Group Policy Management
body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } }
Setting Path:
Explanation
No explanation is available for this setting.
Supported On:
Not available
TG-PO-WIN-U-Security_Staff
Data collected on: 2-9-2025 13:08:44
General
Details
Domainemea.tpg.ads
OwnerEMEA\manantenason.5-adm
Created18-6-2025 12:35:34
Modified18-6-2025 13:08:52
User Revisions1 (AD), 1 (SYSVOL)
Computer Revisions1 (AD), 1 (SYSVOL)
Unique ID{8a790fcf-77cf-4462-a83f-860b64ed825d}
GPO StatusComputer settings disabled
Links
LocationEnforcedLink StatusPath
TGNoEnabledemea.tpg.ads/TG

This list only includes links in the domain of the GPO.
Security Filtering
The settings in this GPO can only apply to the following groups, users, and computers:
Name
EMEA\TG-L-SEC-GPO-Security_Staff
Delegation
These groups and users have the specified permission for this GPO
NameAllowed PermissionsInherited
EMEA\Domain AdminsEdit settings, delete, modify securityNo
EMEA\manantenason.5-admEdit settings, delete, modify securityNo
EMEA\TG-G-ORG-OU AdminsEdit settings, delete, modify securityNo
EMEA\TG-L-SEC-Delegation Modify Group Policy Settings AccessEdit settings, delete, modify securityNo
EMEA\TG-L-SEC-GPO-Security_StaffRead (from Security Filtering)No
NT AUTHORITY\Authenticated UsersReadNo
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSReadNo
NT AUTHORITY\SYSTEMEdit settings, delete, modify securityNo
ROOT\Enterprise AdminsEdit settings, delete, modify securityNo
Computer Configuration (Disabled)
No settings defined.
User Configuration (Enabled)
Policies
Administrative Templates
Policy definitions (ADMX files) retrieved from the central store.
Control Panel
PolicySettingComment
Prohibit access to Control Panel and PC settingsEnabled
Control Panel/Add or Remove Programs
PolicySettingComment
Remove Add or Remove ProgramsEnabled
Control Panel/Display
PolicySettingComment
Disable the Display Control PanelEnabled
Hide Settings tabEnabled
Control Panel/Personalization
PolicySettingComment
Enable screen saverEnabled
Password protect the screen saverEnabled
Screen saver timeoutEnabled
Number of seconds to wait to enable the screen saver
Seconds:300
Control Panel/Programs
PolicySettingComment
Hide "Get Programs" pageEnabled
Hide "Programs and Features" pageEnabled
Hide "Set Program Access and Computer Defaults" pageEnabled
Hide "Windows Features"Enabled
Hide "Windows Marketplace"Enabled
Hide the Programs Control PanelEnabled
Start Menu and Taskbar
PolicySettingComment
Add Logoff to the Start MenuEnabled
Add the Run command to the Start MenuDisabled
Clear the recent programs list for new usersEnabled
Do not allow pinning items in Jump ListsEnabled
Do not allow pinning programs to the TaskbarEnabled
Do not allow pinning Store app to the TaskbarEnabled
Do not search programs and Control Panel itemsEnabled
Do not use the search-based method when resolving shell shortcutsEnabled
Force classic Start MenuEnabled
Hide the TaskView buttonEnabled
Lock all taskbar settingsEnabled
Lock the TaskbarEnabled
Prevent changes to Taskbar and Start Menu SettingsEnabled
Prevent users from customizing their Start ScreenEnabled
Prevent users from resizing the taskbarEnabled
Prevent users from uninstalling applications from StartEnabled
Remove "Recently added" list from Start MenuEnabled
Remove Games link from Start MenuEnabled
Remove Help menu from Start MenuEnabled
Remove Homegroup link from Start MenuEnabled
Remove Music icon from Start MenuEnabled
Remove Network icon from Start MenuEnabled
Remove Pictures icon from Start MenuEnabled
Remove Quick SettingsEnabled
Remove Recommended section from Start MenuEnabled
Remove Recorded TV link from Start MenuEnabled
Remove Run menu from Start MenuEnabled
Remove the "Undock PC" button from the Start MenuEnabled
Remove the Meet Now iconEnabled
Remove the People Bar from the taskbarEnabled
Remove the Security and Maintenance iconEnabled
Remove Videos link from Start MenuEnabled
Show "Run as different user" command on StartDisabled
Show or hide "Most used" list from Start menuEnabled
Choose one of the following actionsHide
PolicySettingComment
Show Windows Store apps on the taskbarDisabled
Turn off personalized menusEnabled
Turn off user trackingEnabled
System
PolicySettingComment
Don't run specified Windows applicationsEnabled
List of disallowed applications
mmc.exe
regedit.exe
*.msc
cmd.exe
powershell_ise.exe
powershell.exe
PolicySettingComment
Prevent access to registry editing toolsEnabled
Disable regedit from running silently?Yes
PolicySettingComment
Prevent access to the command promptEnabled
Disable the command prompt script processing also?No
PolicySettingComment
Restrict these programs from being launched from HelpEnabled
Enter executables separated by commas:powershell.exe,powershell_ise.exe,cmd.exe
Example: calc.exe,paint.exe
Windows Components/Internet Explorer/Internet Control Panel/Advanced Page
PolicySettingComment
Turn off encryption supportEnabled
Secure Protocol combinationsUse SSL 3.0, TLS 1.1, and TLS 1.2
Windows Components/Search
PolicySettingComment
Prevent adding UNC locations to index from Control PanelEnabled
Windows Components/Store
PolicySettingComment
Turn off the Store applicationEnabled
Windows Components/Task Scheduler
PolicySettingComment
Prevent Task Run or EndEnabled
Prohibit New Task CreationEnabled
Prohibit Task DeletionEnabled
Windows Components/Windows Installer
PolicySettingComment
Always install with elevated privilegesEnabled
This policy setting must be set for the machine and the user to be enforced.
Windows Components/Windows Mobility Center
PolicySettingComment
Turn off Windows Mobility CenterEnabled