DeviceLock Consoles and Tools : DeviceLock Group Policy Manager : Using Group Policy to Manage DeviceLock Service for Mac
  
Using Group Policy to Manage DeviceLock Service for Mac
DeviceLock Service for Mac can retrieve configuration settings from Active Directory via DeviceLock Enterprise Server. In order to enable DeviceLock Service for Mac to receive settings from group policies, perform the following steps:
1. Register the Mac computer in the Windows domain.
2. Place the newly added computer into the required OU and configure policies according to your requirements.
3. Install DeviceLock Enterprise Server. No specific settings are required. Make sure that the computer hosting DeviceLock Enterprise Server has access to the domain controller with which the Mac computer is registered.
4. On the Mac computer, enter the address of DeviceLock Enterprise Server configured during the previous step.
Group policies will be applied to the Mac computer in the following cases:
Upon system restart.
Every hour.
When the DeviceLock Enterprise Server(s) parameter is changed in Service Options.
Forced update is performed.
To perform the forced update, use the following command:
/Library/DeviceLockAgent/Utilities/DLAgentControl gpupdate