Enable Group Policy Caching for Servers
Verified with Windows 11 25H2 — updated on July 30, 2026
Supported on: At least Windows Server 2012 R2, Windows 8.1 or Windows RT 8.1
Path in the GPO console
Computer Configuration\Administrative Templates\System\Group Policy Description
This policy setting allows you to configure Group Policy caching behavior on Windows Server machines. If you enable this policy setting, Group Policy caches policy information after every background processing session. This cache saves applicable GPOs and the settings contained within them. When Group Policy runs in synchronous foreground mode, it refers to this cache, which enables it to run faster. When the cache is read, Group Policy attempts to contact a logon domain controller to determine the link speed. When Group Policy runs in background mode or asynchronous foreground mode, it continues to download the latest version of the policy information, and it uses a bandwidth estimate to determine slow link thresholds. (See the “Configure Group Policy Slow Link Detection” policy setting to configure asynchronous foreground behavior.) The slow link value that is defined in this policy setting determines how long Group Policy will wait for a response from the domain controller before reporting the link speed as slow. The default is 500 milliseconds. The timeout value that is defined in this policy setting determines how long Group Policy will wait for a response from the domain controller before determining that there is no network connectivity. This stops the current Group Policy processing. Group Policy will run in the background the next time a connection to a domain controller is established. Setting this value too high might result in longer waits for the user at boot or logon. The default is 5000 milliseconds. If you disable or do not configure this policy setting, the Group Policy client will not cache applicable GPOs or settings that are contained within the GPOs. When Group Policy runs synchronously, it downloads the latest version of the policy from the network and uses bandwidth estimates to determine slow link thresholds. (See the “Configure Group Policy Slow Link Detection” policy setting to configure asynchronous foreground behavior.)
Registry
Software\Policies\Microsoft\Windows\System Value name: EnableLogonOptimizationOnServerSKU
Enabled: EnableLogonOptimizationOnServerSKU = 1
Disabled: EnableLogonOptimizationOnServerSKU = 0
MDM / Intune (CSP)
./Device/Vendor/MSFT/Policy/Config/ADMX_GroupPolicy/EnableLogonOptimizationOnServerSKU Microsoft Learn documentation Mapping data: Microsoft Learn (CC BY 4.0)
Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Enable Group Policy Caching for Servers
; State: Enabled
; Supported on: At least Windows Server 2012 R2, Windows 8.1 or Windows RT 8.1
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\System]
"EnableLogonOptimizationOnServerSKU"=dword:00000001
"SyncModeSlowLinkThresholdOnServerSKU"=dword:000001f4
"SyncModeNoDCThresholdOnServerSKU"=dword:00001388 More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Enable Group Policy Caching for Servers
# State: Enabled
# Supported on: At least Windows Server 2012 R2, Windows 8.1 or Windows RT 8.1
$path = 'HKLM:\Software\Policies\Microsoft\Windows\System'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'EnableLogonOptimizationOnServerSKU' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'SyncModeSlowLinkThresholdOnServerSKU' -Value 500 -Type DWord
Set-ItemProperty -Path $path -Name 'SyncModeNoDCThresholdOnServerSKU' -Value 5000 -Type DWord Intune XML
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/ADMX_GroupPolicy/EnableLogonOptimizationOnServerSKU
Data type: String
Value:
<enabled/>
<data id="SyncModeSlowLinkThreshold1" value="500"/>
<data id="SyncModeNoDCThreshold1" value="5000"/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Enable Group Policy Caching for Servers
# State: Enabled
# Supported on: At least Windows Server 2012 R2, Windows 8.1 or Windows RT 8.1
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows\System' -Name 'EnableLogonOptimizationOnServerSKU' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows\System' -Name 'SyncModeSlowLinkThresholdOnServerSKU' -Expected 500 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows\System' -Name 'SyncModeNoDCThresholdOnServerSKU' -Expected 5000 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Enable Group Policy Caching for Servers
# State: Enabled
# Supported on: At least Windows Server 2012 R2, Windows 8.1 or Windows RT 8.1
$path = 'HKLM:\Software\Policies\Microsoft\Windows\System'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'EnableLogonOptimizationOnServerSKU' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'SyncModeSlowLinkThresholdOnServerSKU' -Value 500 -Type DWord
Set-ItemProperty -Path $path -Name 'SyncModeNoDCThresholdOnServerSKU' -Value 5000 -Type DWord SCCM scripts
# Exported from gporais.com
# Policy: Enable Group Policy Caching for Servers
# State: Enabled
# Supported on: At least Windows Server 2012 R2, Windows 8.1 or Windows RT 8.1
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Enable Group Policy Caching for Servers
# State: Enabled
# Supported on: At least Windows Server 2012 R2, Windows 8.1 or Windows RT 8.1
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows\System' -Name 'EnableLogonOptimizationOnServerSKU' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows\System' -Name 'SyncModeSlowLinkThresholdOnServerSKU' -Expected 500 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows\System' -Name 'SyncModeNoDCThresholdOnServerSKU' -Expected 5000 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Enable Group Policy Caching for Servers
# State: Enabled
# Supported on: At least Windows Server 2012 R2, Windows 8.1 or Windows RT 8.1
$path = 'HKLM:\Software\Policies\Microsoft\Windows\System'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'EnableLogonOptimizationOnServerSKU' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'SyncModeSlowLinkThresholdOnServerSKU' -Value 500 -Type DWord
Set-ItemProperty -Path $path -Name 'SyncModeNoDCThresholdOnServerSKU' -Value 5000 -Type DWord Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.