To manage a Group Policy Object (GPO), create it in Group Policy Management Console (GPMC), link it to the Active Directory site, domain, or organizational unit (OU) that should receive its settings, then edit those settings in Group Policy Management Editor. Creating a GPO alone does not apply it: the link determines its scope.
Before you begin: install GPMC and check permissions
Use a computer with the Group Policy Management feature installed. Microsoft documents GPMC for Windows Server and Windows client operating systems; on a client, Group Policy administration tools are available through Remote Server Administration Tools (RSAT). See Microsoft’s GPMC overview and the GroupPolicy module reference.
Check permissions for each operation. To edit a GPO, your account needs permission to edit settings, delete the GPO, and modify its security. To link a GPO, it needs permission to modify the destination site, domain, or OU. Microsoft says Domain Administrators and Enterprise Administrators have the relevant default permissions described in its GPMC documentation; delegated environments may use different permissions.
Create a GPO in GPMC
- Open Group Policy Management.
- In the console tree, expand the forest and domain where the GPO should be stored.
- Right-click Group Policy Objects and select New.
- Enter a name for the GPO and select OK.
This creates the GPO without linking it to a site, domain, or OU. Microsoft describes linking to an Active Directory container as the primary way to apply a GPO’s policy settings to users and computers. See Group Policy Management Console in Windows.
#1 Best Overall
- Server 2022 Standard 16 Core
Link the GPO to the intended scope
In GPMC, locate the site, domain, or OU that should receive the settings. Use its option to link an existing GPO, then select the GPO you created. You can also create and link a GPO directly from the intended target. Choose the scope carefully: linking to a domain, for example, is broader than linking to a particular OU.
PowerShell provides another way to create a link. Replace the example OU distinguished name with the actual target in your environment:
Rank #2
New-GPO -Name "Example GPO" | New-GPLink -Target "ou=Example,dc=contoso,dc=com"
New-GPO creates a GPO in the default domain context, and by itself it does not link the GPO. New-GPLink links it to the target; a new link is enabled by default. The account running the link operation needs Link GPOs permission on the target. Review Microsoft’s references for New-GPO and New-GPLink before adapting the commands, especially when working across domains or with delegated permissions.
Edit the GPO’s policy settings
- In GPMC, expand Group Policy Objects under the correct forest and domain.
- Right-click the GPO and select Edit.
- In Group Policy Management Editor, navigate to the policy item you want to change.
- Open the item’s properties, configure the setting, and close the editor when finished.
GPMC’s scripting interfaces can automate many console operations, but Microsoft says they cannot edit individual policy settings inside a GPO. Use Group Policy Management Editor for those settings.
Check link state, enforcement, and order
A link has properties that affect how the policy is applied. In GPMC, review the link at its target; PowerShell administrators can inspect or change link properties with Set-GPLink. Confirm you are working on the correct target, particularly if the same GPO has links in multiple locations.
- Enabled: A disabled link does not apply the GPO at that linked scope. New links created with
New-GPLinkare enabled by default. - Enforced: Enforcement is a link property that affects policy processing across the hierarchy. Set it only when that behavior is intended.
- Order: Microsoft’s
Set-GPLinkreference says higher link order numbers are processed before lower numbers. Check the existing order before changing it.
These properties and the link’s scope matter, but they do not by themselves establish the final settings a particular computer or user will receive. That depends on the environment and its policy configuration. See Microsoft’s Set-GPLink reference.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Choose GPMC or PowerShell
| Task | GPMC | PowerShell |
|---|---|---|
| Create a GPO | Right-click Group Policy Objects and select New. | New-GPO creates a GPO; it is unlinked by default. |
| Link a GPO | Use the target site, domain, or OU’s link-existing or create-and-link action. | New-GPLink links a GPO to a target distinguished name. |
| Edit individual policy settings | Open the GPO in Group Policy Management Editor. | GPMC scripting interfaces do not edit individual policy settings; use the editor. |
| Change link properties | Review and configure the link in the console. | Set-GPLink can change link enabled state, enforcement, and order. |
GPMC is useful for interactive navigation and checking the target in the console. PowerShell supports repeatable administration of GPO creation and links, but editing the actual policy settings still requires Group Policy Management Editor. The GroupPolicy module is documented for Windows Server and Windows client systems with RSAT installed.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

