Administrative templates are how Windows exposes registry-backed policy in a human-readable form. Microsoft ships the Windows templates with each release, but Office, Chrome, Edge and many third-party products ship their own ADMX files that you must place somewhere the tools can find them. On-premises that is the SYSVOL Central Store; in Intune it is the imported ADMX catalogue, or for Microsoft products the built-in Administrative Templates. This guide covers Windows Server 2019/2022/2025 domain controllers and Windows 10/11 clients managed by Intune.
Table of Contents
Short answer: For Active Directory, copy each product’s .admx files into \\<domain>\SYSVOL\<domain>\Policies\PolicyDefinitions and the language .adml files into the matching en-US subfolder; the Group Policy Management Editor picks them up automatically. For Intune, go to Devices » Configuration » Import ADMX, upload the .admx and .adml pair for each template in dependency order (Windows.admx first if the vendor file references it), then create a profile using Settings Catalog or Administrative Templates where the imported settings appear.
Download the current templates
- Microsoft 365 Apps: the “Administrative Template files (ADMX/ADML) for Microsoft 365 Apps” download from Microsoft, refreshed with most monthly releases.
- Microsoft Edge: from the Edge for Business site under “Get policy files”; the bundle includes msedge.admx, msedgeupdate.admx and the language folders.
- Google Chrome: the Chrome Enterprise bundle, which contains chrome.admx, google.admx and chrome.adml under windows\admx.
- Windows itself: install the latest “Administrative Templates for Windows 11” MSI on an admin workstation, which populates C:\Program Files (x86)\Microsoft Group Policy\<version>\PolicyDefinitions.
Always match the Windows template version to the newest client build you manage (26H1 as of now); older templates hide newer settings.
Populate the Central Store
Create the store once on any domain controller; DFS-R replicates it:
$store = "\\corp.example\SYSVOL\corp.example\Policies\PolicyDefinitions"
New-Item -ItemType Directory -Path "$store\en-US" -Force
Copy-Item "C:\Program Files (x86)\Microsoft Group Policy\Windows 11 26H1\PolicyDefinitions\*.admx" $store
Copy-Item "C:\Program Files (x86)\Microsoft Group Policy\Windows 11 26H1\PolicyDefinitions\en-US\*.adml" "$store\en-US"
Copy-Item "C:\Downloads\admx\*.admx" $store
Copy-Item "C:\Downloads\admx\en-US\*.adml" "$store\en-US"
Open the Group Policy Management Console, edit any GPO, and check that the Administrative Templates node reads “Policy definitions (ADMX files) retrieved from the central store”. New nodes such as Google » Google Chrome and Microsoft Edge appear under both Computer and User Configuration.
Keep the vendor’s google.admx alongside chrome.admx; chrome.admx references the Google parent category and fails to load without it, producing “Namespace ‘Google.Policies’ is already defined” or “resource ‘$(string.google)’ referenced in attribute displayName could not be found” errors.
Import into Intune
Intune » Devices » Manage devices » Configuration » Import ADMX » Import. Upload the .admx and its .adml together. The dependency rule matters here: a file that uses another namespace fails with “ADMX file referenced not found NamespaceMissing:<name>” until its parent is imported. Practical order:
- Windows.admx (usually already present, but import if the vendor file references a newer version).
- google.admx, then chrome.admx.
- msedgeupdate.admx and msedge.admx.
- Office: the language-neutral office16.admx first, then word16.admx, excel16.admx and the others.
Each upload takes a minute or two to move from “In progress” to “Available”. Once available, create a profile with Devices » Configuration » Create » Windows 10 and later » Templates » Imported Administrative templates (Preview), or use the Settings Catalog where the same imported settings surface under the vendor’s category.
Note that Microsoft 365 Apps and Edge settings are already built into the Settings Catalog and updated by Microsoft, so importing those is only needed when you require a setting newer than the catalogue offers. Chrome is the common reason to use Import ADMX.
Verify on a client
For a GPO-delivered Chrome or Edge policy:
gpupdate /force
reg query "HKLM\SOFTWARE\Policies\Google\Chrome"
reg query "HKLM\SOFTWARE\Policies\Microsoft\Edge"
Then open chrome://policy or edge://policy in the browser; the page lists each applied policy and its source. For Intune, sync the device and check the same registry keys; the Intune policy CSP writes ADMX-backed settings into the same Policies hive, and the profile shows “Succeeded” per device under Devices » Configuration » the profile » Device status.
Common pitfall
Uploading a newer Windows.admx to Intune while older vendor files remain can leave settings referencing missing string resources, and the portal shows the profile as “Error” with no obvious cause. Reimport the vendor templates after any Windows template refresh. On-premises, the same mismatch appears when one administrator’s local PolicyDefinitions folder is newer than the Central Store; the console silently prefers the store, so the setting “disappears” for one person. Standardise on the store and never edit GPOs from a machine without access to it.
Import ADMX templates at a glance

Official documentation: Microsoft Intune documentation, Active Directory Domain Services docs, Windows Server documentation.
Related guides: Deploy a desktop wallpaper and lock screen with Group Policy (plus the registry method for Windows Pro) · Troubleshoot Group Policy not applying: gpresult, RSoP and Events 1058/1030 · Group Policy loopback processing: merge vs replace for RDS hosts and kiosks.
Frequently asked questions
Does importing ADMX into Intune also apply the policies to devices?
No. Import only makes the settings available in the portal. Nothing reaches a device until you build a configuration profile that uses those settings and assign it to a group.
How long does an ADMX import take in Intune?
Most files finish within one to five minutes; large Office bundles can take longer. If a file stays “In progress” for more than fifteen minutes, delete and re-upload it after confirming its dependencies are Available.
Can I remove an imported ADMX file?
Yes, but only after deleting every profile that references its settings; Intune blocks removal while dependencies exist. In the Central Store, deleting an .admx simply hides its settings in the editor; existing registry values on clients remain until the GPO is changed.