Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

Free Fix Event ID 4098

Event ID 4098: Group Policy Preferences items fail to apply on clients

11 min read Updated October 4, 2026 Windows Server: AD, DNS & Group Policy

Fix it now

Event 4098 is written by Group Policy Preferences when one preference item fails, and it carries the policy object, the item and a status code. Microsoft does not publish the event text, so read the status code instead: it is an ordinary Windows error wrapped as an HRESULT, and its low word is the whole diagnosis.

Run the first on the client; use the second only when the failing item is user-targeted

gpupdate /force
gpupdate /logoff
  1. Filter the Application log for 4098 and read the entry. It names the policy object, describes the item that failed, and carries a status code. Those three facts are the diagnosis.
  2. Decode the status code by its low word. 0x80070003 carries Windows error 3, ERROR_PATH_NOT_FOUND, “The system cannot find the path specified”. 0x80070534 carries Windows error 1332, ERROR_NONE_MAPPED, “No mapping between account names and security IDs was done”.
  3. Open that policy object in the editor, find the item under Preferences, and correct the path or the account it references.
  4. If the item sits in the computer half, remember it runs as the machine account before anyone signs in, so test the target with those permissions rather than your own.

An item excluded by item-level targeting never runs and never logs. A missing drive with no 4098 anywhere is a targeting question, not a failure.

If the item does what it was meant to and no new 4098 appears, you are done. If not, the next section covers why preferences fail one at a time.

Why it happens

Preferences are not policy. A policy setting is written into a managed location and reversed when the policy stops applying. A preference item is closer to a scripted action: create this folder, map this drive, put this account in this local group. Each item is evaluated on its own and each can succeed or fail without affecting its neighbours, which is why a single failure never announces itself as a broken policy.

Because of that independence, each preference area writes its own entries into the Application log under a source named for that area, and 4098 is the failure entry across all of them. Microsoft does not publish the message text for the event, so the useful information is not the number: it is the policy object named, the item described, and the status code attached.

That status code is an ordinary Windows error wrapped as an HRESULT. The wrapper is constant and the low word is the error you actually want. 0x80070003 unwraps to error 3, which Microsoft publishes as ERROR_PATH_NOT_FOUND, “The system cannot find the path specified”. 0x80070534 unwraps to error 1332, ERROR_NONE_MAPPED, “No mapping between account names and security IDs was done”. Both are answers to a question the item asked the operating system, so both point at how the item is configured rather than at Group Policy.

Learning that unwrapping is worth more than memorising the two codes above, because a third code will turn up eventually. Take the last four hexadecimal digits, read them as a Windows error number, and look that number up. A reader who can do that never has to guess what a preference item was complaining about.

The path does not exist from the client’s point of view

You have this one if The status is 0x80070003, and the item is a drive map, a file copy, a folder or a shortcut with a target.

  1. Copy the exact path out of the item and test it from an affected client. A renamed share, an old server name or a stray separator are the usual causes.
  2. If the path goes through a namespace, test the target behind it too. A namespace that resolves to an offline target gives the same code.
  3. Check any variables in the path. One that is empty in this context leaves a path that cannot exist.
  4. For items in the computer half, make sure the machine accounts themselves can read the share.

A source on a workstation that is switched off overnight produces this code every night and none during the day. Check the timestamps before rewriting the item.

An account or group cannot be resolved to a security identifier

You have this one if The status is 0x80070534, and the item names a principal somewhere: a local group membership, an owner, an access control entry, or a target.

  1. Open the item and check every place a principal is named. Enter names in domain-qualified form so the lookup is unambiguous.
  2. For built-in local groups, use the entries the editor offers rather than typing names, so the item survives a machine whose operating system is installed in another language.
  3. If the name refers to a deleted account, remove it. There is no identifier to resolve for something that no longer exists.
  4. If it refers to an account in another domain, confirm the trust is healthy from the client.

The item is running in the wrong context

You have this one if The item works when you test it as an administrator and fails when Group Policy applies it, or a user item expects something only the machine can reach.

  1. Check which half of the policy object the item lives in. Computer items run as the machine account before anyone signs in; user items run as the user.
  2. Use the option to run in the signed-in user’s security context only when the item genuinely needs the user’s identity.
  3. Do not use a computer item to write into a user profile that does not exist yet.
  4. Re-test as an ordinary user rather than as an administrator.

The item depends on something another item creates

You have this one if The failure disappears on the second refresh and returns after a rebuild, or two items in the same area consistently give one success and one failure.

  1. Open the area in the editor and check the order. Items are processed in the order they are listed.
  2. Move the item that creates the folder, key or group above the item that writes into it.
  3. Where the dependency crosses two different preference areas, split the work into separate policy objects and control it with link order instead.
  4. Run gpupdate /force twice and confirm the first run is now clean.

Full reference

Unwrapping a status code

Status Windows error Microsoft’s published text
0x80070003 3, ERROR_PATH_NOT_FOUND The system cannot find the path specified
0x80070534 1332, ERROR_NONE_MAPPED No mapping between account names and security IDs was done
0x8007#### The last four digits, in hexadecimal, read as a Windows error number Look that number up in Microsoft’s system error code tables

The two codes above are the ones most people meet, and the rule underneath them is what makes the third one solvable. A status beginning 0x8007 is a Windows error in a wrapper. Convert the last four digits from hexadecimal and look the result up. 0x0003 is 3, 0x0534 is 1332, 0x0005 is 5 and means access denied, and so on.

Which half of the policy the item is in

Half Runs as Runs when
Computer Configuration The machine account At computer startup and on the background refresh
User Configuration The signed-in user At user sign-in and on the background refresh
Either, with the run-as-user option The signed-in user When that user’s cycle runs

Most puzzling 4098 entries turn out to be a context mismatch rather than a broken path. An administrator tests a share by opening it, which works, and concludes the path is fine; the item that failed was in the computer half and asked as the machine account, which has no access at all. Testing the same path with the permissions the item actually runs under settles it in a minute.

Forcing a proper re-test

Command What Microsoft says it does
gpupdate /force Reapplies all policy settings, rather than only the ones that changed
gpupdate /logoff Signs the user out afterwards. Required for extensions that only process at logon
gpupdate /boot Restarts afterwards. Required for extensions that only process at computer startup
gpupdate /wait:<seconds> How long to wait before returning; default 600, -1 waits indefinitely

Silence is not success

  • An item excluded by item-level targeting never runs, so it never logs. If a drive is missing and there is no 4098 anywhere, the targeting excluded the machine or the user, and the item is behaving as configured.
  • An item whose action is Update where nothing has changed also produces nothing. That is normal.
  • A reporting tool that shows the policy object as applied is telling you it was in scope, not that its items succeeded. Only the event log and the extension’s own trace file say what happened on that machine.
  • Two identical-looking items in different policy objects can both apply, in link order, with the later one winning. A correct item that keeps being overwritten looks exactly like an item that fails.

When the event is not specific enough

Each preference area can write a trace file as well as an event, enabled through Group Policy under the logging and tracing settings for that area. The trace records each item as it is evaluated, whether item-level targeting matched, and the call that returned the error. That last point is what turns an unhelpful code into a fix, because it tells you what the item was asking for at the moment it failed rather than only what it was configured to do. Enable it for one area, reproduce the failure, read it, and turn it off again.

Preferences or a script

Where the same work could be done by a sign-in script, preferences are still usually the better choice, and this article is the reason. A script that fails produces nothing to read, no per-item record, and no targeting engine to explain why it did not run somewhere. A preference item that fails produces an event naming the item and a status code you can unwrap. The failure mode is the feature.

Every code this article covers

Code What it points at Source
Event ID 4098 Logged when a Group Policy Preferences item fails. The entry names the policy object, describes the item and carries a status code. Microsoft does not publish the event text, so the status code is what you read not published by the vendor
0x80070003 An HRESULT wrapping Windows error 3, ERROR_PATH_NOT_FOUND: the system cannot find the path specified Microsoft Learn
0x80070534 An HRESULT wrapping Windows error 1332, ERROR_NONE_MAPPED: no mapping between account names and security IDs was done Microsoft Learn

Confirm the fix worked

  1. gpupdate /force on an affected client produces no new 4098 for that item.
  2. The item did what it was meant to: the drive is mapped, the file is present, the membership is correct.
  3. Sign out and back in, then check again, so you know it works during a normal cycle rather than only when forced.
  4. A second client in the same container gets the same result, which proves the fix was in the item rather than in one machine.
  5. The status code no longer appears anywhere in the Application log on either machine.

Questions people ask about this

Is there anything to buy to fix this?

No. Preferences are part of Windows and of the management tools you already have. A 4098 is a configuration fault in one item.

Microsoft does not document 4098. Does that make it unreliable?

No, it makes the number uninformative. The entry itself carries the policy object, the item and a status code, and the status code is a documented Windows error in a wrapper. Read that instead of searching for the event ID.

Why do users see the problem when the policy object reports as applied?

Reporting tools show which policy objects were in scope and what items they contain. They do not re-run the items. Only the event log and the extension’s trace file tell you what happened on that machine.

The drive is missing and there is no 4098 at all. What now?

Then the item never ran. Check item-level targeting, and check that the policy object is actually in scope for that user or computer. An excluded item produces silence, not an error.

Should I use a preference or a sign-in script for drive mappings?

A preference. It gives you per-item logging and a targeting engine, which is exactly the information you need on the day it goes wrong. A script gives you neither.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Free Fix Event ID 5781: dynamic registration of domain controller DNS records failed Free Fix Event ID 1056: DHCP has no credentials for dynamic DNS registration on a DC Free Fix Error 1789 trust relationship failed: rebuilding a broken secure channel Free Fix Error 8453 replication access denied: repairing AD replication permissions
โ† Back to Knowledge Base