Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


November 2007

3 Tools to Manage Group Policy

These products vary in approach, but all function well when change management is integral to the environment
RSS
Subscribe to Windows IT Pro | See More Products / Software Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

The first subfolder stores Active Templates, which are similar to the Delegation Wizard that first debuted in Windows 2000. The ADBackups folder stores exactly what it describes: AD backups. GPO History is a feature that displays the names of everyone who changed a Group Policy and the date the changes were made. Both Group Policy Administrator and GPOADmin have a similar structure, but I liked how Active Administrator made the information easy to find.

Like Group Policy Administrator, Active Administrator has a GPO repository, which Figure 3 shows. But the Active Administrator Group Policy Offline Repository is stored in a folder structure, rather than on a database. This is the KISS (Keep It Simple Stupid) principle at its best—no database requirement or additional administrative overhead.

Testing Active Administrator
I read the “Administrators Guide,” familiarized myself with the product, and then ran through the mock change-management process. When I took a backup of the default domain policy, I immediately noticed a difference with this tool: When you right-click the policy name in the GUI and choose Backup, you have a number of choices:

  1. Backup Security Group Filters
  2. Backup Group Policy Links
  3. Save a GPO Report
  4. Generate Log File
  5. Add additional Group Policies to backup
  6. Schedule the backup

A simple backup and restore mechanism is a necessity for products of this type, but these advanced features set Active Administrator apart from the others.

I then copied the GPO to an offline area by using the Add to Offline Repository menu item. Once the GPO is in the repository it can be checked out, edited, and checked back in. The process is almost identical to Group Policy Administrator except that Active Administrator doesn’t prompt you to add notes.

When it comes to auditing what has happened with Group Policy, Active Administrator has a clear lead on the competition. By using an Active Administrator agent on each DC, you can keep a close eye on who’s doing what with Group Policy. In addition to Group Policy changes, Active Administrator will let you know who has reset a password, deleted a user, and performed other administrative actions. You can capture, track, and report on more than 80 security events. If your company requires you to audit whether Group Policy follows your change-control process, then Active Administrator is the clear choice for your environment.

Active Administrator’s tabbed interface is extremely easy to master. Each area is clearly labeled, and I found Active Administrator the easiest tool to hit the ground running with. However, added features that are outside the scope of Group Policy management make Active Administrator an expensive option.

Reviewing the Pros and Cons
All three products do a good job of improving the Group Policy management process, but each does so in a different way. Group Policy Administrator and Active Administrator both use an offline repository to let you work on GPOs in an offline environment. Group Policy Administrator stores its repository in a SQL Server database. Active Administrator uses a file system as an offline repository. GPOADmin, in contrast, is an extension of GPMC and doesn’t use a repository at all. Instead, GPOADmin backs up a GPO automatically before you start editing and after you finish editing. This tool is geared toward customers who don’t want to modify existing GPOs by following the model that says you replicate an existing GPO, make changes to it, and when you’re ready to deploy it, link it where the existing GPO is and then remove the links to the old GPO. GPOADmin’s approach is different because the product satisfies a different set of customer requirements.

All three products require a back-end database. Group Policy Administrator’s repository is in SQL Server. GPOADmin’s database stores backups and old versions of live, production GPOs in its database. Active Administrator’s database stores security events such as editing, adding, or deleting GPOs, as well as other security-related events.

The look and feel of each product is unique. Group Policy Administrator looks like an extension of GPMC, whereas GPOADmin really is an extension of this Microsoft tool. Active Administrator doesn’t look like either Group Policy Administrator or GPOADmin but resembles the properties of a User object in AD with its tabbed layout.

The reporting capabilities of each product were similar. All three of these tools will help you find the similarities and differences between GPOs.

My Bottom Line
If you administer Group Policy in a medium to large company, then you’re probably familiar with the frustration of not having the tools you need to manage Group Policy in a change-control environment. All three of these products can help you get your GPOs organized in a structure that you can easily manage. NetIQ’s Group Policy Administrator and NetPro’s GPOADmin are both strong products. But because ScriptLogic’s Active Administrator had the best look and feel, was the most intuitive, and includes extra features to help manage Group Policy, I designate it my Editor’s Choice.

End of Article

   Previous  1  2  [3]  Next  


Reader Comments
Great article Eric!

There is not a wasted line of text… Meaning, you explain and lay things out so that an Admin at my level (knows enough to be dangerous) can easily follow along; as well as someone at say, Mark Minasi’s level.

There is great info for everyone, regardless of their skill level.

Keep them coming!

Tim Bolton

jsclmedave November 14, 2007 (Article Rating: )


You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Friday at PASS Europe 2006

Kevin talks about the closing day of the event and shares a funny Microsoft film. ...

The Memory-Optimization Hoax

Don't believe the hype. At best, RAM optimizers have no effect. At worst, they seriously degrade performance. ...

Escape From Yesterworld

Kevin points you to the funniest SQL Server website ever! ...


Related Articles Advanced Group Policy Management Extends Group Policy Management Console

Windows OSs Whitepapers Why SaaS is the Right Solution for Log Management

Are You Satisfied?

A Preliminary Look at Deployment Plans for Microsoft Windows Vista

Related Events Check out our list of Free Email Newsletters!

Windows OSs eBooks Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

SQL Server Administration for Oracle DBAs

Related Windows OSs Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.

Job Openings in IT


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

IT Connections
Dive into the new Microsoft platforms and products you implement and support with the experts from Microsoft, TechNet Magazine, Windows ITPro and industry gurus. There are 70+ sessions and interactive panels with networking opportunities.

Attention User Group Leaders...
Announcing the eNews Generator—a FREE HTML e-newsletter builder for user group leaders. Build your HTML and text e-newsletters in minutes and add Windows IT Pro & SQL Server Mag articles alongside your own message!.

Master SharePoint with 3 eLearning Seminars
Learn how to build a better SharePoint infrastructure and enable powerful collaboration with MVPs Dan Holme and Michael Noel. Register today!

Get SQL Server 2008 at WinConnections
Don’t miss Microsoft Exchange and Windows Connections conferences, the premier events for Microsoft IT Professionals in Las Vegas, November 10-13. Every attendee will receive a copy of SQL Server 2008 Standard Edition with one CAL.



Interested in Email Encryption?
Read about the advantages of identity-based encryption in this free report.

Order Your SQL Fundamentals CD Today!
Learn how to use SQL Server, understand Office integration techniques and dive into the essentials of SQL Express and Visual Basic with this free SQL Fundamentals CD.

Virtualization Congress Oct. 14-16 in London
Don't miss Virtualization Congress, the premiere EMEA conference dedicated to hardware, OS and application virtualization. Oct. 14-16.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technical Resources Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing