Local Policy vs. Group Policy
For System Center Essentials to correctly interoperate with other components running on Microsoft Windows operating systems, some changes must be made to the Essentials 2007 management server, all managed computers, and any remote computer running an Essentials 2007 component such as a remote console or remote database. How these changes are made is determined by whether you can log on to these computers using either Domain Administrator or Group Policy Administrator credentials.
Group Policy
If you can log on with Domain Administrator or Group Policy Administrator credentials when configuring Essentials 2007, any computers running Essentials 2007 components or agents are configured automatically.
Selecting the Group Policy option directs Essentials 2007 to make the following changes to the domain:
An Active Directory group is created.
The Essentials 2007 Management Server is added to the Active Directory group.
Two Group Policy objects (GPOs) are created.
One GPO is targeted at ‘All Computers’ Active Directory group and contains both the Secure Socket Layer (SSL) and Windows Server Update Services (WSUS) certificates and Windows Firewall settings.
The other GPO is specifically targeted at Essentials 2007 managed computers. This GPO is applied to the Active Directory group created by Essentials 2007, and contains settings related to WSUS, Agentless Exception Monitoring (AEM), and Remote Assistance.
A domain-level object, System Center Essentials Managed Computers (Active Directory computer group), is created.
A domain-level object, SCE Managed Computers Group Policy, is created and added to the Access Control List (ACL) of the System Center Essentials Managed Computers group.
A domain-level object, System Center Essentials All Computers Policy, is created. This object's Group Policy applies to computers in the domain.
In addition, selecting the Group Policy option directs Essentials 2007 to make the changes described in the following table.
On the Management Server | On managed computers |
---|---|
|
Note When a computer is added to the Active Directory group, a task is performed automatically that refreshes the computer's group membership. |
Local Policy
If you cannot log on with Domain Administrator or Group Policy Administrator credentials when configuring Essentials 2007, use local policy. If Windows Firewall or another vendor's firewall product is used on computers in your environment, you must create firewall exceptions on the Essentials 2007 Management Server and on managed computers. Also, you must import two certificates on any computer on which you installed a remote Essentials 2007 console. For more information, see How to Install a Remote Essentials 2007 Console.
Selecting the Local Policy option directs Essentials 2007 to make the changes described in the following table.
On the Management Server | On managed computers |
---|---|
|
|
See Also
Tasks
How to Change Windows Firewall Exceptions
How to Install a Remote Essentials 2007 Console
Concepts
Administration Account
Selecting Database Locations
Storing Updates
Supported Deployment Topologies
System Requirements and Supported Platforms