Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsA WMI filter lets a Group Policy Object (GPO) apply only when a query about the destination computer returns true. Create the filter in Group Policy Management Console (GPMC), attach it to the GPO, then test policy processing on representative computers. Use WMI filtering for computer characteristics that cannot be expressed more simply with GPO permissions or Group Policy Preferences item-level targeting.
What a WMI filter does
A WMI filter is a query associated with a GPO. During Group Policy processing, the client evaluates the query on the destination computer: a true result allows the GPO to apply, and a false result excludes it. Microsoft documents one WMI filter per GPO; a filter can be reused by multiple GPOs. See Microsoft’s Group Policy processing guidance.
Choose the right targeting method
| Requirement | Method | How it differs |
|---|---|---|
| Limit a GPO by user or computer group membership and permissions | Security filtering | Uses permissions to determine which users or computers can apply the GPO. See Microsoft’s Group Policy scope guidance. |
| Limit a GPO based on a computer condition, such as an operating-system characteristic | WMI filter | The Group Policy client evaluates the query on the destination computer during policy processing. |
| Apply a condition to an individual Group Policy Preferences item | Item-level targeting | Targets preference items rather than deciding whether the entire GPO applies; multiple conditions can be combined using AND or OR. See Microsoft’s Group Policy Preferences guidance. |
Microsoft recommends using WMI filters primarily for exception management. They are evaluated during Group Policy processing and can add startup or logon time. The cited Microsoft guidance says there is no timeout for WMI filters, so keep queries necessary and straightforward; it does not quantify a delay that applies to every environment. See Microsoft’s security-group and WMI-filter guidance.
How to create a WMI filter for a GPO
Use GPMC, Microsoft’s console for managing GPOs and WMI filters. Install the Group Policy Management feature and have permission to edit the GPO. Linking a GPO to a site, domain, or OU requires permission to modify that container. See Microsoft’s GPMC overview.
#1 Best Overall
- Open GPMC and expand the forest and domain containing the target GPO.
- Select WMI Filters, create a new filter, and give it a descriptive name and a description stating why it exists.
- Add a query, specifying its WMI namespace and query text. Confirm that the query matches the computers you intend to target.
- Save the filter. If an existing filter expresses the same condition, you can reuse it instead of creating a duplicate.
- Select the target GPO and choose the filter in its WMI Filtering section.
Each GPO can have one associated WMI filter, but the same filter can be assigned to more than one GPO. Do not attach multiple filters to a single GPO expecting them to combine.
Example query—and why it is historical
Microsoft’s legacy Create WMI Filters for the GPO procedure is labeled for Windows Server 2012 and was last updated September 5, 2016. It shows this Windows 8 client example, querying Win32_OperatingSystem in the rootCIMv2 namespace:
Rank #2
select * from Win32_OperatingSystem where Version like "6.2%" and ProductType="1"
The query combines a version-prefix condition with a product-type condition. In that legacy example, ProductType 1 denotes client systems, 2 denotes domain controllers, and 3 denotes other servers. The 6.2% prefix is a Windows 8-era example, not a current Windows release selector. Verify the WMI properties and values on the operating systems in your environment; the cited material does not establish one query that is correct for every modern Windows client and server release.
Refresh policy and verify the result
After changing a GPO or its filter, trigger policy processing using a method listed in Microsoft’s processing guidance:
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
- Run
gpupdate.exeon a target computer. - Use the PowerShell
Invoke-GPUpdatecmdlet. - In GPMC, use the Group Policy Update action at an OU.
Test on representative computers before broad deployment. Check that the filter evaluates as intended on each relevant type of system and that the GPO applies only where expected.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why a GPO with a WMI filter is not applying
Check the layers in order: a correct WMI query cannot make a GPO apply if the GPO is not linked or otherwise in scope, and a link alone does not bypass security-filter permissions or a false WMI result.
Rank #4
- Confirm the GPO is linked to the correct site, domain, or OU and that the destination computer is in scope.
- Check security filtering and permissions to ensure the intended computer or user can apply the GPO.
- Inspect the GPO’s WMI Filtering selection and verify that the attached filter is the intended one.
- Evaluate the query against the destination computer’s actual WMI namespace, class, and property values. A false result excludes the GPO.
- Refresh policy and verify the result on the target computer before changing scope more broadly.
If the filter is unexpectedly broad, expensive, or difficult to maintain, revisit whether the condition belongs in security filtering or in item-level targeting for a preference. WMI filters have no timeout in Microsoft’s cited legacy guidance, making unnecessary query complexity a risk to consider.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.

