| MG-PO-WIN-C-Windows 11 Hardening | |
| Data collected on: 2-9-2025 12:47:25 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\manantenason.5-adm |
| Created | 11-3-2025 10:56:52 |
| Modified | 13-4-2025 13:51:52 |
| User Revisions | 1 (AD), 1 (SYSVOL) |
| Computer Revisions | 91 (AD), 91 (SYSVOL) |
| Unique ID | {b9f26ee0-aa89-40c4-a477-e95d07dc17c0} |
| GPO Status | User settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Clients | No | Enabled | emea.tpg.ads/MG/Systems/Clients |
| Name |
|---|
| EMEA\MG-L-SEC-GPO-Hardening_Computers_Windows11 |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\manantenason.5-adm | Edit settings, delete, modify security | No |
| EMEA\MG-G-ORG-OU Admins | Edit settings, delete, modify security | No |
| EMEA\MG-L-SEC-Delegation Group Policy Objects Modify Access | Edit settings, delete, modify security | No |
| EMEA\MG-L-SEC-GPO-Hardening_Computers_Windows11 | Read (from Security Filtering) | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Policy | Setting |
|---|---|
| Deny log on locally | EMEA\MG-L-SEC-GPO-Waha-Folder_Redirection_Startmenu, EMEA\MGANT-G-ORG-GPO-WAHA_User_Configuration_2024 |
| Policy | Setting |
|---|---|
| User Account Control: Admin Approval Mode for the Built-in Administrator account | Disabled |
| User Account Control: Behavior of the elevation prompt for standard users | Prompt for credentials |
| User Account Control: Detect application installations and prompt for elevation | Enabled |
| Policy | Setting |
|---|---|
| Enforce rules of this type | True |
| Action | User | Name | Rule Type | Exceptions |
|---|---|---|---|---|
| Allow | Everyone | Windows Immersivecontrolpanel, de Microsoft Corporation | Publisher | No |
| Allow | BUILTIN\Administrators | Signé par Microsoft Corporation | Publisher | No |
| Allow | Everyone | MicrosoftWindows.Client.WebExperience, de Microsoft Windows | Publisher | No |
| Allow | Everyone | RealtekSemiconductorCorp.HPAudioControl, de Realtek Semiconductor Corp | Publisher | No |
| Allow | Everyone | F46D4000-FD22-4DB4-AC8E-4E1DDDE828FE, de Microsoft Corporation | Publisher | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | Microsoft.BingWeather, de Microsoft Corporation | Publisher | No |
| Allow | NT AUTHORITY\SYSTEM | Signé par Microsoft Windows | Publisher | No |
| Allow | BUILTIN\Administrators | Signé par Microsoft Corporation | Publisher | No |
| Allow | Everyone | MicrosoftWindows.CrossDevice, de Microsoft Windows | Publisher | No |
| Allow | Everyone | Microsoft.Windows.Apprep.ChxApp, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.AAD.BrokerPlugin, de Affecté par votre organisation | Publisher | No |
| Allow | Everyone | Microsoft.LanguageExperiencePackfr-FR, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.Windows.ParentalControls, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.Windows.XGpuEjectDialog, de Microsoft Corporation | Publisher | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | Microsoft.Winget.Source, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | MSTeams, de Microsoft | Publisher | No |
| Allow | Everyone | Microsoft.WindowsCalculator, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.Windows.NarratorQuickStart, de Microsoft | Publisher | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | Microsoft.Windows.DevHome, de Microsoft Corporation | Publisher | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | Microsoft.Paint, de Microsoft Corporation | Publisher | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | NcsiUwpApp, de Microsoft | Publisher | No |
| Allow | Everyone | Microsoft.LockApp, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | RealtekSemiconductorCorp.HPAudioControl, de Realtek Semiconductor Corp | Publisher | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | Microsoft.SecHealthUI, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | E2A4F912-2574-4A75-9BB0-0D023378592B, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.DesktopAppInstaller, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.BioEnrollment, de Microsoft Corporation | Publisher | No |
| Allow | NT AUTHORITY\SYSTEM | "", version 0.0.0.0 versions ultérieures, depuis Microsoft | Publisher | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | Microsoft.XboxGameCallableUI, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.Windows.CallingShellApp, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.Windows.ShellExperienceHost, de Microsoft Corporation | Publisher | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | Microsoft.BingNews, de Microsoft Corporation | Publisher | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | Microsoft.Todos, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.Windows.StartMenuExperienceHost, de ms-resource:StartMenuExperienceHost/PublisherDisplayName | Publisher | No |
| Allow | Everyone | Microsoft.Windows.PeopleExperienceHost, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.Windows.Photos, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.Windows.PinningConfirmationDialog, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.AccountsControl, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.Windows.AssignedAccessLockApp, de Microsoft Corporation | Publisher | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | Microsoft.PowerAutomateDesktop, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.CredDialogHost, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.Windows.CloudExperienceHost, de E-mail, téléphone ou Skype | Publisher | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | Clipchamp.Clipchamp, de Microsoft Corp. | Publisher | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | Microsoft.Windows.Search, de CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US | Publisher | No |
| Allow | Everyone | Windows.CBSPreview, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.Windows.ContentDeliveryManager, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.AsyncTextService, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | MicrosoftWindows.Client.CBS, de Microsoft Windows | Publisher | No |
| Allow | Everyone | Microsoft.ECApp, de Microsoft Corporation | Publisher | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | Microsoft.WindowsNotepad, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | 1527c705-839a-4832-9118-54d4Bd6a0c89, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | c5e2524a-ea46-4f67-841f-6a9465d9d515, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.Windows.SecureAssessmentBrowser, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.BioEnrollment, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.Windows.ContentDeliveryManager, de Microsoft Corporation | Publisher | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | Microsoft.Windows.Apprep.ChxApp, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | NcsiUwpApp, de Microsoft | Publisher | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | Microsoft.GamingApp, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | RealtekSemiconductorCorp.RealtekAudioControl, de Realtek Semiconductor Corp | Publisher | No |
| Allow | NT AUTHORITY\NETWORK SERVICE | Signé par Microsoft Corporation | Publisher | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | MicrosoftCorporationII.QuickAssist, de Microsoft Corp. | Publisher | No |
| Allow | Everyone | Microsoft.Windows.PrintQueueActionCenter, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.SecHealthUI, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.Windows.CapturePicker, de Microsoft Corporation | Publisher | No |
| Allow | NT AUTHORITY\SYSTEM | MicrosoftWindows.Client.WebExperience, de Microsoft Windows | Publisher | No |
| Allow | Everyone | Microsoft.Win32WebViewHost, de Microsoft Corporation | Publisher | No |
| Allow | NT AUTHORITY\SYSTEM | Microsoft.WindowsStore, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.WindowsStore, de Microsoft Corporation | Publisher | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | Microsoft.WindowsTerminal, de Microsoft Corporation | Publisher | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | Microsoft.BingSearch, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.MicrosoftEdgeDevToolsClient, de Microsoft Corporation | Publisher | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | Microsoft.Windows.ContentDeliveryManage de Microsoft Corporation | Publisher | No |
| Allow | Everyone | Windows.PrintDialog, de Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.MicrosoftEdge.Stable, de Microsoft Corporation | Publisher | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | Microsoft.WindowsStore, de Microsoft Corporation | Publisher | No |
| Policy | Setting |
|---|---|
| Enforce rules of this type | True |
| Action | User | Name | Rule Type | Exceptions |
|---|---|---|---|---|
| Allow | Everyone | FILESYNCCONFIG.EXE, dans MICROSOFT ONEDRIVE, de O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | WORDPAD.EXE, dans MICROSOFT® WINDOWS® OPERATING SYSTEM, de O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Allow | Everyone | TEAMS.EXE, dans MICROSOFT TEAMS, de O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | POWERSHELL_ISE.EXE, dans MICROSOFT® WINDOWS® OPERATING SYSTEM, de O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Allow | Everyone | UPDATE.EXE, dans MICROSOFT TEAMS, de O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | MMC.EXE, dans MICROSOFT® WINDOWS® OPERATING SYSTEM, de O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Allow | Everyone | ONEDRIVE.EXE, dans MICROSOFT ONEDRIVE, de O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Allow | Everyone | WEXTRACT.EXE .MUI, dans INTERNET EXPLORER, de O=CITRIX SYSTEMS, INC., L=FORT LAUDERDALE, S=FLORIDA, C=US | Publisher | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | POWERSHELL.EXE, dans MICROSOFT® WINDOWS® OPERATING SYSTEM, de O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Allow | Everyone | \\emea.tpg.ads\sysvol\emea.tpg.ads\Policies\* | Path | No |
| Allow | Everyone | \\emea.tpg.ads\sysvol\emea.tpg.ads\Policies\*\User\Scripts\Logon\Logsession.exe | Path | No |
| Allow | Everyone | %OSDRIVE%\PROGRAMDATA\*\SQUIRRELTEMP\* | Path | No |
| Allow | NT AUTHORITY\SYSTEM | Tous les fichiers | Path | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | %OSDRIVE%\USERS\Downloads\*.vbs | Path | No |
| Allow | NT AUTHORITY\NETWORK SERVICE | Tous les fichiers | Path | No |
| Allow | Everyone | %OSDRIVE%\*\Zoiper.exe | Path | No |
| Allow | Everyone | %OSDRIVE%\TPBlackout\* | Path | No |
| Allow | Everyone | C:\ProgramData\Microsoft\GroupPolicy\* | Path | No |
| Allow | Everyone | \\emea.tpg.ads\sysvol\emea.tpg.ads\Policies\*\User\Scripts\Logoff\Logsession.exe | Path | No |
| Allow | Everyone | %OSDRIVE%\*\TPBlackout.exe | Path | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | %OSDRIVE%\USERS\Downloads\*.vb | Path | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | %OSDRIVE%\USERS\Downloads\*.exe | Path | No |
| Allow | Everyone | (Règle par défaut) Tous les fichiers se trouvant dans le dossier Program Files | Path | No |
| Allow | Everyone | %OSDRIVE%\USERS\*\APPDATA\LOCAL\SQUIRRELTEMP\* | Path | No |
| Allow | Everyone | (Règle par défaut) Tous les fichiers se trouvant dans le dossier Windows | Path | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | %OSDRIVE%\USERS\Downloads\*.bat | Path | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | %OSDRIVE%\USERS\Downloads\*.ps1 | Path | No |
| Allow | Everyone | %OSDRIVE%\USERS\*\APPDATA\LOCAL\MICROSOFT\TEAMS\CURRENT\SQUIRREL.EXE | Path | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | %OSDRIVE%\USERS\Downloads\*.cmd | Path | No |
| Allow | Everyone | %OSDRIVE%\USERS\*\APPDATA\LOCAL\CITRIX\AGEE\* | Path | No |
| Allow | Everyone | %OSDRIVE%\USERS\*\AppData\Roaming\Microsoft\Teams\tmp\* | Path | No |
| Deny | EMEA\MG-L-SEC-Disable Win11 Features | %OSDRIVE%\USERS\Downloads\*.msi | Path | No |
| Allow | BUILTIN\Administrators | (Règle par défaut) Tous les fichiers | Path | No |
| Policy | Setting |
|---|---|
| Enforce rules of this type | True |
| Policy | Setting | Comment |
|---|---|---|
| Allow users to enable online speech recognition services | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off automatic learning | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| IPv6 Configuration Policy | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Prevent use of Offline Files folder | Enabled | |||
| Prohibit user configuration of Offline Files | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Continue experiences on this device | Disabled | Désactivé pour bloquer le partage de proximité (Nearby Sharing) de la zone d'accès rapide |
| Policy | Setting | Comment |
|---|---|---|
| Turn off access to the Store | Enabled | |
| Turn off handwriting personalization data sharing | Enabled | |
| Turn off handwriting recognition error reporting | Enabled | |
| Turn off Help and Support Center "Did you know?" content | Enabled | |
| Turn off the Windows Messenger Customer Experience Improvement Program | Enabled | |
| Turn off Windows Error Reporting | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow publishing of User Activities | Disabled | |
| Allow upload of User Activities | Disabled | |
| Enables Activity Feed | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn Off the hard disk (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Allow standby states (S1-S3) when sleeping (on battery) | Disabled | |
| Allow standby states (S1-S3) when sleeping (plugged in) | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow restore of system to default state | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Configuration | Enabled | |
| Turn off System Restore | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not log users on with temporary profiles | Enabled | |
| Turn off the advertising ID | Enabled |
| Policy | Setting | Comment | ||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Let Windows apps access account information | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access call history | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access contacts | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access diagnostic information about other apps | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access email | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access location | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access messaging | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access motion | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access notifications | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access Tasks | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access the calendar | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access the camera | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access the microphone | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access trusted devices | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps communicate with unpaired devices | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps control radios | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps make phone calls | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps run in the background | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Remove Program Compatibility Property Page | Enabled | |
| Turn off Application Compatibility Engine | Enabled | |
| Turn off Application Telemetry | Enabled | |
| Turn off Inventory Collector | Enabled | |
| Turn off Program Compatibility Assistant | Enabled | |
| Turn off Steps Recorder | Enabled | |
| Turn off SwitchBack Compatibility Engine | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Disallow Autoplay for non-volume devices | Enabled | |||
| Prevent AutoPlay from remembering user choices. | Enabled | |||
| Set the default behavior for AutoRun | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn off Autoplay | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Do not show Windows tips | Enabled | |
| Turn off Microsoft consumer experiences | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Allow Diagnostic Data | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Configure the Commercial ID | Disabled | |||
| Do not show feedback notifications | Enabled | |||
| Limit optional diagnostic data for Desktop Analytics | Disabled | |||
| Toggle user control over Insider builds | Disabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Turn off desktop gadgets | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Do not show the 'new application installed' notification | Enabled | |||
| Start File Explorer with ribbon minimized | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off File History | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn On/Off Find My Device | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off downloading of game information | Enabled | |
| Turn off game updates | Enabled | |
| Turn off tracking of last play time of games in the Games folder | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off location | Enabled | |
| Turn off sensors | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Windows Location Provider | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Block all consumer Microsoft account user authentication | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Microsoft Defender Antivirus | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Configure local setting override for reporting to Microsoft MAPS | Disabled | |||
| Join Microsoft MAPS | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Send file samples when further analysis is required | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Monitor file and program activity on your computer | Disabled | |
| Turn off real-time protection | Disabled | |
| Turn on behavior monitoring | Disabled | |
| Turn on process scanning whenever real-time protection is enabled | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Prevent OneDrive files from syncing over metered connections | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Prevent OneDrive from generating network traffic until the user signs in to OneDrive | Enabled | |||
| Prevent the usage of OneDrive for file storage | Enabled | |||
| Prevent the usage of OneDrive for file storage on Windows 8.1 | Enabled | |||
| Save documents to OneDrive by default | Disabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Turn off Active Help | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Push To Install service | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Allow Cloud Search | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow Cortana | Disabled | |||
| Allow Cortana above lock screen | Disabled | |||
| Allow indexing of encrypted files | Disabled | |||
| Allow search and Cortana to use location | Disabled | |||
| Do not allow web search | Enabled | |||
| Don't search the web or display web results in Search | Enabled | |||
| Fully disable Search UI | Enabled | |||
| Set what information is shared in Search | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Turn on Security Center (Domain PCs only) | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow Automatic Update of Speech Data | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off automatic learning | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow widgets | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Configure Windows Defender SmartScreen | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Automatically send memory dumps for OS-generated error reports | Disabled | |
| Disable Windows Error Reporting | Enabled | |
| Do not send additional data | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Enables or disables Windows Game Recording and Broadcasting | Disabled |
| Action | Update |
| Destination file | C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group1 |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Enabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Supprime le bloc 1 du clic-droit sur le menu Démarrer |
| Action | Update |
| Destination file | C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2 |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Enabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Supprime le bloc 2 du clic-droit sur le menu Démarrer |
| Action | Update |
| Destination file | C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3 |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Enabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Supprime le bloc 3 du clic-droit sur le menu Démarrer |
| Action | Create |
| Source file(s) | \\emea.tpg.ads\sysvol\emea.tpg.ads\Policies\{B9F26EE0-AA89-40C4-A477-E95D07DC17C0}\Machine\Scripts\Bloc-Notes.lnk |
| Destination file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Bloc-Notes.lnk |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Disabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows Defender |
| Value name | DisableAntiSpyware |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| DisableAntiSpyware désactive l'antivirus Microsoft Defender |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows\CloudContent |
| Value name | DisableWindowsConsumerFeatures |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Désactive les expériences Windows, les recommandations personnalisées de Microsoft |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Services\SecurityHealthService |
| Value name | Start |
| Value type | REG_DWORD |
| Value data | 0x3 (3) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Désactive le service Security Center au démarrage |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Config |
| Value name | DownloadMode |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Mode de téléchargement des mises à jours Windows, désactive le peering |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System |
| Value name | EnableFirstLogonAnimation |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Désactive l’animation de première connexion sur Windows 10 / 11 |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\services\USBSTOR |
| Value name | Start |
| Value type | REG_DWORD |
| Value data | 0x4 (4) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Désactive les pilotes de stockage USB (Mass Storage) |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{031E4825-7B94-4dc3-B131-E946B44C8DD} |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Supprime Bibliothèques du profil user |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{1CF1260C-4DD0-4ebb-811F-33C572699FDE} |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Supprime Musiques du profil user |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{374DE290-123F-4565-9164-39C4925E467B} |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Supprime Téléchargements du profil user |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{3ADD1653-EB32-4cb0-BBD7-DFA0ABB5ACCA} |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Supprime Images du profil user |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{A0953C92-50DC-43bf-BE83-3742FED03C9C} |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Supprime Vidéos du profil user |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0} |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Supprime Documents du profil user |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641} |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Supprime Desktop du profil user |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{e88865ea-0e1c-4e20-9aa6-edcd0212c87c} |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Supprime Galerie du profil user |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{f874310e-b6b7-47dc-bc84-b9e6b38f5903} |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Supprime Accueil du profil user |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules |
| Value name | MicrosoftWindows.Client.CBS-WebExperienceHostApp.exe |
| Value type | REG_SZ |
| Value data | v2.32|Action=Block|Active=TRUE|Dir=Out|App=C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\WebExperienceHostApp.exe|Name=Blocage du flux WebExperienceHostApp.exe|Desc=Blocage du flux WebExperienceHostApp.exe| |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Blocage du flux FireWall sur WebExperienceHostApp.exe |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\PolicyManager\default\Connectivity\AllowBluetooth |
| Value name | value |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Désactive le Bluetooth et le masque de la Zone notification |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\ActionCenter\Quick Actions\All\SystemSettings_Device_BluetoothQuickAction |
| Value name | Type |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Masqiue le Bluetooth la Zone notification QuickAction |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | Software\Policies\Microsoft\Windows\AppPrivacy |
| Value name | LetAppsAccessMicrophone |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Supprime la restriction micro dans Confidentialité et Sécurité |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\PolicyManager\current\device\Education |
| Value name | IsEducationEnvironment |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Bloque la partie recommandation du menu Démarrer |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows\Explorer |
| Value name | HideRecommendedSection |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Bloque la partie recommandation du menu Démarrer |
| Action | Delete |
| Hive | HKEY_CLASSES_ROOT |
| Key path | Applications\notepad.exe |
| Value name | NoOpenWith |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Rajoute l'ancien Bloc-Notes (C:\Windows\notepad.exe) aux applications utilisables |
| Action | Create |
| Hive | HKEY_CLASSES_ROOT |
| Key path | txtfilelegacy\DefaultIcon |
| Value name | (Default) |
| Value type | REG_SZ |
| Value data | imageres.dll,-102 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Rajoute l'ancien Bloc-Notes (C:\Windows\notepad.exe) aux applications utilisables |
| Action | Create |
| Hive | HKEY_CLASSES_ROOT |
| Key path | txtfilelegacy\shell\open\command |
| Value name | (Default) |
| Value type | REG_SZ |
| Value data | C:\Windows\System32\notepad.exe "%1" |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Rajoute l'ancien Bloc-Notes (C:\Windows\notepad.exe) aux applications utilisables |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\notepad.exe |
| Value name | UseFilter |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Rajoute l'ancien Bloc-Notes (C:\Windows\notepad.exe) aux applications utilisables |