• RSS
  • Twitter
  • FaceBook

Group Policy Processing At Client Computers

This article explains how Group Policy processing happens at the client computers.

A client computer joined to domain gathers the list of GPOs to be processed as mentioned below:

  • Client computer starts.
  • Winlogon Service on the client computer starts. The DCLocator component executes an API call; DsGetDcName to find the domain controller. A DNS Query is send to configured DNS Server.
  • DNS Server receives the DNS Query and provides the list of domain controllers.
  • Winlogon selects one of the Domain Controller listed in the list and then authenticates the client computer.
  • Winlogon now processes the GPOs to be applies to the computer.
  • It checks the location of Computer Account in the Active Directory and then check the GPOs configured on the OU.
  • Winlogon checks the following permissions for the Computer Account.

Authenticated Users: Read and AGP

Note: Authenticated Users is added by default when you create a GPO and this Security Group has all authenticated domain users and computer accounts.

  • Winlogon next checks the gpcFilePath in the Active Directory to check the path of the SYSVOL share where this policy resides. A gpcFilePath looks like below:

\\DomainName.Com\SysVol\DomainName.Com\Policies\{GUID}

Note: If this attribute is missing or has an empty value then this Group Policy will not be processed for client computers.

  • After it has found the sysvol path, it then processes the Registry.POL file in the GUID folder. The Registry.POL file contains the Registry based settings you have defined in the Group Policy.
  • It processes the settings and activity is logged into the Winlogon.log file of client computer.

 

About Nirmal Sharma

Nirmal is a Microsoft MVP in Directory Services and working as a Technical Architect/Consultant. He has been involved in Microsoft Technologies since 1994 and followed the progression of Microsoft Operating Systems and software. He is specialized in Directory Services, Microsoft Clustering, SQL, MOM, Exchange and Citrix. In his spare time, he likes to help others and write "internal" technical articles, white papers and tips on various Microsoft technologies. You can contact him at nirmal_sharma@mvps.org.


Article not looking right or info is missing? Let us know so that we can fix it: .


Receive all the latest articles by email!

Receive Real-Time & Monthly WindowsNetworking.com article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become a WindowsNetworking.com member!

Discuss your network issues with thousands of other network administrators. Click here to join!

Community Area

Log in | Register

Readers' Choice

Which is your preferred data recovery solution?