Centralised configuration.
WHAT IT DOES
Applies configuration to users and computers automatically.
WHAT IT CAN CONFIGURE
Security settings Software installation Drive and printer mappings Desktop and application settings Scripts
WHERE POLICY IS LINKED
To sites, domains and organisational units.
WHAT THE ORDER OF APPLICATION IS
Local, then site, then domain, then organisational unit, with later settings winning.
WHY THAT MATTERS
Unexpected results usually come from a policy applied at a different level.
WHAT TO USE FOR TROUBLESHOOTING
The reporting tools showing which policies applied and which setting won.
WHAT TO AVOID
Very many policies Policies with both user and computer settings Blocking inheritance and enforcing, combined Policies nobody documented
WHAT TO NAME POLICIES
Descriptively, stating what they do.
WHAT TO DOCUMENT
What each policy does, why, and who owns it.
WHAT TO TEST
On a pilot group, before broad application.
WHAT TO BACK UP
Policies, so they can be restored.
WHAT TO REVIEW
Policies that no longer apply to anything.