Go Premium for a chance to win a PS4. Enter to Win

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 37
  • Last Modified:

REG or GPO - Who wins if both set

A setting that can set by either a change via regedit or set via a group policy, than which setting will take priority ?

Am I right in thinking that settings via group policy just get written in the registry in a "special" location 'policies' ...

Example - The GPO might write key/values here
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate

Example - The historical place to change the settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate


I've had this question in my head for over 10 years - never got around to asking!

thanks
0
pc-cyt
Asked:
pc-cyt
2 Solutions
 
Scott SilvaNetwork AdministratorCommented:
AFAIK either can overwrite the other, but only GPO can "back itself out" after you rescind the policy...
0
 
Dustin SaundersDirector of OperationsCommented:
This article has an explanation that should answer your question.  Essentially, "GP" settings trump "preference" settings when applied.  "GP Preference" settings (registry changes made by GP) behave in a slightly different, hybrid way (there are some roll back and 'apply once' setting options).
0
 
Adam BrownSr Solutions ArchitectCommented:
Group Policies directly modify registry settings. That's all anything set by Administrative Templates in a GPO are...registry modifications. Group Policy will always over-write what you set by directly modifying the registry, so if you make a configuration change in the registry and then create a GPO that modifies the same registry key, the GPO will win.

The example you give is not how it works. Group Policy does not set things in a special section of the registry. It changes the registry to cause the OS to operate according to the description of the policy.

If you open up an ADMX file and read it, you'll see that it is literally just putting a more easily understood UI onto a boatload of registry tweaks. If you have permission to modify the registry, you can actually change the settings control by group policy by changing the registry key values, but they will revert to the group policy settings as soon as the Group Policy refreshes itself. Otherwise, group policy would be completely useless as a method of enforcing policies.
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
Dustin SaundersDirector of OperationsCommented:
I argue that my question adequately answered the question- both in writing and in the link shared for detailed information straight from Microsoft.  I recommend that we split the points 250/250.
0
 
Adam BrownSr Solutions ArchitectCommented:
Given that the link provided explains the difference between setting a Group Policy and a Group Policy Preference, it does not sufficiently answer the question. The question is regarding whether or not modifying the registry through regedit or similar means will over-ride settings deployed by group policy. Deploying the registry modifications through preferences is not part of the equation (given the statement that the question has been in his mind for 10 years or more, while preferences did not exist before server 2008).

My response addressed the apparent misunderstanding the requester had regarding how Group Policies are applied the the Registry. Specifically that Group Policy settings were stored in a different location in the registry than would be modified to achieve the same result in Regedit. This is not the case, since Group Policy settings directly modify the settings that would be modified in Regedit manually to change the setting. Attempting to modify the registry manually with a Group Policy in effect will not change the setting for very long, since it will be immediately changed back to the Group Policy setting's value as soon as Group Policy is refreshed.
0
 
Dustin SaundersDirector of OperationsCommented:
Again, I object and recommend the points be split.  My explanation includes GPOs vs applying registry settings via Preferences- which includes how the GP can apply once, or have rollback which is how it changes or doesn't change an update in regedit.  It is a sufficient explanation with a robust article to support it.

If we can't agree on that then the question will require another party to resolve.
0
 
Adam BrownSr Solutions ArchitectCommented:
Dustin, The question isn't about deploying registry settings via preferences...
A setting that can set by either a change via regedit or set via a group policy, than which setting will take priority ?

Group Policy settings (The Administrative Template branch, at least), at their core, are registry modifications. The question is whether setting the policy with an Administrative Template GPO will over-ride a modification through regedit. It has nothing to do with registry settings deployed by a GPO preference.

I'm trying to point out these facts so other people (and you) can learn from it. I don't care so much about the points as I care about the answer being completely accurate and useful for people in the future, when it inevitably comes up in a google search. Please, re-read the question entirely and explain how Group Policy Preferences enters into it if you still think your answer addresses the issue.
0
 
Dustin SaundersDirector of OperationsCommented:
I'm not going to argue this with you, we'll leave the question for a third party to close.
0
 
pc-cytAuthor Commented:
Adams answer makes the most sense of my question, but i did also learn from Dustins comments, although not really part of my original question.
0
 
Dustin SaundersDirector of OperationsCommented:
Asker is the ultimate judge, thanks for coming back to resolve the open question.
0

Featured Post

Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now