Chat now with support
Chat with Support

GPOADmin 5.21 - User Guide

Introducing Quest GPOADmin Configuring GPOADmin Using GPOADmin
Connecting to the Version Control system Navigating the GPOADmin console Search folders Accessing the GPMC extension Configuring user preferences Working with the live environment Working with controlled objects (version control root)
Creating a custom container hierarchy Selecting security, levels of approval, and notification options Viewing the differences between objects Copying/pasting objects Proposing the creation of controlled objects Merging GPOs Restoring an object to a previous version Restoring links to a previous version Managing your links with search and replace Linking GPOs to multiple Scopes of Management Managing compliance issues automatically with remediation rules Validating GPOs Managing GPO revisions with lineage Setting the change window for specific actions Working with registered objects Working with available objects Working with checked out objects Working with objects pending approval and deployment
Checking compliance Editing objects Synchronizing GPOs Exporting and importing
Creating Reports Appendix: Windows PowerShell Commands Appendix: GPOADmin Event Log Appendix: GPOADmin Backup and Recovery Procedures Appendix: Customizing your workflow Appendix: GPOADmin Silent Installation Commands Appendix: Configuring Gmail for Notifications Appendix: Registering GPOADmin for Microsoft 365 Exchange Online Appendix: GPOADmin with SQL Replication About Us

Validating a GPO against a Protected Settings policies and blocked extensions before a check-in

A GPO can be checked against the Protected Setting policy and blocked extensions before checking it in.

1
Right-click the GPO you want to check and select Protected Settings | Verify Protected Settings.
2
Select View Report to generate a report that displays the differences between the GPO and the Protected Settings policy. You can select to print or save the report. Once you have finished viewing the report click Close.
3
Click OK in the Protected Settings Modifications Detected dialog box to close it.

Working with Protected Settings Policy Baselines

If you have GPOADmin configured with SQL as the configuration store, you can select to assign Protected Setting policies to individual GPOs as policy baselines.

When this option is enabled, the Watcher service will validate the settings against the policy baseline when a registered GPO is modified outside of GPOADmin. If a deviation is detected, a notification will be sent to all subscribers of the policy Deviation notification. The notification will include a difference report that is focused on only the settings that are in the baseline.

3
Select Options | General and select Enable Protected Settings for Group Policy Objects and select Enable Policy Baselines.
1
Expand the Version Control Root node, and the required container.
3
Select Notifications, and subscribe to the Policy Deviation notification.
1
Edit or create a new role and assign the Modify Protected Settings Baseline Assignment right. See Configuring role-based delegation for details.
1
As a user with the Modify Protected Settings Baseline Assignments right and the Read right on one or more Protected Settings Containers, right-click a policy and select Properties.
2
Click the Policy Baseline tab.
3
Click to enable to Monitor this policy for deviations from the following Policy Baselines option.
4
Click Add to open the Policy Browser dialog, select the baselines to add, and click OK.
5
Click OK again to save and apply your changes.

Using GPOADmin

Connecting to the Version Control system

When the GPOADmin console is closed, the GPOADmin servers you were connected to are persisted, so the next time you open GPOADmin the connections to those servers are initiated automatically.

If you selected the “Remember my password” check box during the initial connection, then you will not be prompted for credentials the next time you connect. Each connection to this server from here on will automatically use the specified credentials, which are stored in Windows Credentials Manager. To logon as a different user, you must remove the entry from the Windows Credentials Manager.

1
Right-click the GPOADmin node and select Connect To.
2
Click New to create a new connection and enter the server name.
3
Select the required Version Control server and click Connect to connect with the current logged on user credentials or select the down arrow in the Connect button and select Connect As to enter new credentials (domain\user and password).
4
To save the credentials, select the Remember my password check box and click OK.
Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating