Problem:  Can I deploy a central store and the ADMX files for Microsoft Office?
Solution:  So I tasked myself with deploying the Microsoft Office ADMX files recently and honestly, it was a pretty simple exercise but again seemingly no information on it.  So here’s my write up;
First you have to create the central store for all the other settings.  Here’s how I did it:
To create the GPO Central Store you must copy the folder “C:WindowsPolicyDefinitions” into the folder “C:WindowsSYSVOLsysvolYOURDOMAIN.localPoliciesPolicyDefinitions”.
Just double check this path is correct in your environment, my environment is Windows Server 2012R2 and this path works for me.
Here is a function to I wrote so as I deploy my domain controller this is called and the Central Store is created for me.

Script to create a GPO Central Store after deployment
Author:  Jonathan
Version: 1.0.0
Function Create-CentralStore
$Destination = "C:\Windows\SYSVOL\sysvol\YOURDOMAIN\Policies\PolicyDefinitions"
$Source = "C:\Windows\PolicyDefinitions"
if (!(Test-Path -path $Destination )) { $null = New-Item -ItemType Container -Path $Destination -Force }
Robocopy $Source $Destination /S

The central store contains a number of .ADMX files and a folder which contains .ADML files.  The ADML files are needed otherwise you’ll receive configuration errors when attempting to use group policy.  You can confirm that the central store is set up correctly by cracking open Group Policy and then in turn a Group Policy object.  Navigate down to ‘Administrative Templates either on Computer or User side and you will see in the RHS column that the definitions have been retrieved from the central store:
Once the Central Store is created you need to download the ADMX files for the version of Microsoft Office you use in your environment.  Here are some links for you: – Office 2010 ADMX – Office 2013 ADMX – Office 2016 ADMX

Each link will provide you with a x86 and a x64 downloadable .exe file.  The one you require depends on the the version of office you require to manage via GPO.  In our production environments we have one version of Office, we install the x86 version of Office as advised for most situations by Microsoft. When you run the exe you will be asked to suggest a folder to extract the files to like so…
image   image
Now you’ll have a couple of folders inside the extract but we’re only interested in the ADMX folder.  Inside here are the ADMX files we need and the language packs, I have deleted all language folders except en-us and I am now left with 13 admx files and an en-us folder.  these are the only files that we need to deploy so all the rest can be deleted.  As with the Central Store creation above, you’re left with several ADMX files and then a number of .ADML files inside the en-us folder.
For the sake of completeness, I downloaded both architectures for both 2010 and 2013, extracted, then removed all unneeded files and I am now left with the following folders

This way, when deploying a domain controller I can chose which one to implement on it depending on where I am
I wrote a simple function which looks like this:

Function Import-ADMX
$Destination = "C:\Windows\Sysvol\sysvol\YOURDOMAIN\Policies\PolicyDefinitions"
$Source = .ADMXOffice2010x86
#$Source = .ADMXOffice2013x86
#$Source = .ADMXOffice2013x86
#$Source = .ADMXOffice2013x64
if (!(Test-Path -path $Destination )) { $null = New-Item -ItemType Container -Path $Destination -Force }
Robocopy $Source $Destination /S

Obviously you’re going to have to edit the source folders for your environment, but this will do the following things:
1. Set the destination folder, this is the central store folder
2. Set the source folder, you’ll need to edit this to represent your environment
3. Test for the PolicyDefinitions folder in the default location for the central store, if it isn’t there, create it.
4. Copy in the ADMX & ADML files for the version of Office you use in your environment.

This can be run as a deployment step PowerShell script (which is what I am doing) and must be on the primary domain controller.  To test if this has worked properly crack open a GPO and see if you can see the MS Office items:
As you can see from this my deployment of the Office 2013 ADMX files was successful and they are sitting in a central store.  Happy days!

0 replies

Leave a Reply

Want to join the discussion?
Feel free to contribute!

Leave a Reply

Your email address will not be published. Required fields are marked *