Group Policy, Group Policy Object and RSoP Explained

-

|

Introduction

This guide gives an overview of Group Policy, RSoP (Resultant Set of Policy) and Group Policy Objects.

Acronyms used in this guide:
GP – Group Policy
RSoP – Resultant Set of Policy
GPOs or GP Objects – Group Policy Objects
GPMC – Group Policy Management Console
GP Settings – Group Policy Settings

What is Group Policy (GP)?

Group Policy is a Microsoft infrastructure tool that provides centralized management and configuration of user and computer settings. Group Policy does this through Group Policy settings and Group Policy Preferences.

The beauty of GP is that it provides administrators centralized management and control. For example, an administrator can enforce a password complexity policy. Or modify specific settings of domain-joined computers.

Sponsored Content

Group Policy Management Console (GPMC)

Group Policy, Group Policy Object and RSoP Explained

Group Policy Management Console (GPMC) is the tool used to create GPOs. GPOs are the actual objects where the administrator sets the policies that control users and computer settings.

Below are some of the things you can do with GPMC:

  • Create new and edit existing GPOs
  • Export existing GPO and import GPOs.
  • Also, copy, paste, backup and restore GPOs
  • Create GPO reports, including RSoP reports

RSoP (Resultant Set of Policy)

RSoP is a report of group policy settings applied to users and computers. You can use RSoP.mmc to get RSoP for a local computer. To get RSoP information for a remote computer, use GPResult command line.

GPResult displays the Resultant Set of Policy (RSoP) information for a local or remote user and/or computer. To learn how to use GPResult Command, click GPResult Command: Syntax, Parameters, Examples.

How to Use RSoP.mmc to Get Applied GPOs

  • Log on to the computer with an admin account.
  • Next, hold the Windows logo key and R, to open Run. When Run opens, type RSoP.msc and click Ok. RSoP will start gathering the information (see the second image below the Sponsored Content).
Group Policy, Group Policy Object and RSoP Explained
Sponsored Content

Group Policy, Group Policy Object and RSoP Explained
  • When it finishes, it will display a report similar to the image below.

Generating the policies applied to a computer is useful for troubleshooting and resolving group policy issues. It will help determine what polices are applied or not applied to a user or a computer.

Understanding RSoP.mmc Results

The result generated by RSoP.mmc has two parts, Computer Configuration and User Configuration.

The results are similar to the settings in a typical GPO. But the result only shows settings applied to the computer or user.

As an example, when I click the Computer Configuration\Software Settings node, it is blank. This is because no policy setting was applied to the computer from the settings in this node.

As I said earlier, you can use RSoP results to troubleshoot GPOs. Say you created password policies and applied the GPO to an OU. You have confirmed that a particular computer is in the OU where the GPO is applied. But when you check the computer, the password policy does not apply.

To see the password policies applied to this computer, in the RSoP result, expand \Computer Configuration\Windows Settings\Security Settings\Account Policy. Then click Password Policy. On the right hand side of the console, you can review the password policies applied to this computer.

Tip
There are other factors that may help you determine why a GPO is not applied to a user or a computer. See the next section for details.

Group Policy Objects (GPOs)

A GPO is is a collection of user and computer settings that defines the permissions, behavior and configuration of users or computers the GPO is applied to.

A GPO can be applied at the Domain, Organizational Unit or Site container level.

When you apply a GPO to a container, all objects in that container inherits the policies defined in the GPO settings.

Tip
Objects inhering GPO polices may also be affected by other configurations like Block Inheritance or No override (more on this below).

To apply a GOP to a Domain, OU or site you can create a new GPO or link an existing one.

Enforced, Block Inheritance and GPO Priority

Earlier in this guide, I said that GPOs can be applied to Sites, Domains and Organizational Units (OUs). When you apply a GPO to a container, all objects within the container should apply the GPO settings. But there is a caveat.

There are two GPO settings that affect whether a GPO may be applied to an object or not – Enforced and Block Inheritance. If you do not want higher GPO links to apply to a child container, you can enable Block Inheritance. But if you want to force top level GPOs on child containers, enable Enforced on the higher level GPO.

When a GPO is set to Enforced, it overrides Block Inheritance. This means that Enforced policies takes precedence over Block Inheritance policies.

Tip
Block Inheritance is set at a child container to stop all GPOs in upper higher containers applying to the child container. But if you enable Enforced at the top level GPO, it overrides Block Inheritance set at the child container.

To set Enforced, right-click the top level GPO. Then click Enforced.

To set Block Inheritance, right-click the lower level container. Then click Block Inheritance.

GPO (Group Policy Object) Processing Order

GPO processing is based on a last writer-wins model. This means that a GPO applied later takes precedence over GPOs applier earlier.

GPOs are applied in this order:

  • The local Group Policy object is applied first
  • Then GPOs linked to sites are applied next
  • Followed by GPOs linked to domains
  • Finally, GPOs linked to organizational units (OUs) are applied last
Tip
Except Enforced is enabled at the Site or Domain level, a GPO applied at the OU is applied to an object. This information is very useful for troubleshooting purposes.

To view the Group Policy precedence order of a container:

  • Highlight the container (click on it). On the right hand side, click the Group Policy Inheritance tab.
Sponsored Content

Conclusion

In this guide I covered Group Policy, RSoP (Resultant Set of Policy) and Group Policy Objects. I hope this has improved your knowledge of Group Policy.

If you have any question or comment use the “Leave a Reply” form at the end of the guide. Alternatively, share your experience with configuring, managing and troubleshooting Group Policies and GPOs.

Other Helpful Guides

Additional Resources and References

LEAVE A REPLY

Please enter your comment!
Please enter your name here

FEATURED POSTS

network discovery keeps turning off server 2016

How to Fix Network Discovery If it Keeps Turning Off in Server 2016

Does network discovery keep turning off in your Windows server 2016? It is likely that one of its dependent services is not...
how to install windows 10 1903 update manually

How to Install Windows 10 1903 Update Manually

Windows 10 1903 Update was released in May, 2019. But some users are not yet offered the update via automatic update. The...
spotify web player not working

Spotify Web Player Not Working [Fixed]

Introduction Spotify Web Player may stop working for you with the following error messages: "Spotify Web Player an Error...
DISM.exe /Online /Cleanup-Image /Restorehealth

DISM.exe /Online /Cleanup-Image /Restorehealth Explained

What is DISM.EXE /Online /Cleanup-image /RestoreHealth? "DISM.exe /Online /Cleanup-Image /Restorehealth" is a DISM command that repairs issue with the...
DHCP Relay agent

DHCP Relay Agent: Configuration in Windows Server 2016

What is a DHCP Relay Agent? A DHCP Relay Agent allows DHCP clients in a different network subnet to...

TRENDING POSTS

Remote Desktop Connection

Remote Desktop Connection an Internal Error Has Occurred [Fixed]

Introduction I recently received the error message "Remote Desktop Connection an Internal Error Has Occurred". It was strange because...

Find My Samsung: Register and Use Samsung Find my Mobile

Introduction Ever wondered how you could find your Samsung phone if you lost it? Find my Samsung or Samsung...
What is the Difference Between PowerShell and CMD?

Windows Powershell vs CMD: Differences and Similarities

Introduction This short guide compares Windows PowerShell vs CMD (Windows command prompt). I will cover the history and nature...
Spotify No Longer Supports this Version of Microsoft Edge

Spotify No Longer Supports this Version of Microsoft Edge [Fixed]

Introduction When you open Spotify web player on Microsoft Edge, you may receive the error message "Spotify No Longer...
Windows 10 Won't Boot

Windows 10 Won’t Boot With Black Screen? 3 Ways to Fix It

Why Won't Windows 10 Boot Up? If your Windows 10 stops with a black screen, the first question in...

BEST OF ITECHGUIDES

dhcp relay agent windows server 2016 not working

DHCP Relay Agent Windows Server 2016 Not Working [Fixed]

Introduction Most reports about DHCP relay agent not working in Windows Server 2016 has to do with clients in...

Find My Samsung: Register and Use Samsung Find my Mobile

Introduction Ever wondered how you could find your Samsung phone if you lost it? Find my Samsung or Samsung...
command prompt commands

20 Command Prompt Commands for Sys Admins

Introduction Here is my ultimate list of command prompt commands for very serious Windows Systems Administrators. For each command,...
ClearScore

ClearScore Can Help Improve Your Credit Score for FREE (Here is How)

What is ClearScore and Who is ClearScore? ClearScore (Some call it Clear Score!) is a London-based financial services company...
windows system32 config systemprofile desktop is unav

How to Fix “C:WINDOWSsystem32configsystemprofileDesktop Is Unavailable” Error in Windows 10

Introduction You may receive the error message "WINDOWS system32 config systemprofile Desktop is unavailable" after upgrading to Windows 10....

RECENT POSTS

disable cortana windows 10 featured

How to Disable Cortana in Windows 10 (2 Methods)

Introduction Some Windows 10 users may not like Cortana. Solution? Disable Cortana. You are probably reading this because you...
bootrec /fixboot access is denied

How to Fix BootRec /FixBoot Access is Denied Error in Windows 10

Introduction BootRec /FixBoot Access is Denied Error in Windows 10? This error is likely caused by corrupt EFI directory.
Reset Windows 10

How to Reset Windows 10 (2 Methods)

Introduction If your Windows 10 is broken, one available way to fix it is to use Windows 10 reset....
system restore windows 10

How to Enable and Use System Restore in Windows 10

Introduction System restore in windows 10 is a very important tool that is probably ignored by most users. But...
windows has stopped this device code 43

How to Fix Windows Has Stopped this Device Code 43 Error

Introduction Sometimes you may receive "Windows has stopped this device code 43" error. This error is likely to come...
Windows could not automatically detect this network's proxy settings

How to Fix “Windows Could not Automatically Detect this Network’s Proxy Settings”

Introduction You suddenly lose the ability to connect to the internet. Then you run network troubleshooter and it returns...
printer offline

5 Ways to Restore Your Printer Online If Status is Offline

Introduction Is your printer offline? Setting it online is very simple but sometimes it is more than just setting...

How to Fix “BootMgr is Missing” Error in Windows 10

Introduction If you receive Fix "BootMgr is missing" Error in Windows 10, the default response is panic! But you...
windows 10 search featured

How to Fix Windows 10 Search If it Stops Working

Introduction Are you having troubles with Windows 10 search? Apparently, it is a fairly common problem with a number...
oooops, something went wrong. reload

How to Fix “Oooops something went wrong. reload” Spotify Error

Introduction If you receive "Oooops something went wrong. reload" Spotify error, do not panic. The fix is simpler than...

MUST READ

Windows 10 not booting after update

How to Fix Windows 10 Boot Problem After Windows Update

If you experience Windows 10 not booting after an update, it is likely that the update corrupted the boot files.
scanning and repairing drive

Scanning and Repairing Drive Issue on Windows 10 [Fixed]

Introduction A number of Windows 10 users have reported that when they boot their computer it is stuck on...
your pc ran into a problem and needs to restart

Your PC Ran Into a Problem and Needs to Restart [Fixed]

What Does "Your PC Ran Into a Problem and Needs to Restart" Mean? "Your PC ran into a problem...
SysWOW64 and File System Redirector Explained

SysWOW64 and File System Redirector Explained

Introduction A Windows 64-bits OS has a SysWOW64 folder. It also has a System32 folder. These folders contain OS...

Windows 7 Safe Mode: How to Start Windows 7 in Safe Mode

Introduction If need to perform some advanced troubleshooting on Windows 7, then you may need to start Windows 7...

By using this website you agree to accept our Privacy Policy and Terms & Conditions