[TITLE LE] MDOP : Advanced Group Policy Management Vijay Kolli MEA Architect Microsoft Corp
AGPM : The Sell [PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE] • GPO Management – Offline editing – History – Difference reporting – Search – Multi forest • Workflow – Delegation – Source control
[PRES Architecture ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE] Archive/Offline Production AGPM Server Domain Controller XML File of backups GPO 2 GPO 1 Backups of GPO 2 Backups GPO 1 AGPM Client (GPMC) Administrative Desktop
AGPM 4.0 Client and Server Support [PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE] Operating system on which Operating system on which Status of AGPM 4.0 support AGPM Server 4.0 runs AGPM Client 4.0 runs Supported Windows 7/R2 Best Experience Partially supported Windows Server 2008 R2 Cannot edit policy settings or Windows Vista with SP1/2008 preference items that exist only in Windows Server 2008 R2 or Windows 7 Windows 7/R2 Unsupported Supported with limitations Windows Server 2008 Cannot report or edit policy settings or Windows Vista with SP1/2008 preference items that exist only in Windows Server 2008 R2 or Windows 7
AGPM : The Sell [PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE] • GPO Management – Offline editing – History – Difference reporting – Search – Multi forest • Workflow – Delegation – Source control
Offline Editing [PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE] Edit GPOs offline before deploying live
[PRES ESEN ENTATI TION N TITLE LE] Auditing [PRES ESEN ENTATI TION N TITLE LE] Get complete details on what happened, who did it, and why
History [PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE] History is a list of complete backups Rollback to a safe state Safeguard live environment from unapproved changes and untested settings
[PRES MDOP AGPM ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE] Authoring, History Demo
Differences [PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE] added changed removed Compare settings between GPOs
Reporting [PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE] • Settings – Parity with Group Policy settings reports • Difference – Versions: older compared to newer – Any 2 GPOs – Template: GPO compared to its baseline
[PRES ESEN ENTATI TION N TITLE LE] Search (Filtering) [PRES ESEN ENTATI TION N TITLE LE] • What it does – Filters GPOs by properties – Allows for column precision – Maintains a list of the recent 10 searches • What it doesn’t do – Search for settings
Multi Forest Support [PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE] • What it does – Allows GPO movement from AGPM to AGPM – Preserves origin metadata – Supports migration tables • What it doesn’t do – Online moves between domains/forests – GPP and Migrations Tables limitation
Windows 7/Server 2008 R2 [PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE] • What was supported – Group Policy Preferences – Reporting for all new extensions • Applocker, DNSSEC, IE8, Scheduled Tasks – Service execution – RSAT
[PRES MDOP AGPM ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE] Differences Demo
AGPM : The Sell [PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE] • GPO Management – Offline editing – Difference reporting – History – Search – Multi forest • Workflow – Delegation – Source control
Service [PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE] Production Archive/Offline Proxy AGPM Server Domain Controller GPO 2 GPO 1 Permissions AGPM Client (GPMC) Administrative Desktop
Delegation - Roles [PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE] Editor Full Control Approver Reviewer Define granular control without making everyone a Domain Admin
[PRES MDOP AGPM ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE] Role Delegation Demo
Workflow [PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE] Control Deployment Check-out Offline Reporting Edit Requests Check-in
Granular change tracking [PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE]
Purge historical data [PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE]
Last Step Delegation [PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE]
[PRES MDOP ESEN ENTATI P AGPM TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE] Workflow Demo
[PRES ESEN ENTATI TION N TITLE LE] Q&A [PRES ESEN ENTATI TION N TITLE LE] Q & A
[PRES ESEN ENTATI TION N TITLE LE] [PRES ESEN ENTATI TION N TITLE LE] Partners to go to:
Recommend
More recommend