[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1210
  • Last Modified:

AD GPO settings migration

Hi,

My network is nicely setup and Group Policies are used extensively like everyone else no doubt. IS there a way to migrate Group Policies to a new server on a new network (to 2008 nserver maybe) or some way of easily doucumenting all the settings?

Many thanks
0
leegclystvale
Asked:
leegclystvale
  • 3
1 Solution
 
Pete LongConsultantCommented:
Use the group policy management console you can back up and restore policies with it
0
 
leegclystvaleAuthor Commented:
Thanks Pete. To a new server totally? new network? windows 2003 to 2008 server?
0
 
tigermattCommented:

Hey!

Be careful here. You're trying to migrate GPOs across to a brand new domain, and across different Operating Systems too. Server 2003 and 2008 use different methods to display the policies to you, changing from ADM files in 2003 and below to ADMX files (XML based - just like Microsoft's revamp in Office 2007's file formats) in Vista and Server 2008.

You may be able to backup and restore your policies using the GPMC, but I wouldn't recommend it primarily as a result of the different network operating systems. You will more than likely run into issues, and of course the last thing you want is to have Group Policy not work, causing security issues on your network.

The other problem you will find is unless you have extensive documentation of every GPO change, you will probably find references to servers and other locations on the old network, which would all need to be sifted through and updated or removed, and security identifiers (SIDs) for references users and groups will also be different, potentially causing issues with Active Directory.

My suggestion would be to take the approach of rebuilding GPO from scratch. It's not the nicest of jobs, I know, but I always do it, since the volume of issues you could be hit with just seems stupid to try and play with them for a day to get them to migrate, when you can re-create and re-configure them in half that time.

-Matt
0
 
leegclystvaleAuthor Commented:
Thanks Petelong and Tigermatt.
I'll award the points to tigermatt as he has pointed out the disadvantages of your solution and they seem quite extensive to me anyway. Appreciate the suggestion as a possibility.
Thanks for a great response tigermatt
0
 
leegclystvaleAuthor Commented:
Good logic matt. Thanks for your time.
0

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

  • 3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now