Active Directory

How to Create and Test a Group Policy Object on Windows Server 2025 with GPMC

14 min read

The Back Room Tech is reader-supported. We may earn a commission when you buy through links on our site. Learn more.

Start a Group Policy test with one user and one setting. This guide walks through GPMC, an unlinked Group Policy Object (GPO), a test organizational unit (OU), and a Windows 11 client. You’ll check the result, remove the link, and confirm the rollback.

The example blocks a test user from changing the desktop background. It leaves the current background in place. Put the user account in the test OU; the GPO must be in that user’s applicable policy scope. Loopback processing can instead merge or replace user settings using the computer’s scope.

What Is Group Policy Management Console?

GPMC is the Windows tool for creating GPOs, editing settings, linking GPOs to Active Directory containers, and checking results. You can install it as a Windows Server feature or through Remote Server Administration Tools (RSAT) on a supported Windows PC.

Three parts matter during a test:

  • The GPO holds settings. Creating it under Group Policy Objects leaves it unlinked.
  • A link lets the GPO apply to a site, domain, or OU.
  • The effective setting is what the client receives after Windows checks scope, permissions, filters, inheritance, and policy order.

Check both the client report and the setting’s visible effect. A link alone can’t tell you which policy won.

Prerequisites

  • An existing Active Directory domain managed from Windows Server 2025. This guide does not create a domain.
  • A Windows Server 2025 management server, or a supported Windows 11 Pro, Enterprise, or Education PC that can install RSAT. Windows 11 Home cannot join an Active Directory domain.
  • An account allowed to create and edit GPOs, create or use a test OU, and manage GPO links on that OU. These rights can be delegated separately.
  • A dedicated test OU containing a test user account. Use an isolated, domain-joined Windows 11 client for that user.
  • Network access from the client to a domain controller, with working domain DNS. The client must be able to read the domain’s SYSVOL share.
  • A sign-in session for the test user on the Windows 11 client. You’ll sign out and back in during the test.

Record your Windows 11 edition/build and Windows Server servicing level before testing; the examples below are illustrative, not a claim of a lab run on your builds.

The walkthrough uses these names. Substitute yours in the GUI:

ItemExample
Domaincontoso.com
Test OUOU=GPO-Test
Test usergpo-test-user
Test GPOGPO-TEST-USER-PreventBackgroundChange-2026
Test clientDomain-joined Windows 11 PC

This setting needs no special lab hardware. For repeat tests, a small Windows Server host, a Windows 11 PC or virtual machine, and a UPS are more useful than production-scale gear.

Step-by-Step Guide

Step 1: Install or confirm GPMC on the management computer

On Windows Server 2025, open Server Manager. Select Manage > Add Roles and Features, advance to Features, and select Group Policy Management. Complete the wizard. If the feature is already selected, leave it as is.

You can check the feature in an elevated PowerShell window:

Get-WindowsFeature -Name GPMC

Expected result: Install State shows Installed. If it shows Available, run:

Install-WindowsFeature -Name GPMC

Expected result: the feature installs successfully. Read the result for any restart requirement; it depends on the server’s state.

On a Windows 11 management PC, open Settings > System > Optional features > View features. Search for RSAT: Group Policy Management Tools, select it, and click Next > Add. Install RSAT on the management PC; the test client doesn’t need it.

To check RSAT from an elevated PowerShell window on Windows 11, run:

Get-WindowsCapability -Online -Name 'Rsat.GroupPolicy.Management.Tools*'

Expected result: State : Installed. If it shows NotPresent, install it:

Add-WindowsCapability -Online -Name 'Rsat.GroupPolicy.Management.Tools~~~~0.0.1.0'

If installation fails, check access to Windows Update or your organization’s feature-on-demand source. Get GPMC working before you troubleshoot policy scope.

Windows Server Add Roles and Features Wizard with Group Policy Management selected.

Step 2: Open GPMC and locate the domain

Open Start, search for Group Policy Management, and launch it. You can also press Win+R, enter gpmc.msc, and press Enter.

In the left pane, expand Forest: your-domain > Domains > your-domain. You should see Group Policy Objects and the domain’s OUs.

Expected result: GPMC shows the domain tree without an access error. If the domain is missing, check domain controller access and confirm that your account can read the domain.

GPMC domain tree showing Group Policy Objects and the dedicated GPO-Test OU

Step 3: Prepare the test OU and user

If a dedicated test OU already holds the test user, confirm its location and continue. Otherwise, open Server Manager > Tools > Active Directory Users and Computers. Expand the domain, right-click the domain or an approved parent OU, and select New > Organizational Unit. Name it GPO-Test and click OK.

Prefer a disposable test user. Before moving an existing nonproduction test user, record its original OU and policy results: moving it can change inherited policies. To move that test user into the OU: right-click the account, select Move, choose GPO-Test, and click OK. If you lack permission, ask the delegated OU administrator to prepare the OU and user.

Sign in to the domain-joined Windows 11 client as the test user. Open Settings > Personalization > Background and confirm that you can use the background controls. Record that baseline. If another GPO already locks the setting, you won’t be able to show what this test GPO changed.

Expected result: GPMC shows the test OU, Active Directory Users and Computers shows the user inside it, and the Windows 11 background control works.

Scope note: This setting lives under User Configuration. Link the GPO within the user’s applicable AD container scope and verify filtering, inheritance and permissions. Loopback processing is an exception that can use the computer’s scope for user settings; use an isolated client without loopback for this example.

Step 4: Create an unlinked GPO

In GPMC, right-click Group Policy Objects under your domain and select New. Enter:

GPO-TEST-USER-PreventBackgroundChange-2026

Leave Source Starter GPO as (none) and click OK.

Select the new GPO under Group Policy Objects and check its Scope tab. The Links section should be empty. If you see a link, investigate it before editing.

Record the change in your usual change record: “Block gpo-test-user from changing the desktop background while testing in OU=GPO-Test; remove the test OU link and set the policy to Not Configured after verification.” That gives the test a clear scope and rollback plan.

Expected result: the GPO exists, and its Links section is empty. The client is unaffected.

New GPO dialog with the descriptive GPO-TEST-USER-PreventBackgroundChange-2026 name entered

Step 5: Configure one reversible user setting

Right-click the new GPO and select Edit. In Group Policy Management Editor, navigate to:

User Configuration > Policies > Administrative Templates > Control Panel > Personalization > Prevent changing desktop background

Open Prevent changing desktop background, select Enabled, and click OK. Users who receive this policy can’t change their desktop background. Their current wallpaper and files stay in place.

Check the policy label and path in your installed Administrative Templates before applying this example. Templates may come from the local system or a domain Central Store. Their labels depend on the ADMX files in use. If this setting is missing or has a different path, check its behavior and rollback before you proceed.

Return to GPMC and open the GPO’s Settings tab. Expand the user settings. You should see Prevent changing desktop background: Enabled. The GPO remains unlinked, so the test user should still be able to change the background.

Expected result: the GPO holds one enabled user setting, while the client’s background control still works.

Group Policy Management Editor with Prevent changing desktop background enabled under User Configuration.

Step 6: Link the GPO only to the test OU

In GPMC, right-click GPO-Test and select Link an Existing GPO. Select GPO-TEST-USER-PreventBackgroundChange-2026 and click OK.

Select the GPO under Group Policy Objects and open its Scope tab. Check three areas:

  • Links: only the intended GPO-Test OU should appear for this test.
  • Security Filtering: the test user must be allowed to apply the GPO. The default Authenticated Users filter includes the test user within the linked OU. Leave it in place unless your organization has approved a narrower filter.
  • WMI Filtering: leave it as (none). A WMI filter adds another condition to debug.

Select the test OU and review Group Policy Inheritance. The OU may receive GPOs from its parent domain or OUs. Check for another policy that controls the same background setting. Link order, enforced links, and blocked inheritance can affect which setting wins. Investigate an existing policy before changing inheritance.

Expected result: the test GPO has one enabled link to GPO-Test, and the test user is within its scope.

The test GPO Scope tab with its GPO-Test OU link and Authenticated Users security filtering.

Step 7: Refresh policy on the Windows 11 test client

Sign in to the Windows 11 client as the test user. Open a normal PowerShell window under that account and run:

gpupdate /target:user /force

/target:user refreshes user policy. /force reapplies policies even when Windows detects no change. Neither flag adds an out-of-scope user to the GPO.

Expected output includes:

Updating policy…

User Policy update has completed successfully.

If Windows asks you to sign out, accept. Otherwise, sign out and back in before checking Settings. That gives you a fresh user session.

Open Settings > Personalization > Background. The control may be disabled, hidden or otherwise restricted, depending on the Windows 11 build. Treat that visual effect as secondary evidence; use the policy reports in Step 8 to establish which GPO actually applied.

Windows 11 PowerShell session showing gpupdate user policy completed successfully

Step 8: Verify the GPO and setting on the client

On the test client, while signed in as the test user, run:

gpresult /h "$env:USERPROFILE\Desktop\gpresult.html" /f

/h writes an HTML report. /f replaces the old file at that path, so you can read the current result.

Expected output:

The operation completed successfully.

Open gpresult.html from the test user’s desktop. In User Details, confirm that GPO-TEST-USER-PreventBackgroundChange-2026 appears under applied GPOs. Then check the Administrative Templates result for the background policy. If the GPO appears under Denied GPOs, read the reason.

You can also use Group Policy Results in GPMC. Right-click Group Policy Results > Group Policy Results Wizard. Choose Another computer, enter the test client, and select the test user when prompted. Finish the wizard and inspect the user results. Remote collection may need local admin rights on the client and firewall access. The local gpresult report is usually simpler.

Group Policy Modeling predicts a result from conditions you choose. Group Policy Results and gpresult show what processed on the real client. Use results to verify this test.

Expected result: the report lists the test GPO as applied, shows the background policy as enabled, and Windows 11 blocks the change.

Illustrative Group Policy Results report showing the test GPO and enabled user personalization policy.
Illustrative gpresult HTML report showing the test user GPO and enabled desktop background policy.

Step 9: Remove the test link and reset the setting

Once you’ve recorded the result, return to GPMC. Select the GPO-Test OU and find the linked test GPO in the right pane. Right-click the link under the OU and select Delete. Confirm the prompt. This removes the OU link and keeps the GPO object under Group Policy Objects.

Removing the link stops application through that OU; resetting the object is separate cleanup. First confirm that no other links depend on it, since editing a GPO affects all remaining links. For cleanup of this isolated test object, right-click that GPO and select Edit. Reopen User Configuration > Policies > Administrative Templates > Control Panel > Personalization > Prevent changing desktop background. Select Not Configured and click OK.

Expected result: the GPO’s Scope tab has no test OU link. Its Settings tab no longer lists an enabled background policy. You can keep the empty GPO briefly for the test record, then follow your normal review process before deleting it.

Rollback caution: Check the GPO’s Scope tab for other links before deleting the object. Deleting the object affects every OU, domain, or site linked to it.

Step 10: Confirm the rollback on Windows 11

On the test client, sign in as the same test user and run:

gpupdate /target:user /force

Sign out and back in. Then create a fresh report:

gpresult /h "$env:USERPROFILE\Desktop\gpresult.html" /f

Open the report. The test GPO should be absent from the user’s applied list through the test OU. Reopen Settings > Personalization > Background and confirm that the control works again.

If it’s still locked, check the new report for another GPO that sets the same policy. Removing one link leaves other applicable policies in place.

Expected result: the test GPO is absent from the applied list, and the user can change the background. Record the baseline, applied, and rolled-back states.

Configuration: Scope Settings That Matter

SettingWhere to checkWhat it means for this test
GPO settingsGPO Settings tabShows what the object contains. A link is needed to apply it.
LinksGPO Scope tabShows where the GPO can apply. Keep only the test OU link during the test.
Security FilteringGPO Scope tabSets which in-scope users or computers may apply it. The test user needs Read and Apply Group Policy rights.
WMI FilteringGPO Scope tabAdds a client-side condition. Leave it as (none) for this test.
InheritanceTest OU Group Policy Inheritance tabShows GPOs inherited from parent containers and their precedence.
User versus computer settingsGPO Settings tab and editorNormal user/computer scope follows the relevant AD containers; loopback can change user-policy scope.

Authenticated Users is a practical default when the GPO links only to an isolated test OU. If you use a narrower group, confirm the test user has Apply Group Policy. Also confirm that the principals needed for user policy processing can read the GPO. A missed permission can deny an otherwise valid OU link.

Before adding a production link, review the ADMX version, target users, overlapping GPOs, security filter, rollback owner, and pilot result. A link to a larger OU expands the scope at once.

Tips and Troubleshooting

The GPO exists, but nothing changes

Likely cause: The GPO is unlinked, its link is disabled, or the test user sits outside the linked OU.

Fix:

  • In GPMC, open the GPO’s Scope tab and check Links.
  • In Active Directory Users and Computers, confirm the test user’s OU.
  • Check that the test OU link is enabled.
  • Run gpupdate /target:user /force on the client, sign out and back in, and create a new gpresult report.

An unlinked GPO can hold valid settings. No site, domain, or OU will process them.

The linked GPO is denied

Likely cause: Security filtering excludes the user, a WMI filter returns false, or GPO permissions block application.

Fix:

  • Read the Denied GPOs reason in Group Policy Results or the client report.
  • On the GPO’s Scope tab, check Security Filtering and WMI Filtering.
  • If you use a custom security filter, confirm the test user has Read and Apply Group Policy permissions.
  • Remove an unintended WMI filter or fix its condition. Then refresh policy and create a new report.

Keep the filter scoped to the test. Widening it to the whole domain creates a much larger problem.

The user setting does not appear in the report

Likely cause: You ran the report for another user, signed in with another account, or put only the computer in the linked OU.

Fix:

  • Confirm the signed-in username on Windows 11.
  • Check that the test user is in GPO-Test.
  • Inspect User Details in gpresult.html; this example uses a user setting.
  • Sign out and back in after the policy refresh, then create a new report.

For a Computer Configuration policy, the computer account must sit in the linked OU.

A different setting wins

Likely cause: Another applicable GPO sets the same value with higher precedence.

Fix:

  • Use Group Policy Results to find which GPO supplied the effective background setting.
  • Review Group Policy Inheritance on the test OU.
  • Check link order, enforced links, and blocked inheritance.
  • Fix the test design or work with the existing policy’s owner. Leave production precedence alone for this test.

GPMC can edit the GPO but cannot link it

Likely cause: GPO editing rights and OU link-management rights are separate.

Fix: Ask the OU’s delegated administrator to grant the link-management right or add the test link. Record who made the change so the same team can remove it.

gpupdate succeeds, but the client still shows the old state

Likely cause: The current session hasn’t picked up user policy, the client can’t read the updated GPO, or another policy controls the setting.

Fix:

  • Sign out and back in as the test user.
  • Create a new gpresult report and check its timestamp.
  • Check whether the test GPO applied. If it was denied, read the reason.
  • If processing reports a network or SYSVOL error, check domain DNS and domain controller access before changing GPO settings.

Microsoft’s Group Policy processing guide and troubleshooting guidance cover deeper client checks.

Wrapping Up

The unlinked GPO gives you time to check the setting. The OU link and client report show what Windows applied. Test with one user, confirm the rollback, then review scope and competing policies before a wider rollout.

StepActionApplies To
PrepareInstall GPMC and create a test OUManagement computer and Active Directory
TestCreate the GPO, set one policy, and link the OUTest user
VerifyRefresh policy and inspect gpresultWindows 11 client
Roll backRemove the link, reset the setting, and verify againTest user

For interface details, see Microsoft’s GPMC documentation and Group Policy Modeling and Results documentation.