Wednesday, November 21, 2012

Converting UTC to Local time using VBScript

Hi all.

I've recently searched for a possibility to convert UTC times to local times using VBScript. Every solution I found dealt with string parsing the UTC time value by splitting it into pieces and then adding the timezone bias, retrieved from the registry. That's a crude method, and it is NOT neccessary...

The SWbemDateTime object provides properties and methods to do this conversion directly:

Function ConvertUTCToLocal( varTime )
    Dim myObj, MyDate
    MyDate = CDate( varTime )
    Set myObj = CreateObject( "WbemScripting.SWbemDateTime" )
    myObj.Year = Year( MyDate )
    myObj.Month = Month( MyDate )
    myObj.Day = Day( MyDate )
    myObj.Hours = Hour( MyDate )
    myObj.Minutes = Minute( myDate )
    myObj.Seconds = Second( myDate )
    ConvertUTCToLocal = myObj.GetVarDate( True )
End Function
 

As long as you do not set the .UTC property, the properties you set are UTC time, and GetVarDate returns the local time. And, of course, you can do this the other way - using .SetVarDate and then retrieving the various properties of the DateTime object. In this scenario, of course, you have to retrieve the .UTC property and add it accordingly...

The SWbemDateTimeObject: http://msdn.microsoft.com/en-us/library/windows/desktop/aa393687%28v=vs.85%29.aspx

regards, Martin

Tuesday, November 13, 2012

GUIDs GUIDs GUIDs... (2)

Hallo ins Netz ;-)

Hier noch mal die GUIDs, die für GPOs relevant sind - jetzt aber beide Listen: Sowohl die CSEs (Stand Windows 2012) als auch die Snapins (auch Stand Windows 2012). Da fehlten im letzten Post noch einige...

GUID Name DLL
{35378EAC-683F-11D2-A89A-00C04FBBCFA2} Registry - Registrierungsrichtlinienverarbeitung userenv
{0ACDD40C-75AC-47AB-BAA0-BF6DE7E7FE63} Wireless Group Policy - Drahtlosnetzwerke gptext
{0E28E245-9368-4853-AD84-6DA3BA35BB75} Group Policy Environment - Umgebung gpprefcl
{17D89FEC-5C44-4972-B12D-241CAEF74509} Group Policy Local Users and Groups - Lokale Benutzer und Gruppen gpprefcl
{1A6364EB-776B-4120-ADE1-B63A406A76B5} Group Policy Device Settings - Geräte gpprefcl
{25537BA6-77A8-11D2-9B6C-0000F8080861} Folder Redirection - Ordnerumleitung fdeploy
{3610EDA5-77EF-11D2-8DC5-00C04FA31A66} Microsoft Disk Quota - Datenträgerkontingente dskquota
{3A0DBA37-F8B2-4356-83DE-3E90BD5C261F} Group Policy Network Options - Netzwerkoptionen gpprefcl
{426031C0-0B47-4852-B0CA-AC3D37BFCB39} QoS Packet Scheduler - Netzwerklastenausgleich gptext
{42B5FAAE-6536-11D2-AE5A-0000F87571E3} Scripts - Skriptrichtlinienverarbeitung gptext
{4BCD6CDE-777B-48B6-9804-43568E23545D} Remote Desktop USB Redirection - Remote Desktop USB-Umleitung TsUsbRedirectionGroupPolicyExtension
{4CFB60C1-FAA6-47F1-89AA-0B18730C9FD3} Process Group Policy For Zone Map - Internet Explorer Zonenzuordnung iedkcs32
{5794DAFD-BE60-433F-88A2-1A31939AC01F} Group Policy Drive Maps - Laufwerke gpprefcl
{6232C319-91AC-4931-9385-E70C2B099F0E} Group Policy Folders - Ordner gpprefcl
{6A4C88C6-C502-4F74-8F60-2CB23EDC24E2} Group Policy Network Shares - Netzwerkfreigaben gpprefcl
{7150F9BF-48AD-4DA4-A49C-29EF4A8369BA} Group Policy Files - Dateien gpprefcl
{728EE579-943C-4519-9EF7-AB56765798ED} Group Policy Data Sources - Datenquellen gpprefcl
{74EE6C03-5363-4554-B161-627540339CAB} Group Policy Ini Files - INI-Dateien gpprefcl
{7933F41E-56F8-41D6-A31C-4148A711EE93} Windows Search Group Policy - Windows Suche srchadmin
{7B849a69-220F-451E-B3FE-2CB811AF94AE} Internet Explorer User Accelerators - Internet Explorer User Accelerators iedkcs32
{827D319E-6EAC-11D2-A4EA-00C04F79F83A} Security - Sicherheitsrichtlinien scecli
{8A28E2C5-8D06-49A4-A08C-632DAA493E17} Deployed Printer Connections - Bereitgestellte Drucker gpprnext
{91FBB303-0CD5-4055-BF42-E512A681B325} Group Policy Services - Dienste gpprefcl
{A2E30F80-D7DE-11D2-BBDE-00C04F86AE3B} Internet Explorer Branding - Internet Explorer Wartung iedkcs32
{A3F3E39B-5D83-4940-B954-28315B82F0A8} Group Policy Folder Options - Ordneroptionen gpprefcl
{AADCED64-746C-4633-A97C-D61349046527} Group Policy Scheduled Tasks - Geplante Aufgaben gpprefcl
{B087BE9D-ED37-454F-AF9C-04291E351182} Group Policy Registry - Registry gpprefcl
{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A} EFS recovery - Verschlüsselndes Dateisystem scecli
{B587E2B1-4D59-4E7E-AED9-22B9DF11D053} 802.3 Group Policy - Richtlinien für verkabeltes Netzwerk (802.3) dot3gpclnt
{BC75B1ED-5833-4858-9BB8-CBF0B166DF9D} Group Policy Printers - Drucker gpprefcl
{C418DD9D-0D14-4EFB-8FBF-CFE535C8FAC7} Group Policy Shortcuts - Verknüpfungen gpprefcl
{C631DF4C-088F-4156-B058-4375F0853CD8} Microsoft Offline Files - Offline Dateien cscobj
{C6DC5466-785A-11D2-84D0-00C04FB169F7} Software Installation - Zugewiesene Anwendungen appmgmts
{CDEAFC3D-948D-49DD-AB12-E578BA4AF7AA} TCPIP - IP-Sicherheitsrichtlinien gptext
{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} Internet Explorer Machine Accelerators - Internet Explorer Machine Accelerators iedkcs32
{E437BC1C-AA7D-11D2-A382-00C04F991E27} IP Security - Verbindungssicherheitsregeln polstore
{E47248BA-94CC-49C4-BBB5-9EB7F05183D0} Group Policy Internet Settings - Interneteinstellungen gpprefcl
{E4F48E54-F38D-4884-BFB9-D4D2E5729C18} Group Policy Start Menu Settings - Startmenü gpprefcl
{E5094040-C46C-4115-B030-04FB2E545B00} Group Policy Regional Options - Regionale Einstellungen gpprefcl
{E62688F0-25FD-4C90-BFF5-F508B9D2E31F} Group Policy Power Options - Energieoptionen gpprefcl
{F3CCC681-B74C-4060-9F26-CD84525DCA2A} Audit Policy Configuration - Erweiterte Überwachungskonfiguration auditcse
{F9C77450-3A41-477E-9310-9ACD617BD9E3} Group Policy Applications - Anwendungen gpprefcl
{FB2CA36D-0B40-4307-821B-A13B252DE56C} Enterprise QoS - Richtlinienbasierter QoS gptext
{FBF687E6-F063-4D9F-9F4F-FD9A26ACDD5F} Connectivity Platform - Connectivity Platform gptext


GUID Name
{011BE22D-E453-11D1-945A-00C04FB984F9} SCA - Sicherheitskonfiguration und -analyse
{03F1F940-A0F2-11D0-BB77-00AA00A1EAB7} SMTPProtocol - SMTP-Protokoll
{06993B16-A5C7-47EB-B61C-B1CB7EE600AC} WiredNetworkPolicy - Richtlinien für verkabelte Netzwerke (IEEE 802.3)
{0DA274B5-EB93-47A7-AAFB-65BA532D3FE6} GPO_Applications - Einstellungserweiterung "Anwendungen"
{0E752416-F29E-4195-A9DD-7F0D4D5A9D71} WindowsFirewall_GP - Windows-Firewall mit erweiterter Sicherheit
{0F3621F1-23C6-11D1-AD97-00AA00B88E5A} SysProp - Systemeigenschaften
{0F3F3735-573D-9804-99E4-AB2A69BA5FD4} AdvancedAuditPolicySnapin - Erweiterte Überwachungsrichtlinienkonfiguration
{0F6B957D-509E-11D1-A7CC-0000F87571E3} ADMComputers_1 - Administrative Vorlagen (XP/2003)
{0F6B957E-509E-11D1-A7CC-0000F87571E3} ADMUsers_1 - Administrative Vorlagen (XP/2003)
{127537A8-C1ED-40BC-9AE5-C5891DF6B2D4} GPO_UserControl - Verwendung der Systemsteuerungseinstellungen zulassen
{1612B55C-243C-48DD-A449-FFC097B19776} GPO_DataSources - Einstellungserweiterung "Datenquellen"
{17C6249E-BA57-4F69-AE93-4FB3D25CD9D7} GPO_CompControl - Systemsteuerungseinstellungen
{180F39F3-CF17-4C68-8410-94B71452A22D} DeployedPrinterConnections - Bereitgestellte Drucker
{18BA7139-D98B-43c2-94DA-2604E34E175D} Net_Framework - .Net Framework-Konfiguration
{18EA3F92-D6AA-41D9-A205-2023400C8FBB} ServerManager - Server-Manager
{1AA7F839-C7F5-11D0-A376-00C04FC9DA04} RRA - Routing und RAS
{1AA7F83C-C7F5-11D0-A376-00C04FC9DA04} AppleTalkRouting - AppleTalk-Routing
{1B767E9A-7BE4-4D35-85C1-2E174A7BA951} GPO_Devices - Einstellungserweiterung "Geräte"
{1BC972D6-555C-4FF7-BE2C-C584021A0A6A} SoftwareInstallationUsers_2 - Softwareinstallation - RSoP
{1C5DACFA-16BA-11D2-81D0-0000F87A7AA3} ADSI - ADSI-Bearbeitung
{1F5EEC01-1214-4D94-80C5-4BDCD2014DDD} AuthMan - Autorisierungs-Manager
{23DC5869-BD9F-46fd-AADD-1F869BA64FC3} WirelessMon - Drahtlosmonitor
{243E20B0-48ED-11D2-97DA-00A024D77700} RemStore - Wechselmedien
{2D4156A2-897A-11DB-BA21-001185AD2B89} NetworkListManagerSnapin - Netzwerklisten-Manager-Snapin
{2DA6AA7F-8C88-4194-A558-0D36E7FD3E64} WirelessNetworkPolicy - Richtlinien für Drahtlosnetzwerke (IEEE 802.11)
{2E19B602-48EB-11d2-83CA-00104BCA42CF} IASLogging - IAS-Protokollierung
{2EA1A81B-48E5-45E9-8BB7-A6E3AC170006} GPO_Drives - Einstellungserweiterung "Laufwerkzuordnungen"
{3060E8CE-7020-11D2-842D-00C04FA372D4} RIS - Remoteinstallationsdienste
{317cdc35-c09e-486f-ab09-90dd2e3fdd7d} StorageManagerForSANSSnapIn - Speicher-Manager für SANs
{317CDC37-C09E-486F-AB09-90DD2E3FDD7D} StorageManagerForSANSSnapInExtension - Speicher-Manager für SANs-Erweiterung
{34AB8E82-C27E-11D1-A6C0-00C04FB94F17} PublicKey - Richtlinien Öffentlicher Schlüssel
{35141B6B-498A-4CC7-AD59-CEF93D89B2CE} GPO_Environment - Einstellungserweiterung "Umgebung"
{394C052E-B830-11D0-9A86-00C04FD8DBF7} EventViewer_1 - Ereignisanzeige
{3BAE7E51-E3F4-41D0-853D-9BB9FD47605F} GPO_Files - Einstellungserweiterung "Dateien"
{3BFAE46A-7F3A-467B-8CEA-6AA34DC71F53} GPO_FolderOptions - Einstellungserweiterung "Ordneroptionen"
{3CB6973D-3E6F-11D0-95DB-00A024D77700} RSM - Wechselmedienverwaltung
{3D5D035E-7721-4B83-A645-6C07A3D403B7} RemoteDesktop - Remotedesktops
{3EC4E9D3-714D-471F-88DC-4DD4471AAB47} GPO_Folders - Einstellungserweiterung "Ordner"
{3F276EB4-70EE-11D1-8A0F-00C04FB93753} CertAuthPolSet - Zertifizierungsstellen-Richtlinieneinstellungen
{40B6664F-4972-11D1-A7CA-0000F87571E3} ScriptsMachine_1 - Skripts (Start/Herunterfahren)
{40B66650-4972-11D1-A7CA-0000F87571E3} ScriptsUser_1 - Skripts (Anmelden/Abmelden)- GPEdit
{40B66660-4972-11d1-A7CA-0000F87571E3} ScriptsMachine_2 - Skripts (Start/Herunterfahren) - RSoP
{40B66661-4972-11d1-A7CA-0000F87571E3} ScriptsUser_2 - Skripts (Anmelden/Abmelden) - RSoP
{43668E21-2636-11D1-A1CE-0080C88593A5} DiskDefrag - Defragmentierung
{45AC8C63-23E2-11D1-A696-00C04FD58BC3} SysInfo - Systeminformationen
{45B01F1C-5AC2-458c-9457-42A81B34A26D} GPO_ViewExtensionPro - Registerkarte "Einstellungen"
{516FC620-5D34-4B08-8165-6A06B623EDEB} GPO_IniFiles - Einstellungserweiterung "INI-Dateien"
{53D6AB1D-2488-11D1-A28C-00C04FB94F17} Certs - Zertifikate
{57C596D0-9370-40C0-BA0D-AB491B63255D} IpSecMonitor - IP-Sicherheitsmonitor
{58221C65-EA27-11CF-ADCF-00AA00A80033} SharedFolders - Freigegebene Ordner
{58221C66-EA27-11CF-ADCF-00AA00A80033} Services - Dienste
{58221C67-EA27-11CF-ADCF-00AA00A80033} ComputerManagement - Computerverwaltung
{58221C69-EA27-11CF-ADCF-00AA00A80033} SharedFolders_Ext - Erweiterung für freigegebene Ordner
{5880CD5C-8EC0-11d1-9570-0060B0576642} RemoteAccess - RAS
{5ADF5BF6-E452-11D1-945A-00C04FB984F9} SecurityTemplates - Sicherheitsvorlagen
{5C659257-E236-11D2-8899-00104B2AFB46} WMI - WMI-Steuerung
{5C935941-A954-4F7C-B507-885941ECE5C4} GPO_Internet - Einstellungserweiterung "Interneteinstellungen"
{5D6179C8-17EC-11D1-9AA9-00C04FD8FE93} LocalUsersGroups - Lokale Benutzer und Gruppen
{62C1845D-C4A6-4ACB-BBB0-C895FD090385} UnknownSnapinGUID - Unbekanntes Snapin
{634BDE40-E5E1-49A1-B2CD-140FFFC830F9} EnterprisePKI - Unternehmens-PKI
{6630f2d7-bd52-4072-bfa7-863f3d0c5da0} NPSUI - Netzwerkrichtlinienserver (NPS)
{671EE405-C969-4AF9-AD1B-65E96B3B9A10} DFSSnapIn - DFS-Verwaltung
{677A2D94-28D9-11D1-A95B-008048918FB1} DFS - Verteiltes Dateisystem (DFS)
{6A712058-33C6-4046-BCF9-0EA3A8808EDC} PrefApplications - Snap-Ins für die Einstellungserweiterung "Anwendungen"
{6D8880AF-E518-43A8-986C-1AD21C4C976E} OCSP - Online-Responder
{6DC3804B-7212-458D-ADB0-9A07E2AE1FA2} ResultantSetOfPolicySnapIn - Richtlinienergebnissatz-Snap-In
{6E8E0081-19CD-11D1-AD91-00AA00B8E05A} LogicalMappedDrives - Logische und zugeordnete Laufwerke
{74246bfc-4c96-11d0-abef-0020af6b0b7a} DeviceManager_2 - Geräte-Manager
{7478EF61-8C46-11d1-8D99-00A0C913CAD4} PerfLogsAlerts - Leistungsprotokolle und Warnungen
{753EDB4D-2E1B-11D1-9064-00A0C90AB504} FAXService - Faxdienst
{79F92669-4224-476C-9C5C-6EFB4D87DF4A} GPO_LocalUsersAndGroups - Einstellungserweiterung "Lokale Benutzer und Gruppen"
{7AF60DD3-4979-11D1-8A6C-00C04FC33566} SNMP - SNMP
{7D3830AA-E69E-4E17-8BD1-1B87B97099DA} TPMManagement - TPM-Verwaltung
{7E45546F-6D52-4D10-B702-9C2E67232E62} SoftwareInstalationComputers_2 - Softwareinstallation - RSoP
{803E14A0-B4FB-11D0-A0D0-00A0C90F574B} SecuritySettings_1 - Sicherheitseinstellungen
{813C1B01-6624-4922-9C6C-03C315646584} ShareandStorageManagementSnapIn - Freigabe- und Speicherverwaltung
{88E729D6-BDC1-11D1-BD2A-00C04FB9603F} FolderRedirection_1 - Ordnerumleitung
{89cc9588-7628-4d29-8e4a-6550d0087059} HRA - Integritätsregistrierungsstelle (HRA)
{8EAD3A12-B2C1-11d0-83AA-00A0C92C9D5D} DiskMgmt - Datenträgerverwaltung
{8F8F8DC0-5713-11D1-9551-0060B0576642} IAS - Internetauthentifizierungsdienst (IAS)
{8FC0B734-A0E1-11D1-A7D3-0000F87571E3} GroupPolicySnapIn - Gruppenrichtlinienobjekt-Editor
{90087284-d6d6-11d0-8353-00a0c90640bf} DeviceManager_1 - Geräte-Manager
{90810500-38F1-11D1-9345-00C04FC9DA04} IPXRouting - IPX-Routing
{90810502-38F1-11D1-9345-00C04FC9DA04} IPXRIPRouting - IPX RIP-Routing
{90810504-38F1-11D1-9345-00C04FC9DA04} IPXSAPRouting - IPX SAP-Routing
{942A8E4F-A261-11D1-A760-00C04FB9603F} SoftwareInstalationComputers_1 - Softwareinstallation
{949FB894-E883-42C6-88C1-29169720E8CA} GPO_NetworkOptions - Einstellungserweiterung "Netzwerkoptionen"
{95AD72F0-44CE-11D0-AE29-00AA004B9986} IndexingService - Indexdienst
{975797FC-4E2A-11D0-B702-00C04FD8DBF7} EventViewer_3 - Ereignisanzeige
{9AD2BAFE-63B4-4883-A08C-C3C6196BCAFD} GPO_PowerOptions - Einstellungserweiterung "Energieoptionen"
{9EC88934-C774-11d1-87F4-00C04FC2C17B} DCOMCFG - DCOM-Konfigurationserweiterung
{9FE24B92-C23D-451c-8045-73038D99E620} StarterGPOEditorSnapIn - Gruppenrichtlinien-Editor für Anfangsrichtlinien
{a1bc4eca-66b2-44e8-9915-be02e84438ba} NapSnap - NAP-Clientkonfiguration
{A1BC4ECB-66B2-44E8-9915-BE02E84438BA} NapSnap_GP - NAP-Clientkonfiguration
{A841B6C2-7577-11D0-BB1F-00A0C922E79C} IIS - Internetinformationsdienste
{A8C42CEA-CDB8-4388-97F4-5831F933DA84} GPO_Printers - Einstellungserweiterung "Drucker"
{A994E107-6854-4F3D-917C-E6F01670F6D3} CertsTemplate - Zertifikatvorlagen
{B05566AC-FE9C-4368-BE01-7A4CBB6CBA11} WindowsFirewall_GP2 - Windows-Firewall mit erweiterter Sicherheit
{B05566AC-FE9C-4368-BE02-7A4CBB7CBE11} WindowsFirewall - Windows-Firewall mit erweiterter Sicherheit
{b05566ad-fe9c-4363-be05-7a4cbb7cb510} EventViewer_4 - Ereignisanzeige (Windows Vista)
{B05566AE-FE9C-4363-BE05-7A4CBB7CB510} EventViewer_2 - Ereignisanzeige (Windows Vista)
{B1AFF7D0-0C49-11D1-BB12-00C04FC9A3A3} SendConsoleMessage - Konsolenmeldung senden
{B3408A2F-8DDA-1197-FBD5-2CE69A2DEFC0} equossnap - Enterprise QoS
{B3408A2F-8DDA-1197-FBD5-2CE69A2DEFC1} equossnap - Enterprise QoS
{B52C1E50-1DD2-11D1-BC43-00C04FC31FD3} RAS_DialinUser - RAS-Einwahl - Benutzerknoten
{B6F9C8AE-EF3A-41C8-A911-37370C331DD4} ADMComputers_2 - Administrative Vorlagen - RSoP
{B6F9C8AF-EF3A-41C8-A911-37370C331DD4} ADMUsers_2 - Administrative Vorlagen - RSoP
{B91B6008-32D2-11D2-9888-00A0C925F917} TerminalServices - Remotedesktopdienste-Konfiguration
{B9CCA4DE-E2B9-4CBD-BF7D-11B6EBFBDDF7} GPO_RegionalOptions - Einstellungserweiterung "Regionale Einstellungen"
{BACF5C8A-A3C7-11D1-A760-00C04FB9603F} SoftwareInstallationUsers_1 - Softwareinstallation
{BD95BA60-2E26-AAD1-AD99-00AA00B8E05A} ServiceDependencies - Dienstabhängigkeiten
{BEE07A6A-EC9F-4659-B8C9-0B1937907C83} GPO_Registry - Einstellungserweiterung "Registrierung"
{BFCBBEB0-9DF4-4C0C-A728-434EA66A0373} GPO_NetworkShares - Einstellungserweiterung "Netzwerkfreigaben"
{C11D2F3B-E2F4-4e5b-824B-84A87AB0F666} DomainGPOEditorSnapIn - Gruppenrichtlinienverwaltungs-Editor
{C2FE4500-D6C2-11D0-A37B-00C04FC9DA04} IPRouting - IP-Routing
{C2FE4502-D6C2-11D0-A37B-00C04FC9DA04} DHCPRelayMgmt - DHCP-Relayverwaltung
{C2FE4504-D6C2-11D0-A37B-00C04FC9DA04} RIPRouting - RIP-Routing
{C2FE4506-D6C2-11D0-A37B-00C04FC9DA04} OSPFRouting - OSPF-Routing
{C2FE4508-D6C2-11D0-A37B-00C04FC9DA04} IGMPRouting - IGMP-Routing
{C2FE450B-D6C2-11D0-A37B-00C04FC9DA04} ConnectionSharingNAT - Gemeinsame Verbindungsnutzung (NAT)
{C40D66A0-E90C-46C6-AA3B-473E38C72BF2} FolderRedirection_2 - Ordnerumleitung - RSoP
{C9BC92DF-5B9A-11D1-8F00-00C04FC2C17B} ComponentServices - Komponentendienste
{CAB54552-DEEA-4691-817E-ED4A4D1AFC72} GPO_ScheduledTasks - Einstellungserweiterung "Geplante Aufgaben"
{CC5746A9-9B74-4BE5-AE2E-64379C86E0E4} GPO_Services - Einstellungserweiterung "Dienste"
{CEFFA6E2-E3BD-421B-852C-6F6A79A59BC1} GPO_Shortcuts - Einstellungserweiterung "Verknüpfungen"
{CF848D48-888D-4F45-B530-6A201E62A605} GPO_StartMenu - Einstellungserweiterung "Startmenü"
{D02B1F72-3407-48AE-BA88-E8213C6761F1} ADMComputers_3 - Administrative Vorlagen (Win6/Win7)
{D02B1F73-3407-48AE-BA88-E8213C6761F1} ADMUsers_3 - Administrative Vorlagen (Win6/Win7)
{D2779945-405B-4ACE-8618-508F3E3054AC} FailoverClusters - Failovercluster-Manager
{D524927D-6C08-46BF-86AF-391534D779D3} IEMaintenance_2 - Internet Explorer-Wartung - RSoP
{D70A2BEA-A63E-11D1-A7D4-0000F87571E3} GroupPolicyTab - Registerkarte "Gruppenrichtlinien" für Active Directory-Programme
{D967F824-9968-11D0-B936-00C04FD8D5B0} ActiveDirSitesServices - Active Directory-Standorte und -Dienste
{DAB1A262-4FD7-11D1-842C-00C04FB6C218} Routing - Routing
{DBFCA500-8C31-11D0-AA2C-00A0C92749A3} DiskManagementSnapInExtension - Datenträgerverwaltungserweiterung
{DE751566-4CC6-11D1-8CA0-00C04FC297EB} CertAuth - Zertifizierungsstelle
{DEA8AFA0-CC85-11D0-9CE2-0080C7221EBD} IPSecManage_GP - IP-Sicherheitsrichtlinienverwaltung
{DEA8AFA2-CC85-11d0-9CE2-0080C7221EBD} IpSecManage - IP-Sicherheitsrichtlinienverwaltung
{E12BBB5D-D59D-4E61-947A-301D25AE8C23} GroupPolicyManagementSnapIn - Gruppenrichtlinienverwaltung
{E26D02A0-4C1F-11D1-9AA1-00C04FC3357A} Telephony - Telefonie
{E355E538-1C2E-11D0-8C37-00C04FD8FE93} ActiveDirUsersComp - Active Directory-Benutzer und -Computer
{EBC53A38-A23F-11D0-B09B-00C04FD8DCA6} ActiveDirDomTrusts - Active Directory-Domänen und -Vertrauensstellungen
{F4D8C39A-F43D-42B4-9BDF-4E48D3044BA1} NameResolutionPolicySnapin - Namensauflösungsrichtlinie
{F78FBADD-C21A-4E0A-B53D-C879A9C8F002} DFSSnapInExtension - DFS-Verwaltungserweiterung
{F8ABD46C-1297-4474-9CDF-831EBB245F49} FileServerResourceManagerSnapIn - Ressourcen-Manager für Dateiserver
{F8ABD46E-1297-4474-9CDF-831EBB245F49} FileServerResourceManagerSnapInExtension - Ressourcen-Managererweiterung für Dateiserver
{F9F63D92-6225-410B-BB02-26239B8F1F59} ShareandStorageManagementSnapInExtension - Freigabe- und Speicherverwaltungserweiterung
{FC715823-C5FB-11D1-9EEF-00A0C90347FF} IEMaintenance_1 - Internet Explorer-Wartung
{FD57D297-4FD9-11D1-854E-00C04FC31FD3} QoSAdmission - QoS-Zugangssteuerung
{FE883157-CEBD-4570-B7A2-E4FE06ABE626} SecuritySettings_2 - Sicherheitseinstellungen - RSoP
{FF5903A8-78D6-11D1-92F6-006097B01056} FrontPageExt - FrontPage-Servererweiterungen

Saturday, November 03, 2012

Übersicht aller Einstellungen für Administrative Vorlagen

Hallo da draußen ;-)

Bei Microsoft kann man ja wunderbare Excel-Tabellen herunterladen, in denen sämtliche GPO-Settings inkl. Registry-Wert dokumentiert sind. Leider gibt's die nur auf englisch.

Deshalb gibt's jetzt hier den Einstellungsbericht einer GPO, in der alle - aber wirklich alle - ADM-Vorlagen aktiviert sind. "Show all" und Strg-F, dann findet Ihr Euer Setting schon ;-))



Man beachte auch die aberwitzigen Versionsnummern für Computer und User - die hätte ich zwar faken können, aber so ist's auch nett...

mfg Martin

PS: Natürlich basierend auf den ADMX-Templates von Windows 8/Server 2012...

GUIDs GUIDs GUIDs...

Hallo an alle da draußen ;-)

Was hat es eigentlich mit den ganzen GUIDs auf sich, die bei der GPO-Verarbeitung immer wieder mal auftauchen? Dazu holen wir ein wenig aus:  

Namen sind Schall und Rauch - unter der Haube stecken bei Windows meistens eindeutige Bezeichner. Bei AD-Objekten kennen wir die SIDs (Security Identifier), aber jedes AD-Objekt hat auch eine GUID. Und GUIDs werden auch "sonst überall" verwendet (Globally Unique IDentifiier, laut Microsoft eindeutig in Zeit und Raum): SID vs. GUID

Jedes AD-Objekt hat also eine GUID - so natürlich auch ein GPO. Das hat genauer gesagt sogar 2 GUIDs. Die eine ist das AD-Attribut "objectGUID", das nur AD-intern verwendet wird. Die andere ist das AD-Attribut "name", und das begegnet uns gleich nochmal.

  

Man sieht hier, dass "name" auch den "distinguishedName" festlegt. "name" legt auch den "gPCFileSysPath" fest, das ist der Dateisystemteil des GPO mit den zugehörigen Einstellungen innerhalb der GPO. Und in der GPMC sieht man den Namen als "Eindeutige ID".

Mit einer recht einfachen Abfrage kommt man auch recht schnell vom Namen zur GUID oder umgekehrt:

dsquery * -filter "(|(displayName=xyz)(name={abc}))" -attr name displayname

Hier dann entweder den displayName oder name passend ausfüllen, und schon kommt eine schöne Liste zurück:

dsquery * -filter "(|(displayName=default*)(name={abc}))" -attr name displayname
  name                                      displayname                       
  {6AC1786C-016F-11D2-945F-00C04fB984F9}    Default Domain Controllers Policy 
  {31B2F340-016D-11D2-945F-00C04FB984F9}    Default Domain Policy   
          


Dann gibt's im Attribut-Editor aber noch mehr GUIDs, nämlich in "gPCMachineExtensionNames". Diese definieren den Inhalt der GPO. Hier stehen in eckigen Klammern immer 2 oder mehr GUIDs. Die erste dieser GUIDs gibt die Client Side Extension an, für die in der GPO Einstellungen enthalten sind. Die weiteren GUIDs geben die Snapin Extensions für den Gruppenrichtlinien-Editor an, die für das Bearbeiten dieser Einstellungen zuständig sind.


In der Praxis sieht das dann z.B. so aus:


[{35378EAC-683F-11D2-A89A-00C04FBBCFA2}{53D6AB1D-2488-11D1-A28C-00C04FB94F17}{D02B1F72-3407-48AE-BA88-E8213C6761F1}][{42B5FAAE-6536-11D2-AE5A-0000F87571E3}{40B6664F-4972-11D1-A7CA-0000F87571E3}]

Das ist eine GPO, in der Registry (3537...) und Scripts (42B5...) als CSEs enthalten sind. Zum Bearbeiten der Einstellungen von Registry werden hier gleich zwei Snapins verwendet: Administrative Vorlagen (D02B...) und Firewall mit erweiterter Sicherheit (53D6...). Grund dafür ist, dass die Registry CSE von anderen Snapins "mitverwendet" wird.

Das ganze ist natürlich auch dokumentiert: [MS-GPSO]: Group Policy System Overview

In dieser Doku gibt es dann auch 2 Tabellen, die alle GUIDs für die CSEs und die Snapins auflisten:
3.1.3.1 Group Policy Client-Side Extension List
3.1.3.2 Group Policy Tool Extension List

Die Liste der CSEs taucht ja schon auf einigen anderen Seiten auf, die Liste der Snapins ist noch weitgehend unbekannt. Und da MS eine unvollständige Liste veröffentlicht hat, gibt es hier jetzt die Liste ALLER mir bekannten MMC-Snapins und Snapin Extensions, die Windows "von Haus aus" mitbringt.

Have Fun ;-))

 
GUID Name
{011BE22D-E453-11D1-945A-00C04FB984F9} SCA - Sicherheitskonfiguration und -analyse
{03f1f940-a0f2-11d0-bb77-00aa00a1eab7} SMTPProtocol - SMTP-Protokoll
{06993B16-A5C7-47EB-B61C-B1CB7EE600AC} WiredNetworkPolicy - Richtlinien für verkabelte Netzwerke (IEEE 802.3) - GPEdit
{0DA274B5-EB93-47A7-AAFB-65BA532D3FE6} GPO_Applications - Einstellungserweiterung "Anwendungen"
{0E752416-F29E-4195-A9DD-7F0D4D5A9D71} WindowsFirewall_GP - Windows-Firewall mit erweiterter Sicherheit - GPEdit
{0F3621F1-23C6-11D1-AD97-00AA00B88E5A} SysProp - Systemeigenschaften
{0F6B957D-509E-11D1-A7CC-0000F87571E3} ADMComputers_1 - Administrative Vorlagen (Computer) - GPEdit
{0F6B957E-509E-11D1-A7CC-0000F87571E3} ADMUsers_1 - Administrative Vorlagen (Benutzer) - GPEdit
{127537A8-C1ED-40BC-9AE5-C5891DF6B2D4} GPO_UserControl - Verwendung der Systemsteuerungseinstellungen zulassen (Benutzer)
{1612b55c-243c-48dd-a449-ffc097b19776} GPO_DataSources - Einstellungserweiterung "Datenquellen"
{17C6249E-BA57-4F69-AE93-4FB3D25CD9D7} GPO_CompControl - Systemsteuerungseinstellungen (Computer)
{18BA7139-D98B-43c2-94DA-2604E34E175D} Net_Framework - .Net Framework-Konfiguration
{18ea3f92-d6aa-41d9-a205-2023400c8fbb} ServerManager - Server-Manager
{1AA7F839-C7F5-11D0-A376-00C04FC9DA04} RRA - Routing und RAS
{1AA7F83C-C7F5-11D0-A376-00C04FC9DA04} AppleTalkRouting - AppleTalk-Routing
{1b767e9a-7be4-4d35-85c1-2e174a7ba951} GPO_Devices - Einstellungserweiterung "Geräte"
{1BC972D6-555C-4FF7-BE2C-C584021A0A6A} SoftwareInstallationUsers_2 - Softwareinstallation (Benutzer) - RSoP
{1C5DACFA-16BA-11D2-81D0-0000F87A7AA3} ADSI - ADSI-Bearbeitung
{1F5EEC01-1214-4D94-80C5-4BDCD2014DDD} AuthMan - Autorisierungs-Manager
{23DC5869-BD9F-46fd-AADD-1F869BA64FC3} WirelessMon - Drahtlosmonitor
{243E20B0-48ED-11D2-97DA-00A024D77700} RemStore - Wechselmedien
{2DA6AA7F-8C88-4194-A558-0D36E7FD3E64} WirelessNetworkPolicy - Richtlinien für Drahtlosnetzwerke (IEEE 802.11) - GPEdit
{2E19B602-48EB-11d2-83CA-00104BCA42CF} IASLogging - IAS-Protokollierung
{2EA1A81B-48E5-45E9-8BB7-A6E3AC170006} GPO_Drives - Einstellungserweiterung "Laufwerkzuordnungen"
{3060E8CE-7020-11D2-842D-00C04FA372D4} RIS - Remoteinstallationsdienste - GPEdit
{317cdc35-c09e-486f-ab09-90dd2e3fdd7d} StorageManagerForSANSSnapIn - Speicher-Manager für SANs
{317cdc37-c09e-486f-ab09-90dd2e3fdd7d} StorageManagerForSANSSnapInExtension - Speicher-Manager für SANs-Erweiterung
{34AB8E82-C27E-11D1-A6C0-00C04FB94F17} PublicKey - Richtlinien Öffentlicher Schlüssel
{35141B6B-498A-4cc7-AD59-CEF93D89B2CE} GPO_Environment - Einstellungserweiterung "Umgebung"
{394C052E-B830-11D0-9A86-00C04FD8DBF7} EventViewer_1 - Ereignisanzeige
{3BAE7E51-E3F4-41D0-853D-9BB9FD47605F} GPO_Files - Einstellungserweiterung "Dateien"
{3BFAE46A-7F3A-467B-8CEA-6AA34DC71F53} GPO_FolderOptions - Einstellungserweiterung "Ordneroptionen"
{3CB6973D-3E6F-11D0-95DB-00A024D77700} RSM - Wechselmedienverwaltung
{3D5D035E-7721-4B83-A645-6C07A3D403B7} RemoteDesktop - Remotedesktops
{3EC4E9D3-714D-471F-88DC-4DD4471AAB47} GPO_Folders - Einstellungserweiterung "Ordner"
{3F276EB4-70EE-11D1-8A0F-00C04FB93753} CertAuthPolSet - Zertifizierungsstellen-Richtlinieneinstellungen
{40B6664F-4972-11D1-A7CA-0000F87571E3} ScriptsMachine_1 - Skripts (Start/Herunterfahren) - GPEdit
{40B66650-4972-11D1-A7CA-0000F87571E3} ScriptsUser_1 - Skripts (Anmelden/Abmelden)- GPEdit
{40B66660-4972-11d1-A7CA-0000F87571E3} ScriptsMachine_2 - Skripts (Start/Herunterfahren) - RSoP
{40B66661-4972-11d1-A7CA-0000F87571E3} ScriptsUser_2 - Skripts (Anmelden/Abmelden) - RSoP
{43668E21-2636-11D1-A1CE-0080C88593A5} DiskDefrag - Defragmentierung
{45ac8c63-23e2-11d1-a696-00c04fd58bc3} SysInfo - Systeminformationen
{45B01F1C-5AC2-458c-9457-42A81B34A26D} GPO_ViewExtensionPro - Registerkarte "Einstellungen"
{516FC620-5D34-4B08-8165-6A06B623EDEB} GPO_IniFiles - Einstellungserweiterung "INI-Dateien"
{53D6AB1D-2488-11D1-A28C-00C04FB94F17} Certs - Zertifikate
{57C596D0-9370-40C0-BA0D-AB491B63255D} IpSecMonitor - IP-Sicherheitsmonitor
{58221C65-EA27-11CF-ADCF-00AA00A80033} SharedFolders - Freigegebene Ordner
{58221C66-EA27-11CF-ADCF-00AA00A80033} Services - Dienste
{58221C67-EA27-11CF-ADCF-00AA00A80033} ComputerManagement - Computerverwaltung
{58221C69-EA27-11CF-ADCF-00AA00A80033} SharedFolders_Ext - Erweiterung für freigegebene Ordner
{5880CD5C-8EC0-11d1-9570-0060B0576642} RemoteAccess - RAS
{5ADF5BF6-E452-11D1-945A-00C04FB984F9} SecurityTemplates - Sicherheitsvorlagen
{5C659257-E236-11D2-8899-00104B2AFB46} WMI - WMI-Steuerung
{5C935941-A954-4F7C-B507-885941ECE5C4} GPO_Internet - Einstellungserweiterung "Interneteinstellungen"
{5D6179C8-17EC-11D1-9AA9-00C04FD8FE93} LocalUsersGroups - Lokale Benutzer und Gruppen
{634BDE40-E5E1-49A1-B2CD-140FFFC830F9} EnterprisePKI - Unternehmens-PKI
{6630f2d7-bd52-4072-bfa7-863f3d0c5da0} NPSUI - Netzwerkrichtlinienserver (NPS)
{671ee405-c969-4af9-ad1b-65e96b3b9a10} DFSSnapIn - DFS-Verwaltung
{677A2D94-28D9-11D1-A95B-008048918FB1} DFS - Verteiltes Dateisystem (DFS)
{6A712058-33C6-4046-BCF9-0EA3A8808EDC} PrefApplications - Snap-Ins für die Einstellungserweiterung "Anwendungen"
{6d8880af-e518-43a8-986c-1ad21c4c976e} OCSP - Online-Responder
{6DC3804B-7212-458D-ADB0-9A07E2AE1FA2} ResultantSetOfPolicySnapIn - Richtlinienergebnissatz-Snap-In
{6E8E0081-19CD-11D1-AD91-00AA00B8E05A} LogicalMappedDrives - Logische und zugeordnete Laufwerke
{74246bfc-4c96-11d0-abef-0020af6b0b7a} DeviceManager_2 - Geräte-Manager
{7478EF61-8C46-11d1-8D99-00A0C913CAD4} PerfLogsAlerts - Leistungsprotokolle und Warnungen
{753EDB4D-2E1B-11D1-9064-00A0C90AB504} FAXService - Faxdienst
{79F92669-4224-476c-9C5C-6EFB4D87DF4A} GPO_LocalUsersAndGroups - Einstellungserweiterung "Lokale Benutzer und Gruppen"
{7AF60DD3-4979-11D1-8A6C-00C04FC33566} SNMP - SNMP
{7d3830aa-e69e-4e17-8bd1-1b87b97099da} TPMManagement - TPM-Verwaltung
{7E45546F-6D52-4D10-B702-9C2E67232E62} SoftwareInstalationComputers_2 - Softwareinstallation (Computer) - RSoP
{803E14A0-B4FB-11D0-A0D0-00A0C90F574B} SecuritySettings_1 - Sicherheitseinstellungen - GPEdit
{813C1B01-6624-4922-9C6C-03C315646584} ShareandStorageManagementSnapIn - Freigabe- und Speicherverwaltung
{88E729D6-BDC1-11D1-BD2A-00C04FB9603F} FolderRedirection_1 - Ordnerumleitung - GPEdit
{89cc9588-7628-4d29-8e4a-6550d0087059} HRA - Integritätsregistrierungsstelle (HRA)
{8EAD3A12-B2C1-11d0-83AA-00A0C92C9D5D} DiskMgmt - Datenträgerverwaltung
{8F8F8DC0-5713-11D1-9551-0060B0576642} IAS - Internetauthentifizierungsdienst (IAS)
{8FC0B734-A0E1-11D1-A7D3-0000F87571E3} GroupPolicySnapIn - Gruppenrichtlinienobjekt-Editor
{90087284-d6d6-11d0-8353-00a0c90640bf} DeviceManager_1 - Geräte-Manager
{90810500-38F1-11D1-9345-00C04FC9DA04} IPXRouting - IPX-Routing
{90810502-38F1-11D1-9345-00C04FC9DA04} IPXRIPRouting - IPX RIP-Routing
{90810504-38F1-11D1-9345-00C04FC9DA04} IPXSAPRouting - IPX SAP-Routing
{942A8E4F-A261-11D1-A760-00C04FB9603F} SoftwareInstalationComputers_1 - Softwareinstallation (Computer) - GPEdit
{949FB894-E883-42C6-88C1-29169720E8CA} GPO_NetworkOptions - Einstellungserweiterung "Netzwerkoptionen"
{95AD72F0-44CE-11D0-AE29-00AA004B9986} IndexingService - Indexdienst
{975797FC-4E2A-11D0-B702-00C04FD8DBF7} EventViewer_3 - Ereignisanzeige
{9AD2BAFE-63B4-4883-A08C-C3C6196BCAFD} GPO_PowerOptions - Einstellungserweiterung "Energieoptionen"
{9EC88934-C774-11d1-87F4-00C04FC2C17B} DCOMCFG - DCOM-Konfigurationserweiterung
{9FE24B92-C23D-451c-8045-73038D99E620} StarterGPOEditorSnapIn - Gruppenrichtlinien-Editor für Anfangsrichtlinien
{a1bc4eca-66b2-44e8-9915-be02e84438ba} NapSnap - NAP-Clientkonfiguration
{a1bc4ecb-66b2-44e8-9915-be02e84438ba} NapSnap_GP - NAP-Clientkonfiguration - GPEdit
{A841B6C2-7577-11D0-BB1F-00A0C922E79C} IIS - Internetinformationsdienste
{A8C42CEA-CDB8-4388-97F4-5831F933DA84} GPO_Printers - Einstellungserweiterung "Drucker"
{A994E107-6854-4F3D-917C-E6F01670F6D3} CertsTemplate - Zertifikatvorlagen
{b05566ac-fe9c-4368-be02-7a4cbb7cbe11} WindowsFirewall - Windows-Firewall mit erweiterter Sicherheit
{b05566ad-fe9c-4363-be05-7a4cbb7cb510} EventViewer_4 - Ereignisanzeige (Windows Vista)
{b05566ae-fe9c-4363-be05-7a4cbb7cb510} EventViewer_2 - Ereignisanzeige (Windows Vista)
{B1AFF7D0-0C49-11D1-BB12-00C04FC9A3A3} SendConsoleMessage - Konsolenmeldung senden
{B52C1E50-1DD2-11D1-BC43-00C04FC31FD3} RAS_DialinUser - RAS-Einwahl - Benutzerknoten
{B6F9C8AE-EF3A-41C8-A911-37370C331DD4} ADMComputers_2 - Administrative Vorlagen (Computer) - RSoP
{B6F9C8AF-EF3A-41C8-A911-37370C331DD4} ADMUsers_2 - Administrative Vorlagen (Benutzer) - RSoP
{B91B6008-32D2-11D2-9888-00A0C925F917} TerminalServices - Remotedesktopdienste-Konfiguration
{B9CCA4DE-E2B9-4CBD-BF7D-11B6EBFBDDF7} GPO_RegionalOptions - Einstellungserweiterung "Regionale Einstellungen"
{BACF5C8A-A3C7-11D1-A760-00C04FB9603F} SoftwareInstallationUsers_1 - Softwareinstallation (Benutzer) - GPEdit
{BD95BA60-2E26-AAD1-AD99-00AA00B8E05A} ServiceDependencies - Dienstabhängigkeiten
{BEE07A6A-EC9F-4659-B8C9-0B1937907C83} GPO_Registry - Einstellungserweiterung "Registrierung"
{BFCBBEB0-9DF4-4c0c-A728-434EA66A0373} GPO_NetworkShares - Einstellungserweiterung "Netzwerkfreigaben"
{C11D2F3B-E2F4-4e5b-824B-84A87AB0F666} DomainGPOEditorSnapIn - Gruppenrichtlinienverwaltungs-Editor
{C2FE4500-D6C2-11D0-A37B-00C04FC9DA04} IPRouting - IP-Routing
{C2FE4502-D6C2-11D0-A37B-00C04FC9DA04} DHCPRelayMgmt - DHCP-Relayverwaltung
{C2FE4504-D6C2-11D0-A37B-00C04FC9DA04} RIPRouting - RIP-Routing
{C2FE4506-D6C2-11D0-A37B-00C04FC9DA04} OSPFRouting - OSPF-Routing
{C2FE4508-D6C2-11D0-A37B-00C04FC9DA04} IGMPRouting - IGMP-Routing
{C2FE450B-D6C2-11D0-A37B-00C04FC9DA04} ConnectionSharingNAT - Gemeinsame Verbindungsnutzung (NAT)
{c40d66a0-e90c-46c6-aa3b-473e38c72bf2} FolderRedirection_2 - Ordnerumleitung - RSoP
{C9BC92DF-5B9A-11D1-8F00-00C04FC2C17B} ComponentServices - Komponentendienste
{CAB54552-DEEA-4691-817E-ED4A4D1AFC72} GPO_ScheduledTasks - Einstellungserweiterung "Geplante Aufgaben"
{CC5746A9-9B74-4be5-AE2E-64379C86E0E4} GPO_Services - Einstellungserweiterung "Dienste"
{CEFFA6E2-E3BD-421B-852C-6F6A79A59BC1} GPO_Shortcuts - Einstellungserweiterung "Verknüpfungen"
{CF848D48-888D-4F45-B530-6A201E62A605} GPO_StartMenu - Einstellungserweiterung "Startmenü"
{D2779945-405B-4ACE-8618-508F3E3054AC} FailoverClusters - Failovercluster-Manager
{d524927d-6c08-46bf-86af-391534d779d3} IEMaintenance_2 - Internet Explorer-Wartung - RSoP
{D70A2BEA-A63E-11D1-A7D4-0000F87571E3} GroupPolicyTab - Registerkarte "Gruppenrichtlinien" für Active Directory-Programme
{D967F824-9968-11D0-B936-00C04FD8D5B0} ActiveDirSitesServices - Active Directory-Standorte und -Dienste
{DAB1A262-4FD7-11D1-842C-00C04FB6C218} Routing - Routing
{dbfca500-8c31-11d0-aa2c-00a0c92749a3} DiskManagementSnapInExtension - Datenträgerverwaltungserweiterung
{de751566-4cc6-11d1-8ca0-00c04fc297eb} CertAuth - Zertifizierungsstelle
{DEA8AFA0-CC85-11d0-9CE2-0080C7221EBD} IPSecManage_GP - IP-Sicherheitsrichtlinienverwaltung - GPEdit
{DEA8AFA2-CC85-11d0-9CE2-0080C7221EBD} IpSecManage - IP-Sicherheitsrichtlinienverwaltung
{E12BBB5D-D59D-4E61-947A-301D25AE8C23} GroupPolicyManagementSnapIn - Gruppenrichtlinienverwaltung
{E26D02A0-4C1F-11D1-9AA1-00C04FC3357A} Telephony - Telefonie
{E355E538-1C2E-11D0-8C37-00C04FD8FE93} ActiveDirUsersComp - Active Directory-Benutzer und -Computer
{EBC53A38-A23F-11D0-B09B-00C04FD8DCA6} ActiveDirDomTrusts - Active Directory-Domänen und -Vertrauensstellungen
{f78fbadd-c21a-4e0a-b53d-c879a9c8f002} DFSSnapInExtension - DFS-Verwaltungserweiterung
{f8abd46c-1297-4474-9cdf-831ebb245f49} FileServerResourceManagerSnapIn - Ressourcen-Manager für Dateiserver
{f8abd46e-1297-4474-9cdf-831ebb245f49} FileServerResourceManagerSnapInExtension - Ressourcen-Managererweiterung für Dateiserver
{f9f63d92-6225-410b-bb02-26239b8f1f59} ShareandStorageManagementSnapInExtension - Freigabe- und Speicherverwaltungserweiterung
{FC715823-C5FB-11D1-9EEF-00A0C90347FF} IEMaintenance_1 - Internet Explorer-Wartung - GPEdit
{FD57D297-4FD9-11D1-854E-00C04FC31FD3} QoSAdmission - QoS-Zugangssteuerung
{fe883157-cebd-4570-b7a2-e4fe06abe626} SecuritySettings_2 - Sicherheitseinstellungen - RSoP
{FF5903A8-78D6-11D1-92F6-006097B01056} FrontPageExt - FrontPage-Servererweiterungen

Anmerkung: Nicht alle diese Snapins sind für GPOs relevant...

Thursday, May 31, 2012

Inverting WMI filters

Hi out there in the net! Been some time since my last post, so here we go for an early summer edition. Enjoy the warm rain!

Some of you may have used WMI filtering for Group Policy Objects already. WMI filters are a smart method to target GPOs dynamically based on properties of the actual computer system.
http://support.microsoft.com/kb/555253

But from time to time, a question arises:
How can I target a GPO to a system that has NOT property xyz?

This translates to “how can I invert the result of a WMI filter?”
Imagine the following scenario:

We have a Domain containing a bunch of Servers. Some of them are Citrix Terminal Servers. We want to deploy a GPO that is applied to  all Servers except the Terminal Servers.
Or imagine the following:

We want to deploy MSI packages via GPO, but only to Computers that do not have a given software installed (a given executable file is not present).
The following samples are derived from the first scenario, but I’m sure you’ll manage to implement them for different situations ;-)

What can we filter for?

As you may know, all Citrix Servers have a service running called “IMAService”, that’s responsible for keeping the TS Farm connected (shortly spoken, of course). So our  filter to target for TS Servers may look like this:
Select * from win32_service where name=”IMAService”

This filter evaluates to true on all TS Servers. But how to convert this to a filter that’s true on all other servers? Well, first shot:
Select * from win32_service where NOT name=”IMAService”

See the mistake? This filter matches on ANY service whose name is not “IMAService”, and sure this filter will be true on each and every system we have – even on the TS Servers it will be true.
What now?

Well – there’s Group Policy Preferences and Item Level Targeting, let’s have a look on that: We now will combine that with traditional WMI filtering.
This is how it works!

First, create a new Group Policy Object, navigate to Computer Configuration - Preferences – Windows Settings – Environment and create 2 items. Both define the same environment variable, but with a different value.

Please note that we define the variable “IsTerminalServer” with a value of either 1 or 0.
Then, edit both items, go to the “Common” tab, optionally check “Remove this item when it is no longer applied” (not required, but does not matter anyway),  and make sure to check “Item-level targeting”:

 Now click “Targeting” and in the ILT editor “New Item”  - “WMI Query”. Here’s the ILT filter for the first entry that sets our variable value to 1:

And here’s the filter for the second entry that sets our variable value to 0:

The only difference: The second filter has “Item Options” – “Is Not”, resulting in “does not return a value” in the filter expression you see.
Note: It’s even be possible to retrieve properties of the returned object and save them to (temporary) variables we could use in path or file name fields on the “General” tab… But we don’t need that feature right now.

Remark: In the second above mentioned scenario (targeting for the non-existence of a file), you wouldn’t use a WMI Query – there’s a filter for files already present. I recommend using the predefined filters whenever possible. In my experience, they are easy to use and perform very fast. WMI queries tend to be slow...
Here’s all about Item Level Targeting in detail:

http://technet.microsoft.com/en-us/library/cc733022.aspx
And - unlike Windows in general - within GPP the fabulous "F1" key is always worth being pressed if you need more information...

Now link this new GPO to your Domain or any appropriate OU.

What do we have achieved yet?

Well – each Server that has the IMAService will receive the environment variable “IsTerminalServer” with a value of 1. All other Servers will receive the same variable with a value of 0. Half way done ;-)
Now create one or two WMI filters:


This filter evaluates to true if “IsTerminalServer” is present and contains “1”. The presence and content of the variable is controlled by our previously created GPO with GPP and ILT.

This filter evaluates to true if “IsTerminalServer” is present and contains “0”. The presence and content of the variable is controlled by our previously created GPO with GPP and ILT.
Here’s all about querying WMI  in detail:
http://msdn.microsoft.com/en-us/library/windows/desktop/aa392902.aspx

And here’s all you can query WMI for:
(Most times, you will only use the Win32 classes anyway…)

Link the latter WMI filter to your GPO you want to target to all servers EXCEPT Terminal Servers, and you’re done. The only caveat with this procedure: The GPO using the WMI filter does not work on first boot, but on the second boot (at first boot, the GPP Environment has to be processed, but that happens after WMI filters have been evaluated, so our variable is missing at this very moment…). If you use the WMI filter in user GPOs, it will work immediately.
Cool, isn’t it?

Well, to be honest: The GPP online help suggests using environment variables as an intermediate mechanism when  complex ILT filters are required – build an environment variable based on a complex ILT filter and use this environment variable as a simple ILT filter in other GPP elements. But they forgot to mention the added value when using this with WMI filters.

Stay tuned, regards Martin

Wednesday, March 07, 2012

How to save my screen

Hello there. Often I see questions regarding the screen saver configuration and how to deploy different settings based on computers and not users… Here’s my ultimate guide on
  • What choices do I have?
  • How does each choice work?
  • What are advantages and disadvantages of each choice?
There’s more than one way to configure screen savers, but in corporate environments, you will obviously use Group Policy Administrative Templates to deploy your screen saver settings to your users - most times, at least. Here are the settings we need:









These are user settings. So how am I able to deploy different settings (e.g. different timeout values) to the same user based on the computer this user logs on to? There are several possibilities, three of them I’ll explain now.

Apply WMI filtering to the GPO

WMI filters allow you to filter on  properties of “whatever” on the local computer. The presence or content of these properties will determine whether the filter evaluates to “True” (GPO gets applied) or “False” (GPO is skipped).
As we want to target on different computers, we can use a filter for Win32_Computersystem.Name:
Select * from win32_computersystem where name=”WS01”





This simple filter checks for the given computer names and applies the GPO if a match is found.
WMI filtering has 2 disadvantages:
  1. Filtering may become a performance issue. The filter has to be evaluated, and this takes time. Depending on the filter this could be up to 30 seconds (filters lasting longer are aborted – but that’s undocumented at the time of this writing).
  2. For each and every new workstation, you have to edit the filter again. It’s not possible to use a group here, and it’s also not possible to use environment variables (like “%computername%).

Enable Loopback processing

In a previous post, I explained how loopback processing works. So in short: Enable loopback for all computers in question (“Merge” mode I would suggest) and link the screensaver GPO to your computers OU instead the users OU.






This will result in the following GPO application order:





Assume your corporate screen saver settings reside in the “Users Policy” (green) - these are now overwritten with the specialized settings in “Corp Screensaver Policy” (red), but only for computers that
  1. Have loopback enabled
  2. Belong to “Corp Screensaver Computers”
The first is obvious, for the second read more at http://support.microsoft.com/kb/953768 (the article does not mention “Merge” or “Replace” mode, but this behavior is only true for “Merge” mode).

Skip Administrative Templates, use Preferences!

Starting with Windows Vista, Group Policy Preferences showed up in domain based GP editor. These enable us to configure a huge variety of settings previously unavailable in Group Policy. My favorite among these are Group Policy Preferences “Registry”. But how can I use these to configure the screen saver?
Administrative templates are nothing but a bunch of registry values. And the screen saver does not care about “who set this timeout value”, it only cares about “what timeout is set”. To use preferences, we first need to know what registry values are involved. Since we already created a GPO containing our settings, these can be extracted from registry.pol (the file in the GPOs folder in sysvol holding ADM template registry values). This file is well documented: http://msdn.microsoft.com/en-us/library/windows/desktop/aa374407.aspx
(A different approach would be extracting the values from the admx templates, but since there are 149/157 admx templates in Win7/R2, this could be a tedious job...)
The easiest way to find the registry.pol for a given GPO is: Edit the GPO in question, navigate to Policies - Windows-Settings – Scripts, double click one of the entries in the right pane and then click “Show Files…”. This opens an explorer window where you navigate two folders upwards.










The registry.pol file can be opened with notepad, but as it is a mixup of ANSI and Unicode – the first 4 characters are ANSI “PReg”, all registry keys and values are Unicode – it looks somewhat unreadable.





or my own script I wrote several years ago (that one is able to WRITE registry.pol also - http://www.faq-o-matic.net/2007/03/26/gruppenrichtlinien-per-skript-lesen-und-schreiben/. The site is german, but the download also includes an english readme.)











So there’s a value called “ScreenSaveTimeOut” of type REG_SZ (interesting – the timeout  is a number, shoulnd’t it then be REG_DWORD?), and this value we are going to deploy through GPP Registry instead of ADM Templates.
We now have the full power of GPP Item Level Targeting at hand to select who may (or may not) receive this value.
  • Filter for security group membership of the computer
  • Filter for date or time
  • Filter for the result of LDAP queries against AD
  • Filter for Sites


And remember: All of this not only applies to screen saver settings. It applies to all settings you have in administrative templates - well, "almost" all of them.
That’s all for now, enjoy your new screen saver settings!