One of the primary devices to connumber user and also device settings in Windows is the Group Policy Objects (GPO). Local (these settings are configured in your area on the computer) and domajor GPOs (if a computer is joined to the Active Directory domain) deserve to be used to the computer and its individuals. However before, incorrect configuration of some GPO settings deserve to result in miscellaneous difficulties. Group Policy settings have the right to block the link of USB devices, common printers and also folder, restrict netjob-related accessibility by the Windows Defender Firewall rules, block apps and tools from the installing or running (via SPR or AppLocker policies), restrict regional or remote logons to a computer.

You are watching: What versions of windows began support of multiple local gpos?


If you cannot logon to the computer system locally, or doesn’t know specifically which of the applied GPO settings bring about a trouble, you have to use a manuscript to recollection the Group Policy settings to their defaults. In a “clean” state, namong the Group Policy settings are configured.


In this write-up we present numerous approaches for resetting the settings of local and doprimary Group Policies to default values. This guide can be offered to reset GPO settings on all supported Windows versions: from Windows 7 to Windows 10, and also all versions of Windows Server (2008/R2, 2012/R2, 2016 and 2019).
Contents:

How to Recollection Local Group Policy Editor (Gpmodify.msc) Setups to Default?

This method entails making use of the GUI of the local Group Policy Editor console (gpmodify.msc) to disable all configured plan settings. The neighborhood GPO graphical editor is easily accessible just in Pro, Enterprise and Education Windows 10 editions.


Tip. In the Home editions of Windows, the Local Group Policy Editor consingle (gpedit.msc) is missing.

Run the gpedit.msc MMC snap-in and go to the All Settings area (Local Computer Policy -> Computer Configuration – > Administrative templates). This area has a list of all settings available for configuration in the local bureaucratic GPO templates. Sort plans by the State column and also uncover all configured plans (Disabled or Enabled state). Disable all or some of them by switching them to the Not configured state.

*

You can use the LGPO.exe tool from Security Compliance Manager to backup the current neighborhood GPO settings.

Do the exact same steps in the User Configuration area. Therefore, you have the right to disable all the settings of all settings in the Administrative GPO templates.


Tip. A list of all applied neighborhood and domain policy settings in a convenient HTML report develop deserve to be obtained through the built-in GPResult tool:gpresult /h c:PSGPRreport.html

The above approach for reestablishing Group Policy in Windows is suitable for the most basic cases. Incorrect GPO configuration have the right to cause even more severe problems. For example, the incapability to run the gpedit.msc snap-in or also any regimen or application, loss of the administrator privileges, or a restrict to logon locally. In such situations, you have to reset the saved GPO settings in regional documents on your computer system.

Group Policy Files Regisattempt.pol

The Windows Group Policy architecture is based on one-of-a-kind Registry.pol papers. These files store regisattempt settings that correspond to the configured GPO settings. User and also Computer policies are stored in different Regisattempt.pol records.

The computer system settings (Computer Configuration section) are stored in %SystemRoot%System32GroupPolicyMachine egistry.polThe user settings (User Configuration section) are stored in %SystemRoot%System32GroupPolicyUser egisattempt.pol

*

Throughout the startup, the Windows imports the contents of MachineRegistry.pol to the system regisattempt hive HKEY_LOCAL_MACHINE (HKLM). The contents of the file UserRegistry.pol are imported to the HKEY_CURRENT_USER (HKCU) hive as soon as the user logs in.

When you open up the Local GPO Editor Console, it tons the contents of the registry.pol documents and also mirrors them in a user-friendly graphical way. When you cshed the GPO editor, the alters you make are saved to the Registry.pol documents. When you update the Group Policy settings on your computer (making use of the gpupdate /force command also or on a schedule), the new settings applied to the registry.


Tip. To make transforms to the Regisattempt.pol records, you need to just usage the local GPO Editor console. It is not recommfinished to modify Registry.pol records manually or making use of the older versions of Group Policy Editor!

To remove all current settings for the neighborhood GPO, you need to remove the Regisattempt.pol documents in the GroupPolicy and GroupPolicyUsers folders.

Resetting all Local Group Policy Setups at Once on Windows 10/Windows Server 2016

To force a recollection of all present regional Group Policy settings, you need to delete the Registry.pol files. It is possible to entirely delete directories via plan configuration documents. You have the right to execute it through the complying with regulates, run them in the elevated command prompt:

RD /S /Q "%WinDir%System32GroupPolicyUsers"RD /S /Q "%WinDir%System32GroupPolicy"


In Windows 10 2004, the RD.exe command was removed, so the RMDIR.exe command also need to be offered to remove directories.

After that, you need to recollection the old GPO settings in the regisattempt by applying a clean GPO:

gpupday /force

*

These regulates will certainly recollection all neighborhood Group Policy settings in the Computer Configuration and User Configuration sections.

Open the gpedit.msc and make certain that all policies are in the Not Configured state. After running the gpmodify.msc console, deleted GroupPolicyUsers and GroupPolicy folders will certainly be created automatically with empty Registry.pol files.

*

The following time you make changes to Group Policy, Windows will develop brand-new Registry.pol papers through the brand-new settings.

Recollection Local Security Policy Settings to Default in Windows

Local security policies are configured in a sepaprice mmc console – secpol.msc. If the difficulties with the computer system are resulted in by “tightening the screws” in the regional defense settings, and also if you still have actually neighborhood access to Windows and administrator legal rights, it’s much better to recollection the security policy settings to the default values. To execute it, open the cmd.exe as an administrator and also run the complying with command:

In Windows 10, Windows 8.1/8 and Windows 7: secmodify /connumber /cfg %windir%infdefltbase.inf /db defltbase.sdb /verboseIn Windows XP: secedit /connumber /cfg %windir% epairsecsetup.inf /db secsetup.sdb /verbose

*

Rebegin the computer system.

If you still have troubles via security policies, attempt manually renaming the checksuggest file of the neighborhood protection plan database %windir%securitydatabaseedb.chk.

ren %windir%securitydatabaseedb.chk edb_old.chk

*

Run the command:gpupdate /force

Rebegin Windows making use of the shutdvery own command:Shutdown –f –r –t 0

Reset Local GPO Setups without Logging in

If it is difficult to boot/login Windows, the GPSVC business is not running, you don’t have neighborhood administrator privileges, or you cannot open the command also prompt (for instance, apps are blocked by Applocker/SRP policy), just boot your computer from any Windows installation disc, USB flash drive or LiveCD and also reset regional GPO outside of the installed Windows image.

Boot your computer from any type of Windows installation media and open the command prompt (Shift+F10);Run the command:diskpartThen display the list of quantities on the computer:list volumeIn this situation, the drive letter assigned to the mechanism volume coincides to the mechanism drive C:. However, occasionally it might not complement. So, the commands listed below must be executed in the conmessage of your mechanism drive (e. g., D: or C:);Close diskpart:exitRestart the computer in the normal mode and make sure that the local Group Policy settings are recollection to their default state.

How to Clear and Rerelocate Domain-Applied GPO settings?

A few words about domain Group Policies. If a computer system is joined to an Active Directory doprimary, some of its settings are set by domain-based GPOs

The registry.pol papers of all used domajor Group Policies are stored in the directory %windir%System32GroupPolicyDataStoreSysVolcontoso.comPolicies. Each plan is stored in a sepaprice folder with the domain policy GUID. After your computer system leaves the ADVERTISEMENT doprimary, the registry.pol records of domain Group Policies on the computer system will be deleted and won’t be loaded to the regisattempt at startup. However, periodically, despite rerelocating a computer system from the doprimary, GPO settings have the right to still be used to the computer.

See more: The Nine Gates Of The Kingdom Of Shadows, The Nine Gates To The Kingdom Of Shadows

*

The following registry keys correspond to these regisattempt.pol files:

HKLMSoftwarePoliciesMicrosoftHKCUSoftwarePoliciesMicrosoftHKCUSoftwareMicrosoftWindowsCurrentVersionGroup Policy ObjectsHKCUSoftwareMicrosoftWindowsCurrentVersionPolicies

The versions background of the applied doprimary GPOs that have been offered on the client is situated in the adhering to regisattempt keys:

HKLMSOFTWAREMicrosoftWindowsCurrentVersionGroup PolicyHistoryHKCUSoftwareMicrosoftWindowsCurrentVersionGroup PolicyHistory

The neighborhood cache of used doprimary GPOs is stored in the C:ProgramDataMicrosoftGroup PolicyHistory. Delete the papers in this magazine via the command::

DEL /S /F /Q “%PROGRAMDATA%MicrosoftGroup PolicyHistory*.*”

If you must forcetotally rerelocate the domain GPO settings, you should clean the %windir%System32GroupPolicyDataStoreSysVolcontoso.comPolicies catalog and also delete the mentioned regisattempt tricks (it is strongly recommfinished that you backup the deleted records and registry entries!!!) .

gpupdate /force /boot


Tip. The methods questioned above enable you to reset all local GPO settings in Windows versions. All settings made through the Group Policy Editor will reset. However, the alters made directly right into the regisattempt through the regmodify.exe, REG files, domain regisattempt GPP or in any kind of various other means are not recollection.