EZ GPO. Power Management Tool for Network Administrators.



Similar documents
TECHNICAL DOCUMENTATION SPECOPS DEPLOY / APP 4.7 DOCUMENTATION

ms-help://ms.technet.2005mar.1033/security/tnoffline/security/smbiz/winxp/fwgrppol...

ACTIVE DIRECTORY DEPLOYMENT

Test Note Phone Manager Deployment Windows Group Policy Sever 2003 and XP SPII Clients

Installation Guide - Client. Rev 1.5.0

Administration Guide. . All right reserved. For more information about Specops Deploy and other Specops products, visit

HELP DOCUMENTATION E-SSOM DEPLOYMENT GUIDE

HOW TO SILENTLY INSTALL CLOUD LINK REMOTELY WITHOUT SUPERVISION

Promap V4 ActiveX MSI File

MailStore Outlook Add-in Deployment

DigitalPersona Pro Server for Active Directory v4.x Quick Start Installation Guide

Installation Guide. . All right reserved. For more information about Specops Inventory and other Specops products, visit

How to monitor AD security with MOM

Distributing SMS v2.0

Technical Reference: Deploying the SofTrack MSI Installer

4cast Client Specification and Installation

Deploying the DisplayLink Software using the MSI files

Sharpdesk V3.5. Push Installation Guide for system administrator Version

Tool Tip. SyAM Management Utilities and Non-Admin Domain Users

Chapter. Managing Group Policy MICROSOFT EXAM OBJECTIVES COVERED IN THIS CHAPTER:

DisplayLink Corporate Install Guide

Create, Link, or Edit a GPO with Active Directory Users and Computers

Specops Command. Installation Guide

DeviceLock Management via Group Policy

Using Group Policy to Manage and Enforce ACL on VNX for File P/N REV A01 February 2011

Administration Guide ActivClient for Windows 6.2

ContentWatch Auto Deployment Tool

VERITAS Backup Exec 9.1 for Windows Servers Quick Installation Guide

Aspera Connect User Guide

MS-50255: Managing, Maintaining, and Securing Your Networks Through Group Policy. Course Objectives. Required Exam(s) Price.

Windows XP Service Pack 2 Windows Firewall Group Policy Setup for Executive Software Products

Module 8: Implementing Group Policy

DeviceLock Management via Group Policy

Deployment of Keepit for Windows

White Paper. Deployment of ActiveX Controls via Microsoft Windows Active Directory. Fabasoft Folio 2015 Update Rollup 2

Active Directory Software Deployment

Server Manager Performance Monitor. Server Manager Diagnostics Page. . Information. . Audit Success. . Audit Failure

Server & Workstation Installation of Client Profiles for Windows

Installation Manual (MSI Version)

HP Universal Print Driver Series for Windows Active Directory Administrator Template White Paper

Privilege Guard 3.0 Administration Guide

Contents 1. Introduction 2. Security Considerations 3. Installation 4. Configuration 5. Uninstallation 6. Automated Bulk Enrollment 7.

NetWrix Password Manager. Quick Start Guide

Both MS Windows 2000 Server and MS System Management Server (SMS) support this type of network installation.

Using Microsoft Active Directory 1 Group Policy 2 with Diskeeper

Lesson Plans Microsoft s Managing and Maintaining a Microsoft Windows Server 2003 Environment

UNCLASSIFIED DISABLING USB STORAGE DEVICES THROUGH GROUP POLICY

DriveLock Quick Start Guide

User Document. Adobe Acrobat 7.0 for Microsoft Windows Group Policy Objects and Active Directory

Password Manager Windows Desktop Client

Understanding Group Policy Basics to Manage Windows Vista Systems

Pcounter Web Report 3.x Installation Guide - v Pcounter Web Report Installation Guide Version 3.4

Windows 2008 Server DIRECTIVAS DE GRUPO. Administración SSII

SELF SERVICE RESET PASSWORD MANAGEMENT GPO DISTRIBUTION GUIDE

Outpost Network Security

Citrix Systems, Inc.

safend a w a v e s y s t e m s c o m p a n y

Egress Switch Client Deployment Guide V4.x

Universal Management Service 2015

Deploying Software with Group Policy Whitepaper

STATISTICA VERSION 9 STATISTICA ENTERPRISE INSTALLATION INSTRUCTIONS FOR USE WITH TERMINAL SERVER

XyLoc Security Server w/ AD Integration (XSS-AD 5.x.x) Administrator's Guide

Creating and Issuing the Workstation Authentication Certificate Template on the Certification Authority

ILTA HAND 6B. Upgrading and Deploying. Windows Server In the Legal Environment

ILTA HANDS ON Securing Windows 7

Installation Guide. . All right reserved. For more information about Specops Deploy and other Specops products, visit

Fundamentals, Security, and the Managed Desktop

Understanding Task Scheduler FIGURE Task Scheduler. The error reporting screen.

How To Configure CU*BASE Encryption

MS 50255B: Managing Windows Environments with Group Policy (4 Days)

Adobe Acrobat 9 Deployment on Microsoft Windows Group Policy and the Active Directory service

Pcounter for Windows

Using Group Policies to Install AutoCAD. CMMU 5405 Nate Bartley 9/22/2005

Installing Client GPO Software

Installation Notes for Outpost Network Security (ONS) version 3.2

Windows Clients and GoPrint Print Queues

NetIQ Advanced Authentication Framework. FIDO U2F Authentication Provider Installation Guide. Version 5.1.0

Topaz Installation Sheet

Introduction... 1 Windows Tuning... 2 Compatibility... 2 Windows User Profiles Remote User Configuration Data Execution Prevention...

PowerMapper/SortSite Desktop Deployment Guide v Introduction

Installing OneStop Reporting Products

Using Microsoft Active Directory 1 Group Policy 2 with Diskeeper

e-business Suite Server Install Guide

PLANNING AND DESIGNING GROUP POLICY, PART 1

This document details the procedure for installing Layer8 software agents and reporting dashboards.

EMC Celerra Network Server

Managing Windows Environments with Group Policy

Automating client deployment

NETWRIX ACCOUNT LOCKOUT EXAMINER

XMap 7 Administration Guide. Last updated on 12/13/2009

SOFTWARE INSTALLATION INSTRUCTIONS CLIENT/SERVER EDITION AND WEB COMPONENT VERSION 10

Group Policy 21/05/2013

For Splunk Universal Forwarder and Splunk Cloud

Installation Guide. . All right reserved. For more information about Specops Deploy and other Specops products, visit

Understand Troubleshooting Methodology

DEPARTMENT OF JUSTICE INFORMATION TECHNOLOGY STANDARD

NetIQ Advanced Authentication Framework - Administrative Tools. Installation Guide. Version 5.1.0

Transcription:

EZ GPO Power Management Tool for Network Administrators.

Table of Contents Introduction...3 Installation...4 Configuration...6 Base Options...7 Options Properties Dialogue...8 Suggested Configuration Settings...9 Maintenance...10 Errata...10 Simple Scheme (AC & DC )...10 Troubleshooting...11 Configurations A graphical representation Standard Configuration...13 Security Override...17 Machine Override...21

Introduction EZ GPO is an open source set of tools developed by Terra Novum, under a BSD style license for network administrators to manage computer and user power management settings within computing environments. Originally authored to address power management policy and permission issues with Windows 2000 and Windows XP machines, the tool works natively with Active Directory via Group Policy Objects as well as with Novell NDS/Zenwork clients via registry management systems. The approach taken was to create a process by which users who were not local Administrators or Power Users, the ability to modify the required registry string settings needed for power management. As the native GPO interface for ADM meta language is limited in the Group Policies interface, the method utilized accesses the only areas of the registry that can be managed via process which are Single Value Strings and DWORD (integer) values, both of which are accessed through the GPO tree. EZ GPO is introduced to target environment in two stages. The first stage is the installation, configuration and activation of the server side GPO via ADM (Administrative Template), with the second being the client/workstation application installation via MSI (Microsoft Installer). As with most.adm files, EZ_GPO.adm is a template of set parameters defined by an administrator to configure Group Policy Objects for registry settings. The client/workstation MSI places two executable binary files onto the machine that is to be managed. They are 'EZ_GPO_Tool.exe', which will run as the user, to specify to the system, which power management settings are to be applied for that users account at login. The second executable is named PMService.exe', which is a service application that is run by the machine account, as itself, which will specify, to the machine, which power management settings are to be applied to that machine when no user is logged on. These two client side applications will work in conjunction with the GPO set by the ADM template. Failing the propagation of the GPO from an AD Default Policy, the applications will utilize registry entries set in the HKLM and HKCU software registry branches -allowing administrators without AD or administrators who manage Novell NDS/Zenwork systems the ability to directly manipulate registry settings for required custom values. As the registry entries are Single Value Strings and DWORD (integer) values, which follow Microsoft core API procedures, the settings are available immediately. Since GPOs are applied prior to the actual logon prompt, there is no concern for a binary race condition where the binary would execute prior to the policy set.

Installation 1) ADM Template Unzip the EZ_GPO.zip file. Browse to the Server GPO directory and locate the ADM file named EZ_GPO.adm, you may extract this file to your desktop. {{Note to complete this procedure you must be a member of the Domain Administrators group}} No matter which interface method you use for Group Policy administration, the installation procedure is the same: Non-GPMC install steps: Open Active Directory Users and Computer via the Administrative tools start menu or type: dsa.msc at the run prompt. Right click on the container that holds the domain you wish to manage, select properties and move to the Group Policy tab. Highlight 'Default Domain Policy' and click edit. (continue below) GPMC installation: Open the GPMC console via Administrative tools start menu or type: gpmc.msc at the run prompt. Right click the 'Default Domain Policy' GPO, select Edit. A new MMC will open at the root level showing both Computer Configuration and User Configuration console trees. Expand either of those trees right until you see 'Administrative Templates', right click on Administrative Templates and select 'Add/Remove Templates'. Click Add, browse to your desktop or whichever location you stored the EZ_GPO.adm file, select open, and then click close. At this point within both the Administrative Templates you will see ' EZ GPO by the Environmental Protection Agency', which will contain three new group polices for you to manage. Please be advised on Server2003, the snapin will no longer copy the ADM template to the general store: %SystemRoot%System32 directory. If desired, please copy it there prior to loading the template. 2) Client Binary Executables Installation of the binary client, EZ GPO Installer.msi, is pretty straightforward. It is suggested to install it via assignment computer based software installation policy. {{Having first ensured the msi is available from a readable UNC path.}}

Browse to the Software Settings tree under Computer Configuration. Right click, select new, select package. Select the location of the msi, click open, click assigned, click ok. It is also suggested if installed via the Software Settings assignment, that the client machines are rebooted a few times to give the software a chance to fully install. This is due to Fast Login Optimization and Asynchronous policy refresh. For more information please see: http://support.microsoft.com/default.aspx?scid=kb;en-us;305293&product=winxp and http://msdn.microsoft.com/library/default.asp?url=/library/en-us/policy/policy/logon_optimization.asp

Configuration The installed ADM under your selected Group Policy will show you the following options. (fig 1a) Base Options, Options, AC Profile Scheme and the DC Profile Scheme (fig 1a)

Base Options Suggestion: Enabled In order to activate the GPO the Base Options configuration must be set to Enabled. The default values will work for most systems. The other options are: Control Settings Scheme Major/Minor Version Informs the client applications if the GPO is valid at this location, or if they should look elsewhere for their configuration. Which configuration scheme you would like to configure. The default setting of Simple holds values for six predetermined settings. Options for upgrading between versions, both Minor (revision) and Major (version).

Options Properties Dialogue Suggestion: Enabled Only applies to the machine policy. This option allows an IT admin to have the user's policy be derived from the Machine's policy. In other words, this allows an IT admin to apply a policy on a per machine basis and as users move from machine to machine, their power policies match that of the machine and they do not bring with them a power policy from another machine. Machine Override The option does not require the User Configuration settings to be set, but does require the Computer Configuration to be set and that the workstation to be managed. To verify this setting has been applied, run: powercfg.exe /q at the command prompt. Do not open the Contol Panel Power Options Applet. This will cause the setings to be overwritten. For older Non-S3 capable machines. Force Standby This is a legacy setting and does not have to be enabled for most systems. If it is enabled, it most likely will do no harm. Found only under Admin User Policy. Allows the user binary

Security Bypass Security Override application to bypass OS restrictions that would prevent registry modifications. This option must be set in Computer Configuration, and must be applied to all computer accounts of the workstations to be managed. To verify this setting has been applied, run: powercfg.exe /q at the command prompt. Force Update Do not open the Contol Panel Power Options Applet. This will cause the setings to be overwritten. Forces the system to update the power management settings even if the settings match. Otherwise if no changes need to be made, the application will wait in a loop or exit. Suggested Configuration Settings Depending on your requirements and needs there are three general methods that ensure for a smooth operation of EZ GPO within your environment. : For a graphical representation of these configurations, please see Appendix pages 11-24 Standard configuration: Security Override: Machine Override: You have settings the settings in both the User Configuration and the Computer Configuration GPOs, all of the User and Machine Accounts are managed. The Machine Override option is not enabled. You have set the settings are set in both the User Configuration and the Computer Configuration GPO, all of the User and Machine Accounts are managed The Machine Override option is not enabled. Security Override is enabled. You have set the settings are set in only for the Computer Configuration GPO, all of the Machine Accounts are managed. The Machine Override is enabled. User Configuration is not enabled.

Maintenance Upgrading between versions To upgrade first remove the ADM file from the list of available adm templates in the user portion of the GPO and then apply the changes. Then add in the new updated ADM file It should pick up your old settings but still pick up the new version numbers. Update the MSI installer according to you normal procedures. Errata Simple Scheme (AC & DC ) Where applicable, there are options in both the AC and DC panels. AC controls when the machine is plugged into a wall or other AC power source. DC controls the behavior of the machine when the portable is being powered off of it's internal battery source. User Monitor Timeout - Time until monitor off occurs in minutes User System Standby Timeout - Time until System Standby occurs in minutes Machine Hibernation Timeout - Time until hibernation occurs in minutes (NB: should be 0 or at least one minute larger than system standby and requires that hibernation be enabled)the simple scheme is currently the only scheme implemented in EZ_GPO. It contains six settings, each of which affects either the AC (plugged in settings) or the DC (when on battery settings), and are expressed in minutes. To set any setting to never, input a value of 0 (zero). Please note that the tool is limited in what clients it will set system standby for by default. The limitation is revolves around the presence of a new version of power management named ACPI (more specifically the support for the S3 sleep state). Most older hardware had Advanced Power Management v2 (APM2) and recent Pentium 3 and early Pentium 4 machine had a flavor of ACPI that was not fully implemented. Most Pentium 4s and higher machines these days have full hardware support for ACPI and the S3 sleep state. This behavior can be overridden by employing the ForceStandby option in the above options. This can be useful for machines that are AMD based as they support a form of S3 but do not always show it consistently. There is no reason why you can not set both AC and DC power settings in one policy. If you do, desktops will completely ignore the DC settings since the machine will never be placed on a DC power source. For example, the settings get set but the opportunity never arises for the machine to use them, in essence making them inert. This allows you to manage laptops and desktops with the same policy. Please note that when the laptops are plugged in, they will have the same PM idle times as desktops. To use the hibernation settings, hibernation must first be enabled to allow this setting to take effect. There is unfortunately no way that MS provides, in the form of a (published) API call, to make this happen. If they did, it would have been made an option. The only way for admins to enable this is to do so before deployment, via the source image.

Troubleshooting Verification of Software Installation Verification of GPO application to the User or Machine. I have installed the GPO tool, but I am not seeing any results when I check the power settings via the control panel applet on managed machines. Check to see if the software is installed properly. First check the Add/Remove software for the EZ GPO tool entry. If that exists, verify the software was properly installed by AD by checking for the presence of a file called PMService.exe in the \Windows\System32 directory. If that file is not there, you need to roll back the installation and install the software from the computer policy and not the user policy in AD or chose a different installation method. Verify the GPO was properly applied by checking the registry on the target computer. Under either HKLM or HKCU (which one is dependant on the configuration chosen above), look for entries under \SOFTWARE\Policies\TerraNovum\EZ_GPO Whenever the Control Panel Power Options applet is utilized the system will revert to the last cached power configuration and will makes those settings authoritative despite any updated configuration. This will occur even if you just open the applet and cancel it. This bug is present in Windows XP and will occur regardless of which tool was used to make the power settings. To check the power settings, from the command line enter: powercfg.exe /q for the results. Reboot the system and then check to see if the your defined power settings are visible via powercfg.exe. I have installed the GPO tool, but the managed machines do not seem to be sleeping. You may not be using the Standard Configuration as required for your needs. Check that you have configured settings under Computer Configuration and not the User Configuration. What may be occurring is that the settings are set for the machine only and not for the users,

I have installed the GPO tool, but the managed machines do no seem to be sleeping. I have installed the GPO tool, but the managed machines do not seem to be sleeping. the result would be that the machine itself will sleep but those settings will be overridden by any non defined user settings. : Check the software on the managed machine to see if there are any screen savers or other idle cycle applications running. Any process that requires more than 20% of the CPU time, tells the machine that it is not in an active low power state. Check the Device Manager tab from the System menu. The system will indicate a device error with an exclamation point (!) or a question mark (?) next to the device in an error state. Be advised that generic drivers that are on your system may not be written in a manner to accept or yield to requested sleep or suspend requests from the system. Ensure that all the devices on your system have up to date and accurate drivers for their use.

Configurations A graphical representation Standard Configuration Standard Configuration: Computer Configuration Base Option Properties Standard Configuration: Computer Configuration Options Properties

Standard Configuration: Computer Configuration AC Profile Standard Configuration: Computer Configuration DC Profile

Standard Configuration: User Configuration Base Options Standard Configuration: User Configuration Options

Standard Configuration: User Configuration AC Profile Standard Configuration: User Configuration DC Profile

Security Override Security Override: Computer Configuration Base Options Security Override: Computer Configuration Options

Security Override: Computer Configuration AC Profile Security Override: Computer Configuration DC Profile

Security Override: User Configuration Base Options Security Override: User Configuration Options

Security Override: User Configuration AC Profile Security Override: User Configuration DC Profile

Machine Override Machine Override: Computer Configuration Base Options Machine Override: Computer Configuration - Options

Machine Override: Computer Configuration AC Profile Machine Override: Computer Configuration DC Profile

Machine Override: User Configuration Base Options Machine Override: User Configuration Options

Machine Override: User Configuration AC Profile Machine Override: User Configuration DC Profile