Blog

Group Policy: the good, the bad and the modern

Group Policy has configured Windows estates for two decades. It is genuinely powerful, and left to grow unchecked, it becomes sprawling, conflicted and nearly impossible to audit. Here's how to take back control as you move to the cloud.

The good

Credit where due: Group Policy is one of the most successful management technologies Microsoft ever shipped. Thousands of settings, granular targeting through OUs and security filtering, and central control of everything from password policy to desktop wallpaper. For twenty years, if you wanted a governed Windows estate, GPOs were how you got one.

The bad

The trouble is accumulation. GPOs are easy to create and frightening to delete, so estates grow policies the way lofts grow boxes. Objects duplicate, conflict and layer over one another; precedence becomes archaeology; and the question “what actually applies to this machine?” stops having a knowable answer. Documentation, where it exists, describes the estate as it was years ago.

GPOs are easy to create and frightening to delete, so estates grow policies the way lofts grow boxes.

There's a sharper edge, too. Legacy Group Policy Preferences can carry credentials in a form that has been trivially decryptable since 2014, and they are still out there. When our Scout discovery tool inventories a Group Policy estate, it checks for exactly this, and discloses what it finds prominently, before a long-forgotten setting becomes a security incident.

The modern

Modern management moves configuration to Intune, where policy is cloud-delivered, versioned and reportable. But a straight GPO-to-Intune “lift” repeats the original mistake: migrating the sprawl instead of the intent. Not every setting has a modern equivalent; more importantly, most settings shouldn't move at all, because nothing depends on them any more.

Rationalising on the way out

The right sequence is analyse, rationalise, then migrate. Inventory every GPO and where it applies. Establish which settings are live, which conflict and which are dead weight. Map what remains against Intune's Settings Catalog, flag what has no modern path, and assess the result against CIS, NCSC and Microsoft security baselines. Then migrate a rationalised estate: deliberately, in stages, with rollback.

Done this way, a Group Policy migration isn't a risk to be survived; it's the single best clean-up your Windows estate will ever get.

Time to untangle your Group Policy?

Our Group Policy analysis puts evidence behind every one of these decisions, per domain, at any scale.