Registry Group Policy Preferences items let you create, change or delete registry keys and values on domain computers and user profiles without writing a custom ADMX template or a logon script. You need them when an application stores its settings in the registry and has no policy template, when you want to change a Windows default that users may still adjust later, or when you must remove a value from hundreds of machines at once. This guide covers the Registry item and its four actions, the Registry Wizard, collections, targeting, PowerShell, Intune alternatives, verification and rollback.
Short answer: Edit a GPO and go to Computer Configuration » Preferences » Windows Settings » Registry (or the same path under User Configuration for HKCU). Choose New » Registry Item, set Action to Update, pick the hive, key path, value name, type and data, and click OK. Run gpupdate /force and check the value with reg query.
Table of Contents
Which method to use
| Method | Enforced? | Cleans up when removed? | Best for |
|---|---|---|---|
| GPP Registry item | Reapplied at each refresh; users can change it in between | Only with “Remove this item when it is no longer applied” | Any key or value, including HKLM\SOFTWARE and HKCU |
| Administrative Template (ADMX) setting | Yes, UI often greyed out | Yes, keys under Software\Policies are removed | Settings Microsoft or the vendor already ship a template for |
Set-GPRegistryValue (policy-based registry) | Yes | Yes under Software\Policies, otherwise tattooed | Scripting policy keys without an ADMX |
| Custom ADMX template | Yes | Only for keys under Software\Policies | Reusable settings with a friendly UI |
| Intune Settings catalog, Remediations or platform script | Depends on method | No, unless you script it | Microsoft Entra joined devices |
If a setting has an ADMX policy, use the policy. Use registry Group Policy Preferences items for everything else, and for values you want to set as a default that users may override.
Prerequisites
Registry Group Policy Preferences need very little set-up, but check these points first:
- Windows 11 Pro, Enterprise or Education, or Windows Server 2016 to 2025, joined to the domain. The Group Policy Registry client-side extension is built in.
- Rights to edit and link GPOs and the Group Policy Management Console. For PowerShell, the GroupPolicy module from RSAT.
- The exact key path, value name, type and data, tested on one machine first. Export the key with
reg exportbefore you change it. - A test OU with a computer and a test user.
Method 1: Create a Registry preference item
This is the core registry Group Policy Preferences workflow and the one you will use most.
- In Group Policy Management, create or edit a GPO linked to the OU that holds the target computers (for HKLM) or users (for HKCU).
- Go to
Computer Configuration » Preferences » Windows Settings » RegistryorUser Configuration » Preferences » Windows Settings » Registry. - Right-click Registry and choose New » Registry Item.
- Set Action (see the table below). Use Update unless you have a reason not to.
- Set Hive, for example HKEY_LOCAL_MACHINE, and Key Path without the hive and without leading or trailing backslashes, for example
SOFTWARE\Contoso\LOBApp. The … button browses the registry of the machine you are editing on. - Type the Value name (or tick Default for the key’s default value), choose the Value type and enter the Value data. For REG_DWORD choose Decimal or Hexadecimal.
- Click OK. On a test machine run
gpupdate /forceand check the value.
The Key Path, Value name and Value data fields accept preference variables. Press F3 in a field to insert one, for example %ComputerName% or %LogonUser%.
Create, Replace, Update and Delete
| Action | On a value | On a key (no value name) |
|---|---|---|
| Create | Creates the value only if it does not exist | Creates the key if missing |
| Replace | Deletes and recreates the value, overwriting everything about it | Deletes all values and subkeys in the key, leaving an empty key |
| Update | Changes only what the item defines; creates the value if missing | Creates the key if missing; leaves existing content |
| Delete | Removes the value | Removes the key with all its values and subkeys |
Be careful with Replace on a key: Microsoft documents that it deletes everything below the key before recreating it. That is useful to reset an application’s settings, and disastrous on a shared key such as SOFTWARE\Microsoft\Windows\CurrentVersion\Run.
HKCU vs HKLM
- HKLM items go in Computer Configuration and apply at startup and every background refresh.
- HKCU items go in User Configuration and apply at logon and every background refresh. An HKCU item placed under Computer Configuration writes to the SYSTEM account’s hive, not to the signed-in user.
- User items are processed in the system’s security context by default, so they can write under
HKCU\Software\Policies, which users cannot change themselves. Tick Run in logged-on user’s security context on the Common tab only when the item needs the user’s own network access. - To apply user registry items on specific computers only, such as Remote Desktop hosts, use loopback processing or item-level targeting by computer.
Example: show file name extensions for every user. User Configuration » Preferences » Windows Settings » Registry, action Update, hive HKEY_CURRENT_USER, key Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, value HideFileExt, type REG_DWORD, data 0. Users can still switch it back in File Explorer until the next refresh.
Method 2: Registry Wizard and collections
When an application needs a dozen values, do not type them one by one.
- Configure the application on a reference machine.
- In the GPO, right-click Registry and choose New » Registry Wizard, select the local computer (or another computer you can reach), and click Next.
- Browse to the key and tick each key and value you want. Click Finish.
- The wizard creates one Registry item per value, grouped in a collection named after the path. Open a few items and change the action from Update if needed.
To organise items yourself, right-click Registry and choose New » Collection Item, then drag items into it. Collections have no effect on where values land in the registry, but you can apply item-level targeting to the whole collection instead of each item.
Common options: targeting, apply once and removal
The Common tab decides how registry Group Policy Preferences items behave over time.
| Option | Effect | When to use |
|---|---|---|
| Stop processing items in this extension if an error occurs on this item | A failing item stops later items in the same GPO. Items are processed from the bottom of the list up. | When later items depend on this one |
| Run in logged-on user’s security context | Processes a user item as the user instead of the system | Rarely for registry items |
| Remove this item when it is no longer applied | Deletes the value when the item goes out of scope; changes the action to Replace | Values you want cleaned up when a user or computer leaves the scope |
| Apply once and do not reapply | Writes the value once; later refreshes skip it | A first-run default users may change |
| Item-level targeting | Applies the item only when the conditions are true | Per group, OS, OU or existing registry state |
Useful targeting items for registry work: Security Group (for example only members of Finance Users), Operating System (Windows 11 only), Registry Match (only if the application’s key exists, so you do not create keys for software that is not installed) and Organizational Unit. Add several and combine them with And, Or and Is Not.
Preferences vs ADMX policies and tattooing
A policy setting from an ADMX template writes under Software\Policies or Software\Microsoft\Windows\CurrentVersion\Policies. When the GPO no longer applies, Windows removes those values and the application falls back to its own default. Values written anywhere else stay in the registry after the GPO is gone; this is called tattooing.
- A registry Group Policy Preferences item tattoos by default. Tick Remove this item when it is no longer applied if you want the value removed when the GPO stops applying.
- A custom ADMX template that points at a key outside
Software\Policiesalso tattoos, and it hides that fact behind a policy-style UI. If you write a custom ADMX, keep it underSoftware\Policies\<Vendor>. - Preferences do not grey out the UI. If you must stop users changing a value, use a policy key the application reads, or accept that the preference reapplies at the next refresh.
Method 3: PowerShell
The GroupPolicy module has cmdlets for both preference items and policy-based registry values.
Import-Module GroupPolicy
Set-GPPrefRegistryValue -Name 'APP - LOBApp Settings' -Context Computer -Action Update `
-Key 'HKLM\SOFTWARE\Contoso\LOBApp' -ValueName 'ServerName' `
-Value 'app01.contoso.com' -Type String
Set-GPPrefRegistryValue -Name 'APP - LOBApp Settings' -Context Computer -Action Update `
-Key 'HKLM\SOFTWARE\Contoso\LOBApp' -ValueName 'Port' -Value 8443 -Type DWord
Get-GPPrefRegistryValue -Name 'APP - LOBApp Settings' -Context Computer `
-Key 'HKLM\SOFTWARE\Contoso\LOBApp'
Points to know about Set-GPPrefRegistryValue:
-Actiontakes Create, Replace, Update or Delete;-Typetakes String, ExpandString, Binary, DWord, MultiString or QWord.- It always adds a new item; it does not edit an existing one. Run
Remove-GPPrefRegistryValuewith the same GPO, context, key and value name first, or you end up with duplicates. - It cannot set item-level targeting or the Common tab options. Add those in the editor afterwards.
For policy keys, Set-GPRegistryValue writes a registry-based policy setting, the same kind an ADMX template writes:
Set-GPRegistryValue -Name 'APP - LOBApp Settings' `
-Key 'HKLM\SOFTWARE\Policies\Contoso\LOBApp' `
-ValueName 'DisableUpdates' -Type DWord -Value 1
Get-GPRegistryValue -Name 'APP - LOBApp Settings' -Key 'HKLM\SOFTWARE\Policies\Contoso\LOBApp'
Values written this way appear under Extra Registry Settings in GPMC reports because no ADMX describes them. Keep them under Software\Policies so they are removed when the GPO is unlinked.
Method 4: Intune alternatives
- Settings catalog first. Many Windows and Office settings already exist as CSPs or ingested ADMX. Search the Settings catalog before you build anything custom.
- Custom OMA-URI via ADMX ingestion. You can import a third-party ADMX and set its policies, but Microsoft blocks ingested policies from writing to
System,Software\MicrosoftandSoftware\Policies\Microsoft, apart from listed exceptions such as Office, OneDrive and Edge paths. There is no generic “write any registry value” setting. - Remediations. A detection script checks the value and exits with
1when it is wrong; the remediation script fixes it. Create the package under Devices » Manage devices » Scripts and remediations. Users need Windows Enterprise E3/E5, Education A3/A5 or VDA per user licences. - Platform scripts. A PowerShell script under Devices » Scripts and remediations » Platform scripts runs once per device (or user) and is not reapplied, so it behaves like “Apply once”.
Detection and remediation pair for the example value:
# Detection
$p = 'HKLM:\SOFTWARE\Contoso\LOBApp'
$v = (Get-ItemProperty -Path $p -Name ServerName -ErrorAction SilentlyContinue).ServerName
if ($v -eq 'app01.contoso.com') { exit 0 } else { exit 1 }
# Remediation
$p = 'HKLM:\SOFTWARE\Contoso\LOBApp'
New-Item -Path $p -Force | Out-Null
New-ItemProperty -Path $p -Name ServerName -Value 'app01.contoso.com' -PropertyType String -Force | Out-Null
For HKCU values, set Run this script using the logged-on credentials to Yes, otherwise the script writes to the SYSTEM account’s hive.
Verify it works
Check registry Group Policy Preferences results on a pilot machine before you link the GPO widely.
- Refresh and read the value:
gpupdate /force
reg query "HKLM\SOFTWARE\Contoso\LOBApp" /v ServerName
Get-ItemProperty -Path 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced' -Name HideFileExt - Run
gpresult /h C:\Temp\gp.html(as the user for HKCU items). The report lists each item under Preferences » Windows Settings » Registry with its result. - Look in the Application log for warnings from source Group Policy Registry, such as event ID 4098, which name the failing item and the error code.
- For detail, enable “Configure Registry preference logging and tracing” under
Computer Configuration » Policies » Administrative Templates » System » Group Policy » Logging and tracing. The trace files are written under%ProgramData%\GroupPolicy\Preference\Traceby default. - The items themselves are stored in
Registry.xmlunder\\contoso.com\SYSVOL\contoso.com\Policies\{GPO-GUID}\Machine\Preferences\Registry(orUser\Preferences\Registry).
Troubleshooting
Most registry Group Policy Preferences failures are path, scope or targeting problems.
| Symptom | Likely cause | Fix |
|---|---|---|
| Value not written, no error | Item-level targeting evaluates to false | Enable preference tracing; check group membership and OS targeting |
| 32-bit application ignores the value | The item wrote the 64-bit view | Use SOFTWARE\WOW6432Node\… in the key path |
| Value reverts after users change it | Normal: the item reapplies at each refresh | Use “Apply once and do not reapply” for a default only |
| Value disappears unexpectedly | “Remove this item when it is no longer applied” and the item went out of scope | Check targeting, security filtering and GPO links |
| Other values in the key vanished | Replace action on a key | Use Update; restore from your reg export backup |
| HKCU value appears for SYSTEM, not the user | Item placed under Computer Configuration | Move it to User Configuration |
| Duplicate items after a script run | Set-GPPrefRegistryValue adds new items | Remove the old items first |
| Wrong DWORD data | Decimal and Hexadecimal mixed up | Check the base selected in the item |
Roll back or undo
- Remove a value you deployed: change the item’s action to Delete, let it apply to all machines, then delete the item. Deleting the item straight away leaves the value in place.
- Items with “Remove this item when it is no longer applied”: unlinking the GPO or deleting the item removes the value at the next refresh.
- PowerShell:
Remove-GPPrefRegistryValue -Name 'APP - LOBApp Settings' -Context Computer -Key 'HKLM\SOFTWARE\Contoso\LOBApp' -ValueName 'ServerName'removes the item from the GPO, not the value from clients. - Policy-based values:
Remove-GPRegistryValueor setting the ADMX policy to Not Configured removes values underSoftware\Policiesfrom clients.
Back up the GPO with Backup-GPO before large changes, keep one registry Group Policy Preferences GPO per application, and name items clearly so the next administrator knows why each value exists.
Registry Group Policy Preferences at a glance

Official documentation: Group Policy Preferences, Set-GPPrefRegistryValue, Remediations in Microsoft Intune.
Related guides: Map Network Drives Group Policy: 2026 Item-Level Targeting Made Easy · Group Policy loopback processing: merge vs replace for RDS hosts and kiosks · Back up and restore GPOs with PowerShell.
Frequently asked questions
What is the difference between Update and Replace in a GPP Registry item?
Update changes only the value or key settings defined in the item and creates them if missing. Replace deletes and recreates the value; on a key it deletes all values and subkeys first, so use it with care.
Do Group Policy Preferences registry values stay after the GPO is removed?
Yes, by default the value stays in the registry. Tick “Remove this item when it is no longer applied” on the Common tab if you want Windows to delete it when the item goes out of scope.
Can users change a registry value set by Group Policy Preferences?
Yes. Preferences do not lock the setting, so a user can change it, but the item writes it again at the next Group Policy refresh unless it is set to apply once.
How do I deploy a registry value with Intune instead of Group Policy?
Look for the setting in the Settings catalog first. If none exists, use a Remediations script pair or a platform script, because custom OMA-URI settings cannot write arbitrary registry keys.