?
Solved

How to Cleanup the Policies folder in Sysvol

Posted on 2007-11-15
7
Medium Priority
?
1,994 Views
Last Modified: 2012-08-13
I have group policy folders in my sysvol folder that are not being used.  When I look in AD and list all the policies, those appear to be deleted.  Is there a tool that would compare the two and delete the ones that are no longer being used?
0
Comment
Question by:securitythreat
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
7 Comments
 
LVL 57

Expert Comment

by:Pete Long
ID: 20288750
Stop are you sure they are not in use? you will have two that are in use the default domain an default domain controllers policy (the domain policy starts 31B2F.....) Load the group policy management console and backup your policies before you delete anything
0
 
LVL 57

Accepted Solution

by:
Pete Long earned 2000 total points
ID: 20288761
Get Gpotool.exe from the resource kit and it will tell you what policy is doing what.

GPOTool.exe: Group Policy Verification Tool
Category
Group Policy Verification tool is included in the Windows Server 2003 Deployment Kit.

Version compatibility
The Group Policy Verification tool works on Windows 2000 and higher computers. You use Group Policy Verification tool to check the health of the Group Policy objects on domain controllers. The tool checks GPOs for consistency on each domain controller in your domain. The tool also determines whether the policies are valid and displays detailed information about replicated Group Policy objects (GPOs).

GPOTool.exe ships with the Microsoft Windows 2003 Server Resource Kit and is also available as a free download at the Gpotool.exe: Group Policy Verification Tool page.

For more information about the Group Policy Verification tool, type GPOTool /? at the command line. You can find full documentation for Group Policy Verification tool in the Windows Server 2003 Deployment Kit Tools.

http://technet2.microsoft.com/windowsserver/en/library/e926577a-5619-4912-b5d9-e73d4bdc94911033.mspx?mfr=true
0
 
LVL 1

Author Comment

by:securitythreat
ID: 20288764
I have policies.  They were deleted.  The DC they were deleted from was having FRS issues.  The deletions showed up in ad across the board.  However, the policies folder did not delete the policies out of there.  The FRS issue led to a authoritive restore to resolve.  Once the restore was completed, replication continued.  However, the restore replicated all the old folders.  As a result, the policies deleted in AD but show up in the folder.
0
Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

 
LVL 1

Author Comment

by:securitythreat
ID: 20288782
Once identified, is it ok to manually delete the folders of the un-used gpo's?
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 20288959
Yes - you can manually delete them straight from the sysvol/domainname/policys folder  - if they error when you try and delete them you might need to mess about with dcscalcs but we will cross that bridge when we come to it :)

Pete
0
 
LVL 1

Author Comment

by:securitythreat
ID: 20289063
Ok... right now they are mismatched... so trying to figure that out... thanks for your help all
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 20289153
ThanQ
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Here's a look at newsworthy articles and community happenings during the last month.
Compliance and data security require steps be taken to prevent unauthorized users from copying data.  Here's one method to prevent data theft via USB drives (and writable optical media).
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
Suggested Courses

800 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question