SOLVED

Management of GPOs between branches?

%3CLINGO-SUB%20id%3D%22lingo-sub-67112%22%20slang%3D%22en-US%22%3EManagement%20of%20GPOs%20between%20branches%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-67112%22%20slang%3D%22en-US%22%3E%3CP%3EHow%20does%20Microsoft%20recommend%20managing%20different%20or%20conflicting%20group%20policy%20settings%20across%20branches%3F%20If%20you%20setup%20internal%20rings%2C%20you%20may%20have%202-3%20branches%20across%20your%20organizatin%20at%20any%20given%20time.%20Item-level%20targeting%20does%20not%20currently%20allow%20targeting%20of%20specific%20builds%20of%20Windows%2010.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-68199%22%20slang%3D%22en-US%22%3ERe%3A%20Management%20of%20GPOs%20between%20branches%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-68199%22%20slang%3D%22en-US%22%3E%3CP%3ESo%20far%20I%20never%20run%20in%20issues%20using%20always%20the%20latest%20admx%20for%20the%20Windows%2010%20GPOs.%20If%20the%20feature%20doesn't%20exist%20in%20an%20older%20release%2C%20the%20registry%20value%20created%20by%20the%20GPO%20will%20not%20harm%20anything.%3C%2FP%3E%3CP%3EBut%20we%20branded%20our%20internal%20rings%20in%20a%20private%20WMI%20class%2C%20so%20we%20have%20different%20GPOs%20for%20Internal%20Insider%2C%20Early%20Adopters%20and%20General%20Availability.%20So%20we%20can%20activate%20features%20in%20the%20different%20rings.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-67263%22%20slang%3D%22en-US%22%3ERe%3A%20RE%3A%20Management%20of%20GPOs%20between%20branches%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-67263%22%20slang%3D%22en-US%22%3E%3CP%3EDSC%20is%20datacenter%2Fserver-focused%20and%20PowerShell-based%2C%20which%20puts%20it%20out%20of%20the%20reach%20of%20many%20IT%20pros.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFor%20Windows%2010%20client%20devices%2C%20we%20see%20the%20move%20from%20Group%20Policy%20to%20MDM%20(e.g.%20Intune)%20as%20the%20direction.%20%26nbsp%3BLightweight%2C%20scalable%2C%20and%20simple.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-67261%22%20slang%3D%22en-US%22%3ERe%3A%20Management%20of%20GPOs%20between%20branches%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-67261%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20are%20trying%20our%20best%20to%20make%20policies%20in%20new%20releases%20%22additive%22%20so%20that%20they%20don't%20affect%20older%20releases.%20%26nbsp%3BWith%20that%2C%20you%20don't%20need%20to%20make%20them%20conditional.%20%26nbsp%3BThat's%20not%20always%20worked%20with%20existing%20Windows%2010%20releases%2C%20but%20we%20do%20intend%20to%20make%20that%20better.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-67131%22%20slang%3D%22en-US%22%3ERE%3A%20Management%20of%20GPOs%20between%20branches%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-67131%22%20slang%3D%22en-US%22%3EAlso%2C%20should%20we%20stop%20investing%20in%20Group%20Policy%20and%20instead%20use%20DSC%3F%20What%20are%20the%20intermediate%20plans%20for%20GPO%20as%20a%20technology%3F%20It%20seems%20that%20with%20decentralized%20computing%20GPO%20is%20less%20of%20a%20player.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-67127%22%20slang%3D%22en-US%22%3ERe%3A%20Management%20of%20GPOs%20between%20branches%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-67127%22%20slang%3D%22en-US%22%3EThanks%20Michael%2C%20that%20is%20correct.%20WMI%20filters%20are%20generally%20considered%20last%20resort%20or%20not%20recommended.%20Will%20this%20process%20improve%20in%20the%20future%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-67124%22%20slang%3D%22en-US%22%3ERe%3A%20Management%20of%20GPOs%20between%20branches%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-67124%22%20slang%3D%22en-US%22%3E%3CP%3EI%20assume%20you%20are%20talking%20about%20multiple%20releases%2C%20e.g.%20supporting%20GPOs%20that%20target%20Windows%2010%201511%2C%201607%2C%20and%201703%20simultaneously%3F%20%26nbsp%3BWMI%20filters%20would%20be%20an%20appropriate%20approach%2C%20targeting%20specific%20OS%20builds%20(e.g.%20WMI%20query%20for%20Win32_OperatingSystem).%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

How does Microsoft recommend managing different or conflicting group policy settings across branches? If you setup internal rings, you may have 2-3 branches across your organizatin at any given time. Item-level targeting does not currently allow targeting of specific builds of Windows 10.

6 Replies
best response confirmed by Daniel Ratliff (Occasional Contributor)
Solution

I assume you are talking about multiple releases, e.g. supporting GPOs that target Windows 10 1511, 1607, and 1703 simultaneously?  WMI filters would be an appropriate approach, targeting specific OS builds (e.g. WMI query for Win32_OperatingSystem).

Thanks Michael, that is correct. WMI filters are generally considered last resort or not recommended. Will this process improve in the future?
Also, should we stop investing in Group Policy and instead use DSC? What are the intermediate plans for GPO as a technology? It seems that with decentralized computing GPO is less of a player.

We are trying our best to make policies in new releases "additive" so that they don't affect older releases.  With that, you don't need to make them conditional.  That's not always worked with existing Windows 10 releases, but we do intend to make that better.

 

DSC is datacenter/server-focused and PowerShell-based, which puts it out of the reach of many IT pros.

 

For Windows 10 client devices, we see the move from Group Policy to MDM (e.g. Intune) as the direction.  Lightweight, scalable, and simple.

So far I never run in issues using always the latest admx for the Windows 10 GPOs. If the feature doesn't exist in an older release, the registry value created by the GPO will not harm anything.

But we branded our internal rings in a private WMI class, so we have different GPOs for Internal Insider, Early Adopters and General Availability. So we can activate features in the different rings.

www.000webhost.com