Skip to main content
Question

Active Directory Permissions to Back Up Group Policy Objects

  • March 18, 2025
  • 1 reply
  • 120 views

Forum|alt.badge.img+1

Hello!

Having just upgraded to 2024E, specifically 11.36.41, I notice the Active Directory agent now supports backups for GPO as documented here - Great. Changes in Commvault Platform Release 2024E

However, the permissions required are not particularly helpful:

  • Permissions to Back Up Group Policy Objects via PowerShell: The account must have the necessary permissions to back up GPOs using PowerShell cmdlets. By default, members of the Remote Management Users group possess these permissions.

My question is, if you don’t want the account to be a member of “Remote Management Users” or admin groups, what granular permissions can be set on the account to still achieve the backup?

 

full error:
-----

Currently whilst the backup is completing for AD as it always has, its now completing but with error “Failed to process group policy object”.
Error Code: [28:548]
Description: Failed to process group policy object. Please verify following: (1) User account configured in Active Directory connection settings is member of Remote Management Users group or has administrator permissions. (2) User account configured in Active Directory connection settings has read and write permission to job results directory.

-----

1 reply

Damian Andre
Vaulter
Forum|alt.badge.img+23

Hi ​@Rafter,

I gathered some info internally that may help with this:

To back up Group Policy Objects (GPOs) using PowerShell cmdlets, you need appropriate permissions on the Group Policy objects. Specifically, you require:

1. Minimum Permissions Required

  • Read and Backup permissions on the GPOs you want to back up.

2. Recommended Group Memberships

To successfully back up GPOs, you should be a member of one of the following groups:

  • Domain Admins (recommended)
  • Enterprise Admins
  • Group Policy Creator Owners (if you are the owner of the GPO)
  • A custom security group with at least the following permissions:
    • Read
    • List Contents
    • Read Permissions
    • Backup Group Policy Objects

Reply


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings