Group Policy Management
body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } }
Setting Path:
Explanation
No explanation is available for this setting.
Supported On:
Not available
DACH-PO-ADM-U-Restrictions PCI Windows 11
Data collected on: 2-9-2025 10:19:19
General
Details
Domainemea.tpg.ads
OwnerEMEA\flach.6-adm
Created24-3-2022 15:00:18
Modified26-2-2025 10:38:10
User Revisions329 (AD), 329 (SYSVOL)
Computer Revisions0 (AD), 0 (SYSVOL)
Unique ID{4a8be221-ce3c-4710-802a-6652c66cef3f}
GPO StatusComputer settings disabled
Links
LocationEnforcedLink StatusPath
BANoEnabledemea.tpg.ads/BA
CHNoEnabledemea.tpg.ads/CH
DENoEnabledemea.tpg.ads/DE
GENoEnabledemea.tpg.ads/GE
HRNoEnabledemea.tpg.ads/HR
XKNoEnabledemea.tpg.ads/XK

This list only includes links in the domain of the GPO.
Security Filtering
The settings in this GPO can only apply to the following groups, users, and computers:
Name
EMEA\BA-L-SEC-User Restrictions PCI Windows 11
EMEA\CH-L-SEC-User Restrictions PCI Windows 11
EMEA\DE-L-SEC-User Restrictions PCI Windows 11
EMEA\GE-L-SEC-User Restrictions PCI Windows 11
EMEA\HR-L-SEC-User Restrictions PCI Windows 11
EMEA\XK-L-SEC-User Restrictions PCI Windows 11
Delegation
These groups and users have the specified permission for this GPO
NameAllowed PermissionsInherited
EMEA\BA-L-SEC-User Restrictions PCI Windows 11Read (from Security Filtering)No
EMEA\CH-L-SEC-User Restrictions PCI Windows 11Read (from Security Filtering)No
EMEA\DE-L-SEC-Delegation Modify Group Policy Settings AccessEdit settings, delete, modify securityNo
EMEA\DE-L-SEC-User Restrictions PCI Windows 11Read (from Security Filtering)No
EMEA\Domain AdminsEdit settings, delete, modify securityNo
EMEA\Domain ComputersReadNo
EMEA\GE-L-SEC-User Restrictions PCI Windows 11Read (from Security Filtering)No
EMEA\HR-L-SEC-User Restrictions PCI Windows 11Read (from Security Filtering)No
EMEA\XK-L-SEC-User Restrictions PCI Windows 11Read (from Security Filtering)No
NT AUTHORITY\Authenticated UsersReadNo
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSReadNo
NT AUTHORITY\SYSTEMEdit settings, delete, modify securityNo
ROOT\Enterprise AdminsEdit settings, delete, modify securityNo
Computer Configuration (Disabled)
No settings defined.
User Configuration (Enabled)
Policies
Windows Settings
Security Settings
Software Restriction Policies
Enforcement
PolicySetting
Apply Software Restriction Policies to the followingAll software files except libraries (such as DLLs)
Apply Software Restriction Policies to the following usersAll users
When applying Software Restriction PoliciesIgnore certificate rules
Designated File Types
File ExtensionFile Type
ADEADE File
ADPADP File
BASBAS File
BATWindows Batch File
CHMCompiled HTML Help file
CMDWindows Command Script
COMMS-DOS Application
CPLControl panel item
CRTSecurity Certificate
EXEApplication
HLPHelp file
HTAHTML Application
INFSetup Information
INSINS File
ISPISP File
LNKShortcut
MDBMDB File
MDEMDE File
MSCMicrosoft Common Console Document
MSIWindows Installer Package
MSPWindows Installer Patch
MSTMST File
OCXActiveX control
PCDPCD File
PIFShortcut to MS-DOS Program
REGRegistration Entries
SCRScreen saver
SHSSHS File
URLInternet Shortcut
VBVisual Basic Source File
WSCWindows Script Component
Trusted Publishers
Trusted publisher managementAllow all administrators and users to manage user's own Trusted Publishers
Certificate verificationNone
Software Restriction Policies/Security Levels
PolicySetting
Default Security LevelUnrestricted
Software Restriction Policies/Additional Rules
Path Rules
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%
Security LevelUnrestricted
Description
Date last modified25-3-2022 11:40:53
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir%
Security LevelUnrestricted
Description
Date last modified25-3-2022 11:40:53
%programfiles%\WindowsApps\Microsoft.MicrosoftStickyNotes*
Security LevelDisallowed
Description
Date last modified25-3-2022 12:27:43
%programfiles%\WindowsApps\Microsoft.MSPaint*
Security LevelDisallowed
Description
Date last modified18-10-2022 08:20:50
%programfiles%\WindowsApps\Microsoft.PowerAutomateDesktop*
Security LevelDisallowed
Description
Date last modified25-3-2022 12:53:21
%programfiles%\WindowsApps\Microsoft.ScreenSketch*
Security LevelDisallowed
Description
Date last modified25-3-2022 12:28:14
%programfiles%\WindowsApps\Microsoft.windowscommunicationsapps*
Security LevelDisallowed
Description
Date last modified25-3-2022 12:45:35
%programfiles%\WindowsApps\Microsoft.WindowsFeedbackHub*
Security LevelDisallowed
Description
Date last modified25-3-2022 12:29:51
%programfiles%\WindowsApps\Microsoft.WindowsNotepad*
Security LevelDisallowed
Description
Date last modified25-3-2022 12:30:32
%programfiles%\WindowsApps\Microsoft.WindowsStore*
Security LevelDisallowed
Description
Date last modified11-5-2023 15:51:27
%programfiles%\WindowsApps\Microsoft.WindowsTerminal*
Security LevelDisallowed
Description
Date last modified25-3-2022 12:30:49
%SystemDrive%/Program Files/Windows NT/Accessories/wordpad.exe
Security LevelDisallowed
Description
Date last modified20-6-2024 14:43:44
%windir%\System32\mspaint.exe
Security LevelDisallowed
Description
Date last modified9-12-2022 08:35:30
%windir%\System32\notepad.exe
Security LevelDisallowed
Description
Date last modified14-4-2023 14:26:57
%windir%\System32\SnippingTool.exe
Security LevelDisallowed
Description
Date last modified9-12-2022 08:35:21
C:\Windows\System32\WindowsPowerShell
Security LevelDisallowed
Description
Date last modified25-3-2022 12:38:51
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Security LevelDisallowed
Description
Date last modified1-12-2022 14:54:32
C:\Windows\System32\WindowsPowerShell\v1.0\powershell_ise.exe
Security LevelDisallowed
Description
Date last modified1-12-2022 14:54:40
C:\Windows\SystemApps\Microsoft.549981C3F5F10*
Security LevelDisallowed
Description
Date last modified25-3-2022 12:41:37
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
Security LevelDisallowed
Description
Date last modified1-12-2022 14:54:50
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell_ise.exe
Security LevelDisallowed
Description
Date last modified1-12-2022 14:55:06
Administrative Templates
Policy definitions (ADMX files) retrieved from the central store.
Control Panel
PolicySettingComment
Settings Page VisibilityEnabled
Settings Page Visibility:showonly:display;printers;regionlanguage;taskbar;easeofaccess-mouse;mousetouchpad;network-vpn;personalization-colors
Control Panel/Printers
PolicySettingComment
Browse a common web site to find printersDisabled
Browse the network to find printersDisabled
Prevent addition of printersEnabled
Prevent deletion of printersEnabled
Turn off Windows default printer managementEnabled
Start Menu and Taskbar
PolicySettingComment
Do not keep history of recently opened documentsEnabled
Do not search communicationsEnabled
Do not search for filesEnabled
Do not search InternetEnabled
Do not search programs and Control Panel itemsEnabled
Do not use the search-based method when resolving shell shortcutsEnabled
Do not use the tracking-based method when resolving shell shortcutsEnabled
Remove Notifications and Action CenterEnabled
Turn off all balloon notificationsEnabled
System
PolicySettingComment
Don't run specified Windows applicationsEnabled
List of disallowed applications
powershell.exe
wordpad.exe
mspaint.exe
notepad.exe
SnippingTool.exe
powershell_ise.exe
WinStore.App.exe
Windows Components/Cloud Content
PolicySettingComment
Turn off Spotlight collection on DesktopEnabled
Turn off the Windows Welcome ExperienceEnabled
Turn off Windows Spotlight on Action CenterEnabled
Windows Components/File Explorer
PolicySettingComment
No Computers Near Me in Network LocationsEnabled
No Entire Network in Network LocationsEnabled
Windows Components/Microsoft Management Console
PolicySettingComment
Restrict users to the explicitly permitted list of snap-insEnabled
Windows Components/Windows Copilot
PolicySettingComment
Turn off Windows CopilotEnabled
Preferences
Windows Settings
Registry
SearchboxTaskbarMode (Order: 1)
General
ActionReplace
Properties
HiveHKEY_CURRENT_USER
Key pathSOFTWARE\Microsoft\Windows\CurrentVersion\Search
Value nameSearchboxTaskbarMode
Value typeREG_DWORD
Value data0x0 (0)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Remove this item when it is no longer appliedYes
SilentInstalledAppsEnabled (Order: 2)
General
ActionReplace
Properties
HiveHKEY_CURRENT_USER
Key pathSoftware\Microsoft\Windows\CurrentVersion\ContentDeliveryManager
Value nameSilentInstalledAppsEnabled
Value typeREG_DWORD
Value data0x0 (0)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Remove this item when it is no longer appliedYes
Attributes (Order: 3)
General
ActionReplace
Properties
HiveHKEY_CURRENT_USER
Key pathSoftware\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder
Value nameAttributes
Value typeREG_DWORD
Value data0x100000 (1048576)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Remove this item when it is no longer appliedYes
PrintScreenKeyForSnippingEnabled (Order: 4)
General
ActionReplace
Properties
HiveHKEY_CURRENT_USER
Key pathControl Panel\Keyboard
Value namePrintScreenKeyForSnippingEnabled
Value typeREG_DWORD
Value data0x0 (0)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Remove this item when it is no longer appliedYes
Collection: Games
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Apply once and do not reapplyNo
Registry item: AllowAutoGameMode
General
ActionReplace
Properties
HiveHKEY_CURRENT_USER
Key pathSoftware\Microsoft\GameBar
Value nameAllowAutoGameMode
Value typeREG_DWORD
Value data0x0 (0)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Remove this item when it is no longer appliedYes
Registry item: ShowGameModeNotifications
General
ActionReplace
Properties
HiveHKEY_CURRENT_USER
Key pathSoftware\Microsoft\GameBar
Value nameShowGameModeNotifications
Value typeREG_DWORD
Value data0x0 (0)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Remove this item when it is no longer appliedYes
Collection: OneDrive
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Apply once and do not reapplyNo
Registry item: {018D5C66-4533-4307-9B53-224DE2ED1FE6}
General
ActionReplace
Properties
HiveHKEY_CLASSES_ROOT
Key pathWOW6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}
Value name(Default)
Value typeREG_SZ
Value dataOneDrive
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Remove this item when it is no longer appliedYes
Registry item: {018D5C66-4533-4307-9B53-224DE2ED1FE6}
General
ActionReplace
Properties
HiveHKEY_CLASSES_ROOT
Key pathCLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}
Value name(Default)
Value typeREG_SZ
Value dataOneDrive
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Remove this item when it is no longer appliedYes
Registry item: SortOrderIndex
General
ActionReplace
Properties
HiveHKEY_CLASSES_ROOT
Key pathWOW6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}
Value nameSortOrderIndex
Value typeREG_DWORD
Value data0x42 (66)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Remove this item when it is no longer appliedYes
Registry item: SortOrderIndex
General
ActionReplace
Properties
HiveHKEY_CLASSES_ROOT
Key pathCLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}
Value nameSortOrderIndex
Value typeREG_DWORD
Value data0x42 (66)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Remove this item when it is no longer appliedYes
Registry item: System.IsPinnedToNameSpaceTree
General
ActionReplace
Properties
HiveHKEY_CLASSES_ROOT
Key pathWOW6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}
Value nameSystem.IsPinnedToNameSpaceTree
Value typeREG_DWORD
Value data0x1 (1)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Remove this item when it is no longer appliedYes
Registry item: System.IsPinnedToNameSpaceTree
General
ActionReplace
Properties
HiveHKEY_CLASSES_ROOT
Key pathCLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}
Value nameSystem.IsPinnedToNameSpaceTree
Value typeREG_DWORD
Value data0x1 (1)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Remove this item when it is no longer appliedYes