This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
An administrator wants to know which Group Policy Objects (GPOs) a remote user session processed. Which tool is the best first choice?
Group Policy Modeling
A GPO HTML report
Group Policy Results
Policy Analyzer
A user belongs to the intended security-filter group. The GPO stopped applying after Authenticated Users was removed. Operational events show access denied while retrieving user policy. What is the most likely cause?
The computer no longer has Read permission on the GPO.
The user needs local administrator rights.
Loopback Replace disables all user policy.
The GPO requires an enforced link.
One domain controller reports GPC computer version 24 plus GPT computer version 23. AD DS replication is healthy. What should the administrator investigate next?
24
23
Local Group Policy on the client
DFSR state plus the server-specific GPT
WMI filter syntax
User token renewal
gpupdate /target:computer completes, but a computer-assigned software package doesn't install. The operational log states that the extension requires foreground processing. What is the correct conclusion?
gpupdate /target:computer
The GPO is denied.
Group Policy Modeling must be rerun.
The package needs a startup processing cycle.
The GPT is orphaned.
gpresult lists a browser policy as applied. The expected value isn't effective. The client is MDM-enrolled. What should the administrator do next?
gpresult
Check target support plus competing MDM policy.
Force AD DS replication.
Increase the slow-link threshold.
Run dcgpofix.
dcgpofix
Startup takes 50 seconds longer on one server group. The operational timeline shows a WMI filter consuming 46 seconds. What is the best next action?
Disable every WMI filter in the domain.
Inspect the query, provider, target properties, plus healthy-peer timing.
Run gpupdate /force repeatedly.
gpupdate /force
Make every GPO link enforced.
An LDAP hardening GPO applies successfully. Directory Service events identify unsigned binds from one application. What is the safest response?
Disable signing on every domain controller.
Remove the hardening GPO from the domain.
Update or reconfigure the LDAP client to use signing or TLS; use temporary containment only when a technically feasible control-specific mechanism exists and its actual blast radius is approved.
Reset SYSVOL replication.
A GPO linked to the Servers OU grants Read and Apply Group Policy to CONTOSO\App-Servers and has a GPO-level WMI filter that matches member servers. Within that GPO, one Group Policy Preferences Registry item has item-level targeting that requires membership in CONTOSO\App-Pilot; a second preference item has no item-level targeting. A server is in CONTOSO\App-Servers, passes the WMI filter, but isn't in CONTOSO\App-Pilot. Which statement is correct?
CONTOSO\App-Servers
CONTOSO\App-Pilot
The GPO remains eligible and its other applicable settings and preference items can process, but the targeted Registry item is skipped. Security and GPO-level WMI filtering scope the whole GPO; item-level targeting scopes one preference item and isn't a security boundary.
The failed item-level target removes the entire GPO from the server's applicable GPO list.
The GPO-level WMI filter controls only the Registry preference item, while security filtering controls the other settings.
Item-level targeting grants the pilot group Read and Apply Group Policy even if the GPO's security filtering denies those permissions.
Item-level targeting prevents computers outside the pilot group from reading the preference configuration, so it can safely protect secrets.
You must answer all questions before checking your work.
Was this page helpful?
Need help with this topic?
Want to try using Ask Learn to clarify or guide you through this topic?