GPO Architecture
Group Policy Objects (GPOs) form the backbone of centralized policy management in Windows Server environments. Understanding their architecture and scope is critical for effective security hardening, as GPOs dictate how systems and users are configured across domains, organizational units (OUs), and targeted resources. This section explains the structural components of GPOs, their linking mechanisms, and how scope influences policy application.
GPO Structure and Components¶
A GPO is a collection of configuration settings grouped into categories (e.g., security settings, software installation, user preferences). These settings are stored in the Group Policy Management Console (GPMC) and are applied to targeted scopes. Key components include:
- Policy settings: Define user and computer configurations (e.g., password policies, audit settings).
- WMI filters: Conditional rules that determine when a GPO applies based on system properties (e.g., OS version, hardware).
- Security filtering: Controls which users or groups are affected by the GPO.
Example:
Linking GPOs to Domains and OUs¶
GPOs are linked to domains, OUs, or sites to define their scope. The order of processing follows a hierarchy:
1. Domain-level GPOs apply first.
2. OU-level GPOs are processed in the order they appear in the GPMC.
3. WMI filters further refine applicability.
Example:
# Link a GPO to an OU
New-GPLink -Name "Security Baseline" -Target "OU=Workstations,DC=example,DC=com"
Key Notes:
- Inheritance: Policies from parent OUs cascade to child OUX. Use Block Inheritance to prevent this.
- Precedence: Later-linked GPOs override earlier ones within the same scope.
WMI Filters for Conditional Application¶
WMI filters allow GPOs to apply only to specific systems. For example, a GPO might target Windows 10 machines or devices with a specific hardware ID.
Example:
# Create a WMI filter to target Windows 10
New-WmiFilter -Name "Windows10Only" -Query "SELECT * FROM Win32_OperatingSystem WHERE Version LIKE '10%'"
Linking to a WMI filter:
Policy Processing Order and Scope¶
When a user or computer logs on, Group Policy processes linked GPOs in the following order:
1. Site-level GPOs (if applicable).
2. Domain-level GPOs.
3. OU-level GPOs (processed in the order they appear in the GPMC).
Example:
Note: The "slow link" and "fast link" mechanisms determine how policies are applied, but this is typically abstracted in modern Windows Server versions.
Key takeaways¶
- GPOs are structured around policy settings, WMI filters, and security filtering to control scope.
- Linking GPOs to domains, OUs, or sites defines their application context, with inheritance and precedence rules affecting outcomes.
- WMI filters enable conditional policy application based on system attributes.
- Understanding processing order ensures consistent and predictable policy enforcement across your environment.