mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-12 13:27:23 +00:00
Merged PR 2969: fixing admx info
automation update: GP path, and e->English name; re-orders a few policies as well, and adjusts white-space; one null SKU deleted
This commit is contained in:
parent
a0a26ee374
commit
b104c0cf6f
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - AboveLock
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Accounts
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - ActiveXControls
|
||||
@ -64,7 +64,7 @@ Note: Wild card characters cannot be used when specifying the host URLs.
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Approved Installation Sites for ActiveX Controls*
|
||||
- GP English name: *Approved Installation Sites for ActiveX Controls*
|
||||
- GP name: *ApprovedActiveXInstallSites*
|
||||
- GP path: *Windows Components/ActiveX Installer Service*
|
||||
- GP ADMX file name: *ActiveXInstallService.admx*
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - ApplicationDefaults
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - ApplicationManagement
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - AppVirtualization
|
||||
@ -58,9 +58,9 @@ This policy setting allows you to enable or disable Microsoft Application Virtua
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Enable App-V Client*
|
||||
- GP English name: *Enable App-V Client*
|
||||
- GP name: *EnableAppV*
|
||||
- GP path: *Administrative Templates/System/App-V*
|
||||
- GP path: *System/App-V*
|
||||
- GP ADMX file name: *appv.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -104,9 +104,9 @@ Enables Dynamic Virtualization of supported shell extensions, browser helper obj
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Enable Dynamic Virtualization*
|
||||
- GP English name: *Enable Dynamic Virtualization*
|
||||
- GP name: *Virtualization_JITVEnable*
|
||||
- GP path: *Administrative Templates/System/App-V/Virtualization*
|
||||
- GP path: *System/App-V/Virtualization*
|
||||
- GP ADMX file name: *appv.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -150,9 +150,9 @@ Enables automatic cleanup of appv packages that were added after Windows10 anniv
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Enable automatic cleanup of unused appv packages*
|
||||
- GP English name: *Enable automatic cleanup of unused appv packages*
|
||||
- GP name: *PackageManagement_AutoCleanupEnable*
|
||||
- GP path: *Administrative Templates/System/App-V/PackageManagement*
|
||||
- GP path: *System/App-V/PackageManagement*
|
||||
- GP ADMX file name: *appv.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -196,9 +196,9 @@ Enables scripts defined in the package manifest of configuration files that shou
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Enable Package Scripts*
|
||||
- GP English name: *Enable Package Scripts*
|
||||
- GP name: *Scripting_Enable_Package_Scripts*
|
||||
- GP path: *Administrative Templates/System/App-V/Scripting*
|
||||
- GP path: *System/App-V/Scripting*
|
||||
- GP ADMX file name: *appv.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -242,9 +242,9 @@ Enables a UX to display to the user when a publishing refresh is performed on th
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Enable Publishing Refresh UX*
|
||||
- GP English name: *Enable Publishing Refresh UX*
|
||||
- GP name: *Enable_Publishing_Refresh_UX*
|
||||
- GP path: *Administrative Templates/System/App-V/Publishing*
|
||||
- GP path: *System/App-V/Publishing*
|
||||
- GP ADMX file name: *appv.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -298,9 +298,9 @@ Data Block Size: This value specifies the maximum size in bytes to transmit to t
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Reporting Server*
|
||||
- GP English name: *Reporting Server*
|
||||
- GP name: *Reporting_Server_Policy*
|
||||
- GP path: *Administrative Templates/System/App-V/Reporting*
|
||||
- GP path: *System/App-V/Reporting*
|
||||
- GP ADMX file name: *appv.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -344,9 +344,9 @@ Specifies the file paths relative to %userprofile% that do not roam with a user'
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Roaming File Exclusions*
|
||||
- GP English name: *Roaming File Exclusions*
|
||||
- GP name: *Integration_Roaming_File_Exclusions*
|
||||
- GP path: *Administrative Templates/System/App-V/Integration*
|
||||
- GP path: *System/App-V/Integration*
|
||||
- GP ADMX file name: *appv.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -390,9 +390,9 @@ Specifies the registry paths that do not roam with a user profile. Example usage
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Roaming Registry Exclusions*
|
||||
- GP English name: *Roaming Registry Exclusions*
|
||||
- GP name: *Integration_Roaming_Registry_Exclusions*
|
||||
- GP path: *Administrative Templates/System/App-V/Integration*
|
||||
- GP path: *System/App-V/Integration*
|
||||
- GP ADMX file name: *appv.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -436,9 +436,9 @@ Specifies how new packages should be loaded automatically by App-V on a specific
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Specify what to load in background (aka AutoLoad)*
|
||||
- GP English name: *Specify what to load in background (aka AutoLoad)*
|
||||
- GP name: *Steaming_Autoload*
|
||||
- GP path: *Administrative Templates/System/App-V/Streaming*
|
||||
- GP path: *System/App-V/Streaming*
|
||||
- GP ADMX file name: *appv.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -482,9 +482,9 @@ Migration mode allows the App-V client to modify shortcuts and FTA's for package
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Enable Migration Mode*
|
||||
- GP English name: *Enable Migration Mode*
|
||||
- GP name: *Client_Coexistence_Enable_Migration_mode*
|
||||
- GP path: *Administrative Templates/System/App-V/Client Coexistence*
|
||||
- GP path: *System/App-V/Client Coexistence*
|
||||
- GP ADMX file name: *appv.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -528,9 +528,9 @@ Specifies the location where symbolic links are created to the current version o
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Integration Root User*
|
||||
- GP English name: *Integration Root User*
|
||||
- GP name: *Integration_Root_User*
|
||||
- GP path: *Administrative Templates/System/App-V/Integration*
|
||||
- GP path: *System/App-V/Integration*
|
||||
- GP ADMX file name: *appv.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -574,9 +574,9 @@ Specifies the location where symbolic links are created to the current version o
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Integration Root Global*
|
||||
- GP English name: *Integration Root Global*
|
||||
- GP name: *Integration_Root_Global*
|
||||
- GP path: *Administrative Templates/System/App-V/Integration*
|
||||
- GP path: *System/App-V/Integration*
|
||||
- GP ADMX file name: *appv.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -638,9 +638,9 @@ User Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, D
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Publishing Server 1 Settings*
|
||||
- GP English name: *Publishing Server 1 Settings*
|
||||
- GP name: *Publishing_Server1_Policy*
|
||||
- GP path: *Administrative Templates/System/App-V/Publishing*
|
||||
- GP path: *System/App-V/Publishing*
|
||||
- GP ADMX file name: *appv.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -704,7 +704,7 @@ User Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, D
|
||||
ADMX Info:
|
||||
- GP English name: *Publishing Server 2 Settings*
|
||||
- GP name: *Publishing_Server2_Policy*
|
||||
- GP path: *Administrative Templates/System/App-V/Publishing*
|
||||
- GP path: *System/App-V/Publishing*
|
||||
- GP ADMX file name: *appv.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -766,9 +766,9 @@ User Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, D
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Publishing Server 3 Settings*
|
||||
- GP English name: *Publishing Server 3 Settings*
|
||||
- GP name: *Publishing_Server3_Policy*
|
||||
- GP path: *Administrative Templates/System/App-V/Publishing*
|
||||
- GP path: *System/App-V/Publishing*
|
||||
- GP ADMX file name: *appv.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -830,9 +830,9 @@ User Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, D
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Publishing Server 4 Settings*
|
||||
- GP English name: *Publishing Server 4 Settings*
|
||||
- GP name: *Publishing_Server4_Policy*
|
||||
- GP path: *Administrative Templates/System/App-V/Publishing*
|
||||
- GP path: *System/App-V/Publishing*
|
||||
- GP ADMX file name: *appv.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -894,9 +894,9 @@ User Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, D
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Publishing Server 5 Settings*
|
||||
- GP English name: *Publishing Server 5 Settings*
|
||||
- GP name: *Publishing_Server5_Policy*
|
||||
- GP path: *Administrative Templates/System/App-V/Publishing*
|
||||
- GP path: *System/App-V/Publishing*
|
||||
- GP ADMX file name: *appv.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -940,9 +940,9 @@ Specifies the path to a valid certificate in the certificate store.
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Certificate Filter For Client SSL*
|
||||
- GP English name: *Certificate Filter For Client SSL*
|
||||
- GP name: *Streaming_Certificate_Filter_For_Client_SSL*
|
||||
- GP path: *Administrative Templates/System/App-V/Streaming*
|
||||
- GP path: *System/App-V/Streaming*
|
||||
- GP ADMX file name: *appv.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -986,9 +986,9 @@ This setting controls whether virtualized applications are launched on Windows 8
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Allow First Time Application Launches if on a High Cost Windows 8 Metered Connection*
|
||||
- GP English name: *Allow First Time Application Launches if on a High Cost Windows 8 Metered Connection*
|
||||
- GP name: *Streaming_Allow_High_Cost_Launch*
|
||||
- GP path: *Administrative Templates/System/App-V/Streaming*
|
||||
- GP path: *System/App-V/Streaming*
|
||||
- GP ADMX file name: *appv.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -1032,9 +1032,9 @@ Specifies the CLSID for a compatible implementation of the IAppvPackageLocationP
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Location Provider*
|
||||
- GP English name: *Location Provider*
|
||||
- GP name: *Streaming_Location_Provider*
|
||||
- GP path: *Administrative Templates/System/App-V/Streaming*
|
||||
- GP path: *System/App-V/Streaming*
|
||||
- GP ADMX file name: *appv.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -1078,9 +1078,9 @@ Specifies directory where all new applications and updates will be installed.
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Package Installation Root*
|
||||
- GP English name: *Package Installation Root*
|
||||
- GP name: *Streaming_Package_Installation_Root*
|
||||
- GP path: *Administrative Templates/System/App-V/Streaming*
|
||||
- GP path: *System/App-V/Streaming*
|
||||
- GP ADMX file name: *appv.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -1124,9 +1124,9 @@ Overrides source location for downloading package content.
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Package Source Root*
|
||||
- GP English name: *Package Source Root*
|
||||
- GP name: *Streaming_Package_Source_Root*
|
||||
- GP path: *Administrative Templates/System/App-V/Streaming*
|
||||
- GP path: *System/App-V/Streaming*
|
||||
- GP ADMX file name: *appv.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -1170,9 +1170,9 @@ Specifies the number of seconds between attempts to reestablish a dropped sessio
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Reestablishment Interval*
|
||||
- GP English name: *Reestablishment Interval*
|
||||
- GP name: *Streaming_Reestablishment_Interval*
|
||||
- GP path: *Administrative Templates/System/App-V/Streaming*
|
||||
- GP path: *System/App-V/Streaming*
|
||||
- GP ADMX file name: *appv.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -1216,9 +1216,9 @@ Specifies the number of times to retry a dropped session.
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Reestablishment Retries*
|
||||
- GP English name: *Reestablishment Retries*
|
||||
- GP name: *Streaming_Reestablishment_Retries*
|
||||
- GP path: *Administrative Templates/System/App-V/Streaming*
|
||||
- GP path: *System/App-V/Streaming*
|
||||
- GP ADMX file name: *appv.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -1262,9 +1262,9 @@ Specifies that streamed package contents will be not be saved to the local hard
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Shared Content Store (SCS) mode*
|
||||
- GP English name: *Shared Content Store (SCS) mode*
|
||||
- GP name: *Streaming_Shared_Content_Store_Mode*
|
||||
- GP path: *Administrative Templates/System/App-V/Streaming*
|
||||
- GP path: *System/App-V/Streaming*
|
||||
- GP ADMX file name: *appv.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -1308,9 +1308,9 @@ If enabled, the App-V client will support BrancheCache compatible HTTP streaming
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Enable Support for BranchCache*
|
||||
- GP English name: *Enable Support for BranchCache*
|
||||
- GP name: *Streaming_Support_Branch_Cache*
|
||||
- GP path: *Administrative Templates/System/App-V/Streaming*
|
||||
- GP path: *System/App-V/Streaming*
|
||||
- GP ADMX file name: *appv.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -1354,9 +1354,9 @@ Verifies Server certificate revocation status before streaming using HTTPS.
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Verify certificate revocation list*
|
||||
- GP English name: *Verify certificate revocation list*
|
||||
- GP name: *Streaming_Verify_Certificate_Revocation_List*
|
||||
- GP path: *Administrative Templates/System/App-V/Streaming*
|
||||
- GP path: *System/App-V/Streaming*
|
||||
- GP ADMX file name: *appv.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -1400,9 +1400,9 @@ Specifies a list of process paths (may contain wildcards) which are candidates f
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Virtual Component Process Allow List*
|
||||
- GP English name: *Virtual Component Process Allow List*
|
||||
- GP name: *Virtualization_JITVAllowList*
|
||||
- GP path: *Administrative Templates/System/App-V/Virtualization*
|
||||
- GP path: *System/App-V/Virtualization*
|
||||
- GP ADMX file name: *appv.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - AttachmentManager
|
||||
@ -64,7 +64,7 @@ If you do not configure this policy setting, Windows marks file attachments with
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Do not preserve zone information in file attachments*
|
||||
- GP English name: *Do not preserve zone information in file attachments*
|
||||
- GP name: *AM_MarkZoneOnSavedAtttachments*
|
||||
- GP path: *Windows Components/Attachment Manager*
|
||||
- GP ADMX file name: *AttachmentManager.admx*
|
||||
@ -116,7 +116,7 @@ If you do not configure this policy setting, Windows hides the check box and Unb
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Hide mechanisms to remove zone information*
|
||||
- GP English name: *Hide mechanisms to remove zone information*
|
||||
- GP name: *AM_RemoveZoneInfo*
|
||||
- GP path: *Windows Components/Attachment Manager*
|
||||
- GP ADMX file name: *AttachmentManager.admx*
|
||||
@ -168,7 +168,7 @@ If you do not configure this policy setting, Windows does not call the registere
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Notify antivirus programs when opening attachments*
|
||||
- GP English name: *Notify antivirus programs when opening attachments*
|
||||
- GP name: *AM_CallIOfficeAntiVirus*
|
||||
- GP path: *Windows Components/Attachment Manager*
|
||||
- GP ADMX file name: *AttachmentManager.admx*
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Authentication
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Autoplay
|
||||
@ -62,7 +62,7 @@ If you disable or do not configure this policy setting, AutoPlay is enabled for
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Disallow Autoplay for non-volume devices*
|
||||
- GP English name: *Disallow Autoplay for non-volume devices*
|
||||
- GP name: *NoAutoplayfornonVolume*
|
||||
- GP path: *Windows Components/AutoPlay Policies*
|
||||
- GP ADMX file name: *AutoPlay.admx*
|
||||
@ -121,7 +121,7 @@ If you disable or not configure this policy setting, Windows Vista or later will
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Set the default behavior for AutoRun*
|
||||
- GP English name: *Set the default behavior for AutoRun*
|
||||
- GP name: *NoAutorun*
|
||||
- GP path: *Windows Components/AutoPlay Policies*
|
||||
- GP ADMX file name: *AutoPlay.admx*
|
||||
@ -181,7 +181,7 @@ Note: This policy setting appears in both the Computer Configuration and User Co
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Turn off Autoplay*
|
||||
- GP English name: *Turn off Autoplay*
|
||||
- GP name: *Autorun*
|
||||
- GP path: *Windows Components/AutoPlay Policies*
|
||||
- GP ADMX file name: *AutoPlay.admx*
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Bitlocker
|
||||
@ -85,6 +85,7 @@ ms.date: 08/09/2017
|
||||
<a href="./bitlocker-csp.md#systemdrivesrequirestartupauthentication" id="systemdrivesrequirestartupauthentication">BitLocker/SystemDrivesRequireStartupAuthentication</a>
|
||||
</dd>
|
||||
</dl>
|
||||
|
||||
<!--EndDescription-->
|
||||
<!--EndPolicy-->
|
||||
<hr/>
|
||||
@ -96,3 +97,4 @@ Footnote:
|
||||
- 3 - Added in Windows 10, version 1709.
|
||||
|
||||
<!--EndPolicies-->
|
||||
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Bluetooth
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/25/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Browser
|
||||
@ -684,29 +684,6 @@ By default, the Microsoft compatibility list is enabled and can be viewed by vis
|
||||
<!--StartPolicy-->
|
||||
<a href="" id="browser-alwaysenablebookslibrary"></a>**Browser/AlwaysEnableBooksLibrary**
|
||||
|
||||
<!--StartSKU-->
|
||||
<table>
|
||||
<tr>
|
||||
<th>Home</th>
|
||||
<th>Pro</th>
|
||||
<th>Business</th>
|
||||
<th>Enterprise</th>
|
||||
<th>Education</th>
|
||||
<th>Mobile</th>
|
||||
<th>Mobile Enterprise</th>
|
||||
</tr>
|
||||
<tr>
|
||||
<td></td>
|
||||
<td></td>
|
||||
<td></td>
|
||||
<td></td>
|
||||
<td></td>
|
||||
<td></td>
|
||||
<td></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
<!--EndSKU-->
|
||||
<!--StartDescription-->
|
||||
<p style="margin-left: 20px">
|
||||
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Camera
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Cellular
|
||||
@ -56,7 +56,7 @@ ms.date: 08/09/2017
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Set Per-App Cellular Access UI Visibility*
|
||||
- GP English name: *Set Per-App Cellular Access UI Visibility*
|
||||
- GP name: *ShowAppCellularAccessUI*
|
||||
- GP path: *Network/WWAN Service/WWAN UI Settings*
|
||||
- GP ADMX file name: *wwansvc.admx*
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Connectivity
|
||||
@ -386,8 +386,9 @@ ms.date: 08/09/2017
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Turn off printing over HTTP*
|
||||
- GP English name: *Turn off printing over HTTP*
|
||||
- GP name: *DisableHTTPPrinting_2*
|
||||
- GP path: *Internet Communication settings*
|
||||
- GP ADMX file name: *ICM.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -429,8 +430,9 @@ ADMX Info:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Turn off downloading of print drivers over HTTP*
|
||||
- GP English name: *Turn off downloading of print drivers over HTTP*
|
||||
- GP name: *DisableWebPnPDownload_2*
|
||||
- GP path: *Internet Communication settings*
|
||||
- GP ADMX file name: *ICM.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -472,8 +474,9 @@ ADMX Info:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Turn off Internet download for Web publishing and online ordering wizards*
|
||||
- GP English name: *Turn off Internet download for Web publishing and online ordering wizards*
|
||||
- GP name: *ShellPreventWPWDownload_2*
|
||||
- GP path: *Internet Communication settings*
|
||||
- GP ADMX file name: *ICM.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -519,7 +522,7 @@ If you enable this policy, Windows only allows access to the specified UNC paths
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Hardened UNC Paths*
|
||||
- GP English name: *Hardened UNC Paths*
|
||||
- GP name: *Pol_HardenedPaths*
|
||||
- GP path: *Network/Network Provider*
|
||||
- GP ADMX file name: *networkprovider.admx*
|
||||
@ -563,7 +566,7 @@ ADMX Info:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Prohibit installation and configuration of Network Bridge on your DNS domain network*
|
||||
- GP English name: *Prohibit installation and configuration of Network Bridge on your DNS domain network*
|
||||
- GP name: *NC_AllowNetBridge_NLA*
|
||||
- GP path: *Network/Network Connections*
|
||||
- GP ADMX file name: *NetworkConnections.admx*
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - CredentialProviders
|
||||
@ -66,8 +66,9 @@ To configure Windows Hello for Business, use the Administrative Template policie
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Turn on convenience PIN sign-in*
|
||||
- GP English name: *Turn on convenience PIN sign-in*
|
||||
- GP name: *AllowDomainPINLogon*
|
||||
- GP path: *System/Logon*
|
||||
- GP ADMX file name: *credentialproviders.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -117,8 +118,9 @@ Note that the user's domain password will be cached in the system vault when usi
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Turn off picture password sign-in*
|
||||
- GP English name: *Turn off picture password sign-in*
|
||||
- GP name: *BlockDomainPicturePassword*
|
||||
- GP path: *System/Logon*
|
||||
- GP ADMX file name: *credentialproviders.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - CredentialsUI
|
||||
@ -66,7 +66,7 @@ The policy applies to all Windows components and applications that use the Windo
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Do not display the password reveal button*
|
||||
- GP English name: *Do not display the password reveal button*
|
||||
- GP name: *DisablePasswordReveal*
|
||||
- GP path: *Windows Components/Credential User Interface*
|
||||
- GP ADMX file name: *credui.admx*
|
||||
@ -116,7 +116,7 @@ If you disable this policy setting, users will always be required to type a user
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Enumerate administrator accounts on elevation*
|
||||
- GP English name: *Enumerate administrator accounts on elevation*
|
||||
- GP name: *EnumerateAdministrators*
|
||||
- GP path: *Windows Components/Credential User Interface*
|
||||
- GP ADMX file name: *credui.admx*
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Cryptography
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - DataProtection
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - DataUsage
|
||||
@ -68,7 +68,7 @@ If this policy setting is disabled or is not configured, the cost of 3G connecti
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Set 3G Cost*
|
||||
- GP English name: *Set 3G Cost*
|
||||
- GP name: *SetCost3G*
|
||||
- GP path: *Network/WWAN Service/WWAN Media Cost*
|
||||
- GP ADMX file name: *wwansvc.admx*
|
||||
@ -124,7 +124,7 @@ If this policy setting is disabled or is not configured, the cost of 4G connecti
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Set 4G Cost*
|
||||
- GP English name: *Set 4G Cost*
|
||||
- GP name: *SetCost4G*
|
||||
- GP path: *Network/WWAN Service/WWAN Media Cost*
|
||||
- GP ADMX file name: *wwansvc.admx*
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Defender
|
||||
@ -740,6 +740,74 @@ Value type is string.
|
||||
> [!Note]
|
||||
> This feature depends on three other MAPS settings the must all be enabled- "Configure the 'Block at First Sight' feature; "Join Microsoft MAPS"; "Send file samples when further analysis is required".
|
||||
|
||||
<!--EndDescription-->
|
||||
<!--EndPolicy-->
|
||||
<!--StartPolicy-->
|
||||
<a href="" id="defender-controlledfolderaccessallowedapplications"></a>**Defender/ControlledFolderAccessAllowedApplications**
|
||||
|
||||
<!--StartSKU-->
|
||||
<table>
|
||||
<tr>
|
||||
<th>Home</th>
|
||||
<th>Pro</th>
|
||||
<th>Business</th>
|
||||
<th>Enterprise</th>
|
||||
<th>Education</th>
|
||||
<th>Mobile</th>
|
||||
<th>Mobile Enterprise</th>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><img src="images/crossmark.png" alt="cross mark" /></td>
|
||||
<td><img src="images/checkmark.png" alt="check mark" /><sup>3</sup></td>
|
||||
<td><img src="images/checkmark.png" alt="check mark" /><sup>3</sup></td>
|
||||
<td><img src="images/checkmark.png" alt="check mark" /><sup>3</sup></td>
|
||||
<td><img src="images/checkmark.png" alt="check mark" /><sup>3</sup></td>
|
||||
<td><img src="images/crossmark.png" alt="cross mark" /></td>
|
||||
<td><img src="images/crossmark.png" alt="cross mark" /></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
<!--EndSKU-->
|
||||
<!--StartDescription-->
|
||||
> [!NOTE]
|
||||
> This policy is only enforced in Windows 10 for desktop. The previous name was GuardedFoldersAllowedApplications and changed to ControlledFolderAccessAllowedApplications.
|
||||
|
||||
<p style="margin-left: 20px">Added in Windows 10, version 1709. This policy setting allows user-specified applications to the guard my folders feature. Adding an allowed application means the guard my folders feature will allow the application to modify or delete content in certain folders such as My Documents. In most cases it will not be necessary to add entries. Windows Defender Antivirus will automatically detect and dynamically add applications that are friendly. Value type is string. Use the Unicode  as the substring separator.
|
||||
|
||||
<!--EndDescription-->
|
||||
<!--EndPolicy-->
|
||||
<!--StartPolicy-->
|
||||
<a href="" id="defender-controlledfolderaccessprotectedfolders"></a>**Defender/ControlledFolderAccessProtectedFolders**
|
||||
|
||||
<!--StartSKU-->
|
||||
<table>
|
||||
<tr>
|
||||
<th>Home</th>
|
||||
<th>Pro</th>
|
||||
<th>Business</th>
|
||||
<th>Enterprise</th>
|
||||
<th>Education</th>
|
||||
<th>Mobile</th>
|
||||
<th>Mobile Enterprise</th>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><img src="images/crossmark.png" alt="cross mark" /></td>
|
||||
<td><img src="images/checkmark.png" alt="check mark" /><sup>3</sup></td>
|
||||
<td><img src="images/checkmark.png" alt="check mark" /><sup>3</sup></td>
|
||||
<td><img src="images/checkmark.png" alt="check mark" /><sup>3</sup></td>
|
||||
<td><img src="images/checkmark.png" alt="check mark" /><sup>3</sup></td>
|
||||
<td><img src="images/crossmark.png" alt="cross mark" /></td>
|
||||
<td><img src="images/crossmark.png" alt="cross mark" /></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
<!--EndSKU-->
|
||||
<!--StartDescription-->
|
||||
> [!NOTE]
|
||||
> This policy is only enforced in Windows 10 for desktop. The previous name was GuardedFoldersList and changed to ControlledFolderAccessProtectedFolders.
|
||||
|
||||
<p style="margin-left: 20px">Added in Windows 10, version 1709. This policy settings allows adding user-specified folder locations to the guard my folders feature. These folders will complement the system defined folders such as My Documents and My Pictures. The list of system folders will be displayed in the user interface and can not be changed. Value type is string. Use the Unicode  as the substring separator.
|
||||
|
||||
<!--EndDescription-->
|
||||
<!--EndPolicy-->
|
||||
<!--StartPolicy-->
|
||||
@ -974,74 +1042,6 @@ Value type is string.
|
||||
|
||||
<p style="margin-left: 20px">Each file type must be separated by a **|**. For example, "C:\\Example.exe|C:\\Example1.exe".
|
||||
|
||||
<!--EndDescription-->
|
||||
<!--EndPolicy-->
|
||||
<!--StartPolicy-->
|
||||
<a href="" id="defender-controlledfolderaccessallowedapplications"></a>**Defender/ControlledFolderAccessAllowedApplications**
|
||||
|
||||
<!--StartSKU-->
|
||||
<table>
|
||||
<tr>
|
||||
<th>Home</th>
|
||||
<th>Pro</th>
|
||||
<th>Business</th>
|
||||
<th>Enterprise</th>
|
||||
<th>Education</th>
|
||||
<th>Mobile</th>
|
||||
<th>Mobile Enterprise</th>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><img src="images/crossmark.png" alt="cross mark" /></td>
|
||||
<td><img src="images/checkmark.png" alt="check mark" /><sup>3</sup></td>
|
||||
<td><img src="images/checkmark.png" alt="check mark" /><sup>3</sup></td>
|
||||
<td><img src="images/checkmark.png" alt="check mark" /><sup>3</sup></td>
|
||||
<td><img src="images/checkmark.png" alt="check mark" /><sup>3</sup></td>
|
||||
<td><img src="images/crossmark.png" alt="cross mark" /></td>
|
||||
<td><img src="images/crossmark.png" alt="cross mark" /></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
<!--EndSKU-->
|
||||
<!--StartDescription-->
|
||||
> [!NOTE]
|
||||
> This policy is only enforced in Windows 10 for desktop. The previous name was GuardedFoldersAllowedApplications and changed to ControlledFolderAccessAllowedApplications.
|
||||
|
||||
<p style="margin-left: 20px">Added in Windows 10, version 1709. This policy setting allows user-specified applications to the guard my folders feature. Adding an allowed application means the guard my folders feature will allow the application to modify or delete content in certain folders such as My Documents. In most cases it will not be necessary to add entries. Windows Defender Antivirus will automatically detect and dynamically add applications that are friendly. Value type is string. Use the Unicode  as the substring separator.
|
||||
|
||||
<!--EndDescription-->
|
||||
<!--EndPolicy-->
|
||||
<!--StartPolicy-->
|
||||
<a href="" id="defender-controlledfolderaccessprotectedfolders"></a>**Defender/ControlledFolderAccessProtectedFolders**
|
||||
|
||||
<!--StartSKU-->
|
||||
<table>
|
||||
<tr>
|
||||
<th>Home</th>
|
||||
<th>Pro</th>
|
||||
<th>Business</th>
|
||||
<th>Enterprise</th>
|
||||
<th>Education</th>
|
||||
<th>Mobile</th>
|
||||
<th>Mobile Enterprise</th>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><img src="images/crossmark.png" alt="cross mark" /></td>
|
||||
<td><img src="images/checkmark.png" alt="check mark" /><sup>3</sup></td>
|
||||
<td><img src="images/checkmark.png" alt="check mark" /><sup>3</sup></td>
|
||||
<td><img src="images/checkmark.png" alt="check mark" /><sup>3</sup></td>
|
||||
<td><img src="images/checkmark.png" alt="check mark" /><sup>3</sup></td>
|
||||
<td><img src="images/crossmark.png" alt="cross mark" /></td>
|
||||
<td><img src="images/crossmark.png" alt="cross mark" /></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
<!--EndSKU-->
|
||||
<!--StartDescription-->
|
||||
> [!NOTE]
|
||||
> This policy is only enforced in Windows 10 for desktop. The previous name was GuardedFoldersList and changed to ControlledFolderAccessProtectedFolders.
|
||||
|
||||
<p style="margin-left: 20px">Added in Windows 10, version 1709. This policy settings allows adding user-specified folder locations to the guard my folders feature. These folders will complement the system defined folders such as My Documents and My Pictures. The list of system folders will be displayed in the user interface and can not be changed. Value type is string. Use the Unicode  as the substring separator.
|
||||
|
||||
<!--EndDescription-->
|
||||
<!--EndPolicy-->
|
||||
<!--StartPolicy-->
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - DeliveryOptimization
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Desktop
|
||||
@ -62,8 +62,9 @@ If you enable this setting, users are unable to type a new location in the Targe
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Prohibit User from manually redirecting Profile Folders*
|
||||
- GP English name: *Prohibit User from manually redirecting Profile Folders*
|
||||
- GP name: *DisablePersonalDirChange*
|
||||
- GP path: *Desktop*
|
||||
- GP ADMX file name: *desktop.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - DeviceGuard
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - DeviceInstallation
|
||||
@ -62,7 +62,7 @@ If you disable or do not configure this policy setting, devices can be installed
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Prevent installation of devices that match any of these device IDs*
|
||||
- GP English name: *Prevent installation of devices that match any of these device IDs*
|
||||
- GP name: *DeviceInstall_IDs_Deny*
|
||||
- GP path: *System/Device Installation/Device Installation Restrictions*
|
||||
- GP ADMX file name: *deviceinstallation.admx*
|
||||
@ -112,7 +112,7 @@ If you disable or do not configure this policy setting, Windows can install and
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Prevent installation of devices using drivers that match these device setup classes*
|
||||
- GP English name: *Prevent installation of devices using drivers that match these device setup classes*
|
||||
- GP name: *DeviceInstall_Classes_Deny*
|
||||
- GP path: *System/Device Installation/Device Installation Restrictions*
|
||||
- GP ADMX file name: *deviceinstallation.admx*
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - DeviceLock
|
||||
@ -767,7 +767,7 @@ If you enable this setting, users will no longer be able to modify slide show se
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Prevent enabling lock screen slide show*
|
||||
- GP English name: *Prevent enabling lock screen slide show*
|
||||
- GP name: *CPL_Personalization_NoLockScreenSlideshow*
|
||||
- GP path: *Control Panel/Personalization*
|
||||
- GP ADMX file name: *ControlPanelDisplay.admx*
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Display
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Education
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - EnterpriseCloudPrint
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - ErrorReporting
|
||||
@ -72,8 +72,9 @@ If you disable or do not configure this policy setting, then the default consent
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Customize consent settings*
|
||||
- GP English name: *Customize consent settings*
|
||||
- GP name: *WerConsentCustomize_2*
|
||||
- GP path: *Windows Components/Windows Error Reporting/Consent*
|
||||
- GP ADMX file name: *ErrorReporting.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -121,7 +122,7 @@ If you disable or do not configure this policy setting, the Turn off Windows Err
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Disable Windows Error Reporting*
|
||||
- GP English name: *Disable Windows Error Reporting*
|
||||
- GP name: *WerDisable_2*
|
||||
- GP path: *Windows Components/Windows Error Reporting*
|
||||
- GP ADMX file name: *ErrorReporting.admx*
|
||||
@ -175,7 +176,7 @@ See also the Configure Error Reporting policy setting.
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Display Error Notification*
|
||||
- GP English name: *Display Error Notification*
|
||||
- GP name: *PCH_ShowUI*
|
||||
- GP path: *Windows Components/Windows Error Reporting*
|
||||
- GP ADMX file name: *ErrorReporting.admx*
|
||||
@ -225,7 +226,7 @@ If you disable or do not configure this policy setting, then consent policy sett
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Do not send additional data*
|
||||
- GP English name: *Do not send additional data*
|
||||
- GP name: *WerNoSecondLevelData_2*
|
||||
- GP path: *Windows Components/Windows Error Reporting*
|
||||
- GP ADMX file name: *ErrorReporting.admx*
|
||||
@ -275,7 +276,7 @@ If you disable or do not configure this policy setting, Windows Error Reporting
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Prevent display of the user interface for critical errors*
|
||||
- GP English name: *Prevent display of the user interface for critical errors*
|
||||
- GP name: *WerDoNotShowUI*
|
||||
- GP path: *Windows Components/Windows Error Reporting*
|
||||
- GP ADMX file name: *ErrorReporting.admx*
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - EventLogService
|
||||
@ -64,7 +64,7 @@ Note: Old events may or may not be retained according to the "Backup log automat
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Control Event Log behavior when the log file reaches its maximum size*
|
||||
- GP English name: *Control Event Log behavior when the log file reaches its maximum size*
|
||||
- GP name: *Channel_Log_Retention_1*
|
||||
- GP path: *Windows Components/Event Log Service/Application*
|
||||
- GP ADMX file name: *eventlog.admx*
|
||||
@ -114,7 +114,7 @@ If you disable or do not configure this policy setting, the maximum size of the
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Specify the maximum log file size (KB)*
|
||||
- GP English name: *Specify the maximum log file size (KB)*
|
||||
- GP name: *Channel_LogMaxSize_1*
|
||||
- GP path: *Windows Components/Event Log Service/Application*
|
||||
- GP ADMX file name: *eventlog.admx*
|
||||
@ -164,7 +164,7 @@ If you disable or do not configure this policy setting, the maximum size of the
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Specify the maximum log file size (KB)*
|
||||
- GP English name: *Specify the maximum log file size (KB)*
|
||||
- GP name: *Channel_LogMaxSize_2*
|
||||
- GP path: *Windows Components/Event Log Service/Security*
|
||||
- GP ADMX file name: *eventlog.admx*
|
||||
@ -214,7 +214,7 @@ If you disable or do not configure this policy setting, the maximum size of the
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Specify the maximum log file size (KB)*
|
||||
- GP English name: *Specify the maximum log file size (KB)*
|
||||
- GP name: *Channel_LogMaxSize_4*
|
||||
- GP path: *Windows Components/Event Log Service/System*
|
||||
- GP ADMX file name: *eventlog.admx*
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Experience
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/29/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - ExploitGuard
|
||||
@ -14,6 +14,11 @@ ms.date: 08/29/2017
|
||||
> [!WARNING]
|
||||
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
||||
|
||||
<!--StartPolicies-->
|
||||
<hr/>
|
||||
|
||||
## ExploitGuard policies
|
||||
|
||||
<!--StartPolicy-->
|
||||
<a href="" id="exploitguard-exploitprotectionsettings"></a>**ExploitGuard/ExploitProtectionSettings**
|
||||
|
||||
@ -81,3 +86,4 @@ Footnote:
|
||||
- 3 - Added in Windows 10, version 1709.
|
||||
|
||||
<!--EndPolicies-->
|
||||
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Games
|
||||
|
File diff suppressed because it is too large
Load Diff
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Kerberos
|
||||
@ -62,7 +62,7 @@ If you disable or do not configure this policy setting, the Kerberos client does
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Use forest search order*
|
||||
- GP English name: *Use forest search order*
|
||||
- GP name: *ForestSearch*
|
||||
- GP path: *System/Kerberos*
|
||||
- GP ADMX file name: *Kerberos.admx*
|
||||
@ -111,7 +111,7 @@ If you disable or do not configure this policy setting, the client devices will
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Kerberos client support for claims, compound authentication and Kerberos armoring*
|
||||
- GP English name: *Kerberos client support for claims, compound authentication and Kerberos armoring*
|
||||
- GP name: *EnableCbacAndArmor*
|
||||
- GP path: *System/Kerberos*
|
||||
- GP ADMX file name: *Kerberos.admx*
|
||||
@ -165,7 +165,7 @@ If you disable or do not configure this policy setting, the client computers in
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Fail authentication requests when Kerberos armoring is not available*
|
||||
- GP English name: *Fail authentication requests when Kerberos armoring is not available*
|
||||
- GP name: *ClientRequireFast*
|
||||
- GP path: *System/Kerberos*
|
||||
- GP ADMX file name: *Kerberos.admx*
|
||||
@ -215,7 +215,7 @@ If you disable or do not configure this policy setting, the Kerberos client requ
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Require strict KDC validation*
|
||||
- GP English name: *Require strict KDC validation*
|
||||
- GP name: *ValidateKDC*
|
||||
- GP path: *System/Kerberos*
|
||||
- GP ADMX file name: *Kerberos.admx*
|
||||
@ -269,7 +269,7 @@ Note: This policy setting configures the existing MaxTokenSize registry value in
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Set maximum Kerberos SSPI context token buffer size*
|
||||
- GP English name: *Set maximum Kerberos SSPI context token buffer size*
|
||||
- GP name: *MaxTokenSize*
|
||||
- GP path: *System/Kerberos*
|
||||
- GP ADMX file name: *Kerberos.admx*
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Licensing
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - LocalPoliciesSecurityOptions
|
||||
@ -672,46 +672,6 @@ Valid values:
|
||||
- 0 - disabled
|
||||
- 1 - enabled (allow system to be shut down without having to log on)
|
||||
|
||||
Value type is integer. Supported operations are Add, Get, Replace, and Delete.
|
||||
|
||||
<!--EndDescription-->
|
||||
<!--EndPolicy-->
|
||||
<!--StartPolicy-->
|
||||
<a href="" id="localpoliciessecurityoptions-useraccountcontrol-runalladministratorsinadminapprovalmode"></a>**LocalPoliciesSecurityOptions/UserAccountControl_RunAllAdministratorsInAdminApprovalMode**
|
||||
|
||||
<!--StartSKU-->
|
||||
<table>
|
||||
<tr>
|
||||
<th>Home</th>
|
||||
<th>Pro</th>
|
||||
<th>Business</th>
|
||||
<th>Enterprise</th>
|
||||
<th>Education</th>
|
||||
<th>Mobile</th>
|
||||
<th>Mobile Enterprise</th>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><img src="images/crossmark.png" alt="cross mark" /></td>
|
||||
<td><img src="images/checkmark.png" alt="check mark" /><sup>3</sup></td>
|
||||
<td><img src="images/checkmark.png" alt="check mark" /><sup>3</sup></td>
|
||||
<td><img src="images/checkmark.png" alt="check mark" /><sup>3</sup></td>
|
||||
<td><img src="images/checkmark.png" alt="check mark" /><sup>3</sup></td>
|
||||
<td><img src="images/crossmark.png" alt="cross mark" /></td>
|
||||
<td><img src="images/crossmark.png" alt="cross mark" /></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
<!--EndSKU-->
|
||||
<!--StartDescription-->
|
||||
User Account Control: Turn on Admin Approval Mode
|
||||
|
||||
This policy setting controls the behavior of all User Account Control (UAC) policy settings for the computer. If you change this policy setting, you must restart your computer.
|
||||
|
||||
The options are:
|
||||
- 0 - Disabled: Admin Approval Mode and all related UAC policy settings are disabled. Note: If this policy setting is disabled, the Security Center notifies you that the overall security of the operating system has been reduced.
|
||||
- 1 - Enabled: (Default) Admin Approval Mode is enabled. This policy must be enabled and related UAC policy settings must also be set appropriately to allow the built-in Administrator account and all other users who are members of the Administrators group to run in Admin Approval Mode.
|
||||
|
||||
|
||||
Value type is integer. Supported operations are Add, Get, Replace, and Delete.
|
||||
|
||||
<!--EndDescription-->
|
||||
@ -931,6 +891,46 @@ The options are:
|
||||
- 0 - Disabled: An application runs with UIAccess integrity even if it does not reside in a secure location in the file system.
|
||||
- 1 - Enabled: (Default) If an application resides in a secure location in the file system, it runs only with UIAccess integrity.
|
||||
|
||||
Value type is integer. Supported operations are Add, Get, Replace, and Delete.
|
||||
|
||||
<!--EndDescription-->
|
||||
<!--EndPolicy-->
|
||||
<!--StartPolicy-->
|
||||
<a href="" id="localpoliciessecurityoptions-useraccountcontrol-runalladministratorsinadminapprovalmode"></a>**LocalPoliciesSecurityOptions/UserAccountControl_RunAllAdministratorsInAdminApprovalMode**
|
||||
|
||||
<!--StartSKU-->
|
||||
<table>
|
||||
<tr>
|
||||
<th>Home</th>
|
||||
<th>Pro</th>
|
||||
<th>Business</th>
|
||||
<th>Enterprise</th>
|
||||
<th>Education</th>
|
||||
<th>Mobile</th>
|
||||
<th>Mobile Enterprise</th>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><img src="images/crossmark.png" alt="cross mark" /></td>
|
||||
<td><img src="images/checkmark.png" alt="check mark" /><sup>3</sup></td>
|
||||
<td><img src="images/checkmark.png" alt="check mark" /><sup>3</sup></td>
|
||||
<td><img src="images/checkmark.png" alt="check mark" /><sup>3</sup></td>
|
||||
<td><img src="images/checkmark.png" alt="check mark" /><sup>3</sup></td>
|
||||
<td><img src="images/crossmark.png" alt="cross mark" /></td>
|
||||
<td><img src="images/crossmark.png" alt="cross mark" /></td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
<!--EndSKU-->
|
||||
<!--StartDescription-->
|
||||
User Account Control: Turn on Admin Approval Mode
|
||||
|
||||
This policy setting controls the behavior of all User Account Control (UAC) policy settings for the computer. If you change this policy setting, you must restart your computer.
|
||||
|
||||
The options are:
|
||||
- 0 - Disabled: Admin Approval Mode and all related UAC policy settings are disabled. Note: If this policy setting is disabled, the Security Center notifies you that the overall security of the operating system has been reduced.
|
||||
- 1 - Enabled: (Default) Admin Approval Mode is enabled. This policy must be enabled and related UAC policy settings must also be set appropriately to allow the built-in Administrator account and all other users who are members of the Administrators group to run in Admin Approval Mode.
|
||||
|
||||
|
||||
Value type is integer. Supported operations are Add, Get, Replace, and Delete.
|
||||
|
||||
<!--EndDescription-->
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Location
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - LockDown
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Maps
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Messaging
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - NetworkIsolation
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Notifications
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Power
|
||||
@ -62,7 +62,7 @@ If you disable this policy setting, standby states (S1-S3) are not allowed.
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Allow standby states (S1-S3) when sleeping (plugged in)*
|
||||
- GP English name: *Allow standby states (S1-S3) when sleeping (plugged in)*
|
||||
- GP name: *AllowStandbyStatesAC_2*
|
||||
- GP path: *System/Power Management/Sleep Settings*
|
||||
- GP ADMX file name: *power.admx*
|
||||
@ -114,7 +114,7 @@ ADMX Info:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Turn off the display (on battery)*
|
||||
- GP English name: *Turn off the display (on battery)*
|
||||
- GP name: *VideoPowerDownTimeOutDC_2*
|
||||
- GP path: *System/Power Management/Video and Display Settings*
|
||||
- GP ADMX file name: *power.admx*
|
||||
@ -166,7 +166,7 @@ ADMX Info:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Turn off the display (plugged in)*
|
||||
- GP English name: *Turn off the display (plugged in)*
|
||||
- GP name: *VideoPowerDownTimeOutAC_2*
|
||||
- GP path: *System/Power Management/Video and Display Settings*
|
||||
- GP ADMX file name: *power.admx*
|
||||
@ -219,7 +219,7 @@ ADMX Info:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Specify the system hibernate timeout (on battery)*
|
||||
- GP English name: *Specify the system hibernate timeout (on battery)*
|
||||
- GP name: *DCHibernateTimeOut_2*
|
||||
- GP path: *System/Power Management/Sleep Settings*
|
||||
- GP ADMX file name: *power.admx*
|
||||
@ -271,7 +271,7 @@ ADMX Info:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Specify the system hibernate timeout (plugged in)*
|
||||
- GP English name: *Specify the system hibernate timeout (plugged in)*
|
||||
- GP name: *ACHibernateTimeOut_2*
|
||||
- GP path: *System/Power Management/Sleep Settings*
|
||||
- GP ADMX file name: *power.admx*
|
||||
@ -321,7 +321,7 @@ If you disable this policy setting, the user is not prompted for a password when
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Require a password when a computer wakes (on battery)*
|
||||
- GP English name: *Require a password when a computer wakes (on battery)*
|
||||
- GP name: *DCPromptForPasswordOnResume_2*
|
||||
- GP path: *System/Power Management/Sleep Settings*
|
||||
- GP ADMX file name: *power.admx*
|
||||
@ -371,7 +371,7 @@ If you disable this policy setting, the user is not prompted for a password when
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Require a password when a computer wakes (plugged in)*
|
||||
- GP English name: *Require a password when a computer wakes (plugged in)*
|
||||
- GP name: *ACPromptForPasswordOnResume_2*
|
||||
- GP path: *System/Power Management/Sleep Settings*
|
||||
- GP ADMX file name: *power.admx*
|
||||
@ -423,7 +423,7 @@ ADMX Info:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Specify the system sleep timeout (on battery)*
|
||||
- GP English name: *Specify the system sleep timeout (on battery)*
|
||||
- GP name: *DCStandbyTimeOut_2*
|
||||
- GP path: *System/Power Management/Sleep Settings*
|
||||
- GP ADMX file name: *power.admx*
|
||||
@ -475,7 +475,7 @@ ADMX Info:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Specify the system sleep timeout (plugged in)*
|
||||
- GP English name: *Specify the system sleep timeout (plugged in)*
|
||||
- GP name: *ACStandbyTimeOut_2*
|
||||
- GP path: *System/Power Management/Sleep Settings*
|
||||
- GP ADMX file name: *power.admx*
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Printers
|
||||
@ -75,8 +75,9 @@ If you disable this policy setting:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Point and Print Restrictions*
|
||||
- GP English name: *Point and Print Restrictions*
|
||||
- GP name: *PointAndPrint_Restrictions_Win7*
|
||||
- GP path: *Printers*
|
||||
- GP ADMX file name: *Printing.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
@ -137,7 +138,7 @@ If you disable this policy setting:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Point and Print Restrictions*
|
||||
- GP English name: *Point and Print Restrictions*
|
||||
- GP name: *PointAndPrint_Restrictions*
|
||||
- GP path: *Control Panel/Printers*
|
||||
- GP ADMX file name: *Printing.admx*
|
||||
@ -189,8 +190,9 @@ Note: This settings takes priority over the setting "Automatically publish new p
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Allow printers to be published*
|
||||
- GP English name: *Allow printers to be published*
|
||||
- GP name: *PublishPrinters*
|
||||
- GP path: *Printers*
|
||||
- GP ADMX file name: *Printing2.admx*
|
||||
|
||||
<!--EndADMX-->
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/21/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Privacy
|
||||
@ -2630,6 +2630,5 @@ Footnote:
|
||||
- [Privacy/LetAppsRunInBackground_ForceDenyTheseApps](#privacy-letappsruninbackground-forcedenytheseapps)
|
||||
- [Privacy/LetAppsRunInBackground_UserInControlOfTheseApps](#privacy-letappsruninbackground-userincontroloftheseapps)
|
||||
- [Privacy/PublishUserActivities](#privacy-publishuseractivities)
|
||||
|
||||
<!--EndSurfaceHub-->
|
||||
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - RemoteAssistance
|
||||
@ -68,7 +68,7 @@ If you do not configure this policy setting, the user sees the default warning m
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Customize warning messages*
|
||||
- GP English name: *Customize warning messages*
|
||||
- GP name: *RA_Options*
|
||||
- GP path: *System/Remote Assistance*
|
||||
- GP ADMX file name: *remoteassistance.admx*
|
||||
@ -120,7 +120,7 @@ If you do not configure this setting, application-based settings are used.
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Turn on session logging*
|
||||
- GP English name: *Turn on session logging*
|
||||
- GP name: *RA_Logging*
|
||||
- GP path: *System/Remote Assistance*
|
||||
- GP ADMX file name: *remoteassistance.admx*
|
||||
@ -180,7 +180,7 @@ If you enable this policy setting you should also enable appropriate firewall ex
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Configure Solicited Remote Assistance*
|
||||
- GP English name: *Configure Solicited Remote Assistance*
|
||||
- GP name: *RA_Solicit*
|
||||
- GP path: *System/Remote Assistance*
|
||||
- GP ADMX file name: *remoteassistance.admx*
|
||||
@ -263,7 +263,7 @@ Allow Remote Desktop Exception
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Configure Offer Remote Assistance*
|
||||
- GP English name: *Configure Offer Remote Assistance*
|
||||
- GP name: *RA_Unsolicit*
|
||||
- GP path: *System/Remote Assistance*
|
||||
- GP ADMX file name: *remoteassistance.admx*
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - RemoteDesktopServices
|
||||
@ -68,7 +68,7 @@ You can limit the number of users who can connect simultaneously by configuring
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Allow users to connect remotely by using Remote Desktop Services*
|
||||
- GP English name: *Allow users to connect remotely by using Remote Desktop Services*
|
||||
- GP name: *TS_DISABLE_CONNECTIONS*
|
||||
- GP path: *Windows Components/Remote Desktop Services/Remote Desktop Session Host/Connections*
|
||||
- GP ADMX file name: *terminalserver.admx*
|
||||
@ -128,7 +128,7 @@ FIPS compliance can be configured through the System cryptography. Use FIPS comp
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Set client connection encryption level*
|
||||
- GP English name: *Set client connection encryption level*
|
||||
- GP name: *TS_ENCRYPTION_POLICY*
|
||||
- GP path: *Windows Components/Remote Desktop Services/Remote Desktop Session Host/Security*
|
||||
- GP ADMX file name: *terminalserver.admx*
|
||||
@ -182,7 +182,7 @@ If you do not configure this policy setting, client drive redirection and Clipbo
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Do not allow drive redirection*
|
||||
- GP English name: *Do not allow drive redirection*
|
||||
- GP name: *TS_CLIENT_DRIVE_M*
|
||||
- GP path: *Windows Components/Remote Desktop Services/Remote Desktop Session Host/Device and Resource Redirection*
|
||||
- GP ADMX file name: *terminalserver.admx*
|
||||
@ -232,7 +232,7 @@ If you disable this setting or leave it not configured, the user will be able to
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Do not allow passwords to be saved*
|
||||
- GP English name: *Do not allow passwords to be saved*
|
||||
- GP name: *TS_CLIENT_DISABLE_PASSWORD_SAVING_2*
|
||||
- GP path: *Windows Components/Remote Desktop Services/Remote Desktop Connection Client*
|
||||
- GP ADMX file name: *terminalserver.admx*
|
||||
@ -288,7 +288,7 @@ If you do not configure this policy setting, automatic logon is not specified at
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Always prompt for password upon connection*
|
||||
- GP English name: *Always prompt for password upon connection*
|
||||
- GP name: *TS_PASSWORD*
|
||||
- GP path: *Windows Components/Remote Desktop Services/Remote Desktop Session Host/Security*
|
||||
- GP ADMX file name: *terminalserver.admx*
|
||||
@ -344,7 +344,7 @@ Note: The RPC interface is used for administering and configuring Remote Desktop
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Require secure RPC communication*
|
||||
- GP English name: *Require secure RPC communication*
|
||||
- GP name: *TS_RPC_ENCRYPTION*
|
||||
- GP path: *Windows Components/Remote Desktop Services/Remote Desktop Session Host/Security*
|
||||
- GP ADMX file name: *terminalserver.admx*
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - RemoteManagement
|
||||
@ -56,7 +56,7 @@ ms.date: 08/09/2017
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Allow Basic authentication*
|
||||
- GP English name: *Allow Basic authentication*
|
||||
- GP name: *AllowBasic_2*
|
||||
- GP path: *Windows Components/Windows Remote Management (WinRM)/WinRM Client*
|
||||
- GP ADMX file name: *WindowsRemoteManagement.admx*
|
||||
@ -100,7 +100,7 @@ ADMX Info:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Allow Basic authentication*
|
||||
- GP English name: *Allow Basic authentication*
|
||||
- GP name: *AllowBasic_1*
|
||||
- GP path: *Windows Components/Windows Remote Management (WinRM)/WinRM Service*
|
||||
- GP ADMX file name: *WindowsRemoteManagement.admx*
|
||||
@ -144,7 +144,7 @@ ADMX Info:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Allow CredSSP authentication*
|
||||
- GP English name: *Allow CredSSP authentication*
|
||||
- GP name: *AllowCredSSP_2*
|
||||
- GP path: *Windows Components/Windows Remote Management (WinRM)/WinRM Client*
|
||||
- GP ADMX file name: *WindowsRemoteManagement.admx*
|
||||
@ -188,7 +188,7 @@ ADMX Info:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Allow CredSSP authentication*
|
||||
- GP English name: *Allow CredSSP authentication*
|
||||
- GP name: *AllowCredSSP_1*
|
||||
- GP path: *Windows Components/Windows Remote Management (WinRM)/WinRM Service*
|
||||
- GP ADMX file name: *WindowsRemoteManagement.admx*
|
||||
@ -232,7 +232,7 @@ ADMX Info:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Allow remote server management through WinRM*
|
||||
- GP English name: *Allow remote server management through WinRM*
|
||||
- GP name: *AllowAutoConfig*
|
||||
- GP path: *Windows Components/Windows Remote Management (WinRM)/WinRM Service*
|
||||
- GP ADMX file name: *WindowsRemoteManagement.admx*
|
||||
@ -276,7 +276,7 @@ ADMX Info:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Allow unencrypted traffic*
|
||||
- GP English name: *Allow unencrypted traffic*
|
||||
- GP name: *AllowUnencrypted_2*
|
||||
- GP path: *Windows Components/Windows Remote Management (WinRM)/WinRM Client*
|
||||
- GP ADMX file name: *WindowsRemoteManagement.admx*
|
||||
@ -320,7 +320,7 @@ ADMX Info:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Allow unencrypted traffic*
|
||||
- GP English name: *Allow unencrypted traffic*
|
||||
- GP name: *AllowUnencrypted_1*
|
||||
- GP path: *Windows Components/Windows Remote Management (WinRM)/WinRM Service*
|
||||
- GP ADMX file name: *WindowsRemoteManagement.admx*
|
||||
@ -364,7 +364,7 @@ ADMX Info:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Disallow Digest authentication*
|
||||
- GP English name: *Disallow Digest authentication*
|
||||
- GP name: *DisallowDigest*
|
||||
- GP path: *Windows Components/Windows Remote Management (WinRM)/WinRM Client*
|
||||
- GP ADMX file name: *WindowsRemoteManagement.admx*
|
||||
@ -408,7 +408,7 @@ ADMX Info:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Disallow Negotiate authentication*
|
||||
- GP English name: *Disallow Negotiate authentication*
|
||||
- GP name: *DisallowNegotiate_2*
|
||||
- GP path: *Windows Components/Windows Remote Management (WinRM)/WinRM Client*
|
||||
- GP ADMX file name: *WindowsRemoteManagement.admx*
|
||||
@ -452,7 +452,7 @@ ADMX Info:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Disallow Negotiate authentication*
|
||||
- GP English name: *Disallow Negotiate authentication*
|
||||
- GP name: *DisallowNegotiate_1*
|
||||
- GP path: *Windows Components/Windows Remote Management (WinRM)/WinRM Service*
|
||||
- GP ADMX file name: *WindowsRemoteManagement.admx*
|
||||
@ -496,7 +496,7 @@ ADMX Info:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Disallow WinRM from storing RunAs credentials*
|
||||
- GP English name: *Disallow WinRM from storing RunAs credentials*
|
||||
- GP name: *DisableRunAs*
|
||||
- GP path: *Windows Components/Windows Remote Management (WinRM)/WinRM Service*
|
||||
- GP ADMX file name: *WindowsRemoteManagement.admx*
|
||||
@ -540,7 +540,7 @@ ADMX Info:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Specify channel binding token hardening level*
|
||||
- GP English name: *Specify channel binding token hardening level*
|
||||
- GP name: *CBTHardeningLevel_1*
|
||||
- GP path: *Windows Components/Windows Remote Management (WinRM)/WinRM Service*
|
||||
- GP ADMX file name: *WindowsRemoteManagement.admx*
|
||||
@ -584,7 +584,7 @@ ADMX Info:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Trusted Hosts*
|
||||
- GP English name: *Trusted Hosts*
|
||||
- GP name: *TrustedHosts*
|
||||
- GP path: *Windows Components/Windows Remote Management (WinRM)/WinRM Client*
|
||||
- GP ADMX file name: *WindowsRemoteManagement.admx*
|
||||
@ -628,7 +628,7 @@ ADMX Info:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Turn On Compatibility HTTP Listener*
|
||||
- GP English name: *Turn On Compatibility HTTP Listener*
|
||||
- GP name: *HttpCompatibilityListener*
|
||||
- GP path: *Windows Components/Windows Remote Management (WinRM)/WinRM Service*
|
||||
- GP ADMX file name: *WindowsRemoteManagement.admx*
|
||||
@ -672,7 +672,7 @@ ADMX Info:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Turn On Compatibility HTTPS Listener*
|
||||
- GP English name: *Turn On Compatibility HTTPS Listener*
|
||||
- GP name: *HttpsCompatibilityListener*
|
||||
- GP path: *Windows Components/Windows Remote Management (WinRM)/WinRM Service*
|
||||
- GP ADMX file name: *WindowsRemoteManagement.admx*
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - RemoteProcedureCall
|
||||
@ -66,7 +66,7 @@ Note: This policy will not be applied until the system is rebooted.
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Enable RPC Endpoint Mapper Client Authentication*
|
||||
- GP English name: *Enable RPC Endpoint Mapper Client Authentication*
|
||||
- GP name: *RpcEnableAuthEpResolution*
|
||||
- GP path: *System/Remote Procedure Call*
|
||||
- GP ADMX file name: *rpc.admx*
|
||||
@ -128,7 +128,7 @@ Note: This policy setting will not be applied until the system is rebooted.
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Restrict Unauthenticated RPC clients*
|
||||
- GP English name: *Restrict Unauthenticated RPC clients*
|
||||
- GP name: *RpcRestrictRemoteClients*
|
||||
- GP path: *System/Remote Procedure Call*
|
||||
- GP ADMX file name: *rpc.admx*
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - RemoteShell
|
||||
@ -56,7 +56,7 @@ ms.date: 08/09/2017
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Allow Remote Shell Access*
|
||||
- GP English name: *Allow Remote Shell Access*
|
||||
- GP name: *AllowRemoteShellAccess*
|
||||
- GP path: *Windows Components/Windows Remote Shell*
|
||||
- GP ADMX file name: *WindowsRemoteShell.admx*
|
||||
@ -100,7 +100,7 @@ ADMX Info:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *MaxConcurrentUsers*
|
||||
- GP English name: *MaxConcurrentUsers*
|
||||
- GP name: *MaxConcurrentUsers*
|
||||
- GP path: *Windows Components/Windows Remote Shell*
|
||||
- GP ADMX file name: *WindowsRemoteShell.admx*
|
||||
@ -144,7 +144,7 @@ ADMX Info:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Specify idle Timeout*
|
||||
- GP English name: *Specify idle Timeout*
|
||||
- GP name: *IdleTimeout*
|
||||
- GP path: *Windows Components/Windows Remote Shell*
|
||||
- GP ADMX file name: *WindowsRemoteShell.admx*
|
||||
@ -188,7 +188,7 @@ ADMX Info:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Specify maximum amount of memory in MB per Shell*
|
||||
- GP English name: *Specify maximum amount of memory in MB per Shell*
|
||||
- GP name: *MaxMemoryPerShellMB*
|
||||
- GP path: *Windows Components/Windows Remote Shell*
|
||||
- GP ADMX file name: *WindowsRemoteShell.admx*
|
||||
@ -232,7 +232,7 @@ ADMX Info:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Specify maximum number of processes per Shell*
|
||||
- GP English name: *Specify maximum number of processes per Shell*
|
||||
- GP name: *MaxProcessesPerShell*
|
||||
- GP path: *Windows Components/Windows Remote Shell*
|
||||
- GP ADMX file name: *WindowsRemoteShell.admx*
|
||||
@ -276,7 +276,7 @@ ADMX Info:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Specify maximum number of remote shells per user*
|
||||
- GP English name: *Specify maximum number of remote shells per user*
|
||||
- GP name: *MaxShellsPerUser*
|
||||
- GP path: *Windows Components/Windows Remote Shell*
|
||||
- GP ADMX file name: *WindowsRemoteShell.admx*
|
||||
@ -320,7 +320,7 @@ ADMX Info:
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Specify Shell Timeout*
|
||||
- GP English name: *Specify Shell Timeout*
|
||||
- GP name: *ShellTimeOut*
|
||||
- GP path: *Windows Components/Windows Remote Shell*
|
||||
- GP ADMX file name: *WindowsRemoteShell.admx*
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Search
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Security
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Settings
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - SmartScreen
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Speech
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Start
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Storage
|
||||
@ -62,7 +62,7 @@ If you disable or do not configure this policy setting, Windows will activate un
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Do not allow Windows to activate Enhanced Storage devices*
|
||||
- GP English name: *Do not allow Windows to activate Enhanced Storage devices*
|
||||
- GP name: *TCGSecurityActivationDisabled*
|
||||
- GP path: *System/Enhanced Storage Access*
|
||||
- GP ADMX file name: *enhancedstorage.admx*
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - System
|
||||
@ -546,7 +546,7 @@ Also, see the "Turn off System Restore configuration" policy setting. If the "Tu
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Turn off System Restore*
|
||||
- GP English name: *Turn off System Restore*
|
||||
- GP name: *SR_DisableSR*
|
||||
- GP path: *System/System Restore*
|
||||
- GP ADMX file name: *systemrestore.admx*
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - TextInput
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - TimeLanguageSettings
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/25/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Update
|
||||
@ -46,8 +46,6 @@ ms.date: 08/25/2017
|
||||
|
||||
<!--EndSKU-->
|
||||
<!--StartDescription-->
|
||||
|
||||
|
||||
<p style="margin-left: 20px">Added in Windows 10, version 1607. Allows the IT admin (when used with **Update/ActiveHoursStart**) to manage a range of active hours where update reboots are not scheduled. This value sets the end time. There is a 12 hour maximum from start time.
|
||||
|
||||
> [!NOTE]
|
||||
@ -86,8 +84,6 @@ ms.date: 08/25/2017
|
||||
|
||||
<!--EndSKU-->
|
||||
<!--StartDescription-->
|
||||
|
||||
|
||||
<p style="margin-left: 20px">Added in Windows 10, version 1703. Allows the IT admin to specify the max active hours range. This value sets max number of active hours from start time.
|
||||
|
||||
<p style="margin-left: 20px">Supported values are 8-18.
|
||||
@ -123,8 +119,6 @@ ms.date: 08/25/2017
|
||||
|
||||
<!--EndSKU-->
|
||||
<!--StartDescription-->
|
||||
|
||||
|
||||
<p style="margin-left: 20px">Added in Windows 10, version 1607. Allows the IT admin (when used with **Update/ActiveHoursEnd**) to manage a range of hours where update reboots are not scheduled. This value sets the start time. There is a 12 hour maximum from end time.
|
||||
|
||||
> [!NOTE]
|
||||
@ -163,7 +157,6 @@ ms.date: 08/25/2017
|
||||
|
||||
<!--EndSKU-->
|
||||
<!--StartDescription-->
|
||||
|
||||
<p style="margin-left: 20px">Enables the IT admin to manage automatic update behavior to scan, download, and install updates.
|
||||
|
||||
<p style="margin-left: 20px">Supported operations are Get and Replace.
|
||||
@ -212,7 +205,6 @@ ms.date: 08/25/2017
|
||||
|
||||
<!--EndSKU-->
|
||||
<!--StartDescription-->
|
||||
|
||||
<p style="margin-left: 20px">Added in Windows 10, version 1607. Allows the IT admin to manage whether to scan for app updates from Microsoft Update.
|
||||
|
||||
<p style="margin-left: 20px">The following list shows the supported values:
|
||||
@ -249,7 +241,6 @@ ms.date: 08/25/2017
|
||||
|
||||
<!--EndSKU-->
|
||||
<!--StartDescription-->
|
||||
|
||||
<p style="margin-left: 20px">Allows the IT admin to manage whether Automatic Updates accepts updates signed by entities other than Microsoft when the update is found at the UpdateServiceUrl location. This policy supports using WSUS for 3rd party software and patch distribution.
|
||||
|
||||
<p style="margin-left: 20px">Supported operations are Get and Replace.
|
||||
@ -290,7 +281,6 @@ ms.date: 08/25/2017
|
||||
|
||||
<!--EndSKU-->
|
||||
<!--StartDescription-->
|
||||
|
||||
<p style="margin-left: 20px">Specifies whether the device could use Microsoft Update, Windows Server Update Services (WSUS), or Windows Store.
|
||||
|
||||
<p style="margin-left: 20px">Even when Windows Update is configured to receive updates from an intranet update service, it will periodically retrieve information from the public Windows Update service to enable future connections to Windows Update, and other services like Microsoft Update or the Windows Store
|
||||
@ -369,7 +359,6 @@ ms.date: 08/25/2017
|
||||
|
||||
<!--EndSKU-->
|
||||
<!--StartDescription-->
|
||||
|
||||
<p style="margin-left: 20px">Added in Windows 10, version 1703. Allows the IT Admin to specify the period for auto-restart reminder notifications.
|
||||
|
||||
<p style="margin-left: 20px">Supported values are 15, 30, 60, 120, and 240 (minutes).
|
||||
@ -405,7 +394,6 @@ ms.date: 08/25/2017
|
||||
|
||||
<!--EndSKU-->
|
||||
<!--StartDescription-->
|
||||
|
||||
<p style="margin-left: 20px">Added in Windows 10, version 1703. Allows the IT Admin to specify the method by which the auto-restart required notification is dismissed.
|
||||
|
||||
<p style="margin-left: 20px">The following list shows the supported values:
|
||||
@ -442,7 +430,6 @@ ms.date: 08/25/2017
|
||||
|
||||
<!--EndSKU-->
|
||||
<!--StartDescription-->
|
||||
|
||||
<p style="margin-left: 20px">Added in Windows 10, version 1607. Allows the IT admin to set which branch a device receives their updates from.
|
||||
|
||||
<p style="margin-left: 20px">The following list shows the supported values:
|
||||
@ -479,7 +466,6 @@ ms.date: 08/25/2017
|
||||
|
||||
<!--EndSKU-->
|
||||
<!--StartDescription-->
|
||||
|
||||
<p style="margin-left: 20px">Since this policy is not blocked, you will not get a failure message when you use it to configure a Windows 10 Mobile device. However, the policy will not take effect.
|
||||
|
||||
<p style="margin-left: 20px">Added in Windows 10, version 1607. Defers Feature Updates for the specified number of days.
|
||||
@ -518,7 +504,6 @@ ms.date: 08/25/2017
|
||||
|
||||
<!--EndSKU-->
|
||||
<!--StartDescription-->
|
||||
|
||||
<p style="margin-left: 20px">Added in Windows 10, version 1607. Defers Quality Updates for the specified number of days.
|
||||
|
||||
<p style="margin-left: 20px">Supported values are 0-30.
|
||||
@ -763,7 +748,6 @@ If a machine has Microsoft Update enabled, any Microsoft Updates in these catego
|
||||
|
||||
<!--EndSKU-->
|
||||
<!--StartDescription-->
|
||||
|
||||
<p style="margin-left: 20px">Added in Windows 10, version 1703. Allows the IT Admin to specify the deadline in days before automatically scheduling and executing a pending restart outside of active hours. The deadline can be set between 2 and 30 days from the time the restart becomes pending. If configured, the pending restart will transition from Auto-restart to Engaged restart (pending user schedule) to be automatically executed within the specified period. If no deadline is specified or deadline is set to 0, the restart will not be automatically executed and will remain Engaged restart (pending user scheduling).
|
||||
|
||||
<p style="margin-left: 20px">Supported values are 2-30 days.
|
||||
@ -799,7 +783,6 @@ If a machine has Microsoft Update enabled, any Microsoft Updates in these catego
|
||||
|
||||
<!--EndSKU-->
|
||||
<!--StartDescription-->
|
||||
|
||||
<p style="margin-left: 20px">Added in Windows 10, version 1703. Allows the IT Admin to control the number of days a user can snooze Engaged restart reminder notifications.
|
||||
|
||||
<p style="margin-left: 20px">Supported values are 1-3 days.
|
||||
@ -835,7 +818,6 @@ If a machine has Microsoft Update enabled, any Microsoft Updates in these catego
|
||||
|
||||
<!--EndSKU-->
|
||||
<!--StartDescription-->
|
||||
|
||||
<p style="margin-left: 20px">Added in Windows 10, version 1703. Allows the IT Admin to control the timing before transitioning from Auto restarts scheduled outside of active hours to Engaged restart, which requires the user to schedule. The period can be set between 2 and 30 days from the time the restart becomes pending.
|
||||
|
||||
<p style="margin-left: 20px">Supported values are 2-30 days.
|
||||
@ -1161,7 +1143,6 @@ If a machine has Microsoft Update enabled, any Microsoft Updates in these catego
|
||||
|
||||
<!--EndSKU-->
|
||||
<!--StartDescription-->
|
||||
|
||||
<p style="margin-left: 20px">Added in Windows 10, version 1607. Allows IT Admins to pause Quality Updates.
|
||||
|
||||
<p style="margin-left: 20px">The following list shows the supported values:
|
||||
@ -1313,7 +1294,6 @@ If a machine has Microsoft Update enabled, any Microsoft Updates in these catego
|
||||
|
||||
<!--EndSKU-->
|
||||
<!--StartDescription-->
|
||||
|
||||
<p style="margin-left: 20px">Added in Windows 10, version 1703. Allows the IT Admin to specify the period for auto-restart imminent warning notifications.
|
||||
|
||||
<p style="margin-left: 20px">Supported values are 15, 30, or 60 (minutes).
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - Wifi
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - WindowsDefenderSecurityCenter
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - WindowsInkWorkspace
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - WindowsLogon
|
||||
@ -62,7 +62,7 @@ If you disable or do not configure this policy setting, users can choose which a
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Turn off app notifications on the lock screen*
|
||||
- GP English name: *Turn off app notifications on the lock screen*
|
||||
- GP name: *DisableLockScreenAppNotifications*
|
||||
- GP path: *System/Logon*
|
||||
- GP ADMX file name: *logon.admx*
|
||||
@ -112,7 +112,7 @@ If you disable or don't configure this policy setting, any user can disconnect t
|
||||
|
||||
<!--StartADMX-->
|
||||
ADMX Info:
|
||||
- GP english name: *Do not display network selection UI*
|
||||
- GP English name: *Do not display network selection UI*
|
||||
- GP name: *DontDisplayNetworkSelectionUI*
|
||||
- GP path: *System/Logon*
|
||||
- GP ADMX file name: *logon.admx*
|
||||
|
@ -6,7 +6,7 @@ ms.topic: article
|
||||
ms.prod: w10
|
||||
ms.technology: windows
|
||||
author: nickbrower
|
||||
ms.date: 08/09/2017
|
||||
ms.date: 08/30/2017
|
||||
---
|
||||
|
||||
# Policy CSP - WirelessDisplay
|
||||
|
Loading…
x
Reference in New Issue
Block a user