# Group Policy Not Applying: 12 Checks with gpresult and Events

Source: https://srvscripts.com/guides/group-policy-not-applying/
Updated: 2026-10-07
Publisher: srvScripts (https://srvscripts.com/)

When you find Group Policy not applying to a Windows 11 client or a Windows Server 2025 member server, the cause is almost always on a short list: the GPO is not in scope, it is filtered out, the client cannot reach a domain controller or SYSVOL, or a client-side extension failed while processing. This guide works through that list in the order that finds the fault fastest, with the exact commands, event IDs and registry values you need.

**Short answer:** On the affected machine, run `gpupdate /force`, then `gpresult /h C:\Temp\gp.html` from an elevated prompt and open the report. If the GPO is listed under Denied GPOs, the reason column (Security, WMI Filter, Empty, Disabled) tells you what to fix. If it is missing entirely, the GPO is not linked above the object’s OU. If gpupdate itself fails, read the System log for GroupPolicy events 1058, 1030, 1129 or 1055: they point to SYSVOL access, LDAP, network or name resolution problems.

In short: On the affected machine, run gpupdate /force, then gpresult /h C:\Temp\gp.html from an elevated prompt and open the report.

## Which tool to use

Each tool answers a different question about Group Policy not applying. Start with the client’s own view, then move to the domain side.

| Tool | Answers | Run where | Limits |
| --- | --- | --- | --- |
| gpresult /r | Which GPOs applied or were filtered, last refresh time, DC used, group membership | Client, elevated for computer data | Text only; no individual settings |
| gpresult /h | Every winning setting, the GPO it came from, denied GPOs with reasons, CSE status | Client | Needs a user profile on the machine for user data |
| GPMC » Group Policy Results | The same report, pulled remotely | Admin workstation with RSAT | Needs WMI and remote event log access through the firewall |
| GPMC » Group Policy Modeling | What should apply for a user and computer location | Admin workstation, uses a DC | Simulation only; ignores network and CSE failures |
| rsop.msc | Legacy RSoP snap-in | Client | Does not show Group Policy Preferences; use gpresult instead |
| Event logs | Why processing failed | Client | Operational log is detailed but verbose |
| gpsvc.log | Step-by-step trace of the Group Policy service | Client, after enabling debug logging | Large; turn off when finished |

## Prerequisites

- Local administrator rights on the affected machine (computer-side results need an elevated prompt).

- The Group Policy Management Console from RSAT, and read access to the GPOs.

- For remote results: the Windows Management Instrumentation (WMI-In) and Remote Event Log Management firewall rules enabled on the client.

- The name of the GPO and the exact setting that is not arriving, plus one user and one computer that reproduce the problem.

## Check 1: Force a refresh and read the error

```
gpupdate /force
gpupdate /target:computer /force
gpupdate /target:user /force
```

Read what gpupdate prints. “Computer Policy update has completed successfully” means processing ran; the problem is scope, filtering or the setting itself. “The processing of Group Policy failed” means the client could not finish, and the event log explains why (see Check 7). Some extensions only run at startup or sign-in: Software Installation, Folder Redirection and disk quota settings report that a restart or logoff is needed. Accept the prompt, or restart the machine yourself.

## Check 2: Read gpresult correctly

```
mkdir C:\Temp
gpresult /h C:\Temp\gp.html /f
gpresult /r /scope computer
gpresult /r /scope user
gpresult /s PC042 /user CONTOSO\jsmith /h C:\Temp\pc042.html
```

In the text output, check these lines first:

- **Group Policy was applied from**: the domain controller the client used. If it is a DC in another site or one you know is broken, the problem is DC locator or replication.

- **Last time Group Policy was applied**: if it is days old, processing is failing, not filtering.

- **Applied Group Policy Objects**: the GPO is in scope and passed filtering.

- **The following GPOs were not applied because they were filtered out**: each entry carries a reason such as Filtering: Denied (Security), Denied (WMI Filter), Not Applied (Empty), Disabled (GPO) or Disabled (Link).

- **The computer/user is a part of the following security groups**: the token as the client sees it. A computer picks up new group membership only after a restart; a user after signing out and in, or after `klist purge`.

The HTML report adds the Winning GPO for every setting and a Component Status table. A GPO that applied but whose setting is overridden shows another GPO as the winner, which is a precedence problem, not a case of Group Policy not applying.

## Check 3: Scope, links and inheritance

- In GPMC, select the GPO and open the **Scope** tab. Confirm it is linked to the OU that contains the object that owns the setting: computer settings follow the computer account, user settings follow the user account.

- Open the OU and check the **Group Policy Inheritance** tab. A Block Inheritance icon on the OU stops parent links unless they are Enforced. An enforced GPO higher up can also override yours.

- Check the link is enabled (right-click the link: **Link Enabled** must be ticked).

- On the GPO’s **Details** tab, check **GPO Status**. User configuration settings disabled or Computer configuration settings disabled silently removes half the GPO; All settings disabled removes everything.

- Default containers such as `CN=Computers` and `CN=Users` are not OUs and cannot have GPOs linked. Objects there only receive site and domain-level GPOs.

User settings in a GPO linked to a computer OU never apply unless [loopback processing](/guides/group-policy-loopback-processing/) is enabled on that computer, in Merge or Replace mode. This is the most common reason for user settings on an RDS host or kiosk appearing as Group Policy not applying.

## Check 4: Security filtering and MS16-072

Open the **Delegation** tab and click **Advanced**. A principal needs both Read and Apply group policy to receive the GPO.

- Since the June 2016 security update MS16-072, the client reads **user** policy in the **computer’s** security context. If you removed Authenticated Users from security filtering and added a user group, also give Authenticated Users or Domain Computers the Read permission (without Apply). Without it, gpresult shows the GPO as Denied (Security) or leaves it out, and event 1058 may report access denied.

- A Deny on Apply group policy for any group the object belongs to wins over every Allow.

- Filtering by a group that contains the right users does nothing for computer settings, and the reverse. Computer settings are evaluated against the computer account.

```
Get-GPPermission -Name "SEC - Screen Lock" -All | Format-Table Trustee, Permission, Denied
Set-GPPermission -Name "SEC - Screen Lock" -TargetName "Domain Computers" -TargetType Group -PermissionLevel GpoRead
```

## Check 5: WMI filters that evaluate to false

A WMI filter that returns no rows on the client, or a query with a syntax error, makes the GPO show as Denied (WMI Filter). Test the query on the client exactly as written in GPMC:

```
Get-CimInstance -Query "SELECT * FROM Win32_OperatingSystem WHERE ProductType = 1 AND Version LIKE '10.0.2%'"
```

No output means the filter is false on this machine. Typical mistakes are comparing `Version` against `'10.0.2'` without a wildcard, filtering on `Caption` strings that differ by language, and using a namespace other than `root\CIMv2` without changing it in the filter. Windows 11 still reports version `10.0.x`, so build numbers (22000 and later) are what distinguish it from Windows 10.

## Check 6: Domain controller, DNS and secure channel

When Group Policy not applying affects every GPO on a machine, the cause is usually in this chain. The client finds a DC through DNS SRV records, authenticates with Kerberos, reads the GPO list over LDAP and the files over SMB from SYSVOL. Test each link:

```
ipconfig /all
nltest /dsgetdc:contoso.com
nltest /sc_query:contoso.com
Test-ComputerSecureChannel -Verbose
nslookup -type=SRV _ldap._tcp.dc._msdcs.contoso.com
w32tm /query /status
dir \\contoso.com\SYSVOL\contoso.com\Policies
```

- The client’s DNS servers must be domain DNS servers only. A public resolver as secondary DNS causes intermittent failures that look random.

- Kerberos tolerates 5 minutes of clock difference by default. Larger skew breaks authentication, and therefore Group Policy.

- If the secure channel is broken, see [the trust relationship repair guide](/guides/trust-relationship-failed-fix/).

| Port | Protocol | Used for |
| --- | --- | --- |
| 53 | TCP/UDP | DNS and DC locator SRV lookups |
| 88 | TCP/UDP | Kerberos authentication |
| 389 | TCP/UDP | LDAP: GPO list, links, WMI filter objects, site lookup |
| 445 | TCP | SMB access to SYSVOL (gpt.ini, Registry.pol, scripts) |
| 135 + 49152–65535 | TCP | RPC: remote gpresult, GPMC Results, Invoke-GPUpdate |

## Check 7: Decode the Group Policy events

Open **Event Viewer » Windows Logs » System** and filter on source GroupPolicy. The error events below are the ones that explain a failed refresh:

| Event ID | Meaning | First thing to check |
| --- | --- | --- |
| 1058 | Could not read gpt.ini for a GPO from the DC. Error 3 = path not found, 5 = access denied, 53 = network path not found | Open the path from the event on the client; SYSVOL replication; GPO permissions |
| 1030 | Failed to retrieve new settings; retried at the next refresh. Usually logged together with 1058 | Fix the paired event |
| 1129 | Processing failed because of lack of network connectivity to a DC | Firewall, VPN timing, NIC ready too late at startup |
| 1054 | Could not obtain the name of a domain controller | DNS client settings and SRV records |
| 1055 | Could not resolve the computer name | Name resolution, replication latency, broken secure channel |
| 1053 | Could not resolve the user name | DNS, permissions on the user’s OU, RPC reachability |
| 1006 | LDAP bind failed (could not authenticate to AD). Error 49 = invalid credentials, 258 = timeout | Password or secure channel, DNS, time skew |

For detail, open **Applications and Services Logs » Microsoft » Windows » GroupPolicy » Operational**. Useful events:

- **5308** names the domain controller used; **5312** lists applicable GPOs and **5313** lists GPOs that were filtered out.

- **4016** and **5016** mark each client-side extension starting and completing successfully. **7016** means an extension completed with an error, for example the Security extension failing on an unknown environment variable in a file system path.

- **7017** records a system call during processing (LDAP bind, account lookup or file access) that failed; the event data names the call and the error.

```
Get-WinEvent -LogName 'Microsoft-Windows-GroupPolicy/Operational' -MaxEvents 200 |
  Where-Object Id -in 5308,5312,5313,7016,7017 |
  Format-List TimeCreated, Id, Message
```

## Check 8: SYSVOL replication and version mismatch

A GPO lives in two places: the Group Policy Container in AD and the Group Policy Template in `SYSVOL\domain\Policies\{GUID}`. Each has its own version number. If the DC the client uses has a newer AD version but an older `GPT.INI`, or the folder is missing, the client applies stale settings or logs event 1058. This produces Group Policy not applying on clients that use one DC, while clients using another DC are fine.

```
Get-GPO -Name "SEC - Screen Lock" | Select-Object DisplayName, Id, GpoStatus,
  @{n='CompAD';e={$_.Computer.DSVersion}}, @{n='CompSYSVOL';e={$_.Computer.SysvolVersion}},
  @{n='UserAD';e={$_.User.DSVersion}}, @{n='UserSYSVOL';e={$_.User.SysvolVersion}}
Get-Content \\DC02\SYSVOL\contoso.com\Policies\{GUID}\GPT.INI
```

Run `Get-GPO -Server DC02` against each DC and compare. GPMC shows the same data on the **Details** tab, and the domain node’s **Status** tab (Group Policy Infrastructure Status » Detect Now) compares every DC against a baseline DC in one pass.

If versions differ, check SYSVOL replication:

```
dfsrmig /getglobalstate
Get-DfsrBacklog -GroupName "Domain System Volume" -FolderName "SYSVOL Share" -SourceComputerName DC01 -DestinationComputerName DC02
repadmin /replsummary
```

`dfsrmig` must report the Eliminated state (DFSR, not FRS). A growing backlog, DFSR errors in the DFS Replication event log or AD replication failures need fixing before any GPO change will reach every client; see [the dcdiag and repadmin health check](/guides/dcdiag-repadmin-dc-health-check/).

## Check 9: Slow links, fast logon and startup timing

- **Slow link:** Windows estimates bandwidth to the DC; below 500 kbps by default the link is slow and extensions such as Software Installation and Folder Redirection are skipped. The threshold is set by Computer Configuration » Policies » Administrative Templates » System » Group Policy » “Configure Group Policy slow link detection”. The Operational log records the estimated bandwidth for each refresh.

- **Fast logon optimisation:** Windows 11 signs users in before the network is ready and applies policy in the background. Settings that need foreground processing then take one or two extra restarts or sign-ins. Enable Computer Configuration » Policies » Administrative Templates » System » Logon » “Always wait for the network at computer startup and logon” on machines that rely on software installation or folder redirection.

- **Wi-Fi and VPN:** machines that only reach a DC after the user connects a VPN log 1129 at startup. Computer settings then apply at the next background refresh (every 90 minutes with a random offset of up to 30 minutes).

- **Cached credentials:** a user who signs in with cached credentials while offline gets the last cached policy; nothing new applies until a DC is reachable.

## Check 10: Enable gpsvc debug logging

When events are not enough, the Group Policy service can write a detailed trace:

```
md %windir%\debug\usermode
reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Diagnostics" /v GPSvcDebugLevel /t REG_DWORD /d 0x00030002 /f
gpupdate /force
notepad %windir%\debug\usermode\gpsvc.log
```

The `usermode` folder must exist or no log is written. Search the log for `error`, `failed` and the GPO GUID. It shows the DC chosen, bandwidth estimate, each GPO’s filtering decision and the return code of each extension.

## Check 11: The setting itself

Sometimes Group Policy is applying and the setting is the problem:

- The ADMX in the Central Store is older than the client, so the setting does not exist on that build, or it applies only to certain editions (many settings ignore Windows 11 Pro).

- Security Options and some other settings need a restart even after a successful refresh.

- A Group Policy Preferences item uses item-level targeting that evaluates to false; gpresult shows the preference extension as applied but the item skipped. Check the Operational log and the preference’s Common tab.

- Intune may be configuring the same area. For Policy CSP settings, Group Policy wins unless MDMWinsOverGP is set.

## Check 12: Model before you change anything

In GPMC, right-click **Group Policy Modeling** and run the wizard for the user and computer containers. If modeling shows the GPO applying but the real Results report does not, the design is right and the fault is on the client, the network or a DC. If modeling also denies it, fix scope or filtering first.

## Verify it works

After each fix, confirm the Group Policy not applying symptom is gone on the machine that reproduced it, not only on your admin workstation.

- Run `gpupdate /force` and confirm it completes without errors.

- Run `gpresult /r` and confirm the GPO appears under Applied Group Policy Objects with the expected DC and a current timestamp.

- Check the value the setting writes, for example `reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\System`.

- In the Operational log, confirm event 8004 (manual computer processing completed) or 8001 (user logon processing completed) without a preceding 7016.

## Troubleshooting quick reference

| Symptom | Likely cause | Fix |
| --- | --- | --- |
| GPO missing from gpresult entirely | Not linked above the object, link disabled, object in CN=Computers | Link to the right OU; move the object into an OU |
| Denied (Security) | Filtering excludes the account, or MS16-072 Read missing | Add the group with Apply; give Domain Computers Read |
| Denied (WMI Filter) | Query false on this client | Test with Get-CimInstance; fix the query |
| Not Applied (Empty) | No settings in that half of the GPO, or settings in the wrong half | Move the setting to User or Computer Configuration as needed |
| User settings missing on an RDS host | GPO linked to the computer OU without loopback | Enable loopback, or link to the user OU |
| Event 1058 error 5 | Permissions on the GPO or share | Restore Authenticated Users Read; check SYSVOL share and NTFS ACLs |
| Event 1058 error 3 on one DC | GPT folder not replicated | Fix DFSR, compare AD and SYSVOL versions |
| Event 1129 at every startup | Network not ready, VPN only | Always wait for the network; check NIC drivers and 802.1X |
| Settings arrive only after two restarts | Fast logon optimisation | Always wait for the network at computer startup and logon |
| Old values keep coming back | Another GPO wins or a stale DC | Check Winning GPO in the HTML report; compare DC versions |

## Clean up after troubleshooting

- Turn gpsvc logging off: `reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Diagnostics" /v GPSvcDebugLevel /t REG_DWORD /d 0 /f`, then delete `gpsvc.log`.

- Remove any test Deny entries, temporary WMI filters or links you added while testing.

- Record the root cause of each Group Policy not applying case, so the service desk can match the next occurrence from the event ID.

Most cases of Group Policy not applying are settled at Check 2 or Check 4. Work through the remaining checks only when gpresult shows processing failures or DC-specific differences.

## Group Policy not applying at a glance

**Official documentation:** [Applying Group Policy troubleshooting guidance](https://learn.microsoft.com/en-us/troubleshoot/windows-server/group-policy/applying-group-policy-troubleshooting-guidance), [gpresult command reference](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/gpresult).

**Related guides:** [GPO security filtering: target or exclude users and computers](/guides/group-policy-security-filtering/) · [Group Policy processing order, Enforced and Block Inheritance](/guides/group-policy-processing-order/) · [dcdiag repadmin Health Check: 7 Critical Tests Explained](/guides/dcdiag-repadmin-dc-health-check/).

**See also:** [Event ID 1058: Group Policy Failed to Read gpt.ini (Fix)](/guides/event-id-1058-group-policy/) · [Event ID 1030: Group Policy Processing Failed (Causes and Fix)](/guides/event-id-1030-group-policy/) · [Event ID 1129: Group Policy Failed, No Connectivity to a DC](/guides/event-id-1129-group-policy/)

## Frequently asked questions

### Why is Group Policy not applying even though gpupdate succeeds?

A successful gpupdate only means processing completed. The GPO can still be out of scope, filtered out by security or a WMI filter, overridden by a higher-precedence GPO, or waiting for a restart or sign-in. Check the denied list and the Winning GPO column in gpresult /h.

### What does event 1058 mean?

The client could not read gpt.ini for a GPO from the domain controller. The error code in the event tells you whether the path was not found, access was denied or the network path was unreachable, which points to SYSVOL replication, GPO permissions or name resolution.

### Do I need Authenticated Users on every GPO?

Since MS16-072, user policies are read in the computer’s security context, so the computer needs Read permission. If you remove Authenticated Users from security filtering, add Domain Computers or Authenticated Users back with Read only.

### How long does a GPO change take to reach clients?

Member computers refresh every 90 minutes with a random offset of up to 30 minutes, and domain controllers every 5 minutes. Replication between DCs adds its own delay. Some settings also need a restart or a new sign-in.

### Is rsop.msc still useful?

It still opens, but it does not show Group Policy Preferences and is slower than gpresult. Use gpresult /h or GPMC Group Policy Results instead.
