Skip to main content

Group Policy

Vertex lists every Group Policy Object of the domain, shows where it is linked and its full settings report, and changes GPOs through the GroupPolicy PowerShell module on the domain controller. Group Policy is for Tenant admins only (reading included). Changes need the GPOs write switch and --gpo on in the connector's guard; deleting also needs deletes on both sides.

The web interface is in development

The API calls are given in brackets (Vertex API).

Listing GPOs​

The GPO list (GET /tenants/{tenantID}/gpos, searchable with q) shows each GPO's name, status, comment, owner, WMI filter, creation and change times, user and computer versions, how many links it has, and builtin for the two default domain policies. A GPO's detail (GET …/gpos/{gpoID}) adds its links: the OU (or domain), whether the link is enabled and enforced, its order, and whether the OU is in scope.

The report​

GET …/gpos/{gpoID}/report returns the last XML report of the GPO (Get-GPOReport -ReportType Xml): every setting, including those Vertex does not edit (security settings, scripts, preferences). POST …/gpos/{gpoID}/report reads it from the domain controller again; large reports arrive in parts, and complete turns true when all have arrived.

Creating, renaming, deleting​

ActionDetails
Create (POST …/gpos)A name (at most 255 characters), an optional comment (2,048) and optionally an OU to link it to at once (link_to, a managed OU or below one). The AD account becomes its owner.
Change (PATCH …/gpos/{gpoID})Rename it, change its comment, or its status: AllSettingsEnabled, UserSettingsDisabled, ComputerSettingsDisabled, AllSettingsDisabled. The GPO is backed up first.
Delete (DELETE …/gpos/{gpoID})Needs a step-up (X-Step-Up-Token) and the deletes switch. The GPO is backed up first; if the backup fails, nothing is deleted. Deleting a GPO also removes its links.

POST …/gpos/{gpoID}/links changes the GPO's link on one OU (or the domain object), given by target_dn, which must be a managed OU or below one:

actionEffect
linkLinks the GPO there, optionally with enabled, enforced and order.
setChanges an existing link: enabled, enforced, order.
unlinkRemoves the link (no options).

order is 1 to 1,000; 1 has the highest precedence on that OU. enforced makes the link apply even below OUs that block inheritance. A disabled link stays in place but does not apply.

Registry-based settings​

POST …/gpos/{gpoID}/registry sets and removes registry-based policy settings (Set-GPRegistryValue, Remove-GPRegistryValue): the Administrative Templates settings and any other value under the policy keys. Up to 100 values per request (set and remove together); each counts as one change. The GPO is backed up first.

Each value:

FieldMeaning
scopecomputer (HKLM, Computer Configuration) or user (HKCU, User Configuration).
keyThe key without the hive, for example Software\Policies\Microsoft\Windows\Personalization. Single backslashes, at most 1,024 characters.
value_nameThe value's name (at most 255 characters).
typeFor set: String, ExpandString, DWord, QWord, MultiString or Binary.
valueFor set, in the format of its type (below).
Typevalue format
String, ExpandStringThe text (up to 16 KiB). ExpandString keeps %variables% for the client to expand.
DWord, QWordA decimal number, digits only (1, 4294967295); no hex, no sign.
MultiStringOne string per line (separated by line breaks).
BinaryHexadecimal bytes without separators, for example 01a0ff (up to 4,096 bytes).
{
"set": [
{ "scope": "computer", "key": "Software\\Policies\\Microsoft\\Windows\\Personalization",
"value_name": "NoLockScreen", "type": "DWord", "value": "1" }
],
"remove": [
{ "scope": "user", "key": "Software\\Policies\\Microsoft\\Windows\\Explorer", "value_name": "NoUninstallFromStart" }
]
}

In remove, an empty value_name removes every value under the key. Settings that are not registry-based (security settings, scripts, software installation, preferences) are shown in the report but not changed by Vertex.

Security filtering and delegation​

POST …/gpos/{gpoID}/permissions sets one trustee's permission on the GPO (Set-GPPermission):

FieldMeaning
trusteeA user, group or computer by name (DOMAIN\name or name).
trustee_typeUser, Group or Computer.
levelSee below.
replaceLower an existing higher permission to this level (default: only raise).
levelMeaning
GpoApplyRead and apply the GPO: security filtering.
GpoReadRead only (not applied).
GpoEditEdit the settings.
GpoEditDeleteModifySecurityEdit, delete and change permissions.
NoneRemove the trustee from the GPO.

To apply a GPO to one group only: give that group GpoApply, then set Authenticated Users to GpoRead with replace. Keep read access for Authenticated Users (or Domain Computers): computers must be able to read a GPO to process it.

Backups​

POST …/gpos/{gpoID}/backup backs the GPO up on the domain controller, and Vertex does the same automatically before every change of a GPO's name, status, comment or registry settings and before deleting it. The backups are in %ProgramData%\Entrosity\Vertex GPO Backups on the domain controller, with a comment such as Entrosity Vertex: before delete; an operation's result carries the backup's ID (backup_id). Restore them on the domain controller with the Group Policy Management Console (Manage Backups) or Restore-GPO. Vertex does not restore backups and does not remove old ones.

The default domain policies​

The Default Domain Policy ({31B2F340-016D-11D2-945F-00C04FB984F9}) and the Default Domain Controllers Policy ({6AC1786C-016F-11D2-945F-00C04FB984F9}) are read-only in Vertex: renaming, changing their status or settings, their permissions and deleting them are refused (protected), both by Vertex and on the domain controller. They are listed and their reports can be read and backed up. Change the domain's password and lockout policy there with the Group Policy Management Console, or use fine-grained password policies.