Emergency server help: get in touch

Registry Group Policy Preferences: 4 Safe Ways to Deploy Registry Keys

Deploy, change and remove registry keys and values on Windows 11 and Windows Server 2025 with Group Policy Preferences, the Registry Wizard, item-level targeting and PowerShell, and learn when an ADMX policy or Intune Remediations fits better.

Published Updated 13 min read

Registry Group Policy Preferences items let you create, change or delete registry keys and values on domain computers and user profiles without writing a custom ADMX template or a logon script. You need them when an application stores its settings in the registry and has no policy template, when you want to change a Windows default that users may still adjust later, or when you must remove a value from hundreds of machines at once. This guide covers the Registry item and its four actions, the Registry Wizard, collections, targeting, PowerShell, Intune alternatives, verification and rollback.

Short answer: Edit a GPO and go to Computer Configuration » Preferences » Windows Settings » Registry (or the same path under User Configuration for HKCU). Choose New » Registry Item, set Action to Update, pick the hive, key path, value name, type and data, and click OK. Run gpupdate /force and check the value with reg query.

Which method to use

MethodEnforced?Cleans up when removed?Best for
GPP Registry itemReapplied at each refresh; users can change it in betweenOnly with “Remove this item when it is no longer applied”Any key or value, including HKLM\SOFTWARE and HKCU
Administrative Template (ADMX) settingYes, UI often greyed outYes, keys under Software\Policies are removedSettings Microsoft or the vendor already ship a template for
Set-GPRegistryValue (policy-based registry)YesYes under Software\Policies, otherwise tattooedScripting policy keys without an ADMX
Custom ADMX templateYesOnly for keys under Software\PoliciesReusable settings with a friendly UI
Intune Settings catalog, Remediations or platform scriptDepends on methodNo, unless you script itMicrosoft Entra joined devices

If a setting has an ADMX policy, use the policy. Use registry Group Policy Preferences items for everything else, and for values you want to set as a default that users may override.

Prerequisites

Registry Group Policy Preferences need very little set-up, but check these points first:

  • Windows 11 Pro, Enterprise or Education, or Windows Server 2016 to 2025, joined to the domain. The Group Policy Registry client-side extension is built in.
  • Rights to edit and link GPOs and the Group Policy Management Console. For PowerShell, the GroupPolicy module from RSAT.
  • The exact key path, value name, type and data, tested on one machine first. Export the key with reg export before you change it.
  • A test OU with a computer and a test user.

Method 1: Create a Registry preference item

This is the core registry Group Policy Preferences workflow and the one you will use most.

  1. In Group Policy Management, create or edit a GPO linked to the OU that holds the target computers (for HKLM) or users (for HKCU).
  2. Go to Computer Configuration » Preferences » Windows Settings » Registry or User Configuration » Preferences » Windows Settings » Registry.
  3. Right-click Registry and choose New » Registry Item.
  4. Set Action (see the table below). Use Update unless you have a reason not to.
  5. Set Hive, for example HKEY_LOCAL_MACHINE, and Key Path without the hive and without leading or trailing backslashes, for example SOFTWARE\Contoso\LOBApp. The … button browses the registry of the machine you are editing on.
  6. Type the Value name (or tick Default for the key’s default value), choose the Value type and enter the Value data. For REG_DWORD choose Decimal or Hexadecimal.
  7. Click OK. On a test machine run gpupdate /force and check the value.

The Key Path, Value name and Value data fields accept preference variables. Press F3 in a field to insert one, for example %ComputerName% or %LogonUser%.

Create, Replace, Update and Delete

ActionOn a valueOn a key (no value name)
CreateCreates the value only if it does not existCreates the key if missing
ReplaceDeletes and recreates the value, overwriting everything about itDeletes all values and subkeys in the key, leaving an empty key
UpdateChanges only what the item defines; creates the value if missingCreates the key if missing; leaves existing content
DeleteRemoves the valueRemoves the key with all its values and subkeys

Be careful with Replace on a key: Microsoft documents that it deletes everything below the key before recreating it. That is useful to reset an application’s settings, and disastrous on a shared key such as SOFTWARE\Microsoft\Windows\CurrentVersion\Run.

HKCU vs HKLM

  • HKLM items go in Computer Configuration and apply at startup and every background refresh.
  • HKCU items go in User Configuration and apply at logon and every background refresh. An HKCU item placed under Computer Configuration writes to the SYSTEM account’s hive, not to the signed-in user.
  • User items are processed in the system’s security context by default, so they can write under HKCU\Software\Policies, which users cannot change themselves. Tick Run in logged-on user’s security context on the Common tab only when the item needs the user’s own network access.
  • To apply user registry items on specific computers only, such as Remote Desktop hosts, use loopback processing or item-level targeting by computer.

Example: show file name extensions for every user. User Configuration » Preferences » Windows Settings » Registry, action Update, hive HKEY_CURRENT_USER, key Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, value HideFileExt, type REG_DWORD, data 0. Users can still switch it back in File Explorer until the next refresh.

Method 2: Registry Wizard and collections

When an application needs a dozen values, do not type them one by one.

  1. Configure the application on a reference machine.
  2. In the GPO, right-click Registry and choose New » Registry Wizard, select the local computer (or another computer you can reach), and click Next.
  3. Browse to the key and tick each key and value you want. Click Finish.
  4. The wizard creates one Registry item per value, grouped in a collection named after the path. Open a few items and change the action from Update if needed.

To organise items yourself, right-click Registry and choose New » Collection Item, then drag items into it. Collections have no effect on where values land in the registry, but you can apply item-level targeting to the whole collection instead of each item.

Common options: targeting, apply once and removal

The Common tab decides how registry Group Policy Preferences items behave over time.

OptionEffectWhen to use
Stop processing items in this extension if an error occurs on this itemA failing item stops later items in the same GPO. Items are processed from the bottom of the list up.When later items depend on this one
Run in logged-on user’s security contextProcesses a user item as the user instead of the systemRarely for registry items
Remove this item when it is no longer appliedDeletes the value when the item goes out of scope; changes the action to ReplaceValues you want cleaned up when a user or computer leaves the scope
Apply once and do not reapplyWrites the value once; later refreshes skip itA first-run default users may change
Item-level targetingApplies the item only when the conditions are truePer group, OS, OU or existing registry state

Useful targeting items for registry work: Security Group (for example only members of Finance Users), Operating System (Windows 11 only), Registry Match (only if the application’s key exists, so you do not create keys for software that is not installed) and Organizational Unit. Add several and combine them with And, Or and Is Not.

Preferences vs ADMX policies and tattooing

A policy setting from an ADMX template writes under Software\Policies or Software\Microsoft\Windows\CurrentVersion\Policies. When the GPO no longer applies, Windows removes those values and the application falls back to its own default. Values written anywhere else stay in the registry after the GPO is gone; this is called tattooing.

  • A registry Group Policy Preferences item tattoos by default. Tick Remove this item when it is no longer applied if you want the value removed when the GPO stops applying.
  • A custom ADMX template that points at a key outside Software\Policies also tattoos, and it hides that fact behind a policy-style UI. If you write a custom ADMX, keep it under Software\Policies\<Vendor>.
  • Preferences do not grey out the UI. If you must stop users changing a value, use a policy key the application reads, or accept that the preference reapplies at the next refresh.

Method 3: PowerShell

The GroupPolicy module has cmdlets for both preference items and policy-based registry values.

Import-Module GroupPolicy
Set-GPPrefRegistryValue -Name 'APP - LOBApp Settings' -Context Computer -Action Update `
    -Key 'HKLM\SOFTWARE\Contoso\LOBApp' -ValueName 'ServerName' `
    -Value 'app01.contoso.com' -Type String
Set-GPPrefRegistryValue -Name 'APP - LOBApp Settings' -Context Computer -Action Update `
    -Key 'HKLM\SOFTWARE\Contoso\LOBApp' -ValueName 'Port' -Value 8443 -Type DWord
Get-GPPrefRegistryValue -Name 'APP - LOBApp Settings' -Context Computer `
    -Key 'HKLM\SOFTWARE\Contoso\LOBApp'

Points to know about Set-GPPrefRegistryValue:

  • -Action takes Create, Replace, Update or Delete; -Type takes String, ExpandString, Binary, DWord, MultiString or QWord.
  • It always adds a new item; it does not edit an existing one. Run Remove-GPPrefRegistryValue with the same GPO, context, key and value name first, or you end up with duplicates.
  • It cannot set item-level targeting or the Common tab options. Add those in the editor afterwards.

For policy keys, Set-GPRegistryValue writes a registry-based policy setting, the same kind an ADMX template writes:

Set-GPRegistryValue -Name 'APP - LOBApp Settings' `
    -Key 'HKLM\SOFTWARE\Policies\Contoso\LOBApp' `
    -ValueName 'DisableUpdates' -Type DWord -Value 1
Get-GPRegistryValue -Name 'APP - LOBApp Settings' -Key 'HKLM\SOFTWARE\Policies\Contoso\LOBApp'

Values written this way appear under Extra Registry Settings in GPMC reports because no ADMX describes them. Keep them under Software\Policies so they are removed when the GPO is unlinked.

Method 4: Intune alternatives

  • Settings catalog first. Many Windows and Office settings already exist as CSPs or ingested ADMX. Search the Settings catalog before you build anything custom.
  • Custom OMA-URI via ADMX ingestion. You can import a third-party ADMX and set its policies, but Microsoft blocks ingested policies from writing to System, Software\Microsoft and Software\Policies\Microsoft, apart from listed exceptions such as Office, OneDrive and Edge paths. There is no generic “write any registry value” setting.
  • Remediations. A detection script checks the value and exits with 1 when it is wrong; the remediation script fixes it. Create the package under Devices » Manage devices » Scripts and remediations. Users need Windows Enterprise E3/E5, Education A3/A5 or VDA per user licences.
  • Platform scripts. A PowerShell script under Devices » Scripts and remediations » Platform scripts runs once per device (or user) and is not reapplied, so it behaves like “Apply once”.

Detection and remediation pair for the example value:

# Detection
$p = 'HKLM:\SOFTWARE\Contoso\LOBApp'
$v = (Get-ItemProperty -Path $p -Name ServerName -ErrorAction SilentlyContinue).ServerName
if ($v -eq 'app01.contoso.com') { exit 0 } else { exit 1 }
# Remediation
$p = 'HKLM:\SOFTWARE\Contoso\LOBApp'
New-Item -Path $p -Force | Out-Null
New-ItemProperty -Path $p -Name ServerName -Value 'app01.contoso.com' -PropertyType String -Force | Out-Null

For HKCU values, set Run this script using the logged-on credentials to Yes, otherwise the script writes to the SYSTEM account’s hive.

Verify it works

Check registry Group Policy Preferences results on a pilot machine before you link the GPO widely.

  1. Refresh and read the value:
    gpupdate /force
    reg query "HKLM\SOFTWARE\Contoso\LOBApp" /v ServerName
    Get-ItemProperty -Path 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced' -Name HideFileExt
  2. Run gpresult /h C:\Temp\gp.html (as the user for HKCU items). The report lists each item under Preferences » Windows Settings » Registry with its result.
  3. Look in the Application log for warnings from source Group Policy Registry, such as event ID 4098, which name the failing item and the error code.
  4. For detail, enable “Configure Registry preference logging and tracing” under Computer Configuration » Policies » Administrative Templates » System » Group Policy » Logging and tracing. The trace files are written under %ProgramData%\GroupPolicy\Preference\Trace by default.
  5. The items themselves are stored in Registry.xml under \\contoso.com\SYSVOL\contoso.com\Policies\{GPO-GUID}\Machine\Preferences\Registry (or User\Preferences\Registry).

Troubleshooting

Most registry Group Policy Preferences failures are path, scope or targeting problems.

SymptomLikely causeFix
Value not written, no errorItem-level targeting evaluates to falseEnable preference tracing; check group membership and OS targeting
32-bit application ignores the valueThe item wrote the 64-bit viewUse SOFTWARE\WOW6432Node\… in the key path
Value reverts after users change itNormal: the item reapplies at each refreshUse “Apply once and do not reapply” for a default only
Value disappears unexpectedly“Remove this item when it is no longer applied” and the item went out of scopeCheck targeting, security filtering and GPO links
Other values in the key vanishedReplace action on a keyUse Update; restore from your reg export backup
HKCU value appears for SYSTEM, not the userItem placed under Computer ConfigurationMove it to User Configuration
Duplicate items after a script runSet-GPPrefRegistryValue adds new itemsRemove the old items first
Wrong DWORD dataDecimal and Hexadecimal mixed upCheck the base selected in the item

Roll back or undo

  1. Remove a value you deployed: change the item’s action to Delete, let it apply to all machines, then delete the item. Deleting the item straight away leaves the value in place.
  2. Items with “Remove this item when it is no longer applied”: unlinking the GPO or deleting the item removes the value at the next refresh.
  3. PowerShell: Remove-GPPrefRegistryValue -Name 'APP - LOBApp Settings' -Context Computer -Key 'HKLM\SOFTWARE\Contoso\LOBApp' -ValueName 'ServerName' removes the item from the GPO, not the value from clients.
  4. Policy-based values: Remove-GPRegistryValue or setting the ADMX policy to Not Configured removes values under Software\Policies from clients.

Back up the GPO with Backup-GPO before large changes, keep one registry Group Policy Preferences GPO per application, and name items clearly so the next administrator knows why each value exists.

Registry Group Policy Preferences at a glance

Registry Group Policy Preferences summary card: Edit a GPO and go to Computer Configuration » Preferences » Windows Settings » Registry (or the same path under User…
In short: Edit a GPO and go to Computer Configuration » Preferences » Windows Settings » Registry (or the same path under User Configuration for HKCU).

Official documentation: Group Policy Preferences, Set-GPPrefRegistryValue, Remediations in Microsoft Intune.

Related guides: Map Network Drives Group Policy: 2026 Item-Level Targeting Made Easy · Group Policy loopback processing: merge vs replace for RDS hosts and kiosks · Back up and restore GPOs with PowerShell.

Frequently asked questions

What is the difference between Update and Replace in a GPP Registry item?

Update changes only the value or key settings defined in the item and creates them if missing. Replace deletes and recreates the value; on a key it deletes all values and subkeys first, so use it with care.

Do Group Policy Preferences registry values stay after the GPO is removed?

Yes, by default the value stays in the registry. Tick “Remove this item when it is no longer applied” on the Common tab if you want Windows to delete it when the item goes out of scope.

Can users change a registry value set by Group Policy Preferences?

Yes. Preferences do not lock the setting, so a user can change it, but the item writes it again at the next Group Policy refresh unless it is set to apply once.

How do I deploy a registry value with Intune instead of Group Policy?

Look for the setting in the Settings catalog first. If none exists, use a Remediations script pair or a platform script, because custom OMA-URI settings cannot write arbitrary registry keys.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.