Share via


Performing AGPM Administrator Tasks

In AGPM (Gerenciamento Avançado de Política de Grupo), an Administrador AGPM (Controle Total) configures domain-wide options and delegates permissions to Approvers, Editors, Reviewers, and other Administradores AGPM. By default, an Administrador AGPM is an individual with Full Control—all AGPM permissions—and who therefore can perform tasks associated with any role.

In an environment in which multiple people develop GPOs (Objetos de Política de Grupo), you can choose whether all AGPM users perform the same tasks and have the same level of access or whether Administradores AGPM delegate permissions to Editors who make changes to GPOs and to Approvers who deploy GPOs to the production environment. Administradores AGPM can configure permissions to meet the needs of your organization.

Also, because the Administrador AGPM role includes the permissions for all other roles, an Administrador AGPM can perform the tasks normally associated with any other role.

Additional considerations

By default, the Administrador AGPM role has Full Control—all AGPM permissions:

  • List Contents

  • Read Settings

  • Edit Settings

  • Create GPO

  • Deploy GPO

  • Delete GPO

  • Modify Options

  • Modify Security

  • Create Template

The Modify Options and Modify Security permissions are unique to the role of Administrador AGPM.

-----
É possível obter mais informações sobre o MDOP na Biblioteca do TechNet, pesquisar sobre solução de problemas no Wiki da TechNet ou nos seguir no Facebook ou Twitter.
-----