# Configuring PowerToys Settings Using Group Policy Objects (GPO) for Enterprise Deployment

> Learn to configure PowerToys settings with Group Policy Objects GPO for enterprise deployment. Centralize management and control PowerToys across your organization via registry policies.

- Repository: [Microsoft/PowerToys](https://github.com/microsoft/PowerToys)
- Tags: how-to-guide
- Published: 2026-02-25

---

**PowerToys supports centralized management via Active Directory Group Policy Objects by reading registry values from `HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PowerToys` or `HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\PowerToys`, disabling UI controls when policies are enforced.**

The `microsoft/PowerToys` repository provides native GPO integration that allows IT administrators to deploy consistent settings across enterprise workstations. By leveraging ADMX policy definitions and a dedicated **GPOWrapper** layer, PowerToys enables machine-level and user-level policy enforcement for every module including FancyZones, Image Resizer, and PowerRename.

## How PowerToys GPO Integration Works

### ADMX Policy Definitions and Registry Storage

PowerToys ships with XML-based administrative template files that define available policies and their registry locations. The `PowerToys.admx` file in `src/gpo/assets/PowerToys.admx` declares each policy with its corresponding registry value name and supported PowerToys version.

When a GPO is applied, Windows writes policy values as `DWORD` entries (0 = disabled, 1 = enabled) to:

- `HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PowerToys` (machine scope)
- `HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\PowerToys` (user scope)

Machine-scope keys take precedence over user-scope keys when both exist.

### The GPOWrapper Architecture

PowerToys implements a layered architecture to bridge native registry reading with the C# Settings UI and the C++ runner:

1. **C++ Implementation Layer**: [`src/common/utils/gpo.h`](https://github.com/microsoft/PowerToys/blob/main/src/common/utils/gpo.h) contains `powertoys_gpo::getConfiguredValue()`, which handles registry access, machine vs. user fallback, and validation of DWORD values.

2. **WinRT Wrapper**: [`src/common/GPOWrapper/GPOWrapper.h`](https://github.com/microsoft/PowerToys/blob/main/src/common/GPOWrapper/GPOWrapper.h) exposes static methods like `GetConfiguredFancyZonesEnabledValue()` that call the underlying C++ logic.

3. **C# Projection**: `src/common/GPOWrapperProjection/GPOWrapperProjection.csproj` projects the WinRT component so WPF ViewModels can consume policy states.

4. **UI Enforcement**: Settings ViewModels (e.g., [`src/settings-ui/Settings.UI/ViewModels/ZoomItViewModel.cs`](https://github.com/microsoft/PowerToys/blob/main/src/settings-ui/Settings.UI/ViewModels/ZoomItViewModel.cs)) check `GPOWrapper` methods and set `_enabledStateIsGPOConfigured = true` to display lock icons and disable toggles.

## Policy Resolution Flow in PowerToys Source Code

When PowerToys starts, the runner and each module follow this resolution path:

1. **Policy Definition**: The ADMX file defines a policy such as `ConfigureEnabledUtilityFancyZones` with a specific registry value name.

2. **Registry Write**: Group Policy client service writes the configured DWORD to `HKLM\SOFTWARE\Policies\Microsoft\PowerToys\ConfigureEnabledUtilityFancyZones`.

3. **Value Retrieval**: `powertoys_gpo::getConfiguredValue()` in [`src/common/utils/gpo.h`](https://github.com/microsoft/PowerToys/blob/main/src/common/utils/gpo.h) attempts to read the machine hive first, falling back to the user hive if not found.

4. **Utility-Specific Resolution**: `getUtilityEnabledValue()` checks for module-specific policies first, then falls back to the global `ConfigureGlobalUtilityEnabledState` if no module-specific value exists.

5. **UI and Runtime Enforcement**: The WinRT wrapper exposes the final state (`Enabled`, `Disabled`, or `NotConfigured`) to both the C# Settings UI and the C++ runner, ensuring disabled modules do not appear in the dashboard.

## Implementing GPO Checks in C# Settings UI

The Settings UI uses the `GPOWrapper` to determine whether controls should be locked. Here is the pattern used in ViewModels:

```csharp
using global::PowerToys.GPOWrapper;

public class FancyZonesViewModel : Observable
{
    private bool _enabledStateIsGPOConfigured;
    private GpoRuleConfigured _enabledGpoRuleConfiguration;

    public FancyZonesViewModel()
    {
        // Query the GPO wrapper for the specific module
        var gpoResult = GPOWrapper.GetConfiguredFancyZonesEnabledValue();
        
        _enabledGpoRuleConfiguration = gpoResult;
        
        // If GPO is configured (not NotConfigured), lock the UI
        if (gpoResult != GpoRuleConfigured.NotConfigured)
        {
            _enabledStateIsGPOConfigured = true;
        }
    }
    
    public bool IsEnabledGPOConfigured => _enabledStateIsGPOConfigured;
}

```

The `GpoRuleConfigured` enum maps to the native C++ enum with values:
- `NotConfigured = -1`
- `Disabled = 0`
- `Enabled = 1`

When `_enabledStateIsGPOConfigured` is true, the WPF binding displays a lock icon and disables the toggle control, preventing users from overriding enterprise policy.

## Deploying PowerToys GPOs in Active Directory

To configure PowerToys settings using Group Policy Objects for enterprise deployment, follow these steps:

1. **Copy ADMX/ADML Files**
   - Copy `PowerToys.admx` from the release package to `C:\Windows\PolicyDefinitions` on your domain controller (or the central store).
   - Copy the corresponding language file (e.g., `PowerToys.adml`) to `C:\Windows\PolicyDefinitions\en-US`.

2. **Create or Edit a GPO**
   - Open the Group Policy Management Console (GPMC).
   - Create a new GPO or edit an existing one linked to your target OU.
   - Navigate to **Computer Configuration → Administrative Templates → PowerToys** for machine-wide policies, or **User Configuration → Administrative Templates → PowerToys** for user-specific policies.

3. **Configure Policies**
   - Enable or disable specific PowerToys modules (e.g., "Configure Enabled Utility FancyZones").
   - Set installer-wide policies such as automatic update downloads or toast notification suppression.

4. **Apply and Refresh**
   - Link the GPO to the appropriate Active Directory container.
   - Run `gpupdate /force` on target machines or wait for the standard Group Policy refresh interval.

5. **Verify Deployment**
   - Check the registry on client machines for entries under `HKLM\SOFTWARE\Policies\Microsoft\PowerToys`.
   - Launch PowerToys and confirm that policy-controlled settings display lock icons and cannot be modified.

## Key Source Files for GPO Configuration

The following files in the `microsoft/PowerToys` repository implement the GPO functionality:

- **`src/gpo/assets/PowerToys.admx`** – The ADMX policy definition file that declares all configurable policies, registry locations, and supported PowerToys versions.

- **[`src/common/utils/gpo.h`](https://github.com/microsoft/PowerToys/blob/main/src/common/utils/gpo.h)** – Contains the core C++ implementation including `powertoys_gpo::getConfiguredValue()` for registry reading and the `POLICIES_PATH` constant defining the registry root.

- **[`src/common/GPOWrapper/GPOWrapper.h`](https://github.com/microsoft/PowerToys/blob/main/src/common/GPOWrapper/GPOWrapper.h)** – WinRT component header exposing static methods like `GetConfiguredFancyZonesEnabledValue()` that bridge C++ logic to the C# UI.

- **`src/common/GPOWrapperProjection/GPOWrapperProjection.csproj`** – The projection project enabling the WPF Settings UI to consume the WinRT wrapper.

- **[`src/settings-ui/Settings.UI/ViewModels/ZoomItViewModel.cs`](https://github.com/microsoft/PowerToys/blob/main/src/settings-ui/Settings.UI/ViewModels/ZoomItViewModel.cs)** – Example ViewModel demonstrating how to query `GPOWrapper` and disable UI controls when policies are enforced.

- **[`doc/devdocs/processes/gpo.md`](https://github.com/microsoft/PowerToys/blob/main/doc/devdocs/processes/gpo.md)** – Developer documentation detailing GPO implementation details and testing procedures.

## Enterprise Deployment Checklist

Before rolling out PowerToys via Group Policy in your organization, verify the following:

- [ ] ADMX and ADML files copied to the `PolicyDefinitions` folder on all domain controllers or the central store.
- [ ] GPO created and linked to the correct Active Directory OU containing target machines or users.
- [ ] Policy revision number in ADMX matches the PowerToys version deployed to clients.
- [ ] Registry keys appear under `HKLM\SOFTWARE\Policies\Microsoft\PowerToys` on client machines after `gpupdate`.
- [ ] PowerToys UI displays lock icons for all policy-controlled settings.
- [ ] Modules disabled by policy do not appear in the PowerToys dashboard or system tray menu.
- [ ] Automatic update policies configured according to organizational software deployment standards.

## Summary

Configuring PowerToys settings using Group Policy Objects enables enterprise administrators to enforce consistent configurations across Windows workstations. The implementation relies on ADMX policy definitions stored in `src/gpo/assets/PowerToys.admx`, registry storage under `HKLM\SOFTWARE\Policies\Microsoft\PowerToys`, and a multi-layered code architecture involving [`src/common/utils/gpo.h`](https://github.com/microsoft/PowerToys/blob/main/src/common/utils/gpo.h) and the `GPOWrapper` WinRT component. When policies are active, the Settings UI disables affected controls and displays lock icons, while the runner prevents disabled modules from launching.

- PowerToys reads GPO values from registry keys under `SOFTWARE\Policies\Microsoft\PowerToys`
- Machine-scope policies (`HKLM`) override user-scope policies (`HKCU`)
- The `GPOWrapper` layer bridges C++ registry logic with the C# Settings UI

- ADMX files in `src/gpo/assets/` define available enterprise policies
- UI controls are locked when `GpoRuleConfigured` returns values other than `NotConfigured`

## Frequently Asked Questions

### What registry path does PowerToys use for GPO settings?

PowerToys reads Group Policy values from `HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PowerToys` for computer-wide policies and `HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\PowerToys` for user-specific policies. The `POLICIES_PATH` constant in [`src/common/utils/gpo.h`](https://github.com/microsoft/PowerToys/blob/main/src/common/utils/gpo.h) defines these locations, with the implementation checking `HKLM` first and falling back to `HKCU` if machine-scope keys are not present.

### How does PowerToys handle conflicts between machine and user GPO policies?

When resolving policy values, the `powertoys_gpo::getConfiguredValue()` function in [`src/common/utils/gpo.h`](https://github.com/microsoft/PowerToys/blob/main/src/common/utils/gpo.h) prioritizes machine-scope registry keys (`HKEY_LOCAL_MACHINE`) over user-scope keys (`HKEY_CURRENT_USER`). If a policy value exists in the machine hive, that value is used regardless of any user-level configuration. Only if the machine key is missing does the system check the user hive, ensuring that enterprise-wide computer policies override individual user preferences.

### Can individual PowerToys modules be disabled via GPO?

Yes, administrators can disable or enable specific PowerToys modules through Group Policy. The ADMX definition file in `src/gpo/assets/PowerToys.admx` includes policies such as `ConfigureEnabledUtilityFancyZones`, `ConfigureEnabledUtilityPowerRename`, and similar entries for each module. The `getUtilityEnabledValue()` function checks for module-specific policies first, then falls back to the global `ConfigureGlobalUtilityEnabledState` policy. When a module is disabled via GPO, the Settings UI displays a lock icon on the toggle, and the runner prevents the module from appearing in the dashboard or launching.

### Where are the ADMX files located in the PowerToys repository?

The administrative template files are located in `src/gpo/assets/PowerToys.admx` for the main policy definitions and corresponding language-specific ADML files in the same directory structure. These files ship with PowerToys releases and must be copied to `C:\Windows\PolicyDefinitions` (or the domain central store) on domain controllers to enable Group Policy management. The ADMX file contains the `revision` attribute that should match the installed PowerToys version to ensure policy compatibility.