Force GP Update from Server to all clients

Posted on 2006-10-19
1 Endorsement
Last Modified: 2012-06-22
How can I from the server push Group Policy updates right away on all client machines?
Question by:LeviDaily
LVL 26

Accepted Solution

DireOrbAnt earned 250 total points
ID: 17771430
As far as I know, there is no ways to do that from the DC (server) side.
Gpupdate on 2003 and secedit in 2000 can force it from the client-side.

Author Comment

ID: 17771749
So the only way clients can update is by restarting the computer twice right? Where is the time interval for how often group policy updates clients?
LVL 10

Expert Comment

ID: 17771843
Active Directory Webinar

We all know we need to protect and secure our privileges, but where to start? Join Experts Exchange and ManageEngine on Tuesday, April 11, 2017 10:00 AM PDT to learn how to track and secure privileged users in Active Directory.


Expert Comment

ID: 17772207
If you want to update a client, as DireOrbAnt says, then you just go to the command prompt on a client and type in gpupdate /force (for Windows XP) or use Secedit if its a Windows 2000 machine. To see if the policy has updated type gpresult. This will show you all the policies being applied to the computer. Note that for some policy changes to take effect the client pc will have to be restarted.


Expert Comment

ID: 17772378
I agree with previous comments that GPO refresh can only be forced manually from the Client side.

By default GPOs for computers are refreshed every 90 minutes, with random offset of 0-30 minutes. So in theory default seetings should see the GPO refreshed at most 2 hours after it is saved on the DC (assuming client machines are running).

You can set the refresh interval in the GPO itself:
Computer Configuration\Adminstrative Templates\System\Gorup Policy
Group Policy refresh interval for Computers

Be careful with setting this interval too short in case it increases network traffic and slows down PCs etc.

Assisted Solution

Krompton earned 250 total points
ID: 17773040 provides a free tool called PSEXEC.exe that can be run from the server and would allow you to execute the "gpupdate /force" command (or any other command) to be executed on one or more remote clients. Very useful tool as are many others from sysinternals. (It will occasionally flag your virus software since it could be used for less than legit purposes if someone wanted.)

Before you do this consider the effects on your network of having all your clients updating policy at once. Depending on the number of policies and clients you have can cause serious bandwidth issues at minimum. That is why the there is a default refresh and offset rate as richencoo mentioned.

But if you really need it refreshed NOW this tool will accomplish for you.


Expert Comment

ID: 17774416
Depending if the GPO affects the Computer Configuration of the User Configuration you will have to restart or just logoff.


Expert Comment

ID: 17774876
I am assume that you are running the windows 2003 server and need assistance to know more about the GPO replication.

Once you create a GPO on the server you can expect it to be automatically updated to all the servers. If you want to perform the force replication there are a few steps you can perform if the replication is within the site then try repadmin/syncall & repadmin/kcc.

If its across the site then you can open the replmon and force to all DC's across the site.

You can go through the weblink. 

Best of luck :)

Expert Comment

ID: 17775055
In general AD works by the clients requesting a configuration from the server, not the other way around.  You cannot force the client to do anything until it checks in to get its Group Policy updates.  By default the GP background refresh will run on all computers, so as of now your new policy is probably on your workstations.  Some policies do not take effect until reboot/logon, so you may just need write batch script to reboot all the computers tonight.

Author Comment

ID: 17777706
How would I write a batch script to restart all computers tonight?

Expert Comment

ID: 17777819
The easist way is to do a brute force batch, not a true script.  The command is very easy:
shutdown -r -f -t 180 -m computername

You can use Excel to copy/paste the first part of that command (everything but the computer name) into column A and a list of your computers into column B.  Then do save as and choose Text (Tab delimited) and name the file whatever.bat.

If you need a list of computers you could type
dsquery computer domainroot -o samid -limit 1000 > c:\computers.txt
and open that file with Excel (do a find/replace to remove all $).  Make sure you remove any servers you don’t want restarted and whatever workstation/server will be running the script.

The batch file needs to be run on a computer logged in with Domain Admin rights, and make sure the script doesn’t try to restart the computer it is running on :-)

This batch file will take a long time to run because when it hits a computer which is not on the network it will have to wait and time-out.  Like I said, this isn’t a real script, it is more a down and dirty mass spaming batch file.  You could come up with a more sophisticated VBS script, but its Friday, that’s too much to ask.

Expert Comment

ID: 17777837
Edit:   If you add the word start before each shutdown command it will allow each line to start before the pervious finishes.  This will allow the script to run more quickly and will create a nice show of flashing command prompt windows as it runs.

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Occasionally Windows/Microsoft Updates will fail to update. We have found a code that will delete all temporary files and re-register all dll's related to Windows/Microsoft Updates! This works 99% of the time to get the updates working again! The…
Many people tend to confuse the function of a virus with the one of adware, this misunderstanding of the basic of what each software is and how it operates causes users and organizations to take the wrong security measures that would protect them ag…
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…
Hi friends,  in this video  I'll show you how new windows 10 user can learn the using of windows 10. Thank you.

827 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question