Skip to main content
AD Academy
Defense and Monitoring
Intermediate18 minLast updated: Topic 2 of 3

Group Policy and Audit

How policy helps strengthen security.

Not read

What you will learn here

  • What a GPO is and how it applies
  • How to harden security with policies
  • How to turn on auditing

Worth reading first:Best Practices for Protecting AD

Group Policy () is a mechanism for centrally managing Windows settings. Using a GPO you can enable Audit, forbid weak passwords, restrict running programs, and more.

המדיניות מוחלת בסדר: 1. Local Policy במחשב עצמו. 2. Site — אתר פיזי או רשת. 3. Domain — כל הדומיין. 4. OU — האחרון מנצח. מדיניות מאוחרת דורסת את הקודמת, אלא אם הוגדר Enforced.

Useful GPO settings

  • Audit Policy — enabling logging of logons/logoffs, object changes and privileged actions.
  • Password Policy — minimum length, complexity and password expiration.
  • — automatic rotation of Local Administrator passwords.
  • — protecting Credentials from extraction from memory.
Architecture and Theory — Under the Hood

is applied in LSDOU order: Local → Site → → OU. The last policy wins, unless Enforced or Block Inheritance is configured.

  • Computer Configuration updates at startup, User Configuration at login; background refresh every 90 minutes (+0-30 random).
  • Each consists of a GPC in and a GPT in the SYSVOL folder.
  • Security Filtering and WMI Filtering narrow down the target audience.
Practical Configuration (PowerShell / GUI)
New-GPO -Name "Workstation-Baseline"
New-GPLink -Name "Workstation-Baseline" -Target "OU=Workstations,DC=corp,DC=com"
Set-GPPermission -Name "Workstation-Baseline" -TargetName "IT-PCs" -TargetType Group -PermissionLevel GpoApply
gpupdate /force
gpresult /h C:\report.html
powershell
Troubleshooting
  • Policy not applied — Check Security Filtering and Authenticated Users (Read permission required).
  • gpresult shows Denied (Security) — The user is not in the target audience.
  • SYSVOL replication stuck — dfsrmig /getmigrationstate.

Check yourself

What is a GPO?

Was this page helpful?