Enterprise Policy Management

Manage the lifecycle of your Group Policy Objects

Universal Policy Administrator provides an offline repository for your Group Policy change process: check-out, edit, approval and deployment as separate steps. Every version archived with a full audit trail. Its browser console allows you to manage every domain, trusted or untrusted, from a single server.
UI schematic: central window with a left navigation pane and right content, connected to three domain panels below by curved lines.
Screenshot of a policy management dashboard with left navigation, a middle versions list (Release 24, Release 23, etc.), and a right details pane titled 'Universal Policy Settings Report' showing enabled statuses.

Change Control & Audit

Edit > Approve > Deploy - with audit trail

Native Group Policy has no draft state. There is no copy under review and no staging area — there is the live object in SYSVOL, and every save is production. UPA supplies the intermediate state the tool does not have.

Every Group Policy change then follows the same sequence. Nothing reaches Active Directory until it has been checked in, approved, and deployed by users or groups designated by you.

Check Out
The policy is locked to one editor
Nobody else can change it while it is checked out. Active Directory is untouched.

Edit

Changes are made inside UPA
Settings, templates, preferences and filters are edited in the console.

Check In

A new version is created

The editor supplies a comment explaining the change. The previous version is kept, not overwritten.

Submit

The change is sent for approval

The editor submits the version with a reason - typically a change or ticket reference.

Approve

A different account signs it off

The approver reviews the change and approves or rejects it. Approval rights are separate from editing rights.

Deploy

The approved version is exported to AD

Deployment is a separate action and the only step that changes Active Directory.
Request to production  0:40 · no sound
A change raised against a ticket and awaiting approval. It is approved by a different account, and the resulting history records both steps: checked in and submitted by one account, approved by another.
  • Every version archived

    Nothing is overwritten. A full version history is maintained for documentation, rollback and comparison purposes.
  • Role-based delegation

    Each of the three main steps of the lifecycle — Edit, Approve, Export — can be assigned to different users and groups within your organization.
  • What it looked like on a given date, and who signed it off

    The two questions an auditor asks that native Group Policy cannot answer: editing a GPO discards the previous state, and approval leaves no record. Here both are read from the history, so separation of duties is evidenced rather than asserted.
  • One record across every domain

    Including domains outside your trusts, so an audit question has a single source of truth rather than one per forest.
  • Gold Policy — parent and child policies across domains

    You can create parent-child relationships between policies in different domains. Updates made to the parent policy can be synchronized out to the designated child policies, which keeps critical policies consistent across a multi-domain environment.

Delegation

Give a team authority over their own GPOs, and nothing else

Delegation in UPA consists of three components: the permitted operations within UPA, which part of your Repository they can change, and which users or groups inherit these rights.
  • Role - what they can do

    Editor, Approver, Reviewer, Deployer and Full Administrator are built in, and you can define your own. The list of allowed activities within UPA can be combined into your own custom roles.
  • View — where they can do it

    A View is a slice of your environment, created for delegation. It can be an entire domain, a collection of OUs, or any other grouping that fits your delegation model.
  • Assignment — who gets it

    An Active Directory group, plus a role, plus a view. Membership stays in Active Directory, where it is already managed.
https://upa.corp.example.com/#/administration The Administration tab: Roles, Views and Assignments, with the built-in roles Approver, Deployer, Editor, Full Administrator and Reviewer listed.
Roles, Views and Assignments on one screen, with the built-in roles ready to use and custom roles alongside them.   Click to enlarge
- roles, views and assignments, set up end to end.

AGPM Migration

AGPM support ended in April 2026.
Your change control does not have to.

Controlled editing, approval, version history and rollback all have direct equivalents in Universal Policy Administrator, and your existing versions, comments and history migrate with them. No Software Assurance, and no console to install on an administrator’s desktop.

Watch

Watch Group Policy management in action

Two short films: an introduction to Universal Policy Administrator, and a walkthrough of the console managing Group Policy across domains.

Common Questions

Group Policy management questions, answered

Next Step

Ready to elevate your policy control?

Ready to Elevate Your Policy Control?

Modernize Your Group Policy Management Today

Join leading enterprises in revolutionizing their policy management. Book a personalized demo to see how UPA can future-proof your operations.

Web Console

100% GPO support in a modernized web console

Comprehensive Change Management

Offline changes, workflows, policy analysis, auditing

Enterprise Ready

Delegated administration, every domain, no agent

    I'm interested in: