196 questions with Windows for business | Windows Server | Directory services | Deploy group policy objects tags
GPP-configured environment variable not resolving for a subset of users
Since our GPP-configured environment variable is no longer resolving correctly, and I lost proper application functionality for a subset of users, I was told I needed to re-check our Group Policy setup. I have been looking into this.. and have been on…
Windows for business | Windows Server | Directory services | Deploy group policy objects
GPO Unlink Issue: GPP Registry keys persistent on client endpoints after unlinking
Hey team, facing a minor annoyance with Group Policy Preferences. We recently unlinked a GPO that drops a couple of custom Registry keys on client machines, but the registry values are still persisting on the endpoints even after a force gpupdate and…
Windows for business | Windows Server | Directory services | Deploy group policy objects
Netlogon Secure Channel fails over WiFi after KB5068865 - ERROR_ACCESS_DENIED (0x5) / WSAEACCES (10013)
Environment: Client: Windows 10/11, domain member TESTAPC.vdzti.local DC: Windows Server 2016 (build 14393), KB5070882 (October 2025) Client updates: KB5068865 (November 2025) Problem: Group Policy does not apply over WiFi. Netlogon Secure Channel…
Windows for business | Windows Server | Directory services | Deploy group policy objects
Black screens across all domain controllers after changing bypass traverse checking setting
These are the changes I made to our DC settings in order to get Splunk upgraded, according to their documentation:…
Windows for business | Windows Server | Directory services | Deploy group policy objects
Restrict and manage domain-joined computers/laptops even when they are connected to personal home Wi-Fi networks
Hi Support, In our office environment, we currently allow access only to specific websites through the Fortinet firewall for all client systems connected to our Windows Server 2022 Active Directory. We now want to implement a similar restriction for…
Windows for business | Windows Server | Directory services | Deploy group policy objects
Group Policy preference drive mapping tool failing to clean up old legacy network share links
Hi admins, we retired an old file storage server and replaced it with a modern DFS namespace link. I adjusted our corporate login GPO preference setting to "Replace" the old drive mapping link with the new target path. However, client machines…
Windows for business | Windows Server | Directory services | Deploy group policy objects
Dynamic Lock feature grayed out via corporate Group Policy settings on corporate laptops
Hey guys, multiple field users want to use the Windows Dynamic Lock feature to lock their screens automatically when they walk away with their corporate smartphones. However, the checkbox option under Settings > Accounts > Sign-in options is grayed…
Windows for business | Windows Server | Directory services | Deploy group policy objects
GPO map drive policy failing to apply with Event ID 4098 - Error code 0x80070005 Access Denied
Hey sysadmins, I configured a Group Policy Preference to map a network share drive (Z:) for our accounting OU using Item-Level Targeting based on a security group. The policy hits the client machines, but the drive doesn't map. Event Viewer logs throw…
Windows for business | Windows Server | Directory services | Deploy group policy objects
Cannot edit Group Policy on Domain Controller
Greetings, We have two domain controllers, one can edit Group Policy through Group Policy Management but the other domain controller cannot. All of the ACLs look correct. Domain replication looks to be working correctly. Otherwise editing group policy…
Windows for business | Windows Server | Directory services | Deploy group policy objects
on-premises Active Directory
experiencing an issue where Group Policy Objects (GPOs) created in the on-premises Active Directory are not being applied to the targeted workstations. The gpresult /r command output does not show the configured GPOs on the affected devices.
Windows for business | Windows Server | Directory services | Deploy group policy objects
We need help for a Windows Server 2019 Standard
We need help with a Windows Server 2019 Standard, which is also used as a terminal server. There are two PCs that log on to the terminal server and the local machine with the same user account. A network drive is mapped on all of them via Group Policy.…
Windows for business | Windows Server | Directory services | Deploy group policy objects
How to programmatically read Group Policy Firewall rules in a corporate domain?
Hi everyone, I’m trying to programmatically retrieve the Windows Firewall rules applied via Group Policy using Win32 APIs in a corporate domain, but I’m completely stuck. I tried calling GetGPOList() after grabbing a process token, but it keeps failing…
Windows for business | Windows Server | Directory services | Deploy group policy objects
I want to disable Print Spooler service from our Windows AD DC server
We are planning to stop the Print Spooler service from our AD DC server can you tell me I can do it using steps below or need different approach? Sign in on the Domain Controller Open Group Policy Management Right-click on the Domain Controllers OU …
Windows for business | Windows Server | Directory services | Deploy group policy objects
How to properly export live settings in GPO applied to a machine
Hi, I needed to get which of the following settings, and with which values, are applied live on a server. The needed settings are : SeInteractiveLogonRight SeRemoteInteractiveLogonRight SeDenyInteractiveLogonright SeDenyRemoteInteractiveLogonRight It…
Windows for business | Windows Server | Directory services | Deploy group policy objects
come disabilitare in modo massivo su pc di dominio (attiva avvio rapido )
Buongiorno, sono Diego Fraraccio IT di Formula spa , avrei la necessità di disabilitare in modo massivo l'avvio rapido su circa 500 pc , vorrei farlo con una policy ma stiamo riscontrando problemi potreste indicarci una soluzione grazie
Windows for business | Windows Server | Directory services | Deploy group policy objects
After changing a GPO we can not login to our windows server 2022 dc
By adopting this policy reccomended by defender we are locked out from our domain controller Need remediation urgently
Windows for business | Windows Server | Directory services | Deploy group policy objects
How to get GPO's to run when Server 2025 keeps booting up to the Public Firewall profile?
My GPO's will not work. Running gpupdate /force prompts that the machine must reboot to run the gpo, but it never is able to run because of the firewall profile always starting up as public. Yes, I can restart the NIC, but that does not fix the GPO…
Windows for business | Windows Server | Directory services | Deploy group policy objects
how to deploy exe through GPO
how to deploy .exe through GPO to all clients, i want to push Trend Micro Agent that is in .exe with supporting folder and applications
Windows for business | Windows Server | Directory services | Deploy group policy objects
How to define an GPO for Remote desktop User for specify Computer and user
Hi, How can I create an GPO for RDP Connection that user X does allow connect to the Computer Y? It mean the User X can connect only to the Computer Y. Regards Nick
Windows for business | Windows Server | Directory services | Deploy group policy objects
List of Group Policy which can apply on the Domain controller
Hi All, Is there any Group Policy best practices which I can apply/configure on the Domain Controller? If yes then can you please provide list of Group Policy which I can apply on Domain Controller?