The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| Check the GroupPolicy module | Get-Module -ListAvailable GroupPolicy |
Select-Object Name, Version, Path | View examples |
| List domain GPOs | Get-GPO -All -Domain 'corp.example.com' -Server 'dc01.corp.example.com' |
Sort-Object DisplayName | View examples |
| Resolve a GPO by GUID | Get-GPO -Guid '11111111-2222-3333-4444-555555555555' `
-Domain 'corp.example.com' -Server `
'dc01.corp.example.com' | View examples |
| Export a GPO report | Get-GPOReport -Guid $gpo.Id -ReportType Html -Path `
'C:\Reports\Pilot-GPO.html' -Domain 'corp.example.com' | View examples |
| Inspect OU inheritance | Get-GPInheritance -Target `
'OU=Pilot,OU=Workstations,DC=corp,DC=example,DC=com' `
-Domain 'corp.example.com' | View examples |
| Audit GPO permissions | Get-GPPermission -Guid $gpo.Id -All -Domain `
'corp.example.com' -Server 'dc01.corp.example.com' | View examples |
| Preview one GPO backup | Backup-GPO -Guid $gpo.Id -Path 'C:\GPOBackups' -Domain `
'corp.example.com' -Comment 'Before approved change' `
-WhatIf | View examples |
| Preview all-GPO backup | Backup-GPO -All -Path 'C:\GPOBackups' -Domain `
'corp.example.com' -Server 'dc01.corp.example.com' `
-WhatIf | View examples |
| Preview an unlinked GPO | New-GPO -Name 'Pilot - Example Policy' -Comment `
'CHG-12345; owner: Endpoint' -Domain `
'corp.example.com' -WhatIf | View examples |
| Read a registry policy | Get-GPRegistryValue -Name 'Pilot - Example Policy' -Key `
'HKLM\Software\Policies\Example' -ValueName 'Mode' | View examples |
| Preview a registry policy | Set-GPRegistryValue -Name 'Pilot - Example Policy' -Key `
'HKLM\Software\Policies\Example' -ValueName 'Mode' `
-Type DWord -Value 1 -WhatIf | View examples |
| Preview removing a setting | Remove-GPRegistryValue -Name 'Pilot - Example Policy' `
-Key 'HKLM\Software\Policies\Example' -ValueName `
'Mode' -WhatIf | View examples |
| Preview a disabled pilot link | New-GPLink -Guid $gpo.Id -Target $pilotOu -LinkEnabled `
No -Domain 'corp.example.com' -WhatIf | View examples |
| Preview enabling a link | Set-GPLink -Guid $gpo.Id -Target $pilotOu -LinkEnabled `
Yes -Enforced No -Domain 'corp.example.com' -WhatIf | View examples |
| Preview unlinking a GPO | Remove-GPLink -Guid $gpo.Id -Target $pilotOu -Domain `
'corp.example.com' -WhatIf | View examples |
| Preview read delegation | Set-GPPermission -Guid $gpo.Id -TargetName `
'GG-GPO-Auditors' -TargetType Group -PermissionLevel `
GpoRead -WhatIf | View examples |
| Collect computer RSoP | Get-GPResultantSetOfPolicy -Computer `
'pc042.corp.example.com' -ReportType Html -Path `
'C:\Reports\PC042-RSoP.html' | View examples |
| Generate local gpresult | gpresult.exe /h 'C:\Reports\gpresult.html' /f | View examples |
| Schedule a remote refresh | Invoke-GPUpdate -Computer 'pc042.corp.example.com' `
-Target Computer -RandomDelayInMinutes 30 -AsJob | View examples |
A domain Group Policy change can affect thousands of users or computers after background refresh, sign-in, or restart. Work from a trusted Windows host with the Group Policy Management feature, bind commands to the intended domain and domain controller, capture reports and backups, create policy unlinked, test through a narrow pilot OU, and validate resultant policy before broadening scope. Treat GPO contents, links, link order, security filtering, WMI filters, inheritance, delegation, AD replication, and SYSVOL replication as separate parts of the deployment.
Step by step
Detailed examples
Confirm the management feature, domain, DC, and delegated authority
The GroupPolicy module is installed with Group Policy Management on Windows Server or the GPMC RSAT capability on supported Windows clients. The target domain needs AD DS and healthy DNS, DC, and SYSVOL access, but the management host does not need the AD DS server role. Feature installation and New-GPO require elevation under Microsoft's documented defaults; all mutations also need suitable GPO or container permissions. Creating GPOs is normally limited to Domain Admins, Enterprise Admins, and Group Policy Creator Owners, while linking needs modify permission on the site, domain, or OU. Validate the installed module in Windows PowerShell 5.1 unless your organization has qualified its Windows PowerShell compatibility behavior in PowerShell 7. State -Domain and -Server rather than inheriting an unexpected logon context.
$PSVersionTable | Select-Object PSEdition, PSVersion
Get-ComputerInfo | Select-Object WindowsProductName, WindowsVersion, OsBuildNumber
Get-Module -ListAvailable GroupPolicy | Select-Object Name, Version, Path
[System.Security.Principal.WindowsIdentity]::GetCurrent().Name
Get-CimInstance Win32_ComputerSystem | Select-Object Name, Domain, PartOfDomain
Get-GPO -All -Domain 'corp.example.com' -Server 'dc01.corp.example.com' |
Select-Object -First 1 DomainName, Owner, Id Inventory by GUID and preserve a human-readable baseline
A GPO display name is operationally useful but is not guaranteed to be unique; the GUID is the stable identifier. Inventory status, versions, owner, timestamps, links, filters, and permissions before touching content. Get-GPOReport can emit HTML for review or XML for structured comparison, including settings, links, security filtering, WMI filtering, delegation, and both configuration halves. A report is evidence from the queried DC at that time, not proof that every DC, SYSVOL replica, or client has converged.
$domain = 'corp.example.com'
$server = 'dc01.corp.example.com'
$reportDir = 'C:\Reports\GPO'
$gpo = Get-GPO -Name 'Pilot - Example Policy' -Domain $domain -Server $server
$gpo | Select-Object DisplayName, Id, DomainName, Owner, GpoStatus, `
CreationTime, ModificationTime, UserVersion, ComputerVersion
Get-GPOReport -Guid $gpo.Id -ReportType Html `
-Path (Join-Path $reportDir 'Pilot-GPO.html') -Domain $domain -Server $server
Get-GPOReport -Guid $gpo.Id -ReportType Xml `
-Path (Join-Path $reportDir 'Pilot-GPO.xml') -Domain $domain -Server $server Note: Create and ACL the report directory first. Reports can expose security configuration and should be stored as sensitive administrative records.
Back up before editing and distinguish restore from import
Backup-GPO captures one GPO or all GPOs to an existing directory and supports WhatIf, but a preview does not test free space, share permissions, integrity, or restoration. Protect backups because they can disclose security configuration. Restore-GPO restores a backed-up GPO to its original domain and identity; Import-GPO transfers backup settings into an existing destination GPO and can use a migration table for domain-specific principals and UNC paths. Backups do not replace AD/SYSVOL disaster recovery, do not capture link placement as a restorable part of the GPO, and must be tested before an incident.
$domain = 'corp.example.com'
$server = 'dc01.corp.example.com'
$backupPath = 'C:\GPOBackups'
$gpo = Get-GPO -Name 'Pilot - Example Policy' -Domain $domain -Server $server
Get-GPOReport -Guid $gpo.Id -ReportType Xml -Domain $domain -Server $server `
-Path 'C:\Reports\Pilot-GPO-before.xml'
Backup-GPO -Guid $gpo.Id -Path $backupPath -Domain $domain -Server $server `
-Comment 'CHG-12345 before approved change' -WhatIf Note: After approval, remove WhatIf only when the existing destination is protected, writable, monitored, and covered by a tested restore procedure.
Build policy unlinked and validate the exact client behavior
New-GPO creates an unlinked GPO by default, which provides a safe staging boundary. Configure policy through supported Administrative Templates, security settings, or Group Policy Preferences and document the supported OS editions. Set-GPRegistryValue manages registry-based policy values, not every policy extension. Removing a setting from a GPO with Remove-GPRegistryValue does not delete the existing client value; conversely, Set-GPRegistryValue -Disable can instruct clients to delete a value when policy applies. WhatIf previews the directory-side cmdlet operation, not the client-side consequences or compatibility of the underlying setting.
$domain = 'corp.example.com'
$name = 'Pilot - Example Policy'
New-GPO -Name $name -Comment 'CHG-12345; owner: Endpoint; pilot only' `
-Domain $domain -Server 'dc01.corp.example.com' -WhatIf
# After the GPO is approved and actually created, resolve its GUID before editing.
$gpo = Get-GPO -Name $name -Domain $domain -Server 'dc01.corp.example.com'
$key = 'HKLM\Software\Policies\Example'
Get-GPRegistryValue -Guid $gpo.Id -Key $key -ValueName 'Mode' `
-Domain $domain -ErrorAction SilentlyContinue
Set-GPRegistryValue -Guid $gpo.Id -Key $key -ValueName 'Mode' `
-Type DWord -Value 1 -Domain $domain -WhatIf Note: The Example registry path is deliberately non-production. Replace it only with a vendor-documented policy path and value supported by the exact client editions in scope.
Treat links, precedence, enforcement, and inheritance as policy code
A GPO affects a site, domain, or OU through a link; it is not stored in the linked OU and can have multiple links. Inspect existing direct and inherited links before adding one. Lower link-order numbers have higher precedence at the same container, but processing also depends on LSDOU order, security and WMI filters, loopback, disabled configuration halves, enforcement, and inheritance blocking. Start with a disabled link to a narrow pilot OU, avoid Enforced and Block Inheritance unless the design explicitly requires them, and remember that removing a link is different from deleting the GPO.
$domain = 'corp.example.com'
$pilotOu = 'OU=Pilot,OU=Workstations,DC=corp,DC=example,DC=com'
$gpo = Get-GPO -Name 'Pilot - Example Policy' -Domain $domain `
-Server 'dc01.corp.example.com'
$scope = Get-GPInheritance -Target $pilotOu -Domain $domain `
-Server 'dc01.corp.example.com'
$scope | Select-Object Path, GpoInheritanceBlocked, GpoLinks, InheritedGpoLinks
New-GPLink -Guid $gpo.Id -Target $pilotOu -LinkEnabled No -Enforced No `
-Domain $domain -Server 'dc01.corp.example.com' -WhatIf
Set-GPLink -Guid $gpo.Id -Target $pilotOu -LinkEnabled Yes -Enforced No `
-Domain $domain -Server 'dc01.corp.example.com' -WhatIf Separate editing rights from policy application
GPO delegation controls who can read, edit, delete, or modify security, while security filtering determines which authenticated principals can apply policy. Those are distinct decisions. Preserve the read permissions needed for policy processing, use purpose-specific groups, and avoid replacing ACLs without a full before-state export. WMI filters add client-side evaluation and can create performance or availability risks. Set-GPPermission supports WhatIf, but it cannot predict nested-group expansion, deny ACE behavior, token freshness, cross-domain trust effects, or whether clients can read SYSVOL.
$domain = 'corp.example.com'
$server = 'dc01.corp.example.com'
$gpo = Get-GPO -Name 'Pilot - Example Policy' -Domain $domain -Server $server
Get-GPPermission -Guid $gpo.Id -All -Domain $domain -Server $server |
Select-Object Trustee, TrusteeType, Permission, Inherited
Set-GPPermission -Guid $gpo.Id -TargetName 'GG-GPO-Auditors' `
-TargetType Group -PermissionLevel GpoRead -Domain $domain -Server $server -WhatIf Note: Application filtering needs an explicit design review; GpoRead alone does not grant Apply Group Policy.
Validate resultant policy instead of inferring it from links
A GPO report describes the object; RSoP describes processed policy for a user, computer, or both. Get-GPResultantSetOfPolicy provides logging-mode results and writes HTML or XML; use GPMC Group Policy Modeling for simulation. Remote collection depends on connectivity, firewall, WMI, permissions, and the target's available logging data. Compare expected settings on representative supported editions, verify both user and computer contexts when relevant, and inspect denied GPO reasons rather than assuming link presence means application.
$computer = 'pc042.corp.example.com'
Test-Connection -ComputerName $computer -Count 2
Get-GPResultantSetOfPolicy -Computer $computer -ReportType Html `
-Path 'C:\Reports\PC042-RSoP.html'
# On the target, an elevated local diagnostic can also write:
# gpresult.exe /h 'C:\Reports\gpresult.html' /f Roll out gradually and schedule refresh as a separate change
Group Policy normally refreshes on its own schedule, and some client-side extensions apply only during foreground startup or sign-in. Invoke-GPUpdate creates a scheduled remote refresh and has no WhatIf parameter. It requires the Remote Scheduled Tasks Management RPC/RPC-EPMAP and WMI-In firewall rules on targets plus appropriate remote rights. -Boot and -LogOff can restart a computer or terminate a user's session, so never add them to bulk automation without explicit maintenance approval. A standard background refresh usually needs no reboot, but the configured policy or extension can still require one. Use randomized delay, pilot batches, service monitoring, and fresh RSoP evidence.
$computer = 'pc042.corp.example.com'
Resolve-DnsName -Name $computer -Type A
Test-Connection -ComputerName $computer -Count 2
# No WhatIf is available. Run only after approval and user or workload coordination:
# Invoke-GPUpdate -Computer $computer -Target Computer `
# -RandomDelayInMinutes 30 -AsJob
# After the refresh window, collect new evidence:
# Get-GPResultantSetOfPolicy -Computer $computer -ReportType Html `
# -Path 'C:\Reports\PC042-RSoP-after.html' Note: Do not add -Boot, -LogOff, or -Force casually. WhatIf on earlier GPO-editing cmdlets cannot preview this scheduled client action, AD/SYSVOL replication, extension behavior, application impact, or a rollback.
Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
- MicrosoftGroup Policy Management Consolelearn.microsoft.com
- MicrosoftGroup Policy overview for Windows Serverlearn.microsoft.com
- MicrosoftGroupPolicy Modulelearn.microsoft.com
- MicrosoftGet-GPOReportlearn.microsoft.com
- MicrosoftNew-GPLinklearn.microsoft.com
- MicrosoftSet-GPRegistryValuelearn.microsoft.com
- MicrosoftGet-GPResultantSetOfPolicylearn.microsoft.com
- MicrosoftInvoke-GPUpdatelearn.microsoft.com
- MicrosoftBack up, restore, migrate, and copy Group Policy Objectslearn.microsoft.com
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



