Files
WELA/docs/gpo-package-deployment.md
田中ザック Isaac Mathis f1ed90d189 Create new disabled, unlinked GPOs from reviewed native audit backups (#427)
* Add guarded creation of disabled unlinked audit GPOs

* Reference PR 427 in GPO creation changelogs

* Accept only inert native ADM placeholders and fix PS5 JSON fixture

* Preserve fractional UTC strings in existing probe fixtures
2026-09-20 22:53:00 +09:00

7.3 KiB

Preparing and reviewing a genuine audit-policy GPO

This WELA folder contains deployment components, not a GPO backup. Do not pass it to Import-GPO, copy it into SYSVOL, fabricate Backup.xml, or edit a genuine archived backup to insert its files. Microsoft directs administrators to manage archived backups through GPMC. No domain creation, import, linking, filtering, delegation or policy refresh is performed by WELA's package commands. Microsoft backup/import guidance.

Prepare the source policy in an isolated domain

  1. Verify the component package with the same reviewed WELA version. Read review.md, including every omitted/expanded row and object/service prerequisites. Confirm the intended target role, build, scope and source version; these are declared package inputs, not observations of a domain's computers.
  2. On a disposable, snapshotted lab, use GPMC to create a new unlinked source GPO. Leave existing GPOs, default domain policies and links untouched. In the Group Policy Management Editor, enter only the exported rows under Computer Configuration > Policies > Windows Settings > Security Settings > Advanced Audit Policy Configuration. ExportMask 1 is Success, 2 is Failure, 3 is Success and Failure. Leave omitted rows Not Configured in this new GPO; do not interpret omission as disabling auditing.
  3. In the same GPO, enable Security Options > Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings. The companion GptTmpl.inf shows the exact DWORD requirement. Do not add legacy category audit policy, audit failure options, privileges, SACLs or unrelated registry settings.
  4. Disable both Computer and User settings on the source GPO before backing it up. Review GPMC's Settings report against the package. Require an exact match for the selected audit GUIDs/masks and precedence=1, with no unexpected Computer or User policy settings. Confirm no links or WMI filter. Review the GPO's security filtering/delegation independently. Back up this source GPO through GPMC or Backup-GPO into a fresh protected directory, retaining its backup-instance ID, source GPO ID, report and hashes.

This manual source-GPO preparation is the supported path for a narrow, genuine domain backup. Microsoft documents creating an unlinked GPO and generating backups through Backup-GPO.

Optional LGPO lab route

Obtain Microsoft's signed LGPO utility and its documentation from the Security Compliance Toolkit; WELA does not bundle or execute it. LGPO v3 documents /s GptTmpl.inf for a security template, /a audit.csv for advanced auditing and /b directory /n display-name for a genuine local-policy backup. These apply modes change the lab host and are outside the offline package workflow. Snapshot and record the lab's policy first; inspect all generated settings and compare effective policy before/after. Do not run them on a shared or production administrator workstation.

/a and /ac differ: /ac clears existing advanced auditing before application and copies the CSV into local policy. WELA does not provide a clearing command. /a must not be presented as proof of persistent GPO configuration: local policy editor state, effective AuditPol state and the audit client-side extension are separate observations. LGPO /e audit enables that extension for local processing, but neither its use nor successful import proves correct later policy application.

LGPO /b backs up local policy, including security settings, current advanced audit state, registry policy and configured extensions. Its output can include settings absent from this package, even on a lab machine. Review the complete backup in GPMC. If it contains extras, edit a newly created isolated source GPO through GPMC and make a new genuine backup; do not remove files or patch XML inside the archive. A generic local-policy backup is not automatically a narrow WELA audit-only backup. Microsoft explains the difference between AuditPol state and local policy.

Reviewed create-new-disabled-unlinked command

WELA now provides the separate opt-in gpo-create command for an already prepared genuine narrow backup. Its Review action compares native GPMC reports and actual policy files against a current WELA package. Plan and Create require the reviewed fingerprint, explicit domain GUID/FQDN, exact writable DC, and a unique new name. Both source-backup sides must already be disabled. Creation records the new GUID, disables the empty candidate, rechecks its unlinked/empty state, and imports only into that GUID with protected receipts and final readback. It never links, enables, overwrites or deletes a GPO.

Read that command's single-domain-forest restriction, native prerequisites, failure recovery and concurrency limits before use. The package commands remain offline and never invoke it implicitly. Successful candidate creation is separate from AD/SYSVOL replication and policy application.

Deployment acceptance and recovery

After separate approval of scope, stage any linking on an isolated test OU containing only representative disposable clients/servers. Plan role/build targeting and filtering explicitly; WELA's declared Role/Build is documentation, not a generated WMI or security filter. Check precedence, link order, enforcement, inheritance and resultant policy. No deployment link/force-refresh command is included here.

Record the genuine backup, target GUID, actual GPMC settings, RSoP/GPO source evidence, effective audit masks after ordinary policy processing, relevant SACL/service prerequisites, benign generated XML and collector arrival. Unlinked creation/import does not prove any client applied the settings. More specific or enforced policy can change the result. Group Policy processing.

Rollback must be designed before linking. Preserve existing production GPOs and links throughout preparation. If testing fails, the policy owner should inspect and selectively reverse only the test changes, considering current links, authoritative settings and replication. Unlinking or deleting a GPO is not proof that all effective settings reverted. Retain evidence rather than blindly restoring an old whole-host policy snapshot. No audit-exhaustion test is required or provided.

WELA's package tests validate component contents and unchanged host settings. The separate creation tests also read a genuine Microsoft backup through native GPMC and verify broad-payload/workgroup refusals, while positive creation orchestration uses mocks. Genuine GPO creation/import, absence of unintended policy settings, AD/SYSVOL replication, client/DC/AD CS application and event/collection evidence remain pending lab acceptance for issue #2. Other WELA controls and Sysmon are outside this package.