Hi Ansible Community,
It is my first post here. I am coming to get more information about Windows management with Ansible.
I have been using Ansible for about a year now, and I am able to manage Windows with the WinRM with certificate. My playbooks manage the initial set up for all of the Windows servers (Create ansible user, Set DNS, Join AD, Add AD users to Local Administrator).
What I am wondering is for GPOs. We can agree that all GPOs or LGPOs are linked to Registry Keys in Windows.
At this point I am at a split road. Where I work, we don’t have extensive GPOs from the domain controller, and our structure is not made so we don’t have a central Domain Controller. At this point we have maybe 4-5 environment running a Domain Controller with Simple AD in AWS or AD in AWS. We are looking at potentially having way more in the future. Although we are at a point where we need to securely and configure application, users and other stuff. Usually, I would go and just make GPOs, but we can also agree that GPOs can come repetitive and long to do as it is manual through the GPO manager or AGPM. There is no way I can have a central AD to manage the others.
My question for you guys is: should I use Ansible and the win_regedit module to manage and configure all of our windows machine? or I should keep GPOs and manage it that way and how windows is supposed to be?
I am looking at a solution easy and reproducible where it can scale and provide some kind of version control. Also, money is an important factor, where I do not want to spend much more than what we already use.
Please let me know your thoughts and if you have done something like that, I would be more than happy to get some information.
If you have questions for me, let me know as well!
Thank you very much!
-Simon
This message has been sent on behalf of a company that is part of the Harris Operating Group of Constellation Software Inc. These companies are listed here.
If you prefer not to be contacted by Harris Operating Group please notify us.
This message is intended exclusively for the individual or entity to which it is addressed. This communication may contain information that is proprietary, privileged or confidential or otherwise legally exempt from disclosure. If you are not the named addressee, you are not authorized to read, print, retain, copy or disseminate this message or any part of it. If you have received this message in error, please notify the sender immediately by e-mail and delete all copies of the message.