Best Practice - 1 large domain level gpo vs several smaller OU level gpo
-
Wednesday, May 23, 2012 6:06 PM
So we are in the process of setting up printer deployment via GPO with user preferences but we are unsure what would be the best way to manage this.
Currently its setup like this.
- About 30 OU's based on geographical location
- Each one has a printers GPO linked to it for the printer in their area - all users in the ou get it
- When someone from another OU need to print to a printer in a different location we have to add that printer to that GPO and use item level targeting to keep other users in the same OU from seeing that printer as well.
So as you can tell this can be kind of messy. So I'm thinking of changing it to this:
- Create a security group for each printer
- add any users that need that printer to it.
- create a single domain level policy with all printers in it. Each one pointing to the respective security group.
So here is my concerns and questions.
- In the current setup. When the user logs and and it processes the gpo's does it read and process only linked gpo's that apply to that user or does it read all gpo's, even one say linked to another OU, then process only the ones that apply to them.
- In the new setup concept there will be roughly 50 printers in this one GPO but only 1-3 will be installed based on what groups that user is a member of. Will this take a long time to run?
Thanks all for the help in advance.
All Replies
-
Thursday, May 24, 2012 5:54 AMModerator
Hi,
As to your first question, I suggest you to read below Microsoft article about Group Policy processing and precedence. If several GPOs are linked to an OU, their processing is in the order that is specified by the administrator.
http://technet.microsoft.com/en-us/library/cc785665(v=WS.10).aspxAs to the second question, considering the only 1-3 printers would be installed I suspect it wouldn't take a long time to run. Suggest you try it in the test environment first to make a sure.
Regards,
Cicely- Marked As Answer by Cicely FengMicrosoft Contingent Staff, Moderator Monday, May 28, 2012 2:22 AM

