WorksOnMine
It works on my machine. The oldest sentence in Windows support. Run one script on each machine, drop both files here, and see exactly which policies and registry values disagree, with the Group Policy that set them.
Runs entirely in your browser. Nothing is uploaded, stored, or sent to us.1Run the collector on both machines
Run this from an elevated PowerShell on the machine that works, then on the machine that does not. It reads applied Group Policy from RSoP and sweeps the policy-backed registry paths, then writes a JSON file to the Desktop. It changes nothing. Read it before you run it, which is why it is open source.
Why not gpresult /x? Its XML tells you which GPOs applied, but not which GPO won each
individual value. RSoP gives per-value provenance, which is the question you are actually asking.
About the file it writes: nothing is uploaded, but the JSON on your Desktop does contain your applied policy configuration. It is scoped to policy paths rather than the whole registry, so it avoids most machine-specific noise, though settings under those paths can still include internal URLs, server names, and proxy details. Treat it like any other config export.
2Drop both files here
Two machines is a troubleshooting session. Three hundred is a compliance problem.
RFF watches every endpoint against a baseline continuously, tells you the moment one drifts, and can put it back.
Start free for 100 endpointsWhy two identical machines behave differently
Two machines built from the same image, in the same OU, running the same software, and one of them misbehaves. The difference is nearly always configuration: a Group Policy that applied to one and not the other, a setting changed by hand months ago, or a security filter that quietly excluded one machine.
The usual way to find it, and why it is miserable
The advice you will find is to export both registries with regedit and diff the two files in a source-control tool. That technically works, and it buries the one setting you care about under thousands of legitimate per-machine differences: GUIDs, MRU lists, timestamps, hardware IDs. Microsoft's own Policy Analyzer compares policy backups against baselines rather than two live machines, and is read-only.
What this does instead
- Reads applied policy from RSoP, so you see what actually won, not just what was linked.
- Scopes the registry sweep to policy-backed paths, so real differences are not lost in noise.
- Attributes each value to the GPO that set it, which is the part gpresult XML cannot tell you.
- Floats policy-path differences to the top, because those are the ones that usually explain behaviour.
- Reconciles the two snapshots even when they record registry paths differently, and says when it did.
FAQ
How do I compare Group Policy between two computers?
Run the collector script on both machines from an elevated PowerShell, then drop the two JSON files onto this page. It reads applied policy from RSoP plus the policy-backed registry paths, and shows the differences with the GPO that set each value. Everything is compared in your browser.
How do I compare the registry on two computers?
The usual advice is to export both registries with regedit and diff the text files in a source-control tool, which drowns you in machine-specific noise. This tool scopes to the policy-relevant paths instead, so what you see is configuration that actually differs rather than GUIDs and MRU lists.
Why not just use gpresult /x?
gpresult XML tells you which GPOs applied, but not which GPO won each individual value. That per-value provenance is usually the actual question, so the collector reads it from RSoP WMI instead.
Does it need administrator rights?
Yes, for a complete picture. Without elevation the collector cannot read computer-scope policy, security policy, user rights, or audit policy. Being signed in as an administrator is not the same as running elevated - with UAC on, a normal PowerShell window has a filtered token. The tool records whether each snapshot was elevated and warns you if they do not match.
Is anything uploaded?
No. The two snapshots are compared entirely in your browser. Nothing is uploaded, stored, or sent to us. The collector is open source and you can read it before running it.
Open source
WorksOnMine is MIT-licensed at github.com/deadarcher/works-on-mine. The diff engine on this page is byte-identical to the one in the repo, and our CI fails the build if they ever drift. Self-host it with one line of Docker:
docker run --rm -p 8080:80 ghcr.io/deadarcher/works-on-mine:latest A diff that is wrong or noisy on real machines? Open an issue with the two snapshots if you can share them.