?
Solved

How to Cleanup the Policies folder in Sysvol

Posted on 2007-11-15
7
Medium Priority
?
2,057 Views
Last Modified: 2012-08-13
I have group policy folders in my sysvol folder that are not being used.  When I look in AD and list all the policies, those appear to be deleted.  Is there a tool that would compare the two and delete the ones that are no longer being used?
0
Comment
Question by:securitythreat
  • 4
  • 3
7 Comments
 
LVL 57

Expert Comment

by:Pete Long
ID: 20288750
Stop are you sure they are not in use? you will have two that are in use the default domain an default domain controllers policy (the domain policy starts 31B2F.....) Load the group policy management console and backup your policies before you delete anything
0
 
LVL 57

Accepted Solution

by:
Pete Long earned 2000 total points
ID: 20288761
Get Gpotool.exe from the resource kit and it will tell you what policy is doing what.

GPOTool.exe: Group Policy Verification Tool
Category
Group Policy Verification tool is included in the Windows Server 2003 Deployment Kit.

Version compatibility
The Group Policy Verification tool works on Windows 2000 and higher computers. You use Group Policy Verification tool to check the health of the Group Policy objects on domain controllers. The tool checks GPOs for consistency on each domain controller in your domain. The tool also determines whether the policies are valid and displays detailed information about replicated Group Policy objects (GPOs).

GPOTool.exe ships with the Microsoft Windows 2003 Server Resource Kit and is also available as a free download at the Gpotool.exe: Group Policy Verification Tool page.

For more information about the Group Policy Verification tool, type GPOTool /? at the command line. You can find full documentation for Group Policy Verification tool in the Windows Server 2003 Deployment Kit Tools.

http://technet2.microsoft.com/windowsserver/en/library/e926577a-5619-4912-b5d9-e73d4bdc94911033.mspx?mfr=true
0
 
LVL 1

Author Comment

by:securitythreat
ID: 20288764
I have policies.  They were deleted.  The DC they were deleted from was having FRS issues.  The deletions showed up in ad across the board.  However, the policies folder did not delete the policies out of there.  The FRS issue led to a authoritive restore to resolve.  Once the restore was completed, replication continued.  However, the restore replicated all the old folders.  As a result, the policies deleted in AD but show up in the folder.
0
What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

 
LVL 1

Author Comment

by:securitythreat
ID: 20288782
Once identified, is it ok to manually delete the folders of the un-used gpo's?
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 20288959
Yes - you can manually delete them straight from the sysvol/domainname/policys folder  - if they error when you try and delete them you might need to mess about with dcscalcs but we will cross that bridge when we come to it :)

Pete
0
 
LVL 1

Author Comment

by:securitythreat
ID: 20289063
Ok... right now they are mismatched... so trying to figure that out... thanks for your help all
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 20289153
ThanQ
0

Featured Post

 [eBook] Windows Nano Server

Download this FREE eBook and learn all you need to get started with Windows Nano Server, including deployment options, remote management
and troubleshooting tips and tricks

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Compliance and data security require steps be taken to prevent unauthorized users from copying data.  Here's one method to prevent data theft via USB drives (and writable optical media).
Active Directory can easily get cluttered with unused service, user and computer accounts. In this article, I will show you the way I like to implement ADCleanup..
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

807 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question