- Related Products
- ADAudit Plus
- ADSelfService Plus
- EventLog Analyzer
- Exchange Reporter Plus
- AD360
- Log360
ADManager Plus offers different ways to view GPOs, and an administrator can choose a view depending on the requirement. The different ways to view GPOs and the objects linked to these are:
View all available GPOs in a domain.
Administrators can view the list of all available GPOs in a domain using this option.
Procedure:
The GPOs available in a domain can be viewed using 'Select Domain' available on the 'Manage GPO' page.
Steps:
To view all the GPO(s) available in a domain:
View all the GPOs linked to a specific domain/OU/site.
Administrators can instantly view the list of all the GPOs that are linked to any specific domain/OU/site using this option.
Procedure:
Using 'Select' on the 'Manage GPO Links' page, the GPOs linked to specific domain, OUs, or sites can be viewed.
Steps:
To view all the GPO(s) linked to a domain, OU, or site:
View all the OUs/sites that a GPO is linked to.
This option enables the administrators to know the OUs/sites that any GPO is linked to.
Procedure:
The OUs/sites that a GPO is linked to can be viewed by clicking on the particular GPO from the list of GPOs generated using 'Select Domain'.
Steps:
To view all the OUs/sites to which a GPO is linked:
New GPOs can be created using ADManager Plus, thus eliminating the need to install GPMC in the machine that runs ADManager Plus.
Procedure:
Using 'Create new GPO' at the top right corner of the'Manage GPOs' page, administrators can create GPOs and link those to OUs, sites, or domain.
Steps:
To create a new GPO:
Administrative Templates settings of both User and Computer configurations, and important security settings, viz., Account Policies, Local Policies, Event Log, Restricted Groups, System Services, Registry, and File System, of Computer Configuration can be edited using ADManager Plus.
Procedure:
Use the 'Edit GPO Settings' option in the action column beside each GPO to edit the Administrative Templates and Security Settings associated with each GPO.
Steps:
To edit the settings of a GPO:
With ADManager Plus 'GPO Management', administrators can enable or disable, at one go, multiple GPOs in the required domains. Administrators can also choose to enable/disable the GPOs completely or partially (either the user configuration or computer configuration settings), as needed.Administrators can also enable/ disable a single GPO or GPOs in bulk.
Procedure:
Using 'Select Domain' in 'Manage GPOs' get the list of all GPOs, and enable/disable them completely or partially, as required.
Steps:
To enable/disable GPO(s):
Administrators can delete those GPOs which are no longer required using the 'Delete' option available in ADManager Plus.
Procedure:
After selecting the required domain using 'Select Domain' in the 'Manage GPO' page, choose the GPOs which are to be deleted. Select 'Delete' from the 'Manage' option above the GPO list.
Steps:
To delete GPO(s):
The scope of a GPO can be defined by linking it to a site or a domain or an OU. By default, a GPO will be applied throughout the linked object unless it is narrowed down. One of the common ways to narrow down GPO scope is using filters like Security or WMI filtering.
Steps to configure GPO filters
You can view or configure the GPO permissions for desired security principals by following these steps,
Steps to configure GPO delegation permissions
This option helps administrators apply GPOs to a domain, sites, or OUs, or, remove GPO links which are no longer required for that particular domain, sites, or OUs.
Procedure:
Using 'Link GPOs' in the 'Manage GPO Links' page, link GPOs to required domain, sites, or OUs. GPO links can be removed using the 'Remove Links' available in the 'Manage' option.
Steps:
To link GPO(s):
To remove GPO link(s):
Administrators can enable or disable the application of GPOs to a particular domain, sites, or OUs using this option.
Procedure:
From the list of GPOs available for the selected domain/OU/site, select the required GPOs whose links are to be enabled or disabled. Enable or disable the links using the option available in 'Manage'.
Steps:
To enable/disable GPO link(s):
This option allows administrators to specify the GPOs which have to be enforced on specified target containers, in one single action. Using the remove enforcement option, this enforced application of GPOs can be revoked.
Procedure:
From the list of all GPOs linked to the selected domain, OUs, or sites, select the required GPOs and enforce or remove enforcement, as required.
Steps:
To enforce or remove enforcement of GPO link(s):
Administrators can use this option to block/unblock the inheritance of GPO settings by any OU or domain from its parent container.
Procedure:
Select the OU or domain for which inheritance of GPO settings is to be blocked or unblocked, and then block or unblock inheritance, as required.
Steps:
To block/unblock the inheritance of GPO settings for the required domain/OU:
Recommendation: As a best practice, ensure that the account with which the ADManager Plus runs has the necessary rights to create GPO in the desired domain.