At the time of GPO restoration, tombstone re-animation is automatically carried out by the GPMC. This re-animation can be successfully carried out if the following three requirements are fulfilled: The GPMC works with a domain controller that is running in Windows Server 2003.

The time interval between the deletion and restoration of the GPOs does not extend beyond the defined tombstone interval. By default, the time interval is set to 60 days. The user carrying out the restoration has the permission for tombstone reanimation.

By default, only the domain and organization administrators are given this permission. However, this permission can be given to any other person through the ACL Editor. If the tombstone re-animation fails, a new GUID is assigned to the application that is thus identified as a new application and these problems appear.

Copying of GPOs Whether GPOs should be copied between two domains or whether a GPO should be imported from one domain to another depends on the trust relationship between the domains. If the trust relationship exists, the GPOs will be copied or imported (see the following section).

The latter case is also referred to as the migration of GPOs. Since in the SBS 2003 environment there can be no trust relationships between domains, GPOs cannot be copied. Thus, copying of a GPO from the test environment to the production environment is not possible.

Import and Export of GPOs The import of GPOs is also known as migration. At the time of GPO migration, various factors have to be taken into consideration; the data is complex, it's saved in different memory locations, and some of it is domain-specific.

To migrate the domain-specific data correctly, the GPMC uses Migration Tables (see the Migration Tables section under Group Policy Management). The domain-specific data with new values for the GPO is entered in this table. During import, the settings of a GPO are transferred into an existing GPO.

These settings are sourced from the backup of the GPO. As in the case of copying, the destination GPO can either be located in the same domain or in another domain within the same forest, or it can be located in another domain of another forest. In this case, there need not be a trust relationship between the domains.

All that is needed is access to the storage location of the GPOs in the source domain from the destination domain. The GPO to which the settings are transferred retains its security settings and the links to its WMI filters.

The following steps must be carried out to import a GPO: 1. From the context menu select Import Settings to start the wizard. 2.

You can back up the updated settings, as they will be overwritten at the time of import. To select a backup, click on the Back Up button. A storage location can also be specified.

Click NEXT. 3. Select the back up folder in which the GPO to be imported is located.

If there are several GPOs, select only the desired GPO and click Next. 4. The wizard will examine the selected backup to determine if any UNC paths or security principals need to be transferred (see the following figure).

If this is the case, the transfers will be carried out with the help of the Migration Tables. If there are no transfers to be carried out, click Next. A summary will be displayed.

Figure 8.38: Checking the GPO backup for references to security principals and UNC paths An import can also be script driven. To import a GPO the script ImportGPO.wsf is used, and to import all GPOs the script ImportAllGPOs.wsf is used. These scripts are located in the GPMC\scripts folder.

wsf is used, and to import all GPOs the script ImportAllGPOs.wsf is used. These scripts are located in the GPMC\scripts folder.

