| ES-PO-WIN-ADM-U-Restrictions GECSP W11 | |
| Data collected on: 2-9-2025 12:21:58 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\cespedes.11-adm |
| Created | 9-10-2024 12:34:18 |
| Modified | 10-10-2024 06:00:04 |
| User Revisions | 58 (AD), 58 (SYSVOL) |
| Computer Revisions | 1 (AD), 1 (SYSVOL) |
| Unique ID | {110a1da6-d69d-4ea8-bdfb-8e166b78030f} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| None | |||
| Name |
|---|
| EMEA\ES-L-SEC-User Restriction GECSP W11 |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\ES-L-SEC-Delegation Full Access | Edit settings, delete, modify security | No |
| EMEA\ES-L-SEC-User Restriction GECSP W11 | Read (from Security Filtering) | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Enforcement | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Designated File Types | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Trusted Publishers | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
| Policy | Setting |
|---|---|
| Default Security Level | Unrestricted |
| APPWIZ.CPL (10.0.17763.2028); APPWIZ; Shell Application Manager; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| bitsadmin.exe (7.8.17763.1); bitsadmin.exe; BITS administration utility; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| CACLS.EXE (10.0.17763.1); cacls; Control ACLs Program; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| Cmd.Exe (10.0.17763.1697); cmd; Windows Command Processor; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| compmgmt.msc; 111 KB; 15/09/2018 8:12:44 | ||||||
| ||||||
| CONTROL.EXE (10.0.17763.2300); Control; Windows Control Panel; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| eventvwr.exe (10.0.17763.1); eventvwr; Event Viewer Snapin Launcher; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| gpedit.msc; 144 KB; 15/09/2018 8:13:19 | ||||||
| ||||||
| Help.Exe (10.0.17763.1); Help; Command Line Help Utility; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| HelpPane.exe (10.0.17763.2989); HelpPane.exe; Microsoft Help and Support; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| mmc.exe (10.0.17763.1697); mmc.exe; Microsoft Management Console; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| mstsc.exe (10.0.17763.2867); mstsc.exe; Remote Desktop Connection; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| NOTEPAD.EXE (10.0.17763.5328); Notepad; Notepad; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| PowerShell.EXE (10.0.17763.1); POWERSHELL; Windows PowerShell; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| powershell_ise.EXE (10.0.17763.1); POWERSHELL_ISE; Windows PowerShell ISE; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| REGEDIT.EXE (10.0.17763.1697); REGEDIT; Registry Editor; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| regedt32.exe (10.0.17763.1); regedt32.exe; Registry Editor Utility; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| services.msc; 91 KB; 15/09/2018 8:12:52 | ||||||
|
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% | ||||||
| ||||||
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% | ||||||
|
| Policy | Setting | Comment | |||||
|---|---|---|---|---|---|---|---|
| Prohibit access to Control Panel and PC settings | Enabled | ||||||
| Show only specified Control Panel items | Enabled | ||||||
| |||||||
| Policy | Setting | Comment | ||||||
|---|---|---|---|---|---|---|---|---|
| Enable screen saver | Enabled | |||||||
| Force specific screen saver | Enabled | |||||||
| ||||||||
| Policy | Setting | Comment | ||||||
| Password protect the screen saver | Enabled | |||||||
| Screen saver timeout | Enabled | |||||||
| ||||||||
| Policy | Setting | Comment |
|---|---|---|
| Browse the network to find printers | Disabled | |
| Prevent addition of printers | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Hide and disable all items on the desktop | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Prohibit adding items | Enabled | |
| Prohibit deleting items | Enabled | |
| Prohibit editing items | Enabled |
| Policy | Setting | Comment | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Allow Dinosaur Easter Egg Game | Disabled | ||||||||||||||
| Block access to a list of URLs | Enabled | ||||||||||||||
| |||||||||||||||
| Policy | Setting | Comment | |||||||||||||
| Control where Developer Tools can be used | Enabled | ||||||||||||||
| |||||||||||||||
| Policy | Setting | Comment | |||||||||||||
| Define domains allowed to access Google Workspace | Enabled | ||||||||||||||
| |||||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Enable reporting of usage and crash-related data | Enabled |
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Block access to a list of URLs | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Control where developer tools can be used | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Define domains allowed to access Google Workspace | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Block about:config | Disabled | |||
| Block about:profiles | Enabled | |||
| Block Add-ons Manager | Enabled | |||
| Define domains allowed to access Google Workspace | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Disable Developer Tools | Enabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Prohibit access of the Windows Connect Now wizards | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Add Search Internet link to Start Menu | Disabled | |||
| Add the Run command to the Start Menu | Disabled | |||
| Clear history of recently opened documents on exit | Enabled | |||
| Disable context menus in the Start Menu | Enabled | |||
| Do not allow pinning items in Jump Lists | Enabled | |||
| Do not allow pinning Store app to the Taskbar | Enabled | |||
| Do not display or track items in Jump Lists from remote locations | Enabled | |||
| Do not search communications | Enabled | |||
| Do not search for files | Enabled | |||
| Do not search Internet | Enabled | |||
| Do not search programs and Control Panel items | Enabled | |||
| Do not use the search-based method when resolving shell shortcuts | Enabled | |||
| Do not use the tracking-based method when resolving shell shortcuts | Enabled | |||
| Lock all taskbar settings | Enabled | |||
| Prevent changes to Taskbar and Start Menu Settings | Enabled | |||
| Prevent users from adding or removing toolbars | Enabled | |||
| Prevent users from customizing their Start Screen | Enabled | |||
| Prevent users from moving taskbar to another screen dock location | Enabled | |||
| Prevent users from rearranging toolbars | Enabled | |||
| Prevent users from uninstalling applications from Start | Enabled | |||
| Remove access to the context menus for the taskbar | Enabled | |||
| Remove All Programs list from the Start menu | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Remove common program groups from Start Menu | Enabled | |||
| Remove Default Programs link from the Start menu. | Enabled | |||
| Remove Documents icon from Start Menu | Enabled | |||
| Remove Downloads link from Start Menu | Enabled | |||
| Remove Favorites menu from Start Menu | Enabled | |||
| Remove frequent programs list from the Start Menu | Enabled | |||
| Remove Games link from Start Menu | Enabled | |||
| Remove Help menu from Start Menu | Enabled | |||
| Remove Homegroup link from Start Menu | Enabled | |||
| Remove links and access to Windows Update | Enabled | |||
| Remove Music icon from Start Menu | Enabled | |||
| Remove Network Connections from Start Menu | Enabled | |||
| Remove Network icon from Start Menu | Enabled | |||
| Remove Notifications and Action Center | Enabled | |||
| Remove Pictures icon from Start Menu | Enabled | |||
| Remove pinned programs from the Taskbar | Enabled | |||
| Remove pinned programs list from the Start Menu | Enabled | |||
| Remove Recent Items menu from Start Menu | Enabled | |||
| Remove Recorded TV link from Start Menu | Enabled | |||
| Remove Run menu from Start Menu | Enabled | |||
| Remove Search Computer link | Enabled | |||
| Remove Search link from Start Menu | Enabled | |||
| Remove See More Results / Search Everywhere link | Enabled | |||
| Remove the "Undock PC" button from the Start Menu | Enabled | |||
| Remove the networking icon | Enabled | |||
| Remove the People Bar from the taskbar | Enabled | |||
| Remove the Security and Maintenance icon | Enabled | |||
| Remove user folder link from Start Menu | Enabled | |||
| Remove Videos link from Start Menu | Enabled | |||
| Search just apps from the Apps view | Enabled | |||
| Show "Run as different user" command on Start | Enabled | |||
| Turn off all balloon notifications | Enabled | |||
| Turn off automatic promotion of notification icons to the taskbar | Enabled | |||
| Turn off notification area cleanup | Enabled | |||
| Turn off personalized menus | Enabled | |||
| Turn off user tracking | Enabled | |||
| Policy | Setting | Comment | |||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Don't run specified Windows applications | Enabled | ||||||||||||||||||||||||
| |||||||||||||||||||||||||
| Policy | Setting | Comment | |||||||||||||||||||||||
| Prevent access to registry editing tools | Enabled | ||||||||||||||||||||||||
| |||||||||||||||||||||||||
| Policy | Setting | Comment | |||||||||||||||||||||||
| Prevent access to the command prompt | Enabled | ||||||||||||||||||||||||
| |||||||||||||||||||||||||
| Policy | Setting | Comment | |||||||||||||||||||||||
| Restrict these programs from being launched from Help | Enabled | ||||||||||||||||||||||||
| |||||||||||||||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| All Removable Storage classes: Deny all access | Enabled | |
| CD and DVD: Deny read access | Enabled | |
| CD and DVD: Deny write access | Enabled | |
| Floppy Drives: Deny read access | Enabled | |
| Floppy Drives: Deny write access | Enabled | |
| Removable Disks: Deny read access | Enabled | |
| Removable Disks: Deny write access | Enabled | |
| Tape Drives: Deny read access | Enabled | |
| Tape Drives: Deny write access | Enabled | |
| WPD Devices: Deny read access | Enabled | |
| WPD Devices: Deny write access | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent the wizard from running. | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn off Autoplay | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off all Windows spotlight features | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow edge swipe | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Hide these specified drives in My Computer | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Hides the Manage item on the File Explorer context menu | Enabled | |||
| Prevent access to drives from My Computer | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Remove "Map Network Drive" and "Disconnect Network Drive" | Enabled | |||
| Remove CD Burning features | Enabled | |||
| Remove Hardware tab | Enabled | |||
| Remove UI to change keyboard navigation indicator setting | Enabled | |||
| Turn off Windows Key hotkeys | Enabled | |||
| Turn off Windows Libraries features that rely on indexed file data | Enabled | |||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn on or off details pane | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Do not allow users to enable or disable add-ons | Enabled | |
| Prevent access to Internet Explorer Help | Enabled | |
| Prevent changing proxy settings | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Disable the Advanced page | Enabled | |
| Disable the Programs page | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn off encryption support | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off Developer Tools | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow Extensions | Disabled | |
| Prevent access to the about:flags page in Microsoft Edge | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Restrict the user from entering author mode | Enabled | |
| Restrict users to the explicitly permitted list of snap-ins | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent users from sharing files within their profile. | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Windows presentation settings | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent access to feed list | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Only display the private store within the Microsoft Store | Enabled | |
| Turn off the offer to update to the latest version of Windows | Enabled | |
| Turn off the Store application | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Hide Advanced Properties Checkbox in Add Scheduled Task Wizard | Enabled | |
| Hide Property Pages | Enabled | |
| Prevent Task Run or End | Enabled | |
| Prohibit Browse | Enabled | |
| Prohibit Drag-and-Drop | Enabled | |
| Prohibit New Task Creation | Enabled | |
| Prohibit Task Deletion | Enabled |
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Always install with elevated privileges | Enabled | |||||
| ||||||
| Policy | Setting | Comment |
|---|---|---|
| Do not allow Windows Messenger to be run | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Windows Mobility Center | Enabled |
| Action | Update |
| Destination file | %USERPROFILE%\Desktop |
| Suppress errors on individual file actions | Disabled |
| Read-only | Enabled |
| Hidden | Disabled |
| Archive | Disabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Target type | File system object |
| Shortcut path | %DesktopDir%\Shortcuts |
| Target path | %userprofile%\Documents |
| Shortcut key | None |
| Run | Normal window |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | Yes |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Target type | File system object |
| Shortcut path | %DesktopDir%\Downloads |
| Target path | %userprofile%\Downloads |
| Shortcut key | None |
| Run | Normal window |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | Yes |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Target type | File system object |
| Shortcut path | %DesktopDir%\Downloads |
| Target path | %userprofile%\Downloads |
| Shortcut key | None |
| Run | Normal window |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | Yes |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Target type | File system object |
| Shortcut path | %DesktopDir%\Downloads |
| Target path | %userprofile%\Downloads |
| Shortcut key | None |
| Run | Normal window |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | Yes |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Target type | File system object |
| Shortcut path | %DesktopDir%\Downloads |
| Target path | C:\Windows\explorer.exe |
| Shortcut key | None |
| Run | Normal window |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | Yes |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |