# Group Policy Processing Order: Complete LSDOU Guide with 10 Examples

Source: https://srvscripts.com/guides/group-policy-processing-order/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

Group Policy processing order decides which GPO wins when two of them configure the same setting: Windows applies GPOs from the local computer, then the AD site, then the domain, then each OU from the top down (LSDOU), and the last GPO to write a setting wins. Link order, Enforced links, Block Inheritance and loopback processing change that basic sequence. This guide explains each rule, shows ten worked examples, and covers the GPMC and PowerShell views that confirm which GPO is really in charge.

**Short answer:** Local GPO first, then site, domain and OUs from parent to child; later GPOs override earlier ones. Within one container, link order 1 is processed last and therefore wins. An Enforced link cannot be blocked and beats every non-enforced link below it, and among enforced links the one on the higher container wins. Check the result on the **Group Policy Inheritance** tab in GPMC and confirm it on the client with `gpresult /h`.

In short: Local GPO first, then site, domain and OUs from parent to child; later GPOs override earlier ones.

## The LSDOU sequence

| Step | Level | Where you manage it | Notes |
| --- | --- | --- | --- |
| 1 | Local GPOs | gpedit.msc on the machine | Lowest precedence; overridden by any domain GPO that sets the same value |
| 2 | Site | GPMC » Sites (use Show Sites) | Depends on the client’s IP subnet; rarely used |
| 3 | Domain | GPMC » domain node | Default Domain Policy lives here |
| 4 | OUs, parent to child | GPMC » each OU | The OU closest to the object is processed last |

Settings that do not conflict all apply, whichever level they come from. Group Policy processing order only matters when two GPOs configure the same setting with different values. Not Configured never overrides anything; Disabled is a real value and does override Enabled from an earlier GPO.

The same sequence runs twice: once for the computer object (Computer Configuration, at startup and every background refresh) and once for the user object (User Configuration, at sign-in and every refresh). Each uses the OU path of its own object, so a user in OU=Sales,OU=Users signing in to a PC in OU=Laptops,OU=Workstations receives user settings from the Sales path and computer settings from the Laptops path.

## Prerequisites

- Group Policy Management Console (RSAT on Windows 11) and the `GroupPolicy` PowerShell module.

- Read access to the GPOs and containers you want to inspect; link changes need Link GPOs permission on the container.

- A test user and test computer in the OU you are changing, and admin rights on that computer to run `gpresult /h`.

## Link order within a container

When several GPOs are linked to the same domain or OU, the **Link Order** column on the container’s **Linked Group Policy Objects** tab decides the sequence. The highest number is processed first and link order 1 is processed last, so link order 1 has the highest precedence at that level.

- Select the OU in GPMC and open **Linked Group Policy Objects**.

- Select a GPO and use the arrow buttons on the left to move it up (towards 1) or down.

- Or set it from PowerShell:

```
Set-GPLink -Name 'SEC - Workstation Baseline' -Target 'OU=Workstations,DC=contoso,DC=com' -Order 1
```

A disabled link (Link Enabled cleared) is skipped entirely, as is a GPO whose **GPO Status** on the Details tab disables the relevant half.

## Enforced vs Block Inheritance

### Block Inheritance

Setting **Block Inheritance** on an OU (right-click the OU) stops GPOs linked to parent containers, including the site and the domain, from applying to objects in that OU and its children. GPOs linked directly to the OU still apply. Local GPOs are not affected, because they are not inherited from AD.

```
Set-GPInheritance -Target 'OU=Kiosks,OU=Workstations,DC=contoso,DC=com' -IsBlocked Yes
```

### Enforced

**Enforced** is a property of a link, not of the GPO (right-click the link and tick **Enforced**). An enforced link:

- ignores Block Inheritance on any child OU;

- wins over every non-enforced GPO in the child containers, even though those are processed later;

- loses to an enforced link on a higher container: when both the domain and an OU have enforced links setting the same value, the domain’s link wins.

```
Set-GPLink -Name 'SEC - Domain Baseline' -Target 'DC=contoso,DC=com' -Enforced Yes
```

In the GPMC **Group Policy Inheritance** tab, enforced links always sit at the top of the precedence list, which is the simplest way to see this reversal of the normal Group Policy processing order.

## Local GPOs

Windows 11 and Windows Server support multiple local GPOs: Local Computer Policy, then Administrators or Non-Administrators, then a user-specific local GPO. The more specific one wins among local GPOs, and any domain GPO wins over all of them. To stop local GPOs from being processed at all on domain-joined machines, enable `Computer Configuration » Policies » Administrative Templates » System » Group Policy » "Turn off Local Group Policy Objects processing"`. This is useful when a local image carries old settings you cannot easily find.

## Loopback processing

Loopback changes which GPOs supply the user settings on a computer:

- **Replace:** the user’s own GPO list is discarded. User settings come only from GPOs in the computer’s scope, in the computer’s LSDOU order.

- **Merge:** the user’s list is processed first, then the computer’s list. On a conflict the GPO from the computer’s scope wins, because it is processed later.

Enforced and Block Inheritance still apply within each list. The setting is `Computer Configuration » Policies » Administrative Templates » System » Group Policy » "Configure user Group Policy loopback processing mode"`; our [loopback guide](/guides/group-policy-loopback-processing/) covers RDS and kiosk designs.

## Computer vs user setting conflicts

Some settings exist in both Computer Configuration and User Configuration and write to `HKLM\SOFTWARE\Policies` and `HKCU\SOFTWARE\Policies` respectively. Group Policy processing order does not decide these, because the two values never overwrite each other. The feature reading them decides, and in most cases it reads the machine value first, so the computer setting wins. The **Explain** text of a setting states when that is not the case. To avoid ambiguity, configure a dual setting on one side only.

## Worked examples

The table uses a screen-lock timeout (or a similar single-value setting) set in different places. Domain means a GPO linked at the domain; OU means a GPO linked to the OU that holds the computer.

| # | Configuration | Result | Why |
| --- | --- | --- | --- |
| 1 | Domain: 15 minutes. OU: 10 minutes. | 10 | The OU GPO is processed last |
| 2 | Same OU: GPO A (link order 1) 5 minutes, GPO B (link order 2) 20 minutes | 5 | Link order 1 is processed last |
| 3 | Domain (Enforced): 15. OU: 10. | 15 | Enforced beats non-enforced child links |
| 4 | Domain: USB block. OU: Block Inheritance. | No USB block | Inherited, non-enforced links are blocked |
| 5 | Domain (Enforced): USB block. OU: Block Inheritance. | USB blocked | Enforced links ignore Block Inheritance |
| 6 | Domain (Enforced): 15. OU (Enforced): 10. | 15 | Among enforced links, the higher container wins |
| 7 | Local GPO: wallpaper A. Domain: wallpaper B. | B | Domain GPOs are processed after local ones |
| 8 | Parent OU: 10. Child OU: Not Configured. | 10 | Not Configured does not override |
| 9 | Parent OU: setting Enabled. Child OU: same setting Disabled. | Disabled | Disabled is a value, and the child OU is processed later |
| 10 | RDS host OU with loopback Replace. User OU maps drive H:. RDS OU GPO maps drive S: (user side). | Only S: on the RDS host | Replace discards the user’s own GPO list |

Security filtering and WMI filters are checked after the order is built: a GPO that is filtered out simply drops out of the list, and the next GPO in line becomes the winner.

## Read the order in GPMC and PowerShell

### Group Policy Inheritance tab

- In GPMC, select the OU that holds the object.

- Open the **Group Policy Inheritance** tab. The **Precedence** column lists every GPO that reaches this OU; precedence 1 wins.

- The **Location** column shows where each GPO is linked. The tab does not include site-linked GPOs, because those depend on where the client is.

### Get-GPInheritance

```
$ou = 'OU=Kiosks,OU=Workstations,DC=contoso,DC=com'
Get-GPInheritance -Target $ou | Select-Object ContainerName, GpoInheritanceBlocked
(Get-GPInheritance -Target $ou).InheritedGpoLinks |
    Select-Object Order, DisplayName, Enforced, Enabled, Target | Format-Table -AutoSize
```

`InheritedGpoLinks` is ordered by precedence, like the GPMC tab, and `GpoLinks` shows only the links on the OU itself. To list every blocked OU in the domain:

```
Get-ADOrganizationalUnit -Filter * | ForEach-Object {
    Get-GPInheritance -Target $_.DistinguishedName
} | Where-Object GpoInheritanceBlocked -eq 'Yes' | Select-Object Path
```

### Export the order for every OU

Before a restructure or an audit, save the full Group Policy processing order per OU to a CSV file. It gives you a baseline to compare against after the change.

```
$domain = (Get-ADDomain).DistinguishedName
$targets = @($domain) + (Get-ADOrganizationalUnit -Filter *).DistinguishedName
$rows = foreach ($t in $targets) {
    $inh = Get-GPInheritance -Target $t
    foreach ($l in $inh.InheritedGpoLinks) {
        [pscustomobject]@{
            OU        = $t
            Blocked   = $inh.GpoInheritanceBlocked
            Order     = $l.Order
            GPO       = $l.DisplayName
            LinkedAt  = $l.Target
            Enforced  = $l.Enforced
            Enabled   = $l.Enabled
        }
    }
}
$rows | Export-Csv C:\Reports\GPO-Precedence.csv -NoTypeInformation
```

Open the file in Excel and filter by OU. Rows where LinkedAt differs from OU are inherited GPOs; rows where Enforced is true show where the normal order is reversed.

### Site-linked GPOs

GPOs linked to an AD site apply to every computer whose IP address maps to that site, whatever domain or OU it belongs to. They are processed after local GPOs and before domain GPOs, and they do not appear on the Group Policy Inheritance tab or in `Get-GPInheritance`. If a setting arrives from nowhere you can see, open **Sites** in GPMC (right-click **Sites » Show Sites**) and check the links there, or read the Applied GPOs list in `gpresult /h`, which includes site GPOs.

## Confirm the winning GPO with gpresult

The GPMC views show the planned Group Policy processing order. The client shows what actually happened after filtering.

- On the client, from an elevated prompt, run `gpresult /h C:\Temp\rsop.html` and open the file.

- Under **Computer Details** or **User Details**, each setting has a **Winning GPO** column. That is the GPO whose value is in effect.

- The **Group Policy Objects » Applied GPOs** and **Denied GPOs** sections list which GPOs were used and why others were filtered out.

- From PowerShell, generate the same report for a remote computer and user:

```
Get-GPResultantSetOfPolicy -Computer PC01 -User CONTOSO\jdoe -ReportType Html -Path C:\Temp\PC01-jdoe.html
```

- Use GPMC **Group Policy Modeling** to predict the result before moving an object or changing a link.

## Best-practice design

- **Few domain-level GPOs.** Keep the Default Domain Policy for password, lockout and Kerberos policy only; domain account policies for domain users must be linked at the domain.

- **Enforce sparingly.** Reserve Enforced for a small security baseline that no OU owner should override. Each extra enforced link makes troubleshooting harder.

- **Avoid Block Inheritance where you can.** It hides every domain GPO from the OU, including ones added later. Prefer security filtering or a separate OU branch.

- **One purpose per GPO.** Small GPOs named by function (SEC – USB Block, CFG – Edge Homepage) make the Winning GPO column self-explanatory.

- **Avoid configuring the same setting in several GPOs.** If you must, document which one is meant to win and why.

- **Separate computer and user OUs.** Link computer GPOs to computer OUs and user GPOs to user OUs, and disable the unused half of each GPO.

- **Review the Group Policy processing order after every structural change**, such as moving OUs or adding an enforced link, with Group Policy Modeling.

## A quick checklist when the wrong value wins

- Find the **Winning GPO** for the setting in `gpresult /h` on the affected machine.

- Check whether that GPO’s link is **Enforced**, and at which level it is linked.

- Check the intended GPO: is it linked, enabled, and above the winner in link order at its level?

- Look for Block Inheritance on the OU and every parent OU.

- Check the intended GPO’s security filter and WMI filter in the Denied GPOs section.

- For user settings, check whether loopback is enabled on the computer’s OU.

Following the Group Policy processing order in this sequence finds the cause in almost every case without guesswork.

## Troubleshooting

| Symptom | Likely cause | Fix |
| --- | --- | --- |
| OU GPO value ignored | An enforced link higher up sets the same value | Check the Group Policy Inheritance tab for enforced links at the top |
| Domain GPO missing in one OU | Block Inheritance on that OU or a parent | Run the blocked-OU report; enforce the link or remove the block |
| Wrong GPO wins within one OU | Link order | Move the intended GPO to link order 1 |
| Local setting keeps coming back | No domain GPO configures that setting | Configure it in a domain GPO, or turn off local GPO processing |
| User settings differ on RDS hosts | Loopback Replace or Merge on the host OU | Check gpresult /h for the loopback mode and the user GPO list |
| GPO is first in precedence but not applied | Security or WMI filtering, or a disabled link or GPO half | Look in the Denied GPOs section of gpresult /h |

If a GPO does not appear in the report at all, work through links, replication and client errors with our [Group Policy not applying guide](/guides/group-policy-not-applying/). Once you can read the Group Policy processing order from the Inheritance tab and confirm it with the Winning GPO column, most conflicts take minutes to explain.

## Group Policy processing order at a glance

**Official documentation:** [Get-GPInheritance (GroupPolicy module)](https://learn.microsoft.com/en-us/powershell/module/grouppolicy/get-gpinheritance), [Set-GPLink (GroupPolicy module)](https://learn.microsoft.com/en-us/powershell/module/grouppolicy/set-gplink), [gpresult command reference](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/gpresult).

**Related guides:** [Group Policy loopback processing: merge vs replace for RDS hosts and kiosks](/guides/group-policy-loopback-processing/) · [GPO security filtering: target or exclude users and computers](/guides/group-policy-security-filtering/) · [Troubleshoot Group Policy not applying: gpresult, RSoP and Events 1058/1030](/guides/group-policy-not-applying/).

## Frequently asked questions

### What is the Group Policy processing order?

Local GPOs first, then GPOs linked to the site, the domain and each OU from parent to child (LSDOU). When settings conflict, the GPO processed last wins, so the OU closest to the object normally has the final say.

### Does link order 1 have the highest or lowest precedence?

Highest. GPOs linked to the same container are processed from the highest link order number to 1, so link order 1 is applied last and wins conflicts at that level.

### Which wins, Enforced or Block Inheritance?

Enforced. An enforced link ignores Block Inheritance on child OUs and also overrides non-enforced GPOs linked lower in the tree.

### If the domain and an OU both have enforced GPOs, which wins?

The enforced link on the higher container, here the domain. Enforced reverses the normal order, so higher enforced links take precedence over lower ones.

### How do I see which GPO won a setting?

Run gpresult /h report.html on the client, or Get-GPResultantSetOfPolicy for a remote machine, and read the Winning GPO column next to each setting.
