programming4us
programming4us
SECURITY

Windows Server 2008 and Windows Vista : Advanced Group Policy Management Delegation - Approving, Reviewing

- Free product key for windows 10
- Free Product Key for Microsoft office 365
- Malwarebytes Premium 3.7.1 Serial Keys (LifeTime) 2019

1. Approving

Only users who have been granted the Approver permission will be able to perform some of the more advanced actions in AGPM. The ability to create a new GPO and the ability to deploy a GPO to the production environment are both examples of tasks that require the Approver permission, such as approving a pending GPO, as shown in Figure 1.

Figure 1. A pending GPO requires that someone with the Approver permission either approve it or reject it.

To set up Approver permission or a group in AGPM, follow these steps:

1.
In the GPMC, expand the forest node, and then expand the domain node.

2.
Select the Change Control node.

3.
Select the Controlled tab, located on the Contents tab in the details pane.

4.
Select the GPO for which you want to set up delegation.

5.
If the user or group is already listed as having the specified archive permissions for the selected GPO list, select the group or user for which you are setting up delegation. Then click Advanced to open the Permissions dialog box. Select the group or user name in the Group Or User Names list, and then select the Approver check box in the Allow column.

6.
To add members, click Add, and then select the user or group in the Select User, Computer, or Group dialog box, setting up the Approver delegation after adding the object.

7.
To remove a member, select the member, and then click Remove.

When you select the Approver check box, the Reviewer check box is also selected because it is a required permission for approving GPOs in AGPM. The Approver permission includes:

  • Create GPO

  • List Contents

  • Read Settings

  • Delete GPO

  • Deploy GPO

After a user has been granted the Approver permission, his or her level of control over GPOs depends on whether the permission was granted at the domain level or the individual GPO level. If granted at the domain level, under the Domain Delegation tab, the user can approve any GPO that is brought into AGPM.

2. Reviewing

One of the benefits of AGPM is the ability to provide users with the option to see the settings in the GPOs, but not alter them in any way. Individuals such as managers, IT administrators (not related to Group Policy), and Help desk personnel can see the GPO settings and even compare two GPOs by using difference reporting.

Note

To compare two GPOs, or to compare a GPO to a template, using difference reporting in AGPM, a user must be granted permissions over all GPOs being compared in the report. If the Reviewer permission has been granted at the domain level, permissions are automatically granted to GPOs that are controlled in the domain.


To set up Reviewer privileges for a group in AGPM, follow these steps:

1.
In the GPMC, expand the forest node, and then expand the domain node.

2.
Select the Change Control node.

3.
Select the Controlled tab, located on the Contents tab in the details pane.

4.
Select the GPO for which you want to set up delegation.

5.
If the user or group is already listed as having the specified archive permissions for the selected GPO list, select the group or user for which you are setting up delegation. Then click Advanced to open the Permissions dialog box. Select the group or user name in the Group Or User Names list, and then select the Reviewer check box in the Allow column.

6.
To add members, click Add, and then select the user or group in the Select User, Computer, or Group dialog box, setting up the Reviewer delegation after adding the object.

7.
To remove a member, select the member, and then click Remove.

A user granted these permissions will be able to view the following, as shown in Figure 2:

  • Settings report

  • Difference report

  • GPO history

Figure 2. The Reviewer permission includes the ability to view the settings of a GPO.

Other  
  •  Windows Server 2008 and Windows Vista : Advanced Group Policy Management Delegation - Full Control, Editing
  •  Windows Server 2008 and Windows Vista : Group Policy Management Console Delegation - Modeling GPOs, RSoP of GPOs
  •  Windows Server 2008 and Windows Vista : Group Policy Management Console Delegation - Managing GPOs, Editing GPOs
  •  Windows Server 2008 and Windows Vista : Group Policy Management Console Delegation - Linking GPOs
  •  Windows Server 2008 and Windows Vista : Group Policy Management Console Delegation - Creating GPOs
  •  Windows Server 2008 and Windows Vista : Security Delegation for Administration of GPOs - Default Security Environment
  •  Programming WCF Services : Security - Intranet Application Scenario (part 7) - Identity Management, Callbacks
  •  Programming WCF Services : Security - Intranet Application Scenario (part 6) - Authorization
  •  Programming WCF Services : Security - Intranet Application Scenario (part 5) - Impersonation - Impersonating all operations, Restricting impersonation
  •  Programming WCF Services : Security - Intranet Application Scenario (part 4) - Impersonation - Manual impersonation , Declarative impersonation
  •  
    Top 10
    Free Mobile And Desktop Apps For Accessing Restricted Websites
    MASERATI QUATTROPORTE; DIESEL : Lure of Italian limos
    TOYOTA CAMRY 2; 2.5 : Camry now more comely
    KIA SORENTO 2.2CRDi : Fuel-sipping slugger
    How To Setup, Password Protect & Encrypt Wireless Internet Connection
    Emulate And Run iPad Apps On Windows, Mac OS X & Linux With iPadian
    Backup & Restore Game Progress From Any Game With SaveGameProgress
    Generate A Facebook Timeline Cover Using A Free App
    New App for Women ‘Remix’ Offers Fashion Advice & Style Tips
    SG50 Ferrari F12berlinetta : Prancing Horse for Lion City's 50th
    - Messages forwarded by Outlook rule go nowhere
    - Create and Deploy Windows 7 Image
    - How do I check to see if my exchange 2003 is an open relay? (not using a open relay tester tool online, but on the console)
    - Creating and using an unencrypted cookie in ASP.NET
    - Directories
    - Poor Performance on Sharepoint 2010 Server
    - SBS 2008 ~ The e-mail alias already exists...
    - Public to Private IP - DNS Changes
    - Send Email from Winform application
    - How to create a .mdb file from ms sql server database.......
    programming4us programming4us
    programming4us
     
     
    programming4us