?
Solved

Advanced Group Policy Management Install

Posted on 2016-07-24
3
Medium Priority
?
69 Views
Last Modified: 2016-07-25
I will be installing AGPM in our environment and account to the install guides online you need to install the application under a domain admin account but for the service account you can you a least prividge approach and added the account to the Backup Operators and GP Creator groups..

https://technet.microsoft.com/en-us/itpro/mdop/agpm/step-by-step-guide-for-microsoft-advanced-group-policy-management-40

If I am understand everything correctly one thing about the GP Creator GP is that is does not grant the user full access of already created GP but will on new GP's is this correct. If so with 100 GP's this will be a problem for me
0
Comment
Question by:compdigit44
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 17

Accepted Solution

by:
Learnctx earned 2000 total points
ID: 41726875
Yes, that is correct. In a least privilege setup the AGPM service account will not necessarily have rights to take control and manage any GPO. I am in the same position as you. With hundred's of GPO's, it can be painful. It is easy to script though; just iterate through the GPO's you want to give the AGPM account permissions for and add its group in with rights (you can also just add the account itself in instead of a group).

Set-GPPermissions -Name "GPO Name" -TargetName "Yourdomain\AGPMServiceGroup" -TargetType group -PermissionLevel GpoEditDeleteModifySecurity

Open in new window

0
 
LVL 20

Author Comment

by:compdigit44
ID: 41728573
Great Tip.. How can I dump all GP's my name to a file then have the script add the account needed to each GP?
0
 
LVL 17

Assisted Solution

by:Learnctx
Learnctx earned 2000 total points
ID: 41728635
Obviously the usual disclaimer. Test all scripts in a test lab before you unleash them upon your production environment :)

Get-GPO -All | Select -expand displayname | out-file c:\temp\allgpos.txt

Open in new window

0

Featured Post

NEW Veeam Agent for Microsoft Windows

Backup and recover physical and cloud-based servers and workstations, as well as endpoint devices that belong to remote users. Avoid downtime and data loss quickly and easily for Windows-based physical or public cloud-based workloads!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Here's a look at newsworthy articles and community happenings during the last month.
Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Suggested Courses

719 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question