Chat now with support
Chat with Support

GPOADmin 5.17 - User Guide

Introducing Quest GPOADmin Configuring GPOADmin Using GPOADmin
Connecting to the Version Control system Navigating the GPOADmin console Search folders Accessing the GPMC extension Configuring user preferences Working with the live environment Working with controlled objects (version control root)
Creating a custom container hierarchy Selecting security, levels of approval, and notification options Viewing the differences between objects Copying/pasting objects Proposing the creation of controlled objects Merging GPOs Restoring an object to a previous version Restoring links to a previous version Managing your links with search and replace Linking GPOs to multiple Scopes of Management Managing compliance issues automatically with remediation rules Validating GPOs Managing GPO revisions with lineage Setting when users can modify objects Working with registered objects Working with available objects Working with checked out objects Working with objects pending approval and deployment
Checking compliance Editing objects Synchronizing GPOs Exporting and importing
Creating Reports Appendix: Windows PowerShell Commands Appendix: GPOADmin Event Log Appendix: GPOADmin Backup and Recovery Procedures Appendix: Customizing your workflow Appendix: GPOADmin Silent Installation Commands Appendix: Configuring Gmail for Notifications Appendix: Registering GPOADmin for Office 365 Exchange Online Appendix: GPOADmin with SQL Replication About Us

Linking GPOs

Once GPOs have been created and configured, they must be linked to the appropriate sites, domain, or OU. Before you can link a GPO, you must register and check out the site, domain, or OU. For information on registering Scopes of Management, see Registering objects .

Users with the Link right can link a single GPO with numerous sites, domains, or OUs and link multiple GPOs to a site, domain, or OU. (For more information on setting permissions, see Configuring role-based delegation.)

The Link right grants the user the right to add, modify, and remove links. This right must exist on the GPO and the scope of management being linked.

The Modify Link Properties right grants the right to modify the Enabled and Enforce properties of a GPO Link. This right must exist on the scope of management.

The Edit right, grants the user the right to modify the Link order. This right must exist on the scope of management.

If you link more than one GPO, you must pay attention to their order. The first GPO has the highest precedence because it is processed last. The Link Report and Group Policy Results Report can help you understand the inheritance structure of your group policies.

By default, GPOs affect all users and computers contained within a linked site, domain, or OU. To refine the application of a GPO, see Editing GPOs .

2
Click New Link to add another GPO.
4
Enable Block Inheritance if required.
5
3
In the right pane, ensure that the Add check box is selected for the GPOs you want to link.
5

You can also rollback pre-existing links between GPOs and sites, domains, and OUs when restoring GPOs. For information, see Restoring links to a previous version and Checking compliance .

Synchronizing GPOs

Synchronizing GPOs allows you to automatically push out pre-defined “primary GPO” settings to specified targets both within a forest and between two forests. This allows you to ensure specific GPOs, which are required in every domain, contain the same settings without having to link to a GPO outside of the domain.

You will be able to select one or more GPOs from various domains as synchronization targets for the source GPO. When the source GPO has been successfully deployed, the settings from the last major backup will be imported into each synchronization target GPO.

Enabling synchronization

The ability to synchronize GPOs requires that:

2
Select Options| General.
3
Select Enable Group Policy Object Synchronization.
4

Working with GPO synchronizations

Keep the following in mind when working with synchronizations:

1
In the Version Control Root, right-click the source GPO, and select Synchronize | Set Synchronization Targets.
2
If required, select Add Servers to include other servers that contain the GPOs that you want to target. Select the server and click Connect. Enter the required credentials and click OK.
3
Select the required GPOs and choose Synchronization | Add Synchronization Target to select the required target GPOs. The list of all available GPOs will display.
5
If required, we provide the option to setup a migration table by selecting the target and choosing Synchronization | Select Migration Table. From here, you can add (or remove), create, modify the migration tables that are going to be used during the synchronization using the Microsoft Migration Table Editor.
6
Select the target and choose Synchronization to set the synchronization options. You can choose between the following:
Clear Migration table: Clear the tables when no longer required.
Use Migration Table Exclusively: If enabled, the migration (import operation) will not proceed if any settings security principals or UNC paths configured within the source GPO do not exist in the migration table.
Migrate Security Filters: Migrates any security principals from the security filter that are found in the migration table.
Target State: Select the state that you want the target to be in after the synchronization completes. You can choose between Available, Checked Out, Pending Approval, or Deployed. The default is Checked Out.
Synchronize Deletions: Select to enable this option, if you want any deleted source GPOs to also be deleted in the target.
Set target WMI Filters: Select this option to synchronize WMI filters between domains. You can choose between the following options:
None: When you select this option, the WMI filter in the target GPO will not be updated. Use this option to disable previously set WMI Filter synchronizations.
Auto-map By Name: When you select this option, if a WMI Filter in the target domain is found with the same name as the WMI Filter linked to the source GPO, it is assigned to the target GPO.
Select WMI Filter: This opens a browser that lists all of the WMI Filters in the target domain where the connected account has access. From this list, select the WMI Filter to assign to the target GPO.
1
If you select to Cancel the editor, the warning will not persist.
2
If you select OK, the warning will remain to alert you that the issues must be addressed. When ready to address the issue, simply select the Correct button at the top of the dialog or right-click and select Correct.
1
In the Version Control Root, select the source GPO, and choose Synchronization | Set Synchronization Targets.
2
Select any one of the target GPOs, choose Tools | Update Credentials, and enter the new credentials.
1
Right-click the source GPO and choose Synchronization | Synchronize Now.
2
3
If required, you can select Export to export the data to a .csv file.
1
Right-click a GPO that has synchronization targets set and select Synchronize | Validate Synchronization Results.
Right-click a GPO that has synchronization targets set and select Synchronize | Set Synchronization Targets. Then select one or more synchronization targets and choose Validate Synchronization Results.
In the Version Control Root, select the source GPO, and choose Synchronization | Validate Synchronization Results.
1
In the Version Control Root, select the source GPO, and choose Synchronization | Validate Synchronization Results.
2
1
In the Version Control Root, select the source GPO, and choose Synchronization | Set Synchronization Targets.
2
Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating