Enforcing Group Policy

  • Section(s): Security , Security
  • Published on Feb 14, 2006.
  • Last Modified on Feb 14, 2006.
  • Last Modified by Mitch Tulloch.
  • Rated 3.4 out of 5 based on 7 votes.
How to force Group Policy to apply even when users can override settings using local admin credentials.

Users who have local admin accounts on workstations can edit the registry and thereby undo many Group Policy settings that may have been applied to their computers. Best practice then would be to not give users local admin privileges on their workstations, but sometimes this is not practical. For example, some third-party line of business software will only install and run properly under admin creds.

So what can a sysadmin do to prevent such users from overriding Group Policy? One thing you can do is to go to the following node in your Group Policy Object:

Computer Configuration \ Administrative Templates \ System \ Group Policy

Then look for any policies that end in "...policy processing" and open these policies and select the checkbox that says "Process even if the Group Policy objects have not changed". This will *force* these policies to *always* be applied whether or not any settings in the GPO have actually changed or not. That way, for example, if a user edits their registry to change a wireless setting, the next time Group Policy is refreshed in the background any change they made will be undone.

About Mitch Tulloch

Mitch Tulloch was lead author for the Windows Vista Resource Kit from Microsoft Press, which is the book for IT pros who want to deploy, maintain and support Windows Vista in mid- and large-sized network environments. Mitch was also the author of Introducing Windows Server 2008 and technical project lead for the Microsoft Office Communications Server 2007 Resource Kit, both books also from Microsoft Press. For more information on these and other books by Mitch, see www.mtit.com .

Share this article


Article not looking right or info is missing? Let us know so that we can fix it: .


Receive all the latest articles by email!

Receive Real-Time & Monthly WindowsNetworking.com article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become a WindowsNetworking.com member!

Discuss your network issues with thousands of other network administrators. Click here to join!

Community Area

Log in | Register

Limited time offer!

SolarWinds screenshot

Subscribe to WindowsNetworking.com Newsletters today and get a free copy of the new SolarWinds Exchange Monitor!

Readers' Choice

Which is your preferred software-based Backup solution?