Advanced Group Policy Management - On privileges and roles.
hello!
we rolling out agpm (vlatest). seems work enough.
we have more 1 set of standard permissions. for example, our citrix team controls gpos citrix, our desktop team controls gpos desktops, etc.
is there no way delineate in agpm?
- my first thought use powershell rapidly set, , regularly audit , auto-correct these privileges. true group policy form, there limited powershell support - in case, none @ all.
- my second thought templates might include agpm roles. so 'group x has privileges template a,' 'group y , z have privileges template b,' , forth. when create template, include permissions. nope.
i'm opening access, might tough sell. am 1 has disparate security boundaries around group policies? am overlooking solution this?
thanks!
rcm
hi all,
my apologies if common knowledge or available somewhere, can't seem find it.
looking understand how agpm works.
- if 'import from...' production, or 'control' gpo. which domain controller agpm select from? does behave gpmc , use pdc emulator? does pick site agpm server resides on?
- same question when deploy gpo. which domain controller deploy to?
i ask because when edit policy, see domain controller isn't pdc emulator. this makes sense given aren't editing production gpo, curious see what's going on behind scenes. i'm assuming there isn't way 'deploy specific domain controller'.
also, going bring in every agpm post make; powershell support agpm? does exist? this poor showing, , limiting...
thanks!
Windows Server > Group Policy
Comments
Post a Comment