I have created a domain level GPO that causes the message "Logon is prohibited to unauthorized personnel" to be presented to users when logging on.
I need to modify the GPO such that the domain controller group policy replication is set to occur every 15 minutes and computer group policy replication to occur once every 3 hours.
Could someone tell me a tool I need that could help me verify replication timing? Also it would be nice if someone could show me how to set it up as well.
AD (NTDS) replication is controlled within the AD Sites and Services management console (dssite.msc). You can modify the site links and NTDS settings within there.
For modifying how often clients refresh their policy, you should use Group Policy. Navigate to Computer Configuration > Policies > Administrative Templates > System > Group Policy, and change the Group Policy Refresh Interval settings.
You can use the tool
repadmin
to inspect connections between AD domain controllers:For investigating a specific client, you can use
gpresult
to learn about: