[TITLE LE] MDOP : Advanced Group Policy Management Vijay Kolli MEA Architect Microsoft Corp
Vijay Kolli MEA Architect Microsoft Corp AGPM : The Sell [PRES - - PowerPoint PPT Presentation
Vijay Kolli MEA Architect Microsoft Corp AGPM : The Sell [PRES - - PowerPoint PPT Presentation
[TITLE LE] MDOP : Advanced Group Policy Management Vijay Kolli MEA Architect Microsoft Corp AGPM : The Sell [PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE] GPO Management Offline editing History
[PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE]
AGPM : The Sell
- GPO Management
– Offline editing – History – Difference reporting – Search – Multi forest
- Workflow
– Delegation – Source control
[PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE] Archive/Offline
Architecture
Domain Controller
AGPM Server Administrative Desktop
Backups GPO 1 Backups
- f GPO 2
GPO 1
GPO 2
Production
AGPM Client (GPMC)
XML File of backups
[PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE]
AGPM 4.0 Client and Server Support
Operating system on which AGPM Server 4.0 runs Operating system on which AGPM Client 4.0 runs Status of AGPM 4.0 support Windows Server 2008 R2 Windows 7/R2 Supported
Best Experience
Windows Vista with SP1/2008 Partially supported
Cannot edit policy settings or preference items that exist only in Windows Server 2008 R2 or Windows 7
Windows Server 2008 Windows 7/R2 Unsupported Windows Vista with SP1/2008 Supported with limitations
Cannot report or edit policy settings or preference items that exist only in Windows Server 2008 R2 or Windows 7
[PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE]
AGPM : The Sell
- GPO Management
– Offline editing – History – Difference reporting – Search – Multi forest
- Workflow
– Delegation – Source control
[PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE]
Offline Editing
Edit GPOs offline before deploying live
[PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE]
Auditing Get complete details on what happened, who did it, and why
[PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE]
History History is a list of complete backups Rollback to a safe state
Safeguard live environment from unapproved changes and untested settings
[PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE] MDOP AGPM
Authoring, History Demo
[PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE]
Differences
Compare settings between GPOs
changed added removed
[PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE]
Reporting
- Settings
– Parity with Group Policy settings reports
- Difference
– Versions: older compared to newer – Any 2 GPOs – Template: GPO compared to its baseline
[PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE]
Search (Filtering)
- What it does
– Filters GPOs by properties – Allows for column precision – Maintains a list of the recent 10 searches
- What it doesn’t do
– Search for settings
[PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE]
Multi Forest Support
- What it does
– Allows GPO movement from AGPM to AGPM – Preserves origin metadata – Supports migration tables
- What it doesn’t do
– Online moves between domains/forests – GPP and Migrations Tables limitation
[PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE]
Windows 7/Server 2008 R2
- What was supported
– Group Policy Preferences – Reporting for all new extensions
- Applocker, DNSSEC, IE8, Scheduled Tasks
– Service execution – RSAT
[PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE] MDOP AGPM
Differences Demo
[PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE]
AGPM : The Sell
- GPO Management
– Offline editing – Difference reporting – History – Search – Multi forest
- Workflow
– Delegation – Source control
[PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE]
Service
Archive/Offline
Domain Controller
AGPM Server Administrative Desktop
GPO 1
GPO 2
Production
AGPM Client (GPMC)
Proxy
Permissions
[PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE]
Delegation - Roles
Reviewer Full Control Editor Approver
Define granular control without making everyone a Domain Admin
[PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE] MDOP AGPM
Role Delegation Demo
[PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE]
Workflow
Control Check-out Edit Check-in Requests Reporting Deployment
Offline
[PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE]
Granular change tracking
[PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE]
Purge historical data
[PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE]
Last Step Delegation
[PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE] MDOP P AGPM
Workflow Demo
[PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE]
Q&A
Q & A
[PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE] Partners to go to: