| Copy of EG-PO-ADM-U-windows11 policies | |
| Data collected on: 2-9-2025 11:35:51 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\ghalib.6-adm |
| Created | 12-10-2023 10:31:56 |
| Modified | 25-8-2025 11:17:46 |
| User Revisions | 78 (AD), 78 (SYSVOL) |
| Computer Revisions | 55 (AD), 55 (SYSVOL) |
| Unique ID | {7b89b61c-dd5f-49cb-a9d2-2be702961333} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| DXB | No | Enabled | emea.tpg.ads/AE/Systems/Clients/DXB |
| Agents | Yes | Enabled | emea.tpg.ads/EG/Agents |
| Clients | No | Enabled | emea.tpg.ads/EG/Systems/Clients |
| Name |
|---|
| None |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\EGCAIDTGJN6YY3$ | Custom | No |
| Name | New Wired Network Policy |
| Description | Sample Description |
| Setting | Value |
|---|---|
| Use Windows wired LAN network services for clients | Enabled |
| Shared user credentials for network authentication | Enabled |
| Enable use of IEEE 802.1X authentication for network access | Enabled |
| Enforce use of IEEE 802.1X authentication for network access | Disabled |
| Computer Authentication | User re-authentication |
| Maximum Authentication Failures | 1 |
| Maximum EAPOL-Start Messages Sent | |
| Held Period (seconds) | |
| Start Period (seconds) | |
| Authentication Period (seconds) |
| Authentication method | Protected EAP (PEAP) |
| Validate server certificate | Disabled |
| Enable fast reconnect | Enabled |
| Disconnect if server does not present cryptobinding TLV | Disabled |
| Enforce network access protection | Disabled |
| Authentication method | Secured password (EAP-MSCHAP v2) |
| Automatically use my Windows logon name and password(and domain if any) | Enabled |
| Enforcement | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Designated File Types | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Trusted Publishers | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
| Policy | Setting |
|---|---|
| Default Security Level | Unrestricted |
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% | ||||||
| ||||||
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% | ||||||
|
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows\Explorer |
| Value name | TaskbarNoPinnedList |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\WindowsStore |
| Value name | RemoveWindowsStore |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows Embedded\EmbeddedLogon |
| Value name | BrandingNeutral |
| Value type | REG_DWORD |
| Value data | 0x8 (8) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Service name | dot3svc |
| Action | Start service |
| Startup type: | Automatic |
| Wait timeout if service is locked: | 30 seconds |
| Log on service as: | LocalSystem |
| Allow service to interact with the desktop: | No |
| First failure: | No change |
| Second failure: | No change |
| Subsequent failures: | No change |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Enforcement | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Designated File Types | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Trusted Publishers | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
| Policy | Setting |
|---|---|
| Default Security Level | Unrestricted |
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% | ||||||
| ||||||
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% | ||||||
| ||||||
| C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy | ||||||
|
| Policy | Setting | Comment |
|---|---|---|
| Disable the Display Control Panel | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Hide "Programs and Features" page | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Configure InPrivate mode availability | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Enable printing | Disabled |
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Add Search Internet link to Start Menu | Disabled | |||||
| Add the Run command to the Start Menu | Disabled | |||||
| Clear history of recently opened documents on exit | Enabled | |||||
| Clear the recent programs list for new users | Enabled | |||||
| Disable context menus in the Start Menu | Enabled | |||||
| Do not allow pinning items in Jump Lists | Enabled | |||||
| Do not allow pinning programs to the Taskbar | Enabled | |||||
| Do not allow pinning Store app to the Taskbar | Enabled | |||||
| Do not allow taskbars on more than one display | Enabled | |||||
| Do not search communications | Enabled | |||||
| Do not search for files | Enabled | |||||
| Do not search Internet | Enabled | |||||
| Do not search programs and Control Panel items | Enabled | |||||
| Force Start to be either full screen size or menu size | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Lock all taskbar settings | Enabled | |||||
| Lock the Taskbar | Enabled | |||||
| Prevent changes to Taskbar and Start Menu Settings | Enabled | |||||
| Prevent users from adding or removing toolbars | Enabled | |||||
| Prevent users from resizing the taskbar | Enabled | |||||
| Remove "Recently added" list from Start Menu | Enabled | |||||
| Remove access to the context menus for the taskbar | Enabled | |||||
| Remove All Programs list from the Start menu | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Remove Default Programs link from the Start menu. | Enabled | |||||
| Remove Documents icon from Start Menu | Enabled | |||||
| Remove Favorites menu from Start Menu | Enabled | |||||
| Remove frequent programs list from the Start Menu | Enabled | |||||
| Remove Help menu from Start Menu | Enabled | |||||
| Remove Music icon from Start Menu | Enabled | |||||
| Remove Notifications and Action Center | Enabled | |||||
| Remove Pictures icon from Start Menu | Enabled | |||||
| Remove pinned programs from the Taskbar | Enabled | |||||
| Remove pinned programs list from the Start Menu | Enabled | |||||
| Remove programs on Settings menu | Enabled | |||||
| Remove Recent Items menu from Start Menu | Enabled | |||||
| Remove Run menu from Start Menu | Enabled | |||||
| Remove Search link from Start Menu | Enabled | |||||
| Show or hide "Most used" list from Start menu | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Show the Apps view automatically when the user goes to Start | Disabled | |||||
| Show Windows Store apps on the taskbar | Disabled | |||||
| Start Layout | Enabled | |||||
| ||||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off all Windows spotlight features | Enabled | |
| Turn off Windows Spotlight on Action Center | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent users from adding files to the root of their Users Files folder. | Enabled | |
| Remove "Map Network Drive" and "Disconnect Network Drive" | Enabled | |
| Remove File Explorer's default context menu | Enabled | |
| Remove File menu from File Explorer | Enabled | |
| Remove Search button from File Explorer | Enabled | |
| Remove Security tab | Enabled | |
| Turn off display of recent search entries in the File Explorer search box | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow InPrivate browsing | Disabled | |
| Allow printing | Disabled |
| Action | Update |
| Source file(s) | \\EGCAIFS01.emea.tpg.ads\EGAGZClients$\META\Setting\start2.bin |
| Destination file | %USERPROFILE%\APPDATA\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\LocalState\start2.bin |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Source file(s) | \\EGCAIFS01.emea.tpg.ads\EGAGZClients$\META\Setting\start2.bin |
| Destination file | %USERPROFILE%\APPDATA\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\LocalState\start2.bin |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Source file(s) | \\EGCAIFS01.emea.tpg.ads\EGAGZClients$\META\Setting\start2.bin |
| Destination file | %USERPROFILE%\APPDATA\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\LocalState\start2.bin |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_CURRENT_USER |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer |
| Value name | NoControlPanel |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_CURRENT_USER |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer |
| Value name | NoStartMenuMorePrograms |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_CURRENT_USER |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer |
| Value name | NoSearchFilesInStartMenu |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_CURRENT_USER |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer |
| Value name | NoSearchProgramsInStartMenu |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_CURRENT_USER |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer |
| Value name | NoStartMenuPinnedList |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_CURRENT_USER |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Search |
| Value name | SearchboxTaskbarMode |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Search |
| Value name | SearchboxTaskbarMode |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_CURRENT_USER |
| Key path | SOFTWARE\Policies\Microsoft\Windows\Explorer |
| Value name | DisableSearchBoxSuggestions |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_CURRENT_USER |
| Key path | SOFTWARE\Policies\Microsoft\Windows\Explorer |
| Value name | Hide Recommended Section |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_CURRENT_USER |
| Key path | SOFTWARE\Policies\Microsoft\Windows\Windows Search |
| Value name | DisableSearch |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_CURRENT_USER |
| Key path | SOFTWARE\Microsoft\PolicyManager\Search |
| Value name | DisableSearch |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced |
| Value name | ShowSecondsInSystemClock |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_CURRENT_USER |
| Key path | Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced |
| Value name | ShowSecondsInSystemClock |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |