# Registry Group Policy Preferences: 4 Safe Ways to Deploy Registry Keys

Source: https://srvscripts.com/guides/registry-group-policy-preferences/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

Registry Group Policy Preferences items let you create, change or delete registry keys and values on domain computers and user profiles without writing a custom ADMX template or a logon script. You need them when an application stores its settings in the registry and has no policy template, when you want to change a Windows default that users may still adjust later, or when you must remove a value from hundreds of machines at once. This guide covers the Registry item and its four actions, the Registry Wizard, collections, targeting, PowerShell, Intune alternatives, verification and rollback.

**Short answer:** Edit a GPO and go to `Computer Configuration » Preferences » Windows Settings » Registry` (or the same path under User Configuration for HKCU). Choose **New » Registry Item**, set **Action** to Update, pick the hive, key path, value name, type and data, and click **OK**. Run `gpupdate /force` and check the value with `reg query`.

In short: Edit a GPO and go to Computer Configuration » Preferences » Windows Settings » Registry (or the same path under User Configuration for HKCU).

## Which method to use

| Method | Enforced? | Cleans up when removed? | Best for |
| --- | --- | --- | --- |
| GPP Registry item | Reapplied at each refresh; users can change it in between | Only with “Remove this item when it is no longer applied” | Any key or value, including HKLM\SOFTWARE and HKCU |
| Administrative Template (ADMX) setting | Yes, UI often greyed out | Yes, keys under Software\Policies are removed | Settings Microsoft or the vendor already ship a template for |
| Set-GPRegistryValue (policy-based registry) | Yes | Yes under Software\Policies, otherwise tattooed | Scripting policy keys without an ADMX |
| Custom ADMX template | Yes | Only for keys under Software\Policies | Reusable settings with a friendly UI |
| Intune Settings catalog, Remediations or platform script | Depends on method | No, unless you script it | Microsoft Entra joined devices |

If a setting has an ADMX policy, use the policy. Use registry Group Policy Preferences items for everything else, and for values you want to set as a default that users may override.

## Prerequisites

Registry Group Policy Preferences need very little set-up, but check these points first:

- Windows 11 Pro, Enterprise or Education, or Windows Server 2016 to 2025, joined to the domain. The Group Policy Registry client-side extension is built in.

- Rights to edit and link GPOs and the Group Policy Management Console. For PowerShell, the **GroupPolicy** module from RSAT.

- The exact key path, value name, type and data, tested on one machine first. Export the key with `reg export` before you change it.

- A test OU with a computer and a test user.

## Method 1: Create a Registry preference item

This is the core registry Group Policy Preferences workflow and the one you will use most.

- In **Group Policy Management**, create or edit a GPO linked to the OU that holds the target computers (for HKLM) or users (for HKCU).

- Go to `Computer Configuration » Preferences » Windows Settings » Registry` or `User Configuration » Preferences » Windows Settings » Registry`.

- Right-click **Registry** and choose **New » Registry Item**.

- Set **Action** (see the table below). Use Update unless you have a reason not to.

- Set **Hive**, for example HKEY_LOCAL_MACHINE, and **Key Path** without the hive and without leading or trailing backslashes, for example `SOFTWARE\Contoso\LOBApp`. The **…** button browses the registry of the machine you are editing on.

- Type the **Value name** (or tick **Default** for the key’s default value), choose the **Value type** and enter the **Value data**. For REG_DWORD choose Decimal or Hexadecimal.

- Click **OK**. On a test machine run `gpupdate /force` and check the value.

The Key Path, Value name and Value data fields accept preference variables. Press F3 in a field to insert one, for example `%ComputerName%` or `%LogonUser%`.

### Create, Replace, Update and Delete

| Action | On a value | On a key (no value name) |
| --- | --- | --- |
| Create | Creates the value only if it does not exist | Creates the key if missing |
| Replace | Deletes and recreates the value, overwriting everything about it | Deletes all values and subkeys in the key, leaving an empty key |
| Update | Changes only what the item defines; creates the value if missing | Creates the key if missing; leaves existing content |
| Delete | Removes the value | Removes the key with all its values and subkeys |

Be careful with Replace on a key: Microsoft documents that it deletes everything below the key before recreating it. That is useful to reset an application’s settings, and disastrous on a shared key such as `SOFTWARE\Microsoft\Windows\CurrentVersion\Run`.

### HKCU vs HKLM

- **HKLM items** go in Computer Configuration and apply at startup and every background refresh.

- **HKCU items** go in User Configuration and apply at logon and every background refresh. An HKCU item placed under Computer Configuration writes to the SYSTEM account’s hive, not to the signed-in user.

- User items are processed in the system’s security context by default, so they can write under `HKCU\Software\Policies`, which users cannot change themselves. Tick **Run in logged-on user’s security context** on the **Common** tab only when the item needs the user’s own network access.

- To apply user registry items on specific computers only, such as Remote Desktop hosts, use loopback processing or item-level targeting by computer.

Example: show file name extensions for every user. User Configuration » Preferences » Windows Settings » Registry, action Update, hive HKEY_CURRENT_USER, key `Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced`, value `HideFileExt`, type REG_DWORD, data `0`. Users can still switch it back in File Explorer until the next refresh.

## Method 2: Registry Wizard and collections

When an application needs a dozen values, do not type them one by one.

- Configure the application on a reference machine.

- In the GPO, right-click **Registry** and choose **New » Registry Wizard**, select the local computer (or another computer you can reach), and click **Next**.

- Browse to the key and tick each key and value you want. Click **Finish**.

- The wizard creates one Registry item per value, grouped in a collection named after the path. Open a few items and change the action from Update if needed.

To organise items yourself, right-click **Registry** and choose **New » Collection Item**, then drag items into it. Collections have no effect on where values land in the registry, but you can apply item-level targeting to the whole collection instead of each item.

## Common options: targeting, apply once and removal

The **Common** tab decides how registry Group Policy Preferences items behave over time.

| Option | Effect | When to use |
| --- | --- | --- |
| Stop processing items in this extension if an error occurs on this item | A failing item stops later items in the same GPO. Items are processed from the bottom of the list up. | When later items depend on this one |
| Run in logged-on user’s security context | Processes a user item as the user instead of the system | Rarely for registry items |
| Remove this item when it is no longer applied | Deletes the value when the item goes out of scope; changes the action to Replace | Values you want cleaned up when a user or computer leaves the scope |
| Apply once and do not reapply | Writes the value once; later refreshes skip it | A first-run default users may change |
| Item-level targeting | Applies the item only when the conditions are true | Per group, OS, OU or existing registry state |

Useful targeting items for registry work: **Security Group** (for example only members of Finance Users), **Operating System** (Windows 11 only), **Registry Match** (only if the application’s key exists, so you do not create keys for software that is not installed) and **Organizational Unit**. Add several and combine them with **And**, **Or** and **Is Not**.

## Preferences vs ADMX policies and tattooing

A policy setting from an ADMX template writes under `Software\Policies` or `Software\Microsoft\Windows\CurrentVersion\Policies`. When the GPO no longer applies, Windows removes those values and the application falls back to its own default. Values written anywhere else stay in the registry after the GPO is gone; this is called tattooing.

- A registry Group Policy Preferences item tattoos by default. Tick **Remove this item when it is no longer applied** if you want the value removed when the GPO stops applying.

- A custom ADMX template that points at a key outside `Software\Policies` also tattoos, and it hides that fact behind a policy-style UI. If you write a custom ADMX, keep it under `Software\Policies\<Vendor>`.

- Preferences do not grey out the UI. If you must stop users changing a value, use a policy key the application reads, or accept that the preference reapplies at the next refresh.

## Method 3: PowerShell

The GroupPolicy module has cmdlets for both preference items and policy-based registry values.

```
Import-Module GroupPolicy
Set-GPPrefRegistryValue -Name 'APP - LOBApp Settings' -Context Computer -Action Update `
    -Key 'HKLM\SOFTWARE\Contoso\LOBApp' -ValueName 'ServerName' `
    -Value 'app01.contoso.com' -Type String
Set-GPPrefRegistryValue -Name 'APP - LOBApp Settings' -Context Computer -Action Update `
    -Key 'HKLM\SOFTWARE\Contoso\LOBApp' -ValueName 'Port' -Value 8443 -Type DWord
Get-GPPrefRegistryValue -Name 'APP - LOBApp Settings' -Context Computer `
    -Key 'HKLM\SOFTWARE\Contoso\LOBApp'
```

Points to know about `Set-GPPrefRegistryValue`:

- `-Action` takes Create, Replace, Update or Delete; `-Type` takes String, ExpandString, Binary, DWord, MultiString or QWord.

- It always adds a new item; it does not edit an existing one. Run `Remove-GPPrefRegistryValue` with the same GPO, context, key and value name first, or you end up with duplicates.

- It cannot set item-level targeting or the Common tab options. Add those in the editor afterwards.

For policy keys, `Set-GPRegistryValue` writes a registry-based policy setting, the same kind an ADMX template writes:

```
Set-GPRegistryValue -Name 'APP - LOBApp Settings' `
    -Key 'HKLM\SOFTWARE\Policies\Contoso\LOBApp' `
    -ValueName 'DisableUpdates' -Type DWord -Value 1
Get-GPRegistryValue -Name 'APP - LOBApp Settings' -Key 'HKLM\SOFTWARE\Policies\Contoso\LOBApp'
```

Values written this way appear under Extra Registry Settings in GPMC reports because no ADMX describes them. Keep them under `Software\Policies` so they are removed when the GPO is unlinked.

## Method 4: Intune alternatives

- **Settings catalog first.** Many Windows and Office settings already exist as CSPs or ingested ADMX. Search the Settings catalog before you build anything custom.

- **Custom OMA-URI via ADMX ingestion.** You can import a third-party ADMX and set its policies, but Microsoft blocks ingested policies from writing to `System`, `Software\Microsoft` and `Software\Policies\Microsoft`, apart from listed exceptions such as Office, OneDrive and Edge paths. There is no generic “write any registry value” setting.

- **Remediations.** A detection script checks the value and exits with `1` when it is wrong; the remediation script fixes it. Create the package under **Devices » Manage devices » Scripts and remediations**. Users need Windows Enterprise E3/E5, Education A3/A5 or VDA per user licences.

- **Platform scripts.** A PowerShell script under **Devices » Scripts and remediations » Platform scripts** runs once per device (or user) and is not reapplied, so it behaves like “Apply once”.

Detection and remediation pair for the example value:

```
# Detection
$p = 'HKLM:\SOFTWARE\Contoso\LOBApp'
$v = (Get-ItemProperty -Path $p -Name ServerName -ErrorAction SilentlyContinue).ServerName
if ($v -eq 'app01.contoso.com') { exit 0 } else { exit 1 }
# Remediation
$p = 'HKLM:\SOFTWARE\Contoso\LOBApp'
New-Item -Path $p -Force | Out-Null
New-ItemProperty -Path $p -Name ServerName -Value 'app01.contoso.com' -PropertyType String -Force | Out-Null
```

For HKCU values, set **Run this script using the logged-on credentials** to Yes, otherwise the script writes to the SYSTEM account’s hive.

## Verify it works

Check registry Group Policy Preferences results on a pilot machine before you link the GPO widely.

- Refresh and read the value:

```
gpupdate /forcereg query "HKLM\SOFTWARE\Contoso\LOBApp" /v ServerNameGet-ItemProperty -Path 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced' -Name HideFileExt
```

- Run `gpresult /h C:\Temp\gp.html` (as the user for HKCU items). The report lists each item under Preferences » Windows Settings » Registry with its result.

- Look in the Application log for warnings from source Group Policy Registry, such as event ID 4098, which name the failing item and the error code.

- For detail, enable **“Configure Registry preference logging and tracing”** under `Computer Configuration » Policies » Administrative Templates » System » Group Policy » Logging and tracing`. The trace files are written under `%ProgramData%\GroupPolicy\Preference\Trace` by default.

- The items themselves are stored in `Registry.xml` under `\\contoso.com\SYSVOL\contoso.com\Policies\{GPO-GUID}\Machine\Preferences\Registry` (or `User\Preferences\Registry`).

## Troubleshooting

Most registry Group Policy Preferences failures are path, scope or targeting problems.

| Symptom | Likely cause | Fix |
| --- | --- | --- |
| Value not written, no error | Item-level targeting evaluates to false | Enable preference tracing; check group membership and OS targeting |
| 32-bit application ignores the value | The item wrote the 64-bit view | Use SOFTWARE\WOW6432Node\… in the key path |
| Value reverts after users change it | Normal: the item reapplies at each refresh | Use “Apply once and do not reapply” for a default only |
| Value disappears unexpectedly | “Remove this item when it is no longer applied” and the item went out of scope | Check targeting, security filtering and GPO links |
| Other values in the key vanished | Replace action on a key | Use Update; restore from your reg export backup |
| HKCU value appears for SYSTEM, not the user | Item placed under Computer Configuration | Move it to User Configuration |
| Duplicate items after a script run | Set-GPPrefRegistryValue adds new items | Remove the old items first |
| Wrong DWORD data | Decimal and Hexadecimal mixed up | Check the base selected in the item |

## Roll back or undo

- **Remove a value you deployed:** change the item’s action to Delete, let it apply to all machines, then delete the item. Deleting the item straight away leaves the value in place.

- **Items with “Remove this item when it is no longer applied”:** unlinking the GPO or deleting the item removes the value at the next refresh.

- **PowerShell:** `Remove-GPPrefRegistryValue -Name 'APP - LOBApp Settings' -Context Computer -Key 'HKLM\SOFTWARE\Contoso\LOBApp' -ValueName 'ServerName'` removes the item from the GPO, not the value from clients.

- **Policy-based values:** `Remove-GPRegistryValue` or setting the ADMX policy to Not Configured removes values under `Software\Policies` from clients.

Back up the GPO with `Backup-GPO` before large changes, keep one registry Group Policy Preferences GPO per application, and name items clearly so the next administrator knows why each value exists.

## Registry Group Policy Preferences at a glance

**Official documentation:** [Group Policy Preferences](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/group-policy/group-policy-preferences), [Set-GPPrefRegistryValue](https://learn.microsoft.com/en-us/powershell/module/grouppolicy/set-gpprefregistryvalue), [Remediations in Microsoft Intune](https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/remediations).

**Related guides:** [Map Network Drives Group Policy: 2026 Item-Level Targeting Made Easy](/guides/map-network-drives-group-policy/) · [Group Policy loopback processing: merge vs replace for RDS hosts and kiosks](/guides/group-policy-loopback-processing/) · [Back up and restore GPOs with PowerShell](/guides/backup-restore-gpo-powershell/).

## Frequently asked questions

### What is the difference between Update and Replace in a GPP Registry item?

Update changes only the value or key settings defined in the item and creates them if missing. Replace deletes and recreates the value; on a key it deletes all values and subkeys first, so use it with care.

### Do Group Policy Preferences registry values stay after the GPO is removed?

Yes, by default the value stays in the registry. Tick “Remove this item when it is no longer applied” on the Common tab if you want Windows to delete it when the item goes out of scope.

### Can users change a registry value set by Group Policy Preferences?

Yes. Preferences do not lock the setting, so a user can change it, but the item writes it again at the next Group Policy refresh unless it is set to apply once.

### How do I deploy a registry value with Intune instead of Group Policy?

Look for the setting in the Settings catalog first. If none exists, use a Remediations script pair or a platform script, because custom OMA-URI settings cannot write arbitrary registry keys.
