| PT-PO-WIN-U-Windows 11 Hardening PCI | |
| Data collected on: 2-9-2025 12:10:00 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\brighton.6-adm |
| Created | 20-6-2024 10:20:32 |
| Modified | 7-3-2025 19:43:32 |
| User Revisions | 296 (AD), 296 (SYSVOL) |
| Computer Revisions | 0 (AD), 0 (SYSVOL) |
| Unique ID | {3bd6b34e-c642-4aba-89a8-e55184d8dda1} |
| GPO Status | Computer settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| PT | No | Enabled | emea.tpg.ads/PT |
| Name |
|---|
| None |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\PT-G-ORG-Exceptions Visual Aid W11 | Custom | No |
| Name | Parameters |
|---|---|
| DisableDesktop.ps1 | |
| Restore_PWA_Edge_Chrome.ps1 |
| Enforcement | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Designated File Types | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Trusted Publishers | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
| Policy | Setting |
|---|---|
| Default Security Level | Unrestricted |
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% | ||||||
| ||||||
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% | ||||||
|
| Policy | Setting | Comment |
|---|---|---|
| Prohibit access to Control Panel and PC settings | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent changing desktop background | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not add shares of recently opened documents to Network Locations | Enabled | |
| Hide and disable all items on the desktop | Enabled | |
| Hide Network Locations icon on desktop | Enabled | |
| Prevent adding, dragging, dropping and closing the Taskbar's toolbars | Enabled | |
| Prohibit User from manually redirecting Profile Folders | Enabled | |
| Remove Properties from the Computer icon context menu | Enabled | |
| Remove Properties from the Recycle Bin context menu | Enabled | |
| Remove Recycle Bin icon from desktop | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Enable Translate | Disabled |
| Policy | Setting | Comment | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Allow importing of payment info | Disabled | |||||||||
| Allow importing of saved passwords | Disabled | |||||||||
| Allow or deny screen capture | Disabled | |||||||||
| Block access to a list of URLs | Enabled | |||||||||
| ||||||||||
| Policy | Setting | Comment | ||||||||
| Control where developer tools can be used | Enabled | |||||||||
| ||||||||||
| Policy | Setting | Comment | ||||||||
| Define a list of allowed URLs | Enabled | |||||||||
| ||||||||||
| Policy | Setting | Comment | ||||||||
| Enable AutoFill for addresses | Disabled | |||||||||
| Enable AutoFill for payment instruments | Disabled | |||||||||
| Enable the Collections feature | Disabled | |||||||||
| Enable the Screenshot (previously named Web Capture) feature in Microsoft Edge | Disabled | |||||||||
| Hide the First-run experience and splash screen | Enabled | |||||||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Configure cookies | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Control which extensions cannot be installed | Enabled | |||||
| ||||||
| Policy | Setting | Comment |
|---|---|---|
| Enable saving passwords to the password manager | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow shared folders to be published | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Clear history of recently opened documents on exit | Enabled | |||
| Clear tile notifications during log on | Enabled | |||
| Disable context menus in the Start Menu | Enabled | |||
| Disable showing balloon notifications as toasts. | Enabled | |||
| Do not allow pinning items in Jump Lists | Enabled | |||
| Do not allow pinning programs to the Taskbar | Enabled | |||
| Do not allow pinning Store app to the Taskbar | Enabled | |||
| Do not display any custom toolbars in the taskbar | Enabled | |||
| Do not display or track items in Jump Lists from remote locations | Enabled | |||
| Do not keep history of recently opened documents | Enabled | |||
| Do not use the search-based method when resolving shell shortcuts | Enabled | |||
| Force Start to be either full screen size or menu size | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Hide the notification area | Enabled | |||
| Lock all taskbar settings | Enabled | |||
| Lock the Taskbar | Enabled | |||
| Prevent changes to Taskbar and Start Menu Settings | Enabled | |||
| Prevent users from adding or removing toolbars | Enabled | |||
| Prevent users from customizing their Start Screen | Enabled | |||
| Prevent users from moving taskbar to another screen dock location | Enabled | |||
| Prevent users from rearranging toolbars | Enabled | |||
| Prevent users from resizing the taskbar | Enabled | |||
| Prevent users from uninstalling applications from Start | Enabled | |||
| Remove "Recently added" list from Start Menu | Enabled | |||
| Remove access to the context menus for the taskbar | Enabled | |||
| Remove All Programs list from the Start menu | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Remove common program groups from Start Menu | Enabled | |||
| Remove links and access to Windows Update | Enabled | |||
| Remove Notifications and Action Center | Not Configured | This policy makes the keyboard layouts not working | ||
| Remove pinned programs from the Taskbar | Not Configured | Enable for File Explorer and Microsoft Edge Pinned Taskbar | ||
| Remove Quick Settings | Enabled | |||
| Remove Recommended section from Start Menu | Enabled | |||
| Remove See More Results / Search Everywhere link | Enabled | |||
| Remove the Meet Now icon | Enabled | |||
| Remove the networking icon | Enabled | |||
| Remove the People Bar from the taskbar | Enabled | |||
| Remove the Security and Maintenance icon | Enabled | |||
| Remove the volume control icon | Disabled | Show Volume | ||
| Show or hide "Most used" list from Start menu | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Show QuickLaunch on Taskbar | Enabled | |||
| Show Start on the display the user is using when they press the Windows logo key | Enabled | |||
| Show the Apps view automatically when the user goes to Start | Disabled | |||
| Show Windows Store apps on the taskbar | Disabled | |||
| Turn off all balloon notifications | Enabled | |||
| Turn off automatic promotion of notification icons to the taskbar | Enabled | |||
| Turn off feature advertisement balloon notifications | Enabled | |||
| Turn off notification area cleanup | Enabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Turn off notification mirroring | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Do not display the Getting Started welcome screen at logon | Enabled | |||
| Prevent access to registry editing tools | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Prevent access to the command prompt | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Remove Task Manager | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| All Removable Storage classes: Deny all access | Enabled | |
| CD and DVD: Deny read access | Enabled | |
| CD and DVD: Deny write access | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Default risk level for file attachments | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not preserve zone information in file attachments | Enabled | |||
| Inclusion list for low file types | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Configure Windows spotlight on lock screen | Disabled | |
| Do not suggest third-party content in Windows spotlight | Enabled | |
| Do not use diagnostic data for tailored experiences | Enabled | |
| Turn off all Windows spotlight features | Enabled | |
| Turn off the Windows Welcome Experience | Enabled | |
| Turn off Windows Spotlight on Action Center | Enabled | |
| Turn off Windows Spotlight on Settings | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Do not allow Folder Options to be opened from the Options button on the View tab of the ribbon | Enabled | |||
| Hide these specified drives in My Computer | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Hides the Manage item on the File Explorer context menu | Enabled | |||
| Prevent access to drives from My Computer | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Remove "Map Network Drive" and "Disconnect Network Drive" | Enabled | |||
| Remove CD Burning features | Enabled | |||
| Remove DFS tab | Enabled | |||
| Remove File Explorer's default context menu | Enabled | |||
| Remove File menu from File Explorer | Enabled | |||
| Remove Hardware tab | Enabled | |||
| Remove Security tab | Enabled | |||
| Remove the Search the Internet "Search again" link | Enabled | |||
| Turn off caching of thumbnail pictures | Enabled | |||
| Turn off display of recent search entries in the File Explorer search box | Enabled | |||
| Turn off Windows Key hotkeys | Enabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Hide previous versions list for remote files | Enabled | |
| Prevent restoring remote previous versions | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Restrict users to the explicitly permitted list of snap-ins | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Computer Management | Enabled | |
| Local Users and Groups | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off the offer to update to the latest version of Windows | Enabled | |
| Turn off the Store application | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Windows Copilot | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not allow Windows Messenger to be run | Enabled | |
| Do not automatically start Windows Messenger initially | Enabled |
| Action | Delete |
| Destination file | %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows System\Run.lnk |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Destination file | %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows System\Control Panel.lnk |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Destination file | %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows System\Command Prompt.lnk |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Update |
| Path | %USERPROFILE%\AppData\Local\Microsoft\Windows\WinX\Group2 |
| Read-only | Disabled |
| Hidden | Enabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Path | %USERPROFILE%\AppData\Local\Microsoft\Windows\WinX\Group3 |
| Read-only | Disabled |
| Hidden | Enabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Path | %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell |
| Delete this folder (if emptied) | Enabled |
| Recursively delete all subfolders (if emptied) | Enabled |
| Delete all files in the folder(s) | Enabled |
| Allow deletion of read-only files/folders | Enabled |
| Ignore errors for files/folders that cannot be deleted | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Path | %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows System |
| Delete this folder (if emptied) | Enabled |
| Recursively delete all subfolders (if emptied) | Enabled |
| Delete all files in the folder(s) | Enabled |
| Allow deletion of read-only files/folders | Enabled |
| Ignore errors for files/folders that cannot be deleted | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{031E4825-7B94-4dc3-B131-E946B44C8DD5} |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer |
| Value name | NoRun |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_CURRENT_USER |
| Key path | Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
| Value name | NoRun |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{26EE0668-A00A-44D7-9371-BEB064C98683} |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0} |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_CURRENT_USER |
| Key path | Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum |
| Value name | {59031a47-3f72-44a7-89c5-5595fe6b30ee} |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Control Panel\Accessibility\Keyboard Response |
| Value name | AutoRepeatDelay |
| Value type | REG_SZ |
| Value data | 0 |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Control Panel\Accessibility\Keyboard Response |
| Value name | AutoRepeatRate |
| Value type | REG_SZ |
| Value data | 0 |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Control Panel\Accessibility\Keyboard Response |
| Value name | BounceTime |
| Value type | REG_SZ |
| Value data | 0 |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Control Panel\Accessibility\Keyboard Response |
| Value name | DelayBeforeAcceptance |
| Value type | REG_SZ |
| Value data | 0 |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Control Panel\Accessibility\Keyboard Response |
| Value name | Flags |
| Value type | REG_SZ |
| Value data | 31 |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Control Panel\Accessibility\Keyboard Response |
| Value name | Last BounceKey Setting |
| Value type | REG_DWORD |
| Value data | 0x1F4 (500) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Control Panel\Accessibility\Keyboard Response |
| Value name | Last Valid Delay |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Control Panel\Accessibility\Keyboard Response |
| Value name | Last Valid Repeat |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Control Panel\Accessibility\Keyboard Response |
| Value name | Last Valid Wait |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | software\policies\microsoft\office\16.0\common\insert media\screenshot |
| Value name | disablescreenclippings |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced |
| Value name | TaskbarMn |
| Value type | REG_SZ |
| Value data | 0 |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |