How to Compare Group Policies

1. Introduction

Lepide Auditor now features a new Group Policy Comparison Report within the web console, designed to simplify the process of identifying differences between selected Group Policies across multiple domains. This report provides users with a clear, side-by-side comparison, whether the policies are from the same domain or different domains. By enabling users to efficiently track policy changes and ensure consistency, this new tool helps maintain control over group policy settings across the network. This guide outlines the steps to generate the Group Policy Comparison Report and leverage its features for enhanced policy management.

2. Verify the Group Policy Comparison Report

2.1 Verify the New Report

  • Login to the Web Console

  • Navigate to the Auditor tile

  • Under the Group Policy tree node, confirm that Group Policy Comparison is available

Confirm Group Policy Comparison Report

3. Configure Database for GPO Backup

3.1 Configure SQL Settings

  • Go to the Settings section of the web console.

Configure Database for GPO Backup
  • Check and configure the SQL connection details for the Group Policy SQL Settings to ensure the report functions correctly.

4. Backup Group Policy

Follow the steps below to enable a Group Policy backup in the Lepide console:

  • Open the Lepide Main Console

  • Click on Settings

  • Select Component Management from the available options

A screenshot of a computer

Description automatically generated
Open the Component
  • Click on Added Domain as shown above.

  • In the right-hand panel, click on Create Group Policy Backup as shown in the image below.

Create Group Policy Back Up
  • Once clicked, the Group Policy Backup started.

Group Policy Backup Started

NOTE:    Group Policy Backup can also be scheduled. Click on Properties from the left panel click on Advanced Domain Configuration. Then select Active Directory Backup and click the side icon beside  . Backup Setting wizard will open. Select the backup timings to schedule Group Policy Backup.

A screenshot of a computer

Description automatically generated
Group Policy Backup is Successful
  • Group Policy Back up is successful

NOTE:    If you change the database from web console in SQL Configuration (Fig 2). Then you need take Group Policy Backups again following the above steps.

If you change the default location of Group Policy backup, then you need again restart LepideDSPsvc service from task manager, then take Group Policy Backups again following the above steps.

5. Steps to Configure Group Policy Comparison and Generate a Report

Follow these steps to perform a Group Policy comparison and generate the report:

  • Log in to the Lepide Web Console

image-20260413-094643.png
Web Console Login
  • Click on the Auditor tile

Web Console Homepage
  • In the left-hand navigation pane:

  • Expand the Group Policy node

  • Click on Group Policy Comparison Report

Group Policy Comparison Report

  • Click on Start Comparison

A screenshot of a computer

Description automatically generated
Group Policy Comparison Screen

  • Select the Source Domain

  • In the Source Selection Wizard:

    • Choose the Source Domain

    • Select the Group Policy Name

    • Click Next

A screenshot of a computer

Description automatically generated
Source and Domain Selection

  • Target Selection

    • Expand and select the Target Group Policy to compare

    • Choose the group policy on which the comparison should be performed

Target Selection

  • Define the Comparison Criteria

  • Choose one/multiple of the followings:

    • Similar Settings

    • Different Settings

    • Present in the source but missing in the destination

    • Present in the destination but missing in the source

  • Click Finish.

A screenshot of a computer

Description automatically generated
Define What to Compare
  • The report will be displayed

Group Policy Comparison Report


6. Export the Report to a CSV File

  • Click Export to save the report as a .CSV file.

A screenshot of a computer

Description automatically generated
Exporting the Report
  • Now open the .CSV file to view the report.

CSV File is Exported

  • Now open the .CSV file to view the report.

A screenshot of a computer

Description automatically generated
CSV View of the Report

7. Excluded Group Policy Objects Nodes

The following Group Policy Object (GPO) nodes are excluded from comparison because they contain forcefully created settings or configurations that are unique to each environment.

  • Preferences, Windows Settings

    • No nodes will be shown,

  • Windows Settings

    • Name Resolution Policy

    • Scripts Startup/Shutdown

    • Deployed Printers

  • Windows Settings, Security Settings

    • Restricted Groups

    • Registry

    • File System

    • Wired Network (IEEE 802.3) Policies

  • Windows Firewall with Advanced Security

  • Network List Manager Policies

  • Wireless Network (IEEE 802.11) Policies

  • User Configuration → Preferences

  • Policies

    • Software Settings

    • Windows Settings

  • Policies, Windows Settings, Security Settings

    • Software Restriction Policies

    • Application Control Policies

These exclusions ensure that comparison reports focus only on relevant, configurable GPO settings that have meaningful differences or similarities across environments.