| PT-PO-WIN-U-Windows 11 Hardening v1 | |
| Data collected on: 2-9-2025 10:21:09 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\silva.12303-adm |
| Created | 8-4-2022 10:40:22 |
| Modified | 4-4-2025 10:54:32 |
| User Revisions | 122 (AD), 122 (SYSVOL) |
| Computer Revisions | 3 (AD), 3 (SYSVOL) |
| Unique ID | {9857adf4-bdf5-4d53-aeaa-02bbfa2f63d0} |
| GPO Status | Computer settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| PT | No | Enabled | emea.tpg.ads/PT |
| Name |
|---|
| None |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\PT-L-SEC-U-W11 Hardening PCI | Custom | No |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Prohibit access to Control Panel and PC settings | Enabled | |||
| Settings Page Visibility | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Add Logoff to the Start Menu | Enabled | |||
| Add Search Internet link to Start Menu | Disabled | |||
| Add the Run command to the Start Menu | Disabled | |||
| Change Start Menu power button | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Clear history of recently opened documents on exit | Enabled | |||
| Clear the recent programs list for new users | Enabled | |||
| Clear tile notifications during log on | Enabled | |||
| Disable context menus in the Start Menu | Enabled | |||
| Disable showing balloon notifications as toasts. | Enabled | |||
| Do not allow pinning items in Jump Lists | Enabled | |||
| Do not allow pinning programs to the Taskbar | Enabled | |||
| Do not allow pinning Store app to the Taskbar | Enabled | |||
| Do not display any custom toolbars in the taskbar | Enabled | |||
| Do not display or track items in Jump Lists from remote locations | Enabled | |||
| Do not keep history of recently opened documents | Enabled | |||
| Do not search for files | Enabled | |||
| Do not search Internet | Enabled | |||
| Do not search programs and Control Panel items | Enabled | |||
| Do not use the search-based method when resolving shell shortcuts | Enabled | |||
| Force classic Start Menu | Enabled | |||
| Force Start to be either full screen size or menu size | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Go to the desktop instead of Start when signing in | Enabled | |||
| List desktop apps first in the Apps view | Enabled | |||
| Lock all taskbar settings | Enabled | |||
| Lock the Taskbar | Enabled | |||
| Prevent changes to Taskbar and Start Menu Settings | Enabled | |||
| Prevent grouping of taskbar items | Enabled | |||
| Prevent users from adding or removing toolbars | Enabled | |||
| Prevent users from customizing their Start Screen | Enabled | |||
| Prevent users from moving taskbar to another screen dock location | Enabled | |||
| Prevent users from rearranging toolbars | Enabled | |||
| Prevent users from resizing the taskbar | Enabled | |||
| Prevent users from uninstalling applications from Start | Enabled | |||
| Remove "Recently added" list from Start Menu | Enabled | |||
| Remove access to the context menus for the taskbar | Enabled | |||
| Remove All Programs list from the Start menu | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Remove Balloon Tips on Start Menu items | Enabled | |||
| Remove common program groups from Start Menu | Enabled | |||
| Remove Default Programs link from the Start menu. | Enabled | |||
| Remove Documents icon from Start Menu | Enabled | |||
| Remove Downloads link from Start Menu | Enabled | |||
| Remove Favorites menu from Start Menu | Enabled | |||
| Remove frequent programs list from the Start Menu | Enabled | |||
| Remove Games link from Start Menu | Enabled | |||
| Remove Help menu from Start Menu | Enabled | |||
| Remove Homegroup link from Start Menu | Enabled | |||
| Remove links and access to Windows Update | Enabled | |||
| Remove Music icon from Start Menu | Enabled | |||
| Remove Network Connections from Start Menu | Enabled | |||
| Remove Network icon from Start Menu | Enabled | |||
| Remove Notifications and Action Center | Disabled | Esta Policy activa, faz com que as linguagens de teclado fiquem inactivas | ||
| Remove Pictures icon from Start Menu | Enabled | |||
| Remove pinned programs from the Taskbar | Disabled | Enable for File Explorer and Microsoft Edge Pinned Taskbar | ||
| Remove pinned programs list from the Start Menu | Enabled | |||
| Remove programs on Settings menu | Enabled | |||
| Remove Quick Settings | Enabled | |||
| Remove Recent Items menu from Start Menu | Enabled | |||
| Remove Recorded TV link from Start Menu | Enabled | |||
| Remove Run menu from Start Menu | Enabled | |||
| Remove Search Computer link | Enabled | |||
| Remove Search link from Start Menu | Enabled | |||
| Remove See More Results / Search Everywhere link | Enabled | |||
| Remove the "Undock PC" button from the Start Menu | Enabled | |||
| Remove the battery meter | Disabled | |||
| Remove the Meet Now icon | Enabled | |||
| Remove the networking icon | Enabled | |||
| Remove the People Bar from the taskbar | Enabled | |||
| Remove the Security and Maintenance icon | Enabled | |||
| Remove the volume control icon | Disabled | Show Volume Icon | ||
| Remove user folder link from Start Menu | Enabled | |||
| Remove user's folders from the Start Menu | Enabled | |||
| Remove Videos link from Start Menu | Enabled | |||
| Search just apps from the Apps view | Enabled | |||
| Show "Run as different user" command on Start | Disabled | |||
| Show or hide "Most used" list from Start menu | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Show QuickLaunch on Taskbar | Enabled | |||
| Show Start on the display the user is using when they press the Windows logo key | Enabled | |||
| Show the Apps view automatically when the user goes to Start | Enabled | |||
| Show Windows Store apps on the taskbar | Disabled | |||
| Turn off all balloon notifications | Enabled | |||
| Turn off automatic promotion of notification icons to the taskbar | Enabled | |||
| Turn off feature advertisement balloon notifications | Enabled | |||
| Turn off notification area cleanup | Enabled | |||
| Turn off personalized menus | Enabled | |||
| Turn off taskbar thumbnails | Enabled | |||
| Turn off user tracking | Enabled | |||
| Policy | Setting | Comment |
|---|---|---|
| All Removable Storage classes: Deny all access | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Configure Windows spotlight on lock screen | Disabled | |
| Do not suggest third-party content in Windows spotlight | Enabled | |
| Do not use diagnostic data for tailored experiences | Enabled | |
| Turn off all Windows spotlight features | Enabled | |
| Turn off the Windows Welcome Experience | Enabled | |
| Turn off Windows Spotlight on Action Center | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off display of recent search entries in the File Explorer search box | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Disable changing home page settings | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off the offer to update to the latest version of Windows | Enabled | |
| Turn off the Store application | Enabled |
| Action | Delete |
| Destination file | %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows System\Run.lnk |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Destination file | %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows System\Control Panel.lnk |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Destination file | %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows System\Command Prompt.lnk |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Update |
| Path | %USERPROFILE%\AppData\Local\Microsoft\Windows\WinX\Group2 |
| Read-only | Disabled |
| Hidden | Enabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Removing the right click options on the start button 1/2 |
| Action | Update |
| Path | %USERPROFILE%\AppData\Local\Microsoft\Windows\WinX\Group3 |
| Read-only | Disabled |
| Hidden | Enabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Removing the right click options on the start button 2/2 |
| Action | Delete |
| Path | %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell |
| Delete this folder (if emptied) | Enabled |
| Recursively delete all subfolders (if emptied) | Enabled |
| Delete all files in the folder(s) | Enabled |
| Allow deletion of read-only files/folders | Enabled |
| Ignore errors for files/folders that cannot be deleted | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Path | %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows System |
| Delete this folder (if emptied) | Enabled |
| Recursively delete all subfolders (if emptied) | Enabled |
| Delete all files in the folder(s) | Enabled |
| Allow deletion of read-only files/folders | Enabled |
| Ignore errors for files/folders that cannot be deleted | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
| Value name | NoTrayContextMenu |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder |
| Value name | Attributes |
| Value type | REG_DWORD |
| Value data | 0x100000 (1048576) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Network visable in Explorer change to: b000064 |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ |
| Value name | NoFileMenu |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\People |
| Value name | PeopleBand |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Software\Microsoft\Windows\CurrentVersion\Search |
| Value name | SearchboxTaskbarMode |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Software\Policies\Microsoft\Windows\Explorer |
| Value name | LockedStartLayout |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced |
| Value name | TaskbarSd |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced |
| Value name | ShowTaskViewButton |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced |
| Value name | TaskbarMn |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Hide Chat Taskbar |