Chat now with support
Chat with Support

Welcome, Quadrotech customers to Quest Support Portal click here for for frequently asked questions regarding servicing your supported assets.

GPOADmin 5.13.5 - Release Notes

Known issues

Table 2. Installation

The Remote Registry service must be running on the targeted GPOADmin service when installing the Watcher service standalone.


Use the silent install instructions found in the GPOADmin User Guide.


If you are running GPMC during an upgrade, you must close and re-open it before the GPO Management tab will display. 


If you set a custom report folder path in a previous version, you must change the reports folder path in the User Preferences to point to the existing folder.


GPMC Extension is missing the "Reject" option for objects in a "Pending Deployment" state. Workaround: Use the GPOADmin client to reject pending deployments.


If you create a SOM backup in one forest and import it to another, the links will appear as deleted GPOs if those GPOs cannot be accessed from the second forest.


If the system time is not synchronized between client and server, it can cause misleading error messages.


If an item displayed in the Pending Approval pane of the Dashboard requires multiple approvals, the item will temporarily be removed from the pane during the approval process. It will be added back to the pane during the next polling interval.


Watcher service event log entry will display object "has been brought back into compliance" for some newly deployed objects.


Imports will fail for workflow disabled items if the last user to connect is not the owner of the target item.


Regardless of the number of assigned approvers, workflow buttons are only included in the first approver’s email.


The context menu on the Linked Group Policy Objects page of the Group Policy Modeling Wizard results in the wizard loosing focus when launched via Citrix XenDesktop.


Backups will not be remove for unregistered objects when running the Remove-Backups PowerShell command.


Rolling back a moved OU does not move the OU back to it original location.


Using SQL as a backup store will not allow you to export historical versions of GPOs as Protected Settings Policies.


When adding or removing account from the Access tab in the GPOADmin Properties, the display may not function properly and hide accounts.


Each time that you change the Enable workflow approval through email option, you must restart the service for the change to take effect.


Compliance actions may result in an unhandled exception in the GPMC Extension.

Workaround: To avoid this issue, you can either perform the compliance actions in the client or by running the Check compliance wizard.


If users do not have the User role assigned on the Version Control root, they may not have the required rights to successfully execute the User Activity report.


If an object is renamed or deleted within Active Directory, the Approvals tab does not reflect the change.


Some GPO settings are not backwards compatible between operating systems.For example, you can't import GPO settings from a Microsoft® Windows® Server 2012 version control system into a GPO in a Microsoft Windows Server 2008 version control system.


When you edit GPOs, you are notified of persistent registry values through a flashing icon on the Registry Cleanup button in the GPO Editor. For this notification to display, you must first close and then open the GPO Settings property page by selecting the Edit menu.


The Watcher Service needs to be restarted after changing Configuration Stores.


Deploying a GPO containing existing Software Installation packages may cause each of those packages to be reinstalled on target workstations.


MMC snap-in may become unresponsive when rolling back changes on 15 or more GPOs in the Check Compliance wizard.


Times displayed in GPOADmin reports will be in the local time zone of the client machine. Any times displayed in the GPMC settings reports will appear in the time zone of the GPOADmin server.


When checking for compliance, GPOADmin will not perform a backup if the unauthorized changes result in an object in the same state as the currently stored version.


If you do not have the appropriate language packs installed, GPOs created using Japanese characters on a Japanese OS will not display on an English OS.


After changing storage locations, the individual version information is not transferred from the old storage location to the new. You must keep the old storage server online if you want to still access those individual versions.


When using the SeizeVCRole.exe utility, if a port is specified with the new server name, the utility assumes that the new server is an AD LDS instance. When using an Active Directory Version Control server, the default port of 389 does not need to be specified.


GPOADmin will not delete the information stored in the directory when it is uninstalled. The Version Control information may be deleted manually if it is no longer required. GPOADmin uses "working copies" of objects for editing purposes. If the Version Control information is deleted from the server, while objects are still pending creation or in a minor version, these working copies may be seen as "Unregistered" if a new instance of the version control information is instantiated.


Working with large (3-5MB) GPOs in the GPMC Extension has the potential for the GPOADmin Service or Watcher Service to become unresponsive.


When you are editing a GPO with both the GPOADmin console and the GPMC Extension open, closing the Group Policy Object Editor may not return you to the expected interface.



Table 7. Reports

For GPO difference reports to run properly when they contain Authentication Services settings, Quest Authentication Services must be installed on the GPOADmin client and the GPOADmin server.


In the Difference Report, filters are not supported for GPO Preference settings.


When running the Difference Report for a GPO that contains Scheduled Task Preference settings, the date and time options displayed in the report may not be as expected.

151232, 151435

If the Service Account does not have the correct access to generate Group Policy Results reports, you may receive miscellaneous errors throughout the Report Wizard. To properly generate Group Policy Results reports for a user or computer, the Service Account must have Read Group Policy Results data permission on the domain or OU that contains the user or computer, or the Service Account must be a member of a local Administrator's group on the targeted computer. 

0104882, 0106937

The MMC snap-in may become unresponsive when running the Group Policy Object Consistency Report with 5000 or more GPOs.


In the Group Policy Settings and Resultant Set of Policies reports, some dates (for example, Created, Modified and Applied date) will display with the time zone of the GPOADmin Server.


Pre-existing GPO settings are being displayed in the Change Auditor Working Copies report.


When viewing Preference settings in the Difference Report, the values displayed for text entries may have a capital letter when the actual value is a lower-case letter. This may cause some date settings to be incorrect. 


When installing the GPOADmin service on a system with User Account Control turned on, the installer must be launched using elevated privileges. To do this, run the 'Quest GPOADmin.msi' file from an elevated command prompt.


Table 9. Third Party

Information about new Group Policy preferences in Windows Server 2008.

"Object reference not set to an instance of an object" error message when you view the GPO backup settings in the Group Policy Management Console.

You cannot read the GPO in the SYSVOL directory in Windows® 7 or in Windows® Server 2008 R2 if you enable the "Deny write" permission of the GPO.

System requirements


2Ghz CPU



Hard disk space

1 Gb (prefer 50Gb if backups and reports stored on the same drive) hard disk space

Operating systems

Windows 7

Windows 8

Windows 8.1

Windows 10

Windows Server 2008 R2

Windows Server 2012

Windows Server 2012 R2

Windows Server 2016

Windows Server 2019

NOTE: For Windows 7 or Windows Sever 2008 R2 see Quest provides the SHA-2 certificate with the understanding that even with this update, there may still be situations where certificate cannot be verified.

Same system requirements as GPOADmin.

Upgrade and compatibility

Note the following when upgrading to GPOADmin version 5.13.5:

To permit a user to see the live environment:

1 Login to GPOADmin as a GPOADmin administrator.
2 Right-click the
Live Environment node and select Properties.
3 On the Security tab, add one or more users who require access to the live environment.
4 Click OK.

Authentication Services integration


Due to rebranding, changes are required in the registry setting for the integration to function correctly.

Authentication Services installs to the following registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Quest Software\Quest Group Policy Manager\Extensions\vgp


GPOADmin version 5.12 and above requires the settings to be installed under this registry key:



Compatible Products

GPOADmin 5.13.5 is compatible with the following software:

Related Documents