Q&A: Synchronization of Group Policies (GPOs) with the UCS AD Connector
Question
Are Group Policy Objects (GPOs), including their SYSVOL contents, synchronized between a UCS domain and a Microsoft Active Directory (AD) domain when using the Univention UCS AD Connector?
Answer
No. The Univention UCS AD Connector does not synchronize Group Policy Objects (GPOs) or any contents of the SYSVOL share. Synchronization is strictly limited to directory objects such as user accounts, groups, computers, containers, and organizational units.
Special Case: AD Takeover
- During an Active Directory Takeover with UCS (where Samba/AD on UCS becomes the new Domain Controller), GPOs are not migrated automatically.
- Instead, GPO objects and the related SYSVOL files must be copied separately from the AD server to UCS.
- This confirms that under normal AD Connector operation, no synchronization of GPOs occurs.