Emergency server help: get in touch

Event ID 1030: Group Policy Processing Failed (Causes and Fix)

Event ID 1030 means Group Policy could not retrieve its GPO list from a domain controller. Read the error code, find the cause (DNS, ports, time, secure channel) and fix it.

Published 7 min read

Short answer: Event ID 1030 is logged by Microsoft-Windows-GroupPolicy in the System log when Windows cannot retrieve the list of Group Policy objects from a domain controller. In practice the computer could not reach or authenticate to Active Directory. The real cause is the error code on the event’s Details tab. Most often the client uses the wrong DNS servers, LDAP or RPC traffic is blocked, the clock is off, or the computer’s secure channel is broken. Fix that cause, run gpupdate /force and look for event 1500 to 1503.

Commands checked against the official documentation (linked below) on 7 October 2026; not yet run on our lab servers.

What event ID 1030 means

PropertyValue
LogSystem
Source (provider)Microsoft-Windows-GroupPolicy
LevelError
Symbolic namegpEvent_GPO_QUERY_FAILED
Logged onThe computer that tried to process policy (workstation, member server or domain controller)

The message text, as Microsoft documents it:

The processing of Group Policy failed. Windows attempted to retrieve new Group Policy settings for this user or computer. Look in the Details tab for error code and description. Windows will automatically retry this operation at the next refresh cycle. Computers joined to the domain must have proper name resolution and network connectivity to a domain controller for discovery of new Group Policy objects and settings. An event will be logged when Group Policy is successful.

The message has no placeholders. The useful data is on the Details tab: a Win32 error code (decimal) and its description. Microsoft sums up the cause as “an absence of authenticated connectivity from the computer to the domain controller.” User field SYSTEM means computer policy failed; a user name means that user’s policy failed.

Windows XP and Server 2003 logged a different 1030 from the Userenv source. This page covers the modern event.

Common causes

  • Wrong DNS servers. The client points at a router, an ISP resolver or a public resolver, so it cannot find the domain’s SRV records. The Details tab often shows error 1355 (“The specified domain either does not exist or could not be contacted”).
  • Blocked ports. LDAP (389) or RPC traffic to the DC is blocked by a host firewall, a network firewall or a VPN policy. Microsoft’s guidance for 1030 starts here. Error 1727 (RPC call failed) points the same way.
  • Authentication failure. The computer cannot authenticate to the DC. Typical reasons are a broken secure channel (machine password mismatch) or a clock more than five minutes away from the DC, the default Kerberos tolerance.
  • Permissions. The computer or user cannot read its OU or a GPO’s container in AD (for example after someone removed Authenticated Users from a GPO’s delegation).
  • Unhealthy DC. The DC the client picked has broken replication or services.

How to find the cause

Start with the event itself. This pulls the last ten 1030 events and prints every EventData field, so you see the error code without guessing field names:

Get-WinEvent -FilterHashtable @{LogName='System'; ProviderName='Microsoft-Windows-GroupPolicy'; Id=1030} -MaxEvents 10 |
  ForEach-Object {
    $x = [xml]$_.ToXml()
    [pscustomobject]@{
      Time   = $_.TimeCreated
      User   = $_.UserId
      Fields = ($x.Event.EventData.Data | ForEach-Object { "$($_.Name)=$($_.'#text')" }) -join '; '
    }
  } | Format-List

Translate a Win32 code you do not recognise with net helpmsg 1355 (swap in your number).

Next, follow the same processing run in the Group Policy Operational log. Each run has its own ActivityID, and Microsoft’s troubleshooting guide filters the Operational log on it:

$e   = Get-WinEvent -FilterHashtable @{LogName='System'; ProviderName='Microsoft-Windows-GroupPolicy'; Id=1030} -MaxEvents 1
$aid = $e.ActivityId.ToString('B').ToUpper()
Get-WinEvent -LogName 'Microsoft-Windows-GroupPolicy/Operational' -FilterXPath "*[System/Correlation/@ActivityID='$aid']" |
  Sort-Object TimeCreated | Format-Table TimeCreated, Id, LevelDisplayName, Message -Wrap

Then test the usual suspects from the affected computer (replace contoso.local and dc01 with your names):

ipconfig /all                                    # DNS servers must be your DCs / AD DNS
Resolve-DnsName -Type SRV _ldap._tcp.dc._msdcs.contoso.local
nltest /dsgetdc:contoso.local                    # which DC does the locator return?
Test-NetConnection dc01.contoso.local -Port 389
Test-ComputerSecureChannel -Verbose              # Windows PowerShell 5.1
w32tm /query /status
gpresult /h C:\Temp\gp.html

In the console: open Event Viewer, go to Windows Logs > System, choose Filter Current Log, pick the Microsoft-Windows-GroupPolicy source and enter 1030. Read the newest event’s Details tab for the error code. Per-run detail is under Applications and Services Logs > Microsoft > Windows > GroupPolicy > Operational.

How to fix it

DNS pointing at the wrong servers

Set the client’s DNS servers to your AD DNS servers only, with no public resolver as “secondary”. Run ipconfig /flushdns and ipconfig /registerdns, then check the SRV lookup returns your DCs. Fix DHCP scope options if the bad servers come from there.

Blocked LDAP or RPC

If Test-NetConnection to port 389 fails, open the path between client and DC: Windows Firewall on both ends, network firewalls and VPN split-tunnel rules. Microsoft also points to PortQry for checking the AD port set. Our Windows Firewall Group Policy guide covers deploying rules centrally.

Clock or secure channel

Resync time with w32tm /resync and make sure the domain hierarchy is healthy. Our PDC emulator time sync guide covers the root of that hierarchy. If Test-ComputerSecureChannel returns False, repair it with Test-ComputerSecureChannel -Repair -Credential CONTOSO\admin and restart. See our Event ID 5805 page for the DC side of the same problem.

Permissions on the OU or GPO

List who can read a GPO with Get-GPPermission -Name "Workstation Baseline" -All. The computer (or Authenticated Users or Domain Computers) needs Read on the GPO and on the OU that holds its object.

Unhealthy domain controller

Run dcdiag and repadmin /replsummary on the DC that nltest /dsgetdc returned and fix its errors first.

Check that it worked

Run gpupdate /force on the client, then confirm a success event followed it. Microsoft lists 1500 to 1503 as the “Group Policy is working” events:

gpupdate /force
Get-WinEvent -FilterHashtable @{LogName='System'; ProviderName='Microsoft-Windows-GroupPolicy'; Id=1500,1501,1502,1503,1030} -MaxEvents 6 |
  Format-Table TimeCreated, Id, Message -Wrap

The newest entry should be 1500/1502 (computer) or 1501/1503 (user), not 1030. gpresult /r should list the expected GPOs.

Common problems

  • 1030 only at startup, success a few minutes later: that is a network-ready timing issue, usually logged as 1129. See our Event ID 1129 page.
  • Works on the LAN, fails on VPN: the VPN profile does not push AD DNS servers or does not allow 389/RPC to the DCs.
  • Computer policy works, user policy fails: check the user’s OU and GPO read permissions and whether the user’s password expired while signed in.
  • Test-ComputerSecureChannel is not recognised: it exists only in Windows PowerShell 5.1, not PowerShell 7. Run it in powershell.exe.
Event IDSourceWhat it means
1006Microsoft-Windows-GroupPolicyCould not authenticate to AD (LDAP bind failed). Read the error code.
1054Microsoft-Windows-GroupPolicyCould not obtain the name of a domain controller (usually DNS).
1055Microsoft-Windows-GroupPolicyCould not resolve the computer name (DNS or AD replication latency).
1058Microsoft-Windows-GroupPolicyCould not read a GPO’s gpt.ini from SYSVOL (error 3, 5 or 53 are common).
1097Microsoft-Windows-GroupPolicyCould not determine the computer account; check time sync.
1129Microsoft-Windows-GroupPolicyNo network connectivity to a DC, often at startup.
1500-1503Microsoft-Windows-GroupPolicyComputer (1500, 1502) or user (1501, 1503) policy processed successfully.

Official documentation: Event ID 1030: Group Policy Preprocessing (Active Directory) · Applying Group Policy troubleshooting guidance · Application of Group Policy events (1500-1503)

Related: Group Policy Not Applying: 12 Checks with gpresult and Events · Force gpupdate Remote Computers: 5 Methods for Every OU · Trust Relationship Failed: Fix Workstation Domain Problems · dcdiag repadmin Health Check: 7 Critical Tests Explained

See also: Event ID 1058: Group Policy Failed to Read gpt.ini (Fix) · Event ID 1129: Group Policy Failed, No Connectivity to a DC

Frequently asked questions

Can I ignore event ID 1030?

Not if it repeats. A single 1030 followed by a success event is a transient failure. Repeated 1030s mean the computer is running on cached or old policy and new GPO changes are not reaching it.

Where is the error code for event 1030?

On the Details tab of the event in Event Viewer, or in the EventData fields returned by Get-WinEvent and ToXml(). It is a decimal Win32 code; net helpmsg translates it.

Does gpupdate /force fix event 1030?

Only if the cause was temporary. gpupdate retries processing; it does not fix DNS, firewall, time or secure channel problems. Use it to confirm the fix.

What is the difference between event 1030 and 1058?

1030 means the list of GPOs could not be retrieved from AD. 1058 means a GPO was found but its gpt.ini file could not be read from SYSVOL.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.