ADMX_IIS policy review

This commit is contained in:
Nick White 2023-01-03 13:47:45 -05:00
parent 4b84283544
commit 118f240d5c

View File

@ -1,92 +1,94 @@
--- ---
title: Policy CSP - ADMX_IIS title: ADMX_IIS Policy CSP
description: Learn about the Policy CSP - ADMX_IIS. description: Learn more about the ADMX_IIS Area in Policy CSP
author: vinaypamnani-msft
manager: aaroncz
ms.author: vinpa ms.author: vinpa
ms.date: 01/03/2023
ms.localizationpriority: medium ms.localizationpriority: medium
ms.topic: article
ms.prod: windows-client ms.prod: windows-client
ms.technology: itpro-manage ms.technology: itpro-manage
author: vinaypamnani-msft ms.topic: reference
ms.date: 09/17/2021
ms.reviewer:
manager: aaroncz
--- ---
<!-- Auto-Generated CSP Document -->
<!-- ADMX_IIS-Begin -->
# Policy CSP - ADMX_IIS # Policy CSP - ADMX_IIS
> [!TIP] > [!TIP]
> This is an ADMX-backed policy and requires a special SyncML format to enable or disable. For details, see [Understanding ADMX-backed policies](../understanding-admx-backed-policies.md). > Some of these are ADMX-backed policies and require a special SyncML format to enable or disable. For details, see [Understanding ADMX-backed policies](./understanding-admx-backed-policies.md).
> >
> You must specify the data type in the SyncML as &lt;Format&gt;chr&lt;/Format&gt;. For an example SyncML, refer to [Enabling a policy](../understanding-admx-backed-policies.md#enabling-a-policy). > You must specify the data type in the SyncML as &lt;Format&gt;chr&lt;/Format&gt;. For an example SyncML, refer to [Enabling a policy](./understanding-admx-backed-policies.md#enabling-a-policy).
> >
> The payload of the SyncML must be XML-encoded; for this XML encoding, there are a variety of online encoders that you can use. To avoid encoding the payload, you can use CDATA if your MDM supports it. For more information, see [CDATA Sections](http://www.w3.org/TR/REC-xml/#sec-cdata-sect). > The payload of the SyncML must be XML-encoded; for this XML encoding, there are a variety of online encoders that you can use. To avoid encoding the payload, you can use CDATA if your MDM supports it. For more information, see [CDATA Sections](http://www.w3.org/TR/REC-xml/#sec-cdata-sect).
<hr/> <!-- ADMX_IIS-Editable-Begin -->
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
<!-- ADMX_IIS-Editable-End -->
<!--Policies--> <!-- PreventIISInstall-Begin -->
## ADMX_IIS policies ## PreventIISInstall
<dl> <!-- PreventIISInstall-Applicability-Begin -->
<dd> | Scope | Editions | Applicable OS |
<a href="#admx-iis-preventiisinstall">ADMX_IIS/PreventIISInstall</a> |:--|:--|:--|
</dd> | :heavy_check_mark: Device <br> :x: User | :x: Home <br> :heavy_check_mark: Pro <br> :heavy_check_mark: Enterprise <br> :heavy_check_mark: Education <br> :heavy_check_mark: Windows SE | :heavy_check_mark: Windows 10, version 2004 [10.0.19041.1202] and later <br> :heavy_check_mark: Windows 10, version 2009 [10.0.19042.1202] and later <br> :heavy_check_mark: Windows 10, version 21H1 [10.0.19043.1202] and later <br> :heavy_check_mark: Windows 11, version 21H2 [10.0.22000] and later |
</dl> <!-- PreventIISInstall-Applicability-End -->
<hr/> <!-- PreventIISInstall-OmaUri-Begin -->
```Device
./Device/Vendor/MSFT/Policy/Config/ADMX_IIS/PreventIISInstall
```
<!-- PreventIISInstall-OmaUri-End -->
<!--Policy--> <!-- PreventIISInstall-Description-Begin -->
<a href="" id="admx-iis-preventiisinstall"></a>**ADMX_IIS/PreventIISInstall** <!-- Description-Source-ADMX -->
"This policy setting prevents installation of Internet Information Services (IIS) on this computer. If you enable this policy setting, Internet Information Services (IIS) cannot be installed, and you will not be able to install Windows components or applications that require IIS. Users installing Windows components or applications that require IIS might not receive a warning that IIS cannot be installed because of this Group Policy setting. Enabling this setting will not have any effect on IIS if IIS is already installed on the computer. If you disable or do not configure this policy setting, IIS can be installed, as well as all the programs and applications that require IIS to run."
<!-- PreventIISInstall-Description-End -->
<!--SupportedSKUs--> <!-- PreventIISInstall-Editable-Begin -->
<!-- Add any additional information about this policy here. Anything outside this section will get overwritten. -->
<!-- PreventIISInstall-Editable-End -->
|Edition|Windows 10|Windows 11| <!-- PreventIISInstall-DFProperties-Begin -->
|--- |--- |--- | **Description framework properties**:
|Home|No|No|
|Pro|Yes|Yes|
|Windows SE|No|Yes|
|Business|Yes|Yes|
|Enterprise|Yes|Yes|
|Education|Yes|Yes|
<!--/SupportedSKUs--> | Property name | Property value |
<hr/> |:--|:--|
| Format | chr (string) |
| Access Type | Add, Delete, Get, Replace |
<!-- PreventIISInstall-DFProperties-End -->
<!--Scope--> <!-- PreventIISInstall-AdmxBacked-Begin -->
[Scope](./policy-configuration-service-provider.md#policy-scope): > [!TIP]
> This is an ADMX-backed policy and requires SyncML format for configuration. For details, see [Understanding ADMX-backed policies](./understanding-admx-backed-policies.md).
> [!div class = "checklist"] **ADMX mapping**:
> * Machine
<hr/> | Name | Value |
|:--|:--|
| Name | PreventIISInstall |
| Friendly Name | Prevent IIS installation |
| Location | Computer Configuration |
| Path | Windows Components > Internet Information Services |
| Registry Key Name | Software\Policies\Microsoft\Windows NT\IIS |
| Registry Value Name | PreventIISInstall |
| ADMX File Name | IIS.admx |
<!-- PreventIISInstall-AdmxBacked-End -->
<!--/Scope--> <!-- PreventIISInstall-Examples-Begin -->
<!--Description--> <!-- Add any examples for this policy here. Examples outside this section will get overwritten. -->
This policy setting prevents installation of Internet Information Services (IIS) on this computer. <!-- PreventIISInstall-Examples-End -->
If you enable this policy setting, Internet Information Services (IIS) can't be installed, and you'll not be able to install Windows components or applications that require IIS. Users installing Windows components or applications that require IIS might not receive a warning that IIS can't be installed because of this Group Policy setting. <!-- PreventIISInstall-End -->
Enabling this setting won't have any effect on IIS, if IIS is already installed on the computer. <!-- ADMX_IIS-CspMoreInfo-Begin -->
<!-- Add any additional information about this CSP here. Anything outside this section will get overwritten. -->
<!-- ADMX_IIS-CspMoreInfo-End -->
If you disable or don't configure this policy setting, IIS can be installed, and all the programs and applications that require IIS to run." <!-- ADMX_IIS-End -->
<!--/Description--> ## Related articles
[Policy configuration service provider](policy-configuration-service-provider.md)
<!--ADMXBacked-->
ADMX Info:
- GP Friendly name: *Prevent IIS installation*
- GP name: *PreventIISInstall*
- GP path: *Windows Components\Internet Information Services*
- GP ADMX file name: *IIS.admx*
<!--/ADMXBacked-->
<!--/Policy-->
<hr/>
<!--/Policies-->
## Related topics
[ADMX-backed policies in Policy CSP](./policies-in-policy-csp-admx-backed.md)