Domain Controller
Before updating the templates, you should remove the existing .adm templates and then proceed updating the templates.
To remove the administrative templates on Domain Controller
- Open the Group Policy Management (gpmc.msc).
- Right click on the GPO you have created, set Enforced to disable.
- Again, right click on the GPO, and on the shortcut menu, click Edit.
Group Policy Management Editor opens.
- In the left pane (console tree) of Group Policy Management Editor, expand Computer Configuration\Policies.
- Right-click the Administrative Templates node, and then click Add/Remove Templates.
- In the Add/Remove Templates dialog box, select DefenderGroupPolicy.adm and DefenderBindingGroupPolicy.adm files and click Remove.
To update the administrative templates on Domain Controller
- Navigate to %windir%\SYSVOL\sysvol\<DomainName>\Policies directory.
- Create a folder PolicyDefinitions and copy the DefenderGroupPolicy.admx file into this folder.
- In the PolicyDefinitions folder, create a language specific folder, such as en-US, and then copy the DefenderGroupPolicy.adml file into this folder.
- Open the Group Policy Management Editor and navigate to the Computer Configuration\Administrative Templates\One Identity\Defender directory to see the policy settings.
|
NOTE: Make sure that the policy configuration settings are retained after updating into .admx templates in the Group Policy Management Editor. |
- Right click the GPO in Group Policy Management, and then click Enforced to enable.
Client computer
To remove the administrative templates on client computer
- Open the Group Policy Management Editor (gpedit.msc).
- Expand Computer Configuration\Policies.
- Right-click the Administrative Templates node, and then on the shortcut menu, click Add/Remove Templates.
- In the Add/Remove Templates dialog box, select DefenderGroupPolicy.adm and DefenderBindingGroupPolicy.adm files and click Remove.
To update the administrative templates on client computer
- Copy the DefenderGroupPolicy.admx file into %windir%\PolicyDefinitions folder directory.
- Copy the DefenderGroupPolicy.adml file into %windir%\PolicyDefinitions\en-us directory.
- Open the Group Policy Management Editor and navigate to the Computer Configuration\Administrative Templates\One Identity\Defender directory to see the policy settings
|
NOTE: Make sure that the policy configuration settings are retained after updating into .admx templates in the Group Policy Management Editor. |
Integration with Active Roles
The Defender installation package includes the Defender Integration Pack for Active Roles which extends the Active Roles functionality and allows you to perform Defender-related tasks from within the Active Roles console (MMC Interface) and the Active Roles Web Interface. For example, with this Integration Pack installed, you can assign, remove, test, recover, and program tokens, set Defender IDs and Defender passwords. Also you can enable the automatic deletion of tokens for deprovisioned users and use the Active Roles console to administer Defender objects and delegate specific Defender roles or tasks to the users you want.
Active Roles offers a practical approach to automated user provisioning and administration, for maximum security and efficiency. Active Roles provides total control of user provisioning and administration for Active Directory. For more information about Active Roles, please go to https://www.oneidentity.com/products/active-roles/.
NOTE: Always install OS with Native English language option. For any other language, add Language Pack [e.g German, French] to make Defender appear in ARS web console.
Installing Defender Integration Pack for Active Roles
Before installing the Defender Integration Pack for Active Roles, make sure the target system meets the system requirements listed in the Defender Release Notes.
To install the Defender Integration Pack for Active Roles
- On the target computer, run the ActiveRolesIntegrationPack.exe file supplied in the Defender installation package.
- Step through the Setup Wizard to complete the Integration Pack installation.
In the Setup Wizard, you can select the following features for installation:
- Active Roles Web Interface Extension Install this feature to be able to perform Defender-related tasks from the Active Roles Web Interface. The computer on which you plan to install this feature must have the Active Roles Web Interface installed. For more information about the commands this feature adds to the Active Roles Web Interface, see Commands added to the Active Roles Web Interface.
- Active Roles Console Extension Install this feature to be able to perform Defender-related tasks from the Active Roles console (MMC Interface). After installing this feature, you can use the Active Roles console to manage Defender-related objects and perform Defender-related tasks. The steps you should perform in the Active Roles console to manage Defender objects are identical to those you perform in Microsoft’s Active Directory Users and Computers tool.For more information, see Managing Defender objects in Active Directory.
- After completing the Setup Wizard, restart the Active Roles Administration Service on the computer on which you have installed the Integration Pack.
- On each remote computer running the Active Roles Administration Service in your environment, install the Defender Integration Pack for Active Roles Administration Service.
To install the Defender Integration Pack for Active Roles Administration Service, run the ActiveRolesAdminServiceIntegrationPack.exe file supplied in the Defender installation package, and then complete the wizard.