Which of the following is a Microsoft Active Directory feature that provides centralized management of user and computer settings?

Group Policy is a hierarchical infrastructure that allows a network administrator in charge of Microsoft's Active Directory to implement specific configurations for users and computers. Group Policy is primarily a security tool, and can be used to apply security settings to users and computers. Group Policy allows administrators to define security policies for users and for computers. These policies, which are collectively referred to as Group Policy Objects (GPOs), are based on a collection of individual Group Policy settings. Group Policy objects are administered from a central interface called the Group Policy Management Console. Group Policy can also be managed with command line interface tools such as gpresult and gpupdate.

The Group Policy hierarchy

Group Policy objects are applied in a hierarchical manner, and often multiple Group Policy objects are combined together to form the effective policy. Local Group Policy objects are applied first, followed by site level, domain level, and organizational unit level Group Policy objects.

Group Policy extensibility

The native collection of Group Policy settings pertain exclusively to the Windows operating system. An administrator might for instance use these native Group Policy settings to enforce a minimum password length, hide the Windows Control Panel from users, or force the installation of security patches. However, Group Policy is designed to be extensible through the use of administrative templates. These administrative templates allow various applications to be configured through Group Policy settings. One of the best known examples of this is the collection of administrative templates for Microsoft Office.

Administrative templates consist of two components. An ADMX file is the XML file containing all of the Group Policy settings that are associated with the template. A corresponding ADML file acts as a language file that allows the Group Policy settings to be displayed in the administrator’s language of choice. 

Local vs. centralized Group Policy

Group Policy objects can be applied locally to a Windows computer through its own operating system, or Group Policy objects can be applied through Active Directory. Local group policies allow security settings to be applied to either standalone computers or computers managed by a domain controller, but these policy settings cannot be centrally managed. Conversely, Active Directory based Group Policy objects can be centrally managed, but they are only implemented if a user is logging in from a computer joined to the domain.

Many organizations use a combination of local and Active Directory Group Policy objects. The local policy settings provide security when the user is not logged into a domain, while Active Directory Group Policy objects apply once the user has logged in.

This was last updated in April 2019

Continue Reading About Group Policy

  • Microsoft Group Policy tutorial
  • Desktop restrictions with Group Policy Objects
  • Top five tips for optimizing Active Directory Group Policy performance
  • Group Policy resources from Microsoft
  • Managing Group Policy with VBScript

Dig Deeper on IT operations and infrastructure management

  • Which of the following is a Microsoft Active Directory feature that provides centralized management of user and computer settings?
    Create file server screens and quotas in FSRM

    Which of the following is a Microsoft Active Directory feature that provides centralized management of user and computer settings?

    By: Damon Garn

  • Which of the following is a Microsoft Active Directory feature that provides centralized management of user and computer settings?
    How to use the Office cloud policy service with Microsoft 365

    Which of the following is a Microsoft Active Directory feature that provides centralized management of user and computer settings?

    By: Peter van der Woude

  • Which of the following is a Microsoft Active Directory feature that provides centralized management of user and computer settings?
    Group Policy Object (GPO)

    Which of the following is a Microsoft Active Directory feature that provides centralized management of user and computer settings?

    By: Linda Rosencrance

  • Which of the following is a Microsoft Active Directory feature that provides centralized management of user and computer settings?
    How can you improve Google Chrome management?

    Which of the following is a Microsoft Active Directory feature that provides centralized management of user and computer settings?

    By: Brien Posey

How is the SAML used quizlet?

How is the Security Assertion Markup Language (SAML) used? It allows secure web domains to exchange user authentication and authorization data. It is an authenticator in IEEE 802.1x. It is no longer used because it has been replaced by LDAP.

Which of these is a set of permissions that are attached to an object?

An access control list (ACL), with respect to a computer file system, is a list of permissions attached to an object.

What is the primary advantage of using group policies in a domain environment?

Benefits of Group Policy Objects More efficient management -- GPOs already in place apply a standardized environment to all new users and computers that join an organization's domain, saving time on setup. Ease of administration -- system administrators can deploy software, patches and other updates via GPO.

What is the least restrictive access control model?

Discretionary access control is the least restrictive type of access control. Under this system, individuals are granted complete control over any objects they own and any programs associated with such objects.