Group Policy Setup

  • Thread starter Thread starter ITJACKIE
  • Start date Start date
I

ITJACKIE

Dear
Current we use windows 2000 Server , client using W2K Pro / WXP Pro. I
want to using GPO remote install tools / block download exe . bat file from
internet, redirect windows update services to internal windows update
services site. Anyone prodive me a site to setup guide to setup this
solution.

Thanks
Jackie Wong
 
It is easy enough to use an internal server to authorize and issue Windows
Updates using Software Update Services or the newer Windows Server Update
Services as shown in the links below and you can then use Group Policy to
configure domain clients to automatically download and apply updates.

http://www.microsoft.com/windowsserversystem/updateservices/default.mspx
http://www.microsoft.com/windowsserversystem/updateservices/evaluation/previous/default.mspx
http://www.bris.ac.uk/is/services/computers/operatingsystems/sus/configuring.html

However selectively blocking downloads is much more difficult and that can
not be done via Group Policy. If all of you computers are using only
Internet Explorer you can use Group Policy to manage web content zones to
block internet downloads or restrict then from only trusted sites that you
approve. Otherwise you would need something like ISA 2004 [
firewall/internet proxy gateway] which has very powerful application
filtering which can be used to create rules and filters that actually
examine the http headers in all http traffic and block specific file
extensions and/or by other http filter criteria. If interested in ISA 2004
you can try it for free for 180 days I believe and the links below explains
more about http filtering and ISA 2004 capabilities.

http://www.microsoft.com/technet/prodtechnol/isa/2004/plan/httpfiltering.mspx
http://www.microsoft.com/isaserver/evaluation/whatsnew.mspx
 
Back
Top