AD Tripwires - Removing Domain Policy
Note: Removing the Domain Policy does not fully remove AD Tripwires. Additional steps are required to clean up tripwire accounts, agent configuration, and related infrastructure.
Edit existing policy to configure removal of scheduled task
- Open Group Policy Management Console (
gpmc.msc) - Locate the existing 
H3 IoA Policyobject inside theGroup Policy Objectscontainer. - 
Right click on the policy object and click the Edit option from the context menu.
 - 
Once the
Group Policy Management Editoropens, use the sidebar to navigate toComputer Configuration->Preferences->Control Panel Settings->Scheduled Tasks - 
Right click on the scheduled task in the list. Click Properties from the context menu.
 - 
Once the Scheduled Task Properties Dialog window opens, navigate to the
Generaltab if it isn't there already. - 
Change the
Actiondropdown fromReplacetoDelete. - 
Click Apply and then OK.
 - Close the 
Group Policy Management Editorwindow. - 
ATTENTION: Wait for group policy to replicate to all domain controllers
Typical Timeframes
Small domains (1-10 DCs): 15 minutes to 1 hour
Medium enterprises (10-50 DCs): 1-4 hours
Large enterprises (50+ DCs): 2-8 hours
Very large/global enterprises: 8-24 hours
 
You can also run gpupdate /force on individual domain controllers to force an immediate Group Policy refresh.
- Spot check domain controllers to verify that scheduled task has been removed
 
Remove Group Policy Object
Once the GPO has replicated and removed the scheduled task from all domain controllers, the group policy itself can be unlinked and removed.
- Open Group Policy Management Console (
gpmc.msc) - 
Locate the
H3 IoA Policylink under theDomain ControllersOU and right click on the link and select Delete from the context menu. - 
Locate the
H3 IoA Policyobject under theGroup Policy Objectscontainer. Right click on the policy object and select Delete from the context menu. 






