196 questions with Windows for business | Windows Server | Directory services | Deploy group policy objects tags

Sort by: Updated
1 answer

GPP-configured environment variable not resolving for a subset of users

Since our GPP-configured environment variable is no longer resolving correctly, and I lost proper application functionality for a subset of users, I was told I needed to re-check our Group Policy setup. I have been looking into this.. and have been on…

Windows for business | Windows Server | Directory services | Deploy group policy objects
asked 2026-07-31T16:42:55.8966667+00:00
Liam Wilson 20 Reputation points
edited an answer 2026-08-03T06:54:13.6433333+00:00
Daphne Huynh (WICLOUD CORPORATION) 985 Reputation points Microsoft External Staff Moderator
1 answer

GPO Unlink Issue: GPP Registry keys persistent on client endpoints after unlinking

Hey team, facing a minor annoyance with Group Policy Preferences. We recently unlinked a GPO that drops a couple of custom Registry keys on client machines, but the registry values are still persisting on the endpoints even after a force gpupdate and…

Windows for business | Windows Server | Directory services | Deploy group policy objects
asked 2026-07-31T03:12:45.6733333+00:00
Advait Mohammad 40 Reputation points
answered 2026-07-31T03:20:48.7933333+00:00
Marcin Policht 103.1K Reputation points MVP Volunteer Moderator
5 answers One of the answers was accepted by the question author.

Netlogon Secure Channel fails over WiFi after KB5068865 - ERROR_ACCESS_DENIED (0x5) / WSAEACCES (10013)

Environment: Client: Windows 10/11, domain member TESTAPC.vdzti.local DC: Windows Server 2016 (build 14393), KB5070882 (October 2025) Client updates: KB5068865 (November 2025) Problem: Group Policy does not apply over WiFi. Netlogon Secure Channel…

Windows for business | Windows Server | Directory services | Deploy group policy objects
asked 2026-05-27T20:14:09.27+00:00
Anatolijs Artemjevs 45 Reputation points
commented 2026-07-29T06:59:10.04+00:00
bl1982 0 Reputation points
1 answer

Black screens across all domain controllers after changing bypass traverse checking setting

These are the changes I made to our DC settings in order to get Splunk upgraded, according to their documentation:…

Windows for business | Windows Server | Directory services | Deploy group policy objects
asked 2026-06-23T15:47:07.6033333+00:00
Washington, Candace N 20 Reputation points
commented 2026-06-23T21:30:57.4133333+00:00
Washington, Candace N 20 Reputation points
1 answer One of the answers was accepted by the question author.

Restrict and manage domain-joined computers/laptops even when they are connected to personal home Wi-Fi networks

Hi Support, In our office environment, we currently allow access only to specific websites through the Fortinet firewall for all client systems connected to our Windows Server 2022 Active Directory. We now want to implement a similar restriction for…

Windows for business | Windows Server | Directory services | Deploy group policy objects
asked 2026-06-20T11:17:57.0833333+00:00
Ravinder Makkar 100 Reputation points
accepted 2026-06-20T12:19:49.99+00:00
Ravinder Makkar 100 Reputation points
2 answers

Group Policy preference drive mapping tool failing to clean up old legacy network share links

Hi admins, we retired an old file storage server and replaced it with a modern DFS namespace link. I adjusted our corporate login GPO preference setting to "Replace" the old drive mapping link with the new target path. However, client machines…

Windows for business | Windows Server | Directory services | Deploy group policy objects
asked 2026-06-11T10:47:47.64+00:00
Laura Wagner 20 Reputation points
answered 2026-06-11T11:52:37.3833333+00:00
Jason Nguyen Tran 24,545 Reputation points Independent Advisor
2 answers

Dynamic Lock feature grayed out via corporate Group Policy settings on corporate laptops

Hey guys, multiple field users want to use the Windows Dynamic Lock feature to lock their screens automatically when they walk away with their corporate smartphones. However, the checkbox option under Settings > Accounts > Sign-in options is grayed…

Windows for business | Windows Server | Directory services | Deploy group policy objects
asked 2026-06-08T14:06:36.88+00:00
John Wilson 20 Reputation points
answered 2026-06-08T14:43:01.9133333+00:00
Domic Vo 29,480 Reputation points Independent Advisor
2 answers

GPO map drive policy failing to apply with Event ID 4098 - Error code 0x80070005 Access Denied

Hey sysadmins, I configured a Group Policy Preference to map a network share drive (Z:) for our accounting OU using Item-Level Targeting based on a security group. The policy hits the client machines, but the drive doesn't map. Event Viewer logs throw…

Windows for business | Windows Server | Directory services | Deploy group policy objects
asked 2026-06-05T11:00:15.6333333+00:00
David Huber 20 Reputation points
answered 2026-06-05T11:43:23.2566667+00:00
Harry Phan 28,050 Reputation points Independent Advisor
3 answers

Cannot edit Group Policy on Domain Controller

Greetings, We have two domain controllers, one can edit Group Policy through Group Policy Management but the other domain controller cannot. All of the ACLs look correct. Domain replication looks to be working correctly. Otherwise editing group policy…

Windows for business | Windows Server | Directory services | Deploy group policy objects
asked 2026-05-27T03:10:09.4533333+00:00
FunMum 140 Reputation points
answered 2026-05-27T23:41:55.7066667+00:00
FunMum 140 Reputation points
2 answers

on-premises Active Directory

 experiencing an issue where Group Policy Objects (GPOs) created in the on-premises Active Directory are not being applied to the targeted workstations. The gpresult /r command output does not show the configured GPOs on the affected devices.

Windows for business | Windows Server | Directory services | Deploy group policy objects
asked 2026-05-19T14:09:17.6733333+00:00
abdo elbarbary 70 Reputation points
answered 2026-05-19T14:54:22.4166667+00:00
Quinnie Quoc 11,830 Reputation points Independent Advisor
2 answers

We need help for a Windows Server 2019 Standard

We need help with a Windows Server 2019 Standard, which is also used as a terminal server. There are two PCs that log on to the terminal server and the local machine with the same user account. A network drive is mapped on all of them via Group Policy.…

Windows for business | Windows Server | Directory services | Deploy group policy objects
asked 2026-05-06T13:46:05.8366667+00:00
Werner Bender 0 Reputation points
answered 2026-05-06T14:34:51.3966667+00:00
Harry Phan 28,050 Reputation points Independent Advisor
2 answers

How to programmatically read Group Policy Firewall rules in a corporate domain?

Hi everyone, I’m trying to programmatically retrieve the Windows Firewall rules applied via Group Policy using Win32 APIs in a corporate domain, but I’m completely stuck. I tried calling GetGPOList() after grabbing a process token, but it keeps failing…

Windows for business | Windows Server | Directory services | Deploy group policy objects
asked 2026-04-27T13:15:15.2333333+00:00
Jack 5T 0 Reputation points
answered 2026-04-27T13:42:05.56+00:00
Domic Vo 29,480 Reputation points Independent Advisor
3 answers

I want to disable Print Spooler service from our Windows AD DC server

We are planning to stop the Print Spooler service from our AD DC server can you tell me I can do it using steps below or need different approach? Sign in on the Domain Controller Open Group Policy Management Right-click on the Domain Controllers OU …

Windows for business | Windows Server | Directory services | Deploy group policy objects
asked 2026-04-13T05:15:24.7566667+00:00
Joshi Omkar 0 Reputation points
answered 2026-04-26T00:42:59.0866667+00:00
Jason Nguyen Tran 24,545 Reputation points Independent Advisor
4 answers One of the answers was accepted by the question author.

How to properly export live settings in GPO applied to a machine

Hi, I needed to get which of the following settings, and with which values, are applied live on a server. The needed settings are : SeInteractiveLogonRight SeRemoteInteractiveLogonRight SeDenyInteractiveLogonright SeDenyRemoteInteractiveLogonRight It…

Windows for business | Windows Server | Directory services | Deploy group policy objects
asked 2026-04-16T15:04:39.7333333+00:00
Egoitz Aurrekoetxea 81 Reputation points
edited an answer 2026-04-16T15:34:40.64+00:00
Egoitz Aurrekoetxea 81 Reputation points
1 answer

come disabilitare in modo massivo su pc di dominio (attiva avvio rapido )

Buongiorno, sono Diego Fraraccio IT di Formula spa , avrei la necessità di disabilitare in modo massivo l'avvio rapido su circa 500 pc , vorrei farlo con una policy ma stiamo riscontrando problemi potreste indicarci una soluzione grazie

Windows for business | Windows Server | Directory services | Deploy group policy objects
asked 2026-04-02T07:05:53.9+00:00
Admin Fraraccio 0 Reputation points
answered 2026-04-02T10:05:57.8066667+00:00
Harry Phan 28,050 Reputation points Independent Advisor
2 answers

After changing a GPO we can not login to our windows server 2022 dc

By adopting this policy reccomended by defender we are locked out from our domain controller Need remediation urgently

Windows for business | Windows Server | Directory services | Deploy group policy objects
asked 2026-03-27T11:33:22.08+00:00
Merkouris Bouchlas 0 Reputation points
answered 2026-03-27T16:08:10.1166667+00:00
Domic Vo 29,480 Reputation points Independent Advisor
1 answer One of the answers was accepted by the question author.

How to get GPO's to run when Server 2025 keeps booting up to the Public Firewall profile?

My GPO's will not work. Running gpupdate /force prompts that the machine must reboot to run the gpo, but it never is able to run because of the firewall profile always starting up as public. Yes, I can restart the NIC, but that does not fix the GPO…

Windows for business | Windows Server | Directory services | Deploy group policy objects
asked 2026-03-17T15:43:54.3366667+00:00
Chris Watkins 40 Reputation points
commented 2026-03-17T17:17:37.45+00:00
Chris Watkins 40 Reputation points
2 answers

how to deploy exe through GPO

how to deploy .exe through GPO to all clients, i want to push Trend Micro Agent that is in .exe with supporting folder and applications

Windows for business | Windows Server | Directory services | Deploy group policy objects
asked 2026-03-16T23:23:31.96+00:00
Mohammed Ahmed 0 Reputation points
answered 2026-03-17T05:44:27.4933333+00:00
Domic Vo 29,480 Reputation points Independent Advisor
2 answers One of the answers was accepted by the question author.

How to define an GPO for Remote desktop User for specify Computer and user

Hi, How can I create an GPO for RDP Connection that user X does allow connect to the Computer Y? It mean the User X can connect only to the Computer Y. Regards Nick

Windows for business | Windows Server | Directory services | Deploy group policy objects
asked 2026-03-02T15:13:58.69+00:00
SSE@TUE 360 Reputation points
accepted 2026-03-03T12:43:59.84+00:00
SSE@TUE 360 Reputation points
2 answers

List of Group Policy which can apply on the Domain controller

Hi All, Is there any Group Policy best practices which I can apply/configure on the Domain Controller? If yes then can you please provide list of Group Policy which I can apply on Domain Controller?

Windows for business | Windows Server | Directory services | Deploy group policy objects
asked 2026-02-23T10:59:59.9766667+00:00
Kaushal Shah 0 Reputation points
answered 2026-02-23T11:46:25.1633333+00:00
Tan Vu 2,655 Reputation points Independent Advisor