Recommended: Click Here to Update All of Your PCs Outdated Drivers

Resultant Set of Policies

On Overview on Resultant Set of Policies (RSoP)

Group Policy Objects (GPOs) containing Group Policy settings can be linked to sites, domains, and organizational units (OUs), so that they are applied to user objects or computer objects located in the particular site, domain, or OU in Active Directory. Because of numerous Group Policy settings that exist, and the flexibility of group policies, Group Policy management can be an intricate task. GPOs can be linked, filtered, inherited and blocked, and are cumulative when they are applied to the local computer, site, domain or OU.
Resultant Set of Policy (RSoP) actually refers to the sum of all group policies which are applied to a user and computer. This includes all filters and exceptions. Exceptions are the No Override option and Block Policy Inheritance option. As you can see, just determining the Resultant Set of Policy of a particular user or computer can be an overwhelming experience. To simplify group policy management, and to simplify the process of determining the RSoP of a user or computer, Windows Server 2003 includes the Resultant Set of Policy feature for this purpose. What this means is that you can create and run RSoP queries in Windows Server 2003 to find out what the RSoP of a user or computer is. Based on the information specified in the RSoP query, RSoP collects information on all existing group policies to determine the policies which are associated with a user or computer, and its effects. RSoP also determines the order in which policies are applied, and reports on its search results. You can use RSoP queries to determine what would occur when a particular user logs on to a particular computer. You can also use RSoP queries to determine what occurs with group policies if a particular user object or computer object is moved to a different OU. RSoP queries can assist with Group Policy planning and troubleshooting.

A RSoP query has the following two modes:

You can run RSoP queries on a number of different containers and objects. The objects and containers on which you can run queries are listed below:

Windows Server 2003 includes the tools listed below which can be used to generate RSoP queries:

Using the Resultant Set of Policy (RSoP) Wizard to Create RSoP Queries

The Resultant Set Of Policy Wizard included in Windows Server 2003 can be used to generate RSoP queries. The Resultant Set Of Policy Wizard can be used to determine the effects of existing group policies on users and computers. You can also use the wizard when planning your Group Policy implementation strategy for your organization. The two modes which you can choose between when running the Resultant Set Of Policy Wizard are discussed in more detail next.

The ways in which you can create a RSoP query using planning mode or logging mode are listed below:

RSoP Planning Mode
If you are busy planning a Group Policy implementation, or restructuring your existing design, then you should use RSoP planning mode. Planning mode enables you to query and test policy settings to determine the effects of them on users and computers. You can also use planning mode to determine how group policies behave when a user or computer is moved to a different location or to a different security group.

RSoP planning mode is typically used for the purposes listed below:

The options which are presented by the Resultant Set of Policy Wizard when the wizard runs in planning mode are listed below:

How to create a RSoP query with the Resultant Set Of Policy Wizard (Planning Mode)

  1. Click Start, Run, and enter mmc in the Run dialog box. Click OK.
  2. From the File menu, select Add/Remove Snap-In.
  3. When the Add/Remove Snap-In dialog box opens, click Add.
  4. When the Add Standalone Snap-In dialog box opens, select Resultant Set of Policy from the available list, and click Add.
  5. Click Close to close the Add Standalone Snap-In dialog box opens.
  6. Click OK in the Add/Remove Snap-In dialog box.
  7. Proceed to right-click Resultant Set of Policy in the MMC, and select Generate RSoP Data on the shortcut menu.
  8. The Resultant Set of Policy Wizard launches.
  9. Click Next on the Welcome To The Resultant Set Of Policy Wizard page.
  10. When the Mode Selection page appears, select Planning Mode. Click Next.
  11. 1
  12. On the User And Computer Selection page, proceed to enter the name of the user, and enter the name of the computer. Use the Browse button to search for a user or computer. Click Next.
  13. 1
  14. When the Advanced Simulation Options page opens, you can enable the Slow Network Connection checkbox, enable the Loopback Processing checkbox, and select the site which RSoP should use in the Site list. Click Next.
  15. 1
  16. The Alternate Active Directory Paths page allows you to set a different OU for the user and computer which you have previously selected. Click Next.
  17. 1
  18. The User Security Groups page displays the security groups to which the user is a member of and enables you to select additional groups or remove groups to ascertain what changes will take place. Click Next.
  19. 1
  20. On the Computer Security Groups page choose additional groups, or remove groups to determine what changes will take place. Click Next.
  21. 1
  22. On the WMI Filters for Users page choose which WMI filters to utilize on the user in the simulation. Click Next
  23. 1
  24. On the WMI Filters for Computers page choose which WMI filters to utilize on the computer in the simulation. Click Next.
  25. When the Summary Of Selections page opens, check that the domain controller listed for the simulation is the correct one. Click the Browse button to choose a different domain controller. Click Next.
  26. After the RSoP query has been processed, a Finish page is displayed.

RSoP Logging Mode
If you want to determine what the current Group Policy settings are for a particular user account or computer account, you would need to utilize logging mode. Logging mode provides the means for you to re-examine the existing GPOs which are applied to a user or computer. You can also use logging mode to examine existing software installation applications and security for a user or computer.

RSoP logging mode is typically used for the purposes listed below:

How to create a RSoP query with the Resultant Set Of Policy Wizard (Logging Mode)

  1. Click Start, Run, and enter mmc in the Run dialog box. Click OK.
  2. From the File menu, select Add/Remove Snap-In.
  3. When the Add/Remove Snap-In dialog box opens, click Add.
  4. When the Add Standalone Snap-In dialog box opens, select Resultant Set of Policy from the available list, and click Add.
  5. Click Close to close the Add Standalone Snap-In dialog box opens.
  6. Click OK in the Add/Remove Snap-In dialog box.
  7. Proceed to right-click Resultant Set of Policy in the MMC, and select Generate RSoP Data on the shortcut menu.
  8. The Resultant Set of Policy Wizard launches.
  9. Click Next on the Welcome To The Resultant Set Of Policy Wizard page.
  10. When the Mode Selection page appears, select Logging Mode. Click Next.
  11. 1
  12. On the Computer Selection page, you can choose the This Computer option, or you can choose the Another Computer option. If you select the Another Computer option, click Browse to select the other computer.
  13. 1
  14. Enable the Do Not Display Policy Settings For The Selected Computer In the Results | Display User Policy Settings Only! checkbox if you only want to view user policy settings. Click Next.
  15. 1
  16. On the User Selection page, you can choose the Current User option, or you can choose the Select A Specific User option. If you select the Select A Specific User option, choose the user from the list.
  17. 1
  18. Enable the Do Not Display User Policy Settings In the Results | Display Computer Policy Settings Only! checkbox if you only want to view computer policy settings. Click Next.
  19. 1
  20. When the Summary Of Selections page opens, verify that the options which you chose are correct.
  21. 1
  22. Click Finish.
  23. 1
  24. To view the query results, click the folders in the RSoP console tree.

How to save RSoP queries
You can view the results of the RSoP query in the RSoP query console after you have saved it. To save a RSoP query,

  1. On the console for the RSoP query, click Save on the File menu.
  2. When the Save As dialog box opens, enter the name which you want to use in the File Name box.
  3. Click Save.
  4. The RSoP query console which you saved is now displayed in the Administrative Tools menu.

How to save the data from a RSoP query

  1. On the console for the RSoP query, right-click the computer account or the user account node, click View, and then click Archive Data In Console File on the shortcut menu.
  2. Click Save on the File menu.
  3. When the Save As dialog box opens, enter the name which you want to use in the File Name box.
  4. Click Save.
  5. The RSoP query console which contains the archived data that you saved is now displayed in the Administrative Tools menu.

How to view RSoP query results using the RSoP query console

The RSoP query console includes the different types of information listed below, which you can view:

When viewing individual policy settings, the RSoP query console contains the RSoP query results for the different policy setting types, including:

Use the steps below to view individual policy settings connected to a RSoP query.

  1. Access the appropriate RSoP query console.
  2. In the RSoP query console tree, double-click the user account or the computer account.
  3. Proceed to double-click the subfolders.
  4. The individual policy settings are displayed in the details pane of the RSoP query console.

Use the steps below to view the GPOs connected to the RSoP query.

  1. Access the appropriate RSoP query console.
  2. In the RSoP query console tree, double-click the user account or the computer account.
  3. Right-click Computer Configuration and click Properties on the shortcut menu, or right-click User Configuration and click Properties on the shortcut menu.
  4. In the Properties dialog box for user configuration or computer configuration, on the General tab, click the Display All GPOs And Filtering Status checkbox.
  5. The GPOs connected to the RSoP query are displayed.

Use the steps below to view GPO revision information

  1. Access the appropriate RSoP query console.
  2. In the RSoP query console tree, double-click the user account or the computer account.
  3. Right-click Computer Configuration and click Properties on the shortcut menu, or right-click User Configuration and click Properties on the shortcut menu.
  4. In the Properties dialog box for user configuration or computer configuration, on the General tab, click the Display Revision Information checkbox.
  5. The information is displayed in the Revision column.

Use the steps below to view the scope of management connected to the RSoP query

  1. Access the appropriate RSoP query console.
  2. In the RSoP query console tree, double-click the user account or the computer account.
  3. Right-click Computer Configuration and click Properties on the shortcut menu, or right-click User Configuration and click Properties on the shortcut menu
  4. In the Properties dialog box for user configuration or computer configuration, on the General tab, click the Display Scope Of Management checkbox.
  5. The information is displayed in the Scope Of Management column.

Using the Gpresult Command-line Utility to Create RSoP Queries

You can use the Gpresult command-line utility to create a RSoP query using the command line, and to display an RSoP query. The information which Gpresult can provide is listed below:

The syntax of the Gpresult command and its parameters are listed below:

gpresult [/s computer [/u domain\user /p password]] [/user username] [/scope {user|computer}] [/v] [/z]

Using the Advanced System Information-Policy Tool to Create RSoP Queries

The Advanced System Information-Policy tool can be used to create an RSoP query. You can view the RSoP query results in a HTML report which is displayed in the Help And Support Center window. You can choose to print the report, or you can save the report to a.htm file. The RSoP query results in this case is acquired from RSoP logging mode for the user currently logged on to the computer from which the RSoP query is performed. The information displayed in the HTML report is listed below:

Use the steps below to create a RSoP query using the Advanced System Information-Policy Tool

  1. Click Start, and click Help And Support.
  2. In Support Tasks, proceed to click Tools.
  3. When the Tools pane opens, click Advanced System Information in Help And Support Center Tools.
  4. Click View Group Policy Settings Applied in Advanced System Information.
  5. The Group Policy results are displayed.

How to delegate control of RsoP

You can delegate administrative control of the RSoP Wizard to specific users so that they can create RSoP queries. To delegate control of RSoP, you have to be a member of the Enterprise Admins group.

Use the steps below to delegate control of RSoP to specific users

  1. Click Start, Administrative Tools, and click Active Directory Users And Computers.
  2. In the console tree, navigate to the domain or OU for which you want to delegate control of RSoP.
  3. Right-click the domain or OU, and then choose Delegate Control from the shortcut menu.
  4. The Delegation Of Control Wizard launches.
  5. Click Next on the Welcome To The Delegation Of Control Wizard page.
  6. When the Users Or Groups page opens, click Add.
  7. On the Select Users, Computers, Or Groups dialog box, enter the names of the users or groups who should be able to create RSoP queries. Click OK. Click Next.
  8. When the Tasks To Delegate page appears, click Delegate The Following Common Tasks. You can select one of, or both of the following checkboxes:
    • Generate Resultant Set Of Policy (Logging) checkbox
    • Generate Resultant Set Of Policy (Planning) checkbox
    Click Next.
  9. Verify that you chose the correct settings on the Completing The Delegation Of Control Wizard page.
  10. Click Finish.


Top 5 Free Networking Tools

Bookmark Resultant Set of Policies

Latest Blog Posts


Copyright 2008 Tech-FAQ. All rights reserved.