SECURITY

Windows Server 2008 and Windows Vista : Advanced Group Policy Management Delegation - Approving, Reviewing

10/26/2013 2:26:08 AM

1. Approving

Only users who have been granted the Approver permission will be able to perform some of the more advanced actions in AGPM. The ability to create a new GPO and the ability to deploy a GPO to the production environment are both examples of tasks that require the Approver permission, such as approving a pending GPO, as shown in Figure 1.

Figure 1. A pending GPO requires that someone with the Approver permission either approve it or reject it.

To set up Approver permission or a group in AGPM, follow these steps:

1.
In the GPMC, expand the forest node, and then expand the domain node.

2.
Select the Change Control node.

3.
Select the Controlled tab, located on the Contents tab in the details pane.

4.
Select the GPO for which you want to set up delegation.

5.
If the user or group is already listed as having the specified archive permissions for the selected GPO list, select the group or user for which you are setting up delegation. Then click Advanced to open the Permissions dialog box. Select the group or user name in the Group Or User Names list, and then select the Approver check box in the Allow column.

6.
To add members, click Add, and then select the user or group in the Select User, Computer, or Group dialog box, setting up the Approver delegation after adding the object.

7.
To remove a member, select the member, and then click Remove.

When you select the Approver check box, the Reviewer check box is also selected because it is a required permission for approving GPOs in AGPM. The Approver permission includes:

  • Create GPO

  • List Contents

  • Read Settings

  • Delete GPO

  • Deploy GPO

After a user has been granted the Approver permission, his or her level of control over GPOs depends on whether the permission was granted at the domain level or the individual GPO level. If granted at the domain level, under the Domain Delegation tab, the user can approve any GPO that is brought into AGPM.

2. Reviewing

One of the benefits of AGPM is the ability to provide users with the option to see the settings in the GPOs, but not alter them in any way. Individuals such as managers, IT administrators (not related to Group Policy), and Help desk personnel can see the GPO settings and even compare two GPOs by using difference reporting.

Note

To compare two GPOs, or to compare a GPO to a template, using difference reporting in AGPM, a user must be granted permissions over all GPOs being compared in the report. If the Reviewer permission has been granted at the domain level, permissions are automatically granted to GPOs that are controlled in the domain.


To set up Reviewer privileges for a group in AGPM, follow these steps:

1.
In the GPMC, expand the forest node, and then expand the domain node.

2.
Select the Change Control node.

3.
Select the Controlled tab, located on the Contents tab in the details pane.

4.
Select the GPO for which you want to set up delegation.

5.
If the user or group is already listed as having the specified archive permissions for the selected GPO list, select the group or user for which you are setting up delegation. Then click Advanced to open the Permissions dialog box. Select the group or user name in the Group Or User Names list, and then select the Reviewer check box in the Allow column.

6.
To add members, click Add, and then select the user or group in the Select User, Computer, or Group dialog box, setting up the Reviewer delegation after adding the object.

7.
To remove a member, select the member, and then click Remove.

A user granted these permissions will be able to view the following, as shown in Figure 2:

  • Settings report

  • Difference report

  • GPO history

Figure 2. The Reviewer permission includes the ability to view the settings of a GPO.

Other  
  •  Windows Server 2008 and Windows Vista : Advanced Group Policy Management Delegation - Full Control, Editing
  •  Windows Server 2008 and Windows Vista : Group Policy Management Console Delegation - Modeling GPOs, RSoP of GPOs
  •  Windows Server 2008 and Windows Vista : Group Policy Management Console Delegation - Managing GPOs, Editing GPOs
  •  Windows Server 2008 and Windows Vista : Group Policy Management Console Delegation - Linking GPOs
  •  Windows Server 2008 and Windows Vista : Group Policy Management Console Delegation - Creating GPOs
  •  Windows Server 2008 and Windows Vista : Security Delegation for Administration of GPOs - Default Security Environment
  •  Programming WCF Services : Security - Intranet Application Scenario (part 7) - Identity Management, Callbacks
  •  Programming WCF Services : Security - Intranet Application Scenario (part 6) - Authorization
  •  Programming WCF Services : Security - Intranet Application Scenario (part 5) - Impersonation - Impersonating all operations, Restricting impersonation
  •  Programming WCF Services : Security - Intranet Application Scenario (part 4) - Impersonation - Manual impersonation , Declarative impersonation
  •  
    Most View
    Spring Is Here (Part 2)
    Is 802.11ac Worth Adopting?
    BlackBerry Z10 - A Touchscreen-Based Smartphone (Part 1)
    LG Intuition Review - Skirts The Line Between Smartphone And Tablet (Part 5)
    Fujifilm X-E1 - A Retro Camera That Inspires (Part 4)
    My SQL : Replication for High Availability - Procedures (part 6) - Slave Promotion - A revised method for promoting a slave
    10 Contenders For The 'Ultimate Protector' Crown (Part 3) : Eset Smart Security 6, Kaspersky Internet Security 2013, Zonealarm Internet Security 2013
    HTC Desire C - Does It Have Anything Good?
    Windows Phone 7 : Understanding Matrix Transformations (part 2) - Applying Multiple Transformations
    How To Lock Windows By Image Password
    REVIEW
    - First look: Apple Watch

    - 10 Amazing Tools You Should Be Using with Dropbox
    VIDEO TUTORIAL
    - How to create your first Swimlane Diagram or Cross-Functional Flowchart Diagram by using Microsoft Visio 2010 (Part 1)

    - How to create your first Swimlane Diagram or Cross-Functional Flowchart Diagram by using Microsoft Visio 2010 (Part 2)

    - How to create your first Swimlane Diagram or Cross-Functional Flowchart Diagram by using Microsoft Visio 2010 (Part 3)
    Popular Tags
    Microsoft Access Microsoft Excel Microsoft OneNote Microsoft PowerPoint Microsoft Project Microsoft Visio Microsoft Word Active Directory Biztalk Exchange Server Microsoft LynC Server Microsoft Dynamic Sharepoint Sql Server Windows Server 2008 Windows Server 2012 Windows 7 Windows 8 Adobe Indesign Adobe Flash Professional Dreamweaver Adobe Illustrator Adobe After Effects Adobe Photoshop Adobe Fireworks Adobe Flash Catalyst Corel Painter X CorelDRAW X5 CorelDraw 10 QuarkXPress 8 windows Phone 7 windows Phone 8 BlackBerry Android Ipad Iphone iOS
    Top 10
    OPEL MERIVA : Making a grand entrance
    FORD MONDEO 2.0 ECOBOOST : Modern Mondeo
    BMW 650i COUPE : Sexy retooling of BMW's 6-series
    BMW 120d; M135i - Finely tuned
    PHP Tutorials : Storing Images in MySQL with PHP (part 2) - Creating the HTML, Inserting the Image into MySQL
    PHP Tutorials : Storing Images in MySQL with PHP (part 1) - Why store binary files in MySQL using PHP?
    Java Tutorials : Nested For Loop (part 2) - Program to create a Two-Dimensional Array
    Java Tutorials : Nested For Loop (part 1)
    C# Tutorial: Reading and Writing XML Files (part 2) - Reading XML Files
    C# Tutorial: Reading and Writing XML Files (part 1) - Writing XML Files