Emergency server help: get in touch

Group Policy Not Applying: 12 Checks with gpresult and Events

A systematic way to find out why a GPO does not reach a Windows 11 client or Windows Server 2025 member: read gpresult, check scope and filtering, decode the Group Policy events, compare AD and SYSVOL versions and turn on gpsvc debug logging.

Published Updated 15 min read

When you find Group Policy not applying to a Windows 11 client or a Windows Server 2025 member server, the cause is almost always on a short list: the GPO is not in scope, it is filtered out, the client cannot reach a domain controller or SYSVOL, or a client-side extension failed while processing. This guide works through that list in the order that finds the fault fastest, with the exact commands, event IDs and registry values you need.

Short answer: On the affected machine, run gpupdate /force, then gpresult /h C:\Temp\gp.html from an elevated prompt and open the report. If the GPO is listed under Denied GPOs, the reason column (Security, WMI Filter, Empty, Disabled) tells you what to fix. If it is missing entirely, the GPO is not linked above the object’s OU. If gpupdate itself fails, read the System log for GroupPolicy events 1058, 1030, 1129 or 1055: they point to SYSVOL access, LDAP, network or name resolution problems.

Which tool to use

Each tool answers a different question about Group Policy not applying. Start with the client’s own view, then move to the domain side.

ToolAnswersRun whereLimits
gpresult /rWhich GPOs applied or were filtered, last refresh time, DC used, group membershipClient, elevated for computer dataText only; no individual settings
gpresult /hEvery winning setting, the GPO it came from, denied GPOs with reasons, CSE statusClientNeeds a user profile on the machine for user data
GPMC » Group Policy ResultsThe same report, pulled remotelyAdmin workstation with RSATNeeds WMI and remote event log access through the firewall
GPMC » Group Policy ModelingWhat should apply for a user and computer locationAdmin workstation, uses a DCSimulation only; ignores network and CSE failures
rsop.mscLegacy RSoP snap-inClientDoes not show Group Policy Preferences; use gpresult instead
Event logsWhy processing failedClientOperational log is detailed but verbose
gpsvc.logStep-by-step trace of the Group Policy serviceClient, after enabling debug loggingLarge; turn off when finished

Prerequisites

  • Local administrator rights on the affected machine (computer-side results need an elevated prompt).
  • The Group Policy Management Console from RSAT, and read access to the GPOs.
  • For remote results: the Windows Management Instrumentation (WMI-In) and Remote Event Log Management firewall rules enabled on the client.
  • The name of the GPO and the exact setting that is not arriving, plus one user and one computer that reproduce the problem.

Check 1: Force a refresh and read the error

gpupdate /force
gpupdate /target:computer /force
gpupdate /target:user /force

Read what gpupdate prints. “Computer Policy update has completed successfully” means processing ran; the problem is scope, filtering or the setting itself. “The processing of Group Policy failed” means the client could not finish, and the event log explains why (see Check 7). Some extensions only run at startup or sign-in: Software Installation, Folder Redirection and disk quota settings report that a restart or logoff is needed. Accept the prompt, or restart the machine yourself.

Check 2: Read gpresult correctly

mkdir C:\Temp
gpresult /h C:\Temp\gp.html /f
gpresult /r /scope computer
gpresult /r /scope user
gpresult /s PC042 /user CONTOSO\jsmith /h C:\Temp\pc042.html

In the text output, check these lines first:

  • Group Policy was applied from: the domain controller the client used. If it is a DC in another site or one you know is broken, the problem is DC locator or replication.
  • Last time Group Policy was applied: if it is days old, processing is failing, not filtering.
  • Applied Group Policy Objects: the GPO is in scope and passed filtering.
  • The following GPOs were not applied because they were filtered out: each entry carries a reason such as Filtering: Denied (Security), Denied (WMI Filter), Not Applied (Empty), Disabled (GPO) or Disabled (Link).
  • The computer/user is a part of the following security groups: the token as the client sees it. A computer picks up new group membership only after a restart; a user after signing out and in, or after klist purge.

The HTML report adds the Winning GPO for every setting and a Component Status table. A GPO that applied but whose setting is overridden shows another GPO as the winner, which is a precedence problem, not a case of Group Policy not applying.

  1. In GPMC, select the GPO and open the Scope tab. Confirm it is linked to the OU that contains the object that owns the setting: computer settings follow the computer account, user settings follow the user account.
  2. Open the OU and check the Group Policy Inheritance tab. A Block Inheritance icon on the OU stops parent links unless they are Enforced. An enforced GPO higher up can also override yours.
  3. Check the link is enabled (right-click the link: Link Enabled must be ticked).
  4. On the GPO’s Details tab, check GPO Status. User configuration settings disabled or Computer configuration settings disabled silently removes half the GPO; All settings disabled removes everything.
  5. Default containers such as CN=Computers and CN=Users are not OUs and cannot have GPOs linked. Objects there only receive site and domain-level GPOs.

User settings in a GPO linked to a computer OU never apply unless loopback processing is enabled on that computer, in Merge or Replace mode. This is the most common reason for user settings on an RDS host or kiosk appearing as Group Policy not applying.

Check 4: Security filtering and MS16-072

Open the Delegation tab and click Advanced. A principal needs both Read and Apply group policy to receive the GPO.

  • Since the June 2016 security update MS16-072, the client reads user policy in the computer’s security context. If you removed Authenticated Users from security filtering and added a user group, also give Authenticated Users or Domain Computers the Read permission (without Apply). Without it, gpresult shows the GPO as Denied (Security) or leaves it out, and event 1058 may report access denied.
  • A Deny on Apply group policy for any group the object belongs to wins over every Allow.
  • Filtering by a group that contains the right users does nothing for computer settings, and the reverse. Computer settings are evaluated against the computer account.
Get-GPPermission -Name "SEC - Screen Lock" -All | Format-Table Trustee, Permission, Denied
Set-GPPermission -Name "SEC - Screen Lock" -TargetName "Domain Computers" -TargetType Group -PermissionLevel GpoRead

Check 5: WMI filters that evaluate to false

A WMI filter that returns no rows on the client, or a query with a syntax error, makes the GPO show as Denied (WMI Filter). Test the query on the client exactly as written in GPMC:

Get-CimInstance -Query "SELECT * FROM Win32_OperatingSystem WHERE ProductType = 1 AND Version LIKE '10.0.2%'"

No output means the filter is false on this machine. Typical mistakes are comparing Version against '10.0.2' without a wildcard, filtering on Caption strings that differ by language, and using a namespace other than root\CIMv2 without changing it in the filter. Windows 11 still reports version 10.0.x, so build numbers (22000 and later) are what distinguish it from Windows 10.

Check 6: Domain controller, DNS and secure channel

When Group Policy not applying affects every GPO on a machine, the cause is usually in this chain. The client finds a DC through DNS SRV records, authenticates with Kerberos, reads the GPO list over LDAP and the files over SMB from SYSVOL. Test each link:

ipconfig /all
nltest /dsgetdc:contoso.com
nltest /sc_query:contoso.com
Test-ComputerSecureChannel -Verbose
nslookup -type=SRV _ldap._tcp.dc._msdcs.contoso.com
w32tm /query /status
dir \\contoso.com\SYSVOL\contoso.com\Policies
  • The client’s DNS servers must be domain DNS servers only. A public resolver as secondary DNS causes intermittent failures that look random.
  • Kerberos tolerates 5 minutes of clock difference by default. Larger skew breaks authentication, and therefore Group Policy.
  • If the secure channel is broken, see the trust relationship repair guide.
PortProtocolUsed for
53TCP/UDPDNS and DC locator SRV lookups
88TCP/UDPKerberos authentication
389TCP/UDPLDAP: GPO list, links, WMI filter objects, site lookup
445TCPSMB access to SYSVOL (gpt.ini, Registry.pol, scripts)
135 + 49152–65535TCPRPC: remote gpresult, GPMC Results, Invoke-GPUpdate

Check 7: Decode the Group Policy events

Open Event Viewer » Windows Logs » System and filter on source GroupPolicy. The error events below are the ones that explain a failed refresh:

Event IDMeaningFirst thing to check
1058Could not read gpt.ini for a GPO from the DC. Error 3 = path not found, 5 = access denied, 53 = network path not foundOpen the path from the event on the client; SYSVOL replication; GPO permissions
1030Failed to retrieve new settings; retried at the next refresh. Usually logged together with 1058Fix the paired event
1129Processing failed because of lack of network connectivity to a DCFirewall, VPN timing, NIC ready too late at startup
1054Could not obtain the name of a domain controllerDNS client settings and SRV records
1055Could not resolve the computer nameName resolution, replication latency, broken secure channel
1053Could not resolve the user nameDNS, permissions on the user’s OU, RPC reachability
1006LDAP bind failed (could not authenticate to AD). Error 49 = invalid credentials, 258 = timeoutPassword or secure channel, DNS, time skew

For detail, open Applications and Services Logs » Microsoft » Windows » GroupPolicy » Operational. Useful events:

  • 5308 names the domain controller used; 5312 lists applicable GPOs and 5313 lists GPOs that were filtered out.
  • 4016 and 5016 mark each client-side extension starting and completing successfully. 7016 means an extension completed with an error, for example the Security extension failing on an unknown environment variable in a file system path.
  • 7017 records a system call during processing (LDAP bind, account lookup or file access) that failed; the event data names the call and the error.
Get-WinEvent -LogName 'Microsoft-Windows-GroupPolicy/Operational' -MaxEvents 200 |
  Where-Object Id -in 5308,5312,5313,7016,7017 |
  Format-List TimeCreated, Id, Message

Check 8: SYSVOL replication and version mismatch

A GPO lives in two places: the Group Policy Container in AD and the Group Policy Template in SYSVOL\domain\Policies\{GUID}. Each has its own version number. If the DC the client uses has a newer AD version but an older GPT.INI, or the folder is missing, the client applies stale settings or logs event 1058. This produces Group Policy not applying on clients that use one DC, while clients using another DC are fine.

Get-GPO -Name "SEC - Screen Lock" | Select-Object DisplayName, Id, GpoStatus,
  @{n='CompAD';e={$_.Computer.DSVersion}}, @{n='CompSYSVOL';e={$_.Computer.SysvolVersion}},
  @{n='UserAD';e={$_.User.DSVersion}}, @{n='UserSYSVOL';e={$_.User.SysvolVersion}}
Get-Content \\DC02\SYSVOL\contoso.com\Policies\{GUID}\GPT.INI

Run Get-GPO -Server DC02 against each DC and compare. GPMC shows the same data on the Details tab, and the domain node’s Status tab (Group Policy Infrastructure Status » Detect Now) compares every DC against a baseline DC in one pass.

If versions differ, check SYSVOL replication:

dfsrmig /getglobalstate
Get-DfsrBacklog -GroupName "Domain System Volume" -FolderName "SYSVOL Share" -SourceComputerName DC01 -DestinationComputerName DC02
repadmin /replsummary

dfsrmig must report the Eliminated state (DFSR, not FRS). A growing backlog, DFSR errors in the DFS Replication event log or AD replication failures need fixing before any GPO change will reach every client; see the dcdiag and repadmin health check.

  • Slow link: Windows estimates bandwidth to the DC; below 500 kbps by default the link is slow and extensions such as Software Installation and Folder Redirection are skipped. The threshold is set by Computer Configuration » Policies » Administrative Templates » System » Group Policy » “Configure Group Policy slow link detection”. The Operational log records the estimated bandwidth for each refresh.
  • Fast logon optimisation: Windows 11 signs users in before the network is ready and applies policy in the background. Settings that need foreground processing then take one or two extra restarts or sign-ins. Enable Computer Configuration » Policies » Administrative Templates » System » Logon » “Always wait for the network at computer startup and logon” on machines that rely on software installation or folder redirection.
  • Wi-Fi and VPN: machines that only reach a DC after the user connects a VPN log 1129 at startup. Computer settings then apply at the next background refresh (every 90 minutes with a random offset of up to 30 minutes).
  • Cached credentials: a user who signs in with cached credentials while offline gets the last cached policy; nothing new applies until a DC is reachable.

Check 10: Enable gpsvc debug logging

When events are not enough, the Group Policy service can write a detailed trace:

md %windir%\debug\usermode
reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Diagnostics" /v GPSvcDebugLevel /t REG_DWORD /d 0x00030002 /f
gpupdate /force
notepad %windir%\debug\usermode\gpsvc.log

The usermode folder must exist or no log is written. Search the log for error, failed and the GPO GUID. It shows the DC chosen, bandwidth estimate, each GPO’s filtering decision and the return code of each extension.

Check 11: The setting itself

Sometimes Group Policy is applying and the setting is the problem:

  • The ADMX in the Central Store is older than the client, so the setting does not exist on that build, or it applies only to certain editions (many settings ignore Windows 11 Pro).
  • Security Options and some other settings need a restart even after a successful refresh.
  • A Group Policy Preferences item uses item-level targeting that evaluates to false; gpresult shows the preference extension as applied but the item skipped. Check the Operational log and the preference’s Common tab.
  • Intune may be configuring the same area. For Policy CSP settings, Group Policy wins unless MDMWinsOverGP is set.

Check 12: Model before you change anything

In GPMC, right-click Group Policy Modeling and run the wizard for the user and computer containers. If modeling shows the GPO applying but the real Results report does not, the design is right and the fault is on the client, the network or a DC. If modeling also denies it, fix scope or filtering first.

Verify it works

After each fix, confirm the Group Policy not applying symptom is gone on the machine that reproduced it, not only on your admin workstation.

  1. Run gpupdate /force and confirm it completes without errors.
  2. Run gpresult /r and confirm the GPO appears under Applied Group Policy Objects with the expected DC and a current timestamp.
  3. Check the value the setting writes, for example reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\System.
  4. In the Operational log, confirm event 8004 (manual computer processing completed) or 8001 (user logon processing completed) without a preceding 7016.

Troubleshooting quick reference

SymptomLikely causeFix
GPO missing from gpresult entirelyNot linked above the object, link disabled, object in CN=ComputersLink to the right OU; move the object into an OU
Denied (Security)Filtering excludes the account, or MS16-072 Read missingAdd the group with Apply; give Domain Computers Read
Denied (WMI Filter)Query false on this clientTest with Get-CimInstance; fix the query
Not Applied (Empty)No settings in that half of the GPO, or settings in the wrong halfMove the setting to User or Computer Configuration as needed
User settings missing on an RDS hostGPO linked to the computer OU without loopbackEnable loopback, or link to the user OU
Event 1058 error 5Permissions on the GPO or shareRestore Authenticated Users Read; check SYSVOL share and NTFS ACLs
Event 1058 error 3 on one DCGPT folder not replicatedFix DFSR, compare AD and SYSVOL versions
Event 1129 at every startupNetwork not ready, VPN onlyAlways wait for the network; check NIC drivers and 802.1X
Settings arrive only after two restartsFast logon optimisationAlways wait for the network at computer startup and logon
Old values keep coming backAnother GPO wins or a stale DCCheck Winning GPO in the HTML report; compare DC versions

Clean up after troubleshooting

  • Turn gpsvc logging off: reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Diagnostics" /v GPSvcDebugLevel /t REG_DWORD /d 0 /f, then delete gpsvc.log.
  • Remove any test Deny entries, temporary WMI filters or links you added while testing.
  • Record the root cause of each Group Policy not applying case, so the service desk can match the next occurrence from the event ID.

Most cases of Group Policy not applying are settled at Check 2 or Check 4. Work through the remaining checks only when gpresult shows processing failures or DC-specific differences.

Group Policy not applying at a glance

Group Policy Not Applying summary card: On the affected machine, run gpupdate /force, then gpresult /h C:\Temp\gp.html from an elevated prompt and open the…
In short: On the affected machine, run gpupdate /force, then gpresult /h C:\Temp\gp.html from an elevated prompt and open the report.

Official documentation: Applying Group Policy troubleshooting guidance, gpresult command reference.

Related guides: GPO security filtering: target or exclude users and computers · Group Policy processing order, Enforced and Block Inheritance · dcdiag repadmin Health Check: 7 Critical Tests Explained.

See also: Event ID 1058: Group Policy Failed to Read gpt.ini (Fix) · Event ID 1030: Group Policy Processing Failed (Causes and Fix) · Event ID 1129: Group Policy Failed, No Connectivity to a DC

Frequently asked questions

Why is Group Policy not applying even though gpupdate succeeds?

A successful gpupdate only means processing completed. The GPO can still be out of scope, filtered out by security or a WMI filter, overridden by a higher-precedence GPO, or waiting for a restart or sign-in. Check the denied list and the Winning GPO column in gpresult /h.

What does event 1058 mean?

The client could not read gpt.ini for a GPO from the domain controller. The error code in the event tells you whether the path was not found, access was denied or the network path was unreachable, which points to SYSVOL replication, GPO permissions or name resolution.

Do I need Authenticated Users on every GPO?

Since MS16-072, user policies are read in the computer’s security context, so the computer needs Read permission. If you remove Authenticated Users from security filtering, add Domain Computers or Authenticated Users back with Read only.

How long does a GPO change take to reach clients?

Member computers refresh every 90 minutes with a random offset of up to 30 minutes, and domain controllers every 5 minutes. Replication between DCs adds its own delay. Some settings also need a restart or a new sign-in.

Is rsop.msc still useful?

It still opens, but it does not show Group Policy Preferences and is slower than gpresult. Use gpresult /h or GPMC Group Policy Results instead.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.