Emergency server help: get in touch

Group Policy Processing Order: Complete LSDOU Guide with 10 Examples

Understand which GPO wins: local, site, domain and OU processing, link order, Enforced and Block Inheritance, loopback and computer vs user conflicts, with ten worked examples and the GPMC and PowerShell views that show the real result.

Published Updated 12 min read

Group Policy processing order decides which GPO wins when two of them configure the same setting: Windows applies GPOs from the local computer, then the AD site, then the domain, then each OU from the top down (LSDOU), and the last GPO to write a setting wins. Link order, Enforced links, Block Inheritance and loopback processing change that basic sequence. This guide explains each rule, shows ten worked examples, and covers the GPMC and PowerShell views that confirm which GPO is really in charge.

Short answer: Local GPO first, then site, domain and OUs from parent to child; later GPOs override earlier ones. Within one container, link order 1 is processed last and therefore wins. An Enforced link cannot be blocked and beats every non-enforced link below it, and among enforced links the one on the higher container wins. Check the result on the Group Policy Inheritance tab in GPMC and confirm it on the client with gpresult /h.

The LSDOU sequence

StepLevelWhere you manage itNotes
1Local GPOsgpedit.msc on the machineLowest precedence; overridden by any domain GPO that sets the same value
2SiteGPMC » Sites (use Show Sites)Depends on the client’s IP subnet; rarely used
3DomainGPMC » domain nodeDefault Domain Policy lives here
4OUs, parent to childGPMC » each OUThe OU closest to the object is processed last

Settings that do not conflict all apply, whichever level they come from. Group Policy processing order only matters when two GPOs configure the same setting with different values. Not Configured never overrides anything; Disabled is a real value and does override Enabled from an earlier GPO.

The same sequence runs twice: once for the computer object (Computer Configuration, at startup and every background refresh) and once for the user object (User Configuration, at sign-in and every refresh). Each uses the OU path of its own object, so a user in OU=Sales,OU=Users signing in to a PC in OU=Laptops,OU=Workstations receives user settings from the Sales path and computer settings from the Laptops path.

Prerequisites

  • Group Policy Management Console (RSAT on Windows 11) and the GroupPolicy PowerShell module.
  • Read access to the GPOs and containers you want to inspect; link changes need Link GPOs permission on the container.
  • A test user and test computer in the OU you are changing, and admin rights on that computer to run gpresult /h.

When several GPOs are linked to the same domain or OU, the Link Order column on the container’s Linked Group Policy Objects tab decides the sequence. The highest number is processed first and link order 1 is processed last, so link order 1 has the highest precedence at that level.

  1. Select the OU in GPMC and open Linked Group Policy Objects.
  2. Select a GPO and use the arrow buttons on the left to move it up (towards 1) or down.
  3. Or set it from PowerShell:
    Set-GPLink -Name 'SEC - Workstation Baseline' -Target 'OU=Workstations,DC=contoso,DC=com' -Order 1

A disabled link (Link Enabled cleared) is skipped entirely, as is a GPO whose GPO Status on the Details tab disables the relevant half.

Enforced vs Block Inheritance

Block Inheritance

Setting Block Inheritance on an OU (right-click the OU) stops GPOs linked to parent containers, including the site and the domain, from applying to objects in that OU and its children. GPOs linked directly to the OU still apply. Local GPOs are not affected, because they are not inherited from AD.

Set-GPInheritance -Target 'OU=Kiosks,OU=Workstations,DC=contoso,DC=com' -IsBlocked Yes

Enforced

Enforced is a property of a link, not of the GPO (right-click the link and tick Enforced). An enforced link:

  • ignores Block Inheritance on any child OU;
  • wins over every non-enforced GPO in the child containers, even though those are processed later;
  • loses to an enforced link on a higher container: when both the domain and an OU have enforced links setting the same value, the domain’s link wins.
Set-GPLink -Name 'SEC - Domain Baseline' -Target 'DC=contoso,DC=com' -Enforced Yes

In the GPMC Group Policy Inheritance tab, enforced links always sit at the top of the precedence list, which is the simplest way to see this reversal of the normal Group Policy processing order.

Local GPOs

Windows 11 and Windows Server support multiple local GPOs: Local Computer Policy, then Administrators or Non-Administrators, then a user-specific local GPO. The more specific one wins among local GPOs, and any domain GPO wins over all of them. To stop local GPOs from being processed at all on domain-joined machines, enable Computer Configuration » Policies » Administrative Templates » System » Group Policy » "Turn off Local Group Policy Objects processing". This is useful when a local image carries old settings you cannot easily find.

Loopback processing

Loopback changes which GPOs supply the user settings on a computer:

  • Replace: the user’s own GPO list is discarded. User settings come only from GPOs in the computer’s scope, in the computer’s LSDOU order.
  • Merge: the user’s list is processed first, then the computer’s list. On a conflict the GPO from the computer’s scope wins, because it is processed later.

Enforced and Block Inheritance still apply within each list. The setting is Computer Configuration » Policies » Administrative Templates » System » Group Policy » "Configure user Group Policy loopback processing mode"; our loopback guide covers RDS and kiosk designs.

Computer vs user setting conflicts

Some settings exist in both Computer Configuration and User Configuration and write to HKLM\SOFTWARE\Policies and HKCU\SOFTWARE\Policies respectively. Group Policy processing order does not decide these, because the two values never overwrite each other. The feature reading them decides, and in most cases it reads the machine value first, so the computer setting wins. The Explain text of a setting states when that is not the case. To avoid ambiguity, configure a dual setting on one side only.

Worked examples

The table uses a screen-lock timeout (or a similar single-value setting) set in different places. Domain means a GPO linked at the domain; OU means a GPO linked to the OU that holds the computer.

#ConfigurationResultWhy
1Domain: 15 minutes. OU: 10 minutes.10The OU GPO is processed last
2Same OU: GPO A (link order 1) 5 minutes, GPO B (link order 2) 20 minutes5Link order 1 is processed last
3Domain (Enforced): 15. OU: 10.15Enforced beats non-enforced child links
4Domain: USB block. OU: Block Inheritance.No USB blockInherited, non-enforced links are blocked
5Domain (Enforced): USB block. OU: Block Inheritance.USB blockedEnforced links ignore Block Inheritance
6Domain (Enforced): 15. OU (Enforced): 10.15Among enforced links, the higher container wins
7Local GPO: wallpaper A. Domain: wallpaper B.BDomain GPOs are processed after local ones
8Parent OU: 10. Child OU: Not Configured.10Not Configured does not override
9Parent OU: setting Enabled. Child OU: same setting Disabled.DisabledDisabled is a value, and the child OU is processed later
10RDS host OU with loopback Replace. User OU maps drive H:. RDS OU GPO maps drive S: (user side).Only S: on the RDS hostReplace discards the user’s own GPO list

Security filtering and WMI filters are checked after the order is built: a GPO that is filtered out simply drops out of the list, and the next GPO in line becomes the winner.

Read the order in GPMC and PowerShell

Group Policy Inheritance tab

  1. In GPMC, select the OU that holds the object.
  2. Open the Group Policy Inheritance tab. The Precedence column lists every GPO that reaches this OU; precedence 1 wins.
  3. The Location column shows where each GPO is linked. The tab does not include site-linked GPOs, because those depend on where the client is.

Get-GPInheritance

$ou = 'OU=Kiosks,OU=Workstations,DC=contoso,DC=com'
Get-GPInheritance -Target $ou | Select-Object ContainerName, GpoInheritanceBlocked
(Get-GPInheritance -Target $ou).InheritedGpoLinks |
    Select-Object Order, DisplayName, Enforced, Enabled, Target | Format-Table -AutoSize

InheritedGpoLinks is ordered by precedence, like the GPMC tab, and GpoLinks shows only the links on the OU itself. To list every blocked OU in the domain:

Get-ADOrganizationalUnit -Filter * | ForEach-Object {
    Get-GPInheritance -Target $_.DistinguishedName
} | Where-Object GpoInheritanceBlocked -eq 'Yes' | Select-Object Path

Export the order for every OU

Before a restructure or an audit, save the full Group Policy processing order per OU to a CSV file. It gives you a baseline to compare against after the change.

$domain = (Get-ADDomain).DistinguishedName
$targets = @($domain) + (Get-ADOrganizationalUnit -Filter *).DistinguishedName
$rows = foreach ($t in $targets) {
    $inh = Get-GPInheritance -Target $t
    foreach ($l in $inh.InheritedGpoLinks) {
        [pscustomobject]@{
            OU        = $t
            Blocked   = $inh.GpoInheritanceBlocked
            Order     = $l.Order
            GPO       = $l.DisplayName
            LinkedAt  = $l.Target
            Enforced  = $l.Enforced
            Enabled   = $l.Enabled
        }
    }
}
$rows | Export-Csv C:\Reports\GPO-Precedence.csv -NoTypeInformation

Open the file in Excel and filter by OU. Rows where LinkedAt differs from OU are inherited GPOs; rows where Enforced is true show where the normal order is reversed.

Site-linked GPOs

GPOs linked to an AD site apply to every computer whose IP address maps to that site, whatever domain or OU it belongs to. They are processed after local GPOs and before domain GPOs, and they do not appear on the Group Policy Inheritance tab or in Get-GPInheritance. If a setting arrives from nowhere you can see, open Sites in GPMC (right-click Sites » Show Sites) and check the links there, or read the Applied GPOs list in gpresult /h, which includes site GPOs.

Confirm the winning GPO with gpresult

The GPMC views show the planned Group Policy processing order. The client shows what actually happened after filtering.

  1. On the client, from an elevated prompt, run gpresult /h C:\Temp\rsop.html and open the file.
  2. Under Computer Details or User Details, each setting has a Winning GPO column. That is the GPO whose value is in effect.
  3. The Group Policy Objects » Applied GPOs and Denied GPOs sections list which GPOs were used and why others were filtered out.
  4. From PowerShell, generate the same report for a remote computer and user:
    Get-GPResultantSetOfPolicy -Computer PC01 -User CONTOSO\jdoe -ReportType Html -Path C:\Temp\PC01-jdoe.html
  5. Use GPMC Group Policy Modeling to predict the result before moving an object or changing a link.

Best-practice design

  • Few domain-level GPOs. Keep the Default Domain Policy for password, lockout and Kerberos policy only; domain account policies for domain users must be linked at the domain.
  • Enforce sparingly. Reserve Enforced for a small security baseline that no OU owner should override. Each extra enforced link makes troubleshooting harder.
  • Avoid Block Inheritance where you can. It hides every domain GPO from the OU, including ones added later. Prefer security filtering or a separate OU branch.
  • One purpose per GPO. Small GPOs named by function (SEC – USB Block, CFG – Edge Homepage) make the Winning GPO column self-explanatory.
  • Avoid configuring the same setting in several GPOs. If you must, document which one is meant to win and why.
  • Separate computer and user OUs. Link computer GPOs to computer OUs and user GPOs to user OUs, and disable the unused half of each GPO.
  • Review the Group Policy processing order after every structural change, such as moving OUs or adding an enforced link, with Group Policy Modeling.

A quick checklist when the wrong value wins

  1. Find the Winning GPO for the setting in gpresult /h on the affected machine.
  2. Check whether that GPO’s link is Enforced, and at which level it is linked.
  3. Check the intended GPO: is it linked, enabled, and above the winner in link order at its level?
  4. Look for Block Inheritance on the OU and every parent OU.
  5. Check the intended GPO’s security filter and WMI filter in the Denied GPOs section.
  6. For user settings, check whether loopback is enabled on the computer’s OU.

Following the Group Policy processing order in this sequence finds the cause in almost every case without guesswork.

Troubleshooting

SymptomLikely causeFix
OU GPO value ignoredAn enforced link higher up sets the same valueCheck the Group Policy Inheritance tab for enforced links at the top
Domain GPO missing in one OUBlock Inheritance on that OU or a parentRun the blocked-OU report; enforce the link or remove the block
Wrong GPO wins within one OULink orderMove the intended GPO to link order 1
Local setting keeps coming backNo domain GPO configures that settingConfigure it in a domain GPO, or turn off local GPO processing
User settings differ on RDS hostsLoopback Replace or Merge on the host OUCheck gpresult /h for the loopback mode and the user GPO list
GPO is first in precedence but not appliedSecurity or WMI filtering, or a disabled link or GPO halfLook in the Denied GPOs section of gpresult /h

If a GPO does not appear in the report at all, work through links, replication and client errors with our Group Policy not applying guide. Once you can read the Group Policy processing order from the Inheritance tab and confirm it with the Winning GPO column, most conflicts take minutes to explain.

Group Policy processing order at a glance

Group Policy Processing Order summary card: Local GPO first, then site, domain and OUs from parent to child; later GPOs override earlier ones.
In short: Local GPO first, then site, domain and OUs from parent to child; later GPOs override earlier ones.

Official documentation: Get-GPInheritance (GroupPolicy module), Set-GPLink (GroupPolicy module), gpresult command reference.

Related guides: Group Policy loopback processing: merge vs replace for RDS hosts and kiosks · GPO security filtering: target or exclude users and computers · Troubleshoot Group Policy not applying: gpresult, RSoP and Events 1058/1030.

Frequently asked questions

What is the Group Policy processing order?

Local GPOs first, then GPOs linked to the site, the domain and each OU from parent to child (LSDOU). When settings conflict, the GPO processed last wins, so the OU closest to the object normally has the final say.

Does link order 1 have the highest or lowest precedence?

Highest. GPOs linked to the same container are processed from the highest link order number to 1, so link order 1 is applied last and wins conflicts at that level.

Which wins, Enforced or Block Inheritance?

Enforced. An enforced link ignores Block Inheritance on child OUs and also overrides non-enforced GPOs linked lower in the tree.

If the domain and an OU both have enforced GPOs, which wins?

The enforced link on the higher container, here the domain. Enforced reverses the normal order, so higher enforced links take precedence over lower ones.

How do I see which GPO won a setting?

Run gpresult /h report.html on the client, or Get-GPResultantSetOfPolicy for a remote machine, and read the Winning GPO column next to each setting.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.