Solved

REG or GPO - Who wins if both set

Posted on 2016-08-02
13
31 Views
Last Modified: 2016-08-25
A setting that can set by either a change via regedit or set via a group policy, than which setting will take priority ?

Am I right in thinking that settings via group policy just get written in the registry in a "special" location 'policies' ...

Example - The GPO might write key/values here
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate

Example - The historical place to change the settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate


I've had this question in my head for over 10 years - never got around to asking!

thanks
0
Comment
Question by:pc-cyt
13 Comments
 
LVL 10

Expert Comment

by:Scott Silva
ID: 41739859
AFAIK either can overwrite the other, but only GPO can "back itself out" after you rescind the policy...
0
 
LVL 12

Assisted Solution

by:Dustin Saunders
Dustin Saunders earned 50 total points (awarded by participants)
ID: 41739881
This article has an explanation that should answer your question.  Essentially, "GP" settings trump "preference" settings when applied.  "GP Preference" settings (registry changes made by GP) behave in a slightly different, hybrid way (there are some roll back and 'apply once' setting options).
0
 
LVL 39

Accepted Solution

by:
Adam Brown earned 450 total points (awarded by participants)
ID: 41740027
Group Policies directly modify registry settings. That's all anything set by Administrative Templates in a GPO are...registry modifications. Group Policy will always over-write what you set by directly modifying the registry, so if you make a configuration change in the registry and then create a GPO that modifies the same registry key, the GPO will win.

The example you give is not how it works. Group Policy does not set things in a special section of the registry. It changes the registry to cause the OS to operate according to the description of the policy.

If you open up an ADMX file and read it, you'll see that it is literally just putting a more easily understood UI onto a boatload of registry tweaks. If you have permission to modify the registry, you can actually change the settings control by group policy by changing the registry key values, but they will revert to the group policy settings as soon as the Group Policy refreshes itself. Otherwise, group policy would be completely useless as a method of enforcing policies.
0
NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

 
LVL 12

Expert Comment

by:Dustin Saunders
ID: 41759344
I argue that my question adequately answered the question- both in writing and in the link shared for detailed information straight from Microsoft.  I recommend that we split the points 250/250.
0
 
LVL 39

Expert Comment

by:Adam Brown
ID: 41759971
Given that the link provided explains the difference between setting a Group Policy and a Group Policy Preference, it does not sufficiently answer the question. The question is regarding whether or not modifying the registry through regedit or similar means will over-ride settings deployed by group policy. Deploying the registry modifications through preferences is not part of the equation (given the statement that the question has been in his mind for 10 years or more, while preferences did not exist before server 2008).

My response addressed the apparent misunderstanding the requester had regarding how Group Policies are applied the the Registry. Specifically that Group Policy settings were stored in a different location in the registry than would be modified to achieve the same result in Regedit. This is not the case, since Group Policy settings directly modify the settings that would be modified in Regedit manually to change the setting. Attempting to modify the registry manually with a Group Policy in effect will not change the setting for very long, since it will be immediately changed back to the Group Policy setting's value as soon as Group Policy is refreshed.
0
 
LVL 12

Expert Comment

by:Dustin Saunders
ID: 41759997
Again, I object and recommend the points be split.  My explanation includes GPOs vs applying registry settings via Preferences- which includes how the GP can apply once, or have rollback which is how it changes or doesn't change an update in regedit.  It is a sufficient explanation with a robust article to support it.

If we can't agree on that then the question will require another party to resolve.
0
 
LVL 39

Expert Comment

by:Adam Brown
ID: 41760029
Dustin, The question isn't about deploying registry settings via preferences...
A setting that can set by either a change via regedit or set via a group policy, than which setting will take priority ?

Group Policy settings (The Administrative Template branch, at least), at their core, are registry modifications. The question is whether setting the policy with an Administrative Template GPO will over-ride a modification through regedit. It has nothing to do with registry settings deployed by a GPO preference.

I'm trying to point out these facts so other people (and you) can learn from it. I don't care so much about the points as I care about the answer being completely accurate and useful for people in the future, when it inevitably comes up in a google search. Please, re-read the question entirely and explain how Group Policy Preferences enters into it if you still think your answer addresses the issue.
0
 
LVL 12

Expert Comment

by:Dustin Saunders
ID: 41760066
I'm not going to argue this with you, we'll leave the question for a third party to close.
0
 
LVL 1

Author Closing Comment

by:pc-cyt
ID: 41770861
Adams answer makes the most sense of my question, but i did also learn from Dustins comments, although not really part of my original question.
0
 
LVL 12

Expert Comment

by:Dustin Saunders
ID: 41770879
Asker is the ultimate judge, thanks for coming back to resolve the open question.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you need to start windows update installation remotely or as a scheduled task you will find this very helpful.
While working, an annoying popup showing below will come and we cannot cancel or close it form the screen. The error message will come again and again.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

786 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question