Group Policy Management
body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } }
Setting Path:
Explanation
No explanation is available for this setting.
Supported On:
Not available
RO-PO-WIN-C-Windows 11 Hardening PCI
Data collected on: 2-9-2025 12:25:29
General
Details
Domainemea.tpg.ads
OwnerEMEA\trifan.5-adm
Created5-11-2024 11:45:54
Modified18-7-2025 11:38:32
User Revisions1 (AD), 1 (SYSVOL)
Computer Revisions14 (AD), 14 (SYSVOL)
Unique ID{5a52b59b-2d4f-42ba-ac06-43aa6eac7c83}
GPO StatusUser settings disabled
Links
LocationEnforcedLink StatusPath
ClientsNoEnabledemea.tpg.ads/RO/Systems/Clients

This list only includes links in the domain of the GPO.
Security Filtering
The settings in this GPO can only apply to the following groups, users, and computers:
Name
EMEA\RO-L-SEC-Windows Restrictions PCI Windows 11
Delegation
These groups and users have the specified permission for this GPO
NameAllowed PermissionsInherited
EMEA\Domain AdminsEdit settings, delete, modify securityNo
EMEA\RO-G-ORG-OU AdminsEdit settings, delete, modify securityNo
EMEA\RO-L-SEC-Windows Restrictions PCI Windows 11Read (from Security Filtering)No
EMEA\trifan.5-admEdit settings, delete, modify securityNo
NT AUTHORITY\Authenticated UsersReadNo
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSReadNo
NT AUTHORITY\SYSTEMEdit settings, delete, modify securityNo
ROOT\Enterprise AdminsEdit settings, delete, modify securityNo
Computer Configuration (Enabled)
Policies
Windows Settings
Security Settings
System Services
AppX Deployment Service (AppXSVC) (Startup Mode: Disabled)
Permissions
No permissions specified
Auditing
No auditing specified
Bluetooth Audio Gateway Service (Startup Mode: Disabled)
Permissions
No permissions specified
Auditing
No auditing specified
Bluetooth Support Service (Startup Mode: Disabled)
Permissions
No permissions specified
Auditing
No auditing specified
Windows Defender Advanced Threat Protection Service (Startup Mode: Disabled)
Permissions
No permissions specified
Auditing
No auditing specified
Microsoft Defender Antivirus Network Inspection Service (Startup Mode: Disabled)
Permissions
No permissions specified
Auditing
No auditing specified
Microsoft Defender Antivirus Service (Startup Mode: Disabled)
Permissions
No permissions specified
Auditing
No auditing specified
WMI Performance Adapter (Startup Mode: Automatic)
Permissions
No permissions specified
Auditing
No auditing specified
File System
%SystemRoot%\System32\osk.exe
Configure this file or folder then: Propagate inheritable permissions to all subfolders and files
Owner
Permissions
TypeNamePermissionApply To
DenyAPPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGESFull ControlThis folder, subfolders and files
Allow inheritable permissions from the parent to propagate to this object and all child objectsDisabled
Auditing
No auditing specified
Software Restriction Policies
Enforcement
PolicySetting
Apply Software Restriction Policies to the followingAll software files except libraries (such as DLLs)
Apply Software Restriction Policies to the following usersAll users
When applying Software Restriction PoliciesIgnore certificate rules
Designated File Types
File ExtensionFile Type
ADEADE File
ADPADP File
BASBAS File
BATWindows Batch File
CHMCompiled HTML Help file
CMDWindows Command Script
COMMS-DOS Application
CPLControl panel item
CRTSecurity Certificate
EXEApplication
HLPHelp file
HTAHTML Application
INFSetup Information
INSINS File
ISPISP File
LNKShortcut
MDBMDB File
MDEMDE File
MSCMicrosoft Common Console Document
MSIWindows Installer Package
MSPWindows Installer Patch
MSTMST File
OCXActiveX control
PCDPCD File
PIFShortcut to MS-DOS Program
REGRegistration Entries
SCRScreen saver
SHSSHS File
URLInternet Shortcut
VBVisual Basic Source File
WSCWindows Script Component
Trusted Publishers
Trusted publisher managementAllow all administrators and users to manage user's own Trusted Publishers
Certificate verificationNone
Software Restriction Policies/Security Levels
PolicySetting
Default Security LevelUnrestricted
Software Restriction Policies/Additional Rules
Path Rules
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%
Security LevelUnrestricted
Description
Date last modified2-7-2024 11:47:48
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir%
Security LevelUnrestricted
Description
Date last modified2-7-2024 11:47:48
C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy
Security LevelDisallowed
DescriptionDeny Search
Date last modified2-7-2024 11:48:28
C:\Windows\SystemApps\Microsoft.Windows.Search*
Security LevelDisallowed
DescriptionDeny Search
Date last modified2-7-2024 11:48:47
Administrative Templates
Policy definitions (ADMX files) retrieved from the central store.
Control Panel
PolicySettingComment
Allow Online TipsDisabled
Google/Google Chrome
PolicySettingComment
Allow user feedbackDisabled
Google/Google Chrome/Google Cast
PolicySettingComment
Enable Google CastDisabled
Show the Google Cast toolbar iconDisabled
Microsoft Edge
PolicySettingComment
Ads setting for sites with intrusive adsEnabled
Ads setting for sites with intrusive adsBlock ads on sites with intrusive ads. (Default value)
PolicySettingComment
Allow user feedbackDisabled
Microsoft Edge/Cast
PolicySettingComment
Enable Google CastDisabled
Show the cast icon in the toolbarDisabled
Start Menu and Taskbar
PolicySettingComment
Hide the TaskView buttonEnabled
System/Group Policy
PolicySettingComment
Configure Logon Script DelayEnabled
minute:1
System/Logon
PolicySettingComment
Show first sign-in animation Disabled
System/Troubleshooting and Diagnostics/Scheduled Maintenance
PolicySettingComment
Configure Scheduled Maintenance BehaviorDisabled
Windows Components/App Privacy
PolicySettingComment
Let Windows apps access account informationEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access an eye tracker deviceEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access call historyEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access contactsEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access diagnostic information about other appsEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access emailEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access locationEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access messagingEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access motionEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access notificationsEnabled
Default for all apps:Force Allow
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access TasksEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access the calendarEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access the cameraEnabled
Default for all apps:Force Allow
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access the microphoneEnabled
Default for all apps:Force Allow
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access trusted devicesEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps communicate with unpaired devicesEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps control radiosEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps make phone callsEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps run in the backgroundEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
Windows Components/Application Compatibility
PolicySettingComment
Turn off Application TelemetryEnabled
Turn off Inventory CollectorEnabled
Turn off Steps RecorderEnabled
Windows Components/Cloud Content
PolicySettingComment
Do not show Windows tipsEnabled
Turn off Microsoft consumer experiencesEnabled
Windows Components/Data Collection and Preview Builds
PolicySettingComment
Allow Diagnostic DataEnabled
Send required diagnostic data
PolicySettingComment
Do not show feedback notificationsEnabled
Windows Components/Location and Sensors
PolicySettingComment
Turn off locationEnabled
Turn off sensorsEnabled
Windows Components/Microsoft Defender Antivirus
PolicySettingComment
Turn off Microsoft Defender AntivirusDisabled
Windows Components/Microsoft Defender Antivirus/Client Interface
PolicySettingComment
Enable headless UI modeDisabled
Windows Components/Microsoft Edge
PolicySettingComment
Configure Password ManagerDisabled
Windows Components/News and interests
PolicySettingComment
Enable news and interests on the taskbarDisabled
Windows Components/OneDrive
PolicySettingComment
Prevent the usage of OneDrive for file storageEnabled
Windows Components/Online Assistance
PolicySettingComment
Turn off Active HelpEnabled
Windows Components/Remote Desktop Services/Remote Desktop Session Host/Remote Session Environment
PolicySettingComment
Remove Windows Security item from Start menuEnabled
Windows Components/Search
PolicySettingComment
Allow CortanaDisabled
Allow Cortana above lock screenDisabled
Do not allow web searchEnabled
Don't search the web or display web results in SearchEnabled
Fully disable Search UIEnabled
Windows Components/Security Center
PolicySettingComment
Turn on Security Center (Domain PCs only)Enabled
Windows Components/Store
PolicySettingComment
Disable all apps from Microsoft Store Enabled
Turn off Automatic Download and Install of updatesEnabled
Turn off the offer to update to the latest version of WindowsEnabled
Turn off the Store applicationEnabled
Windows Components/Sync your settings
PolicySettingComment
Do not syncEnabled
Allow users to turn syncing on.Disabled
PolicySettingComment
Do not sync personalizeEnabled
Allow users to turn "personalize" syncing on.Disabled
Windows Components/Widgets
PolicySettingComment
Allow widgetsDisabled
Windows Components/Windows Error Reporting
PolicySettingComment
Disable Windows Error ReportingEnabled
Windows Components/Windows Game Recording and Broadcasting
PolicySettingComment
Enables or disables Windows Game Recording and BroadcastingDisabled
Windows Components/Windows Hello for Business
PolicySettingComment
Use Windows Hello for BusinessDisabled
Windows Components/Windows Ink Workspace
PolicySettingComment
Allow suggested apps in Windows Ink WorkspaceDisabled
Windows Components/Windows Mail
PolicySettingComment
Turn off Windows Mail applicationEnabled
Windows Components/Windows Media Player
PolicySettingComment
Do Not Show First Use Dialog BoxesEnabled
Prevent Automatic UpdatesEnabled
Prevent Desktop Shortcut CreationEnabled
Prevent Media SharingEnabled
Prevent Quick Launch Toolbar Shortcut CreationEnabled
Windows Components/Windows Messenger
PolicySettingComment
Do not allow Windows Messenger to be runEnabled
Do not automatically start Windows Messenger initiallyEnabled
Windows Components/Windows Mobility Center
PolicySettingComment
Turn off Windows Mobility CenterEnabled
Windows Components/Windows PowerShell
PolicySettingComment
Turn on Script ExecutionEnabled
Execution PolicyAllow all scripts
Windows Components/Windows Security/Systray
PolicySettingComment
Hide Windows Security SystrayEnabled
Preferences
Windows Settings
Registry
DefaultMicrophoneSetting (Order: 1)
General
ActionUpdate
Properties
HiveHKEY_LOCAL_MACHINE
Key pathHKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge
Value nameDefaultMicrophoneSetting
Value typeREG_DWORD
Value data0x1 (1)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
User Configuration (Disabled)
No settings defined.