In this guide, you will learn how to use the GPResult command line tool to verify what group policy objects are applied to a user or computer.

GPResult is a command line tool that shows the Resultant Set of Policy (RsoP) information for a user and computer. In other words, it creates a report that displays what group policies objects are applied to a user and computer.

Gpupdate

For more detailed information, review the event log or run GPRESULT /H GPReport.html from the command line to access information about Group Policy results.-When I execute gpresult /h gpresult.html, and confirm the result, there are 3 errors listed as below. First 2 errors link to the following Microsoft article after clicking more. GPResult is a command line tool that shows the Resultant Set of Policy (RsoP) information for a user and computer. In other words, it creates a report that displays what group policies objects are applied to a user and computer. If your using group policy in your. If gpupdate.exe hangs or generates an error, you may need to move on to the Event Log. Gpresult ^ Gpresult.exe is a great invaluable tool for troubleshooting Group Policy that has been improved in Windows 7 and Windows Server 2008 R2.

If your using group policy in your environment then you definitely should know how to use this tool.

Gpresult is a command-line tool that shows the Resultant Set of Policy ( RSoP) for a user or computer based on applied Group Policy settings. It ships with all versions of Windows, including Windows XP, Windows 7, Windows Server 2003 and Windows Server 2008.

GPResult Video Tutorial

If you don’t like video tutorials or want more details, then continue reading the instructions below.

Recommended Tool:SolarWinds Server & Application Monitor

Group Policy is an effective way for administrators to control policy settings, deploy software, apply permissions and so on across the entire domain.

When you have multiple Group Policy Objects you need a way to verify those objects are getting applied to a user or computer.

This is exactly what GPresult was built to do.

Let’s look at the example below, I have 4 group policy objects applied at different levels of the domain. One at the root, two at ADPro Computers and one at the ADPRo users OU.

Gpupdate result html

How do I know if they are working?

How can I check if these GPOs are getting applied correctly?

In the next section I’ll show you exactly how I can use gpresult to verify these GPOs are getting applied.

The GPResult command is included with Windows Server versions 2008 and higher. It is also included in client version Windows 7 and higher.

Gpupdate Result

GPResult Examples

Gpupdate ResultGpupdate results

Tip: Run the command prompt as administrator or you may run into issues with the command returning computer settings.

Display All Applied GPOs applied to (User and Computer)

This is the most common usage of the gpresult command, it a quick way to display all group policy objects to a user and computer.

It will display the GPO order, displays details such as last time group policy was applied, which domain controller it run from, which security groups the user and computer is a member of.

From the screenshot of my group policy management console there should be 3 GPOs that get applied to the computer and one to the user. Let’s look at the results of the command to verify that is happening.

I can see under applied group policy objects that all three GPOs are getting applied.

Now let’s check the user GPOs. Yes, I can see the Users – Browser Settings GPO is getting applied.

Display GPOs applied to a specific user

If you don’t want to see both User and Computer GPOs then you can use the scope option to specify user or computer

Gpupdate Result Html

Display GPOs applied to a specific computer

Display GPOs applied on a remote computer

Generate HTML Report

This generates an html report of the applied group policy objects. If you don’t specify a path it will save it to the system32 folder.

Export to a text file

You can redirect the output to a text file with the command below. This is helpful if the results are producing lots of information.

Group policy can be a pain, even when best practices are followed group policy can still be challenging. Knowing how to use these built in tools will help you to verify and troubleshoot group policy’s in your environment. Go give it a try and let me know if you have any questions.

Recommended Tool: SolarWinds Server & Application Monitor

This utility was designed to Monitor Active Directory and other critical services like DNS & DHCP. It will quickly spot domain controller issues, prevent replication failures, track failed logon attempts and much more.

What I like best about SAM is it’s easy to use dashboard and alerting features. It also has the ability to monitor virtual machines and storage.

The gpupdate command refreshes a computer's local Group Policy, and any Active Directory-based group policies.

Availability

Gpupdate is an external command and is available for the following Microsoft operating systems as gpupdate.exe.

Gpupdate syntax

/Target:{Computer User}Specifies that only user or only computer policy settings be refreshed. By default, both user and computer policy settings are refreshed.
/ForceReapplies all policy settings. By default, only policy settings that have changed are applied.
/Wait:{value}Sets the number of seconds to wait for policy processing to finish. The default is 600 seconds. The value '0' means not to wait. The value '-1' means to wait indefinitely. When the time limit is exceeded, the command prompt returns, but policy processing continues.
/LogoffCauses a logoff after the Group Policy settings are refreshed, which is required for those client-side extensions that don't process policy on a background refresh cycle but do during log on. Examples include user-targeted Software Installation and Folder Redirection. This option has no effect if there are no extensions called that require a logoff.
/BootCauses a reboot after the Group Policy settings are refreshed, for those client-side extensions that don't process policy on a background refresh cycle but do at startup. Examples include computer-targeted Software Installation. This option has no effect if there are no extensions called that require a reboot.
/SyncCauses the next foreground policy application to be done synchronously. Foreground policy applications occur at computer boot and user login. You can specify this for the user, computer or both using the /Target parameter. The /Force and /Wait parameters are ignored if specified.

How To Run Gpupdate

Gpupdate examples

Gpupdate Results Command

Running the command alone refreshes the computers policies as shown below in the example output.

Gpupdate Log File Location

Additional information

Gpupdate Results

  • See our Active Directory definition for further information and related links on this term.