Always use local ADM files for Group Policy Object Editor
Verified with Windows 11 25H2 — updated on July 30, 2026
Supported on: Windows Server 2003 and Windows XP only
Path in the GPO console
Computer Configuration\Administrative Templates\System\Group Policy Description
This policy setting lets you always use local ADM files for the Group Policy snap-in. By default, when you edit a Group Policy Object (GPO) using the Group Policy Object Editor snap-in, the ADM files are loaded from that GPO into the Group Policy Object Editor snap-in. This allows you to use the same version of the ADM files that were used to create the GPO while editing this GPO. This leads to the following behavior: - If you originally created the GPO with, for example, an English system, the GPO contains English ADM files. - If you later edit the GPO from a different-language system, you get the English ADM files as they were in the GPO. You can change this behavior by using this setting. If you enable this setting, the Group Policy Object Editor snap-in always uses local ADM files in your %windir%\inf directory when editing GPOs. This leads to the following behavior: - If you had originally created the GPO with an English system, and then you edit the GPO with a Japanese system, the Group Policy Object Editor snap-in uses the local Japanese ADM files, and you see the text in Japanese under Administrative Templates. If you disable or do not configure this setting, the Group Policy Object Editor snap-in always loads all ADM files from the actual GPO. Note: If the ADMs that you require are not all available locally in your %windir%\inf directory, you might not be able to see all the settings that have been configured in the GPO that you are editing.
Registry
Software\Policies\Microsoft\Windows\Group Policy Value name: OnlyUseLocalAdminFiles
Enabled: OnlyUseLocalAdminFiles = 1
Disabled: OnlyUseLocalAdminFiles = 0
MDM / Intune (CSP)
./Device/Vendor/MSFT/Policy/Config/ADMX_GroupPolicy/OnlyUseLocalAdminFiles Microsoft Learn documentation Mapping data: Microsoft Learn (CC BY 4.0)
Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Always use local ADM files for Group Policy Object Editor
; State: Enabled
; Supported on: Windows Server 2003 and Windows XP only
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Group Policy]
"OnlyUseLocalAdminFiles"=dword:00000001 More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Always use local ADM files for Group Policy Object Editor
# State: Enabled
# Supported on: Windows Server 2003 and Windows XP only
$path = 'HKLM:\Software\Policies\Microsoft\Windows\Group Policy'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'OnlyUseLocalAdminFiles' -Value 1 -Type DWord Intune XML
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/ADMX_GroupPolicy/OnlyUseLocalAdminFiles
Data type: String
Value:
<enabled/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Always use local ADM files for Group Policy Object Editor
# State: Enabled
# Supported on: Windows Server 2003 and Windows XP only
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows\Group Policy' -Name 'OnlyUseLocalAdminFiles' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Always use local ADM files for Group Policy Object Editor
# State: Enabled
# Supported on: Windows Server 2003 and Windows XP only
$path = 'HKLM:\Software\Policies\Microsoft\Windows\Group Policy'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'OnlyUseLocalAdminFiles' -Value 1 -Type DWord SCCM scripts
# Exported from gporais.com
# Policy: Always use local ADM files for Group Policy Object Editor
# State: Enabled
# Supported on: Windows Server 2003 and Windows XP only
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Always use local ADM files for Group Policy Object Editor
# State: Enabled
# Supported on: Windows Server 2003 and Windows XP only
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows\Group Policy' -Name 'OnlyUseLocalAdminFiles' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Always use local ADM files for Group Policy Object Editor
# State: Enabled
# Supported on: Windows Server 2003 and Windows XP only
$path = 'HKLM:\Software\Policies\Microsoft\Windows\Group Policy'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'OnlyUseLocalAdminFiles' -Value 1 -Type DWord Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.