Group Policy Management
body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } }
Setting Path:
Explanation
No explanation is available for this setting.
Supported On:
Not available
CZ-PO-SEC-U- Supervisors Restriction Settings
Data collected on: 2-9-2025 09:54:13
General
Details
Domainemea.tpg.ads
OwnerS-1-5-21-513466819-3096973226-347852806-583600
Created5-3-2021 07:46:34
Modified4-9-2024 14:23:20
User Revisions70 (AD), 70 (SYSVOL)
Computer Revisions11 (AD), 11 (SYSVOL)
Unique ID{c9a57c26-96dd-4af8-bfb3-ec08cc4f2231}
GPO StatusComputer settings disabled
Links
LocationEnforcedLink StatusPath
AgentsNoEnabledemea.tpg.ads/CZ/Agents

This list only includes links in the domain of the GPO.
Security Filtering
The settings in this GPO can only apply to the following groups, users, and computers:
Name
None
Delegation
These groups and users have the specified permission for this GPO
NameAllowed PermissionsInherited
S-1-5-21-513466819-3096973226-347852806-395914CustomNo
Computer Configuration (Disabled)
Policies
Administrative Templates
Policy definitions (ADMX files) retrieved from the central store.
Windows Components/Windows PowerShell
PolicySettingComment
Turn on Script ExecutionEnabled
Execution PolicyAllow all scripts
User Configuration (Enabled)
Policies
Windows Settings
Security Settings
Software Restriction Policies
Enforcement
PolicySetting
Apply Software Restriction Policies to the followingAll software files except libraries (such as DLLs)
Apply Software Restriction Policies to the following usersAll users
When applying Software Restriction PoliciesIgnore certificate rules
Designated File Types
File ExtensionFile Type
ADEADE File
ADPADP File
BASBAS File
BATWindows Batch File
CHMCompiled HTML Help file
CMDWindows Command Script
COMMS-DOS Application
CPLControl panel item
CRTSecurity Certificate
EXEApplication
HLPHelp file
HTAHTML Application
INFSetup Information
INSINS File
ISPISP File
LNKShortcut
MDBMDB File
MDEMDE File
MSCMicrosoft Common Console Document
MSIWindows Installer Package
MSPWindows Installer Patch
MSTMST File
OCXActiveX control
PCDPCD File
PIFShortcut to MS-DOS Program
REGRegistration Entries
SCRScreen saver
SHSSHS File
URLInternet Shortcut
VBVisual Basic Source File
WSCWindows Script Component
Trusted Publishers
Trusted publisher managementAllow all administrators and users to manage user's own Trusted Publishers
Certificate verificationNone
Software Restriction Policies/Security Levels
PolicySetting
Default Security LevelUnrestricted
Software Restriction Policies/Additional Rules
Path Rules
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%
Security LevelUnrestricted
Description
Date last modified23-7-2021 17:22:15
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir%
Security LevelUnrestricted
Description
Date last modified23-7-2021 17:22:15
C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy
Security LevelDisallowed
DescriptionSearch bar disabled
Date last modified23-7-2021 17:23:18
C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy
Security LevelDisallowed
DescriptionSearch bar disabled from 20H2
Date last modified23-7-2021 17:22:53
Administrative Templates
Policy definitions (ADMX files) retrieved from the central store.
Control Panel
PolicySettingComment
Show only specified Control Panel itemsEnabled
List of allowed Control Panel items
Microsoft.Keyboard
Microsoft.Mouse
Microsoft.Sound
Microsoft.SyncCenter
Microsoft.WindowsUpdate
Microsoft.RegionalAndLanguageOptions
Control Panel/Programs
PolicySettingComment
Hide the Programs Control PanelEnabled
Control Panel/Regional and Language Options
PolicySettingComment
Turn off autocorrect misspelled wordsDisabled
Turn off highlight misspelled wordsDisabled
Desktop
PolicySettingComment
Hide Network Locations icon on desktopEnabled
Prohibit User from manually redirecting Profile FoldersEnabled
Remove Properties from the Computer icon context menuEnabled
Remove Properties from the Documents icon context menuEnabled
Remove Properties from the Recycle Bin context menuEnabled
Remove the Desktop Cleanup WizardEnabled
Desktop/Active Directory
PolicySettingComment
Hide Active Directory folderEnabled
Maximum size of Active Directory searchesEnabled
Number of objects returned: 0
Google/Google Chrome/Removed policies
PolicySettingComment
Configure extension installation blocklistEnabled
Extension IDs the user should be prevented from installing (or * for all)
*
PolicySettingComment
Default search provider instant URLEnabled
Default search provider instant URLwww.google.com
Microsoft Edge
PolicySettingComment
Allow user feedbackDisabled
Automatically import another browser's data and settings at first runEnabled
Automatically import another browser's data and settings at first runAutomatically imports all supported datatypes and settings from Internet Explorer
PolicySettingComment
Configure InPrivate mode availabilityEnabled
Configure InPrivate mode availabilityInPrivate mode disabled
Microsoft Edge/Extensions
PolicySettingComment
Control which extensions cannot be installedEnabled
Extension IDs the user should be prevented from installing (or * for all)
*
Mozilla/Firefox/Addons
PolicySettingComment
Allow add-on installs from websitesEnabled
Mozilla/Firefox/Extensions
PolicySettingComment
Extension ManagementEnabled
PolicySettingComment
Extension UpdateEnabled
Extensions to InstallEnabled
amazon.com
Start Menu and Taskbar
PolicySettingComment
Add Search Internet link to Start MenuDisabled
Clear the recent programs list for new usersEnabled
Do not allow pinning Store app to the TaskbarEnabled
Do not display any custom toolbars in the taskbarEnabled
Do not search communicationsEnabled
Do not search for filesEnabled
Do not search InternetEnabled
Do not search programs and Control Panel itemsEnabled
Prevent users from uninstalling applications from StartEnabled
Remove Downloads link from Start MenuEnabled
Remove Games link from Start MenuEnabled
Remove Help menu from Start MenuEnabled
Remove Homegroup link from Start MenuEnabled
Remove Music icon from Start MenuEnabled
Remove Run menu from Start MenuEnabled
Remove the People Bar from the taskbarEnabled
Show Windows Store apps on the taskbarDisabled
System
PolicySettingComment
Don't run specified Windows applicationsEnabled
List of disallowed applications
powershell.exe
powershell_ise.exe
StikyNot.exe
Microsoft.StickyNotes.exe
MicrosoftEdge.exe
MicrosoftEdgeCP.exe
Microsoft.MicrosoftEdge_8wekyb3d8bbwe
Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe
wordpad.exe
PolicySettingComment
Prevent access to registry editing toolsEnabled
Disable regedit from running silently?No
PolicySettingComment
Prevent access to the command promptEnabled
Disable the command prompt script processing also?No
PolicySettingComment
Restrict these programs from being launched from HelpEnabled
Enter executables separated by commas:stickynote.exe, Microsoft.StickyNotes.exe,wordpad.exe
Example: calc.exe,paint.exe
System/Ctrl+Alt+Del Options
PolicySettingComment
Remove Task ManagerEnabled
System/Group Policy
PolicySettingComment
Set Group Policy refresh interval for usersEnabled
This setting allows you to customize how often Group Policy is applied
to users. The range is 0 to 44640 minutes (31 days).
Minutes:15
This is a random time added to the refresh interval to prevent
all clients from requesting Group Policy at the same time.
The range is 0 to 1440 minutes (24 hours)
Minutes:15
System/Removable Storage Access
PolicySettingComment
All Removable Storage classes: Deny all accessEnabled
Windows Components/File Explorer
PolicySettingComment
Disable Known FoldersEnabled
Disable these Known Folders.
{2112AB0A-C86A-4FFE-A368-0DE96E47012E}
{A990AE9F-A03B-4E80-94BC-9912D7504104}
{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}
{491E922F-5643-4AF4-A7EB-4E7A138D8174}
PolicySettingComment
Do not allow Folder Options to be opened from the Options button on the View tab of the ribbonEnabled
Do not display the Welcome Center at user logonEnabled
Hide these specified drives in My ComputerEnabled
Pick one of the following combinationsRestrict A, B, C and D drives only
PolicySettingComment
Hides the Manage item on the File Explorer context menuEnabled
Prevent access to drives from My ComputerEnabled
Pick one of the following combinationsRestrict A, B, C and D drives only
PolicySettingComment
Prevent users from adding files to the root of their Users Files folder.Enabled
Remove "Map Network Drive" and "Disconnect Network Drive"Enabled
Remove CD Burning featuresEnabled
Remove Hardware tabEnabled
Remove Security tabEnabled
Remove Shared Documents from My ComputerEnabled
Remove the Search the Internet "Search again" linkEnabled
Turn off caching of thumbnail picturesEnabled
Turn off display of recent search entries in the File Explorer search boxEnabled
Turn off shell protocol protected modeEnabled
Turn off Windows Key hotkeysEnabled
Turn on Classic ShellDisabled
Preferences
Windows Settings
Folders
Folder (Path: %Appdata%\Microsoft\Windows\Start Menu\Programs\System Tools)
System Tools (Order: 1)
General
ActionDelete
Attributes
Path%Appdata%\Microsoft\Windows\Start Menu\Programs\System Tools
Delete this folder (if emptied)Enabled
Recursively delete all subfolders (if emptied)Enabled
Delete all files in the folder(s)Enabled
Allow deletion of read-only files/foldersEnabled
Ignore errors for files/folders that cannot be deletedEnabled
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Apply once and do not reapplyNo
Folder (Path: %Appdata%\Microsoft\Windows\Start Menu\Programs\Windows PowerShell)
Windows PowerShell (Order: 2)
General
ActionDelete
Attributes
Path%Appdata%\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
Delete this folder (if emptied)Enabled
Recursively delete all subfolders (if emptied)Enabled
Delete all files in the folder(s)Enabled
Allow deletion of read-only files/foldersEnabled
Ignore errors for files/folders that cannot be deletedEnabled
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Apply once and do not reapplyNo
Folder (Path: %USERPROFILE%\AppData\Local\Microsoft\Windows\WinX\Group3)
Group3 (Order: 3)
General
ActionUpdate
Attributes
Path%USERPROFILE%\AppData\Local\Microsoft\Windows\WinX\Group3
Read-onlyDisabled
HiddenEnabled
ArchiveDisabled
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Folder (Path: %USERPROFILE%\AppData\Local\Microsoft\Windows\WinX\Group2)
Group2 (Order: 4)
General
ActionUpdate
Attributes
Path%USERPROFILE%\AppData\Local\Microsoft\Windows\WinX\Group2
Read-onlyDisabled
HiddenEnabled
ArchiveDisabled
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Folder (Path: %USERPROFILE%\AppData\Local\Microsoft\Windows\WinX\Group1)
Group1 (Order: 5)
General
ActionUpdate
Attributes
Path%USERPROFILE%\AppData\Local\Microsoft\Windows\WinX\Group1
Read-onlyDisabled
HiddenEnabled
ArchiveDisabled
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Registry
ShellFeedsTaskbarViewMode (Order: 1)
General
ActionUpdate
Properties
HiveHKEY_CURRENT_USER
Key pathSOFTWARE\Microsoft\Windows\CurrentVersion\Feeds
Value nameShellFeedsTaskbarViewMode
Value typeREG_DWORD
Value data0x2 (2)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Control Panel Settings
Folder Options
Folder Options (At least Windows Vista)
Folder Options (At least Windows Vista) (Order: 1)
General
Properties
Always show icons, never thumbnailsDisabled
Always show menusDisabled
Display file icon on thumbnailsEnabled
Display file size information in folder tipsEnabled
Display simple folder view in Navigation paneEnabled
Display the full path in the titlebar (classic folders only)Disabled
Hidden files and foldersDo not show hidden files and folders
Hide extensions for known file typesEnabled
Hide protected operating system files (Recommended)Enabled
Launch folder windows in separate processDisabled
Remember each folder's view settingsEnabled
Restore previous folder windows at logonDisabled
Show drive lettersEnabled
Show encrypted or compressed NTFS files in colorEnabled
Show pop-up description for folder and desktop itemsEnabled
Show preview handlers in preview paneEnabled
Use check boxes to select itemsDisabled
Use sharing wizard (Recommended)Enabled
When typing into list viewSelect the typed item in the view
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)Yes
Apply once and do not reapplyNo
Start Menu
Start Menu (At least Windows Vista)
Start Menu (At least Windows Vista) (Order: 1)
General
General
Number of programs on the Start menu9
Advanced settings
ComputerDisplay as a link
Connect toNo
Control PanelDo not display this item
Default ProgramsDisplay this item
DocumentsDo not display this item
Enable context menus and dragging and droppingYes
FavoritesDo not display this item
GamesDo not display this item
HelpDo not display this item
Highlight newly installed programsYes
MusicDo not display this item
NetworkDo not display this item
Open submenus when I pause on them with the mouse pointerNo
Personal FolderDisplay as a link
PicturesDo not display this item
PrintersDo not display this item
Run commandDo not display this item
SearchNo
Search CommunicationsNo
Search Favorites and historyNo
Search filesDo not search for files
Search programsNo
Sort All Programs menu by nameYes
System administrative toolsDo not display this item
Use Large IconsYes
List most recently used documentsYes
Clear recent documents listNo
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)Yes
Apply once and do not reapplyNo