Solved

REG or GPO - Who wins if both set

Posted on 2016-08-02
13
30 Views
Last Modified: 2016-08-25
A setting that can set by either a change via regedit or set via a group policy, than which setting will take priority ?

Am I right in thinking that settings via group policy just get written in the registry in a "special" location 'policies' ...

Example - The GPO might write key/values here
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate

Example - The historical place to change the settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate


I've had this question in my head for over 10 years - never got around to asking!

thanks
0
Comment
Question by:pc-cyt
13 Comments
 
LVL 9

Expert Comment

by:Scott Silva
ID: 41739859
AFAIK either can overwrite the other, but only GPO can "back itself out" after you rescind the policy...
0
 
LVL 12

Assisted Solution

by:Dustin Saunders
Dustin Saunders earned 50 total points (awarded by participants)
ID: 41739881
This article has an explanation that should answer your question.  Essentially, "GP" settings trump "preference" settings when applied.  "GP Preference" settings (registry changes made by GP) behave in a slightly different, hybrid way (there are some roll back and 'apply once' setting options).
0
 
LVL 38

Accepted Solution

by:
Adam Brown earned 450 total points (awarded by participants)
ID: 41740027
Group Policies directly modify registry settings. That's all anything set by Administrative Templates in a GPO are...registry modifications. Group Policy will always over-write what you set by directly modifying the registry, so if you make a configuration change in the registry and then create a GPO that modifies the same registry key, the GPO will win.

The example you give is not how it works. Group Policy does not set things in a special section of the registry. It changes the registry to cause the OS to operate according to the description of the policy.

If you open up an ADMX file and read it, you'll see that it is literally just putting a more easily understood UI onto a boatload of registry tweaks. If you have permission to modify the registry, you can actually change the settings control by group policy by changing the registry key values, but they will revert to the group policy settings as soon as the Group Policy refreshes itself. Otherwise, group policy would be completely useless as a method of enforcing policies.
0
 
LVL 12

Expert Comment

by:Dustin Saunders
ID: 41759344
I argue that my question adequately answered the question- both in writing and in the link shared for detailed information straight from Microsoft.  I recommend that we split the points 250/250.
0
 
LVL 38

Expert Comment

by:Adam Brown
ID: 41759971
Given that the link provided explains the difference between setting a Group Policy and a Group Policy Preference, it does not sufficiently answer the question. The question is regarding whether or not modifying the registry through regedit or similar means will over-ride settings deployed by group policy. Deploying the registry modifications through preferences is not part of the equation (given the statement that the question has been in his mind for 10 years or more, while preferences did not exist before server 2008).

My response addressed the apparent misunderstanding the requester had regarding how Group Policies are applied the the Registry. Specifically that Group Policy settings were stored in a different location in the registry than would be modified to achieve the same result in Regedit. This is not the case, since Group Policy settings directly modify the settings that would be modified in Regedit manually to change the setting. Attempting to modify the registry manually with a Group Policy in effect will not change the setting for very long, since it will be immediately changed back to the Group Policy setting's value as soon as Group Policy is refreshed.
0
Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

 
LVL 12

Expert Comment

by:Dustin Saunders
ID: 41759997
Again, I object and recommend the points be split.  My explanation includes GPOs vs applying registry settings via Preferences- which includes how the GP can apply once, or have rollback which is how it changes or doesn't change an update in regedit.  It is a sufficient explanation with a robust article to support it.

If we can't agree on that then the question will require another party to resolve.
0
 
LVL 38

Expert Comment

by:Adam Brown
ID: 41760029
Dustin, The question isn't about deploying registry settings via preferences...
A setting that can set by either a change via regedit or set via a group policy, than which setting will take priority ?

Group Policy settings (The Administrative Template branch, at least), at their core, are registry modifications. The question is whether setting the policy with an Administrative Template GPO will over-ride a modification through regedit. It has nothing to do with registry settings deployed by a GPO preference.

I'm trying to point out these facts so other people (and you) can learn from it. I don't care so much about the points as I care about the answer being completely accurate and useful for people in the future, when it inevitably comes up in a google search. Please, re-read the question entirely and explain how Group Policy Preferences enters into it if you still think your answer addresses the issue.
0
 
LVL 12

Expert Comment

by:Dustin Saunders
ID: 41760066
I'm not going to argue this with you, we'll leave the question for a third party to close.
0
 
LVL 1

Author Closing Comment

by:pc-cyt
ID: 41770861
Adams answer makes the most sense of my question, but i did also learn from Dustins comments, although not really part of my original question.
0
 
LVL 12

Expert Comment

by:Dustin Saunders
ID: 41770879
Asker is the ultimate judge, thanks for coming back to resolve the open question.
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A safe way to clean winsxs folder from your windows server 2008 R2 editions
While working, an annoying popup showing below will come and we cannot cancel or close it form the screen. The error message will come again and again.
This Micro Tutorial will go in depth within Systems and Security in Windows 7 and will go into detail regarding Action Center, Windows Firewall, System, etc. This will be demonstrated using Windows 7 operating system.
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

914 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now