Go Premium for a chance to win a PS4. Enter to Win

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 306
  • Last Modified:

Advanced Group Policy Management

Hello

I've just got a few questions on AGPM

1. Should this be installed on a completely separate server - eg no DHCP or other apps.
2. Is there a Fault Tolerance / HA functionality with AGPM - if not and the server crashes, what is the quickest way to recover AND can Group Policy still be used if AGPM is offline ?

Could you provide any MS TechNet / Best Practices links to back up the answers if possible !

Thank you for your help
0
nico-
Asked:
nico-
  • 2
  • 2
1 Solution
 
compdigit44Commented:
Inregards to you first question if you can install AGPM on a DC or DHCP server... MS States the following

 "You should install AGPM Server on a member server or domain controller with the most recent version of the GPMC that is available to you and supported by AGPM. AGPM uses the GPMC to back up and restore GPOs, and newer versions of the GPMC provide additional policy settings not available in preceding versions. If the version of the GPMC on your AGPM Server is older than the version on the computers that administrators use to manage Group Policy, the AGPM Server will be unable to store those policy settings not available in the older version of the GPMC.

http://technet.microsoft.com/en-us/library/bb767569.aspx

Personally install would install this on a small VM just to run this server . I always like to separate by server roles

I am looking still looking into your second questoin
0
 
compdigit44Commented:
So far in regards to high availibity of AGPM server is to only backup the AGPM Server Config and Archive and restore it to a new server when need...

I am still looking though

Have you thought about running this by MS support to see if they have any new recommedations
0
 
nico-Author Commented:
knew the top bit but wondered if there any significantly obviously answers / best practices rather than preferences ..
seems not !! closing as has been open waiting for answers for a good few days
0
 
nico-Author Commented:
no solution
0
 
Member_2_7971295Commented:
Hi

If you're still looking for an answer to this ... you can get some sort of failover and fault tolerance using DFSR and 2 servers. Install each server separately, using a domain account to run the service on both machines (same account on both). Stop the service on your 'standby' box.

Configure DFSR to replicate the archive between the two servers, and only ever have the service running on one machine.

You should find that you can run the service on the first server, and if for any reason it goes offline your second server can start the service successfully. The contents of the archive have been replicated to it and are up to date. The AGPM archive seems to be self contained so this is a simple solution with very little that can go wrong.

Failover isn't automatic, but you could script that if you wanted to.

It seems to work just fine to me and thus far I've not had any issues with it :)

Regards

Al
0

Featured Post

Ask an Anonymous Question!

Don't feel intimidated by what you don't know. Ask your question anonymously. It's easy! Learn more and upgrade.

  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now