Windows Tech Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Monday, 21 February 2011

Group Policy Horrors

Posted on 15:33 by Unknown

I'm reviewing a client's environment to assess the root causes for reported "slow logins".  I do my usual quick-pass analysis of the AD environment, the connectivity, DNS, blah blah.  Then I do a second pass with DCDIAG, NETDIAG, REPADMIN, event logs, nslookup, and gpresult, etc.  Three words: Oh My God.  They don't have a log of GPO's in their environment, but after 30 minutes of intense scrutiny of what each GPO has "enabled" or "disabled" and I had to look around to find where my jaw bone had fallen off.

People.

Please.

If you tinker with GPO's…

TEST THEM in an ISOLATED environment BEFORE you ever put them into PRODUCTION.

I beg you.  Please.

Apparently, the sysadmin dudes (I haven't yet met them so I will withhold judgement until I do) had found quite a few (translation: hundreds) of settings they thought interesting enough to modify their setting.  Aside from the DNS errors, the replication errors, the DHCP errors, the roaming profiles (oh holy geez, I haven't yet begun to digest that part, ugh), and the WINS/NetBIOS master browser bullshit flying around like gnats at carcas party in the Sahara, I would say that at least a good portion of the "slowness" is from having to process a (excuse my technical term here…) shitload of Group Policy settings at every login, every 90 minutes thereafter, as well as at every startup, login, logoff and shutdown.  Yes.  I'm not kidding.  They enabled or disabled things for all of those events. Wonderful.

How can I compare this to something tangible in life?…. hmm…. finger's tapping…. stares into space pondering a suitable analogy or metaphor…. hmm….

Ok.

It's like this:  Group Policy is powerful and insanely useful.  It is fire.  Fire can cook food.  It can provide warmth in a harshly cold environment.  It can dry things.  It can also burn the absolute living shit out of you if you don't treat it with respect.  Yes.  I mean that absolutely.  GPO's are not something to tinker with unless you've studied them, tested them and tested them again.  Jeremy Moskowitz has some great info out there to read up on, as do many other sites, blogs, etc.

One word to keep in mind at all times with GPO's is "tattooing".  Undoing a GPO change in a large environment can often be a daunting and difficult task.  It's not always a matter of changing a setting from "Enabled" to "Not Configured".  Many times you have to "double-smack" it by setting it to the opposite, and then back to "Not Configured".  It's messy.  In some instances things can get broken so bad that the only pragmatic "fix" is a new environment.  Yep.  I've seen that.

My wife is cooking something that smells so f-ing good I'm ready to eat my own shirt sleeve in response to uncontrollable hunger.  Gotta go - cheers!

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in group policy, network administration, windows | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Voting Time: Help Me Out?
    I need to get a better view of how I should manage this blog if I'm going to keep at it. I'd like to know how you typically discover...
  • A World Without Competition
    Try to imagine what things would be like today had there not been fierce competition in certain key parts of our world.  I’ll give you some ...
  • Book Update
    I posted some gibberish a few weeks ago about another book project.  Well, I'm getting close to wrapping it up, so I thought I'd go ...
  • Cost
    Software technology, like any technology, provides a means to solving problems.  Some big. Some small.  Some that help.  Some that hurt.  An...
  • Windows 7: Default User vs All Users
    A lot of confusion seems to occur with understanding the difference between the "Default User" profile, and the "All Users...
  • Time to Give Props
    With the ever-expanding volume and breadth of information on the Internet today, it's easy to focus on my own thoughts, experiences, ide...
  • Table of Contents (Preliminary)
    Here's the preliminary Table of Contents for my new book "The AutoCAD Network Administrator's Bible - 2013 Edition".  I...
  • The Nicest IT and IT Vendor Folks I Know
    I've ranted many times before how it's unfair to "hate" an entire company, without providing a rationale for it based on s...
  • Windows 8
    Two small, yet irritating things, that I hope Windows 8 addresses with respect to Windows 7: Being able to put the Recycle Bin in the S...
  • Stupid Assumptions
    After years of watching sci-fi TV shows, movies, etc. it's finally come to a point where even the so-called brightest of our authors and...

Categories

  • a
  • activation
  • active directory
  • advertising
  • agile
  • agility
  • amazon
  • american
  • apple
  • application virtualization
  • applications
  • art
  • articles
  • asp
  • augi
  • authors
  • autocad
  • AutoCAD Autodesk
  • autodesk
  • autolisp
  • automation
  • automotive
  • backups
  • batch
  • beer
  • beta
  • blackberry
  • blogs
  • bongloads
  • book
  • books
  • Books writing kindle amazon technology business projects
  • browsers
  • business
  • cad
  • career
  • certification
  • chrome
  • city government
  • civilization
  • cloud services
  • cmd
  • cmmi
  • comedy
  • command
  • community
  • computers
  • conferences
  • config manager
  • consultants
  • consulting
  • contracting
  • cranium drainium
  • crapware
  • culture
  • data center
  • data mining
  • databases
  • deployment
  • directx
  • DLL
  • domains
  • dumb
  • earth
  • economy
  • editor
  • education
  • election
  • elections
  • employment
  • engineering
  • entertainment
  • environment
  • error monitoring
  • events
  • exchange
  • facebook
  • family
  • firefox
  • flexnet
  • fud
  • fun
  • funny
  • games
  • gary vaynerchuk
  • gmail
  • google
  • government
  • group policy
  • hampton roads
  • health
  • history
  • holidays
  • home
  • html5
  • humor
  • hyper-v
  • iis
  • industry
  • infrastructure
  • installation
  • installshield
  • internet
  • internet explorer
  • interviews
  • jobs
  • jtbworld
  • kindle
  • kixtart
  • lab setup
  • languages
  • ldap
  • learning
  • legal
  • licensing
  • life
  • lifecycle
  • linux
  • lisp
  • logging
  • management
  • manufacturing
  • marketing
  • markets
  • mdop
  • mdt
  • medical
  • messaging
  • microsoft
  • microsoft access
  • military
  • mountains
  • movies
  • mozilla
  • music
  • nature
  • network administration
  • news
  • nook
  • nothing
  • office
  • open source
  • openoffice
  • opera
  • operating systems
  • oracle
  • osx
  • packaging
  • patches
  • people
  • photos
  • podcasts
  • policy
  • politics
  • powershell
  • predictions
  • process automation
  • products
  • programming
  • projects
  • psychology
  • publishing
  • rail
  • reading
  • registry
  • religion
  • reporting
  • reviews
  • rsat
  • rss
  • safari
  • safety
  • sales
  • satire
  • sccm
  • scheduling
  • science
  • scripting
  • search
  • security
  • servers
  • services
  • sharepoint
  • shopping
  • sms
  • social stuff
  • society
  • softgrid
  • software assurance
  • software deployment
  • software development
  • software packaging
  • sony
  • speaking
  • sports
  • sql express
  • sql server
  • statistics
  • Statistics news marketing
  • steve jobs
  • stories
  • stuff
  • stupidity
  • symantec
  • sysinternals
  • system center
  • systems architecture
  • t-sql
  • taxes
  • technet
  • technical support
  • technology
  • TED
  • ted talks
  • testing
  • textpad
  • thoughts
  • traffic
  • training
  • transportation
  • travel
  • troubleshooting
  • tutorials
  • twitter
  • ubuntu
  • unattend
  • unemployment
  • updates
  • upfront ezine
  • utilities
  • vacation
  • vba
  • vbscript
  • video
  • virginia
  • virginia beach
  • virtualization
  • visual lisp
  • vmware
  • vmware server
  • voting
  • war
  • weather
  • web
  • web browsers
  • web development
  • web sites
  • windows
  • windows 7
  • windows live
  • windows server
  • windows server 2012
  • windows8
  • winpe
  • wise
  • wmi
  • work
  • writing
  • ws08
  • wsus
  • wwa
  • x64
  • xml
  • ze frank

Blog Archive

  • ►  2013 (37)
    • ►  October (1)
    • ►  September (5)
    • ►  August (8)
    • ►  July (2)
    • ►  June (4)
    • ►  May (4)
    • ►  April (2)
    • ►  March (2)
    • ►  February (8)
    • ►  January (1)
  • ►  2012 (120)
    • ►  December (14)
    • ►  November (12)
    • ►  October (10)
    • ►  September (7)
    • ►  August (3)
    • ►  July (2)
    • ►  June (6)
    • ►  May (6)
    • ►  April (20)
    • ►  March (16)
    • ►  February (18)
    • ►  January (6)
  • ▼  2011 (343)
    • ►  December (15)
    • ►  November (23)
    • ►  October (27)
    • ►  September (35)
    • ►  August (29)
    • ►  July (17)
    • ►  June (23)
    • ►  May (20)
    • ►  April (38)
    • ►  March (61)
    • ▼  February (54)
      • MSIEXEC Error Codes
      • IBM and Watson
      • Consulting Rules
      • How to Make Better Drivers
      • Launch IE and Wait for it to be Closed
      • Another Interview, part 2
      • Upgrades and Downgrades
      • New Zealand
      • Group Policy Horrors
      • Standards Needed
      • My Eyes are Permanently Damaged
      • AutoCAD Performance Tips
      • Shitty Web Sites of The Week
      • The %ProgramFiles% Bug, Part 2 / Distrust & Uncert...
      • Microsoft: Too Early, Too Late
      • So far today...
      • Script of the Day - Open IE on Login (Just One Time)
      • Happy Friday
      • IT Jobs
      • Software Licensing
      • Mixing Gravy with Lumps
      • What Goes Up…
      • Tenuous Linking
      • Sys Admin Tips, Part 1
      • Observations
      • Grammy's Get it Right
      • What a slob I am
      • Repeat After Me: Beer is Tasty
      • Programming Ka-blamming
      • Songs I Could Do Without: Forever
      • Parse and Reparse were Sitting on a Fence
      • Happy Friday: Scripting Windows Search
      • Out of the Box and Free
      • Weekly Summary
      • LDAP / AD script stuff
      • Democracy 101
      • Stupidity
      • Food for Thought
      • Misperceptions are Often Impossible to Change
      • Right Way, and Wrong Way
      • Useful SCCM Developer Tip of the Day
      • Avoid Extremes
      • The Day After
      • Stack Overflow in a pinch
      • Attention AD Admins
      • Bugs/Annoyances: TurboTax Online
      • Windows Admin Basics: Security 101
      • Is Computer a Member of a Domain "Laptops" Group
      • Detection Deflection Reflection
      • Let's Put This Another Way
      • Top-Ranked Customer Service
      • SCCM Web Management
      • Fonts: 101
      • How to: Convert MIT Open Courseware to Kindle Reader
    • ►  January (1)
Powered by Blogger.

About Me

Unknown
View my complete profile