Windows AD RSoP and GPO Scanning Now Available in UpGuard

By UpGuard on February 23, 2017

Filed under: Microsoft, Windows, active directory, IT management

Etcd Scanning Now Available in UpGuard

Managing complexity in heterogeneous infrastructures is a challenge faced by all enterprise IT departments, even if their environments are relegated to *NIX or Windows. In the case of the latter, UpGuard's new RSoP/GPO scanning capability streamlines remediation and compliance efforts by enabling Windows operators to easily scan and monitor the disparate security configurations of their Active Directory (AD) instances.

About RSoP/GPO

Group Policy Objects (GPOs) are used in large Windows environments to manage the security settings of AD instances, which in turn manage and organize network resource settings: user accounts, passwords, and other details. GPOs provide a centralized mechanism for managing and configuring OS instances, software applications, and user settings in the Windows AD environment—essentially defining what instances will look like and how they will function per user group.

However, in many cases multiple GPOs will be applied to an AD instance, resulting in AD settings derived from different GPOs' policies. How does an AD admin go about figuring out which settings/policies are in play? 

The answer is with Resultant Set of Policy (RSoP) reports. By running a RSoP report, an AD admin can identify which GPO policies are being applied and understand the cumulative effect a series of GPOs have on a given machine.

How does UpGuard scan RSoPs/GPOs?

RSoP enables Windows operators to understand the true state of their AD instances, but not without some elbow grease: the report generation process is typically a manual, CLI-based affair; additionally, reports must be first parsed/prepped in order to glean actionable information for remediation or compliance purposes. UpGuard's new RSoP/GPO scanning feature alleviates these difficulties by automatically ingesting and visualizing GPOs and RSoP reporting results as configuration items.

UpGuard enables AD admins to scan GPOs on AD machines as configuration items and view/manage their settings via the platform's node visualization. Similarly, UpGuard will run RSoP reports on AD machines and display the results as configuration items in the node visualization. And because they are ingested as standard IT asset configuration items, security states can be captured and enforced via policy, remediation can be automated, and compliance can be proven more easily, without breaking a sweat.

Why does this matter?

Detecting problematic issues quickly is critical for preventing costly systems downtime and data breaches. RSoP reporting provides an effective mechanism for understanding key security configurations in complex AD environments, but the results take time to generate and make actionable. UpGuard provides a way to track GPOs and RSoP reporting results as standard configuration items for ongoing monitoring and compliance reporting purposes. With this new feature, enterprises can immediately get a firm grasp of the true security/governance state of their AD machines and bring non-compliant systems back into alignment quickly and efficiently.   

Request a Free Demo

More Articles

Improved Policies Make Testing and Compliance Even Easier

It's hard to understate how valuable automated testing can be. Policies are now coupled more tightly with node scans, giving you one interface to see exactly how a node is configured, how it's changing, and how compliant it is with your operational or security standards.
Read Article >

UpGuard Policy: 10 Essential Steps For Configuring a New Server

In our previous piece, 10 Essential Steps for Configuring a New Server, we walked through some of the best practices to follow when setting up a new Linux server. But how can you tell if your server is setup correctly?
Read Article >

UpGuard 101: Managing IIS Server Configs

One of the best out-of-the-box features of UpGuard is the ability to build a policy from one configuration and apply that policy to other nodes that should match it. This gives you instant visibility of the differences in configuration between systems.
Read Article >