Every now and then Microsoft releases a new operating system and if you are in a domain environment you should be interested in manage your new (and old) computer via Group Polices. To manage your computer you need either the target operating system version (or later) with RSAT (Remote Server Administrative Tools) or equivalent server operating system to be able to see and configure all features. You also need updated Group Policy settings files, Group Policy Administrative Templates or simply updated ADMX files for the new operating system. You can get these ADMX files in different ways either download them from Microsoft Download pages: Administrative Templates (.admx) for Windows 10 or in the folder “%WinDir%\PolicyDefinitions” from the operating system you want to manage, make sure it is fully updated with all service packs, patches etc.

If you install RSAT on the target computer and manage Group Policies from there you are fine, no need to change any thing, but if you want to manage the Group Policies from a server that are not the latest and maybe not the same templates, you need to do one of two things.

  • Update “%WinDir%\PolicyDefinitions” with the latest templates (replace the existing). Note! The downside of doing this is if you have more than one server you are managing group policies from you need to update all of them
  • Update central store for Group Policy Administrative Templates. This is a preferred way in this case the domain controllers will replicate the templates and makes sure you have the latest templates available where ever you are without any local changes. Microsoft just updated the KB how to do this and it is really simple so just go and do it
    How to create and manage the Central Store for Group Policy Administrative Templates in Windows

Note! When you are done it should look like this in your \\<domain>\SysVol\<Domain>\Policies folder.

If you have trouble with permissions you could update the local Sysvol folder on a Domain controller: %WinDir%\SYSVOL\sysvol\[<Domain>\Policies. (You may need to modify the permissions, since default is only SYSTEM has full control)


Also note the problem descibed in the next post about WindowsLocationProvider


Did I miss anything, or do you have any problems updating the templates. Let me know in the comments