Using GPResult Tool to Check What GPOs are Applied

GPResult.exe is a console administrative software designed to analyze and diagnose group coverage settings that are utilized to a pc and/or consumer within the Active Directory area. In specific, GPResult permits you to get the RSOP (Resultant Set of Policy) information, the record of utilized area insurance policies (GPO), their settings and detailed details about errors throughout GPO processing . This software is part of Windows OS since Windows XP. The GPResult software permits you to reply such a questions: does a specific coverage apply to a pc, which GPO has modified a specific Windows setting and to troubleshoot .

In this text we have a look at the specifics of utilizing the GPResult command to diagnose efficiency and debug Group Policies within the Active Directory area.

In earlier Windows variations, the RSOP.msc graphical console was used to diagnose the appliance of group insurance policies on a shopper aspect, which allowed you to get the ensuing coverage settings (area + native) utilized to the pc and consumer in a graphical type related to the GPO editor console. The RSOP.msc console on the screenshot under exhibits that the Windows replace settings are set by the .

However, the RSOP.msc console in trendy Windows variations is impractical to use, as a result of it doesn’t present the settings utilized by varied group-policy extensions (client-side extensions – CSE), akin to GPP (Group Policy Preferences), doesn’t permit to search amongst settings, offers not a whole lot of diagnostic info (in Windows 10 even a warning seems that RSOP doesn’t give a full report, not like GPResult). Therefore, the GPResult command immediately is the first software to carry out GPO diagnostic in Windows.

How to Use the Group Policy Results (GPResult.exe) Tool

The GPResult command should be run on the pc on which you need to examine the appliance of group insurance policies. The GPResult command has the next syntax:

GPRESULT [/S system [/U username [/P [password]]]] [/SCOPE scope] [/USER targetusername] [/R | /V | /Z] [(/X | /H) [/F]]

To get an in depth details about the group insurance policies, utilized to a consumer or a pc, in addition to different parameters associated to the GPO infrastructure (the ensuing GPO coverage settings – RsoP), run this command:

The outcomes of this command are subdivided into two sections:

  • COMPUTER SETTINGS – the part comprises the knowledge on the GP objects utilized to the pc (as an Active Directory object);
  • USER SETTINGS – it is a consumer coverage part (the insurance policies utilized to the account of the AD consumer).

Let’s briefly cowl the essential settings/sections within the GPResult output that may be of curiosity for us:

  • Site Name – is the identify of the AD web site the place the pc is positioned;
  • CN – full canonical consumer / pc identify for which RSoP information was generated;
  • Last time Group Policy was utilized – is the time when the group insurance policies had been final utilized;
  • Group Policy was utilized from – is the area controller identify the final GPO model has been downloaded from;
  • Domain Name and Domain Type – is the identify and the model variety of the Active Directory area schema;
  • Applied Group Policy Objects – are the lists of utilized Group Policy objects;
  • The following GPOs weren’t utilized as a result of they had been filtered out – are GPOs which have  not been utilized or have been filtered out;
  • The consumer is part of the next safety teams – are the area teams the consumer is a member of.

In this instance, you may see that four group insurance policies are utilized to the consumer object.

If you don’t need to concurrently show details about consumer and pc insurance policies, you need to use the  /scope possibility to show solely the part you want. Only ensuing consumer’s coverage:

or solely utilized pc insurance policies:

gpresult /r /scope:pc

Since Gpresult software shows its information instantly to the command line, which isn’t at all times handy for additional evaluation, the output might be redirected to the clipboard:

or a textual content file:

Gpresult /r > c:psgpresult.txt

To show tremendous detailed RSOP info, you want to add the /z key.

RSoP HTML Report Using GPResult

GPResult can even generate an HTML report on the utilized resultant insurance policies (out there in Windows 7 and better). This report comprises the detailed info on all system settings that are set by the Group Policies and the names of the sure GPOs which have set them (in its construction, this report resembles the Settings tab within the Group Policy Management Console – gpmc.msc). You can generate the GPResult HTML report utilizing the command:

GPResult /h c:PSgpo-report.html /f

To generate the report and routinely open it in a browser, run the next command:

GPResult /h GPResult.html & GPResult.html

The gpresult HTML report comprises numerous helpful info: you may see GPOs applyingerrors , processing time (in ms) for a particular insurance policies and CSEs (within the Computer Details -> Component Status part). For instance, within the screenshot above you may see that the Enforce password historical past coverage with the settings “24 passwords remembered” is utilized by the Default Domain Policy (Winning GPO column). As you may see, this gpresult HTML report is way more handy for analyzing the utilized insurance policies than the rsop.msc.

How to Run GPResult on a Remote Computer?

GPResult can gather information from a distant pc as nicely without having to log regionally or through the RDP on to the distant system. The command to gather RSOP from a distant pc is seems to be like this:

GPResult /s distant-laptop-name1 /r

Similarly, you may remotely gather information on each consumer and pc insurance policies.

The User Does Not Have RSoP Data

When the UAC is enabled and GPResult is utilized in non-elevated mode, solely the consumer settings part of the group insurance policies are proven. If you want each sections (USER SETTINGS and COMPUTER SETTINGS) to be displayed, the command should be working within the command immediate with the administrator privileges. If a command immediate with elevated privileges is that’s totally different from the present consumer, the software will present the warning: INFO: The consumer “domainuser” doesn’t have RSOP information. It occurs since GPResult tries to gather the information of the consumer that has began it, however as a result of this consumer has not logged in, there is no such thing as a RSOP info for him. To gather RSOP info from a consumer with an energetic session, you want to specify his account:

gpresult /r /consumer:saedward

If you don’t know the identify of an account that’s logged on to a distant pc, you will get a username like this:

qwinsta /SERVER:remotePC1

Also examine the time (and ) on the shopper. The time should match the time on the PDC (Primary Domain Controller).

The following GPOs weren’t utilized as a result of they had been filtered out

When troubleshooting the group insurance policies, it’s value to concentrate to the part: The following GPOs weren’t utilized as a result of they had been filtered out. It comprises the record of the GPOs that are not utilized to this object by any motive. Here are some explanation why the insurance policies are not utilized:

So, on this article we now have thought of the peculiarities of the diagnostics the appliance of group insurance policies utilizing GPResult software and coated primary situations of utilizing it.

Check Also

Configuring L2TP/IPSec VPN Connection Behind a NAT, VPN Error Code 809

Due to disabling PPTP VPN help in iOS, one in all my shoppers determined to …

Leave a Reply

Your email address will not be published. Required fields are marked *