Free tools Windows power users keep installed
One-click scans. No signup required.
KB3163622 (MS16-072) did not intentionally “break” Group Policy. Microsoft’s June 14, 2016 security update changed user Group Policy retrieval from the user’s security context to the computer’s security context. A user GPO can therefore stop applying when its permissions do not let the computer-side principal read it. The supported remedy is to correct the GPO permissions in Group Policy Management Console (GPMC), not to remove the security update.
What KB3163622 changed
MS16-072 addressed an elevation-of-privilege vulnerability involving traffic between a domain controller and a target computer. Microsoft’s bulletin says the update enforces Kerberos authentication for certain LDAP calls to protect against a man-in-the-middle attack.
The operational change administrators noticed was in user-policy retrieval. Before the update, user Group Policy was retrieved with the user’s security context. After the update, it is retrieved with the computer’s security context. Microsoft describes that behavior as an intentional security change.
What failure looks like
Microsoft’s documented symptom is that all user Group Policy—including policies security-filtered to user accounts, security groups, or both—may fail to apply on domain-joined computers.
#1 Best Overall
This can look like a policy-processing or patch problem, but the immediate question is whether the computer account (or a group containing it) can read the GPO that is being requested.
Why a previously working GPO can stop applying
A GPO can be linked correctly and still fail if its access control entries do not grant the new retrieval context the required Read permission. Common configurations affected by the change include:
Rank #2
- Upgraded Two Zipper Pockets: Forvencer server books feature two secure zipper pockets for better organization of coins, cash, and receipts, ensuring that everything you collect has a safe and secure place
- Smart Storage & Quick Access: Designed with 8 multi-functional compartments, the right side includes a guest receipt pad, while the left has a money pocket, ticket pocket, and credit card slot. Two small clear pockets store bills, receipts, and other visible items. A stitched pen loop ensures you always have your favorite pen ready
- High-quality & Easy to Clean: Crafted from high-quality PU leather with heavy-duty stitching, this server book is built to last. It resists tears, scratches, and its waterproof surface makes cleaning easy with just a damp cloth or a non-chlorine sanitizer
- Perfect Fit for Your Apron: Measuring 5” x 8”, this compact organizer is slightly smaller than other models, making it ideal for bending or sitting while carrying in your server apron. It holds everything a waitress needs—a place for everything
- What's Included: This server organizer comes with multiple open and zippered pockets to store money, receipts, tips, etc. Clear sleeves are perfect for keeping menus or special lists while serving. Available in a variety of colors, allowing you to express yourself even when in uniform
- GPOs missing Read for Authenticated Users. This is Microsoft’s primary documented permission issue.
- Security-filtered GPOs missing Read for Domain Computers. When filtering targets particular users or groups, the computer-side principal still needs to read the GPO.
- Loopback Processing in Merge mode. Microsoft says to include the specific users and computers for which the GPO is intended in the GPO’s Security Filtering area. The exact entries depend on the policy’s design.
Microsoft’s documented GPMC remediation
1. Open the affected GPO
- On an administration computer, open Group Policy Management.
- Locate the domain and organizational unit containing the affected linked GPO.
- Select the GPO and open its Scope tab.
2. Check security filtering and delegation
Review the Security Filtering list and the GPO’s permissions in the delegation view. The objective is to ensure that the computer-side principal can read the GPO while preserving the policy’s intended filtering.
3. Restore the required Read permission
For a normally scoped user GPO, add Authenticated Users with Read permission when it is absent. If the GPO uses security filtering, add Domain Computers with Read permission as Microsoft documents, while leaving the policy’s intended user or group filtering in place.
Recommended Free Tools
Rank #3
4. Handle loopback Merge deliberately
With loopback processing set to Merge, add the specific users and computers the GPO addresses in Security Filtering. Do not apply a blanket entry without checking which users and computers the loopback design actually targets.
5. Refresh and verify
After correcting permissions, refresh Group Policy on an affected domain-joined computer and verify that the expected user settings apply. If the policy still fails, compare the GPO link, security filtering, and Read permissions against the computer and user principals that should receive it.
Permission checks by configuration
| GPO configuration | Read permission to check | What to preserve |
|---|---|---|
| Standard user GPO | Authenticated Users | The GPO link and any intended user-side scope |
| Security-filtered GPO | Domain Computers, in addition to the filtering design | The selected users or security groups that should receive settings |
| Loopback Processing in Merge mode | The specific users and computers addressed by the GPO | The loopback targeting model; entries are configuration-specific |
What not to do
- Do not treat the security update as an ordinary broken patch. The context change was designed to close an elevation-of-privilege vulnerability.
- Do not start by uninstalling KB3163622. Microsoft’s documented fix is permission remediation in GPMC.
- Do not broaden access blindly. Add the documented Read permissions needed for computer-side retrieval while retaining the GPO’s intended security filtering.
A practical troubleshooting sequence
- Identify the exact user settings that stopped applying and the GPO that contains them.
- Confirm that the affected machines are domain joined and that the GPO is linked to the relevant organizational unit.
- Inspect the GPO’s Security Filtering and delegation permissions.
- Check for Read permission for Authenticated Users; for security-filtered policies, check Domain Computers as Microsoft specifies.
- If loopback Merge is enabled, verify that the targeted users and computers are included in Security Filtering.
- Refresh policy and test again on an affected computer.
The bottom line for legacy deployments
KB3163622 exposed a permissions assumption in some existing GPOs: user-policy retrieval could no longer rely only on the user’s ability to read the policy. The durable fix is to align each GPO’s Read permissions and filtering with computer-context retrieval, including the special targeting required by loopback Merge. The security protection supplied by MS16-072 should remain in place.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

