The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Check the GroupPolicy moduleGet-Module -ListAvailable GroupPolicy | Select-Object Name, Version, PathView examples
List domain GPOsGet-GPO -All -Domain 'corp.example.com' -Server 'dc01.corp.example.com' | Sort-Object DisplayNameView examples
Resolve a GPO by GUIDGet-GPO -Guid '11111111-2222-3333-4444-555555555555' ` -Domain 'corp.example.com' -Server ` 'dc01.corp.example.com'View examples
Export a GPO reportGet-GPOReport -Guid $gpo.Id -ReportType Html -Path ` 'C:\Reports\Pilot-GPO.html' -Domain 'corp.example.com'View examples
Inspect OU inheritanceGet-GPInheritance -Target ` 'OU=Pilot,OU=Workstations,DC=corp,DC=example,DC=com' ` -Domain 'corp.example.com'View examples
Audit GPO permissionsGet-GPPermission -Guid $gpo.Id -All -Domain ` 'corp.example.com' -Server 'dc01.corp.example.com'View examples
Preview one GPO backupBackup-GPO -Guid $gpo.Id -Path 'C:\GPOBackups' -Domain ` 'corp.example.com' -Comment 'Before approved change' ` -WhatIfView examples
Preview all-GPO backupBackup-GPO -All -Path 'C:\GPOBackups' -Domain ` 'corp.example.com' -Server 'dc01.corp.example.com' ` -WhatIfView examples
Preview an unlinked GPONew-GPO -Name 'Pilot - Example Policy' -Comment ` 'CHG-12345; owner: Endpoint' -Domain ` 'corp.example.com' -WhatIfView examples
Read a registry policyGet-GPRegistryValue -Name 'Pilot - Example Policy' -Key ` 'HKLM\Software\Policies\Example' -ValueName 'Mode'View examples
Preview a registry policySet-GPRegistryValue -Name 'Pilot - Example Policy' -Key ` 'HKLM\Software\Policies\Example' -ValueName 'Mode' ` -Type DWord -Value 1 -WhatIfView examples
Preview removing a settingRemove-GPRegistryValue -Name 'Pilot - Example Policy' ` -Key 'HKLM\Software\Policies\Example' -ValueName ` 'Mode' -WhatIfView examples
Preview a disabled pilot linkNew-GPLink -Guid $gpo.Id -Target $pilotOu -LinkEnabled ` No -Domain 'corp.example.com' -WhatIfView examples
Preview enabling a linkSet-GPLink -Guid $gpo.Id -Target $pilotOu -LinkEnabled ` Yes -Enforced No -Domain 'corp.example.com' -WhatIfView examples
Preview unlinking a GPORemove-GPLink -Guid $gpo.Id -Target $pilotOu -Domain ` 'corp.example.com' -WhatIfView examples
Preview read delegationSet-GPPermission -Guid $gpo.Id -TargetName ` 'GG-GPO-Auditors' -TargetType Group -PermissionLevel ` GpoRead -WhatIfView examples
Collect computer RSoPGet-GPResultantSetOfPolicy -Computer ` 'pc042.corp.example.com' -ReportType Html -Path ` 'C:\Reports\PC042-RSoP.html'View examples
Generate local gpresultgpresult.exe /h 'C:\Reports\gpresult.html' /fView examples
Schedule a remote refreshInvoke-GPUpdate -Computer 'pc042.corp.example.com' ` -Target Computer -RandomDelayInMinutes 30 -AsJobView examples

A domain Group Policy change can affect thousands of users or computers after background refresh, sign-in, or restart. Work from a trusted Windows host with the Group Policy Management feature, bind commands to the intended domain and domain controller, capture reports and backups, create policy unlinked, test through a narrow pilot OU, and validate resultant policy before broadening scope. Treat GPO contents, links, link order, security filtering, WMI filters, inheritance, delegation, AD replication, and SYSVOL replication as separate parts of the deployment.

Step by step

Detailed examples

01

Confirm the management feature, domain, DC, and delegated authority

The GroupPolicy module is installed with Group Policy Management on Windows Server or the GPMC RSAT capability on supported Windows clients. The target domain needs AD DS and healthy DNS, DC, and SYSVOL access, but the management host does not need the AD DS server role. Feature installation and New-GPO require elevation under Microsoft's documented defaults; all mutations also need suitable GPO or container permissions. Creating GPOs is normally limited to Domain Admins, Enterprise Admins, and Group Policy Creator Owners, while linking needs modify permission on the site, domain, or OU. Validate the installed module in Windows PowerShell 5.1 unless your organization has qualified its Windows PowerShell compatibility behavior in PowerShell 7. State -Domain and -Server rather than inheriting an unexpected logon context.

Capture local tooling and domain context
$PSVersionTable | Select-Object PSEdition, PSVersion
Get-ComputerInfo | Select-Object WindowsProductName, WindowsVersion, OsBuildNumber
Get-Module -ListAvailable GroupPolicy | Select-Object Name, Version, Path
[System.Security.Principal.WindowsIdentity]::GetCurrent().Name
Get-CimInstance Win32_ComputerSystem | Select-Object Name, Domain, PartOfDomain
Get-GPO -All -Domain 'corp.example.com' -Server 'dc01.corp.example.com' |
  Select-Object -First 1 DomainName, Owner, Id
Back to quick reference ↑
02

Inventory by GUID and preserve a human-readable baseline

A GPO display name is operationally useful but is not guaranteed to be unique; the GUID is the stable identifier. Inventory status, versions, owner, timestamps, links, filters, and permissions before touching content. Get-GPOReport can emit HTML for review or XML for structured comparison, including settings, links, security filtering, WMI filtering, delegation, and both configuration halves. A report is evidence from the queried DC at that time, not proof that every DC, SYSVOL replica, or client has converged.

Resolve one GPO and create baseline reports
$domain = 'corp.example.com'
$server = 'dc01.corp.example.com'
$reportDir = 'C:\Reports\GPO'
$gpo = Get-GPO -Name 'Pilot - Example Policy' -Domain $domain -Server $server
$gpo | Select-Object DisplayName, Id, DomainName, Owner, GpoStatus, `
  CreationTime, ModificationTime, UserVersion, ComputerVersion
Get-GPOReport -Guid $gpo.Id -ReportType Html `
  -Path (Join-Path $reportDir 'Pilot-GPO.html') -Domain $domain -Server $server
Get-GPOReport -Guid $gpo.Id -ReportType Xml `
  -Path (Join-Path $reportDir 'Pilot-GPO.xml') -Domain $domain -Server $server

Note: Create and ACL the report directory first. Reports can expose security configuration and should be stored as sensitive administrative records.

Back to quick reference ↑
03

Back up before editing and distinguish restore from import

Backup-GPO captures one GPO or all GPOs to an existing directory and supports WhatIf, but a preview does not test free space, share permissions, integrity, or restoration. Protect backups because they can disclose security configuration. Restore-GPO restores a backed-up GPO to its original domain and identity; Import-GPO transfers backup settings into an existing destination GPO and can use a migration table for domain-specific principals and UNC paths. Backups do not replace AD/SYSVOL disaster recovery, do not capture link placement as a restorable part of the GPO, and must be tested before an incident.

Preview and document a single-GPO backup
$domain = 'corp.example.com'
$server = 'dc01.corp.example.com'
$backupPath = 'C:\GPOBackups'
$gpo = Get-GPO -Name 'Pilot - Example Policy' -Domain $domain -Server $server
Get-GPOReport -Guid $gpo.Id -ReportType Xml -Domain $domain -Server $server `
  -Path 'C:\Reports\Pilot-GPO-before.xml'
Backup-GPO -Guid $gpo.Id -Path $backupPath -Domain $domain -Server $server `
  -Comment 'CHG-12345 before approved change' -WhatIf

Note: After approval, remove WhatIf only when the existing destination is protected, writable, monitored, and covered by a tested restore procedure.

Back to quick reference ↑
04

Build policy unlinked and validate the exact client behavior

New-GPO creates an unlinked GPO by default, which provides a safe staging boundary. Configure policy through supported Administrative Templates, security settings, or Group Policy Preferences and document the supported OS editions. Set-GPRegistryValue manages registry-based policy values, not every policy extension. Removing a setting from a GPO with Remove-GPRegistryValue does not delete the existing client value; conversely, Set-GPRegistryValue -Disable can instruct clients to delete a value when policy applies. WhatIf previews the directory-side cmdlet operation, not the client-side consequences or compatibility of the underlying setting.

Preview an unlinked GPO and one illustrative setting
$domain = 'corp.example.com'
$name = 'Pilot - Example Policy'
New-GPO -Name $name -Comment 'CHG-12345; owner: Endpoint; pilot only' `
  -Domain $domain -Server 'dc01.corp.example.com' -WhatIf

# After the GPO is approved and actually created, resolve its GUID before editing.
$gpo = Get-GPO -Name $name -Domain $domain -Server 'dc01.corp.example.com'
$key = 'HKLM\Software\Policies\Example'
Get-GPRegistryValue -Guid $gpo.Id -Key $key -ValueName 'Mode' `
  -Domain $domain -ErrorAction SilentlyContinue
Set-GPRegistryValue -Guid $gpo.Id -Key $key -ValueName 'Mode' `
  -Type DWord -Value 1 -Domain $domain -WhatIf

Note: The Example registry path is deliberately non-production. Replace it only with a vendor-documented policy path and value supported by the exact client editions in scope.

Back to quick reference ↑
05

Treat links, precedence, enforcement, and inheritance as policy code

A GPO affects a site, domain, or OU through a link; it is not stored in the linked OU and can have multiple links. Inspect existing direct and inherited links before adding one. Lower link-order numbers have higher precedence at the same container, but processing also depends on LSDOU order, security and WMI filters, loopback, disabled configuration halves, enforcement, and inheritance blocking. Start with a disabled link to a narrow pilot OU, avoid Enforced and Block Inheritance unless the design explicitly requires them, and remember that removing a link is different from deleting the GPO.

Inspect scope and preview a disabled pilot link
$domain = 'corp.example.com'
$pilotOu = 'OU=Pilot,OU=Workstations,DC=corp,DC=example,DC=com'
$gpo = Get-GPO -Name 'Pilot - Example Policy' -Domain $domain `
  -Server 'dc01.corp.example.com'
$scope = Get-GPInheritance -Target $pilotOu -Domain $domain `
  -Server 'dc01.corp.example.com'
$scope | Select-Object Path, GpoInheritanceBlocked, GpoLinks, InheritedGpoLinks
New-GPLink -Guid $gpo.Id -Target $pilotOu -LinkEnabled No -Enforced No `
  -Domain $domain -Server 'dc01.corp.example.com' -WhatIf
Set-GPLink -Guid $gpo.Id -Target $pilotOu -LinkEnabled Yes -Enforced No `
  -Domain $domain -Server 'dc01.corp.example.com' -WhatIf
Back to quick reference ↑
06

Separate editing rights from policy application

GPO delegation controls who can read, edit, delete, or modify security, while security filtering determines which authenticated principals can apply policy. Those are distinct decisions. Preserve the read permissions needed for policy processing, use purpose-specific groups, and avoid replacing ACLs without a full before-state export. WMI filters add client-side evaluation and can create performance or availability risks. Set-GPPermission supports WhatIf, but it cannot predict nested-group expansion, deny ACE behavior, token freshness, cross-domain trust effects, or whether clients can read SYSVOL.

Audit delegation and preview a narrow read grant
$domain = 'corp.example.com'
$server = 'dc01.corp.example.com'
$gpo = Get-GPO -Name 'Pilot - Example Policy' -Domain $domain -Server $server
Get-GPPermission -Guid $gpo.Id -All -Domain $domain -Server $server |
  Select-Object Trustee, TrusteeType, Permission, Inherited
Set-GPPermission -Guid $gpo.Id -TargetName 'GG-GPO-Auditors' `
  -TargetType Group -PermissionLevel GpoRead -Domain $domain -Server $server -WhatIf

Note: Application filtering needs an explicit design review; GpoRead alone does not grant Apply Group Policy.

Back to quick reference ↑
07

Validate resultant policy instead of inferring it from links

A GPO report describes the object; RSoP describes processed policy for a user, computer, or both. Get-GPResultantSetOfPolicy provides logging-mode results and writes HTML or XML; use GPMC Group Policy Modeling for simulation. Remote collection depends on connectivity, firewall, WMI, permissions, and the target's available logging data. Compare expected settings on representative supported editions, verify both user and computer contexts when relevant, and inspect denied GPO reasons rather than assuming link presence means application.

Collect a pilot computer RSoP report
$computer = 'pc042.corp.example.com'
Test-Connection -ComputerName $computer -Count 2
Get-GPResultantSetOfPolicy -Computer $computer -ReportType Html `
  -Path 'C:\Reports\PC042-RSoP.html'
# On the target, an elevated local diagnostic can also write:
# gpresult.exe /h 'C:\Reports\gpresult.html' /f
Back to quick reference ↑
08

Roll out gradually and schedule refresh as a separate change

Group Policy normally refreshes on its own schedule, and some client-side extensions apply only during foreground startup or sign-in. Invoke-GPUpdate creates a scheduled remote refresh and has no WhatIf parameter. It requires the Remote Scheduled Tasks Management RPC/RPC-EPMAP and WMI-In firewall rules on targets plus appropriate remote rights. -Boot and -LogOff can restart a computer or terminate a user's session, so never add them to bulk automation without explicit maintenance approval. A standard background refresh usually needs no reboot, but the configured policy or extension can still require one. Use randomized delay, pilot batches, service monitoring, and fresh RSoP evidence.

Review a pilot, then schedule a controlled refresh
$computer = 'pc042.corp.example.com'
Resolve-DnsName -Name $computer -Type A
Test-Connection -ComputerName $computer -Count 2

# No WhatIf is available. Run only after approval and user or workload coordination:
# Invoke-GPUpdate -Computer $computer -Target Computer `
#   -RandomDelayInMinutes 30 -AsJob

# After the refresh window, collect new evidence:
# Get-GPResultantSetOfPolicy -Computer $computer -ReportType Html `
#   -Path 'C:\Reports\PC042-RSoP-after.html'

Note: Do not add -Boot, -LogOff, or -Force casually. WhatIf on earlier GPO-editing cmdlets cannot preview this scheduled client action, AD/SYSVOL replication, extension behavior, application impact, or a rollback.

Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. MicrosoftGroup Policy Management Consolelearn.microsoft.com
  2. MicrosoftGroup Policy overview for Windows Serverlearn.microsoft.com
  3. MicrosoftGroupPolicy Modulelearn.microsoft.com
  4. MicrosoftGet-GPOReportlearn.microsoft.com
  5. MicrosoftNew-GPLinklearn.microsoft.com
  6. MicrosoftSet-GPRegistryValuelearn.microsoft.com
  7. MicrosoftGet-GPResultantSetOfPolicylearn.microsoft.com
  8. MicrosoftInvoke-GPUpdatelearn.microsoft.com
  9. MicrosoftBack up, restore, migrate, and copy Group Policy Objectslearn.microsoft.com

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback