QA: Synchronization of Group Policies (GPOs) with the UCS AD Connector

Q&A: Synchronization of Group Policies (GPOs) with the UCS AD Connector

Question

Are Group Policy Objects (GPOs), including their SYSVOL contents, synchronized between a UCS domain and a Microsoft Active Directory (AD) domain when using the Univention UCS AD Connector?

Answer

No. The Univention UCS AD Connector does not synchronize Group Policy Objects (GPOs) or any contents of the SYSVOL share. Synchronization is strictly limited to directory objects such as user accounts, groups, computers, containers, and organizational units.


Special Case: AD Takeover

  • During an Active Directory Takeover with UCS (where Samba/AD on UCS becomes the new Domain Controller), GPOs are not migrated automatically.
  • Instead, GPO objects and the related SYSVOL files must be copied separately from the AD server to UCS.
  • This confirms that under normal AD Connector operation, no synchronization of GPOs occurs.