Monitor GPO HealthTroubleshooting problems with Group Policy is a necessary art. Problems will occur, and you will need to resolve them. However, you may be able to head off Group Policy issues by monitoring GPO health. If you find problems before they are reported via user complaints, or before the lack of security enforcement results in a successful attack, all the better. To monitor GPO health, you should monitor each of these:DNSNetwork connectivityDC healthReplicationGPO-specific issues The first four items are discussed in earlier sections. You can monitor many GPO-specific issues by using the GPMonitor.exe tool and by using the reporting features of GPMC. GPMonitor.exe is a resource kit tool that creates reports when policy settings are refreshed. Policy stability and replication can be checked. To get started, run GPMonitor.exe on each DC to extract the .msi file, the help file, and the gpmonitor.adm template. The gpmon service monitors refreshes and updates info to a centralized share; the share location is set through the gpmonitor.adm template.Run the msi file on every domain controller (you can distribute the files through Group Policy) to install the gpmon service and start it. The service does not listen on the network.To add the new gpmonitor.adm template and configure gpmonitor, follow these steps:
To configure the policy do the following:
The reports and the information they provide are listed in Table 9-8. More information on GPMC scripts can be found in the %Programfiles% \gpmc\scripts\gpmc.chm file on a computer where GPMC has been installed.
|