Group Policy Management
body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } }
Setting Path:
Explanation
No explanation is available for this setting.
Supported On:
Not available
PT-PO-WIN-C-Windows 11 Hardening PCI - Deny Camera
Data collected on: 2-9-2025 13:17:01
General
Details
Domainemea.tpg.ads
OwnerEMEA\brighton.6-adm
Created18-8-2025 12:42:02
Modified18-8-2025 13:07:40
User Revisions3 (AD), 3 (SYSVOL)
Computer Revisions4 (AD), 4 (SYSVOL)
Unique ID{ee769556-df06-4ed4-a34f-c8ee21d2429e}
GPO StatusUser settings disabled
Links
LocationEnforcedLink StatusPath
ClientsNoEnabledemea.tpg.ads/PT/Systems/Clients

This list only includes links in the domain of the GPO.
Security Filtering
The settings in this GPO can only apply to the following groups, users, and computers:
Name
EMEA\PT-L-SEC-C-Windows 11 Hardening Deny Camera
Delegation
These groups and users have the specified permission for this GPO
NameAllowed PermissionsInherited
EMEA\brighton.6-admEdit settings, delete, modify securityNo
EMEA\Domain AdminsEdit settings, delete, modify securityNo
EMEA\PT-L-SEC-C-Windows 11 Hardening Deny CameraRead (from Security Filtering)No
EMEA\PT-L-SEC-Delegation Modify Group Policy Settings AccessEdit settings, delete, modify securityNo
NT AUTHORITY\Authenticated UsersReadNo
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSReadNo
NT AUTHORITY\SYSTEMEdit settings, delete, modify securityNo
ROOT\Enterprise AdminsEdit settings, delete, modify securityNo
Computer Configuration (Enabled)
Policies
Windows Settings
Scripts
Startup
For this GPO, Script order: Windows PowerShell scripts will run first
NameParameters
remove_winkey.bat
Security Settings
System Services
AppX Deployment Service (AppXSVC) (Startup Mode: Disabled)
Permissions
No permissions specified
Auditing
No auditing specified
Bluetooth Audio Gateway Service (Startup Mode: Disabled)
Permissions
No permissions specified
Auditing
No auditing specified
Bluetooth Support Service (Startup Mode: Disabled)
Permissions
No permissions specified
Auditing
No auditing specified
Windows Defender Advanced Threat Protection Service (Startup Mode: Disabled)
Permissions
No permissions specified
Auditing
No auditing specified
Microsoft Defender Antivirus Network Inspection Service (Startup Mode: Disabled)
Permissions
No permissions specified
Auditing
No auditing specified
Microsoft Defender Antivirus Service (Startup Mode: Disabled)
Permissions
No permissions specified
Auditing
No auditing specified
WMI Performance Adapter (Startup Mode: Automatic)
Permissions
No permissions specified
Auditing
No auditing specified
File System
%SystemRoot%\System32\osk.exe
Configure this file or folder then: Propagate inheritable permissions to all subfolders and files
Owner
Permissions
TypeNamePermissionApply To
DenyAPPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGESFull ControlThis folder, subfolders and files
Allow inheritable permissions from the parent to propagate to this object and all child objectsDisabled
Auditing
No auditing specified
Software Restriction Policies
Enforcement
PolicySetting
Apply Software Restriction Policies to the followingAll software files except libraries (such as DLLs)
Apply Software Restriction Policies to the following usersAll users
When applying Software Restriction PoliciesIgnore certificate rules
Designated File Types
File ExtensionFile Type
ADEADE File
ADPADP File
BASBAS File
BATWindows Batch File
CHMCompiled HTML Help file
CMDWindows Command Script
COMMS-DOS Application
CPLControl panel item
CRTSecurity Certificate
EXEApplication
HLPHelp file
HTAHTML Application
INFSetup Information
INSINS File
ISPISP File
LNKShortcut
MDBMDB File
MDEMDE File
MSCMicrosoft Common Console Document
MSIWindows Installer Package
MSPWindows Installer Patch
MSTMST File
OCXActiveX control
PCDPCD File
PIFShortcut to MS-DOS Program
REGRegistration Entries
SCRScreen saver
SHSSHS File
URLInternet Shortcut
VBVisual Basic Source File
WSCWindows Script Component
Trusted Publishers
Trusted publisher managementAllow all administrators and users to manage user's own Trusted Publishers
Certificate verificationNone
Software Restriction Policies/Security Levels
PolicySetting
Default Security LevelUnrestricted
Software Restriction Policies/Additional Rules
Path Rules
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%
Security LevelUnrestricted
Description
Date last modified2-7-2024 11:47:48
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir%
Security LevelUnrestricted
Description
Date last modified2-7-2024 11:47:48
C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy
Security LevelDisallowed
DescriptionDeny Search
Date last modified2-7-2024 11:48:28
C:\Windows\SystemApps\Microsoft.Windows.Search*
Security LevelDisallowed
DescriptionDeny Search
Date last modified2-7-2024 11:48:47
Administrative Templates
Policy definitions (ADMX files) retrieved from the central store.
Control Panel
PolicySettingComment
Allow Online TipsDisabled
Google/Google Chrome
PolicySettingComment
Allow user feedbackDisabled
Google/Google Chrome/Google Cast
PolicySettingComment
Enable Google CastDisabled
Show the Google Cast toolbar iconDisabled
Microsoft Edge
PolicySettingComment
Ads setting for sites with intrusive adsEnabled
Ads setting for sites with intrusive adsBlock ads on sites with intrusive ads. (Default value)
PolicySettingComment
Allow user feedbackDisabled
Microsoft Edge/Cast
PolicySettingComment
Enable Google CastDisabled
Show the cast icon in the toolbarDisabled
System/Group Policy
PolicySettingComment
Configure Logon Script DelayEnabled
minute:1
System/Logon
PolicySettingComment
Show first sign-in animation Disabled
System/Troubleshooting and Diagnostics/Scheduled Maintenance
PolicySettingComment
Configure Scheduled Maintenance BehaviorDisabled
Windows Components/App Privacy
PolicySettingComment
Let Windows apps access account informationEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access an eye tracker deviceEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access call historyEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access contactsEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access diagnostic information about other appsEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access emailEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access locationEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access messagingEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access motionEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access notificationsEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access TasksEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access the calendarEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access the cameraEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access the microphoneEnabled
Default for all apps:Force Allow
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access trusted devicesEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps communicate with unpaired devicesEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps control radiosEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps make phone callsEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps run in the backgroundEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
Windows Components/Application Compatibility
PolicySettingComment
Turn off Application TelemetryEnabled
Turn off Inventory CollectorEnabled
Turn off Steps RecorderEnabled
Windows Components/Cloud Content
PolicySettingComment
Do not show Windows tipsEnabled
Turn off Microsoft consumer experiencesEnabled
Windows Components/Data Collection and Preview Builds
PolicySettingComment
Allow Diagnostic DataEnabled
Send required diagnostic data
PolicySettingComment
Do not show feedback notificationsEnabled
Windows Components/Location and Sensors
PolicySettingComment
Turn off locationEnabled
Turn off sensorsEnabled
Windows Components/Microsoft Defender Antivirus
PolicySettingComment
Turn off Microsoft Defender AntivirusDisabled
Windows Components/Microsoft Defender Antivirus/Client Interface
PolicySettingComment
Enable headless UI modeDisabled
Windows Components/Microsoft Edge
PolicySettingComment
Configure Password ManagerDisabled
Windows Components/News and interests
PolicySettingComment
Enable news and interests on the taskbarDisabled
Windows Components/OneDrive
PolicySettingComment
Prevent the usage of OneDrive for file storageEnabled
Windows Components/Online Assistance
PolicySettingComment
Turn off Active HelpEnabled
Windows Components/Remote Desktop Services/Remote Desktop Session Host/Remote Session Environment
PolicySettingComment
Remove Windows Security item from Start menuEnabled
Windows Components/Search
PolicySettingComment
Allow CortanaDisabled
Allow Cortana above lock screenDisabled
Do not allow web searchEnabled
Don't search the web or display web results in SearchEnabled
Fully disable Search UIEnabled
Windows Components/Security Center
PolicySettingComment
Turn on Security Center (Domain PCs only)Enabled
Windows Components/Store
PolicySettingComment
Disable all apps from Microsoft Store Enabled
Turn off Automatic Download and Install of updatesEnabled
Turn off the offer to update to the latest version of WindowsEnabled
Turn off the Store applicationEnabled
Windows Components/Sync your settings
PolicySettingComment
Do not syncEnabled
Allow users to turn syncing on.Disabled
PolicySettingComment
Do not sync personalizeEnabled
Allow users to turn "personalize" syncing on.Disabled
Windows Components/Widgets
PolicySettingComment
Allow widgetsDisabled
Windows Components/Windows Error Reporting
PolicySettingComment
Disable Windows Error ReportingEnabled
Windows Components/Windows Game Recording and Broadcasting
PolicySettingComment
Enables or disables Windows Game Recording and BroadcastingDisabled
Windows Components/Windows Hello for Business
PolicySettingComment
Use Windows Hello for BusinessDisabled
Windows Components/Windows Ink Workspace
PolicySettingComment
Allow suggested apps in Windows Ink WorkspaceDisabled
Windows Components/Windows Mail
PolicySettingComment
Turn off Windows Mail applicationEnabled
Windows Components/Windows Media Player
PolicySettingComment
Do Not Show First Use Dialog BoxesEnabled
Prevent Automatic UpdatesEnabled
Prevent Desktop Shortcut CreationEnabled
Prevent Media SharingEnabled
Prevent Quick Launch Toolbar Shortcut CreationEnabled
Windows Components/Windows Messenger
PolicySettingComment
Do not allow Windows Messenger to be runEnabled
Do not automatically start Windows Messenger initiallyEnabled
Windows Components/Windows Mobility Center
PolicySettingComment
Turn off Windows Mobility CenterEnabled
Windows Components/Windows PowerShell
PolicySettingComment
Turn on Script ExecutionEnabled
Execution PolicyAllow all scripts
Windows Components/Windows Security/Systray
PolicySettingComment
Hide Windows Security SystrayEnabled
Preferences
Windows Settings
Files
File (Target Path: C:\Bin\DeleteXMLFilesAltitude.ps1)
DeleteXMLFilesAltitude.ps1 (Order: 1)
General
ActionReplace
Properties
Source file(s)\\emea.tpg.ads\pt\Lisbon-CIT\Clients\Settings\GPO\Scripts\Altitude\DeleteXMLFilesAltitude.ps1
Destination fileC:\Bin\DeleteXMLFilesAltitude.ps1
Suppress errors on individual file actionsDisabled
Attributes
Read-onlyDisabled
HiddenDisabled
ArchiveEnabled
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedYes
Control Panel Settings
Scheduled Tasks
Scheduled Task (At least Windows 7) (Name: AltitudeDeleteXMLFiles)
AltitudeDeleteXMLFiles (Order: 1)
General
ActionReplace
Task
Name AltitudeDeleteXMLFiles
Author EMEA\brighton.6-adm
Description
Run only when user is logged on InteractiveToken
UserId %LogonDomain%\%LogonUser%
Run with highest privileges HighestAvailable
Hidden No
Configure for 1.3
Enabled Yes
Triggers
1. Run at user logon
Delay task for 30 seconds
Activate 2-7-2024 16:04:20Synchronize across time zones No
Enabled Yes
Actions
1. Start a program
Program/script %SystemRoot%\system32\WindowsPowerShell\v1.0\powershell.exe
Arguments -ExecutionPolicy Bypass -File "C:\Bin\DeleteXMLFilesAltitude.ps1"
Settings
Stop if the computer ceases to be idle No
Restart if the idle state resumes No
Start the task only if the computer is on AC power No
Stop if the computer switches to battery power No
Allow task to be run on demand No
Stop task if it runs longer than 2 hours
If the running task does not end when requested, force it to stop No
If the task is already running, then the following rule applies IgnoreNew
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedYes
User Configuration (Disabled)
No settings defined.