Group Policy
Vertex lists every Group Policy Object of the domain, shows where it
is linked and its full settings report, and changes GPOs through the
GroupPolicy PowerShell module on the domain controller. Group Policy is
for Tenant admins only (reading included). Changes need the GPOs
write switch and --gpo on in the connector's guard;
deleting also needs deletes on both sides.
The API calls are given in brackets (Vertex API).
Listing GPOs
The GPO list (GET /tenants/{tenantID}/gpos, searchable with q) shows
each GPO's name, status, comment, owner, WMI filter, creation and change
times, user and computer versions, how many links it has, and builtin
for the two default domain policies. A GPO's detail
(GET …/gpos/{gpoID}) adds its links: the OU (or domain), whether the
link is enabled and enforced, its order, and whether the OU is in scope.
The report
GET …/gpos/{gpoID}/report returns the last XML report of the GPO
(Get-GPOReport -ReportType Xml): every setting, including those Vertex
does not edit (security settings, scripts, preferences).
POST …/gpos/{gpoID}/report reads it from the domain controller again;
large reports arrive in parts, and complete turns true when all have
arrived.
Creating, renaming, deleting
| Action | Details |
|---|---|
Create (POST …/gpos) | A name (at most 255 characters), an optional comment (2,048) and optionally an OU to link it to at once (link_to, a managed OU or below one). The AD account becomes its owner. |
Change (PATCH …/gpos/{gpoID}) | Rename it, change its comment, or its status: AllSettingsEnabled, UserSettingsDisabled, ComputerSettingsDisabled, AllSettingsDisabled. The GPO is backed up first. |
Delete (DELETE …/gpos/{gpoID}) | Needs a step-up (X-Step-Up-Token) and the deletes switch. The GPO is backed up first; if the backup fails, nothing is deleted. Deleting a GPO also removes its links. |
Links
POST …/gpos/{gpoID}/links changes the GPO's link on one OU (or the
domain object), given by target_dn, which must be a managed OU or
below one:
action | Effect |
|---|---|
link | Links the GPO there, optionally with enabled, enforced and order. |
set | Changes an existing link: enabled, enforced, order. |
unlink | Removes the link (no options). |
order is 1 to 1,000; 1 has the highest precedence on that OU.
enforced makes the link apply even below OUs that block inheritance.
A disabled link stays in place but does not apply.
Registry-based settings
POST …/gpos/{gpoID}/registry sets and removes registry-based policy
settings (Set-GPRegistryValue, Remove-GPRegistryValue): the
Administrative Templates settings and any other value under the policy
keys. Up to 100 values per request (set and remove together); each
counts as one change. The GPO is backed up first.
Each value:
| Field | Meaning |
|---|---|
scope | computer (HKLM, Computer Configuration) or user (HKCU, User Configuration). |
key | The key without the hive, for example Software\Policies\Microsoft\Windows\Personalization. Single backslashes, at most 1,024 characters. |
value_name | The value's name (at most 255 characters). |
type | For set: String, ExpandString, DWord, QWord, MultiString or Binary. |
value | For set, in the format of its type (below). |
| Type | value format |
|---|---|
String, ExpandString | The text (up to 16 KiB). ExpandString keeps %variables% for the client to expand. |
DWord, QWord | A decimal number, digits only (1, 4294967295); no hex, no sign. |
MultiString | One string per line (separated by line breaks). |
Binary | Hexadecimal bytes without separators, for example 01a0ff (up to 4,096 bytes). |
{
"set": [
{ "scope": "computer", "key": "Software\\Policies\\Microsoft\\Windows\\Personalization",
"value_name": "NoLockScreen", "type": "DWord", "value": "1" }
],
"remove": [
{ "scope": "user", "key": "Software\\Policies\\Microsoft\\Windows\\Explorer", "value_name": "NoUninstallFromStart" }
]
}
In remove, an empty value_name removes every value under the key.
Settings that are not registry-based (security settings, scripts,
software installation, preferences) are shown in the report but not
changed by Vertex.
Security filtering and delegation
POST …/gpos/{gpoID}/permissions sets one trustee's permission on the
GPO (Set-GPPermission):
| Field | Meaning |
|---|---|
trustee | A user, group or computer by name (DOMAIN\name or name). |
trustee_type | User, Group or Computer. |
level | See below. |
replace | Lower an existing higher permission to this level (default: only raise). |
level | Meaning |
|---|---|
GpoApply | Read and apply the GPO: security filtering. |
GpoRead | Read only (not applied). |
GpoEdit | Edit the settings. |
GpoEditDeleteModifySecurity | Edit, delete and change permissions. |
None | Remove the trustee from the GPO. |
To apply a GPO to one group only: give that group GpoApply, then set
Authenticated Users to GpoRead with replace. Keep read access for
Authenticated Users (or Domain Computers): computers must be able to read
a GPO to process it.
Backups
POST …/gpos/{gpoID}/backup backs the GPO up on the domain controller,
and Vertex does the same automatically before every change of a GPO's
name, status, comment or registry settings and before deleting it. The
backups are in %ProgramData%\Entrosity\Vertex GPO Backups on the domain
controller, with a comment such as Entrosity Vertex: before delete; an
operation's result carries the backup's ID (backup_id). Restore them on
the domain controller with the Group Policy Management Console (Manage
Backups) or Restore-GPO. Vertex does not restore backups and does not
remove old ones.
The default domain policies
The Default Domain Policy ({31B2F340-016D-11D2-945F-00C04FB984F9})
and the Default Domain Controllers Policy
({6AC1786C-016F-11D2-945F-00C04FB984F9}) are read-only in Vertex:
renaming, changing their status or settings, their permissions and
deleting them are refused (protected), both by Vertex and on the domain
controller. They are listed and their reports can be read and backed up.
Change the domain's password and lockout policy there with the Group
Policy Management Console, or use
fine-grained password policies.