Skip to main content

GPO X-Ray overview

GPO X-Ray turns the Group Policy collected from your domain controllers into an operator view. It shows which setting wins at each organizational unit (OU), why it wins, which GPOs contribute nothing to the modeled result, and what changed between snapshots.

The header reads GPO X-Ray, with the subtitle Policy inheritance · conflict resolution.

GPO X-Ray header focused on the synthetic domain, counts, collection confidence, freshness, and four workspace tabs

Before you start

  • Install the Retrievy Agent on Windows on a domain controller and complete at least one scan that collects Group Policy.
  • Make sure your role can view Active Directory findings. The permission is under Settings > Roles & Permissions, in the Active Directory group.
  • Use a plan that includes SCM. See the plan feature matrix.

Open GPO X-Ray

Open the SCM Active Directory dashboard. In Policy Hygiene Observations, select Open GPO X-Ray.

If more than one domain has been scanned, use the domain selector in the header. Changing the domain reloads the workspace from that domain's latest snapshot.

Read the header first

The header tells you whether the analysis is ready to support a decision:

  • GPOs, settings, conflicts, and the hygiene count summarize the selected domain.
  • The freshness indicator shows when Group Policy was collected.
  • The source count shows how many collection sources succeeded.
  • Collected, Modeled, or Incomplete describes the confidence of the result.

Collected means the supporting configuration was collected. Modeled means Retrievy calculated a deterministic result from that snapshot, but did not observe endpoint runtime state. Incomplete means at least one required source was missing, stale, unreadable, unsupported, or not evaluated. Hover the badge to see the reasons.

Run a fresh scan before acting when the snapshot is stale or confidence is Incomplete.

Search the whole policy model

Use Search GPOs, settings, OUs… (gpo: setting: ou:) to find GPOs, settings, OUs, and sites without first choosing a tab. Select a result to open the matching GPO in GPO Library, container in AD Explorer, or setting at the domain root.

Prefixes narrow the search:

  • gpo: for GPOs
  • setting: or key: for settings
  • ou: for organizational units
  • site: for sites

The four tabs

TabUse it to
AD ExplorerResolve effective settings at an OU, compare contributing GPOs, and inspect conflicts. See AD Explorer.
GPO LibraryInventory every GPO, inspect links and versions, and identify policies with no modeled contribution. See GPO Library.
ChangesReview plain-language policy change stories, then inspect the underlying added, removed, and modified events. See Changes.
GPO HygieneReview shadowed, orphaned, empty, and disabled GPOs as cleanup candidates. See GPO Hygiene.

Snapshot and analysis limits

GPO X-Ray does not query domain controllers or endpoints while you browse. It analyzes the latest saved scan. A change made after that scan will not appear until the next collection.

The model resolves registry-based policy and OU inheritance from collected data. Security-filter membership, WMI results, Group Policy Preferences, loopback processing, and site-linked policy may be unavailable or only partially evaluated. The confidence badge calls out these limits. Confirm a planned change with native Group Policy tools and a controlled test OU.

How this affects your Retrievy Index

Empty GPO, Orphaned GPO, Shadowed GPO, and Conflicting GPO Setting are tracked as informational findings. They can appear in finding workflows and can resolve or reopen after later scans, but informational severity has zero weight. These observations stay out of Active Findings severity totals and do not lower the Retrievy Index.

Active Directory hardening and risk findings on the SCM Active Directory dashboard can affect the Index. See the scoring rules catalog for the exact rules.

Troubleshooting

GPO X-Ray shows Zero Data. Confirm the Windows agent is running on a domain controller and that a scan completed Group Policy collection. Then return to GPO X-Ray.

The domain selector is missing. It appears only after more than one Active Directory domain has been scanned.

A result does not match an endpoint. Check freshness and confidence first. The page models collected policy, not runtime Resultant Set of Policy. Run a fresh scan and validate the endpoint separately.