
&lt;p&gt;-&amp;gt; The ability to suppress the EULA of the Windows Mobile Device Center&lt;/p&gt;
&lt;p&gt;-&amp;gt; The ability to suppress all update links of the Windows Mobile Device Center&lt;/p&gt;
&lt;p&gt;2) Policies that exist, but lack some functionality:&lt;/p&gt;
&lt;p&gt;ActiveX Installer Service: &lt;/p&gt;
&lt;p&gt; You should have the option to specify wild characters&lt;/p&gt;
&lt;p&gt; You should have an additional option that blocks all other sites for installation (=no UAC prompt), if not listed&lt;/p&gt;
&lt;p&gt;Screen saver:&lt;/p&gt;
&lt;p&gt;At our company we want that after 15 minutes of idle time the screen saver is turned on and password protected, but we don't want to enforce the screen saver. Today you can't accomplish that.&lt;/p&gt;
&lt;p&gt;UAC:&lt;/p&gt;
&lt;p&gt;Today you can enforce UAC, however the user (if he/she has permissions) can still modify this using the interface or using msconfig.&lt;/p&gt;
&lt;p&gt;Normally in both interfaces this option should be grayed out and furthermore this registry key should be protected by a system integrity level.&lt;/p&gt;
&lt;p&gt;Internet Explorer Add-on Management:&lt;/p&gt;
&lt;p&gt;It still lacks the ability to allow/block add-ons based on publisher (similar to what's available for the sidebar)&lt;/p&gt;
&lt;p&gt;3) Policies that don't work:&lt;/p&gt;
&lt;p&gt;Windows Sidebar - Turn Off User Installed Windows Sidebar Gadgets&lt;/p&gt;
&lt;p&gt;4) Some things about Policy processing:&lt;/p&gt;
&lt;p&gt;Make policy processing more robust when connections are slow/unreliable. Even if the processing fails the computer should still has its old settings. We had a Fix for this issue on XP, but on Vista the problem is still there.&lt;/p&gt;
&lt;p&gt;I'm not sure how WMI filters work, but I believe each time a policy is processed the WMI filter is processed as well. This means if you have 10 policies with the same WMI filter attached, the WMI query is executed 10 times. This would be very inefficient and if this is the case today, could you please adapt this? &lt;/p&gt;
&lt;p&gt;Best Regards,&lt;/p&gt;
&lt;p&gt;Kris Titeca&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1427699" width="1" height="1"&gt;</description></item></channel></rss>