Group Policy loopback processing makes the user settings that apply at sign-in depend on the computer, not only on where the user account sits in Active Directory. You need it when the same people sign in to their own desktop and to an RDS host, a kiosk or a classroom PC, and those machines need a different, usually stricter, user experience. This guide explains merge and replace mode, how Windows gathers the GPO list, how to set it up for RDS and kiosks, the security filtering rules that trip most admins, and how to prove it works.
Short answer: Link a GPO to the OU that holds the RDS hosts or kiosks and enable Computer Configuration » Policies » Administrative Templates » System » Group Policy » "Configure user Group Policy loopback processing mode" with mode Merge (RDS) or Replace (kiosks). Put the user settings for those machines in GPOs linked to the same OU. Keep Authenticated Users with Read on every GPO so computers can read the user settings, and check the result with gpresult /scope user /r as a test user on the host.
Table of Contents
When you need loopback
- RDS session hosts: hide drives, lock down the Start menu or set session behaviour for everyone on the host, while their own PCs stay normal.
- Kiosks and reception PCs: give every user the same fixed desktop, whatever OU their account is in.
- Classrooms and labs: apply lab-specific user settings to students and staff.
- Servers: give administrators a different Explorer or browser configuration when they sign in to servers.
You do not need loopback for computer settings. For example, the RDS session time limits exist under Computer Configuration as well, and the computer-side version applies to every session without Group Policy loopback processing.
For a single preference item, such as one drive map that should only appear on RDS hosts, item-level targeting with a Terminal Session or Organizational Unit condition is often simpler than loopback. Use loopback when you need a whole set of user policies to depend on the machine, not just one or two items.
How user settings are gathered
Normally, user settings come from GPOs linked along the user object’s path, and computer settings from GPOs along the computer object’s path. Take user Adele in OU=Sales,OU=Staff signing in to RDS01 in OU=RDS,OU=Servers:
| Mode | User GPO list, in processing order | Winner on conflict |
|---|---|---|
| No loopback | Local, site, domain, Staff, Sales | Sales OU GPOs |
| Merge | Local, site, domain, Staff, Sales, then site, domain, Servers, RDS | RDS OU GPOs (they apply last) |
| Replace | Local, site, domain, Servers, RDS only | RDS OU GPOs; Sales and Staff GPOs are ignored |
In merge mode, Windows builds the user’s normal list, then appends the list it got for the computer at startup. The computer’s list is processed later, so its user settings win any conflict. In replace mode, Windows processes the user settings as if the user object lived in the computer’s OU.
Loopback is computer-wide
The setting is an Administrative Template value on the computer: UserPolicyMode (REG_DWORD) under HKLM\SOFTWARE\Policies\Microsoft\Windows\System, with 1 for merge and 2 for replace. Once any GPO that applies to the computer sets it, it changes user processing for every user who signs in and for every GPO, not only the GPO that contains the setting. One GPO with loopback enabled on an OU is enough.
Merge or replace?
| Merge | Replace | |
|---|---|---|
| User’s own GPOs | Apply first | Ignored |
| Computer-path user settings | Apply last and win | The only user settings |
| Drive maps, printers, folder redirection from the user OU | Still apply | Do not apply unless also linked to the computer path |
| Typical use | RDS hosts, staff laptops in special OUs | Kiosks, classrooms, public PCs |
| Main risk | Slower sign-in; domain-linked GPOs are processed twice | Users miss settings they expect |
Pick merge when users should keep their normal drives and settings and you only add restrictions. Pick replace when the machine must look the same for everyone and you do not want department GPOs to apply at all.
Prerequisites
- Domain-joined computers; loopback does not work in a workgroup.
- RDS hosts, kiosks or lab PCs in their own OU, separate from normal workstations.
- Rights to create and link GPOs, and GPMC.
- A test user account that is not an administrator.
Configure Group Policy loopback processing
Step 1: Enable loopback on the computer OU
- In GPMC, right-click the RDS or kiosk OU and choose Create a GPO in this domain, and Link it here. Name it, for example, CFG – Loopback Merge.
- Edit it and go to
Computer Configuration » Policies » Administrative Templates » System » Group Policy. - Open “Configure user Group Policy loopback processing mode”, select Enabled, choose Merge or Replace in Mode, and click OK.
- Keep this GPO small. A dedicated GPO makes it obvious in reports why user settings behave differently on these machines.
Step 2: Add the user settings
- Create a second GPO linked to the same OU, for example USR – RDS Lockdown.
- Configure only User Configuration, for example
User Configuration » Policies » Administrative Templates » Windows Components » File Explorer » "Hide these specified drives in My Computer", or Start menu restrictions. - In the GPO’s Details tab, set GPO Status to Computer configuration settings disabled. It speeds up computer processing and shows the GPO’s purpose.
Step 3: Restart and sign in
The loopback value is a computer setting, so restart the host or run gpupdate /force and wait for the next computer refresh. Then sign in as the test user; user settings from the computer’s path are applied during that sign-in.
Security filtering with loopback
This is where most Group Policy loopback processing setups fail. Three rules apply:
- The GPO that enables loopback is computer-side. The computer account needs Read and Apply group policy, which Authenticated Users gives by default.
- The GPO with the user settings is still processed for the user, in the user’s security context. The user needs Read and Apply group policy on it, even though it is linked to the computer’s OU.
- The computer must read user GPOs. Since MS16-072 (June 2016), Windows retrieves user policy with the computer’s security context. The computer account needs at least Read on every GPO that holds user settings, otherwise the user part fails with access denied.
A classic mistake is to filter USR – RDS Lockdown to a group of RDS host computer accounts. The hosts can read it, but users have no Apply permission, so nothing applies. The correct pattern to target only some users on the host:
- On the GPO’s Delegation tab, click Advanced, select Authenticated Users and clear Apply group policy, keeping Read.
- Add the user group, for example SG-RDS-Users, with Read and Apply group policy.
- To exclude admins, add SG-Admins and tick Deny for Apply group policy.
Check the result with PowerShell:
Get-GPPermission -Name 'USR - RDS Lockdown' -All | Format-Table Trustee, Permission, Denied
RDS host example (merge)
- CFG – Loopback Merge on
OU=RDS: loopback in merge mode. - USR – RDS Lockdown on
OU=RDS: hide the C: drive, remove Run from the Start menu, and prevent access to the command prompt, filtered to SG-RDS-Users. - Normal user GPOs on
OU=Staff: drive maps, printers and folder redirection keep working on the host because merge keeps the user’s own list.
If a staff GPO and the RDS GPO set the same value, the RDS GPO wins on the host. On the user’s own PC, loopback is not enabled, so only the staff GPO applies.
Kiosk example (replace)
- CFG – Loopback Replace on
OU=Kiosks: loopback in replace mode. - USR – Kiosk Desktop on
OU=Kiosks: wallpaper, a fixed browser home page, no Control Panel and the kiosk printer. - Staff GPOs on
OU=Staffnever apply on kiosks, so a department drive map or a Sales script does not appear there. If kiosks still need a GPO that is linked at domain level, it applies because the domain is on the computer’s path too.
Users from another forest who sign in to these computers get replace mode for the computer’s GPOs unless you allow cross-forest user policy.
Design tips
- Link loopback low in the tree. Never enable it in a GPO linked to the domain or a large parent OU. Link it to the smallest OU that holds only the special machines.
- Separate the OUs. Keep RDS hosts, kiosks and labs in their own OUs, away from normal servers and workstations, so the loopback link cannot reach them by accident through inheritance.
- Name GPOs by side. A prefix such as CFG for computer settings and USR for user settings makes it clear which GPOs on a computer OU are meant to be read through loopback.
- Watch Block Inheritance and Enforced. In replace mode, the computer’s path decides the user list, so an Enforced user GPO linked at domain level still applies on kiosks, and Block Inheritance on the kiosk OU stops non-enforced domain GPOs for users as well as computers.
- Preferences follow the same list. Drive maps, printers and shortcuts in User Configuration » Preferences are gathered exactly like Administrative Templates, so item-level targeting still works inside a loopback GPO.
- Profiles and folder redirection. Folder redirection is a user setting too. In replace mode, a redirection GPO linked to the user OU does not apply on the host, which can leave users with local folders there. Decide deliberately whether RDS users should get the same redirected folders.
- Test with a real user. Administrators are often excluded or have extra rights, so always test Group Policy loopback processing with a normal account from each department.
Verify it works
- On the host, confirm the mode:
reg query "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v UserPolicyMode0x1is merge and0x2is replace. - Sign in as the test user and list the applied user GPOs:
gpresult /scope user /r
gpresult /h C:\Temp\loopback.html /f
With Group Policy loopback processing active, the user’s Applied Group Policy Objects list includes GPOs linked to the computer’s OU, such as USR – RDS Lockdown. GPOs filtered out appear with the reason, for example Denied (Security). - As an admin, you can run the same report for another user who has signed in to that host:
gpresult /s RDS01 /user CONTOSO\adele /h C:\Temp\adele.html, or use the Group Policy Results wizard in GPMC. - To plan a change before you make it, run the Group Policy Modeling wizard in GPMC and select the loopback option with merge or replace.
- In Event Viewer, open
Microsoft-Windows-GroupPolicy/Operational. For the user processing cycle, event 5312 lists the applicable GPOs and event 5313 lists GPOs filtered out and why.
For deep troubleshooting, set GPSvcDebugLevel (REG_DWORD 0x30002) under HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Diagnostics, create %windir%\debug\usermode if it does not exist, reproduce the sign-in and read gpsvc.log. Remove the value afterwards.
Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
| User settings from the computer OU do not apply | Loopback GPO not applied to the computer, or no restart | Check UserPolicyMode and gpresult /scope computer /r |
| Access denied for user GPOs in the report | Computer lacks Read after Authenticated Users was removed | Give Authenticated Users or Domain Computers Read only |
| GPO filtered to host computers applies nothing | Users lack Apply on a user-settings GPO | Grant the user group Read and Apply |
| Users lost drive maps on kiosks | Replace mode ignores the user OU | Expected; link needed items to the kiosk path or use merge |
| Loopback affects servers you did not expect | Loopback enabled in a GPO linked higher up, such as the domain | Link the loopback GPO only to the specific OU |
| Slow sign-in on RDS | Merge processes domain-linked user GPOs twice | Consider replace, or trim user GPOs linked at domain level |
| Admins also locked down on the host | No deny for the admin group | Deny Apply group policy for the admin group on the user-settings GPO |
Roll back or undo
- Set “Configure user Group Policy loopback processing mode” to Not Configured, or unlink the loopback GPO.
- Run
gpupdate /forceor restart the host so theUserPolicyModevalue is removed. - Users get their normal user settings at the next sign-in; Administrative Template values from the computer-path GPOs are removed when they no longer apply.
- Preference items without “Remove this item when it is no longer applied” leave their changes behind, so review drive maps, registry and shortcut items in the user-settings GPO before unlinking it.
Document which OUs use Group Policy loopback processing and in which mode. It is the first thing to check when a user reports that a setting behaves differently on one machine.
Group Policy loopback processing at a glance

Official documentation: Circle back to loopback (Ask the Directory Services Team), Cannot apply user GPO when computer objects do not have Read permissions, Diagnose scope, precedence, filtering, and targeting.
Related guides: Group Policy processing order, Enforced and Block Inheritance · GPO security filtering: target or exclude users and computers · Troubleshoot Group Policy not applying: gpresult, RSoP and Events 1058/1030.
Frequently asked questions
What is the difference between merge and replace in loopback processing?
Merge applies the user’s normal GPOs first and then the user settings from GPOs on the computer’s path, which win conflicts. Replace ignores the user’s normal GPOs and applies only the user settings from the computer’s path.
Does loopback only affect the GPO where I enable it?
No. It is a computer setting, so once any GPO that applies to the computer enables it, user processing changes for every user and every GPO on that computer.
Why are my loopback user settings not applying?
Most often the user lacks Read and Apply group policy on the GPO linked to the computer’s OU, or the computer lacks Read after Authenticated Users was removed. Check the Delegation tab and the gpresult report.
Should I use merge or replace on an RDS host?
Use merge on most RDS hosts, so users keep their drive maps and printers and you only add restrictions. Use replace for kiosks and public PCs that must look the same for everyone.
How can I see whether loopback is enabled on a computer?
Query UserPolicyMode under HKLM\SOFTWARE\Policies\Microsoft\Windows\System: 1 means merge and 2 means replace. The gpresult HTML report also shows the setting in the computer section.