Index
G
Generate Security Audits right, 467
/generaterollback, 93–94
geographical hierarchy, 162–163, 189
GINA (graphical identification and authentication), 202
Global Catalog (GC) server, 491
Global groupsdescribed, 516
function of, 491
nesting, 493, 494
in permission structure, 492, 498
global objects, 466
GPO. see Group Policy Objects
GPUpdate command, 94–96
graphical identification and authentication, 202
Gravity Storm Software Service Pack Manager 2000, 216–217
Group Policyaccount security policies in, 463
applying security templates via, 133–137
Audit policy creation with, 482
auditing settings in, 480–481
client/server authentication settings, 60–61
configuring Restricted groups in, 470–471
deploying security settings with, 76–80
for domains, 80–82
group security with, 497
IPSec policies and, 342–343
Kerberos policy creation in, 472–474
for password policy design, 462
patch management and, 632
Recovery Console options, 611
setting permissions via, 458–460
setting registry access permissions via, 546–552
tunnels configured via, 260
for WLAN network infrastructure, 322–326
Group Policy Editor snap-in, 310
Group Policy Management Console (GPMC), 97–98
Group Policy Object Editor snap-in, 331–334
Group Policy Objects (GPOs)assigning IPSec policy and, 277–278
assigning IPSec policy to, 285–286
IPSec policy assignment and, 275
RSoP and, 9
AD configuration and, 675–676
for administrator security, 197
for deployment of software updates, 213–215, 232
OS access restriction and, 637–638, 672, 676–677
for patching IIS servers, 237
recovery agents and, 579
group policy settings, 802.1x, 331–334
group scopes, 491
group strategy for accessing resourcesgroup scopes, 491
important points about, 499
permission structure for data, 491–495
uses for groups, 490
GROUP_MGMT, 89
groupsaccount vs. resource, 619
account, maintenance delegation, 529–530
Administrative, 645–646
combining/nesting, 493–494
default for DNS RRs in Active Directory, 302–303
default for DNS Server Service, 299
default in AD-Integrated zones, 300–301
deleted, troubleshooting, 622
interactive, 512
local as resource groups, 519–521
obsolete, LDAP query for, 526–529
overview of, 515
privileges and, 622
resource, maintenance delegation, 529–530
Restricted groups, 470–472
security, 515–516
groups, securitycreation policy defining, 521–522
Delegation of Control Wizard, 530–534
described, 515
maintenance, delegating, 529
naming policy, defining, 522–523
nesting policy, defining, 524–525
request process, defining, 522
retirement policy, defining, 526–529
described, 528