Troubleshoot Group Policy Processing on Windows
When a Windows setting is missing, trace policy processing from the affected user or computer to the domain controller and then to the individual Group Policy Object (GPO). This workflow uses result reports and event logs before requesting another policy refresh.
Run the checks on the affected computer with an account that can read the relevant policy results. A forced refresh can trigger scripts, software installation, or a restart request, so gather evidence first and coordinate the refresh with the device owner.
Check Domain Membership and the Current Network
Starting StateVerify domain membership, domain controller discovery, and the secure channel. A client pointed at a public DNS resolver or an unreachable domain controller may not process domain policy.
$computer = Get-CimInstance Win32_ComputerSystem$computer | Select-Object Name, Domain, PartOfDomainnltest /dsgetdc:$($computer.Domain)Test-ComputerSecureChannel -Verboseipconfig /allβ― View Expected Console Output
PartOfDomain : TrueDomain : corp.exampleThe command completed successfullyCapture gpresult Reports for Both Scopes
Policy ResultsRun the computer report from an elevated shell and the user report in the affected userβs session. Review applied and denied GPO lists, including the reason each denied GPO was filtered.
New-Item -ItemType Directory -Path C:\Temp\GpoReview -Force | Out-Nullgpresult /scope computer /h C:\Temp\GpoReview\computer.html /fgpresult /scope user /h C:\Temp\GpoReview\user.html /fgpresult /r /scope computerβ― View Expected Console Output
Applied Group Policy Objects Workstation Security BaselineGPOs not applied because they were filtered out Legacy Kiosk Policy
Figure 1: Compare applied GPOs and filtering reasons in a Group Policy results report.
Trace a Setting to Its Winning Policy
Policy SourceUse Resultant Set of Policy to inspect the winning setting. Then review the Group Policy operational log around the last processing cycle for extension, connectivity, or permission errors.
rsop.mscGet-WinEvent -FilterHashtable @{ LogName = 'Microsoft-Windows-GroupPolicy/Operational' StartTime = (Get-Date).AddHours(-4)} -ErrorAction SilentlyContinue | Select-Object -First 30 TimeCreated, Id, LevelDisplayName, Message | Format-Listβ― View Expected Console Output
Group Policy processing completed successfully.Review event details for the extension name and policy path.Apply the Approved Policy Change
Controlled RefreshCheck scope, security filtering, WMI filtering, replication, SYSVOL access, and setting precedence. After coordinating the fix and refresh, rerun the reports and verify the target setting.
gpupdate /target:computer /forcegpresult /scope computer /rβ― View Expected Console Output
Computer Policy update has completed successfully.