Group Policy Blog by Darren Mar-Elia (The “GPOGUY”)
Configuring Event Logs with Group Policy and Intune
Years ago, if you wanted to configure Windows Event Logs for things like maximum log size or retention behavior, you typically did that in Security Settings. Starting with Windows 8, Microsoft added a new Administrative Template that added new Administrative Template...
What Is the Registry Policy Archive File and How It Can Be Abused
How many of you remember that, long before GP Preferences was acquired by Microsoft, they used to refer to any Administrative Template settings that did not set values in the 4 magic registry keys as…wait for it…preferences? That’s right, there were “preferences” long...
How to Deploy Group Policy Preferences through Microsoft Intune?
82% of our customers are operating in a hybrid world for their configuration governance tasks, balancing between premises and one or multiple clouds. Group Policy has been around for 26 years, and still serves many customers well, especially for Windows Server...
Demystifying Loopback Processing in Group Policy
I still stumble across questions about Group Policy Loopback Processing on Reddit and other platforms. It confounds a lot of folks because what it does is a bit complex. In this blog, I am going to try to break it down so it is easy to digest. What is Loopback...
Evaluating OU Membership Using WMI Filters
I was reminded of a thread I read a while back where someone was trying to filter a domain-linked GPO by OU membership. The objective was to allow or block computers in a specific OU from receiving a domain-linked GPO purely by evaluating the OU to which they...
Windows Management History, Part 2: Automation Grows Up (2005–2011)
Check the beginning of the story here. By 2005, things were changing quickly. DesktopStandard was acquired by Microsoft, and I went from watching the future unfold from the outside to helping build it from the inside. Walking into Microsoft felt like stepping onto a...
Tattooing Windows with Microsoft Intune
Tattooing has been part of Windows configuration management for decades. In the Group Policy world, tattooing occurred when a policy wrote a value but didn’t remove it when the policy no longer applied. The result was familiar to anyone who has supported Windows...
Windows Management History, Part 1: When Monad Quietly Lit the Fuse
In the early 2000s, Windows administration was a patchwork of tools that never quite agreed with each other. MMC snap‑ins behaved like they were built by different teams on different planets. VBScript was powerful but brittle. Command‑line tools spoke in wildly...
How to Disable Group Policy Processing… on Purpose?
I have to say that after 25 years of messing around with Group Policy, I am constantly amazed by the new things I still learn about the technology and its behavior. Especially when those things are substantial and weird. Such was my recent experience when a colleague...
The Stryker Breach: A Wake-Up Call for Change Management, Privilege Management and Zero Trust
The recent cyberattack on the Stryker Corporation has created chaos through healthcare and cybersecurity sectors. Beginning on March 11, 2026, the incident disrupted global operations, manufacturing, and surgical schedules. This wasn't a standard ransomware play; it...
