|

FEATURED POSTS

How to Change Outlook Password in 3 Different Ways

How to Change Outlook Password in 2 Easy Steps

Introduction Before you change your Outlook Password you have to first change it with your email provider. The reason...
spotify web player not working

Spotify Web Player Not Working [Fixed]

Introduction Spotify Web Player may stop working for you with the following error messages: "Spotify Web Player an Error...
DISM.exe /Online /Cleanup-Image /Restorehealth

DISM.exe /Online /Cleanup-Image /Restorehealth Explained

What is DISM.EXE /Online /Cleanup-image /RestoreHealth? "DISM.exe /Online /Cleanup-Image /Restorehealth" is a DISM command that repairs issue with the...
DHCP Relay agent

DHCP Relay Agent: Configuration in Windows Server 2016

What is a DHCP Relay Agent? A DHCP Relay Agent allows DHCP clients in a different network subnet to...
ForEach-Powershell

PowerShell ForEach: Syntax, Parameters, Examples

What is PowerShell ForEach? PowerShell ForEach (ForEach PowerShell) is a PowerShell construct used in iterating through values in a...

TRENDING POSTS

Remote Desktop Connection

Remote Desktop Connection an Internal Error Has Occurred [Fixed]

Introduction I recently received the error message "Remote Desktop Connection an Internal Error Has Occurred". It was strange because...

Find My Samsung: Register and Use Samsung Find my Mobile

Introduction Ever wondered how you could find your Samsung phone if you lost it? Find my Samsung or Samsung...
PowerShell vs CMD

Powershell vs CMD: Differences and Similarities Compared

Introduction This short guide compares PowerShell vs CMD (Windows command prompt). I will cover the history and nature of...
Spotify No Longer Supports this Version of Microsoft Edge

Spotify No Longer Supports this Version of Microsoft Edge [Fixed]

Introduction When you open Spotify web player on Microsoft Edge, you may receive the error message "Spotify No Longer...
Windows 10 Won't Boot

Windows 10 Won’t Boot With Black Screen? 3 Ways to Fix It

Why Won't Windows 10 Boot Up? If your Windows 10 stops with a black screen, the first question in...

BEST OF ITECHGUIDES

Walmart Baby Registry

Walmart Baby Registry: Your Definitive Guide

Introduction Walmart Baby Registry gives expectant mothers a place to create a list of items they need for their...
RAID 5 vs RAID 6

RAID 5 vs RAID 6: Differences, Benefits and Disadvantages

What is RAID 5 vs RAID 6? RAID 5 and RAID 6 uses striping with distributed parity technique. However,...
spotify web player not working

Spotify Web Player Not Working [Fixed]

Introduction Spotify Web Player may stop working for you with the following error messages: "Spotify Web Player an Error...
PortalOffice365

Portal Office 365: Your Ultimate Guide to Office 365 Admin Portal

What is PortalOffice365? PortalOffice365 (portal.office.com) is a Microsoft cloud-based portal that allows administrators to create and manage users and...
FTP and SFTP ports

FTP and FTP Port, SFTP and SFTP Port: Quick Reference

Introduction FTP and SFTP are two protocols for transferring files between a server and a client computer. FTP port...

RECENT POSTS

how to merge cells in excel

How to Merge Cells in Excel in 2 Easy Ways

Introduction You can merge two Cells in Excel using CONCATENATE function or the “&” (ampersand) operator. Though Excel has...
How to Make a Pivot Table in Google Sheets

How to Make a Pivot Table in Google Sheets

Introduction You can make a Pivot Table in Google Sheets to simplify analysis of complex data. A Pivot Table...
how to make Pivot Table

How to Make a Pivot Table in Excel

Introduction A Pivot Table allows you to analyze, summarize and calculate large data to help find relationships. With a...
RAID 3 (Redundant Array of Independent Disks) Explained

RAID 3 (Redundant Array of Independent Disks) Explained

What is RAID 3? RAID 3 is a RAID implementation that uses striping with a dedicated parity disk....
RAID 5 vs RAID 6

RAID 5 vs RAID 6: Differences, Benefits and Disadvantages

What is RAID 5 vs RAID 6? RAID 5 and RAID 6 uses striping with distributed parity technique. However,...
concatenate excel

Concatenate in Excel: How to Concatenate Columns and Strings

What is Concatenate in Excel? Concatenate in Excel is joining two strings into one continuous string. You can join...

How to Add in Excel (Excel Sum) with Examples

Introduction There are different ways to add numbers in Excel. You could simply select the cells containing the data....
Excel Count

Excel Count: How to Count in Excel With Examples

Introduction Excel COUNT Function is used for counting items in a worksheet. Excel COUNT also has the conditional function,...
powershell.exe -command

Powershell.exe Command: Syntax, Parameters and Examples

Introduction You may be wondering why write on Powershell.exe Command. Are there special commands for Powershell.exe? Yes! When you...
how to move columns in excel

How to Move Columns to Rows and Rows to Columns in Excel

Introduction If you receive some Excel data in columns, you can easily move the columns to rows in Excel...

MUST READ

Remote Desktop Connection

Remote Desktop Connection an Internal Error Has Occurred [Fixed]

Introduction I recently received the error message "Remote Desktop Connection an Internal Error Has Occurred". It was strange because...
dns server not responding featured image

“DNS Server Not Responding” Error [Fixed]

What Could Cause "DNS Server Not Responding" Error Message? The error messages "DNS Server Not Responding" or "DNS...
dropbox login

Dropbox Login: Your Ultimate Guide to Dropbox

Introduction Dropbox login allows you to sign in to and use Dropbox. But what is Dropbox? Let's kick off...
PortalOffice365

Portal Office 365: Your Ultimate Guide to Office 365 Admin Portal

What is PortalOffice365? PortalOffice365 (portal.office.com) is a Microsoft cloud-based portal that allows administrators to create and manage users and...
DISM.exe /Online /Cleanup-Image /Restorehealth

DISM.exe /Online /Cleanup-Image /Restorehealth Explained

What is DISM.EXE /Online /Cleanup-image /RestoreHealth? "DISM.exe /Online /Cleanup-Image /Restorehealth" is a DISM command that repairs issue with the...

Group Policy, Group Policy Object and RSoP Explained

-

Introduction

This guide gives an overview of Group Policy, RSoP (Resultant Set of Policy) and Group Policy Objects.

Acronyms used in this guide:
GP – Group Policy
RSoP – Resultant Set of Policy
GPOs or GP Objects – Group Policy Objects
GPMC – Group Policy Management Console
GP Settings – Group Policy Settings

What is Group Policy (GP)?

Group Policy is a Microsoft infrastructure tool that provides centralized management and configuration of user and computer settings. Group Policy does this through Group Policy settings and Group Policy Preferences.

The beauty of GP is that it provides administrators centralized management and control. For example, an administrator can enforce a password complexity policy. Or modify specific settings of domain-joined computers.

Sponsored Content

Group Policy Management Console (GPMC)

Group Policy, Group Policy Object and RSoP Explained

Group Policy Management Console (GPMC) is the tool used to create GPOs. GPOs are the actual objects where the administrator sets the policies that control users and computer settings.

Below are some of the things you can do with GPMC:

  • Create new and edit existing GPOs
  • Export existing GPO and import GPOs.
  • Also, copy, paste, backup and restore GPOs
  • Create GPO reports, including RSoP reports

RSoP (Resultant Set of Policy)

RSoP is a report of group policy settings applied to users and computers. You can use RSoP.mmc to get RSoP for a local computer. To get RSoP information for a remote computer, use GPResult command line.

GPResult displays the Resultant Set of Policy (RSoP) information for a local or remote user and/or computer. To learn how to use GPResult Command, click GPResult Command: Syntax, Parameters, Examples.

How to Use RSoP.mmc to Get Applied GPOs

  • Log on to the computer with an admin account.
  • Next, hold the Windows logo key and R, to open Run. When Run opens, type RSoP.msc and click Ok. RSoP will start gathering the information (see the second image below the Sponsored Content).
Group Policy, Group Policy Object and RSoP Explained
Sponsored Content

Group Policy, Group Policy Object and RSoP Explained
  • When it finishes, it will display a report similar to the image below.

Generating the policies applied to a computer is useful for troubleshooting and resolving group policy issues. It will help determine what polices are applied or not applied to a user or a computer.

Understanding RSoP.mmc Results

The result generated by RSoP.mmc has two parts, Computer Configuration and User Configuration.

The results are similar to the settings in a typical GPO. But the result only shows settings applied to the computer or user.

As an example, when I click the Computer Configuration\Software Settings node, it is blank. This is because no policy setting was applied to the computer from the settings in this node.

As I said earlier, you can use RSoP results to troubleshoot GPOs. Say you created password policies and applied the GPO to an OU. You have confirmed that a particular computer is in the OU where the GPO is applied. But when you check the computer, the password policy does not apply.

To see the password policies applied to this computer, in the RSoP result, expand \Computer Configuration\Windows Settings\Security Settings\Account Policy. Then click Password Policy. On the right hand side of the console, you can review the password policies applied to this computer.

Tip
There are other factors that may help you determine why a GPO is not applied to a user or a computer. See the next section for details.

Group Policy Objects (GPOs)

A GPO is is a collection of user and computer settings that defines the permissions, behavior and configuration of users or computers the GPO is applied to.

A GPO can be applied at the Domain, Organizational Unit or Site container level.

When you apply a GPO to a container, all objects in that container inherits the policies defined in the GPO settings.

Tip
Objects inhering GPO polices may also be affected by other configurations like Block Inheritance or No override (more on this below).

To apply a GOP to a Domain, OU or site you can create a new GPO or link an existing one.

Enforced, Block Inheritance and GPO Priority

Earlier in this guide, I said that GPOs can be applied to Sites, Domains and Organizational Units (OUs). When you apply a GPO to a container, all objects within the container should apply the GPO settings. But there is a caveat.

There are two GPO settings that affect whether a GPO may be applied to an object or not – Enforced and Block Inheritance. If you do not want higher GPO links to apply to a child container, you can enable Block Inheritance. But if you want to force top level GPOs on child containers, enable Enforced on the higher level GPO.

When a GPO is set to Enforced, it overrides Block Inheritance. This means that Enforced policies takes precedence over Block Inheritance policies.

Tip
Block Inheritance is set at a child container to stop all GPOs in upper higher containers applying to the child container. But if you enable Enforced at the top level GPO, it overrides Block Inheritance set at the child container.

To set Enforced, right-click the top level GPO. Then click Enforced.

To set Block Inheritance, right-click the lower level container. Then click Block Inheritance.

GPO (Group Policy Object) Processing Order

GPO processing is based on a last writer-wins model. This means that a GPO applied later takes precedence over GPOs applier earlier.

GPOs are applied in this order:

  • The local Group Policy object is applied first
  • Then GPOs linked to sites are applied next
  • Followed by GPOs linked to domains
  • Finally, GPOs linked to organizational units (OUs) are applied last
Tip
Except Enforced is enabled at the Site or Domain level, a GPO applied at the OU is applied to an object. This information is very useful for troubleshooting purposes.

To view the Group Policy precedence order of a container:

  • Highlight the container (click on it). On the right hand side, click the Group Policy Inheritance tab.
Sponsored Content

Conclusion

In this guide I covered Group Policy, RSoP (Resultant Set of Policy) and Group Policy Objects. I hope this has improved your knowledge of Group Policy.

If you have any question or comment use the “Leave a Reply” form at the end of the guide. Alternatively, share your experience with configuring, managing and troubleshooting Group Policies and GPOs.

Other Helpful Guides

Additional Resources and References

YOU MAY ALSO LIKE:

LEAVE A REPLY

Please enter your comment!
Please enter your name here

By using this website you agree to accept our Privacy Policy and Terms & Conditions