AD Tripwires - Removing Domain Policy
Note: Removing the Domain Policy does not fully remove AD Tripwires. Additional steps are required to clean up tripwire accounts, agent configuration, and related infrastructure.
Edit existing policy to configure removal of scheduled task
- Open Group Policy Management Console (
gpmc.msc
) - Locate the existing
H3 IoA Policy
object inside theGroup Policy Objects
container. -
Right click on the policy object and click the Edit option from the context menu.
-
Once the
Group Policy Management Editor
opens, use the sidebar to navigate toComputer Configuration
->Preferences
->Control Panel Settings
->Scheduled Tasks
-
Right click on the scheduled task in the list. Click Properties from the context menu.
-
Once the Scheduled Task Properties Dialog window opens, navigate to the
General
tab if it isn't there already. -
Change the
Action
dropdown fromReplace
toDelete
. -
Click Apply and then OK.
- Close the
Group Policy Management Editor
window. -
ATTENTION: Wait for group policy to replicate to all domain controllers
Typical Timeframes
Small domains (1-10 DCs): 15 minutes to 1 hour
Medium enterprises (10-50 DCs): 1-4 hours
Large enterprises (50+ DCs): 2-8 hours
Very large/global enterprises: 8-24 hours
You can also run gpupdate /force
on individual domain controllers to force an immediate Group Policy refresh.
- Spot check domain controllers to verify that scheduled task has been removed
Remove Group Policy Object
Once the GPO has replicated and removed the scheduled task from all domain controllers, the group policy itself can be unlinked and removed.
- Open Group Policy Management Console (
gpmc.msc
) -
Locate the
H3 IoA Policy
link under theDomain Controllers
OU and right click on the link and select Delete from the context menu. -
Locate the
H3 IoA Policy
object under theGroup Policy Objects
container. Right click on the policy object and select Delete from the context menu.