The LSDOU order, which GPO wins a conflict, and how Block Inheritance, Enforced and link order change the result.
From Ultra Transcenders AZ-802 by Tony Rough (coming November 2026)
Group Policy applies computer and user settings from GPOs linked to sites, domains and OUs. Knowing exactly which GPO wins is the core Group Policy skill.
By default Group Policy is inherited and cumulative. GPOs are processed in this order, and each later GPO can override earlier settings:
The container closest to the user or computer wins. Where several GPOs are linked to the same container, the GPO with the lowest link order number in the Group Policy Object Links list has precedence. Computer-related settings override user-related settings when they conflict.
| Feature | Property of | Effect |
|---|---|---|
| Enforced | The GPO link | Lower-level GPOs can’t override the linked GPO’s settings; if several enforced links exist at different levels, the highest enforced link takes precedence |
| Block Inheritance | The domain or OU (the GPOptions attribute) | Stops GPOs linked to higher-level sites, domains and parent OUs from applying |
| Disable GPO, computer settings or user settings | The GPO | Turns off the whole GPO or one half; disabling an unused half also speeds up processing |
Enforced beats Block Inheritance: a blocked OU still receives settings from enforced links above it. Set-GPInheritance -Target <DN> -IsBlocked Yes blocks inheritance from PowerShell. Figure 3.1 shows the processing order and how the two settings interact.
Common trap: Using Block Inheritance on an OU to escape a domain-level security GPO that is enforced - enforced is a link property that takes precedence over block inheritance, a container property, so the enforced settings still apply.
A GPO is stored in two places: the Group Policy container in AD DS (replicated by AD replication) and the Group Policy template in SYSVOL (replicated by DFS Replication, every 15 minutes within a site). Changes reach a client only after they replicate to the DC it uses.
To force a refresh, run gpupdate locally (for example gpupdate /force), use Invoke-GPUpdate for local or remote computers, or right-click an OU in the Group Policy Management Console (GPMC) and select Group Policy Update.
This note is one section of Ultra Transcenders AZ-802: Administering Windows Server, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in November 2026, in Kindle and paperback editions.
About the book · AZ-802 terms in the glossary · All AZ-802 study notes
Which operations master roles exist per forest and per domain, what each does and the placement guidance for each.
When to deploy an RODC, how staged installation works and how the allowed and denied groups decide which passwords are cached.
Which managed service account type fits a service, its requirements such as the KDS root key, and how Windows Server 2025 delegated MSAs migrate old accounts.
How the two DHCP failover modes split or reserve addresses, what MCLT does and how relay agents fit in.
What SMB over QUIC needs on the server, the certificate rules, which editions support it and how client access control works.
The Storage Replica topologies, when to use synchronous or asynchronous mode, log volume requirements and the Standard edition limits.
How Windows LAPS rotates and stores local administrator passwords, its policy settings, encryption and the cmdlets to retrieve them.