AD Tripwires - Removing Domain Policy
Note: Removing the Domain Policy does not fully remove AD Tripwires. Additional steps are required to clean up tripwire accounts, agent configuration, and related infrastructure.
Edit existing policy to configure removal of scheduled task
- Open Group Policy Management Console (gpmc.msc)
- Locate the existing H3 IoA Policyobject inside theGroup Policy Objectscontainer.
- 
Right click on the policy object and click the Edit option from the context menu. 
- 
Once the Group Policy Management Editoropens, use the sidebar to navigate toComputer Configuration->Preferences->Control Panel Settings->Scheduled Tasks
- 
Right click on the scheduled task in the list. Click Properties from the context menu. 
- 
Once the Scheduled Task Properties Dialog window opens, navigate to the Generaltab if it isn't there already.
- 
Change the Actiondropdown fromReplacetoDelete.
- 
Click Apply and then OK. 
- Close the Group Policy Management Editorwindow.
- 
ATTENTION: Wait for group policy to replicate to all domain controllers Typical Timeframes Small domains (1-10 DCs): 15 minutes to 1 hour Medium enterprises (10-50 DCs): 1-4 hours Large enterprises (50+ DCs): 2-8 hours Very large/global enterprises: 8-24 hours 
You can also run gpupdate /force on individual domain controllers to force an immediate Group Policy refresh.
- Spot check domain controllers to verify that scheduled task has been removed
Remove Group Policy Object
Once the GPO has replicated and removed the scheduled task from all domain controllers, the group policy itself can be unlinked and removed.
- Open Group Policy Management Console (gpmc.msc)
- 
Locate the H3 IoA Policylink under theDomain ControllersOU and right click on the link and select Delete from the context menu.
- 
Locate the H3 IoA Policyobject under theGroup Policy Objectscontainer. Right click on the policy object and select Delete from the context menu.






