Skip to content
GPO audit tool

Audit the policy setting that wins, not just the GPO that exists.

Retrievy GPO X-Ray inventories Group Policy Objects, follows collected domain and OU links, applies link order, enforced-link, and block-inheritance rules, and shows the registry or security-policy setting that wins in that collected hierarchy. It adds scope estimates, hygiene evidence, drift, and remediation without presenting the result as endpoint Resultant Set of Policy.

Inventory is not outcome

Knowing that a GPO is linked does not tell you which value governs.

A conventional GPO list answers what exists and where it is linked. A security audit needs the next layer: link order, deeper OU links, enforced parents, blocked inheritance, disabled partitions, conflicting settings, and the population beneath each linked OU.

That still is not full endpoint RSoP. Local and Site policy processing, live WMI evaluation, custom security-filter token resolution, loopback, and endpoint-local state can change the final outcome. Retrievy stays explicit about the boundary of the collected domain and OU evidence.

Within that boundary, GPO X-Ray turns raw policy files and hierarchy data into a reviewable explanation of the winner, the silenced values, the likely scope, and what changed between snapshots.

Beyond a GPO list

Explain precedence, scope, and change from one collected model.

The value is the relationship between the objects, links, settings, and affected hierarchy, not another inventory export.

Inventory and link map

Inventory GPO identity and status, domain-root and OU links, link order, enabled state, enforced links, block inheritance, and user or computer partition state.

Collected setting resolution

Decode supported Registry.pol and security-policy entries, walk the collected domain-to-OU chain, and explain the winning value and the values it supersedes.

Scope and hygiene

Estimate the maximum users and computers beneath a linked OU, then highlight empty, orphaned, and shadowed-within-the-model GPO conditions with supporting context.

Drift and remediation

Compare consecutive snapshots for GPO, link, status, and collected effective-setting changes, then keep evidence and remediation work attached to the finding.

What Retrievy examines

The parts of Group Policy that determine the collected result.

GPO X-Ray distinguishes computed evidence from scope indicators that still require endpoint validation.

Check 01

GPO inventory and status

Known policy objects, machine and user partition status, linked and unlinked state, and whether policy files contain supported settings.

Check 02

Links and link order

Domain and OU attachment points, enabled state, ordering at each scope, and the hierarchy a setting traverses.

Check 03

Enforcement and inheritance

Enforced links and block-inheritance boundaries that change which upstream policy settings remain in the collected chain.

Check 04

Security and WMI filter indicators

Whether custom security filtering or a WMI filter is attached, plus collected filter metadata. Retrievy does not claim live per-endpoint predicate or token evaluation.

Check 05

Registry and security settings

Supported machine and user Registry.pol entries plus supported security-policy settings that are not stored in Registry.pol.

Check 06

ADMX enrichment

Friendly policy names and descriptions when an imported ADMX definition matches; raw registry evidence remains visible when it does not.

Check 07

Targeted permission risk

Supported dangerous GPO delegation findings, not a complete effective ACL matrix for every principal.

Check 08

Change evidence

Added, removed, relinked, reordered, reconfigured, or newly winning settings across consecutive collected snapshots.

Retrievy GPO X-Ray showing policy settings, collected precedence conflicts, and affected scope
GPO X-Ray. Collected setting winners, conflicts, and scope. Example product data is illustrative.
Product workflow

Follow a policy from collection to verified correction.

  1. 1 Detect

    Build the collected hierarchy

    The Windows collector gathers the domain and OU tree, GPO metadata, links, supported policy files, and filtering indicators needed for server-side analysis.

  2. 2 Prioritize

    Show the winner and likely reach

    GPO X-Ray explains why a setting wins, shows conflicting values, and estimates the maximum users and computers beneath the relevant linked OU.

  3. 3 Remediate

    Change the right policy layer

    Evidence identifies the setting, GPO, link location, and defeat reason so the operator can remove an obsolete exception or correct the intended policy.

  4. 4 Verify

    Compare the next snapshot

    The next collection recalculates the hierarchy and records whether links, settings, and winners changed as intended or drifted again.

Illustrative example · fictional environment

A child OU silently weakens an SMB baseline

In this fictional lab, the domain-linked Workstation Baseline requires SMB signing. A Legacy Devices GPO linked to a child OU sets the same registry value to disabled for 42 computers.

Setting
Microsoft network client: Digitally sign communications (always)
Upstream value
Workstation Baseline → Enabled
Winning value
Legacy Devices → Disabled
Scope estimate
Maximum 42 computers beneath the linked OU

Analysis

A simple inventory reports both GPOs as present. The collected precedence view explains that the deeper OU link wins for the subtree and preserves the registry evidence behind both values.

Remediation

The AD owner validates the legacy dependency, narrows or removes the exception, and records the correction against the GPO evidence. Endpoint validation remains appropriate where WMI or custom security filtering can alter application.

Verification

The next snapshot recalculates the winner. Retrievy can show that the weakening value no longer wins in the collected hierarchy and retain the change in drift history.

Why GPO X-Ray

A defensible explanation, with clear boundaries.

Winner with proof

See the winning and silenced settings, their GPOs, OU levels, enforcement state, and defeat reasons rather than a flat applied/not-applied label.

Scope without false precision

User and computer counts are presented as a maximum OU-scope impact estimate, not an exact endpoint blast radius when filters may narrow application.

Raw and friendly evidence

ADMX enrichment makes known registry settings readable while preserving raw paths and values when no definition matches.

Change as a first-class signal

Snapshot comparison makes relinking, setting changes, and a new effective winner reviewable instead of waiting for the next annual audit.

Related GPO checks

Use cases beyond inventory.

  • Which collected setting wins at this OU, and why?
  • Which upstream values are silenced by a deeper or enforced link?
  • Where does block inheritance alter the policy chain?
  • Which GPOs are empty, orphaned, or appear fully superseded in the collected hierarchy?
  • Which supported registry settings have a matching ADMX explanation?
  • What changed between the two most recent policy snapshots?
Frequently asked

GPO Audit Tool, answered.

1. Is GPO X-Ray a full Resultant Set of Policy engine?
No. It resolves supported settings across the collected domain and OU hierarchy. It does not evaluate Local or Site policy, endpoint-local state, live WMI predicates, custom security-filter tokens, or every RSoP processing rule.
2. Does Retrievy evaluate security filtering and WMI filters?
Retrievy records supported attachment and metadata indicators so reviewers know they can affect scope. It does not claim live, per-endpoint evaluation of WMI predicates or custom security-filter membership.
3. Is the blast radius an exact affected-device count?
No. It is a maximum scope estimate based on users and computers beneath the linked OU. WMI filters, custom security filtering, and endpoint state can reduce actual application.
4. Can Retrievy read every Group Policy setting?
No. It decodes supported Registry.pol and security-policy entries. ADMX matches enrich known settings, while unmatched values remain as raw registry evidence. Group Policy Preferences are not comprehensively parsed.
5. How does GPO change monitoring work?
Retrievy compares consecutive collected snapshots and records supported changes to GPOs, links, status, settings, and the winner calculated for the collected hierarchy.
Next step

Trace the setting before you change the wrong GPO.

Use GPO X-Ray to review collected precedence, scope, evidence, and drift in your own Active Directory hierarchy.