|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/windows-gpo-for-active-directory-202520222019w11/
课程评论:没有评论
课程名称:活动目录与组策略(2025, 2022, 2019, W11) 课程概述: 在当今快速变化的IT环境中,有效的策略管理至关重要。《GPO指挥中心:Windows服务器2025-2019及Windows 10/11的活动目录政策掌握》课程将理论与实践相结合,使管理员能够在异构Windows环境中架构、部署和故障排查组策略对象(GPO)。您将深入了解从服务器2019到服务器2025的功能集演变,并掌握Windows 10和11的客户端细节。 适合人群: - 系统管理员,旨在标准化域范围内的配置 - IT架构师,设计可扩展的活动目录基础设施 - 安全工程师,负责通过GPO驱动的设置强制合规 - 帮助台负责人,自动化桌面配置和软件部署 - DevOps从业者,将政策管理集成到CI/CD管道中 课程前提: - 对Windows服务器(2019/2022)有基本了解 - 了解活动目录和域概念的基础知识 - 能够访问管理控制台(服务器管理器、GPMC) 学习目标: 完成课程后,您将能够: - 导航和扩展活动目录的OU结构以优化GPO链接 - 创建、编辑和链接GPO到目标Windows服务器2019、2022、2025及Windows客户端的站点、域和OU - 在中央存储中管理ADMX/ADML模板以实现多语言部署 - 通过GPO设置实施高级安全性(凭据保护、应用程序锁、BitLocker) - 自动部署软件和文件夹重定向,以实现无缝用户体验 - 故障排查GPO应用顺序、复制和权限问题 模块主题: 1. AD与GPO基础 - AD架构与复制 - GPO处理顺序(LSDOU) - 本地与域GPO优先级 2. GPMC深入研究 - 创建与编辑GPO - 备份/恢复及版本控制 - 委派与权限 3. ADMX/ADML管理 - 理解管理模板 - 中央存储设置 - 自定义ADMX创建 4. 核心策略场景 - 密码、锁定和审计策略 - 软件安装(MSI、脚本) - 文件夹重定向与漫游个人资料 5. 以安全为中心的GPO - BitLocker强制 - AppLocker规则集 - Windows Defender ATP集成 6. 多版本兼容性 - 管理混合操作系统环境 - 版本特定的策略设置 - AD复制注意事项 7. 故障排查与审计 - GPResult和日志记录 - 常见错误及解决方案 - 审计策略与GPO健康检查 本课程将通过实践实验帮助学员真正掌握活用活动目录与组策略的技能。
Introduction & RationaleIn today's dynamic IT landscape, effective policy management is non‑negotiable. "GPO Command Center: Active Directory Policy Mastery for Windows Server 2025-2019 & Win 10/11" bridges theory and practice, empowering administrators to architect, deploy, and troubleshoot Group Policy Objects (GPOs) across heterogeneous Windows environments. You'll gain deep insight into the evolving feature set from Server 2019 through Server 2025, and master the client‑side nuances of Windows 10 and 11.Who Should EnrollSystems Administrators looking to standardize domain‑wide configurations.IT Architects designing scalable Active Directory infrastructures.Security Engineers tasked with enforcing compliance via GPO‑driven settings.Helpdesk Leads automating desktop configurations and software deployment.DevOps Practitioners integrating policy management into CI/CD pipelines.PrerequisitesBasic familiarity with Windows Server (2019/2022).Foundational knowledge of Active Directory and domain concepts.Comfort accessing administrative consoles (Server Manager, GPMC).Learning ObjectivesBy course end, you will be able to:Navigate and extend Active Directory's OU structure for optimal GPO linkage.Create, edit, and link GPOs to Sites, Domains, and OUs targeting Windows Server 2019, 2022, 2025, and Windows clients.Manage ADMX/ADML templates in a Central Store for multi‑language deployments.Implement advanced security (Credential Guard, AppLocker, BitLocker) via GPO settings.Automate software deployment and folder redirection for seamless user experiences.Troubleshoot GPO application order, replication, and permission issues across domain controllersModuleTopics CoveredHands‑On Lab1. AD & GPO Foundations• AD architecture & replication• GPO processing order (LSDOU)• Local vs. Domain GPO precedenceConfigure Local GPO on Windows 10 VM; observe policy clashes.2. GPMC Deep Dive• Creating and editing GPOs• Backup/restore and versioning• Delegation and permissionsBuild GPOs for password policies; delegate to junior admins.3. ADMX/ADML Management• Understanding Administrative Templates• Central Store setup• Custom ADMX creationImport ADMX for Server 2025; create a custom template for in‑house app.4. Core Policy Scenarios• Password, lockout, and audit policies• Software Installation (MSI, scripts)• Folder Redirection & Roaming ProfilesDeploy MSI package via GPO; configure Documents folder redirection.5. Security‑Centric GPOs• BitLocker enforcement• AppLocker rule sets• Windows Defender ATP integrationEnforce BitLocker with startup PIN; create AppLocker rules.6. Multi‑Version Compatibility• Managing mixed‑OS environments• Version‑specific policy settings• AD replication considerationsTest policy application on Server 2019 vs Server 2025 DCs; troubleshoot schema mismatches.7. Troubleshooting & Auditing• GPResult and logging• Common errors and resolutions• Audit policies and GP health checksSimulate replication failure; use Event Viewer and GPLogView to diagnose.