2018-05-11 10:45:43 -07:00

2.3 MiB
Raw Blame History

title, description, ms.assetid, ms.author, ms.topic, ms.prod, ms.technology, author, ms.date
title description ms.assetid ms.author ms.topic ms.prod ms.technology author ms.date
Policy DDF file Policy DDF file D90791B5-A772-4AF8-B058-5D566865AF8D maricia article w10 windows MariciaAlforque 04/26/2018

Policy DDF file

This topic shows the OMA DM device description framework (DDF) for the Policy configuration service provider. DDF files are used only with OMA DM provisioning XML.

You can download the DDF files from the links below:

The XML below is the DDF for Windows 10, version 1803.

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE MgmtTree PUBLIC " -//OMA//DTD-DM-DDF 1.2//EN"
  "http://www.openmobilealliance.org/tech/DTD/DM_DDF-V1_2.dtd"
  [<?oma-dm-ddf-ver supported-versions="1.2"?>]>
<MgmtTree xmlns:MSFT="http://schemas.microsoft.com/MobileDevice/DM">
  <VerDTD>1.2</VerDTD>
  <Node>
    <NodeName>Policy</NodeName>
    <Path>./User/Vendor/MSFT</Path>
    <DFProperties>
      <AccessType>
        <Get />
      </AccessType>
      <DFFormat>
        <node />
      </DFFormat>
      <Occurrence>
        <One />
      </Occurrence>
      <Scope>
        <Permanent />
      </Scope>
      <DFType>
        <MIME>com.microsoft/7.0/MDM/Policy</MIME>
      </DFType>
    </DFProperties>
    <Node>
      <NodeName>Config</NodeName>
      <DFProperties>
        <AccessType>
          <Add />
          <Delete />
          <Get />
        </AccessType>
        <DFFormat>
          <node />
        </DFFormat>
        <Occurrence>
          <ZeroOrOne />
        </Occurrence>
        <Scope>
          <Dynamic />
        </Scope>
        <DFType>
          <DDFName></DDFName>
        </DFType>
      </DFProperties>
      <Node>
        <NodeName>ApplicationManagement</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>MSIAlwaysInstallWithElevatedPrivileges</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RequirePrivateStoreOnly</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>AttachmentManager</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>DoNotPreserveZoneInformation</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideZoneInfoMechanism</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NotifyAntivirusPrograms</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Authentication</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowEAPCertSSO</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Autoplay</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>DisallowAutoplayForNonVolumeDevices</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SetDefaultAutoRunBehavior</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TurnOffAutoPlay</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Browser</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowAddressBarDropdown</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting lets you decide whether the Address bar drop-down functionality is available in Microsoft Edge. We recommend disabling this setting if you want to minimize network connections from Microsoft Edge to Microsoft services.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowAutofill</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting lets you decide whether employees can use Autofill to automatically fill in form fields while using Microsoft Edge.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowBrowser</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowConfigurationUpdateForBooksLibrary</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting lets you decide whether Microsoft Edge can automatically update the configuration data for the Books Library.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowCookies</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting lets you configure how your company deals with cookies.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowDeveloperTools</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting lets you decide whether employees can use F12 Developer Tools on Microsoft Edge.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowDoNotTrack</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting lets you decide whether employees can send Do Not Track headers to websites that request tracking info.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowExtensions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting lets you decide whether employees can load extensions in Microsoft Edge.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowFlash</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting lets you decide whether employees can run Adobe Flash in Microsoft Edge.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowFlashClickToRun</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Configure the Adobe Flash Click-to-Run setting.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowInPrivate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting lets you decide whether employees can browse using InPrivate website browsing.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowMicrosoftCompatibilityList</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting lets you decide whether the Microsoft Compatibility List is enabled or disabled in Microsoft Edge. This feature uses a Microsoft-provided list to ensure that any sites with known compatibility issues are displayed correctly when a user navigates to them. By default, the Microsoft Compatibility List is enabled and can be viewed by navigating to about:compat.

If you enable or dont configure this setting, Microsoft Edge will periodically download the latest version of the list from Microsoft and will apply the configurations specified there during browser navigation. If a user visits a site on the Microsoft Compatibility List, he or she will be prompted to open the site in Internet Explorer 11. Once in Internet Explorer, the site will automatically be rendered as if the user is viewing it in the previous version of Internet Explorer it requires to display correctly.

If you disable this setting, the Microsoft Compatibility List will not be used during browser navigation.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPasswordManager</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting lets you decide whether employees can save their passwords locally, using Password Manager.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPopups</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting lets you decide whether to turn on Pop-up Blocker and whether to allow pop-ups to appear in secondary windows.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSearchEngineCustomization</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Allow search engine customization for MDM enrolled devices. Users can change their default search engine.

If this setting is turned on or not configured, users can add new search engines and change the default used in the address bar from within Microsoft Edge Settings.
If this setting is disabled, users will be unable to add search engines or change the default used in the address bar.

This policy will only apply on domain joined machines or when the device is MDM enrolled. For more information, see Microsoft browser extension policy (aka.ms/browserpolicy).</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSearchSuggestionsinAddressBar</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting lets you decide whether search suggestions should appear in the Address bar of Microsoft Edge.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSmartScreen</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting lets you decide whether to turn on Windows Defender SmartScreen.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AlwaysEnableBooksLibrary</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Specifies whether the Books Library in Microsoft Edge will always be visible regardless of the country or region setting for the device.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ClearBrowsingDataOnExit</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Specifies whether to always clear browsing history on exiting Microsoft Edge.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConfigureAdditionalSearchEngines</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Allows you to add up to 5 additional search engines for MDM-enrolled devices.

If this setting is turned on, you can add up to 5 additional search engines for your employee. For each additional search engine you wish to add, you must specify a link to the OpenSearch XML file that contains, at minimum, the short name and the URL to the search engine. This policy does not affect the default search engine. Employees will not be able to remove these search engines, but they can set any one of these as the default.

If this setting is not configured, the search engines are the ones specified in the App settings. If this setting is disabled, the search engines you had added will be deleted from your employee's machine.

Due to Protected Settings (aka.ms/browserpolicy), this policy will only apply on domain-joined machines or when the device is MDM-enrolled.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableLockdownOfStartPages</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Boolean policy that specifies whether the lockdown on the Start pages is disabled. This policy works with the Browser/HomePages policy, which locks down the Start pages that the users cannot modify. You can use the DisableLockdownOfStartPages policy to allow users to modify the Start pages when Browser/HomePages policy is in effect.

Note: This policy has no effect when Browser/HomePages is not configured.

Important
This setting can only be used with domain-joined or MDM-enrolled devices. For more info, see the Microsoft browser extension policy (aka.ms/browserpolicy).</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableExtendedBooksTelemetry</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting allows organizations to send extended telemetry on book usage from the Books Library.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnterpriseModeSiteList</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting lets you configure whether your company uses Enterprise Mode and the Enterprise Mode Site List to address common compatibility problems with legacy websites.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnterpriseSiteListServiceUrl</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>FirstRunURL</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Configure first run URL.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HomePages</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Configure the Start page URLs for your employees.
Example:
If you wanted to allow contoso.com and fabrikam.com then you would append /support to the site strings like contoso.com/support and fabrikam.com/support.
Encapsulate each string with greater than and less than characters like any other XML tag.

Version 1703 or later: If you don't want to send traffic to Microsoft, you can use the about:blank value (encapsulate with greater than and less than characters like any other XML tag), which is honored for both domain- and non-domain-joined machines, when it's the only configured URL.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockdownFavorites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting lets you decide whether employees can add, import, sort, or edit the Favorites list on Microsoft Edge.

If you enable this setting, employees won't be able to add, import, or change anything in the Favorites list. Also as part of this, Save a Favorite, Import settings, and the context menu items (such as, Create a new folder) are all turned off.

Important
Don't enable both this setting and the Keep favorites in sync between Internet Explorer and Microsoft Edge setting. Enabling both settings stops employees from syncing their favorites between Internet Explorer and Microsoft Edge.

If you disable or don't configure this setting (default), employees can add, import and make changes to the Favorites list.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventAccessToAboutFlagsInMicrosoftEdge</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Prevent access to the about:flags page in Microsoft Edge.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventFirstRunPage</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Specifies whether the First Run webpage is prevented from automatically opening on the first launch of Microsoft Edge. This policy is only available for Windows 10 version 1703 or later for desktop.

Due to Protected Settings (aka.ms/browserpolicy), this policy will only apply on domain-joined machines or when the device is MDM-enrolled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventLiveTileDataCollection</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy lets you decide whether Microsoft Edge can gather Live Tile metadata from the ieonline.microsoft.com service to provide a better experience while pinning a Live Tile to the Start menu.

Due to Protected Settings (aka.ms/browserpolicy), this policy will only apply on domain-joined machines or when the device is MDM-enrolled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventSmartScreenPromptOverride</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Don't allow Windows Defender SmartScreen warning overrides</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventSmartScreenPromptOverrideForFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Don't allow Windows Defender SmartScreen warning overrides for unverified files.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventTabPreloading</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Prevent Microsoft Edge from starting and loading the Start and New Tab page at Windows startup and each time Microsoft Edge is closed.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventUsingLocalHostIPAddressForWebRTC</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Prevent using localhost IP address for WebRTC</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ProvisionFavorites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting allows you to configure a default set of favorites, which will appear for employees. Employees cannot modify, sort, move, export or delete these provisioned favorites.

If you enable this setting, you can set favorite URL's and favorite folders to appear on top of users' favorites list (either in the Hub or Favorites Bar). The user favorites will appear after these provisioned favorites.

Important
Don't enable both this setting and the Keep favorites in sync between Internet Explorer and Microsoft Edge setting. Enabling both settings stops employees from syncing their favorites between Internet Explorer and Microsoft Edge.

If you disable or don't configure this setting, employees will see the favorites they set in the Hub and Favorites Bar.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SendIntranetTraffictoInternetExplorer</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Sends all intranet traffic over to Internet Explorer.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SetDefaultSearchEngine</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Sets the default search engine for MDM-enrolled devices. Users can still change their default search engine.

If this setting is turned on, you are setting the default search engine that you would like your employees to use. Employees can still change the default search engine, unless you apply the AllowSearchEngineCustomization policy which will disable the ability to change it. You must specify a link to the OpenSearch XML file that contains, at minimum, the short name and the URL to the search engine. If you would like for your employees to use the Edge factory settings for the default search engine for their market, set the string EDGEDEFAULT; if you would like for your employees to use Bing as the default search engine, set the string EDGEBING.

If this setting is not configured, the default search engine is set to the one specified in App settings and can be changed by your employees.  If this setting is disabled, the policy-set search engine will be removed, and, if it is the current default, the default will be set back to the factory Microsoft Edge search engine for the market.

Due to Protected Settings (aka.ms/browserpolicy), this policy will only apply on domain-joined machines or when the device is MDM-enrolled.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ShowMessageWhenOpeningSitesInInternetExplorer</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Show message when opening sites in Internet Explorer</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SyncFavoritesBetweenIEAndMicrosoftEdge</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Specifies whether favorites are kept in sync between Internet Explorer and Microsoft Edge. Changes to favorites in one browser are reflected in the other, including: additions, deletions, modifications, and ordering.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UseSharedFolderForBooks</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting specifies whether organizations should use a folder shared across users to store books from the Books Library.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>CredentialsUI</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>DisablePasswordReveal</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Desktop</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>PreventUserRedirectionOfProfileFolders</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Display</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>EnablePerProcessDpi</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Enable or disable Per-Process System DPI for all applications.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Education</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>DefaultPrinterName</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy sets user's default printer</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventAddingNewPrinters</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Boolean that specifies whether or not to prevent user to install new printers</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PrinterNames</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy provisions per-user network printers</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>EnterpriseCloudPrint</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>CloudPrinterDiscoveryEndPoint</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy provisions per-user discovery end point to discover cloud printers</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>CloudPrintOAuthAuthority</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Authentication endpoint for acquiring OAuth tokens</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>CloudPrintOAuthClientId</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>A GUID identifying the client application authorized to retrieve OAuth tokens from the OAuthAuthority</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>CloudPrintResourceId</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Resource URI for which access is being requested by the Enterprise Cloud Print client during OAuth authentication</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DiscoveryMaxPrinterLimit</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Defines the maximum number of printers that should be queried from discovery end point</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MopriaDiscoveryResourceId</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Resource URI for which access is being requested by the Mopria discovery client during OAuth authentication</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Experience</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowTailoredExperiencesWithDiagnosticData</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowThirdPartySuggestionsInWindowsSpotlight</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowWindowsSpotlight</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowWindowsSpotlightOnActionCenter</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowWindowsSpotlightOnSettings</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowWindowsSpotlightWindowsWelcomeExperience</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConfigureWindowsSpotlightOnLockScreen</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>InternetExplorer</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AddSearchProvider</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowActiveXFiltering</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowAddOnList</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowAutoComplete</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowCertificateAddressMismatchWarning</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowDeletingBrowsingHistoryOnExit</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowEnhancedProtectedMode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowEnterpriseModeFromToolsMenu</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowEnterpriseModeSiteList</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowInternetExplorer7PolicyList</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowInternetExplorerStandardsMode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowInternetZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowIntranetZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLocalMachineZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLockedDownInternetZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLockedDownIntranetZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLockedDownLocalMachineZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLockedDownRestrictedSitesZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowOneWordEntry</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSiteToZoneAssignmentList</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowsLockedDownTrustedSitesZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSoftwareWhenSignatureIsInvalid</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowsRestrictedSitesZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSuggestedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowTrustedSitesZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>CheckServerCertificateRevocation</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>CheckSignaturesOnDownloadedPrograms</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConsistentMimeHandlingInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableAdobeFlash</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableBypassOfSmartScreenWarnings</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableBypassOfSmartScreenWarningsAboutUncommonFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableConfiguringHistory</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableCrashDetection</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableCustomerExperienceImprovementProgramParticipation</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableDeletingUserVisitedWebsites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableEnclosureDownloading</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableEncryptionSupport</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableFirstRunWizard</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableFlipAheadFeature</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableHomePageChange</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableIgnoringCertificateErrors</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableInPrivateBrowsing</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableProcessesInEnhancedProtectedMode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableProxyChange</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableSearchProviderChange</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableSecondaryHomePageChange</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableSecuritySettingsCheck</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DoNotAllowActiveXControlsInProtectedMode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DoNotBlockOutdatedActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DoNotBlockOutdatedActiveXControlsOnSpecificDomains</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IncludeAllLocalSites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IncludeAllNetworkPaths</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowCopyPasteViaScript</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowDragAndDropCopyAndPasteFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowLoadingOfXAMLFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowOnlyApprovedDomainsToUseActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowOnlyApprovedDomainsToUseTDCActiveXControl</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowScriptingOfInternetExplorerWebBrowserControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowScriptInitiatedWindows</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowUpdatesToStatusBarViaScript</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowVBScriptToRunInInternetExplorer</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneDoNotRunAntimalwareAgainstActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneDownloadSignedActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneDownloadUnsignedActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneEnableCrossSiteScriptingFilter</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneEnableDraggingOfContentFromDifferentDomainsAcrossWindows</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneEnableDraggingOfContentFromDifferentDomainsWithinWindows</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneEnableMIMESniffing</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneEnableProtectedMode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneIncludeLocalPathWhenUploadingFilesToServer</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneLaunchingApplicationsAndFilesInIFRAME</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneLogonOptions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneRunNETFrameworkReliantComponentsSignedWithAuthenticode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneShowSecurityWarningForPotentiallyUnsafeFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneUsePopupBlocker</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneDoNotRunAntimalwareAgainstActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneDoNotRunAntimalwareAgainstActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MimeSniffingSafetyFeatureInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MKProtocolSecurityRestrictionInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NotificationBarInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventManagingSmartScreenFilter</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventPerUserInstallationOfActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ProtectionFromZoneElevationInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RemoveRunThisTimeButtonForOutdatedActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictActiveXInstallInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowActiveScripting</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowBinaryAndScriptBehaviors</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowCopyPasteViaScript</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowDragAndDropCopyAndPasteFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowLoadingOfXAMLFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowMETAREFRESH</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowOnlyApprovedDomainsToUseActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowOnlyApprovedDomainsToUseTDCActiveXControl</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowScriptingOfInternetExplorerWebBrowserControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowScriptInitiatedWindows</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowUpdatesToStatusBarViaScript</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowVBScriptToRunInInternetExplorer</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneDoNotRunAntimalwareAgainstActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneDownloadSignedActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneDownloadUnsignedActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneEnableCrossSiteScriptingFilter</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneEnableDraggingOfContentFromDifferentDomainsAcrossWindows</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneEnableDraggingOfContentFromDifferentDomainsWithinWindows</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneEnableMIMESniffing</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneIncludeLocalPathWhenUploadingFilesToServer</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneLaunchingApplicationsAndFilesInIFRAME</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneLogonOptions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneRunActiveXControlsAndPlugins</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneRunNETFrameworkReliantComponentsSignedWithAuthenticode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneScriptActiveXControlsMarkedSafeForScripting</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneScriptingOfJavaApplets</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneShowSecurityWarningForPotentiallyUnsafeFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneTurnOnProtectedMode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneUsePopupBlocker</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictFileDownloadInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScriptedWindowSecurityRestrictionsInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SearchProviderList</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SpecifyUseOfActiveXInstallerService</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneDoNotRunAntimalwareAgainstActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>KioskBrowser</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>BlockedUrlExceptions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of exceptions to the blocked website URLs (with wildcard support). This is used to configure URLs kiosk browsers are allowed to navigate to, which are a subset of the blocked URLs.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>BlockedUrls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of blocked website URLs (with wildcard support). This is used to configure blocked URLs kiosk browsers can not navigate to.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DefaultURL</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Configures the default URL kiosk browsers to navigate on launch and restart.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableEndSessionButton</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Enable/disable kiosk browser's end session button.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableHomeButton</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Enable/disable kiosk browser's home button.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableNavigationButtons</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Enable/disable kiosk browser's navigation buttons (forward/back).</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestartOnIdleTime</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Amount of time in minutes the session is idle until the kiosk browser restarts in a fresh state.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Notifications</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>DisallowNotificationMirroring</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisallowTileNotification</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Printers</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>PointAndPrintRestrictions_User</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Settings</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>ConfigureTaskbarCalendar</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Start</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>DisableContextMenus</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Enabling this policy prevents context menus from being invoked in the Start Menu.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HidePeopleBar</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Enabling this policy removes the people icon from the taskbar as well as the corresponding settings toggle. It also prevents users from pinning people to the taskbar.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>StartLayout</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>System</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowTelemetry</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>WindowsPowerShell</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>TurnOnPowerShellScriptBlockLogging</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
    </Node>
    <Node>
      <NodeName>Result</NodeName>
      <DFProperties>
        <AccessType>
          <Get />
        </AccessType>
        <DFFormat>
          <node />
        </DFFormat>
        <Occurrence>
          <One />
        </Occurrence>
        <Scope>
          <Permanent />
        </Scope>
        <DFType>
          <DDFName></DDFName>
        </DFType>
      </DFProperties>
      <Node>
        <NodeName>ApplicationManagement</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>MSIAlwaysInstallWithElevatedPrivileges</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MSI.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MSI~AT~WindowsComponents~MSI</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AlwaysInstallElevated</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RequirePrivateStoreOnly</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsStore.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsStore~AT~WindowsComponents~WindowsStore</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>RequirePrivateStoreOnly</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>AttachmentManager</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>DoNotPreserveZoneInformation</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>AttachmentManager.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>AttachmentManager~AT~WindowsComponents~AM_AM</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AM_MarkZoneOnSavedAtttachments</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideZoneInfoMechanism</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>AttachmentManager.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>AttachmentManager~AT~WindowsComponents~AM_AM</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AM_RemoveZoneInfo</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NotifyAntivirusPrograms</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>AttachmentManager.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>AttachmentManager~AT~WindowsComponents~AM_AM</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AM_CallIOfficeAntiVirus</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Authentication</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowEAPCertSSO</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Autoplay</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>DisallowAutoplayForNonVolumeDevices</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>AutoPlay.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>AutoPlay~AT~WindowsComponents~AutoPlay</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>NoAutoplayfornonVolume</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SetDefaultAutoRunBehavior</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>AutoPlay.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>AutoPlay~AT~WindowsComponents~AutoPlay</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>NoAutorun</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TurnOffAutoPlay</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>AutoPlay.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>AutoPlay~AT~WindowsComponents~AutoPlay</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Autorun</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Browser</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowAddressBarDropdown</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This policy setting lets you decide whether the Address bar drop-down functionality is available in Microsoft Edge. We recommend disabling this setting if you want to minimize network connections from Microsoft Edge to Microsoft services.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowAddressBarDropdown</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowAutofill</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This setting lets you decide whether employees can use Autofill to automatically fill in form fields while using Microsoft Edge.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowAutofill</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowBrowser</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>desktop</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowConfigurationUpdateForBooksLibrary</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This policy setting lets you decide whether Microsoft Edge can automatically update the configuration data for the Books Library.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowCookies</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>2</DefaultValue>
            <Description>This setting lets you configure how your company deals with cookies.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>CookiesListBox</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Cookies</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowDeveloperTools</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This setting lets you decide whether employees can use F12 Developer Tools on Microsoft Edge.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowDeveloperTools</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowDoNotTrack</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This setting lets you decide whether employees can send Do Not Track headers to websites that request tracking info.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowDoNotTrack</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowExtensions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This setting lets you decide whether employees can load extensions in Microsoft Edge.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowExtensions</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowFlash</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This setting lets you decide whether employees can run Adobe Flash in Microsoft Edge.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowFlash</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowFlashClickToRun</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>Configure the Adobe Flash Click-to-Run setting.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowFlashClickToRun</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowInPrivate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This setting lets you decide whether employees can browse using InPrivate website browsing.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowInPrivate</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowMicrosoftCompatibilityList</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This policy setting lets you decide whether the Microsoft Compatibility List is enabled or disabled in Microsoft Edge. This feature uses a Microsoft-provided list to ensure that any sites with known compatibility issues are displayed correctly when a user navigates to them. By default, the Microsoft Compatibility List is enabled and can be viewed by navigating to about:compat.

If you enable or dont configure this setting, Microsoft Edge will periodically download the latest version of the list from Microsoft and will apply the configurations specified there during browser navigation. If a user visits a site on the Microsoft Compatibility List, he or she will be prompted to open the site in Internet Explorer 11. Once in Internet Explorer, the site will automatically be rendered as if the user is viewing it in the previous version of Internet Explorer it requires to display correctly.

If you disable this setting, the Microsoft Compatibility List will not be used during browser navigation.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowCVList</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPasswordManager</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This setting lets you decide whether employees can save their passwords locally, using Password Manager.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowPasswordManager</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPopups</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This setting lets you decide whether to turn on Pop-up Blocker and whether to allow pop-ups to appear in secondary windows.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowPopups</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSearchEngineCustomization</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>Allow search engine customization for MDM enrolled devices. Users can change their default search engine.

If this setting is turned on or not configured, users can add new search engines and change the default used in the address bar from within Microsoft Edge Settings.
If this setting is disabled, users will be unable to add search engines or change the default used in the address bar.

This policy will only apply on domain joined machines or when the device is MDM enrolled. For more information, see Microsoft browser extension policy (aka.ms/browserpolicy).</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowSearchEngineCustomization</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSearchSuggestionsinAddressBar</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This setting lets you decide whether search suggestions should appear in the Address bar of Microsoft Edge.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowSearchSuggestionsinAddressBar</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSmartScreen</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This setting lets you decide whether to turn on Windows Defender SmartScreen.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowSmartScreen</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AlwaysEnableBooksLibrary</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Specifies whether the Books Library in Microsoft Edge will always be visible regardless of the country or region setting for the device.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AlwaysEnableBooksLibrary</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ClearBrowsingDataOnExit</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Specifies whether to always clear browsing history on exiting Microsoft Edge.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowClearingBrowsingDataOnExit</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConfigureAdditionalSearchEngines</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>Allows you to add up to 5 additional search engines for MDM-enrolled devices.

If this setting is turned on, you can add up to 5 additional search engines for your employee. For each additional search engine you wish to add, you must specify a link to the OpenSearch XML file that contains, at minimum, the short name and the URL to the search engine. This policy does not affect the default search engine. Employees will not be able to remove these search engines, but they can set any one of these as the default.

If this setting is not configured, the search engines are the ones specified in the App settings. If this setting is disabled, the search engines you had added will be deleted from your employee's machine.

Due to Protected Settings (aka.ms/browserpolicy), this policy will only apply on domain-joined machines or when the device is MDM-enrolled.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>ConfigureAdditionalSearchEngines_Prompt</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ConfigureAdditionalSearchEngines</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableLockdownOfStartPages</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Boolean policy that specifies whether the lockdown on the Start pages is disabled. This policy works with the Browser/HomePages policy, which locks down the Start pages that the users cannot modify. You can use the DisableLockdownOfStartPages policy to allow users to modify the Start pages when Browser/HomePages policy is in effect.

Note: This policy has no effect when Browser/HomePages is not configured.

Important
This setting can only be used with domain-joined or MDM-enrolled devices. For more info, see the Microsoft browser extension policy (aka.ms/browserpolicy).</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableLockdownOfStartPages</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableExtendedBooksTelemetry</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This setting allows organizations to send extended telemetry on book usage from the Books Library.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>EnableExtendedBooksTelemetry</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnterpriseModeSiteList</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This setting lets you configure whether your company uses Enterprise Mode and the Enterprise Mode Site List to address common compatibility problems with legacy websites.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>EnterSiteListPrompt</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>EnterpriseModeSiteList</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnterpriseSiteListServiceUrl</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>FirstRunURL</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>Configure first run URL.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>desktop</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HomePages</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>Configure the Start page URLs for your employees.
Example:
If you wanted to allow contoso.com and fabrikam.com then you would append /support to the site strings like contoso.com/support and fabrikam.com/support.
Encapsulate each string with greater than and less than characters like any other XML tag.

Version 1703 or later: If you don't want to send traffic to Microsoft, you can use the about:blank value (encapsulate with greater than and less than characters like any other XML tag), which is honored for both domain- and non-domain-joined machines, when it's the only configured URL.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>HomePagesPrompt</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>HomePages</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockdownFavorites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy setting lets you decide whether employees can add, import, sort, or edit the Favorites list on Microsoft Edge.

If you enable this setting, employees won't be able to add, import, or change anything in the Favorites list. Also as part of this, Save a Favorite, Import settings, and the context menu items (such as, Create a new folder) are all turned off.

Important
Don't enable both this setting and the Keep favorites in sync between Internet Explorer and Microsoft Edge setting. Enabling both settings stops employees from syncing their favorites between Internet Explorer and Microsoft Edge.

If you disable or don't configure this setting (default), employees can add, import and make changes to the Favorites list.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LockdownFavorites</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventAccessToAboutFlagsInMicrosoftEdge</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Prevent access to the about:flags page in Microsoft Edge.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>PreventAccessToAboutFlagsInMicrosoftEdge</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventFirstRunPage</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Specifies whether the First Run webpage is prevented from automatically opening on the first launch of Microsoft Edge. This policy is only available for Windows 10 version 1703 or later for desktop.

Due to Protected Settings (aka.ms/browserpolicy), this policy will only apply on domain-joined machines or when the device is MDM-enrolled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>PreventFirstRunPage</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventLiveTileDataCollection</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy lets you decide whether Microsoft Edge can gather Live Tile metadata from the ieonline.microsoft.com service to provide a better experience while pinning a Live Tile to the Start menu.

Due to Protected Settings (aka.ms/browserpolicy), this policy will only apply on domain-joined machines or when the device is MDM-enrolled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>PreventLiveTileDataCollection</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventSmartScreenPromptOverride</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Don't allow Windows Defender SmartScreen warning overrides</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>PreventSmartScreenPromptOverride</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventSmartScreenPromptOverrideForFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Don't allow Windows Defender SmartScreen warning overrides for unverified files.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>PreventSmartScreenPromptOverrideForFiles</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventTabPreloading</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Prevent Microsoft Edge from starting and loading the Start and New Tab page at Windows startup and each time Microsoft Edge is closed.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>PreventTabPreloading</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventUsingLocalHostIPAddressForWebRTC</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Prevent using localhost IP address for WebRTC</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>HideLocalHostIPAddress</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ProvisionFavorites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This policy setting allows you to configure a default set of favorites, which will appear for employees. Employees cannot modify, sort, move, export or delete these provisioned favorites.

If you enable this setting, you can set favorite URL's and favorite folders to appear on top of users' favorites list (either in the Hub or Favorites Bar). The user favorites will appear after these provisioned favorites.

Important
Don't enable both this setting and the Keep favorites in sync between Internet Explorer and Microsoft Edge setting. Enabling both settings stops employees from syncing their favorites between Internet Explorer and Microsoft Edge.

If you disable or don't configure this setting, employees will see the favorites they set in the Hub and Favorites Bar.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>ConfiguredFavoritesPrompt</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ConfiguredFavorites</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SendIntranetTraffictoInternetExplorer</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Sends all intranet traffic over to Internet Explorer.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>SendIntranetTraffictoInternetExplorer</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SetDefaultSearchEngine</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>Sets the default search engine for MDM-enrolled devices. Users can still change their default search engine.

If this setting is turned on, you are setting the default search engine that you would like your employees to use. Employees can still change the default search engine, unless you apply the AllowSearchEngineCustomization policy which will disable the ability to change it. You must specify a link to the OpenSearch XML file that contains, at minimum, the short name and the URL to the search engine. If you would like for your employees to use the Edge factory settings for the default search engine for their market, set the string EDGEDEFAULT; if you would like for your employees to use Bing as the default search engine, set the string EDGEBING.

If this setting is not configured, the default search engine is set to the one specified in App settings and can be changed by your employees.  If this setting is disabled, the policy-set search engine will be removed, and, if it is the current default, the default will be set back to the factory Microsoft Edge search engine for the market.

Due to Protected Settings (aka.ms/browserpolicy), this policy will only apply on domain-joined machines or when the device is MDM-enrolled.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>SetDefaultSearchEngine_Prompt</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>SetDefaultSearchEngine</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ShowMessageWhenOpeningSitesInInternetExplorer</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Show message when opening sites in Internet Explorer</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ShowMessageWhenOpeningSitesInInternetExplorer</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SyncFavoritesBetweenIEAndMicrosoftEdge</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Specifies whether favorites are kept in sync between Internet Explorer and Microsoft Edge. Changes to favorites in one browser are reflected in the other, including: additions, deletions, modifications, and ordering.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>SyncFavoritesBetweenIEAndMicrosoftEdge</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UseSharedFolderForBooks</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This setting specifies whether organizations should use a folder shared across users to store books from the Books Library.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>UseSharedFolderForBooks</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>CredentialsUI</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>DisablePasswordReveal</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>credui.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>CredUI~AT~WindowsComponents~CredUI</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisablePasswordReveal</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Desktop</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>PreventUserRedirectionOfProfileFolders</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>desktop.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>desktop~AT~Desktop</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisablePersonalDirChange</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Display</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>EnablePerProcessDpi</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>Enable or disable Per-Process System DPI for all applications.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>Display.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>DisplayGlobalPerProcessSystemDpiSettings</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>Display~AT~System~DisplayCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisplayPerProcessSystemDpiSettings</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Education</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>DefaultPrinterName</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This policy sets user's default printer</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventAddingNewPrinters</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Boolean that specifies whether or not to prevent user to install new printers</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>Printing.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>Printing~AT~ControlPanel~CplPrinters</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>NoAddPrinter</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PrinterNames</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This policy provisions per-user network printers</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>EnterpriseCloudPrint</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>CloudPrinterDiscoveryEndPoint</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This policy provisions per-user discovery end point to discover cloud printers</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>CloudPrintOAuthAuthority</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>Authentication endpoint for acquiring OAuth tokens</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>CloudPrintOAuthClientId</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>A GUID identifying the client application authorized to retrieve OAuth tokens from the OAuthAuthority</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>CloudPrintResourceId</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>Resource URI for which access is being requested by the Enterprise Cloud Print client during OAuth authentication</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DiscoveryMaxPrinterLimit</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>20</DefaultValue>
            <Description>Defines the maximum number of printers that should be queried from discovery end point</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="65535"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MopriaDiscoveryResourceId</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>Resource URI for which access is being requested by the Mopria discovery client during OAuth authentication</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Experience</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowTailoredExperiencesWithDiagnosticData</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>CloudContent.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>CloudContent~AT~WindowsComponents~CloudContent</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableTailoredExperiencesWithDiagnosticData</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowThirdPartySuggestionsInWindowsSpotlight</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>CloudContent.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>CloudContent~AT~WindowsComponents~CloudContent</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableThirdPartySuggestions</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowWindowsSpotlight</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>CloudContent.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>CloudContent~AT~WindowsComponents~CloudContent</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableWindowsSpotlightFeatures</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowWindowsSpotlightOnActionCenter</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>CloudContent.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>CloudContent~AT~WindowsComponents~CloudContent</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableWindowsSpotlightOnActionCenter</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowWindowsSpotlightOnSettings</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>CloudContent.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>CloudContent~AT~WindowsComponents~CloudContent</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableWindowsSpotlightOnSettings</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowWindowsSpotlightWindowsWelcomeExperience</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>CloudContent.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>CloudContent~AT~WindowsComponents~CloudContent</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableWindowsSpotlightWindowsWelcomeExperience</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConfigureWindowsSpotlightOnLockScreen</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="3"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>CloudContent.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>CloudContent~AT~WindowsComponents~CloudContent</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ConfigureWindowsSpotlight</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>InternetExplorer</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AddSearchProvider</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AddSearchProvider</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowActiveXFiltering</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>TurnOnActiveXFiltering</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowAddOnList</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~SecurityFeatures~IESF_AddOnManagement</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AddonManagement_AddOnList</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowAutoComplete</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>RestrictFormSuggestPW</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowCertificateAddressMismatchWarning</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyWarnCertMismatch</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowDeletingBrowsingHistoryOnExit</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~DeleteBrowsingHistory</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DBHDisableDeleteOnExit</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowEnhancedProtectedMode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~AdvancedPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Advanced_EnableEnhancedProtectedMode</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowEnterpriseModeFromToolsMenu</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>EnterpriseModeEnable</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowEnterpriseModeSiteList</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>EnterpriseModeSiteList</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowInternetExplorer7PolicyList</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~CategoryCompatView</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>CompatView_UsePolicyList</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowInternetExplorerStandardsMode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~CategoryCompatView</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>CompatView_IntranetSites</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowInternetZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyInternetZoneTemplate</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowIntranetZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyIntranetZoneTemplate</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLocalMachineZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyLocalMachineZoneTemplate</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLockedDownInternetZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyInternetZoneLockdownTemplate</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLockedDownIntranetZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyIntranetZoneLockdownTemplate</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLockedDownLocalMachineZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyLocalMachineZoneLockdownTemplate</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLockedDownRestrictedSitesZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyRestrictedSitesZoneLockdownTemplate</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowOneWordEntry</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetSettings~Advanced~Browsing</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>UseIntranetSiteForOneWordEntry</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSiteToZoneAssignmentList</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Zonemaps</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowsLockedDownTrustedSitesZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyTrustedSitesZoneLockdownTemplate</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSoftwareWhenSignatureIsInvalid</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~AdvancedPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Advanced_InvalidSignatureBlock</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowsRestrictedSitesZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyRestrictedSitesZoneTemplate</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSuggestedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>EnableSuggestedSites</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowTrustedSitesZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyTrustedSitesZoneTemplate</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>CheckServerCertificateRevocation</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~AdvancedPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Advanced_CertificateRevocation</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>CheckSignaturesOnDownloadedPrograms</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~AdvancedPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Advanced_DownloadSignatures</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConsistentMimeHandlingInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~SecurityFeatures~IESF_CategoryConsistentMimeHandling</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IESF_PolicyExplorerProcesses_5</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableAdobeFlash</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~SecurityFeatures~IESF_AddOnManagement</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableFlashInIE</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableBypassOfSmartScreenWarnings</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableSafetyFilterOverride</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableBypassOfSmartScreenWarningsAboutUncommonFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableSafetyFilterOverrideForAppRepUnknown</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableConfiguringHistory</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~DeleteBrowsingHistory</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>RestrictHistory</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableCrashDetection</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AddonManagement_RestrictCrashDetection</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableCustomerExperienceImprovementProgramParticipation</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>SQM_DisableCEIP</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableDeletingUserVisitedWebsites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~DeleteBrowsingHistory</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DBHDisableDeleteHistory</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableEnclosureDownloading</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~RSS_Feeds</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Disable_Downloading_of_Enclosures</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableEncryptionSupport</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~AdvancedPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Advanced_SetWinInetProtocols</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableFirstRunWizard</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>NoFirstRunCustomise</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableFlipAheadFeature</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~AdvancedPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Advanced_DisableFlipAhead</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableHomePageChange</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>RestrictHomePage</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableIgnoringCertificateErrors</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>NoCertError</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableInPrivateBrowsing</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~CategoryPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableInPrivateBrowsing</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableProcessesInEnhancedProtectedMode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~AdvancedPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Advanced_EnableEnhancedProtectedMode64Bit</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableProxyChange</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>RestrictProxy</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableSearchProviderChange</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>NoSearchProvider</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableSecondaryHomePageChange</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>SecondaryHomePages</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableSecuritySettingsCheck</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Disable_Security_Settings_Check</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DoNotAllowActiveXControlsInProtectedMode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~AdvancedPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Advanced_DisableEPMCompat</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DoNotBlockOutdatedActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~SecurityFeatures~IESF_AddOnManagement</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>VerMgmtDisable</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DoNotBlockOutdatedActiveXControlsOnSpecificDomains</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~SecurityFeatures~IESF_AddOnManagement</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>VerMgmtDomainAllowlist</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IncludeAllLocalSites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_IncludeUnspecifiedLocalSites</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IncludeAllNetworkPaths</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_UNCAsIntranet</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAccessDataSourcesAcrossDomains_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarActiveXURLaction_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarDownloadURLaction_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowCopyPasteViaScript</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAllowPasteViaScript_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowDragAndDropCopyAndPasteFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyDropOrPasteFiles_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyFontDownload_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyZoneElevationURLaction_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowLoadingOfXAMLFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_XAML_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUnsignedFrameworkComponentsURLaction_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowOnlyApprovedDomainsToUseActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyOnlyAllowApprovedDomainsToUseActiveXWithoutPrompt_Both_Internet</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowOnlyApprovedDomainsToUseTDCActiveXControl</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAllowTDCControl_Both_Internet</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowScriptingOfInternetExplorerWebBrowserControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_WebBrowserControl_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowScriptInitiatedWindows</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyWindowsRestrictionsURLaction_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_AllowScriptlets_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_Phishing_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowUpdatesToStatusBarViaScript</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_ScriptStatusBar_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUserdataPersistence_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowVBScriptToRunInInternetExplorer</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAllowVBScript_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneDoNotRunAntimalwareAgainstActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAntiMalwareCheckingOfActiveXControls_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneDownloadSignedActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyDownloadSignedActiveX_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneDownloadUnsignedActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyDownloadUnsignedActiveX_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneEnableCrossSiteScriptingFilter</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyTurnOnXSSFilter_Both_Internet</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneEnableDraggingOfContentFromDifferentDomainsAcrossWindows</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyDragDropAcrossDomainsAcrossWindows_Both_Internet</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneEnableDraggingOfContentFromDifferentDomainsWithinWindows</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyDragDropAcrossDomainsWithinWindow_Both_Internet</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneEnableMIMESniffing</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyMimeSniffingURLaction_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneEnableProtectedMode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_TurnOnProtectedMode_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneIncludeLocalPathWhenUploadingFilesToServer</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_LocalPathForUpload_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyScriptActiveXNotMarkedSafe_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyJavaPermissions_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneLaunchingApplicationsAndFilesInIFRAME</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyLaunchAppsAndFilesInIFRAME_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneLogonOptions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyLogon_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNavigateSubframesAcrossDomains_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneRunNETFrameworkReliantComponentsSignedWithAuthenticode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicySignedFrameworkComponentsURLaction_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneShowSecurityWarningForPotentiallyUnsafeFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_UnsafeFiles_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneUsePopupBlocker</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyBlockPopupWindows_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAccessDataSourcesAcrossDomains_3</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarActiveXURLaction_3</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarDownloadURLaction_3</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyFontDownload_3</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyZoneElevationURLaction_3</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUnsignedFrameworkComponentsURLaction_3</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_AllowScriptlets_3</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_Phishing_3</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUserdataPersistence_3</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneDoNotRunAntimalwareAgainstActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAntiMalwareCheckingOfActiveXControls_3</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyScriptActiveXNotMarkedSafe_3</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyJavaPermissions_3</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNavigateSubframesAcrossDomains_3</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAccessDataSourcesAcrossDomains_9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarActiveXURLaction_9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarDownloadURLaction_9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyFontDownload_9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyZoneElevationURLaction_9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUnsignedFrameworkComponentsURLaction_9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_AllowScriptlets_9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_Phishing_9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUserdataPersistence_9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneDoNotRunAntimalwareAgainstActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAntiMalwareCheckingOfActiveXControls_9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyScriptActiveXNotMarkedSafe_9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyJavaPermissions_9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNavigateSubframesAcrossDomains_9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAccessDataSourcesAcrossDomains_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarActiveXURLaction_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarDownloadURLaction_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyFontDownload_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyZoneElevationURLaction_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUnsignedFrameworkComponentsURLaction_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_AllowScriptlets_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_Phishing_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUserdataPersistence_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyScriptActiveXNotMarkedSafe_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyJavaPermissions_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNavigateSubframesAcrossDomains_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyJavaPermissions_4</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAccessDataSourcesAcrossDomains_4</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarActiveXURLaction_4</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarDownloadURLaction_4</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyFontDownload_4</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyZoneElevationURLaction_4</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUnsignedFrameworkComponentsURLaction_4</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_AllowScriptlets_4</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_Phishing_4</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUserdataPersistence_4</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyScriptActiveXNotMarkedSafe_4</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNavigateSubframesAcrossDomains_4</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAccessDataSourcesAcrossDomains_10</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarActiveXURLaction_10</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarDownloadURLaction_10</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyFontDownload_10</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyZoneElevationURLaction_10</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUnsignedFrameworkComponentsURLaction_10</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_AllowScriptlets_10</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_Phishing_10</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUserdataPersistence_10</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyScriptActiveXNotMarkedSafe_10</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyJavaPermissions_10</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNavigateSubframesAcrossDomains_10</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAccessDataSourcesAcrossDomains_8</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarActiveXURLaction_8</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarDownloadURLaction_8</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyFontDownload_8</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyZoneElevationURLaction_8</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUnsignedFrameworkComponentsURLaction_8</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_AllowScriptlets_8</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_Phishing_8</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUserdataPersistence_8</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyScriptActiveXNotMarkedSafe_8</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyJavaPermissions_8</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNavigateSubframesAcrossDomains_8</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAccessDataSourcesAcrossDomains_6</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarActiveXURLaction_6</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarDownloadURLaction_6</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyFontDownload_6</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyZoneElevationURLaction_6</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUnsignedFrameworkComponentsURLaction_6</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_AllowScriptlets_6</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_Phishing_6</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUserdataPersistence_6</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyScriptActiveXNotMarkedSafe_6</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyJavaPermissions_6</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNavigateSubframesAcrossDomains_6</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MimeSniffingSafetyFeatureInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~SecurityFeatures~IESF_CategoryMimeSniffingSafetyFeature</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IESF_PolicyExplorerProcesses_6</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MKProtocolSecurityRestrictionInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~SecurityFeatures~IESF_CategoryMKProtocolSecurityRestriction</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IESF_PolicyExplorerProcesses_3</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NotificationBarInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~SecurityFeatures~IESF_CategoryInformationBar</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IESF_PolicyExplorerProcesses_10</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventManagingSmartScreenFilter</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Disable_Managing_Safety_Filter_IE9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventPerUserInstallationOfActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisablePerUserActiveXInstall</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ProtectionFromZoneElevationInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~SecurityFeatures~IESF_CategoryProtectionFromZoneElevation</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IESF_PolicyExplorerProcesses_9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RemoveRunThisTimeButtonForOutdatedActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~SecurityFeatures~IESF_AddOnManagement</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>VerMgmtDisableRunThisTime</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictActiveXInstallInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~SecurityFeatures~IESF_CategoryRestrictActiveXInstall</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IESF_PolicyExplorerProcesses_11</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAccessDataSourcesAcrossDomains_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowActiveScripting</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyActiveScripting_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarActiveXURLaction_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarDownloadURLaction_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowBinaryAndScriptBehaviors</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyBinaryBehaviors_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowCopyPasteViaScript</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAllowPasteViaScript_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowDragAndDropCopyAndPasteFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyDropOrPasteFiles_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyFileDownload_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyFontDownload_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyZoneElevationURLaction_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowLoadingOfXAMLFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_XAML_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowMETAREFRESH</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAllowMETAREFRESH_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUnsignedFrameworkComponentsURLaction_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowOnlyApprovedDomainsToUseActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyOnlyAllowApprovedDomainsToUseActiveXWithoutPrompt_Both_Restricted</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowOnlyApprovedDomainsToUseTDCActiveXControl</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAllowTDCControl_Both_Restricted</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowScriptingOfInternetExplorerWebBrowserControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_WebBrowserControl_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowScriptInitiatedWindows</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyWindowsRestrictionsURLaction_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_AllowScriptlets_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_Phishing_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowUpdatesToStatusBarViaScript</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_ScriptStatusBar_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUserdataPersistence_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowVBScriptToRunInInternetExplorer</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAllowVBScript_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneDoNotRunAntimalwareAgainstActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAntiMalwareCheckingOfActiveXControls_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneDownloadSignedActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyDownloadSignedActiveX_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneDownloadUnsignedActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyDownloadUnsignedActiveX_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneEnableCrossSiteScriptingFilter</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyTurnOnXSSFilter_Both_Restricted</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneEnableDraggingOfContentFromDifferentDomainsAcrossWindows</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyDragDropAcrossDomainsAcrossWindows_Both_Restricted</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneEnableDraggingOfContentFromDifferentDomainsWithinWindows</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyDragDropAcrossDomainsWithinWindow_Both_Restricted</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneEnableMIMESniffing</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyMimeSniffingURLaction_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneIncludeLocalPathWhenUploadingFilesToServer</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_LocalPathForUpload_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyScriptActiveXNotMarkedSafe_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyJavaPermissions_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneLaunchingApplicationsAndFilesInIFRAME</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyLaunchAppsAndFilesInIFRAME_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneLogonOptions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyLogon_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNavigateSubframesAcrossDomains_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneRunActiveXControlsAndPlugins</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyRunActiveXControls_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneRunNETFrameworkReliantComponentsSignedWithAuthenticode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicySignedFrameworkComponentsURLaction_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneScriptActiveXControlsMarkedSafeForScripting</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyScriptActiveXMarkedSafe_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneScriptingOfJavaApplets</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyScriptingOfJavaApplets_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneShowSecurityWarningForPotentiallyUnsafeFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_UnsafeFiles_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneTurnOnProtectedMode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_TurnOnProtectedMode_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneUsePopupBlocker</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyBlockPopupWindows_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictFileDownloadInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~SecurityFeatures~IESF_CategoryRestrictFileDownload</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IESF_PolicyExplorerProcesses_12</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScriptedWindowSecurityRestrictionsInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~SecurityFeatures~IESF_CategoryScriptedWindowSecurityRestrictions</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IESF_PolicyExplorerProcesses_8</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SearchProviderList</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>SpecificSearchProvider</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SpecifyUseOfActiveXInstallerService</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>OnlyUseAXISForActiveXInstall</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAccessDataSourcesAcrossDomains_5</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarActiveXURLaction_5</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarDownloadURLaction_5</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyFontDownload_5</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyZoneElevationURLaction_5</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUnsignedFrameworkComponentsURLaction_5</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_AllowScriptlets_5</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_Phishing_5</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUserdataPersistence_5</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneDoNotRunAntimalwareAgainstActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAntiMalwareCheckingOfActiveXControls_5</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyScriptActiveXNotMarkedSafe_5</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyJavaPermissions_5</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNavigateSubframesAcrossDomains_5</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>KioskBrowser</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>BlockedUrlExceptions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of exceptions to the blocked website URLs (with wildcard support). This is used to configure URLs kiosk browsers are allowed to navigate to, which are a subset of the blocked URLs.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>BlockedUrls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of blocked website URLs (with wildcard support). This is used to configure blocked URLs kiosk browsers can not navigate to.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DefaultURL</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>Configures the default URL kiosk browsers to navigate on launch and restart.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableEndSessionButton</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Enable/disable kiosk browser's end session button.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableHomeButton</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Enable/disable kiosk browser's home button.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableNavigationButtons</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Enable/disable kiosk browser's navigation buttons (forward/back).</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestartOnIdleTime</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Amount of time in minutes the session is idle until the kiosk browser restarts in a fresh state.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="1" high="1440"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Notifications</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>DisallowNotificationMirroring</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WPN.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WPN~AT~StartMenu~NotificationsCategory</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>NoNotificationMirroring</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisallowTileNotification</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WPN.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WPN~AT~StartMenu~NotificationsCategory</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>NoTileNotification</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Printers</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>PointAndPrintRestrictions_User</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>Printing.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>Printing~AT~ControlPanel~CplPrinters</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>PointAndPrint_Restrictions</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Settings</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>ConfigureTaskbarCalendar</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="3"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>Taskbar.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>Taskbar~AT~StartMenu~TPMCategory</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ConfigureTaskbarCalendar</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Start</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>DisableContextMenus</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Enabling this policy prevents context menus from being invoked in the Start Menu.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>StartMenu.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>StartMenu~AT~StartMenu</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableContextMenusInStart</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HidePeopleBar</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Enabling this policy removes the people icon from the taskbar as well as the corresponding settings toggle. It also prevents users from pinning people to the taskbar.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>StartMenu.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>StartMenu~AT~StartMenu</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>HidePeopleBar</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>StartLayout</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>StartMenu.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>StartMenu~AT~StartMenu</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LockedStartLayout</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>System</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowTelemetry</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>3</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="3"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>DataCollection.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>AllowTelemetry</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DataCollection~AT~WindowsComponents~DataCollectionAndPreviewBuilds</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowTelemetry</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>WindowsPowerShell</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>TurnOnPowerShellScriptBlockLogging</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>PowerShellExecutionPolicy.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>PowerShellExecutionPolicy~AT~WindowsComponents~PowerShell</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>EnableScriptBlockLogging</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
    </Node>
  </Node>
  <Node>
    <NodeName>Policy</NodeName>
    <Path>./Device/Vendor/MSFT</Path>
    <DFProperties>
      <AccessType>
        <Get />
      </AccessType>
      <DFFormat>
        <node />
      </DFFormat>
      <Occurrence>
        <One />
      </Occurrence>
      <Scope>
        <Permanent />
      </Scope>
      <DFType>
        <MIME>com.microsoft/7.0/MDM/Policy</MIME>
      </DFType>
    </DFProperties>
    <Node>
      <NodeName>ConfigOperations</NodeName>
      <DFProperties>
        <AccessType>
          <Add />
          <Delete />
          <Get />
        </AccessType>
        <Description>Policy CSP ConfigOperations</Description>
        <DFFormat>
          <node />
        </DFFormat>
        <Occurrence>
          <ZeroOrOne />
        </Occurrence>
        <Scope>
          <Dynamic />
        </Scope>
        <DFType>
          <DDFName></DDFName>
        </DFType>
      </DFProperties>
      <Node>
        <NodeName>ADMXInstall</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <Description>Win32 App ADMX Ingestion</Description>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>*</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
            </AccessType>
            <Description>Win32 App Name</Description>
            <DFFormat>
              <node />
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <DDFName></DDFName>
            </DFType>
          </DFProperties>
          <Node>
            <NodeName>*</NodeName>
            <DFProperties>
              <AccessType>
                <Add />
                <Delete />
                <Get />
              </AccessType>
              <Description>Setting Type of Win32 App. Policy Or Preference</Description>
              <DFFormat>
                <node />
              </DFFormat>
              <Occurrence>
                <ZeroOrOne />
              </Occurrence>
              <Scope>
                <Dynamic />
              </Scope>
              <DFType>
                <DDFName></DDFName>
              </DFType>
            </DFProperties>
            <Node>
              <NodeName>*</NodeName>
              <DFProperties>
                <AccessType>
                  <Add />
                  <Delete />
                  <Get />
                </AccessType>
                <Description>Unique ID of ADMX file</Description>
                <DFFormat>
                  <chr />
                </DFFormat>
                <Occurrence>
                  <ZeroOrOne />
                </Occurrence>
                <Scope>
                  <Dynamic />
                </Scope>
                <DFType>
                  <DDFName></DDFName>
                </DFType>
              </DFProperties>
            </Node>
          </Node>
        </Node>
      </Node>
    </Node>
    <Node>
      <NodeName>Config</NodeName>
      <DFProperties>
        <AccessType>
          <Add />
          <Delete />
          <Get />
        </AccessType>
        <DFFormat>
          <node />
        </DFFormat>
        <Occurrence>
          <ZeroOrOne />
        </Occurrence>
        <Scope>
          <Dynamic />
        </Scope>
        <DFType>
          <DDFName></DDFName>
        </DFType>
      </DFProperties>
      <Node>
        <NodeName>AboveLock</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowActionCenterNotifications</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowCortanaAboveLock</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowToasts</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Accounts</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowAddingNonMicrosoftAccountsManually</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowMicrosoftAccountConnection</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowMicrosoftAccountSignInAssistant</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DomainNamesForEmailSync</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>ActiveXControls</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>ApprovedInstallationSites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>ApplicationDefaults</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>DefaultAssociationsConfiguration</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableAppUriHandlers</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Enables web-to-app linking, which allows apps to be launched with a http(s) URI</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>ApplicationManagement</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowAllTrustedApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowAppStoreAutoUpdate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowDeveloperUnlock</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowGameDVR</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSharedUserAppData</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowStore</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ApplicationRestrictions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableStoreOriginatedApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MSIAllowUserControlOverInstall</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MSIAlwaysInstallWithElevatedPrivileges</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RequirePrivateStoreOnly</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictAppDataToSystemVolume</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictAppToSystemVolume</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>AppRuntime</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowMicrosoftAccountsToBeOptional</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>AppVirtualization</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowAppVClient</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowDynamicVirtualization</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPackageCleanup</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPackageScripts</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPublishingRefreshUX</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowReportingServer</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowRoamingFileExclusions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowRoamingRegistryExclusions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowStreamingAutoload</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ClientCoexistenceAllowMigrationmode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntegrationAllowRootGlobal</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntegrationAllowRootUser</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PublishingAllowServer1</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PublishingAllowServer2</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PublishingAllowServer3</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PublishingAllowServer4</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PublishingAllowServer5</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>StreamingAllowCertificateFilterForClient_SSL</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>StreamingAllowHighCostLaunch</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>StreamingAllowLocationProvider</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>StreamingAllowPackageInstallationRoot</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>StreamingAllowPackageSourceRoot</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>StreamingAllowReestablishmentInterval</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>StreamingAllowReestablishmentRetries</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>StreamingSharedContentStoreMode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>StreamingSupportBranchCache</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>StreamingVerifyCertificateRevocationList</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>VirtualComponentsAllowList</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Authentication</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowAadPasswordReset</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Specifies whether password reset is enabled for AAD accounts.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowFastReconnect</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSecondaryAuthenticationDevice</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Autoplay</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>DisallowAutoplayForNonVolumeDevices</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SetDefaultAutoRunBehavior</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TurnOffAutoPlay</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Bitlocker</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>EncryptionMethod</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Bluetooth</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowAdvertising</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowDiscoverableMode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPrepairing</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPromptedProximalConnections</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalDeviceName</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ServicesAllowedList</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Browser</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowAddressBarDropdown</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting lets you decide whether the Address bar drop-down functionality is available in Microsoft Edge. We recommend disabling this setting if you want to minimize network connections from Microsoft Edge to Microsoft services.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowAutofill</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting lets you decide whether employees can use Autofill to automatically fill in form fields while using Microsoft Edge.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowBrowser</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowConfigurationUpdateForBooksLibrary</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting lets you decide whether Microsoft Edge can automatically update the configuration data for the Books Library.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowCookies</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting lets you configure how your company deals with cookies.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowDeveloperTools</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting lets you decide whether employees can use F12 Developer Tools on Microsoft Edge.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowDoNotTrack</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting lets you decide whether employees can send Do Not Track headers to websites that request tracking info.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowExtensions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting lets you decide whether employees can load extensions in Microsoft Edge.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowFlash</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting lets you decide whether employees can run Adobe Flash in Microsoft Edge.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowFlashClickToRun</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Configure the Adobe Flash Click-to-Run setting.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowInPrivate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting lets you decide whether employees can browse using InPrivate website browsing.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowMicrosoftCompatibilityList</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting lets you decide whether the Microsoft Compatibility List is enabled or disabled in Microsoft Edge. This feature uses a Microsoft-provided list to ensure that any sites with known compatibility issues are displayed correctly when a user navigates to them. By default, the Microsoft Compatibility List is enabled and can be viewed by navigating to about:compat.

If you enable or dont configure this setting, Microsoft Edge will periodically download the latest version of the list from Microsoft and will apply the configurations specified there during browser navigation. If a user visits a site on the Microsoft Compatibility List, he or she will be prompted to open the site in Internet Explorer 11. Once in Internet Explorer, the site will automatically be rendered as if the user is viewing it in the previous version of Internet Explorer it requires to display correctly.

If you disable this setting, the Microsoft Compatibility List will not be used during browser navigation.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPasswordManager</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting lets you decide whether employees can save their passwords locally, using Password Manager.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPopups</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting lets you decide whether to turn on Pop-up Blocker and whether to allow pop-ups to appear in secondary windows.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSearchEngineCustomization</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Allow search engine customization for MDM enrolled devices. Users can change their default search engine.

If this setting is turned on or not configured, users can add new search engines and change the default used in the address bar from within Microsoft Edge Settings.
If this setting is disabled, users will be unable to add search engines or change the default used in the address bar.

This policy will only apply on domain joined machines or when the device is MDM enrolled. For more information, see Microsoft browser extension policy (aka.ms/browserpolicy).</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSearchSuggestionsinAddressBar</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting lets you decide whether search suggestions should appear in the Address bar of Microsoft Edge.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSmartScreen</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting lets you decide whether to turn on Windows Defender SmartScreen.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AlwaysEnableBooksLibrary</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Specifies whether the Books Library in Microsoft Edge will always be visible regardless of the country or region setting for the device.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ClearBrowsingDataOnExit</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Specifies whether to always clear browsing history on exiting Microsoft Edge.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConfigureAdditionalSearchEngines</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Allows you to add up to 5 additional search engines for MDM-enrolled devices.

If this setting is turned on, you can add up to 5 additional search engines for your employee. For each additional search engine you wish to add, you must specify a link to the OpenSearch XML file that contains, at minimum, the short name and the URL to the search engine. This policy does not affect the default search engine. Employees will not be able to remove these search engines, but they can set any one of these as the default.

If this setting is not configured, the search engines are the ones specified in the App settings. If this setting is disabled, the search engines you had added will be deleted from your employee's machine.

Due to Protected Settings (aka.ms/browserpolicy), this policy will only apply on domain-joined machines or when the device is MDM-enrolled.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableLockdownOfStartPages</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Boolean policy that specifies whether the lockdown on the Start pages is disabled. This policy works with the Browser/HomePages policy, which locks down the Start pages that the users cannot modify. You can use the DisableLockdownOfStartPages policy to allow users to modify the Start pages when Browser/HomePages policy is in effect.

Note: This policy has no effect when Browser/HomePages is not configured.

Important
This setting can only be used with domain-joined or MDM-enrolled devices. For more info, see the Microsoft browser extension policy (aka.ms/browserpolicy).</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableExtendedBooksTelemetry</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting allows organizations to send extended telemetry on book usage from the Books Library.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnterpriseModeSiteList</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting lets you configure whether your company uses Enterprise Mode and the Enterprise Mode Site List to address common compatibility problems with legacy websites.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnterpriseSiteListServiceUrl</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>FirstRunURL</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Configure first run URL.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HomePages</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Configure the Start page URLs for your employees.
Example:
If you wanted to allow contoso.com and fabrikam.com then you would append /support to the site strings like contoso.com/support and fabrikam.com/support.
Encapsulate each string with greater than and less than characters like any other XML tag.

Version 1703 or later: If you don't want to send traffic to Microsoft, you can use the about:blank value (encapsulate with greater than and less than characters like any other XML tag), which is honored for both domain- and non-domain-joined machines, when it's the only configured URL.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockdownFavorites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting lets you decide whether employees can add, import, sort, or edit the Favorites list on Microsoft Edge.

If you enable this setting, employees won't be able to add, import, or change anything in the Favorites list. Also as part of this, Save a Favorite, Import settings, and the context menu items (such as, Create a new folder) are all turned off.

Important
Don't enable both this setting and the Keep favorites in sync between Internet Explorer and Microsoft Edge setting. Enabling both settings stops employees from syncing their favorites between Internet Explorer and Microsoft Edge.

If you disable or don't configure this setting (default), employees can add, import and make changes to the Favorites list.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventAccessToAboutFlagsInMicrosoftEdge</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Prevent access to the about:flags page in Microsoft Edge.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventFirstRunPage</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Specifies whether the First Run webpage is prevented from automatically opening on the first launch of Microsoft Edge. This policy is only available for Windows 10 version 1703 or later for desktop.

Due to Protected Settings (aka.ms/browserpolicy), this policy will only apply on domain-joined machines or when the device is MDM-enrolled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventLiveTileDataCollection</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy lets you decide whether Microsoft Edge can gather Live Tile metadata from the ieonline.microsoft.com service to provide a better experience while pinning a Live Tile to the Start menu.

Due to Protected Settings (aka.ms/browserpolicy), this policy will only apply on domain-joined machines or when the device is MDM-enrolled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventSmartScreenPromptOverride</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Don't allow Windows Defender SmartScreen warning overrides</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventSmartScreenPromptOverrideForFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Don't allow Windows Defender SmartScreen warning overrides for unverified files.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventTabPreloading</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Prevent Microsoft Edge from starting and loading the Start and New Tab page at Windows startup and each time Microsoft Edge is closed.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventUsingLocalHostIPAddressForWebRTC</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Prevent using localhost IP address for WebRTC</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ProvisionFavorites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting allows you to configure a default set of favorites, which will appear for employees. Employees cannot modify, sort, move, export or delete these provisioned favorites.

If you enable this setting, you can set favorite URL's and favorite folders to appear on top of users' favorites list (either in the Hub or Favorites Bar). The user favorites will appear after these provisioned favorites.

Important
Don't enable both this setting and the Keep favorites in sync between Internet Explorer and Microsoft Edge setting. Enabling both settings stops employees from syncing their favorites between Internet Explorer and Microsoft Edge.

If you disable or don't configure this setting, employees will see the favorites they set in the Hub and Favorites Bar.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SendIntranetTraffictoInternetExplorer</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Sends all intranet traffic over to Internet Explorer.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SetDefaultSearchEngine</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Sets the default search engine for MDM-enrolled devices. Users can still change their default search engine.

If this setting is turned on, you are setting the default search engine that you would like your employees to use. Employees can still change the default search engine, unless you apply the AllowSearchEngineCustomization policy which will disable the ability to change it. You must specify a link to the OpenSearch XML file that contains, at minimum, the short name and the URL to the search engine. If you would like for your employees to use the Edge factory settings for the default search engine for their market, set the string EDGEDEFAULT; if you would like for your employees to use Bing as the default search engine, set the string EDGEBING.

If this setting is not configured, the default search engine is set to the one specified in App settings and can be changed by your employees.  If this setting is disabled, the policy-set search engine will be removed, and, if it is the current default, the default will be set back to the factory Microsoft Edge search engine for the market.

Due to Protected Settings (aka.ms/browserpolicy), this policy will only apply on domain-joined machines or when the device is MDM-enrolled.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ShowMessageWhenOpeningSitesInInternetExplorer</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Show message when opening sites in Internet Explorer</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SyncFavoritesBetweenIEAndMicrosoftEdge</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Specifies whether favorites are kept in sync between Internet Explorer and Microsoft Edge. Changes to favorites in one browser are reflected in the other, including: additions, deletions, modifications, and ordering.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UseSharedFolderForBooks</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting specifies whether organizations should use a folder shared across users to store books from the Books Library.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Camera</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowCamera</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Cellular</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>LetAppsAccessCellularData</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting specifies whether Windows apps can access cellular data.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCellularData_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Windows Store Apps. Listed apps are allowed access to cellular data. This setting overrides the default LetAppsAccessCellularData policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCellularData_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are denied access to cellular data. This setting overrides the default LetAppsAccessCellularData policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCellularData_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the cellular data access setting for the listed apps. This setting overrides the default LetAppsAccessCellularData policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ShowAppCellularAccessUI</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Connectivity</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowBluetooth</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowCellularData</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowCellularDataRoaming</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowConnectedDevices</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowNFC</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPhonePCLinking</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowUSBConnection</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowVPNOverCellular</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowVPNRoamingOverCellular</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DiablePrintingOverHTTP</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableDownloadingOfPrintDriversOverHTTP</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableInternetDownloadForWebPublishingAndOnlineOrderingWizards</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisallowNetworkConnectivityActiveTests</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HardenedUNCPaths</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ProhibitInstallationAndConfigurationOfNetworkBridge</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>ControlPolicyConflict</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>MDMWinsOverGP</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Get />
              <Replace />
            </AccessType>
            <Description>If set to 1 then any MDM policy that is set that has an equivalent GP policy will result in GP service blocking the setting of the policy by GP MMC</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>CredentialProviders</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowPINLogon</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>BlockPicturePassword</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableAutomaticReDeploymentCredentials</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>CredentialsDelegation</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>RemoteHostAllowsDelegationOfNonExportableCredentials</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>CredentialsUI</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>DisablePasswordReveal</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnumerateAdministrators</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Cryptography</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowFipsAlgorithmPolicy</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TLSCipherSuites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>DataProtection</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowDirectMemoryAccess</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LegacySelectiveWipeID</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>DataUsage</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>SetCost3G</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SetCost4G</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Defender</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowArchiveScanning</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowBehaviorMonitoring</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowCloudProtection</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowEmailScanning</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowFullScanOnMappedNetworkDrives</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowFullScanRemovableDriveScanning</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowIntrusionPreventionSystem</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowIOAVProtection</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowOnAccessProtection</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowRealtimeMonitoring</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowScanningNetworkFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowScriptScanning</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowUserUIAccess</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AttackSurfaceReductionOnlyExclusions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AttackSurfaceReductionRules</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AvgCPULoadFactor</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>CloudBlockLevel</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>CloudExtendedTimeout</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ControlledFolderAccessAllowedApplications</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ControlledFolderAccessProtectedFolders</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DaysToRetainCleanedMalware</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableControlledFolderAccess</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableNetworkProtection</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ExcludedExtensions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ExcludedPaths</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ExcludedProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PUAProtection</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RealTimeScanDirection</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScanParameter</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScheduleQuickScanTime</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScheduleScanDay</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScheduleScanTime</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SignatureUpdateInterval</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SubmitSamplesConsent</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ThreatSeverityDefaultAction</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>DeliveryOptimization</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>DOAbsoluteMaxCacheSize</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOAllowVPNPeerCaching</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DODelayBackgroundDownloadFromHttp</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DODelayForegroundDownloadFromHttp</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DODownloadMode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOGroupId</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOGroupIdSource</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOMaxCacheAge</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOMaxCacheSize</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOMaxDownloadBandwidth</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOMaxUploadBandwidth</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOMinBackgroundQos</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOMinBatteryPercentageAllowedToUpload</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOMinDiskSizeAllowedToPeer</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOMinFileSizeToCache</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOMinRAMAllowedToPeer</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOModifyCacheDrive</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOMonthlyUploadDataCap</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOPercentageMaxBackgroundBandwidth</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOPercentageMaxDownloadBandwidth</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOPercentageMaxForegroundBandwidth</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DORestrictPeerSelectionBy</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOSetHoursToLimitBackgroundDownloadBandwidth</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOSetHoursToLimitForegroundDownloadBandwidth</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>DeviceGuard</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>EnableVirtualizationBasedSecurity</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Turns On Virtualization Based Security(VBS)</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LsaCfgFlags</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Credential Guard Configuration: 0 - Turns off CredentialGuard remotely if configured previously without UEFI Lock, 1 - Turns on CredentialGuard with UEFI lock. 2 - Turns on CredentialGuard without UEFI lock.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RequirePlatformSecurityFeatures</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Select Platform Security Level: 1 - Turns on VBS with Secure Boot, 3 - Turns on VBS with Secure Boot and DMA. DMA requires hardware support.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>DeviceInstallation</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>PreventInstallationOfMatchingDeviceIDs</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventInstallationOfMatchingDeviceSetupClasses</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>DeviceLock</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowIdleReturnWithoutPassword</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Specifies whether the user must input a PIN or password when the device resumes from an idle state.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowScreenTimeoutWhileLockedUserConfig</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Specifies whether to show a user-configurable setting to control the screen timeout while on the lock screen of Windows 10 Mobile devices.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSimpleDevicePassword</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Specifies whether PINs or passwords such as 1111 or 1234 are allowed. For the desktop, it also controls the use of picture passwords.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AlphanumericDevicePasswordRequired</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Determines the type of PIN or password required. This policy only applies if the DeviceLock/DevicePasswordEnabled policy is set to 0</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DevicePasswordEnabled</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Specifies whether device lock is enabled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DevicePasswordExpiration</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Specifies when the password expires (in days).</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DevicePasswordHistory</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Specifies how many passwords can be stored in the history that cant be used.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnforceLockScreenAndLogonImage</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnforceLockScreenProvider</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MaxDevicePasswordFailedAttempts</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MaxInactivityTimeDeviceLock</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>The number of authentication failures allowed before the device will be wiped. A value of 0 disables device wipe functionality.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MaxInactivityTimeDeviceLockWithExternalDisplay</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Sets the maximum timeout value for the external display.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MinDevicePasswordComplexCharacters</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>The number of complex element types (uppercase and lowercase letters, numbers, and punctuation) required for a strong PIN or password.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MinDevicePasswordLength</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Specifies the minimum number or characters required in the PIN or password.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MinimumPasswordAge</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This security setting determines the period of time (in days) that a password must be used before the user can change it. You can set a value between 1 and 998 days, or you can allow changes immediately by setting the number of days to 0.

The minimum password age must be less than the Maximum password age, unless the maximum password age is set to 0, indicating that passwords will never expire. If the maximum password age is set to 0, the minimum password age can be set to any value between 0 and 998.

Configure the minimum password age to be more than 0 if you want Enforce password history to be effective. Without a minimum password age, users can cycle through passwords repeatedly until they get to an old favorite. The default setting does not follow this recommendation, so that an administrator can specify a password for a user and then require the user to change the administrator-defined password when the user logs on. If the password history is set to 0, the user does not have to choose a new password. For this reason, Enforce password history is set to 1 by default.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventEnablingLockScreenCamera</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventLockScreenSlideShow</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScreenTimeoutWhileLocked</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Specifies whether to show a user-configurable setting to control the screen timeout while on the lock screen of Windows 10 Mobile devices.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Display</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>DisablePerProcessDpiForApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy allows you to disable Per-Process System DPI for a semicolon-separated list of applications. Applications can be specified either by using full paths or with filenames and extensions. This policy will override the system-wide default value.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnablePerProcessDpi</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Enable or disable Per-Process System DPI for all applications.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnablePerProcessDpiForApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy allows you to enable Per-Process System DPI for a semicolon-separated list of applications. Applications can be specified either by using full paths or with filenames and extensions. This policy will override the system-wide default value.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TurnOffGdiDPIScalingForApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy allows to force turn off GDI DPI Scaling for a semicolon separated list of applications. Applications can be specified either by using full path or just filename and extension.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TurnOnGdiDPIScalingForApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy allows to turn on GDI DPI Scaling for a semicolon separated list of applications. Applications can be specified either by using full path or just filename and extension.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>ErrorReporting</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>CustomizeConsentSettings</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableWindowsErrorReporting</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisplayErrorNotification</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DoNotSendAdditionalData</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventCriticalErrorDisplay</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>EventLogService</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>ControlEventLogBehavior</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SpecifyMaximumFileSizeApplicationLog</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SpecifyMaximumFileSizeSecurityLog</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SpecifyMaximumFileSizeSystemLog</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Experience</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowCopyPaste</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowCortana</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowDeviceDiscovery</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowFindMyDevice</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowManualMDMUnenrollment</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSaveAsOfOfficeFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowScreenCapture</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSharingOfOfficeFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSIMErrorDialogPromptWhenNoSIM</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSyncMySettings</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowTaskSwitcher</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowVoiceRecording</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowWindowsConsumerFeatures</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowWindowsTips</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DoNotShowFeedbackNotifications</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>ExploitGuard</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>ExploitProtectionSettings</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>FileExplorer</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>TurnOffDataExecutionPreventionForExplorer</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TurnOffHeapTerminationOnCorruption</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Games</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowAdvancedGamingServices</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Specifies whether advanced gaming services can be used. These services may send data to Microsoft or publishers of games that use these services.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Handwriting</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>PanelDefaultModeDocked</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Specifies whether the handwriting panel comes up floating near the text box or attached to the bottom of the screen</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>InternetExplorer</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AddSearchProvider</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowActiveXFiltering</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowAddOnList</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowCertificateAddressMismatchWarning</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowDeletingBrowsingHistoryOnExit</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowEnhancedProtectedMode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowEnterpriseModeFromToolsMenu</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowEnterpriseModeSiteList</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowFallbackToSSL3</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowInternetExplorer7PolicyList</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowInternetExplorerStandardsMode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowInternetZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowIntranetZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLocalMachineZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLockedDownInternetZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLockedDownIntranetZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLockedDownLocalMachineZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLockedDownRestrictedSitesZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowOneWordEntry</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSiteToZoneAssignmentList</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowsLockedDownTrustedSitesZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSoftwareWhenSignatureIsInvalid</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowsRestrictedSitesZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSuggestedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowTrustedSitesZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>CheckServerCertificateRevocation</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>CheckSignaturesOnDownloadedPrograms</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConsistentMimeHandlingInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableAdobeFlash</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableBypassOfSmartScreenWarnings</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableBypassOfSmartScreenWarningsAboutUncommonFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableConfiguringHistory</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableCrashDetection</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableCustomerExperienceImprovementProgramParticipation</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableDeletingUserVisitedWebsites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableEnclosureDownloading</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableEncryptionSupport</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableFirstRunWizard</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableFlipAheadFeature</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableIgnoringCertificateErrors</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableInPrivateBrowsing</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableProcessesInEnhancedProtectedMode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableProxyChange</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableSearchProviderChange</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableSecondaryHomePageChange</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableSecuritySettingsCheck</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableUpdateCheck</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DoNotAllowActiveXControlsInProtectedMode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DoNotAllowUsersToAddSites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DoNotAllowUsersToChangePolicies</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DoNotBlockOutdatedActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DoNotBlockOutdatedActiveXControlsOnSpecificDomains</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IncludeAllLocalSites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IncludeAllNetworkPaths</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowCopyPasteViaScript</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowDragAndDropCopyAndPasteFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowLoadingOfXAMLFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowOnlyApprovedDomainsToUseActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowOnlyApprovedDomainsToUseTDCActiveXControl</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowScriptingOfInternetExplorerWebBrowserControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowScriptInitiatedWindows</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowUpdatesToStatusBarViaScript</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowVBScriptToRunInInternetExplorer</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneDoNotRunAntimalwareAgainstActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneDownloadSignedActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneDownloadUnsignedActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneEnableCrossSiteScriptingFilter</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneEnableDraggingOfContentFromDifferentDomainsAcrossWindows</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneEnableDraggingOfContentFromDifferentDomainsWithinWindows</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneEnableMIMESniffing</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneEnableProtectedMode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneIncludeLocalPathWhenUploadingFilesToServer</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneLaunchingApplicationsAndFilesInIFRAME</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneLogonOptions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneRunNETFrameworkReliantComponentsSignedWithAuthenticode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneShowSecurityWarningForPotentiallyUnsafeFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneUsePopupBlocker</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneDoNotRunAntimalwareAgainstActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneDoNotRunAntimalwareAgainstActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MimeSniffingSafetyFeatureInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MKProtocolSecurityRestrictionInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NotificationBarInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventManagingSmartScreenFilter</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventPerUserInstallationOfActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ProtectionFromZoneElevationInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RemoveRunThisTimeButtonForOutdatedActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictActiveXInstallInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowActiveScripting</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowBinaryAndScriptBehaviors</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowCopyPasteViaScript</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowDragAndDropCopyAndPasteFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowLoadingOfXAMLFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowMETAREFRESH</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowOnlyApprovedDomainsToUseActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowOnlyApprovedDomainsToUseTDCActiveXControl</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowScriptingOfInternetExplorerWebBrowserControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowScriptInitiatedWindows</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowUpdatesToStatusBarViaScript</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowVBScriptToRunInInternetExplorer</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneDoNotRunAntimalwareAgainstActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneDownloadSignedActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneDownloadUnsignedActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneEnableCrossSiteScriptingFilter</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneEnableDraggingOfContentFromDifferentDomainsAcrossWindows</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneEnableDraggingOfContentFromDifferentDomainsWithinWindows</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneEnableMIMESniffing</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneIncludeLocalPathWhenUploadingFilesToServer</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneLaunchingApplicationsAndFilesInIFRAME</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneLogonOptions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneRunActiveXControlsAndPlugins</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneRunNETFrameworkReliantComponentsSignedWithAuthenticode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneScriptActiveXControlsMarkedSafeForScripting</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneScriptingOfJavaApplets</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneShowSecurityWarningForPotentiallyUnsafeFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneTurnOnProtectedMode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneUsePopupBlocker</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictFileDownloadInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScriptedWindowSecurityRestrictionsInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SearchProviderList</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SecurityZonesUseOnlyMachineSettings</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SpecifyUseOfActiveXInstallerService</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneDoNotRunAntimalwareAgainstActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Kerberos</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowForestSearchOrder</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>KerberosClientSupportsClaimsCompoundArmor</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RequireKerberosArmoring</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RequireStrictKDCValidation</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SetMaximumContextTokenSize</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>KioskBrowser</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>BlockedUrlExceptions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of exceptions to the blocked website URLs (with wildcard support). This is used to configure URLs kiosk browsers are allowed to navigate to, which are a subset of the blocked URLs.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>BlockedUrls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of blocked website URLs (with wildcard support). This is used to configure blocked URLs kiosk browsers can not navigate to.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DefaultURL</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Configures the default URL kiosk browsers to navigate on launch and restart.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableEndSessionButton</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Enable/disable kiosk browser's end session button.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableHomeButton</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Enable/disable kiosk browser's home button.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableNavigationButtons</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Enable/disable kiosk browser's navigation buttons (forward/back).</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestartOnIdleTime</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Amount of time in minutes the session is idle until the kiosk browser restarts in a fresh state.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>LanmanWorkstation</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>EnableInsecureGuestLogons</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Licensing</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowWindowsEntitlementReactivation</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisallowKMSClientOnlineAVSValidation</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>LocalPoliciesSecurityOptions</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>Accounts_BlockMicrosoftAccounts</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting prevents users from adding new Microsoft accounts on this computer.

If you select the "Users cant add Microsoft accounts" option, users will not be able to create new Microsoft accounts on this computer, switch a local account to a Microsoft account, or connect a domain account to a Microsoft account. This is the preferred option if you need to limit the use of Microsoft accounts in your enterprise.

If you select the "Users cant add or log on with Microsoft accounts" option, existing Microsoft account users will not be able to log on to Windows. Selecting this option might make it impossible for an existing administrator on this computer to log on and manage the system.

If you disable or do not configure this policy (recommended), users will be able to use Microsoft accounts with Windows.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>Accounts_EnableAdministratorAccountStatus</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This security setting determines whether the local Administrator account is enabled or disabled.

Notes

If you try to reenable the Administrator account after it has been disabled, and if the current Administrator password does not meet the password requirements, you cannot reenable the account. In this case, an alternative member of the Administrators group must reset the password on the Administrator account. For information about how to reset a password, see To reset a password.
Disabling the Administrator account can become a maintenance issue under certain circumstances. 

Under Safe Mode boot, the disabled Administrator account will only be enabled if the machine is non-domain joined and there are no other local active administrator accounts.  If the computer is domain joined the disabled administrator will not be enabled.

Default: Disabled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>Accounts_EnableGuestAccountStatus</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This security setting determines if the Guest account is enabled or disabled.

Default: Disabled.

Note: If the Guest account is disabled and the security option Network Access: Sharing and Security Model for local accounts is set to Guest Only, network logons, such as those performed by the Microsoft Network Server (SMB Service), will fail.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>Accounts_LimitLocalAccountUseOfBlankPasswordsToConsoleLogonOnly</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Accounts: Limit local account use of blank passwords to console logon only

This security setting determines whether local accounts that are not password protected can be used to log on from locations other than the physical computer console. If enabled, local accounts that are not password protected will only be able to log on at the computer's keyboard.

Default: Enabled.


Warning:

Computers that are not in physically secure locations should always enforce strong password policies for all local user accounts. Otherwise, anyone with physical access to the computer can log on by using a user account that does not have a password. This is especially important for portable computers.
If you apply this security policy to the Everyone group, no one will be able to log on through Remote Desktop Services.

Notes

This setting does not affect logons that use domain accounts.
It is possible for applications that use remote interactive logons to bypass this setting.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>Accounts_RenameAdministratorAccount</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Accounts: Rename administrator account

This security setting determines whether a different account name is associated with the security identifier (SID) for the account Administrator. Renaming the well-known Administrator account makes it slightly more difficult for unauthorized persons to guess this privileged user name and password combination.

Default: Administrator.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>Accounts_RenameGuestAccount</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Accounts: Rename guest account

This security setting determines whether a different account name is associated with the security identifier (SID) for the account "Guest." Renaming the well-known Guest account makes it slightly more difficult for unauthorized persons to guess this user name and password combination.

Default: Guest.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>Devices_AllowedToFormatAndEjectRemovableMedia</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Devices: Allowed to format and eject removable media

This security setting determines who is allowed to format and eject removable NTFS media. This capability can be given to:

Administrators
Administrators and Interactive Users

Default: This policy is not defined and only Administrators have this ability.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>Devices_AllowUndockWithoutHavingToLogon</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Devices: Allow undock without having to log on
This security setting determines whether a portable computer can be undocked without having to log on. If this policy is enabled, logon is not required and an external hardware eject button can be used to undock the computer. If disabled, a user must log on and have the Remove computer from docking station privilege to undock the computer.
Default: Enabled.

Caution
Disabling this policy may tempt users to try and physically remove the laptop from its docking station using methods other than the external hardware eject button. Since this may cause damage to the hardware, this setting, in general, should only be disabled on laptop configurations that are physically securable.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>Devices_PreventUsersFromInstallingPrinterDriversWhenConnectingToSharedPrinters</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Devices: Prevent users from installing printer drivers when connecting to shared printers

For a computer to print to a shared printer, the driver for that shared printer must be installed on the local computer. This security setting determines who is allowed to install a printer driver as part of connecting to a shared printer. If this setting is enabled, only Administrators can install a printer driver as part of connecting to a shared printer. If this setting is disabled, any user can install a printer driver as part of connecting to a shared printer.

Default on servers: Enabled.
Default on workstations: Disabled

Notes

This setting does not affect the ability to add a local printer.
This setting does not affect Administrators.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>Devices_RestrictCDROMAccessToLocallyLoggedOnUserOnly</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Devices: Restrict CD-ROM access to locally logged-on user only

This security setting determines whether a CD-ROM is accessible to both local and remote users simultaneously.

If this policy is enabled, it allows only the interactively logged-on user to access removable CD-ROM media. If this policy is enabled and no one is logged on interactively, the CD-ROM can be accessed over the network.

Default: This policy is not defined and CD-ROM access is not restricted to the locally logged-on user.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DomainMember_DigitallyEncryptOrSignSecureChannelDataAlways</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Domain member: Digitally encrypt or sign secure channel data (always)

This security setting determines whether all secure channel traffic initiated by the domain member must be signed or encrypted.

When a computer joins a domain, a computer account is created. After that, when the system starts, it uses the computer account password to create a secure channel with a domain controller for its domain. This secure channel is used to perform operations such as NTLM pass through authentication, LSA SID/name Lookup etc.

This setting determines whether or not all secure channel traffic initiated by the domain member meets minimum security requirements. Specifically it determines whether all secure channel traffic initiated by the domain member must be signed or encrypted. If this policy is enabled, then the secure channel will not be established unless either signing or encryption of all secure channel traffic is negotiated. If this policy is disabled, then encryption and signing of all secure channel traffic is negotiated with the Domain Controller in which case the level of signing and encryption depends on the version of the Domain Controller and the settings of the following two policies:

Domain member: Digitally encrypt secure channel data (when possible)
Domain member: Digitally sign secure channel data (when possible)

Default: Enabled.

Notes:

If this policy is enabled, the policy Domain member: Digitally sign secure channel data (when possible) is assumed to be enabled regardless of its current setting. This ensures that the domain member attempts to negotiate at least signing of the secure channel traffic.
If this policy is enabled, the policy Domain member: Digitally sign secure channel data (when possible) is assumed to be enabled regardless of its current setting. This ensures that the domain member attempts to negotiate at least signing of the secure channel traffic.
Logon information transmitted over the secure channel is always encrypted regardless of whether encryption of ALL other secure channel traffic is negotiated or not.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DomainMember_DigitallyEncryptSecureChannelDataWhenPossible</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Domain member: Digitally encrypt secure channel data (when possible)

This security setting determines whether a domain member attempts to negotiate encryption for all secure channel traffic that it initiates.

When a computer joins a domain, a computer account is created. After that, when the system starts, it uses the computer account password to create a secure channel with a domain controller for its domain. This secure channel is used to perform operations such as NTLM pass-through authentication, LSA SID/name Lookup etc.

This setting determines whether or not the domain member attempts to negotiate encryption for all secure channel traffic that it initiates. If enabled, the domain member will request encryption of all secure channel traffic. If the domain controller supports encryption of all secure channel traffic, then all secure channel traffic will be encrypted. Otherwise only logon information transmitted over the secure channel will be encrypted. If this setting is disabled, then the domain member will not attempt to negotiate secure channel encryption.

Default: Enabled.

Important

There is no known reason for disabling this setting. Besides unnecessarily reducing the potential confidentiality level of the secure channel, disabling this setting may unnecessarily reduce secure channel throughput, because concurrent API calls that use the secure channel are only possible when the secure channel is signed or encrypted.

Note: Domain controllers are also domain members and establish secure channels with other domain controllers in the same domain as well as domain controllers in trusted domains.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DomainMember_DisableMachineAccountPasswordChanges</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Domain member: Disable machine account password changes

Determines whether a domain member periodically changes its computer account password. If this setting is enabled, the domain member does not attempt to change its computer account password. If this setting is disabled, the domain member attempts to change its computer account password as specified by the setting for Domain Member: Maximum age for machine account password, which by default is every 30 days.

Default: Disabled.

Notes

This security setting should not be enabled. Computer account passwords are used to establish secure channel communications between members and domain controllers and, within the domain, between the domain controllers themselves. Once it is established, the secure channel is used to transmit sensitive information that is necessary for making authentication and authorization decisions.
This setting should not be used in an attempt to support dual-boot scenarios that use the same computer account. If you want to dual-boot two installations that are joined to the same domain, give the two installations different computer names.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InteractiveLogon_DisplayUserInformationWhenTheSessionIsLocked</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Interactive Logon:Display user information when the session is locked
User display name, domain and user names (1)
User display name only (2)
Do not display user information (3)</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InteractiveLogon_DoNotDisplayLastSignedIn</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Interactive logon: Don't display last signed-in
This security setting determines whether the Windows sign-in screen will show the username of the last person who signed in on this PC.
If this policy is enabled, the username will not be shown.

If this policy is disabled, the username will be shown.

Default: Disabled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InteractiveLogon_DoNotDisplayUsernameAtSignIn</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Interactive logon: Don't display username at sign-in
This security setting determines whether the username of the person signing in to this PC appears at Windows sign-in, after credentials are entered, and before the PC desktop is shown.
If this policy is enabled, the username will not be shown.

If this policy is disabled, the username will be shown.

Default: Disabled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InteractiveLogon_DoNotRequireCTRLALTDEL</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Interactive logon: Do not require CTRL+ALT+DEL

This security setting determines whether pressing CTRL+ALT+DEL is required before a user can log on.

If this policy is enabled on a computer, a user is not required to press CTRL+ALT+DEL to log on. Not having to press CTRL+ALT+DEL leaves users susceptible to attacks that attempt to intercept the users' passwords. Requiring CTRL+ALT+DEL before users log on ensures that users are communicating by means of a trusted path when entering their passwords.

If this policy is disabled, any user is required to press CTRL+ALT+DEL before logging on to Windows.

Default on domain-computers: Enabled: At least Windows  8/Disabled: Windows 7 or earlier.
Default on stand-alone computers: Enabled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InteractiveLogon_MachineInactivityLimit</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Interactive logon: Machine inactivity limit.

Windows notices inactivity of a logon session, and if the amount of inactive time exceeds the inactivity limit, then the screen saver will run, locking the session.

Default: not enforced.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InteractiveLogon_MessageTextForUsersAttemptingToLogOn</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Interactive logon: Message text for users attempting to log on

This security setting specifies a text message that is displayed to users when they log on.

This text is often used for legal reasons, for example, to warn users about the ramifications of misusing company information or to warn them that their actions may be audited.

Default: No message.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InteractiveLogon_MessageTitleForUsersAttemptingToLogOn</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Interactive logon: Message title for users attempting to log on

This security setting allows the specification of a title to appear in the title bar of the window that contains the Interactive logon: Message text for users attempting to log on.

Default: No message.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InteractiveLogon_SmartCardRemovalBehavior</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Interactive logon: Smart card removal behavior

This security setting determines what happens when the smart card for a logged-on user is removed from the smart card reader.

The options are:

 No Action
 Lock Workstation
 Force Logoff
 Disconnect if a Remote Desktop Services session 

If you click Lock Workstation in the Properties dialog box for this policy, the workstation is locked when the smart card is removed, allowing users to leave the area, take their smart card with them, and still maintain a protected session.

If you click Force Logoff in the Properties dialog box for this policy, the user is automatically logged off when the smart card is removed.

If you click Disconnect if a Remote Desktop Services session, removal of the smart card disconnects the session without logging the user off. This allows the user to insert the smart card and resume the session later, or at another smart card reader-equipped computer, without having to log on again. If the session is local, this policy functions identically to Lock Workstation.

Note: Remote Desktop Services was called Terminal Services in previous versions of Windows Server.

Default: This policy is not defined, which means that the system treats it as No action.

On Windows Vista and above: For this setting to work, the Smart Card Removal Policy service must be started.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MicrosoftNetworkClient_DigitallySignCommunicationsIfServerAgrees</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Microsoft network client: Digitally sign communications (if server agrees)

This security setting determines whether the SMB client attempts to negotiate SMB packet signing.

The server message block (SMB) protocol provides the basis for Microsoft file and print sharing and many other networking operations, such as remote Windows administration. To prevent man-in-the-middle attacks that modify SMB packets in transit, the SMB protocol supports the digital signing of SMB packets. This policy setting determines whether the SMB client component attempts to negotiate SMB packet signing when it connects to an SMB server.

If this setting is enabled, the Microsoft network client will ask the server to perform SMB packet signing upon session setup. If packet signing has been enabled on the server, packet signing will be negotiated. If this policy is disabled, the SMB client will never negotiate SMB packet signing.

Default: Enabled.

Notes

All Windows operating systems support both a client-side SMB component and a server-side SMB component. On Windows 2000 and later, enabling or requiring packet signing for client and server-side SMB components is controlled by the following four policy settings:
Microsoft network client: Digitally sign communications (always) - Controls whether or not the client-side SMB component requires packet signing.
Microsoft network client: Digitally sign communications (if server agrees) - Controls whether or not the client-side SMB component has packet signing enabled.
Microsoft network server: Digitally sign communications (always) - Controls whether or not the server-side SMB component requires packet signing.
Microsoft network server: Digitally sign communications (if client agrees) - Controls whether or not the server-side SMB component has packet signing enabled.
If both client-side and server-side SMB signing is enabled and the client establishes an SMB 1.0 connection to the server, SMB signing will be attempted.
SMB packet signing can significantly degrade SMB performance, depending on dialect version, OS version, file sizes, processor offloading capabilities, and application IO behaviors. This setting only applies to SMB 1.0 connections.
For more information, reference: https://go.microsoft.com/fwlink/?LinkID=787136.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MicrosoftNetworkClient_SendUnencryptedPasswordToThirdPartySMBServers</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Microsoft network client: Send unencrypted password to connect to third-party SMB servers

If this security setting is enabled, the Server Message Block (SMB) redirector is allowed to send plaintext passwords to non-Microsoft SMB servers that do not support password encryption during authentication.

Sending unencrypted passwords is a security risk.

Default: Disabled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MicrosoftNetworkServer_AmountOfIdleTimeRequiredBeforeSuspendingSession</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Microsoft network server: Amount of idle time required before suspending a session

This security setting determines the amount of continuous idle time that must pass in a Server Message Block (SMB) session before the session is suspended due to inactivity.

Administrators can use this policy to control when a computer suspends an inactive SMB session. If client activity resumes, the session is automatically reestablished.

For this policy setting, a value of 0 means to disconnect an idle session as quickly as is reasonably possible. The maximum value is 99999, which is 208 days; in effect, this value disables the policy.

Default:This policy is not defined, which means that the system treats it as 15 minutes for servers and undefined for workstations.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MicrosoftNetworkServer_DigitallySignCommunicationsAlways</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Microsoft network server: Digitally sign communications (always)

This security setting determines whether packet signing is required by the SMB server component.

The server message block (SMB) protocol provides the basis for Microsoft file and print sharing and many other networking operations, such as remote Windows administration. To prevent man-in-the-middle attacks that modify SMB packets in transit, the SMB protocol supports the digital signing of SMB packets. This policy setting determines whether SMB packet signing must be negotiated before further communication with an SMB client is permitted.

If this setting is enabled, the Microsoft network server will not communicate with a Microsoft network client unless that client agrees to perform SMB packet signing. If this setting is disabled, SMB packet signing is negotiated between the client and server.

Default:

Disabled for member servers.
Enabled for domain controllers.

Notes

All Windows operating systems support both a client-side SMB component and a server-side SMB component. On Windows 2000 and later, enabling or requiring packet signing for client and server-side SMB components is controlled by the following four policy settings:
Microsoft network client: Digitally sign communications (always) - Controls whether or not the client-side SMB component requires packet signing.
Microsoft network client: Digitally sign communications (if server agrees) - Controls whether or not the client-side SMB component has packet signing enabled.
Microsoft network server: Digitally sign communications (always) - Controls whether or not the server-side SMB component requires packet signing.
Microsoft network server: Digitally sign communications (if client agrees) - Controls whether or not the server-side SMB component has packet signing enabled.
Similarly, if client-side SMB signing is required, that client will not be able to establish a session with servers that do not have packet signing enabled. By default, server-side SMB signing is enabled only on domain controllers.
If server-side SMB signing is enabled, SMB packet signing will be negotiated with clients that have client-side SMB signing enabled.
SMB packet signing can significantly degrade SMB performance, depending on dialect version, OS version, file sizes, processor offloading capabilities, and application IO behaviors.

Important

For this policy to take effect on computers running Windows 2000, server-side packet signing must also be enabled. To enable server-side SMB packet signing, set the following policy:
Microsoft network server: Digitally sign communications (if server agrees)

For Windows 2000 servers to negotiate signing with Windows NT 4.0 clients, the following registry value must be set to 1 on the Windows 2000 server:
HKLM\System\CurrentControlSet\Services\lanmanserver\parameters\enableW9xsecuritysignature
For more information, reference: https://go.microsoft.com/fwlink/?LinkID=787136.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MicrosoftNetworkServer_DigitallySignCommunicationsIfClientAgrees</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Microsoft network server: Digitally sign communications (if client agrees)

This security setting determines whether the SMB server will negotiate SMB packet signing with clients that request it.

The server message block (SMB) protocol provides the basis for Microsoft file and print sharing and many other networking operations, such as remote Windows administration. To prevent man-in-the-middle attacks that modify SMB packets in transit, the SMB protocol supports the digital signing of SMB packets. This policy setting determines whether the SMB server will negotiate SMB packet signing when an SMB client requests it.

If this setting is enabled, the Microsoft network server will negotiate SMB packet signing as requested by the client. That is, if packet signing has been enabled on the client, packet signing will be negotiated. If this policy is disabled, the SMB client will never negotiate SMB packet signing.

Default: Enabled on domain controllers only.

Important

For Windows 2000 servers to negotiate signing with Windows NT 4.0 clients, the following registry value must be set to 1 on the server running Windows 2000: HKLM\System\CurrentControlSet\Services\lanmanserver\parameters\enableW9xsecuritysignature

Notes

All Windows operating systems support both a client-side SMB component and a server-side SMB component. For Windows 2000 and above, enabling or requiring packet signing for client and server-side SMB components is controlled by the following four policy settings:
Microsoft network client: Digitally sign communications (always) - Controls whether or not the client-side SMB component requires packet signing.
Microsoft network client: Digitally sign communications (if server agrees) - Controls whether or not the client-side SMB component has packet signing enabled.
Microsoft network server: Digitally sign communications (always) - Controls whether or not the server-side SMB component requires packet signing.
Microsoft network server: Digitally sign communications (if client agrees) - Controls whether or not the server-side SMB component has packet signing enabled.
If both client-side and server-side SMB signing is enabled and the client establishes an SMB 1.0 connection to the server, SMB signing will be attempted.
SMB packet signing can significantly degrade SMB performance, depending on dialect version, OS version, file sizes, processor offloading capabilities, and application IO behaviors. This setting only applies to SMB 1.0 connections.
For more information, reference: https://go.microsoft.com/fwlink/?LinkID=787136.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NetworkAccess_DoNotAllowAnonymousEnumerationOfSAMAccounts</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Network access: Do not allow anonymous enumeration of SAM accounts

This security setting determines what additional permissions will be granted for anonymous connections to the computer.

Windows allows anonymous users to perform certain activities, such as enumerating the names of domain accounts and network shares. This is convenient, for example, when an administrator wants to grant access to users in a trusted domain that does not maintain a reciprocal trust.

This security option allows additional restrictions to be placed on anonymous connections as follows:

Enabled: Do not allow enumeration of SAM accounts. This option replaces Everyone with Authenticated Users in the security permissions for resources.
Disabled: No additional restrictions. Rely on default permissions.

Default on workstations: Enabled.
Default on server:Enabled.

Important

This policy has no impact on domain controllers.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NetworkAccess_DoNotAllowAnonymousEnumerationOfSamAccountsAndShares</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Network access: Do not allow anonymous enumeration of SAM accounts and shares

This security setting determines whether anonymous enumeration of SAM accounts and shares is allowed.

Windows allows anonymous users to perform certain activities, such as enumerating the names of domain accounts and network shares. This is convenient, for example, when an administrator wants to grant access to users in a trusted domain that does not maintain a reciprocal trust. If you do not want to allow anonymous enumeration of SAM accounts and shares, then enable this policy.

Default: Disabled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NetworkAccess_RestrictAnonymousAccessToNamedPipesAndShares</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Network access: Restrict anonymous access to Named Pipes and Shares

When enabled, this security setting restricts anonymous access to shares and pipes to the settings for:

Network access: Named pipes that can be accessed anonymously
Network access: Shares that can be accessed anonymously
Default: Enabled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NetworkAccess_RestrictClientsAllowedToMakeRemoteCallsToSAM</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Network access: Restrict clients allowed to make remote calls to SAM

This policy setting allows you to restrict remote rpc connections to SAM.

If not selected, the default security descriptor will be used.

This policy is supported on at least Windows Server 2016.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NetworkSecurity_AllowPKU2UAuthenticationRequests</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Network security: Allow PKU2U authentication requests to this computer to use online identities.

This policy will be turned off by default on domain joined machines. This would prevent online identities from authenticating to the domain joined machine.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NetworkSecurity_DoNotStoreLANManagerHashValueOnNextPasswordChange</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Network security: Do not store LAN Manager hash value on next password change

This security setting determines if, at the next password change, the LAN Manager (LM) hash value for the new password is stored. The LM hash is relatively weak and prone to attack, as compared with the cryptographically stronger Windows NT hash. Since the LM hash is stored on the local computer in the security database the passwords can be compromised if the security database is attacked.


Default on Windows Vista and above: Enabled
Default on Windows XP: Disabled.

Important

Windows 2000 Service Pack 2 (SP2) and above offer compatibility with authentication to previous versions of Windows, such as Microsoft Windows NT 4.0.
This setting can affect the ability of computers running Windows 2000 Server, Windows 2000 Professional, Windows XP, and the Windows Server 2003 family to communicate with computers running Windows 95 and Windows 98.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NetworkSecurity_LANManagerAuthenticationLevel</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Network security LAN Manager authentication level

This security setting determines which challenge/response authentication protocol is used for network logons. This choice affects the level of authentication protocol used by clients, the level of session security negotiated, and the level of authentication accepted by servers as follows:

Send LM and NTLM responses: Clients use LM and NTLM authentication and never use NTLMv2 session security; domain controllers accept LM, NTLM, and NTLMv2 authentication.

Send LM and NTLM - use NTLMv2 session security if negotiated: Clients use LM and NTLM authentication and use NTLMv2 session security if the server supports it; domain controllers accept LM, NTLM, and NTLMv2 authentication.

Send NTLM response only: Clients use NTLM authentication only and use NTLMv2 session security if the server supports it; domain controllers accept LM, NTLM, and NTLMv2 authentication.

Send NTLMv2 response only: Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it; domain controllers accept LM, NTLM, and NTLMv2 authentication.

Send NTLMv2 response only\refuse LM: Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it; domain controllers refuse LM (accept only NTLM and NTLMv2 authentication).

Send NTLMv2 response only\refuse LM and NTLM: Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it; domain controllers refuse LM and NTLM (accept only NTLMv2 authentication).

Important

This setting can affect the ability of computers running Windows 2000 Server, Windows 2000 Professional, Windows XP Professional, and the Windows Server 2003 family to communicate with computers running Windows NT 4.0 and earlier over the network. For example, at the time of this writing, computers running Windows NT 4.0 SP4 and earlier did not support NTLMv2. Computers running Windows 95 and Windows 98 did not support NTLM.

Default:

Windows 2000 and windows XP: send LM and NTLM responses

Windows Server 2003: Send NTLM response only

Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2: Send NTLMv2 response only</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NetworkSecurity_MinimumSessionSecurityForNTLMSSPBasedServers</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Network security: Minimum session security for NTLM SSP based (including secure RPC) servers

This security setting allows a server to require the negotiation of 128-bit encryption and/or NTLMv2 session security. These values are dependent on the LAN Manager Authentication Level security setting value. The options are:

Require NTLMv2 session security: The connection will fail if message integrity is not negotiated.
Require 128-bit encryption. The connection will fail if strong encryption (128-bit) is not negotiated.

Default:

Windows XP, Windows Vista, Windows 2000 Server, Windows Server 2003, and Windows Server 2008: No requirements.

Windows 7 and Windows Server 2008 R2: Require 128-bit encryption</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NetworkSecurity_RestrictNTLM_AddRemoteServerExceptionsForNTLMAuthentication</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Network security: Restrict NTLM: Add remote server exceptions for NTLM authentication

This policy setting allows you to create an exception list of remote servers to which clients are allowed to use NTLM authentication if the  "Network Security: Restrict NTLM: Outgoing NTLM traffic to remote servers" policy setting is configured.

If you configure this policy setting, you can define a list of remote servers to which clients are allowed to use NTLM authentication.

If you do not configure this policy setting, no exceptions will be applied.

The naming format for servers on this exception list is the fully qualified domain name (FQDN) or NetBIOS server name used by the application, listed one per line. To ensure exceptions the name used by all applications needs to be in the list, and to ensure an exception is accurate, the server name should be listed in both naming formats . A single asterisk (*) can be used anywhere in the string as a wildcard character.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NetworkSecurity_RestrictNTLM_AuditIncomingNTLMTraffic</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Network security: Restrict NTLM: Audit Incoming NTLM Traffic

This policy setting allows you to audit incoming NTLM traffic.

If you select "Disable", or do not configure this policy setting, the server will not log events for incoming NTLM traffic.

If you select "Enable auditing for domain accounts", the server will log events for NTLM pass-through authentication requests that would be blocked when the "Network Security: Restrict NTLM: Incoming NTLM traffic" policy setting is set to the "Deny all domain accounts" option.

If you select "Enable auditing for all accounts", the server will log events for all NTLM authentication requests that would be blocked when the "Network Security: Restrict NTLM: Incoming NTLM traffic" policy setting is set to the "Deny all accounts" option.

This policy is supported on at least Windows 7 or Windows Server 2008 R2.

Note: Audit events are recorded on this computer in the "Operational" Log located under the Applications and Services Log/Microsoft/Windows/NTLM.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NetworkSecurity_RestrictNTLM_IncomingNTLMTraffic</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Network security: Restrict NTLM: Incoming NTLM traffic

This policy setting allows you to deny or allow incoming NTLM traffic.

If you select "Allow all" or do not configure this policy setting, the server will allow all NTLM authentication requests.

If you select "Deny all domain accounts," the server will deny NTLM authentication requests for domain logon and display an NTLM blocked error, but allow local account logon.

If you select "Deny all accounts," the server will deny NTLM authentication requests from incoming traffic and display an NTLM blocked error.

This policy is supported on at least Windows 7 or Windows Server 2008 R2.

Note: Block events are recorded on this computer in the "Operational" Log located under the Applications and Services Log/Microsoft/Windows/NTLM.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NetworkSecurity_RestrictNTLM_OutgoingNTLMTrafficToRemoteServers</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers

This policy setting allows you to deny or audit outgoing NTLM traffic from this Windows 7 or this Windows Server 2008 R2 computer to any Windows remote server.

If you select "Allow all" or do not configure this policy setting, the client computer can authenticate identities to a remote server by using NTLM authentication.

If you select "Audit all," the client computer logs an event for each NTLM authentication request to a remote server. This allows you to identify those servers receiving NTLM authentication requests from the client computer.

If you select "Deny all," the client computer cannot authenticate identities to a remote server by using NTLM authentication. You can use the "Network security: Restrict NTLM: Add remote server exceptions for NTLM authentication" policy setting to define a list of remote servers to which clients are allowed to use NTLM authentication.

This policy is supported on at least Windows 7 or Windows Server 2008 R2.

Note: Audit and block events are recorded on this computer in the "Operational" Log located under the Applications and Services Log/Microsoft/Windows/NTLM.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>Shutdown_AllowSystemToBeShutDownWithoutHavingToLogOn</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Shutdown: Allow system to be shut down without having to log on

This security setting determines whether a computer can be shut down without having to log on to Windows.

When this policy is enabled, the Shut Down command is available on the Windows logon screen.

When this policy is disabled, the option to shut down the computer does not appear on the Windows logon screen. In this case, users must be able to log on to the computer successfully and have the Shut down the system user right before they can perform a system shutdown.

Default on workstations: Enabled.
Default on servers: Disabled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>Shutdown_ClearVirtualMemoryPageFile</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Shutdown: Clear virtual memory pagefile

This security setting determines whether the virtual memory pagefile is cleared when the system is shut down.

Virtual memory support uses a system pagefile to swap pages of memory to disk when they are not used. On a running system, this pagefile is opened exclusively by the operating system, and it is well protected. However, systems that are configured to allow booting to other operating systems might have to make sure that the system pagefile is wiped clean when this system shuts down. This ensures that sensitive information from process memory that might go into the pagefile is not available to an unauthorized user who manages to directly access the pagefile.

When this policy is enabled, it causes the system pagefile to be cleared upon clean shutdown. If you enable this security option, the hibernation file (hiberfil.sys) is also zeroed out when hibernation is disabled.

Default: Disabled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UserAccountControl_AllowUIAccessApplicationsToPromptForElevation</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>User Account Control: Allow UIAccess applications to prompt for elevation without using the secure desktop.

This policy setting controls whether User Interface Accessibility (UIAccess or UIA) programs can automatically disable the secure desktop for elevation prompts used by a standard user.

• Enabled: UIA programs, including Windows Remote Assistance, automatically disable the secure desktop for elevation prompts. If you do not disable the "User Account Control: Switch to the secure desktop when prompting for elevation" policy setting, the prompts appear on the interactive user's desktop instead of the secure desktop.

• Disabled: (Default) The secure desktop can be disabled only by the user of the interactive desktop or by disabling the "User Account Control: Switch to the secure desktop when prompting for elevation" policy setting.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UserAccountControl_BehaviorOfTheElevationPromptForAdministrators</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode

This policy setting controls the behavior of the elevation prompt for administrators.

The options are:

• Elevate without prompting: Allows privileged accounts to perform an operation that requires elevation without requiring consent or credentials. Note: Use this option only in the most constrained environments.

• Prompt for credentials on the secure desktop: When an operation requires elevation of privilege, the user is prompted on the secure desktop to enter a privileged user name and password. If the user enters valid credentials, the operation continues with the user's highest available privilege.

• Prompt for consent on the secure desktop: When an operation requires elevation of privilege, the user is prompted on the secure desktop to select either Permit or Deny. If the user selects Permit, the operation continues with the user's highest available privilege.

• Prompt for credentials: When an operation requires elevation of privilege, the user is prompted to enter an administrative user name and password. If the user enters valid credentials, the operation continues with the applicable privilege.

• Prompt for consent: When an operation requires elevation of privilege, the user is prompted to select either Permit or Deny. If the user selects Permit, the operation continues with the user's highest available privilege.

• Prompt for consent for non-Windows binaries: (Default) When an operation for a non-Microsoft application requires elevation of privilege, the user is prompted on the secure desktop to select either Permit or Deny. If the user selects Permit, the operation continues with the user's highest available privilege.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UserAccountControl_BehaviorOfTheElevationPromptForStandardUsers</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>User Account Control: Behavior of the elevation prompt for standard users
This policy setting controls the behavior of the elevation prompt for standard users.

The options are:

• Prompt for credentials: (Default) When an operation requires elevation of privilege, the user is prompted to enter an administrative user name and password. If the user enters valid credentials, the operation continues with the applicable privilege.

• Automatically deny elevation requests: When an operation requires elevation of privilege, a configurable access denied error message is displayed. An enterprise that is running desktops as standard user may choose this setting to reduce help desk calls.

• Prompt for credentials on the secure desktop: When an operation requires elevation of privilege, the user is prompted on the secure desktop to enter a different user name and password. If the user enters valid credentials, the operation continues with the applicable privilege.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UserAccountControl_DetectApplicationInstallationsAndPromptForElevation</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>User Account Control: Detect application installations and prompt for elevation

This policy setting controls the behavior of application installation detection for the computer.

The options are:

Enabled: (Default) When an application installation package is detected that requires elevation of privilege, the user is prompted to enter an administrative user name and password. If the user enters valid credentials, the operation continues with the applicable privilege.

Disabled: Application installation packages are not detected and prompted for elevation. Enterprises that are running standard user desktops and use delegated installation technologies such as Group Policy Software Installation or Systems Management Server (SMS) should disable this policy setting. In this case, installer detection is unnecessary.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UserAccountControl_OnlyElevateExecutableFilesThatAreSignedAndValidated</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>User Account Control: Only elevate executable files that are signed and validated

This policy setting enforces public key infrastructure (PKI) signature checks for any interactive applications that request elevation of privilege. Enterprise administrators can control which applications are allowed to run by adding certificates to the Trusted Publishers certificate store on local computers.

The options are:

• Enabled: Enforces the PKI certification path validation for a given executable file before it is permitted to run.

• Disabled: (Default) Does not enforce PKI certification path validation before a given executable file is permitted to run.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UserAccountControl_OnlyElevateUIAccessApplicationsThatAreInstalledInSecureLocations</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>User Account Control: Only elevate UIAccess applications that are installed in secure locations

This policy setting controls whether applications that request to run with a User Interface Accessibility (UIAccess) integrity level must reside in a secure location in the file system. Secure locations are limited to the following:

- …\Program Files\, including subfolders
- …\Windows\system32\
- …\Program Files (x86)\, including subfolders for 64-bit versions of Windows

Note: Windows enforces a public key infrastructure (PKI) signature check on any interactive application that requests to run with a UIAccess integrity level regardless of the state of this security setting.

The options are:

• Enabled: (Default) If an application resides in a secure location in the file system, it runs only with UIAccess integrity.

• Disabled: An application runs with UIAccess integrity even if it does not reside in a secure location in the file system.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UserAccountControl_RunAllAdministratorsInAdminApprovalMode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>User Account Control: Turn on Admin Approval Mode

This policy setting controls the behavior of all User Account Control (UAC) policy settings for the computer. If you change this policy setting, you must restart your computer.

The options are:

• Enabled: (Default) Admin Approval Mode is enabled. This policy must be enabled and related UAC policy settings must also be set appropriately to allow the built-in Administrator account and all other users who are members of the Administrators group to run in Admin Approval Mode. 

• Disabled: Admin Approval Mode and all related UAC policy settings are disabled. Note: If this policy setting is disabled, the Security Center notifies you that the overall security of the operating system has been reduced.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UserAccountControl_SwitchToTheSecureDesktopWhenPromptingForElevation</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>User Account Control: Switch to the secure desktop when prompting for elevation

This policy setting controls whether the elevation request prompt is displayed on the interactive user's desktop or the secure desktop.

The options are:

• Enabled: (Default) All elevation requests go to the secure desktop regardless of prompt behavior policy settings for administrators and standard users.

• Disabled: All elevation requests go to the interactive user's desktop. Prompt behavior policy settings for administrators and standard users are used.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UserAccountControl_UseAdminApprovalMode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>User Account Control: Use Admin Approval Mode for the built-in Administrator account

This policy setting controls the behavior of Admin Approval Mode for the built-in Administrator account.

The options are:

• Enabled: The built-in Administrator account uses Admin Approval Mode. By default, any operation that requires elevation of privilege will prompt the user to approve the operation.

• Disabled: (Default) The built-in Administrator account runs all applications with full administrative privilege.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UserAccountControl_VirtualizeFileAndRegistryWriteFailuresToPerUserLocations</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>User Account Control: Virtualize file and registry write failures to per-user locations

This policy setting controls whether application write failures are redirected to defined registry and file system locations. This policy setting mitigates applications that run as administrator and write run-time application data to %ProgramFiles%, %Windir%, %Windir%\system32, or HKLM\Software.

The options are:

• Enabled: (Default) Application write failures are redirected at run time to defined user locations for both the file system and registry.

• Disabled: Applications that write data to protected locations fail.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Location</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>EnableLocation</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>LockDown</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowEdgeSwipe</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Maps</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowOfflineMapsDownloadOverMeteredConnection</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableOfflineMapsAutoUpdate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Messaging</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowMessageSync</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting allows backup and restore of cellular text messages to Microsoft's cloud services.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowMMS</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting allows you to enable or disable the sending and receiving cellular MMS messages.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowRCS</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting allows you to enable or disable the sending and receiving of cellular RCS (Rich Communication Services) messages.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>MSSecurityGuide</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>ApplyUACRestrictionsToLocalAccountsOnNetworkLogon</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConfigureSMBV1ClientDriver</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConfigureSMBV1Server</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableStructuredExceptionHandlingOverwriteProtection</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TurnOnWindowsDefenderProtectionAgainstPotentiallyUnwantedApplications</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>WDigestAuthentication</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>MSSLegacy</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowICMPRedirectsToOverrideOSPFGeneratedRoutes</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowTheComputerToIgnoreNetBIOSNameReleaseRequestsExceptFromWINSServers</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IPSourceRoutingProtectionLevel</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IPv6SourceRoutingProtectionLevel</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>NetworkIsolation</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>EnterpriseCloudResources</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnterpriseInternalProxyServers</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnterpriseIPRange</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnterpriseIPRangesAreAuthoritative</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnterpriseNetworkDomainNames</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnterpriseProxyServers</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnterpriseProxyServersAreAuthoritative</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NeutralResources</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Notifications</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>DisallowCloudNotification</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Power</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowStandbyStatesWhenSleepingOnBattery</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowStandbyWhenSleepingPluggedIn</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisplayOffTimeoutOnBattery</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisplayOffTimeoutPluggedIn</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HibernateTimeoutOnBattery</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HibernateTimeoutPluggedIn</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RequirePasswordWhenComputerWakesOnBattery</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RequirePasswordWhenComputerWakesPluggedIn</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>StandbyTimeoutOnBattery</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>StandbyTimeoutPluggedIn</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Printers</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>PointAndPrintRestrictions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PublishPrinters</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Privacy</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowAutoAcceptPairingAndPrivacyConsentPrompts</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowInputPersonalization</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableAdvertisingId</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableActivityFeed</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Enables ActivityFeed, which is responsible for mirroring different activity types (as applicable) across device graph of the user.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessAccountInfo</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting specifies whether Windows apps can access account information.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessAccountInfo_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are allowed access to account information. This setting overrides the default LetAppsAccessAccountInfo policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessAccountInfo_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are denied access to account information. This setting overrides the default LetAppsAccessAccountInfo policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessAccountInfo_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. The user is able to control the account information privacy setting for the listed Windows apps. This setting overrides the default LetAppsAccessAccountInfo policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCalendar</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting specifies whether Windows apps can access the calendar.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCalendar_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are allowed access to the calendar. This setting overrides the default LetAppsAccessCalendar policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCalendar_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are denied access to the calendar. This setting overrides the default LetAppsAccessCalendar policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCalendar_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. The user is able to control the calendar privacy setting for the listed Windows apps. This setting overrides the default LetAppsAccessCalendar policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCallHistory</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting specifies whether Windows apps can access call history.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCallHistory_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are allowed access to call history. This setting overrides the default LetAppsAccessCallHistory policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCallHistory_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are denied access to call history. This setting overrides the default LetAppsAccessCallHistory policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCallHistory_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. The user is able to control the call history privacy setting for the listed Windows apps. This setting overrides the default LetAppsAccessCallHistory policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCamera</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting specifies whether Windows apps can access the camera.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCamera_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are allowed access to the camera. This setting overrides the default LetAppsAccessCamera policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCamera_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are denied access to the camera. This setting overrides the default LetAppsAccessCamera policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCamera_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the camera privacy setting for the listed apps. This setting overrides the default LetAppsAccessCamera policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessContacts</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting specifies whether Windows apps can access contacts.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessContacts_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are allowed access to contacts. This setting overrides the default LetAppsAccessContacts policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessContacts_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are denied access to contacts. This setting overrides the default LetAppsAccessContacts policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessContacts_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the contacts privacy setting for the listed apps. This setting overrides the default LetAppsAccessContacts policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessEmail</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting specifies whether Windows apps can access email.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessEmail_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are allowed access to email. This setting overrides the default LetAppsAccessEmail policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessEmail_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are denied access to email. This setting overrides the default LetAppsAccessEmail policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessEmail_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the email privacy setting for the listed apps. This setting overrides the default LetAppsAccessEmail policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessGazeInput</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting specifies whether Windows apps can access the eye tracker.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessGazeInput_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Windows Store Apps. Listed apps are allowed access to the eye tracker. This setting overrides the default LetAppsAccessGazeInput policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessGazeInput_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Windows Store Apps. Listed apps are denied access to the eye tracker. This setting overrides the default LetAppsAccessGazeInput policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessGazeInput_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Windows Store Apps. The user is able to control the eye tracker privacy setting for the listed apps. This setting overrides the default LetAppsAccessGazeInput policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessLocation</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting specifies whether Windows apps can access location.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessLocation_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are allowed access to location. This setting overrides the default LetAppsAccessLocation policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessLocation_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are denied access to location. This setting overrides the default LetAppsAccessLocation policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessLocation_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the location privacy setting for the listed apps. This setting overrides the default LetAppsAccessLocation policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessMessaging</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting specifies whether Windows apps can read or send messages (text or MMS).</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessMessaging_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are allowed to read or send messages (text or MMS). This setting overrides the default LetAppsAccessMessaging policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessMessaging_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are not allowed to read or send messages (text or MMS). This setting overrides the default LetAppsAccessMessaging policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessMessaging_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the messaging privacy setting for the listed apps. This setting overrides the default LetAppsAccessMessaging policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessMicrophone</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting specifies whether Windows apps can access the microphone.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessMicrophone_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are allowed access to the microphone. This setting overrides the default LetAppsAccessMicrophone policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessMicrophone_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are denied access to the microphone. This setting overrides the default LetAppsAccessMicrophone policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessMicrophone_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the microphone privacy setting for the listed apps. This setting overrides the default LetAppsAccessMicrophone policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessMotion</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting specifies whether Windows apps can access motion data.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessMotion_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are allowed access to motion data. This setting overrides the default LetAppsAccessMotion policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessMotion_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are denied access to motion data. This setting overrides the default LetAppsAccessMotion policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessMotion_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the motion privacy setting for the listed apps. This setting overrides the default LetAppsAccessMotion policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessNotifications</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting specifies whether Windows apps can access notifications.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessNotifications_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are allowed access to notifications. This setting overrides the default LetAppsAccessNotifications policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessNotifications_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are denied access to notifications. This setting overrides the default LetAppsAccessNotifications policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessNotifications_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the notifications privacy setting for the listed apps. This setting overrides the default LetAppsAccessNotifications policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessPhone</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting specifies whether Windows apps can make phone calls</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessPhone_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are allowed to make phone calls. This setting overrides the default LetAppsAccessPhone policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessPhone_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are not allowed to make phone calls. This setting overrides the default LetAppsAccessPhone policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessPhone_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the phone call privacy setting for the listed apps. This setting overrides the default LetAppsAccessPhone policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessRadios</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting specifies whether Windows apps have access to control radios.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessRadios_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps will have access to control radios. This setting overrides the default LetAppsAccessRadios policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessRadios_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps will not have access to control radios. This setting overrides the default LetAppsAccessRadios policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessRadios_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the radios privacy setting for the listed apps. This setting overrides the default LetAppsAccessRadios policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessTasks</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting specifies whether Windows apps can access tasks.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessTasks_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are allowed access to tasks. This setting overrides the default LetAppsAccessTasks policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessTasks_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are denied access to tasks. This setting overrides the default LetAppsAccessTasks policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessTasks_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the tasks privacy setting for the listed apps. This setting overrides the default LetAppsAccessTasks policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessTrustedDevices</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting specifies whether Windows apps can access trusted devices.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessTrustedDevices_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps will have access to trusted devices. This setting overrides the default LetAppsAccessTrustedDevices policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessTrustedDevices_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps will not have access to trusted devices. This setting overrides the default LetAppsAccessTrustedDevices policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessTrustedDevices_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the 'trusted devices' privacy setting for the listed apps. This setting overrides the default LetAppsAccessTrustedDevices policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsGetDiagnosticInfo</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting specifies whether Windows apps can get diagnostic information about other apps, including user names.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsGetDiagnosticInfo_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are allowed to get diagnostic information about other apps, including user names. This setting overrides the default LetAppsGetDiagnosticInfo policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsGetDiagnosticInfo_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are not allowed to get diagnostic information about other apps, including user names. This setting overrides the default LetAppsGetDiagnosticInfo policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsGetDiagnosticInfo_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. The user is able to control the app diagnostics privacy setting for the listed Windows apps. This setting overrides the default LetAppsGetDiagnosticInfo policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsRunInBackground</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting specifies whether Windows apps can run in the background.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsRunInBackground_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are allowed to run in the background. This setting overrides the default LetAppsRunInBackground policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsRunInBackground_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are not allowed to run in the background. This setting overrides the default LetAppsRunInBackground policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsRunInBackground_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. The user is able to control the background apps privacy setting for the listed Windows apps. This setting overrides the default LetAppsRunInBackground policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsSyncWithDevices</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting specifies whether Windows apps can communicate with unpaired wireless devices.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsSyncWithDevices_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps will be allowed to communicate with unpaired wireless devices. This setting overrides the default LetAppsSyncWithDevices policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsSyncWithDevices_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps will not be allowed to communicate with unpaired wireless devices. This setting overrides the default LetAppsSyncWithDevices policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsSyncWithDevices_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the 'Communicate with unpaired wireless devices' privacy setting for the listed apps. This setting overrides the default LetAppsSyncWithDevices policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PublishUserActivities</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Allows apps/system to publish 'User Activities' into ActivityFeed.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UploadUserActivities</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Allows ActivityFeed to upload published 'User Activities'.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>RemoteAssistance</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>CustomizeWarningMessages</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SessionLogging</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SolicitedRemoteAssistance</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UnsolicitedRemoteAssistance</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>RemoteDesktopServices</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowUsersToConnectRemotely</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ClientConnectionEncryptionLevel</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DoNotAllowDriveRedirection</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DoNotAllowPasswordSaving</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PromptForPasswordUponConnection</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RequireSecureRPCCommunication</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>RemoteManagement</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowBasicAuthentication_Client</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowBasicAuthentication_Service</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowCredSSPAuthenticationClient</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowCredSSPAuthenticationService</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowRemoteServerManagement</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowUnencryptedTraffic_Client</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowUnencryptedTraffic_Service</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisallowDigestAuthentication</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisallowNegotiateAuthenticationClient</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisallowNegotiateAuthenticationService</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisallowStoringOfRunAsCredentials</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SpecifyChannelBindingTokenHardeningLevel</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedHosts</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TurnOnCompatibilityHTTPListener</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TurnOnCompatibilityHTTPSListener</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>RemoteProcedureCall</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>RestrictUnauthenticatedRPCClients</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RPCEndpointMapperClientAuthentication</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>RemoteShell</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowRemoteShellAccess</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MaxConcurrentUsers</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SpecifyIdleTimeout</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SpecifyMaxMemory</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SpecifyMaxProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SpecifyMaxRemoteShells</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SpecifyShellTimeout</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>RestrictedGroups</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>ConfigureGroupMembership</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This security setting allows an administrator to define the members of a security-sensitive (restricted) group. When a Restricted Groups Policy is enforced, any current member of a restricted group that is not on the Members list is removed. Any user on the Members list who is not currently a member of the restricted group is added. You can use Restricted Groups policy to control group membership. Using the policy, you can specify what members are part of a group. Any members that are not specified in the policy are removed during configuration or refresh. For example, you can create a Restricted Groups policy to only allow specified users (for example, Alice and John) to be members of the Administrators group. When policy is refreshed, only Alice and John will remain as members of the Administrators group.
Caution: If a Restricted Groups policy is applied, any current member not on the Restricted Groups policy members list is removed. This can include default members, such as administrators. Restricted Groups should be used primarily to configure membership of local groups on workstation or member servers. An empty Members list means that the restricted group has no members.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Search</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowCloudSearch</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowCortanaInAAD</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This features allows you to show the cortana opt-in page during Windows Setup</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowIndexingEncryptedStoresOrItems</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSearchToUseLocation</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowStoringImagesFromVisionSearch</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowUsingDiacritics</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowWindowsIndexer</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AlwaysUseAutoLangDetection</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableBackoff</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableRemovableDriveIndexing</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DoNotUseWebResults</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventIndexingLowDiskSpaceMB</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventRemoteQueries</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SafeSearchPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Security</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowAddProvisioningPackage</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowManualRootCertificateInstallation</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowRemoveProvisioningPackage</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AntiTheftMode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ClearTPMIfNotReady</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConfigureWindowsPasswords</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Configures the use of passwords for Windows features</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventAutomaticDeviceEncryptionForAzureADJoinedDevices</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RequireDeviceEncryption</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RequireProvisioningPackageSignature</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RequireRetrieveHealthCertificateOnBoot</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Settings</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowAutoPlay</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowDataSense</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowDateTime</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowEditDeviceName</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLanguage</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowOnlineTips</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPowerSleep</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowRegion</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSignInOptions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowVPN</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowWorkplace</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowYourAccount</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PageVisibilityList</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>SmartScreen</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>EnableAppInstallControl</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableSmartScreenInShell</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventOverrideForFilesInShell</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Speech</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowSpeechModelUpdate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Start</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowPinnedFolderDocuments</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy controls the visibility of the Documents shortcut on the Start menu. The possible values are 0 - means that the shortcut should be hidden and grays out the corresponding toggle in the Settings app, 1 - means that the shortcut should be visible and grays out the corresponding toggle in the Settings app, 65535 - means that there is no enforced configuration and the setting can be changed by the user.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPinnedFolderDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy controls the visibility of the Downloads shortcut on the Start menu. The possible values are 0 - means that the shortcut should be hidden and grays out the corresponding toggle in the Settings app, 1 - means that the shortcut should be visible and grays out the corresponding toggle in the Settings app, 65535 - means that there is no enforced configuration and the setting can be changed by the user.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPinnedFolderFileExplorer</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy controls the visibility of the File Explorer shortcut on the Start menu. The possible values are 0 - means that the shortcut should be hidden and grays out the corresponding toggle in the Settings app, 1 - means that the shortcut should be visible and grays out the corresponding toggle in the Settings app, 65535 - means that there is no enforced configuration and the setting can be changed by the user.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPinnedFolderHomeGroup</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy controls the visibility of the HomeGroup shortcut on the Start menu. The possible values are 0 - means that the shortcut should be hidden and grays out the corresponding toggle in the Settings app, 1 - means that the shortcut should be visible and grays out the corresponding toggle in the Settings app, 65535 - means that there is no enforced configuration and the setting can be changed by the user.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPinnedFolderMusic</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy controls the visibility of the Music shortcut on the Start menu. The possible values are 0 - means that the shortcut should be hidden and grays out the corresponding toggle in the Settings app, 1 - means that the shortcut should be visible and grays out the corresponding toggle in the Settings app, 65535 - means that there is no enforced configuration and the setting can be changed by the user.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPinnedFolderNetwork</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy controls the visibility of the Network shortcut on the Start menu. The possible values are 0 - means that the shortcut should be hidden and grays out the corresponding toggle in the Settings app, 1 - means that the shortcut should be visible and grays out the corresponding toggle in the Settings app, 65535 - means that there is no enforced configuration and the setting can be changed by the user.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPinnedFolderPersonalFolder</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy controls the visibility of the PersonalFolder shortcut on the Start menu. The possible values are 0 - means that the shortcut should be hidden and grays out the corresponding toggle in the Settings app, 1 - means that the shortcut should be visible and grays out the corresponding toggle in the Settings app, 65535 - means that there is no enforced configuration and the setting can be changed by the user.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPinnedFolderPictures</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy controls the visibility of the Pictures shortcut on the Start menu. The possible values are 0 - means that the shortcut should be hidden and grays out the corresponding toggle in the Settings app, 1 - means that the shortcut should be visible and grays out the corresponding toggle in the Settings app, 65535 - means that there is no enforced configuration and the setting can be changed by the user.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPinnedFolderSettings</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy controls the visibility of the Settings shortcut on the Start menu. The possible values are 0 - means that the shortcut should be hidden and grays out the corresponding toggle in the Settings app, 1 - means that the shortcut should be visible and grays out the corresponding toggle in the Settings app, 65535 - means that there is no enforced configuration and the setting can be changed by the user.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPinnedFolderVideos</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy controls the visibility of the Videos shortcut on the Start menu. The possible values are 0 - means that the shortcut should be hidden and grays out the corresponding toggle in the Settings app, 1 - means that the shortcut should be visible and grays out the corresponding toggle in the Settings app, 65535 - means that there is no enforced configuration and the setting can be changed by the user.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableContextMenus</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Enabling this policy prevents context menus from being invoked in the Start Menu.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ForceStartSize</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideAppList</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Setting the value of this policy to 1 or 2 collapses the app list. Setting the value of this policy to 3 removes the app list entirely. Setting the value of this policy to 2 or 3 disables the corresponding toggle in the Settings app.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideChangeAccountSettings</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Enabling this policy hides "Change account settings" from appearing in the user tile in the start menu.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideFrequentlyUsedApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Enabling this policy hides the most used apps from appearing on the start menu and disables the corresponding toggle in the Settings app.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideHibernate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Enabling this policy hides "Hibernate" from appearing in the power button in the start menu.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideLock</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Enabling this policy hides "Lock" from appearing in the user tile in the start menu.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HidePowerButton</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Enabling this policy hides the power button from appearing in the start menu.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideRecentJumplists</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Enabling this policy hides recent jumplists from appearing on the start menu/taskbar and disables the corresponding toggle in the Settings app.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideRecentlyAddedApps</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Enabling this policy hides recently added apps from appearing on the start menu and disables the corresponding toggle in the Settings app.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideRestart</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Enabling this policy hides "Restart/Update and restart" from appearing in the power button in the start menu.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideShutDown</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Enabling this policy hides "Shut down/Update and shut down" from appearing in the power button in the start menu.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideSignOut</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Enabling this policy hides "Sign out" from appearing in the user tile in the start menu.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideSleep</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Enabling this policy hides "Sleep" from appearing in the power button in the start menu.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideSwitchAccount</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Enabling this policy hides "Switch account" from appearing in the user tile in the start menu.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideUserTile</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Enabling this policy hides the user tile from appearing in the start menu.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ImportEdgeAssets</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting allows you to import Edge assets to be used with StartLayout policy. Start layout can contain secondary tile from Edge app which looks for Edge local asset file. Edge local asset would not exist and cause Edge secondary tile to appear empty in this case. This policy only gets applied when StartLayout policy is modified.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NoPinningToTaskbar</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting allows you to control pinning programs to the Taskbar. If you enable this policy setting, users cannot change the programs currently pinned to the Taskbar. If any programs are already pinned to the Taskbar, these programs continue to show in the Taskbar. However, users cannot unpin these programs already pinned to the Taskbar, and they cannot pin new programs to the Taskbar. If you disable or do not configure this policy setting, users can change the programs currently pinned to the Taskbar.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>StartLayout</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Storage</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowDiskHealthModelUpdates</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnhancedStorageDevices</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>System</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowBuildPreview</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowEmbeddedMode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowExperimentation</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowFontProviders</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLocation</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowStorageCard</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowTelemetry</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowUserToResetPhone</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>BootStartDriverInitialization</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConfigureTelemetryOptInChangeNotification</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConfigureTelemetryOptInSettingsUx</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableEnterpriseAuthProxy</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting blocks the Connected User Experience and Telemetry service from automatically using an authenticated proxy to send data back to Microsoft on Windows 10. If you disable or do not configure this policy setting, the Connected User Experience and Telemetry service will automatically use an authenticated proxy to send data back to Microsoft. Enabling this policy will block the Connected User Experience and Telemetry service from automatically using an authenticated proxy.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableOneDriveFileSync</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting lets you prevent apps and features from working with files on OneDrive. If you enable this policy setting: users cant access OneDrive from the OneDrive app and file picker; Microsoft Store apps cant access OneDrive using the WinRT API; OneDrive doesnt appear in the navigation pane in File Explorer; OneDrive files arent kept in sync with the cloud; Users cant automatically upload photos and videos from the camera roll folder. If you disable or do not configure this policy setting, apps and features can work with OneDrive file storage.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableSystemRestore</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>FeedbackHubAlwaysSaveDiagnosticsLocally</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Diagnostic files created when a feedback is filed in the Feedback Hub app will always be saved locally. If this policy is not present or set to false, users will be presented with the option to save locally. The default is to not save locally.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LimitEnhancedDiagnosticDataWindowsAnalytics</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting, in combination with the Allow Telemetry policy setting, enables organizations to send Microsoft a specific set of diagnostic data for IT insights via Windows Analytics services. By configuring this setting, you're not stopping people from changing their Telemetry Settings; however, you are stopping them from choosing a higher level than you've set for the organization. To enable this behavior, you must complete two steps: 1. Enable this policy setting 2. Set Allow Telemetry to level 2 (Enhanced).If you configure these policy settings together, you'll send the Basic level of diagnostic data plus any additional events that are required for Windows Analytics, to Microsoft. The additional events are documented here: https://go.Microsoft.com/fwlink/?linked=847594. If you enable Enhanced diagnostic data in the Allow Telemetry policy setting, but you don't configure this policy setting, you'll send the required events for Windows Analytics, plus any additional Enhanced level telemetry data to Microsoft. This setting has no effect on computers configured to send Full, Basic, or Security level diagnostic data to Microsoft. If you disable or don't configure this policy setting, then the level of diagnostic data sent to Microsoft is determined by the Allow Telemetry policy setting.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TelemetryProxy</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>SystemServices</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>ConfigureHomeGroupListenerServiceStartupMode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting determines whether the service's start type is Automaic(2), Manual(3), Disabled(4). Default: Manual.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConfigureHomeGroupProviderServiceStartupMode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting determines whether the service's start type is Automaic(2), Manual(3), Disabled(4). Default: Manual.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConfigureXboxAccessoryManagementServiceStartupMode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting determines whether the service's start type is Automaic(2), Manual(3), Disabled(4). Default: Manual.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConfigureXboxLiveAuthManagerServiceStartupMode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting determines whether the service's start type is Automaic(2), Manual(3), Disabled(4). Default: Manual.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConfigureXboxLiveGameSaveServiceStartupMode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting determines whether the service's start type is Automaic(2), Manual(3), Disabled(4). Default: Manual.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConfigureXboxLiveNetworkingServiceStartupMode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting determines whether the service's start type is Automaic(2), Manual(3), Disabled(4). Default: Manual.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>TaskScheduler</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>EnableXboxGameSaveTask</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This setting determines whether the specific task is enabled (1) or disabled (0). Default: Enabled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>TextInput</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowHardwareKeyboardTextSuggestions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowIMELogging</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowIMENetworkAccess</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowInputPanel</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowJapaneseIMESurrogatePairCharacters</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowJapaneseIVSCharacters</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowJapaneseNonPublishingStandardGlyph</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowJapaneseUserDictionary</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowKeyboardTextSuggestions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLanguageFeaturesUninstall</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLinguisticDataCollection</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableTouchKeyboardAutoInvokeInDesktopMode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ExcludeJapaneseIMEExceptJIS0208</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ExcludeJapaneseIMEExceptJIS0208andEUDC</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ExcludeJapaneseIMEExceptShiftJIS</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ForceTouchKeyboardDockedState</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TouchKeyboardDictationButtonAvailability</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TouchKeyboardEmojiButtonAvailability</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TouchKeyboardFullModeAvailability</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TouchKeyboardHandwritingModeAvailability</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TouchKeyboardNarrowModeAvailability</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TouchKeyboardSplitModeAvailability</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TouchKeyboardWideModeAvailability</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>TimeLanguageSettings</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowSet24HourClock</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Update</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>ActiveHoursEnd</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ActiveHoursMaxRange</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ActiveHoursStart</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowAutoUpdate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowAutoWindowsUpdateDownloadOverMeteredNetwork</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowMUUpdateService</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowNonMicrosoftSignedUpdate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowUpdateService</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AutoRestartDeadlinePeriodInDays</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AutoRestartNotificationSchedule</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AutoRestartRequiredNotificationDismissal</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>BranchReadinessLevel</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConfigureFeatureUpdateUninstallPeriod</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Enable enterprises/IT admin to configure feature update uninstall period</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DeferFeatureUpdatesPeriodInDays</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DeferQualityUpdatesPeriodInDays</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DeferUpdatePeriod</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DeferUpgradePeriod</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DetectionFrequency</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableDualScan</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Do not allow update deferral policies to cause scans against Windows Update</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EngagedRestartDeadline</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EngagedRestartSnoozeSchedule</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EngagedRestartTransitionSchedule</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ExcludeWUDriversInQualityUpdate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>FillEmptyContentUrls</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IgnoreMOAppDownloadLimit</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IgnoreMOUpdateDownloadLimit</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ManagePreviewBuilds</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PauseDeferrals</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PauseFeatureUpdates</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PauseFeatureUpdatesStartTime</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PauseQualityUpdates</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PauseQualityUpdatesStartTime</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PhoneUpdateRestrictions</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RequireDeferUpgrade</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RequireUpdateApproval</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScheduledInstallDay</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScheduledInstallEveryWeek</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScheduledInstallFirstWeek</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScheduledInstallFourthWeek</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScheduledInstallSecondWeek</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScheduledInstallThirdWeek</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScheduledInstallTime</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScheduleImminentRestartWarning</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScheduleRestartWarning</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SetAutoRestartNotificationDisable</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SetEDURestart</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UpdateServiceUrl</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UpdateServiceUrlAlternate</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>UserRights</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AccessCredentialManagerAsTrustedCaller</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This user right is used by Credential Manager during Backup/Restore. No accounts should have this privilege, as it is only assigned to Winlogon. Users' saved credentials might be compromised if this privilege is given to other entities.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AccessFromNetwork</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This user right determines which users and groups are allowed to connect to the computer over the network. Remote Desktop Services are not affected by this user right.Note: Remote Desktop Services was called Terminal Services in previous versions of Windows Server.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ActAsPartOfTheOperatingSystem</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This user right allows a process to impersonate any user without authentication. The process can therefore gain access to the same local resources as that user. Processes that require this privilege should use the LocalSystem account, which already includes this privilege, rather than using a separate user account with this privilege specially assigned. Caution:Assigning this user right can be a security risk. Only assign this user right to trusted users.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLocalLogOn</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This user right determines which users can log on to the computer. Note: Modifying this setting may affect compatibility with clients, services, and applications. For compatibility information about this setting, see Allow log on locally (https://go.microsoft.com/fwlink/?LinkId=24268 ) at the Microsoft website. </Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>BackupFilesAndDirectories</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This user right determines which users can bypass file, directory, registry, and other persistent objects permissions when backing up files and directories.Specifically, this user right is similar to granting the following permissions to the user or group in question on all files and folders on the system:Traverse Folder/Execute File, Read. Caution: Assigning this user right can be a security risk. Since users with this user right can read any registry settings and files, only assign this user right to trusted users</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ChangeSystemTime</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This user right determines which users and groups can change the time and date on the internal clock of the computer. Users that are assigned this user right can affect the appearance of event logs. If the system time is changed, events that are logged will reflect this new time, not the actual time that the events occurred.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>CreateGlobalObjects</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This security setting determines whether users can create global objects that are available to all sessions. Users can still create objects that are specific to their own session if they do not have this user right. Users who can create global objects could affect processes that run under other users' sessions, which could lead to application failure or data corruption. Caution: Assigning this user right can be a security risk. Assign this user right only to trusted users.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>CreatePageFile</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This user right determines which users and groups can call an internal application programming interface (API) to create and change the size of a page file. This user right is used internally by the operating system and usually does not need to be assigned to any users</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>CreatePermanentSharedObjects</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This user right determines which accounts can be used by processes to create a directory object using the object manager. This user right is used internally by the operating system and is useful to kernel-mode components that extend the object namespace. Because components that are running in kernel mode already have this user right assigned to them, it is not necessary to specifically assign it.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>CreateSymbolicLinks</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This user right determines if the user can create a symbolic link from the computer he is logged on to. Caution: This privilege should only be given to trusted users. Symbolic links can expose security vulnerabilities in applications that aren't designed to handle them. Note: This setting can be used in conjunction a symlink filesystem setting that can be manipulated with the command line utility to control the kinds of symlinks that are allowed on the machine. Type 'fsutil behavior set symlinkevaluation /?' at the command line to get more information about fsutil and symbolic links.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>CreateToken</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This user right determines which accounts can be used by processes to create a token that can then be used to get access to any local resources when the process uses an internal application programming interface (API) to create an access token. This user right is used internally by the operating system. Unless it is necessary, do not assign this user right to a user, group, or process other than Local System. Caution: Assigning this user right can be a security risk. Do not assign this user right to any user, group, or process that you do not want to take over the system.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DebugPrograms</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This user right determines which users can attach a debugger to any process or to the kernel. Developers who are debugging their own applications do not need to be assigned this user right. Developers who are debugging new system components will need this user right to be able to do so. This user right provides complete access to sensitive and critical operating system components. Caution:Assigning this user right can be a security risk. Only assign this user right to trusted users.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DenyAccessFromNetwork</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This user right determines which users are prevented from accessing a computer over the network. This policy setting supersedes the Access this computer from the network policy setting if a user account is subject to both policies.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DenyLocalLogOn</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This security setting determines which service accounts are prevented from registering a process as a service. Note: This security setting does not apply to the System, Local Service, or Network Service accounts.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DenyRemoteDesktopServicesLogOn</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This user right determines which users and groups are prohibited from logging on as a Remote Desktop Services client.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableDelegation</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This user right determines which users can set the Trusted for Delegation setting on a user or computer object. The user or object that is granted this privilege must have write access to the account control flags on the user or computer object. A server process running on a computer (or under a user context) that is trusted for delegation can access resources on another computer using delegated credentials of a client, as long as the client account does not have the Account cannot be delegated account control flag set. Caution: Misuse of this user right, or of the Trusted for Delegation setting, could make the network vulnerable to sophisticated attacks using Trojan horse programs that impersonate incoming clients and use their credentials to gain access to network resources.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>GenerateSecurityAudits</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This user right determines which accounts can be used by a process to add entries to the security log. The security log is used to trace unauthorized system access. Misuse of this user right can result in the generation of many auditing events, potentially hiding evidence of an attack or causing a denial of service. Shut down system immediately if unable to log security audits security policy setting is enabled.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ImpersonateClient</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>Assigning this user right to a user allows programs running on behalf of that user to impersonate a client. Requiring this user right for this kind of impersonation prevents an unauthorized user from convincing a client to connect (for example, by remote procedure call (RPC) or named pipes) to a service that they have created and then impersonating that client, which can elevate the unauthorized user's permissions to administrative or system levels. Caution: Assigning this user right can be a security risk. Only assign this user right to trusted users. Note: By default, services that are started by the Service Control Manager have the built-in Service group added to their access tokens. Component Object Model (COM) servers that are started by the COM infrastructure and that are configured to run under a specific account also have the Service group added to their access tokens. As a result, these services get this user right when they are started. In addition, a user can also impersonate an access token if any of the following conditions exist. 
1) The access token that is being impersonated is for this user.
2) The user, in this logon session, created the access token by logging on to the network with explicit credentials.
3) The requested level is less than Impersonate, such as Anonymous or Identify.
Because of these factors, users do not usually need this user right. Warning: If you enable this setting, programs that previously had the Impersonate privilege may lose it, and they may not run.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IncreaseSchedulingPriority</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This user right determines which accounts can use a process with Write Property access to another process to increase the execution priority assigned to the other process. A user with this privilege can change the scheduling priority of a process through the Task Manager user interface.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LoadUnloadDeviceDrivers</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This user right determines which users can dynamically load and unload device drivers or other code in to kernel mode. This user right does not apply to Plug and Play device drivers. It is recommended that you do not assign this privilege to other users. Caution: Assigning this user right can be a security risk. Do not assign this user right to any user, group, or process that you do not want to take over the system.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockMemory</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This user right determines which accounts can use a process to keep data in physical memory, which prevents the system from paging the data to virtual memory on disk. Exercising this privilege could significantly affect system performance by decreasing the amount of available random access memory (RAM).</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ManageAuditingAndSecurityLog</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This user right determines which users can specify object access auditing options for individual resources, such as files, Active Directory objects, and registry keys. This security setting does not allow a user to enable file and object access auditing in general. You can view audited events in the security log of the Event Viewer. A user with this privilege can also view and clear the security log.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ManageVolume</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This user right determines which users and groups can run maintenance tasks on a volume, such as remote defragmentation. Use caution when assigning this user right. Users with this user right can explore disks and extend files in to memory that contains other data. When the extended files are opened, the user might be able to read and modify the acquired data.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ModifyFirmwareEnvironment</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This user right determines who can modify firmware environment values. Firmware environment variables are settings stored in the nonvolatile RAM of non-x86-based computers. The effect of the setting depends on the processor.On x86-based computers, the only firmware environment value that can be modified by assigning this user right is the Last Known Good Configuration setting, which should only be modified by the system. On Itanium-based computers, boot information is stored in nonvolatile RAM. Users must be assigned this user right to run bootcfg.exe and to change the Default Operating System setting on Startup and Recovery in System Properties. On all computers, this user right is required to install or upgrade Windows.Note: This security setting does not affect who can modify the system environment variables and user environment variables that are displayed on the Advanced tab of System Properties.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ModifyObjectLabel</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This user right determines which user accounts can modify the integrity label of objects, such as files, registry keys, or processes owned by other users. Processes running under a user account can modify the label of an object owned by that user to a lower level without this privilege.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ProfileSingleProcess</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This user right determines which users can use performance monitoring tools to monitor the performance of system processes.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RemoteShutdown</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This user right determines which users are allowed to shut down a computer from a remote location on the network. Misuse of this user right can result in a denial of service.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestoreFilesAndDirectories</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This user right determines which users can bypass file, directory, registry, and other persistent objects permissions when restoring backed up files and directories, and determines which users can set any valid security principal as the owner of an object. Specifically, this user right is similar to granting the following permissions to the user or group in question on all files and folders on the system:Traverse Folder/Execute File, Write. Caution: Assigning this user right can be a security risk. Since users with this user right can overwrite registry settings, hide data, and gain ownership of system objects, only assign this user right to trusted users.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TakeOwnership</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This user right determines which users can take ownership of any securable object in the system, including Active Directory objects, files and folders, printers, registry keys, processes, and threads. Caution: Assigning this user right can be a security risk. Since owners of objects have full control of them, only assign this user right to trusted users.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Wifi</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowAutoConnectToWiFiSenseHotspots</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowInternetSharing</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowManualWiFiConfiguration</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowWiFi</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowWiFiDirect</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>WLANScanMode</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>WindowsConnectionManager</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>ProhitConnectionToNonDomainNetworksWhenConnectedToDomainAuthenticatedNetwork</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>WindowsDefenderSecurityCenter</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>CompanyName</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableAccountProtectionUI</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableAppBrowserUI</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableDeviceSecurityUI</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableEnhancedNotifications</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableFamilyUI</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableHealthUI</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableNetworkUI</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableNotifications</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableVirusUI</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisallowExploitProtectionOverride</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>Email</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableCustomizedToasts</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableInAppCustomization</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideRansomwareDataRecovery</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideSecureBoot</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideTPMTroubleshooting</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>Phone</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>URL</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>WindowsInkWorkspace</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowSuggestedAppsInWindowsInkWorkspace</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowWindowsInkWorkspace</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>WindowsLogon</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>DisableLockScreenAppNotifications</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DontDisplayNetworkSelectionUI</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnumerateLocalUsersOnDomainJoinedComputers</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideFastUserSwitching</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting allows you to hide the Switch User interface in the Logon UI, the Start menu and the Task Manager. If you enable this policy setting, the Switch User interface is hidden from the user who is attempting to log on or is logged on to the computer that has this policy applied. The locations that Switch User interface appear are in the Logon UI, the Start menu and the Task Manager. If you disable or do not configure this policy setting, the Switch User interface is accessible to the user in the three locations.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SignInLastInteractiveUserAutomaticallyAfterASystemInitiatedRestart</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>WindowsPowerShell</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>TurnOnPowerShellScriptBlockLogging</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>WirelessDisplay</NodeName>
        <DFProperties>
          <AccessType>
            <Add />
            <Delete />
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <ZeroOrOne />
          </Occurrence>
          <Scope>
            <Dynamic />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowMdnsAdvertisement</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting allows you to turn off the Wireless Display multicast DNS service advertisement from a Wireless Display receiver.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowMdnsDiscovery</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting allows you to turn off discovering the display service advertised over multicast DNS by a Wireless Display receiver.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowProjectionFromPC</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy allows you to turn off projection from a PC.
                            If you set it to 0, your PC cannot discover or project to other devices.
                            If you set it to 1, your PC can discover and project to other devices.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowProjectionFromPCOverInfrastructure</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy allows you to turn off projection from a PC over infrastructure.
                            If you set it to 0, your PC cannot discover or project to other infrastructure devices, though it may still be possible to discover and project over WiFi Direct.
                            If you set it to 1, your PC can discover and project to other devices over infrastructure.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowProjectionToPC</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting allows you to turn off projection to a PC
                            If you set it to 0, your PC isn't discoverable and can't be projected to
                            If you set it to 1, your PC is discoverable and can be projected to above the lock screen only. The user has an option to turn it always on or off except for manual launch, too.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowProjectionToPCOverInfrastructure</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting allows you to turn off projection to a PC over infrastructure.
                            If you set it to 0, your PC cannot be discoverable and can't be projected to over infrastructure, though it may still be possible to project over WiFi Direct.
                            If you set it to 1, your PC can be discoverable and can be projected to over infrastructure.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowUserInputFromWirelessDisplayReceiver</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RequirePinForPairing</NodeName>
          <DFProperties>
            <AccessType>
              <Add />
              <Delete />
              <Get />
              <Replace />
            </AccessType>
            <Description>This policy setting allows you to require a pin for pairing.
                            If you turn this on, the pairing ceremony for new devices will always require a PIN
                            If you turn it off or don't configure it, a pin isn't required for pairing.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <ZeroOrOne />
            </Occurrence>
            <Scope>
              <Dynamic />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
          </DFProperties>
        </Node>
      </Node>
    </Node>
    <Node>
      <NodeName>Result</NodeName>
      <DFProperties>
        <AccessType>
          <Get />
        </AccessType>
        <DFFormat>
          <node />
        </DFFormat>
        <Occurrence>
          <One />
        </Occurrence>
        <Scope>
          <Permanent />
        </Scope>
        <DFType>
          <DDFName></DDFName>
        </DFType>
      </DFProperties>
      <Node>
        <NodeName>AboveLock</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowActionCenterNotifications</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>desktop</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowCortanaAboveLock</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>Search.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>Search~AT~WindowsComponents~Search</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowCortanaAboveLock</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowToasts</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Accounts</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowAddingNonMicrosoftAccountsManually</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowMicrosoftAccountConnection</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowMicrosoftAccountSignInAssistant</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="0,1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DomainNamesForEmailSync</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>ActiveXControls</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>ApprovedInstallationSites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>ActiveXInstallService.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>ActiveXInstallService~AT~WindowsComponents~AxInstSv</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ApprovedActiveXInstallSites</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>ApplicationDefaults</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>DefaultAssociationsConfiguration</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsExplorer.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>DefaultAssociationsConfiguration_TextBox</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsExplorer~AT~WindowsComponents~WindowsExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DefaultAssociationsConfiguration</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableAppUriHandlers</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>Enables web-to-app linking, which allows apps to be launched with a http(s) URI</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>GroupPolicy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>GroupPolicy~AT~System~PolicyPolicies</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>EnableAppUriHandlers</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>ApplicationManagement</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowAllTrustedApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>65535</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="0,1,65535"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>AppxPackageManager.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>AppxPackageManager~AT~WindowsComponents~AppxDeployment</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AppxDeploymentAllowAllTrustedApps</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowAppStoreAutoUpdate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>2</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsStore.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsStore~AT~WindowsComponents~WindowsStore</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableAutoInstall</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowDeveloperUnlock</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>65535</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="0,1,65535"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>AppxPackageManager.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>AppxPackageManager~AT~WindowsComponents~AppxDeployment</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowDevelopmentWithoutDevLicense</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowGameDVR</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>GameDVR.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>GameDVR~AT~WindowsComponents~GAMEDVR</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowGameDVR</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSharedUserAppData</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>AppxPackageManager.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>AppxPackageManager~AT~WindowsComponents~AppxDeployment</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowSharedLocalAppData</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowStore</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>desktop</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ApplicationRestrictions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>desktop</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableStoreOriginatedApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsStore.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsStore~AT~WindowsComponents~WindowsStore</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableStoreApps</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MSIAllowUserControlOverInstall</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MSI.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MSI~AT~WindowsComponents~MSI</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>EnableUserControl</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MSIAlwaysInstallWithElevatedPrivileges</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MSI.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MSI~AT~WindowsComponents~MSI</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AlwaysInstallElevated</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RequirePrivateStoreOnly</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsStore.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsStore~AT~WindowsComponents~WindowsStore</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>RequirePrivateStoreOnly</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictAppDataToSystemVolume</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>AppxPackageManager.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>AppxPackageManager~AT~WindowsComponents~AppxDeployment</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>RestrictAppDataToSystemVolume</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictAppToSystemVolume</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>AppxPackageManager.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>AppxPackageManager~AT~WindowsComponents~AppxDeployment</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableDeploymentToNonSystemVolumes</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>AppRuntime</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowMicrosoftAccountsToBeOptional</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>AppXRuntime.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>AppXRuntime~AT~WindowsComponents~AppXRuntime</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AppxRuntimeMicrosoftAccountsOptional</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>AppVirtualization</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowAppVClient</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>appv.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>appv~AT~System~CAT_AppV</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>EnableAppV</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowDynamicVirtualization</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>appv.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>appv~AT~System~CAT_AppV~CAT_Virtualization</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Virtualization_JITVEnable</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPackageCleanup</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>appv.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>appv~AT~System~CAT_AppV~CAT_PackageManagement</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>PackageManagement_AutoCleanupEnable</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPackageScripts</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>appv.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>appv~AT~System~CAT_AppV~CAT_Scripting</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Scripting_Enable_Package_Scripts</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPublishingRefreshUX</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>appv.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>appv~AT~System~CAT_AppV~CAT_Publishing</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Enable_Publishing_Refresh_UX</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowReportingServer</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>appv.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>appv~AT~System~CAT_AppV~CAT_Reporting</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Reporting_Server_Policy</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowRoamingFileExclusions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>appv.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>appv~AT~System~CAT_AppV~CAT_Integration</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Integration_Roaming_File_Exclusions</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowRoamingRegistryExclusions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>appv.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>appv~AT~System~CAT_AppV~CAT_Integration</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Integration_Roaming_Registry_Exclusions</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowStreamingAutoload</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>appv.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>appv~AT~System~CAT_AppV~CAT_Streaming</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Steaming_Autoload</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ClientCoexistenceAllowMigrationmode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>appv.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>appv~AT~System~CAT_AppV~CAT_Client_Coexistence</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Client_Coexistence_Enable_Migration_mode</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntegrationAllowRootGlobal</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>appv.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>appv~AT~System~CAT_AppV~CAT_Integration</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Integration_Root_User</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntegrationAllowRootUser</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>appv.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>appv~AT~System~CAT_AppV~CAT_Integration</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Integration_Root_Global</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PublishingAllowServer1</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>appv.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>appv~AT~System~CAT_AppV~CAT_Publishing</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Publishing_Server1_Policy</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PublishingAllowServer2</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>appv.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>appv~AT~System~CAT_AppV~CAT_Publishing</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Publishing_Server2_Policy</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PublishingAllowServer3</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>appv.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>appv~AT~System~CAT_AppV~CAT_Publishing</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Publishing_Server3_Policy</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PublishingAllowServer4</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>appv.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>appv~AT~System~CAT_AppV~CAT_Publishing</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Publishing_Server4_Policy</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PublishingAllowServer5</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>appv.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>appv~AT~System~CAT_AppV~CAT_Publishing</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Publishing_Server5_Policy</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>StreamingAllowCertificateFilterForClient_SSL</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>appv.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>appv~AT~System~CAT_AppV~CAT_Streaming</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Streaming_Certificate_Filter_For_Client_SSL</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>StreamingAllowHighCostLaunch</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>appv.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>appv~AT~System~CAT_AppV~CAT_Streaming</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Streaming_Allow_High_Cost_Launch</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>StreamingAllowLocationProvider</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>appv.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>appv~AT~System~CAT_AppV~CAT_Streaming</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Streaming_Location_Provider</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>StreamingAllowPackageInstallationRoot</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>appv.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>appv~AT~System~CAT_AppV~CAT_Streaming</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Streaming_Package_Installation_Root</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>StreamingAllowPackageSourceRoot</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>appv.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>appv~AT~System~CAT_AppV~CAT_Streaming</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Streaming_Package_Source_Root</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>StreamingAllowReestablishmentInterval</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>appv.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>appv~AT~System~CAT_AppV~CAT_Streaming</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Streaming_Reestablishment_Interval</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>StreamingAllowReestablishmentRetries</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>appv.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>appv~AT~System~CAT_AppV~CAT_Streaming</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Streaming_Reestablishment_Retries</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>StreamingSharedContentStoreMode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>appv.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>appv~AT~System~CAT_AppV~CAT_Streaming</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Streaming_Shared_Content_Store_Mode</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>StreamingSupportBranchCache</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>appv.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>appv~AT~System~CAT_AppV~CAT_Streaming</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Streaming_Support_Branch_Cache</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>StreamingVerifyCertificateRevocationList</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>appv.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>appv~AT~System~CAT_AppV~CAT_Streaming</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Streaming_Verify_Certificate_Revocation_List</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>VirtualComponentsAllowList</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>appv.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>appv~AT~System~CAT_AppV~CAT_Virtualization</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Virtualization_JITVAllowList</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Authentication</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowAadPasswordReset</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Specifies whether password reset is enabled for AAD accounts.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowFastReconnect</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSecondaryAuthenticationDevice</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>DeviceCredential.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>DeviceCredential~AT~WindowsComponents~MSSecondaryAuthFactorCategory</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>MSSecondaryAuthFactor_AllowSecondaryAuthenticationDevice</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Autoplay</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>DisallowAutoplayForNonVolumeDevices</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>AutoPlay.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>AutoPlay~AT~WindowsComponents~AutoPlay</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>NoAutoplayfornonVolume</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SetDefaultAutoRunBehavior</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>AutoPlay.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>AutoPlay~AT~WindowsComponents~AutoPlay</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>NoAutorun</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TurnOffAutoPlay</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>AutoPlay.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>AutoPlay~AT~WindowsComponents~AutoPlay</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Autorun</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Bitlocker</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>EncryptionMethod</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>6</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="3,4,6,7"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Bluetooth</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowAdvertising</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowDiscoverableMode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPrepairing</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPromptedProximalConnections</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalDeviceName</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ServicesAllowedList</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Browser</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowAddressBarDropdown</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This policy setting lets you decide whether the Address bar drop-down functionality is available in Microsoft Edge. We recommend disabling this setting if you want to minimize network connections from Microsoft Edge to Microsoft services.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowAddressBarDropdown</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowAutofill</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This setting lets you decide whether employees can use Autofill to automatically fill in form fields while using Microsoft Edge.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowAutofill</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowBrowser</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>desktop</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowConfigurationUpdateForBooksLibrary</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This policy setting lets you decide whether Microsoft Edge can automatically update the configuration data for the Books Library.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowCookies</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>2</DefaultValue>
            <Description>This setting lets you configure how your company deals with cookies.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>CookiesListBox</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Cookies</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowDeveloperTools</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This setting lets you decide whether employees can use F12 Developer Tools on Microsoft Edge.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowDeveloperTools</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowDoNotTrack</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This setting lets you decide whether employees can send Do Not Track headers to websites that request tracking info.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowDoNotTrack</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowExtensions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This setting lets you decide whether employees can load extensions in Microsoft Edge.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowExtensions</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowFlash</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This setting lets you decide whether employees can run Adobe Flash in Microsoft Edge.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowFlash</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowFlashClickToRun</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>Configure the Adobe Flash Click-to-Run setting.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowFlashClickToRun</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowInPrivate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This setting lets you decide whether employees can browse using InPrivate website browsing.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowInPrivate</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowMicrosoftCompatibilityList</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This policy setting lets you decide whether the Microsoft Compatibility List is enabled or disabled in Microsoft Edge. This feature uses a Microsoft-provided list to ensure that any sites with known compatibility issues are displayed correctly when a user navigates to them. By default, the Microsoft Compatibility List is enabled and can be viewed by navigating to about:compat.

If you enable or dont configure this setting, Microsoft Edge will periodically download the latest version of the list from Microsoft and will apply the configurations specified there during browser navigation. If a user visits a site on the Microsoft Compatibility List, he or she will be prompted to open the site in Internet Explorer 11. Once in Internet Explorer, the site will automatically be rendered as if the user is viewing it in the previous version of Internet Explorer it requires to display correctly.

If you disable this setting, the Microsoft Compatibility List will not be used during browser navigation.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowCVList</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPasswordManager</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This setting lets you decide whether employees can save their passwords locally, using Password Manager.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowPasswordManager</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPopups</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This setting lets you decide whether to turn on Pop-up Blocker and whether to allow pop-ups to appear in secondary windows.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowPopups</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSearchEngineCustomization</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>Allow search engine customization for MDM enrolled devices. Users can change their default search engine.

If this setting is turned on or not configured, users can add new search engines and change the default used in the address bar from within Microsoft Edge Settings.
If this setting is disabled, users will be unable to add search engines or change the default used in the address bar.

This policy will only apply on domain joined machines or when the device is MDM enrolled. For more information, see Microsoft browser extension policy (aka.ms/browserpolicy).</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowSearchEngineCustomization</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSearchSuggestionsinAddressBar</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This setting lets you decide whether search suggestions should appear in the Address bar of Microsoft Edge.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowSearchSuggestionsinAddressBar</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSmartScreen</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This setting lets you decide whether to turn on Windows Defender SmartScreen.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowSmartScreen</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AlwaysEnableBooksLibrary</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Specifies whether the Books Library in Microsoft Edge will always be visible regardless of the country or region setting for the device.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AlwaysEnableBooksLibrary</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ClearBrowsingDataOnExit</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Specifies whether to always clear browsing history on exiting Microsoft Edge.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowClearingBrowsingDataOnExit</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConfigureAdditionalSearchEngines</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>Allows you to add up to 5 additional search engines for MDM-enrolled devices.

If this setting is turned on, you can add up to 5 additional search engines for your employee. For each additional search engine you wish to add, you must specify a link to the OpenSearch XML file that contains, at minimum, the short name and the URL to the search engine. This policy does not affect the default search engine. Employees will not be able to remove these search engines, but they can set any one of these as the default.

If this setting is not configured, the search engines are the ones specified in the App settings. If this setting is disabled, the search engines you had added will be deleted from your employee's machine.

Due to Protected Settings (aka.ms/browserpolicy), this policy will only apply on domain-joined machines or when the device is MDM-enrolled.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>ConfigureAdditionalSearchEngines_Prompt</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ConfigureAdditionalSearchEngines</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableLockdownOfStartPages</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Boolean policy that specifies whether the lockdown on the Start pages is disabled. This policy works with the Browser/HomePages policy, which locks down the Start pages that the users cannot modify. You can use the DisableLockdownOfStartPages policy to allow users to modify the Start pages when Browser/HomePages policy is in effect.

Note: This policy has no effect when Browser/HomePages is not configured.

Important
This setting can only be used with domain-joined or MDM-enrolled devices. For more info, see the Microsoft browser extension policy (aka.ms/browserpolicy).</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableLockdownOfStartPages</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableExtendedBooksTelemetry</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This setting allows organizations to send extended telemetry on book usage from the Books Library.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>EnableExtendedBooksTelemetry</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnterpriseModeSiteList</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This setting lets you configure whether your company uses Enterprise Mode and the Enterprise Mode Site List to address common compatibility problems with legacy websites.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>EnterSiteListPrompt</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>EnterpriseModeSiteList</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnterpriseSiteListServiceUrl</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>FirstRunURL</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>Configure first run URL.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>desktop</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HomePages</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>Configure the Start page URLs for your employees.
Example:
If you wanted to allow contoso.com and fabrikam.com then you would append /support to the site strings like contoso.com/support and fabrikam.com/support.
Encapsulate each string with greater than and less than characters like any other XML tag.

Version 1703 or later: If you don't want to send traffic to Microsoft, you can use the about:blank value (encapsulate with greater than and less than characters like any other XML tag), which is honored for both domain- and non-domain-joined machines, when it's the only configured URL.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>HomePagesPrompt</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>HomePages</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockdownFavorites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy setting lets you decide whether employees can add, import, sort, or edit the Favorites list on Microsoft Edge.

If you enable this setting, employees won't be able to add, import, or change anything in the Favorites list. Also as part of this, Save a Favorite, Import settings, and the context menu items (such as, Create a new folder) are all turned off.

Important
Don't enable both this setting and the Keep favorites in sync between Internet Explorer and Microsoft Edge setting. Enabling both settings stops employees from syncing their favorites between Internet Explorer and Microsoft Edge.

If you disable or don't configure this setting (default), employees can add, import and make changes to the Favorites list.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LockdownFavorites</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventAccessToAboutFlagsInMicrosoftEdge</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Prevent access to the about:flags page in Microsoft Edge.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>PreventAccessToAboutFlagsInMicrosoftEdge</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventFirstRunPage</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Specifies whether the First Run webpage is prevented from automatically opening on the first launch of Microsoft Edge. This policy is only available for Windows 10 version 1703 or later for desktop.

Due to Protected Settings (aka.ms/browserpolicy), this policy will only apply on domain-joined machines or when the device is MDM-enrolled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>PreventFirstRunPage</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventLiveTileDataCollection</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy lets you decide whether Microsoft Edge can gather Live Tile metadata from the ieonline.microsoft.com service to provide a better experience while pinning a Live Tile to the Start menu.

Due to Protected Settings (aka.ms/browserpolicy), this policy will only apply on domain-joined machines or when the device is MDM-enrolled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>PreventLiveTileDataCollection</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventSmartScreenPromptOverride</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Don't allow Windows Defender SmartScreen warning overrides</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>PreventSmartScreenPromptOverride</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventSmartScreenPromptOverrideForFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Don't allow Windows Defender SmartScreen warning overrides for unverified files.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>PreventSmartScreenPromptOverrideForFiles</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventTabPreloading</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Prevent Microsoft Edge from starting and loading the Start and New Tab page at Windows startup and each time Microsoft Edge is closed.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>PreventTabPreloading</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventUsingLocalHostIPAddressForWebRTC</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Prevent using localhost IP address for WebRTC</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>HideLocalHostIPAddress</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ProvisionFavorites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This policy setting allows you to configure a default set of favorites, which will appear for employees. Employees cannot modify, sort, move, export or delete these provisioned favorites.

If you enable this setting, you can set favorite URL's and favorite folders to appear on top of users' favorites list (either in the Hub or Favorites Bar). The user favorites will appear after these provisioned favorites.

Important
Don't enable both this setting and the Keep favorites in sync between Internet Explorer and Microsoft Edge setting. Enabling both settings stops employees from syncing their favorites between Internet Explorer and Microsoft Edge.

If you disable or don't configure this setting, employees will see the favorites they set in the Hub and Favorites Bar.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>ConfiguredFavoritesPrompt</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ConfiguredFavorites</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SendIntranetTraffictoInternetExplorer</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Sends all intranet traffic over to Internet Explorer.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>SendIntranetTraffictoInternetExplorer</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SetDefaultSearchEngine</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>Sets the default search engine for MDM-enrolled devices. Users can still change their default search engine.

If this setting is turned on, you are setting the default search engine that you would like your employees to use. Employees can still change the default search engine, unless you apply the AllowSearchEngineCustomization policy which will disable the ability to change it. You must specify a link to the OpenSearch XML file that contains, at minimum, the short name and the URL to the search engine. If you would like for your employees to use the Edge factory settings for the default search engine for their market, set the string EDGEDEFAULT; if you would like for your employees to use Bing as the default search engine, set the string EDGEBING.

If this setting is not configured, the default search engine is set to the one specified in App settings and can be changed by your employees.  If this setting is disabled, the policy-set search engine will be removed, and, if it is the current default, the default will be set back to the factory Microsoft Edge search engine for the market.

Due to Protected Settings (aka.ms/browserpolicy), this policy will only apply on domain-joined machines or when the device is MDM-enrolled.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>SetDefaultSearchEngine_Prompt</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>SetDefaultSearchEngine</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ShowMessageWhenOpeningSitesInInternetExplorer</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Show message when opening sites in Internet Explorer</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ShowMessageWhenOpeningSitesInInternetExplorer</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SyncFavoritesBetweenIEAndMicrosoftEdge</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Specifies whether favorites are kept in sync between Internet Explorer and Microsoft Edge. Changes to favorites in one browser are reflected in the other, including: additions, deletions, modifications, and ordering.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>SyncFavoritesBetweenIEAndMicrosoftEdge</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UseSharedFolderForBooks</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This setting specifies whether organizations should use a folder shared across users to store books from the Books Library.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>MicrosoftEdge.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>MicrosoftEdge~AT~WindowsComponents~MicrosoftEdge</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>UseSharedFolderForBooks</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Camera</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowCamera</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>Camera.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>Camera~AT~WindowsComponents~L_Camera_GroupPolicyCategory</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>L_AllowCamera</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Cellular</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>LetAppsAccessCellularData</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy setting specifies whether Windows apps can access cellular data.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>wwansvc.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessCellularData_Enum</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>wwansvc~AT~Network~WwanSvc_Category~CellularDataAccess</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessCellularData</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCellularData_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Windows Store Apps. Listed apps are allowed access to cellular data. This setting overrides the default LetAppsAccessCellularData policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>wwansvc.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessCellularData_ForceAllowTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>wwansvc~AT~Network~WwanSvc_Category~CellularDataAccess</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessCellularData</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCellularData_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are denied access to cellular data. This setting overrides the default LetAppsAccessCellularData policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>wwansvc.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessCellularData_ForceDenyTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>wwansvc~AT~Network~WwanSvc_Category~CellularDataAccess</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessCellularData</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCellularData_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the cellular data access setting for the listed apps. This setting overrides the default LetAppsAccessCellularData policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>wwansvc.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessCellularData_UserInControlOfTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>wwansvc~AT~Network~WwanSvc_Category~CellularDataAccess</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessCellularData</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ShowAppCellularAccessUI</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXBacked>wwansvc.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>wwansvc~AT~Network~WwanSvc_Category~UISettings_Category</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ShowAppCellularAccessUI</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Connectivity</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowBluetooth</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>2</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="0,2"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowCellularData</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowCellularDataRoaming</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WCM.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WCM~AT~Network~WCM_Category</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>WCM_DisableRoaming</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowConnectedDevices</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowNFC</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>desktop</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPhonePCLinking</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>grouppolicy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>grouppolicy~AT~System~PolicyPolicies</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>enableMMX</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowUSBConnection</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>desktop</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowVPNOverCellular</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowVPNRoamingOverCellular</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DiablePrintingOverHTTP</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>ICM.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>ICM~AT~System~InternetManagement~InternetManagement_Settings</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableHTTPPrinting_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableDownloadingOfPrintDriversOverHTTP</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>ICM.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>ICM~AT~System~InternetManagement~InternetManagement_Settings</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableWebPnPDownload_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableInternetDownloadForWebPublishingAndOnlineOrderingWizards</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>ICM.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>ICM~AT~System~InternetManagement~InternetManagement_Settings</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ShellPreventWPWDownload_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisallowNetworkConnectivityActiveTests</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>ICM.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>ICM~AT~System~InternetManagement~InternetManagement_Settings</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>NoActiveProbe</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HardenedUNCPaths</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>networkprovider.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>NetworkProvider~AT~Network~Cat_NetworkProvider</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Pol_HardenedPaths</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ProhibitInstallationAndConfigurationOfNetworkBridge</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>NetworkConnections.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>NetworkConnections~AT~Network~NetworkConnections</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>NC_AllowNetBridge_NLA</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>ControlPolicyConflict</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>MDMWinsOverGP</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>If set to 1 then any MDM policy that is set that has an equivalent GP policy will result in GP service blocking the setting of the policy by GP MMC</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="1" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>CredentialProviders</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowPINLogon</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>credentialproviders.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>CredentialProviders~AT~System~Logon</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowDomainPINLogon</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>BlockPicturePassword</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>credentialproviders.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>CredentialProviders~AT~System~Logon</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>BlockDomainPicturePassword</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableAutomaticReDeploymentCredentials</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>CredentialsDelegation</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>RemoteHostAllowsDelegationOfNonExportableCredentials</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>CredSsp.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>CredSsp~AT~System~CredentialsDelegation</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowProtectedCreds</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>CredentialsUI</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>DisablePasswordReveal</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>credui.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>CredUI~AT~WindowsComponents~CredUI</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisablePasswordReveal</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnumerateAdministrators</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>credui.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>CredUI~AT~WindowsComponents~CredUI</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>EnumerateAdministrators</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Cryptography</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowFipsAlgorithmPolicy</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>System cryptography: Use FIPS-compliant algorithms for encryption, hashing, and signing</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TLSCipherSuites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>DataProtection</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowDirectMemoryAccess</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LegacySelectiveWipeID</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>DataUsage</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>SetCost3G</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXBacked>wwansvc.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>wwansvc~AT~Network~WwanSvc_Category~NetworkCost_Category</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>SetCost3G</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SetCost4G</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXBacked>wwansvc.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>wwansvc~AT~Network~WwanSvc_Category~NetworkCost_Category</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>SetCost4G</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Defender</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowArchiveScanning</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~Scan</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Scan_DisableArchiveScanning</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowBehaviorMonitoring</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~RealtimeProtection</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>RealtimeProtection_DisableBehaviorMonitoring</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowCloudProtection</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>SpynetReporting</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~Spynet</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>SpynetReporting</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowEmailScanning</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~Scan</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Scan_DisableEmailScanning</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowFullScanOnMappedNetworkDrives</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~Scan</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Scan_DisableScanningMappedNetworkDrivesForFullScan</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowFullScanRemovableDriveScanning</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~Scan</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Scan_DisableRemovableDriveScanning</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowIntrusionPreventionSystem</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowIOAVProtection</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~RealtimeProtection</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>RealtimeProtection_DisableIOAVProtection</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowOnAccessProtection</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~RealtimeProtection</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>RealtimeProtection_DisableOnAccessProtection</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowRealtimeMonitoring</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~RealtimeProtection</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableRealtimeMonitoring</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowScanningNetworkFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~Scan</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Scan_DisableScanningNetworkFiles</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowScriptScanning</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowUserUIAccess</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~ClientInterface</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>UX_Configuration_UILockdown</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AttackSurfaceReductionOnlyExclusions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>ExploitGuard_ASR_ASROnlyExclusions</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~ExploitGuard~ExploitGuard_ASR</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ExploitGuard_ASR_ASROnlyExclusions</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AttackSurfaceReductionRules</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>ExploitGuard_ASR_Rules</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~ExploitGuard~ExploitGuard_ASR</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ExploitGuard_ASR_Rules</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AvgCPULoadFactor</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>50</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="100"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>Scan_AvgCPULoadFactor</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~Scan</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Scan_AvgCPULoadFactor</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>CloudBlockLevel</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="6"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>MpCloudBlockLevel</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~MpEngine</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>MpEngine_MpCloudBlockLevel</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>CloudExtendedTimeout</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="50"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>MpBafsExtendedTimeout</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~MpEngine</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>MpEngine_MpBafsExtendedTimeout</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ControlledFolderAccessAllowedApplications</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>ExploitGuard_ControlledFolderAccess_AllowedApplications</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~ExploitGuard~ExploitGuard_ControlledFolderAccess</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ExploitGuard_ControlledFolderAccess_AllowedApplications</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ControlledFolderAccessProtectedFolders</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>ExploitGuard_ControlledFolderAccess_ProtectedFolders</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~ExploitGuard~ExploitGuard_ControlledFolderAccess</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ExploitGuard_ControlledFolderAccess_ProtectedFolders</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DaysToRetainCleanedMalware</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="90"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>Quarantine_PurgeItemsAfterDelay</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~Quarantine</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Quarantine_PurgeItemsAfterDelay</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableControlledFolderAccess</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="4"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>ExploitGuard_ControlledFolderAccess_EnableControlledFolderAccess</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~ExploitGuard~ExploitGuard_ControlledFolderAccess</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ExploitGuard_ControlledFolderAccess_EnableControlledFolderAccess</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableNetworkProtection</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>ExploitGuard_EnableNetworkProtection</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~ExploitGuard~ExploitGuard_NetworkProtection</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ExploitGuard_EnableNetworkProtection</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ExcludedExtensions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>Exclusions_PathsList</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~Exclusions</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Exclusions_Paths</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ExcludedPaths</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>Exclusions_ExtensionsList</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~Exclusions</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Exclusions_Extensions</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ExcludedProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>Exclusions_ProcessesList</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~Exclusions</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Exclusions_Processes</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PUAProtection</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RealTimeScanDirection</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>RealtimeProtection_RealtimeScanDirection</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~RealtimeProtection</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>RealtimeProtection_RealtimeScanDirection</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScanParameter</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="1" high="2"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>Scan_ScanParameters</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~Scan</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Scan_ScanParameters</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScheduleQuickScanTime</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>120</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1380"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>Scan_ScheduleQuickScantime</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~Scan</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Scan_ScheduleQuickScantime</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScheduleScanDay</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="8"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>Scan_ScheduleDay</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~Scan</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Scan_ScheduleDay</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScheduleScanTime</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>120</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1380"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>Scan_ScheduleTime</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~Scan</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Scan_ScheduleTime</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SignatureUpdateInterval</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>8</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="24"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>SignatureUpdate_SignatureUpdateInterval</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~SignatureUpdate</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>SignatureUpdate_SignatureUpdateInterval</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SubmitSamplesConsent</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="3"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>SubmitSamplesConsent</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~Spynet</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>SubmitSamplesConsent</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ThreatSeverityDefaultAction</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefender.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>Threats_ThreatSeverityDefaultActionList</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsDefender~AT~WindowsComponents~AntiSpywareDefender~Threats</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Threats_ThreatSeverityDefaultAction</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>DeliveryOptimization</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>DOAbsoluteMaxCacheSize</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>10</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="4294967295"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>DeliveryOptimization.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>AbsoluteMaxCacheSize</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DeliveryOptimization~AT~WindowsComponents~DeliveryOptimizationCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AbsoluteMaxCacheSize</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOAllowVPNPeerCaching</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>DeliveryOptimization.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>AllowVPNPeerCaching</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DeliveryOptimization~AT~WindowsComponents~DeliveryOptimizationCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowVPNPeerCaching</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DODelayBackgroundDownloadFromHttp</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="4294967295"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>DeliveryOptimization.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>DelayBackgroundDownloadFromHttp</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DeliveryOptimization~AT~WindowsComponents~DeliveryOptimizationCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DelayBackgroundDownloadFromHttp</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DODelayForegroundDownloadFromHttp</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="4294967295"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>DeliveryOptimization.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>DelayForegroundDownloadFromHttp</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DeliveryOptimization~AT~WindowsComponents~DeliveryOptimizationCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DelayForegroundDownloadFromHttp</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DODownloadMode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="0,1,2,3,99,100"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>DeliveryOptimization.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>DownloadMode</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DeliveryOptimization~AT~WindowsComponents~DeliveryOptimizationCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DownloadMode</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOGroupId</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>DeliveryOptimization.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>GroupId</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DeliveryOptimization~AT~WindowsComponents~DeliveryOptimizationCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>GroupId</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOGroupIdSource</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="4"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>DeliveryOptimization.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>GroupIdSource</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DeliveryOptimization~AT~WindowsComponents~DeliveryOptimizationCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>GroupIdSource</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOMaxCacheAge</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>259200</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="4294967295"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>DeliveryOptimization.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>MaxCacheAge</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DeliveryOptimization~AT~WindowsComponents~DeliveryOptimizationCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>MaxCacheAge</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOMaxCacheSize</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>20</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="1" high="100"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>DeliveryOptimization.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>MaxCacheSize</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DeliveryOptimization~AT~WindowsComponents~DeliveryOptimizationCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>MaxCacheSize</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOMaxDownloadBandwidth</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="4294967295"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>DeliveryOptimization.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>MaxDownloadBandwidth</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DeliveryOptimization~AT~WindowsComponents~DeliveryOptimizationCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>MaxDownloadBandwidth</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOMaxUploadBandwidth</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="4000000"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>DeliveryOptimization.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>MaxUploadBandwidth</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DeliveryOptimization~AT~WindowsComponents~DeliveryOptimizationCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>MaxUploadBandwidth</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOMinBackgroundQos</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>500</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="1" high="4294967295"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>DeliveryOptimization.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>MinBackgroundQos</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DeliveryOptimization~AT~WindowsComponents~DeliveryOptimizationCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>MinBackgroundQos</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOMinBatteryPercentageAllowedToUpload</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="100"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>DeliveryOptimization.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>MinBatteryPercentageAllowedToUpload</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DeliveryOptimization~AT~WindowsComponents~DeliveryOptimizationCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>MinBatteryPercentageAllowedToUpload</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOMinDiskSizeAllowedToPeer</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>32</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="1" high="100000"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>DeliveryOptimization.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>MinDiskSizeAllowedToPeer</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DeliveryOptimization~AT~WindowsComponents~DeliveryOptimizationCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>MinDiskSizeAllowedToPeer</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOMinFileSizeToCache</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>100</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="1" high="100000"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>DeliveryOptimization.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>MinFileSizeToCache</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DeliveryOptimization~AT~WindowsComponents~DeliveryOptimizationCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>MinFileSizeToCache</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOMinRAMAllowedToPeer</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>4</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="1" high="100000"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>DeliveryOptimization.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>MinRAMAllowedToPeer</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DeliveryOptimization~AT~WindowsComponents~DeliveryOptimizationCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>MinRAMAllowedToPeer</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOModifyCacheDrive</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>%SystemDrive%</DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>DeliveryOptimization.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>ModifyCacheDrive</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DeliveryOptimization~AT~WindowsComponents~DeliveryOptimizationCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ModifyCacheDrive</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOMonthlyUploadDataCap</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>20</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="4294967295"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>DeliveryOptimization.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>MonthlyUploadDataCap</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DeliveryOptimization~AT~WindowsComponents~DeliveryOptimizationCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>MonthlyUploadDataCap</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOPercentageMaxBackgroundBandwidth</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="100"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>DeliveryOptimization.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>PercentageMaxBackgroundBandwidth</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DeliveryOptimization~AT~WindowsComponents~DeliveryOptimizationCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>PercentageMaxBackgroundBandwidth</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOPercentageMaxDownloadBandwidth</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="100"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOPercentageMaxForegroundBandwidth</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="100"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>DeliveryOptimization.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>PercentageMaxForegroundBandwidth</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DeliveryOptimization~AT~WindowsComponents~DeliveryOptimizationCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>PercentageMaxForegroundBandwidth</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DORestrictPeerSelectionBy</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="0,1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>DeliveryOptimization.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>RestrictPeerSelectionBy</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DeliveryOptimization~AT~WindowsComponents~DeliveryOptimizationCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>RestrictPeerSelectionBy</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOSetHoursToLimitBackgroundDownloadBandwidth</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXBacked>DeliveryOptimization.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>DeliveryOptimization~AT~WindowsComponents~DeliveryOptimizationCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>SetHoursToLimitBackgroundDownloadBandwidth</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:XMLSchema><![CDATA[<xs:schema xmlns:xs="http://www.w3.org/2001/XMLSchema">
                <xs:simpleType name="hours">
                    <xs:restriction base="xs:integer">
                        <xs:minInclusive value="0"/>
                        <xs:maxInclusive value="23"/>
                    </xs:restriction>
                </xs:simpleType>
                <xs:simpleType name="percent">
                    <xs:restriction base="xs:integer">
                        <xs:minInclusive value="0"/>
                        <xs:maxInclusive value="100"/>
                    </xs:restriction>
                </xs:simpleType>
                <xs:element name="Range">
                    <xs:complexType mixed="true">
                        <xs:sequence>
                            <xs:element
                                name="RangeStartTime"
                                type="hours"
                            />
                            <xs:element
                                name="RangeEndTime"
                                type="hours"
                            />
                            <xs:element
                                name="PercentageMaxDownloadBandwidthIn"
                                type="percent"
                            />
                            <xs:element
                                name="PercentageMaxDownloadBandwidthOut"
                                type="percent"
                        />
                        </xs:sequence>
                    </xs:complexType>
                </xs:element>
            </xs:schema>]]></MSFT:XMLSchema>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DOSetHoursToLimitForegroundDownloadBandwidth</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXBacked>DeliveryOptimization.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>DeliveryOptimization~AT~WindowsComponents~DeliveryOptimizationCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>SetHoursToLimitForegroundDownloadBandwidth</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:XMLSchema><![CDATA[<xs:schema xmlns:xs="http://www.w3.org/2001/XMLSchema">
                <xs:simpleType name="hours">
                    <xs:restriction base="xs:integer">
                        <xs:minInclusive value="0"/>
                        <xs:maxInclusive value="23"/>
                    </xs:restriction>
                </xs:simpleType>
                <xs:simpleType name="percent">
                    <xs:restriction base="xs:integer">
                        <xs:minInclusive value="0"/>
                        <xs:maxInclusive value="100"/>
                    </xs:restriction>
                </xs:simpleType>
                <xs:element name="Range">
                    <xs:complexType mixed="true">
                        <xs:sequence>
                            <xs:element
                                name="RangeStartTime"
                                type="hours"
                            />
                            <xs:element
                                name="RangeEndTime"
                                type="hours"
                            />
                            <xs:element
                                name="PercentageMaxDownloadBandwidthIn"
                                type="percent"
                            />
                            <xs:element
                                name="PercentageMaxDownloadBandwidthOut"
                                type="percent"
                        />
                        </xs:sequence>
                    </xs:complexType>
                </xs:element>
            </xs:schema>]]></MSFT:XMLSchema>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>DeviceGuard</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>EnableVirtualizationBasedSecurity</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Turns On Virtualization Based Security(VBS)</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="0,1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>DeviceGuard.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>DeviceGuard~AT~System~DeviceGuardCategory</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>VirtualizationBasedSecurity</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LsaCfgFlags</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Credential Guard Configuration: 0 - Turns off CredentialGuard remotely if configured previously without UEFI Lock, 1 - Turns on CredentialGuard with UEFI lock. 2 - Turns on CredentialGuard without UEFI lock.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="0,1,2"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>DeviceGuard.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>CredentialIsolationDrop</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DeviceGuard~AT~System~DeviceGuardCategory</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>VirtualizationBasedSecurity</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecureZeroHasNoLimits</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RequirePlatformSecurityFeatures</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>Select Platform Security Level: 1 - Turns on VBS with Secure Boot, 3 - Turns on VBS with Secure Boot and DMA. DMA requires hardware support.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="1,3"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>DeviceGuard.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>RequirePlatformSecurityFeaturesDrop</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DeviceGuard~AT~System~DeviceGuardCategory</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>VirtualizationBasedSecurity</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>DeviceInstallation</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>PreventInstallationOfMatchingDeviceIDs</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>deviceinstallation.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>DeviceInstallation~AT~System~DeviceInstall_Category~DeviceInstall_Restrictions_Category</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DeviceInstall_IDs_Deny</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventInstallationOfMatchingDeviceSetupClasses</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>deviceinstallation.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>DeviceInstallation~AT~System~DeviceInstall_Category~DeviceInstall_Restrictions_Category</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DeviceInstall_Classes_Deny</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>DeviceLock</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowIdleReturnWithoutPassword</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>Specifies whether the user must input a PIN or password when the device resumes from an idle state.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>desktop</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowScreenTimeoutWhileLockedUserConfig</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Specifies whether to show a user-configurable setting to control the screen timeout while on the lock screen of Windows 10 Mobile devices.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSimpleDevicePassword</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>Specifies whether PINs or passwords such as 1111 or 1234 are allowed. For the desktop, it also controls the use of picture passwords.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AlphanumericDevicePasswordRequired</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>2</DefaultValue>
            <Description>Determines the type of PIN or password required. This policy only applies if the DeviceLock/DevicePasswordEnabled policy is set to 0</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DevicePasswordEnabled</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>Specifies whether device lock is enabled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DevicePasswordExpiration</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Specifies when the password expires (in days).</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="730"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecureZeroHasNoLimits</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DevicePasswordHistory</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Specifies how many passwords can be stored in the history that cant be used.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="50"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnforceLockScreenAndLogonImage</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnforceLockScreenProvider</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MaxDevicePasswordFailedAttempts</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="999"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecureZeroHasNoLimits</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MaxInactivityTimeDeviceLock</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>The number of authentication failures allowed before the device will be wiped. A value of 0 disables device wipe functionality.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="999"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecureZeroHasNoLimits</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MaxInactivityTimeDeviceLockWithExternalDisplay</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Sets the maximum timeout value for the external display.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="1" high="999"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>desktop</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MinDevicePasswordComplexCharacters</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>The number of complex element types (uppercase and lowercase letters, numbers, and punctuation) required for a strong PIN or password.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="1" high="3"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MinDevicePasswordLength</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>4</DefaultValue>
            <Description>Specifies the minimum number or characters required in the PIN or password.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="4" high="18"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>HighestValueMostSecureZeroHasNoLimits</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MinimumPasswordAge</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This security setting determines the period of time (in days) that a password must be used before the user can change it. You can set a value between 1 and 998 days, or you can allow changes immediately by setting the number of days to 0.

The minimum password age must be less than the Maximum password age, unless the maximum password age is set to 0, indicating that passwords will never expire. If the maximum password age is set to 0, the minimum password age can be set to any value between 0 and 998.

Configure the minimum password age to be more than 0 if you want Enforce password history to be effective. Without a minimum password age, users can cycle through passwords repeatedly until they get to an old favorite. The default setting does not follow this recommendation, so that an administrator can specify a password for a user and then require the user to change the administrator-defined password when the user logs on. If the password history is set to 0, the user does not have to choose a new password. For this reason, Enforce password history is set to 1 by default.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="998"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Account Policies~Password Policy</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Minimum password age</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventEnablingLockScreenCamera</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>ControlPanelDisplay.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>ControlPanelDisplay~AT~ControlPanel~Personalization</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>CPL_Personalization_NoLockScreenCamera</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventLockScreenSlideShow</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>ControlPanelDisplay.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>ControlPanelDisplay~AT~ControlPanel~Personalization</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>CPL_Personalization_NoLockScreenSlideshow</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScreenTimeoutWhileLocked</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>10</DefaultValue>
            <Description>Specifies whether to show a user-configurable setting to control the screen timeout while on the lock screen of Windows 10 Mobile devices.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="10" high="1800"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Display</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>DisablePerProcessDpiForApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This policy allows you to disable Per-Process System DPI for a semicolon-separated list of applications. Applications can be specified either by using full paths or with filenames and extensions. This policy will override the system-wide default value.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>Display.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>DisplayDisablePerProcessSystemDpiSettings</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>Display~AT~System~DisplayCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisplayPerProcessSystemDpiSettings</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnablePerProcessDpi</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>Enable or disable Per-Process System DPI for all applications.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>Display.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>DisplayGlobalPerProcessSystemDpiSettings</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>Display~AT~System~DisplayCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisplayPerProcessSystemDpiSettings</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnablePerProcessDpiForApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This policy allows you to enable Per-Process System DPI for a semicolon-separated list of applications. Applications can be specified either by using full paths or with filenames and extensions. This policy will override the system-wide default value.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>Display.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>DisplayEnablePerProcessSystemDpiSettings</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>Display~AT~System~DisplayCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisplayPerProcessSystemDpiSettings</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TurnOffGdiDPIScalingForApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This policy allows to force turn off GDI DPI Scaling for a semicolon separated list of applications. Applications can be specified either by using full path or just filename and extension.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>Display.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>DisplayTurnOffGdiDPIScalingPrompt</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>Display~AT~System~DisplayCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisplayTurnOffGdiDPIScaling</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TurnOnGdiDPIScalingForApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This policy allows to turn on GDI DPI Scaling for a semicolon separated list of applications. Applications can be specified either by using full path or just filename and extension.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>Display.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>DisplayTurnOnGdiDPIScalingPrompt</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>Display~AT~System~DisplayCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisplayTurnOnGdiDPIScaling</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>ErrorReporting</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>CustomizeConsentSettings</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>ErrorReporting.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>ErrorReporting~AT~WindowsComponents~CAT_WindowsErrorReporting</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>WerConsentCustomize_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableWindowsErrorReporting</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>ErrorReporting.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>ErrorReporting~AT~WindowsComponents~CAT_WindowsErrorReporting</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>WerDisable_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisplayErrorNotification</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>ErrorReporting.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>ErrorReporting~AT~WindowsComponents~CAT_WindowsErrorReporting</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>PCH_ShowUI</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DoNotSendAdditionalData</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>ErrorReporting.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>ErrorReporting~AT~WindowsComponents~CAT_WindowsErrorReporting</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>WerNoSecondLevelData_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventCriticalErrorDisplay</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>ErrorReporting.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>ErrorReporting~AT~WindowsComponents~CAT_WindowsErrorReporting</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>WerDoNotShowUI</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>EventLogService</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>ControlEventLogBehavior</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>eventlog.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>EventLog~AT~WindowsComponents~EventLogCategory~EventLog_Application</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Channel_Log_Retention_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SpecifyMaximumFileSizeApplicationLog</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>eventlog.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>EventLog~AT~WindowsComponents~EventLogCategory~EventLog_Application</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Channel_LogMaxSize_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SpecifyMaximumFileSizeSecurityLog</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>eventlog.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>EventLog~AT~WindowsComponents~EventLogCategory~EventLog_Security</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Channel_LogMaxSize_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SpecifyMaximumFileSizeSystemLog</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>eventlog.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>EventLog~AT~WindowsComponents~EventLogCategory~EventLog_System</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Channel_LogMaxSize_4</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Experience</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowCopyPaste</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>desktop</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowCortana</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>Search.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>Search~AT~WindowsComponents~Search</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowCortana</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowDeviceDiscovery</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowFindMyDevice</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>FindMy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>FindMy~AT~WindowsComponents~FindMyDeviceCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>FindMy_AllowFindMyDeviceConfig</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowManualMDMUnenrollment</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSaveAsOfOfficeFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowScreenCapture</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSharingOfOfficeFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSIMErrorDialogPromptWhenNoSIM</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSyncMySettings</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowTaskSwitcher</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>desktop</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowVoiceRecording</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>desktop</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowWindowsConsumerFeatures</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>CloudContent.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>CloudContent~AT~WindowsComponents~CloudContent</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableWindowsConsumerFeatures</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowWindowsTips</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>CloudContent.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>CloudContent~AT~WindowsComponents~CloudContent</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableSoftLanding</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DoNotShowFeedbackNotifications</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>FeedbackNotifications.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>FeedbackNotifications~AT~WindowsComponents~DataCollectionAndPreviewBuilds</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DoNotShowFeedbackNotifications</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>ExploitGuard</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>ExploitProtectionSettings</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>ExploitGuard.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>ExploitProtection_Name</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>ExploitGuard~AT~WindowsComponents~WindowsDefenderExploitGuard~ExploitProtection</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ExploitProtection_Name</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>FileExplorer</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>TurnOffDataExecutionPreventionForExplorer</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>Explorer.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>Explorer~AT~WindowsExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>NoDataExecutionPrevention</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TurnOffHeapTerminationOnCorruption</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>Explorer.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>Explorer~AT~WindowsExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>NoHeapTerminationOnCorruption</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Games</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowAdvancedGamingServices</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>Specifies whether advanced gaming services can be used. These services may send data to Microsoft or publishers of games that use these services.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Handwriting</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>PanelDefaultModeDocked</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Specifies whether the handwriting panel comes up floating near the text box or attached to the bottom of the screen</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>Handwriting.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>Handwriting~AT~WindowsComponents~Handwriting</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>PanelDefaultModeDocked</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>InternetExplorer</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AddSearchProvider</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AddSearchProvider</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowActiveXFiltering</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>TurnOnActiveXFiltering</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowAddOnList</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~SecurityFeatures~IESF_AddOnManagement</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AddonManagement_AddOnList</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowCertificateAddressMismatchWarning</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyWarnCertMismatch</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowDeletingBrowsingHistoryOnExit</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~DeleteBrowsingHistory</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DBHDisableDeleteOnExit</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowEnhancedProtectedMode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~AdvancedPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Advanced_EnableEnhancedProtectedMode</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowEnterpriseModeFromToolsMenu</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>EnterpriseModeEnable</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowEnterpriseModeSiteList</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>EnterpriseModeSiteList</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowFallbackToSSL3</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~SecurityFeatures</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Advanced_EnableSSL3Fallback</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowInternetExplorer7PolicyList</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~CategoryCompatView</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>CompatView_UsePolicyList</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowInternetExplorerStandardsMode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~CategoryCompatView</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>CompatView_IntranetSites</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowInternetZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyInternetZoneTemplate</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowIntranetZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyIntranetZoneTemplate</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLocalMachineZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyLocalMachineZoneTemplate</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLockedDownInternetZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyInternetZoneLockdownTemplate</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLockedDownIntranetZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyIntranetZoneLockdownTemplate</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLockedDownLocalMachineZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyLocalMachineZoneLockdownTemplate</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLockedDownRestrictedSitesZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyRestrictedSitesZoneLockdownTemplate</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowOneWordEntry</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetSettings~Advanced~Browsing</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>UseIntranetSiteForOneWordEntry</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSiteToZoneAssignmentList</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Zonemaps</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowsLockedDownTrustedSitesZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyTrustedSitesZoneLockdownTemplate</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSoftwareWhenSignatureIsInvalid</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~AdvancedPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Advanced_InvalidSignatureBlock</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowsRestrictedSitesZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyRestrictedSitesZoneTemplate</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSuggestedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>EnableSuggestedSites</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowTrustedSitesZoneTemplate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyTrustedSitesZoneTemplate</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>CheckServerCertificateRevocation</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~AdvancedPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Advanced_CertificateRevocation</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>CheckSignaturesOnDownloadedPrograms</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~AdvancedPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Advanced_DownloadSignatures</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConsistentMimeHandlingInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~SecurityFeatures~IESF_CategoryConsistentMimeHandling</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IESF_PolicyExplorerProcesses_5</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableAdobeFlash</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~SecurityFeatures~IESF_AddOnManagement</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableFlashInIE</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableBypassOfSmartScreenWarnings</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableSafetyFilterOverride</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableBypassOfSmartScreenWarningsAboutUncommonFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableSafetyFilterOverrideForAppRepUnknown</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableConfiguringHistory</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~DeleteBrowsingHistory</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>RestrictHistory</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableCrashDetection</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AddonManagement_RestrictCrashDetection</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableCustomerExperienceImprovementProgramParticipation</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>SQM_DisableCEIP</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableDeletingUserVisitedWebsites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~DeleteBrowsingHistory</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DBHDisableDeleteHistory</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableEnclosureDownloading</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~RSS_Feeds</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Disable_Downloading_of_Enclosures</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableEncryptionSupport</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~AdvancedPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Advanced_SetWinInetProtocols</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableFirstRunWizard</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>NoFirstRunCustomise</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableFlipAheadFeature</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~AdvancedPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Advanced_DisableFlipAhead</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableIgnoringCertificateErrors</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>NoCertError</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableInPrivateBrowsing</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~CategoryPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableInPrivateBrowsing</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableProcessesInEnhancedProtectedMode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~AdvancedPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Advanced_EnableEnhancedProtectedMode64Bit</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableProxyChange</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>RestrictProxy</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableSearchProviderChange</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>NoSearchProvider</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableSecondaryHomePageChange</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>SecondaryHomePages</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableSecuritySettingsCheck</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Disable_Security_Settings_Check</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableUpdateCheck</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>NoUpdateCheck</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DoNotAllowActiveXControlsInProtectedMode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~AdvancedPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Advanced_DisableEPMCompat</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DoNotAllowUsersToAddSites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Security_zones_map_edit</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DoNotAllowUsersToChangePolicies</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Security_options_edit</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DoNotBlockOutdatedActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~SecurityFeatures~IESF_AddOnManagement</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>VerMgmtDisable</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DoNotBlockOutdatedActiveXControlsOnSpecificDomains</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~SecurityFeatures~IESF_AddOnManagement</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>VerMgmtDomainAllowlist</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IncludeAllLocalSites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_IncludeUnspecifiedLocalSites</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IncludeAllNetworkPaths</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_UNCAsIntranet</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAccessDataSourcesAcrossDomains_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarActiveXURLaction_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarDownloadURLaction_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowCopyPasteViaScript</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAllowPasteViaScript_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowDragAndDropCopyAndPasteFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyDropOrPasteFiles_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyFontDownload_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyZoneElevationURLaction_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowLoadingOfXAMLFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_XAML_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUnsignedFrameworkComponentsURLaction_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowOnlyApprovedDomainsToUseActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyOnlyAllowApprovedDomainsToUseActiveXWithoutPrompt_Both_Internet</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowOnlyApprovedDomainsToUseTDCActiveXControl</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAllowTDCControl_Both_Internet</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowScriptingOfInternetExplorerWebBrowserControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_WebBrowserControl_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowScriptInitiatedWindows</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyWindowsRestrictionsURLaction_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_AllowScriptlets_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_Phishing_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowUpdatesToStatusBarViaScript</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_ScriptStatusBar_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUserdataPersistence_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneAllowVBScriptToRunInInternetExplorer</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAllowVBScript_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneDoNotRunAntimalwareAgainstActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAntiMalwareCheckingOfActiveXControls_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneDownloadSignedActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyDownloadSignedActiveX_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneDownloadUnsignedActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyDownloadUnsignedActiveX_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneEnableCrossSiteScriptingFilter</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyTurnOnXSSFilter_Both_Internet</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneEnableDraggingOfContentFromDifferentDomainsAcrossWindows</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyDragDropAcrossDomainsAcrossWindows_Both_Internet</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneEnableDraggingOfContentFromDifferentDomainsWithinWindows</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyDragDropAcrossDomainsWithinWindow_Both_Internet</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneEnableMIMESniffing</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyMimeSniffingURLaction_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneEnableProtectedMode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_TurnOnProtectedMode_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneIncludeLocalPathWhenUploadingFilesToServer</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_LocalPathForUpload_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyScriptActiveXNotMarkedSafe_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyJavaPermissions_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneLaunchingApplicationsAndFilesInIFRAME</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyLaunchAppsAndFilesInIFRAME_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneLogonOptions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyLogon_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNavigateSubframesAcrossDomains_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneRunNETFrameworkReliantComponentsSignedWithAuthenticode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicySignedFrameworkComponentsURLaction_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneShowSecurityWarningForPotentiallyUnsafeFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_UnsafeFiles_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InternetZoneUsePopupBlocker</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyBlockPopupWindows_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAccessDataSourcesAcrossDomains_3</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarActiveXURLaction_3</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarDownloadURLaction_3</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyFontDownload_3</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyZoneElevationURLaction_3</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUnsignedFrameworkComponentsURLaction_3</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_AllowScriptlets_3</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_Phishing_3</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUserdataPersistence_3</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneDoNotRunAntimalwareAgainstActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAntiMalwareCheckingOfActiveXControls_3</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyScriptActiveXNotMarkedSafe_3</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyJavaPermissions_3</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IntranetZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNavigateSubframesAcrossDomains_3</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAccessDataSourcesAcrossDomains_9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarActiveXURLaction_9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarDownloadURLaction_9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyFontDownload_9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyZoneElevationURLaction_9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUnsignedFrameworkComponentsURLaction_9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_AllowScriptlets_9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_Phishing_9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUserdataPersistence_9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneDoNotRunAntimalwareAgainstActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAntiMalwareCheckingOfActiveXControls_9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyScriptActiveXNotMarkedSafe_9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyJavaPermissions_9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LocalMachineZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNavigateSubframesAcrossDomains_9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAccessDataSourcesAcrossDomains_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarActiveXURLaction_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarDownloadURLaction_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyFontDownload_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyZoneElevationURLaction_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUnsignedFrameworkComponentsURLaction_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_AllowScriptlets_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_Phishing_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUserdataPersistence_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyScriptActiveXNotMarkedSafe_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyJavaPermissions_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownInternetZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_InternetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNavigateSubframesAcrossDomains_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyJavaPermissions_4</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAccessDataSourcesAcrossDomains_4</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarActiveXURLaction_4</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarDownloadURLaction_4</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyFontDownload_4</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyZoneElevationURLaction_4</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUnsignedFrameworkComponentsURLaction_4</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_AllowScriptlets_4</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_Phishing_4</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUserdataPersistence_4</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyScriptActiveXNotMarkedSafe_4</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownIntranetZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_IntranetZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNavigateSubframesAcrossDomains_4</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAccessDataSourcesAcrossDomains_10</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarActiveXURLaction_10</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarDownloadURLaction_10</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyFontDownload_10</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyZoneElevationURLaction_10</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUnsignedFrameworkComponentsURLaction_10</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_AllowScriptlets_10</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_Phishing_10</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUserdataPersistence_10</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyScriptActiveXNotMarkedSafe_10</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyJavaPermissions_10</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownLocalMachineZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_LocalMachineZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNavigateSubframesAcrossDomains_10</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAccessDataSourcesAcrossDomains_8</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarActiveXURLaction_8</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarDownloadURLaction_8</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyFontDownload_8</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyZoneElevationURLaction_8</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUnsignedFrameworkComponentsURLaction_8</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_AllowScriptlets_8</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_Phishing_8</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUserdataPersistence_8</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyScriptActiveXNotMarkedSafe_8</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyJavaPermissions_8</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownRestrictedSitesZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNavigateSubframesAcrossDomains_8</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAccessDataSourcesAcrossDomains_6</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarActiveXURLaction_6</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarDownloadURLaction_6</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyFontDownload_6</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyZoneElevationURLaction_6</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUnsignedFrameworkComponentsURLaction_6</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_AllowScriptlets_6</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_Phishing_6</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUserdataPersistence_6</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyScriptActiveXNotMarkedSafe_6</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyJavaPermissions_6</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockedDownTrustedSitesZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZoneLockdown</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNavigateSubframesAcrossDomains_6</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MimeSniffingSafetyFeatureInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~SecurityFeatures~IESF_CategoryMimeSniffingSafetyFeature</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IESF_PolicyExplorerProcesses_6</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MKProtocolSecurityRestrictionInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~SecurityFeatures~IESF_CategoryMKProtocolSecurityRestriction</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IESF_PolicyExplorerProcesses_3</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NotificationBarInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~SecurityFeatures~IESF_CategoryInformationBar</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IESF_PolicyExplorerProcesses_10</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventManagingSmartScreenFilter</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Disable_Managing_Safety_Filter_IE9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventPerUserInstallationOfActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisablePerUserActiveXInstall</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ProtectionFromZoneElevationInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~SecurityFeatures~IESF_CategoryProtectionFromZoneElevation</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IESF_PolicyExplorerProcesses_9</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RemoveRunThisTimeButtonForOutdatedActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~SecurityFeatures~IESF_AddOnManagement</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>VerMgmtDisableRunThisTime</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictActiveXInstallInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~SecurityFeatures~IESF_CategoryRestrictActiveXInstall</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IESF_PolicyExplorerProcesses_11</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAccessDataSourcesAcrossDomains_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowActiveScripting</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyActiveScripting_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarActiveXURLaction_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarDownloadURLaction_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowBinaryAndScriptBehaviors</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyBinaryBehaviors_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowCopyPasteViaScript</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAllowPasteViaScript_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowDragAndDropCopyAndPasteFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyDropOrPasteFiles_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyFileDownload_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyFontDownload_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyZoneElevationURLaction_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowLoadingOfXAMLFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_XAML_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowMETAREFRESH</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAllowMETAREFRESH_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUnsignedFrameworkComponentsURLaction_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowOnlyApprovedDomainsToUseActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyOnlyAllowApprovedDomainsToUseActiveXWithoutPrompt_Both_Restricted</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowOnlyApprovedDomainsToUseTDCActiveXControl</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAllowTDCControl_Both_Restricted</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowScriptingOfInternetExplorerWebBrowserControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_WebBrowserControl_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowScriptInitiatedWindows</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyWindowsRestrictionsURLaction_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_AllowScriptlets_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_Phishing_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowUpdatesToStatusBarViaScript</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_ScriptStatusBar_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUserdataPersistence_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneAllowVBScriptToRunInInternetExplorer</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAllowVBScript_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneDoNotRunAntimalwareAgainstActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAntiMalwareCheckingOfActiveXControls_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneDownloadSignedActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyDownloadSignedActiveX_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneDownloadUnsignedActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyDownloadUnsignedActiveX_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneEnableCrossSiteScriptingFilter</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyTurnOnXSSFilter_Both_Restricted</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneEnableDraggingOfContentFromDifferentDomainsAcrossWindows</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyDragDropAcrossDomainsAcrossWindows_Both_Restricted</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneEnableDraggingOfContentFromDifferentDomainsWithinWindows</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyDragDropAcrossDomainsWithinWindow_Both_Restricted</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneEnableMIMESniffing</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyMimeSniffingURLaction_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneIncludeLocalPathWhenUploadingFilesToServer</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_LocalPathForUpload_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyScriptActiveXNotMarkedSafe_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyJavaPermissions_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneLaunchingApplicationsAndFilesInIFRAME</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyLaunchAppsAndFilesInIFRAME_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneLogonOptions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyLogon_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNavigateSubframesAcrossDomains_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneRunActiveXControlsAndPlugins</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyRunActiveXControls_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneRunNETFrameworkReliantComponentsSignedWithAuthenticode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicySignedFrameworkComponentsURLaction_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneScriptActiveXControlsMarkedSafeForScripting</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyScriptActiveXMarkedSafe_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneScriptingOfJavaApplets</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyScriptingOfJavaApplets_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneShowSecurityWarningForPotentiallyUnsafeFiles</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_UnsafeFiles_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneTurnOnProtectedMode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_TurnOnProtectedMode_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictedSitesZoneUsePopupBlocker</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_RestrictedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyBlockPopupWindows_7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestrictFileDownloadInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~SecurityFeatures~IESF_CategoryRestrictFileDownload</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IESF_PolicyExplorerProcesses_12</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScriptedWindowSecurityRestrictionsInternetExplorerProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~SecurityFeatures~IESF_CategoryScriptedWindowSecurityRestrictions</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IESF_PolicyExplorerProcesses_8</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SearchProviderList</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>SpecificSearchProvider</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SecurityZonesUseOnlyMachineSettings</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Security_HKLM_only</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SpecifyUseOfActiveXInstallerService</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>OnlyUseAXISForActiveXInstall</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowAccessToDataSources</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAccessDataSourcesAcrossDomains_5</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowAutomaticPromptingForActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarActiveXURLaction_5</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowAutomaticPromptingForFileDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNotificationBarDownloadURLaction_5</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowFontDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyFontDownload_5</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowLessPrivilegedSites</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyZoneElevationURLaction_5</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowNETFrameworkReliantComponents</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUnsignedFrameworkComponentsURLaction_5</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowScriptlets</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_AllowScriptlets_5</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowSmartScreenIE</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_Policy_Phishing_5</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneAllowUserDataPersistence</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyUserdataPersistence_5</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneDoNotRunAntimalwareAgainstActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyAntiMalwareCheckingOfActiveXControls_5</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneInitializeAndScriptActiveXControls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyScriptActiveXNotMarkedSafe_5</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneJavaPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyJavaPermissions_5</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedSitesZoneNavigateWindowsAndFrames</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>inetres.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>inetres~AT~WindowsComponents~InternetExplorer~InternetCPL~IZ_SecurityPage~IZ_TrustedSitesZone</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IZ_PolicyNavigateSubframesAcrossDomains_5</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Kerberos</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowForestSearchOrder</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>Kerberos.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>Kerberos~AT~System~kerberos</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ForestSearch</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>KerberosClientSupportsClaimsCompoundArmor</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>Kerberos.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>Kerberos~AT~System~kerberos</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>EnableCbacAndArmor</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RequireKerberosArmoring</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>Kerberos.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>Kerberos~AT~System~kerberos</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ClientRequireFast</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RequireStrictKDCValidation</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>Kerberos.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>Kerberos~AT~System~kerberos</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ValidateKDC</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SetMaximumContextTokenSize</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>Kerberos.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>Kerberos~AT~System~kerberos</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>MaxTokenSize</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>KioskBrowser</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>BlockedUrlExceptions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of exceptions to the blocked website URLs (with wildcard support). This is used to configure URLs kiosk browsers are allowed to navigate to, which are a subset of the blocked URLs.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>BlockedUrls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of blocked website URLs (with wildcard support). This is used to configure blocked URLs kiosk browsers can not navigate to.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DefaultURL</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>Configures the default URL kiosk browsers to navigate on launch and restart.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableEndSessionButton</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Enable/disable kiosk browser's end session button.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableHomeButton</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Enable/disable kiosk browser's home button.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableNavigationButtons</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Enable/disable kiosk browser's navigation buttons (forward/back).</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestartOnIdleTime</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Amount of time in minutes the session is idle until the kiosk browser restarts in a fresh state.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="1" high="1440"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>LanmanWorkstation</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>EnableInsecureGuestLogons</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>LanmanWorkstation.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>LanmanWorkstation~AT~Network~Cat_LanmanWorkstation</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Pol_EnableInsecureGuestLogons</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Licensing</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowWindowsEntitlementReactivation</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>AVSValidationGP.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>AVSValidationGP~AT~WindowsComponents~SoftwareProtectionPlatform</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowWindowsEntitlementReactivation</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisallowKMSClientOnlineAVSValidation</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>AVSValidationGP.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>AVSValidationGP~AT~WindowsComponents~SoftwareProtectionPlatform</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>NoAcquireGT</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>LocalPoliciesSecurityOptions</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>Accounts_BlockMicrosoftAccounts</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy setting prevents users from adding new Microsoft accounts on this computer.

If you select the "Users cant add Microsoft accounts" option, users will not be able to create new Microsoft accounts on this computer, switch a local account to a Microsoft account, or connect a domain account to a Microsoft account. This is the preferred option if you need to limit the use of Microsoft accounts in your enterprise.

If you select the "Users cant add or log on with Microsoft accounts" option, existing Microsoft account users will not be able to log on to Windows. Selecting this option might make it impossible for an existing administrator on this computer to log on and manage the system.

If you disable or do not configure this policy (recommended), users will be able to use Microsoft accounts with Windows.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="0,1,3"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Accounts: Block Microsoft accounts</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>Accounts_EnableAdministratorAccountStatus</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This security setting determines whether the local Administrator account is enabled or disabled.

Notes

If you try to reenable the Administrator account after it has been disabled, and if the current Administrator password does not meet the password requirements, you cannot reenable the account. In this case, an alternative member of the Administrators group must reset the password on the Administrator account. For information about how to reset a password, see To reset a password.
Disabling the Administrator account can become a maintenance issue under certain circumstances. 

Under Safe Mode boot, the disabled Administrator account will only be enabled if the machine is non-domain joined and there are no other local active administrator accounts.  If the computer is domain joined the disabled administrator will not be enabled.

Default: Disabled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Accounts: Administrator account status</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>Accounts_EnableGuestAccountStatus</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This security setting determines if the Guest account is enabled or disabled.

Default: Disabled.

Note: If the Guest account is disabled and the security option Network Access: Sharing and Security Model for local accounts is set to Guest Only, network logons, such as those performed by the Microsoft Network Server (SMB Service), will fail.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Accounts: Guest account status</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>Accounts_LimitLocalAccountUseOfBlankPasswordsToConsoleLogonOnly</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>Accounts: Limit local account use of blank passwords to console logon only

This security setting determines whether local accounts that are not password protected can be used to log on from locations other than the physical computer console. If enabled, local accounts that are not password protected will only be able to log on at the computer's keyboard.

Default: Enabled.


Warning:

Computers that are not in physically secure locations should always enforce strong password policies for all local user accounts. Otherwise, anyone with physical access to the computer can log on by using a user account that does not have a password. This is especially important for portable computers.
If you apply this security policy to the Everyone group, no one will be able to log on through Remote Desktop Services.

Notes

This setting does not affect logons that use domain accounts.
It is possible for applications that use remote interactive logons to bypass this setting.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Accounts: Limit local account use of blank passwords to console logon only</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>Accounts_RenameAdministratorAccount</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>Administrator</DefaultValue>
            <Description>Accounts: Rename administrator account

This security setting determines whether a different account name is associated with the security identifier (SID) for the account Administrator. Renaming the well-known Administrator account makes it slightly more difficult for unauthorized persons to guess this privileged user name and password combination.

Default: Administrator.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Accounts: Rename administrator account</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>Accounts_RenameGuestAccount</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>Guest</DefaultValue>
            <Description>Accounts: Rename guest account

This security setting determines whether a different account name is associated with the security identifier (SID) for the account "Guest." Renaming the well-known Guest account makes it slightly more difficult for unauthorized persons to guess this user name and password combination.

Default: Guest.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Accounts: Rename guest account</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>Devices_AllowedToFormatAndEjectRemovableMedia</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Devices: Allowed to format and eject removable media

This security setting determines who is allowed to format and eject removable NTFS media. This capability can be given to:

Administrators
Administrators and Interactive Users

Default: This policy is not defined and only Administrators have this ability.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Devices: Allowed to format and eject removable media</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>Devices_AllowUndockWithoutHavingToLogon</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>Devices: Allow undock without having to log on
This security setting determines whether a portable computer can be undocked without having to log on. If this policy is enabled, logon is not required and an external hardware eject button can be used to undock the computer. If disabled, a user must log on and have the Remove computer from docking station privilege to undock the computer.
Default: Enabled.

Caution
Disabling this policy may tempt users to try and physically remove the laptop from its docking station using methods other than the external hardware eject button. Since this may cause damage to the hardware, this setting, in general, should only be disabled on laptop configurations that are physically securable.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Devices: Allow undock without having to log on</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>Devices_PreventUsersFromInstallingPrinterDriversWhenConnectingToSharedPrinters</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Devices: Prevent users from installing printer drivers when connecting to shared printers

For a computer to print to a shared printer, the driver for that shared printer must be installed on the local computer. This security setting determines who is allowed to install a printer driver as part of connecting to a shared printer. If this setting is enabled, only Administrators can install a printer driver as part of connecting to a shared printer. If this setting is disabled, any user can install a printer driver as part of connecting to a shared printer.

Default on servers: Enabled.
Default on workstations: Disabled

Notes

This setting does not affect the ability to add a local printer.
This setting does not affect Administrators.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Devices: Prevent users from installing printer drivers</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>Devices_RestrictCDROMAccessToLocallyLoggedOnUserOnly</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Devices: Restrict CD-ROM access to locally logged-on user only

This security setting determines whether a CD-ROM is accessible to both local and remote users simultaneously.

If this policy is enabled, it allows only the interactively logged-on user to access removable CD-ROM media. If this policy is enabled and no one is logged on interactively, the CD-ROM can be accessed over the network.

Default: This policy is not defined and CD-ROM access is not restricted to the locally logged-on user.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Devices: Restrict CD-ROM access to locally logged-on user only</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DomainMember_DigitallyEncryptOrSignSecureChannelDataAlways</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>Domain member: Digitally encrypt or sign secure channel data (always)

This security setting determines whether all secure channel traffic initiated by the domain member must be signed or encrypted.

When a computer joins a domain, a computer account is created. After that, when the system starts, it uses the computer account password to create a secure channel with a domain controller for its domain. This secure channel is used to perform operations such as NTLM pass through authentication, LSA SID/name Lookup etc.

This setting determines whether or not all secure channel traffic initiated by the domain member meets minimum security requirements. Specifically it determines whether all secure channel traffic initiated by the domain member must be signed or encrypted. If this policy is enabled, then the secure channel will not be established unless either signing or encryption of all secure channel traffic is negotiated. If this policy is disabled, then encryption and signing of all secure channel traffic is negotiated with the Domain Controller in which case the level of signing and encryption depends on the version of the Domain Controller and the settings of the following two policies:

Domain member: Digitally encrypt secure channel data (when possible)
Domain member: Digitally sign secure channel data (when possible)

Default: Enabled.

Notes:

If this policy is enabled, the policy Domain member: Digitally sign secure channel data (when possible) is assumed to be enabled regardless of its current setting. This ensures that the domain member attempts to negotiate at least signing of the secure channel traffic.
If this policy is enabled, the policy Domain member: Digitally sign secure channel data (when possible) is assumed to be enabled regardless of its current setting. This ensures that the domain member attempts to negotiate at least signing of the secure channel traffic.
Logon information transmitted over the secure channel is always encrypted regardless of whether encryption of ALL other secure channel traffic is negotiated or not.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Domain member: Digitally encrypt or sign secure channel data (always)</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DomainMember_DigitallyEncryptSecureChannelDataWhenPossible</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>Domain member: Digitally encrypt secure channel data (when possible)

This security setting determines whether a domain member attempts to negotiate encryption for all secure channel traffic that it initiates.

When a computer joins a domain, a computer account is created. After that, when the system starts, it uses the computer account password to create a secure channel with a domain controller for its domain. This secure channel is used to perform operations such as NTLM pass-through authentication, LSA SID/name Lookup etc.

This setting determines whether or not the domain member attempts to negotiate encryption for all secure channel traffic that it initiates. If enabled, the domain member will request encryption of all secure channel traffic. If the domain controller supports encryption of all secure channel traffic, then all secure channel traffic will be encrypted. Otherwise only logon information transmitted over the secure channel will be encrypted. If this setting is disabled, then the domain member will not attempt to negotiate secure channel encryption.

Default: Enabled.

Important

There is no known reason for disabling this setting. Besides unnecessarily reducing the potential confidentiality level of the secure channel, disabling this setting may unnecessarily reduce secure channel throughput, because concurrent API calls that use the secure channel are only possible when the secure channel is signed or encrypted.

Note: Domain controllers are also domain members and establish secure channels with other domain controllers in the same domain as well as domain controllers in trusted domains.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Domain member: Digitally encrypt secure channel data (when possible)</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DomainMember_DisableMachineAccountPasswordChanges</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Domain member: Disable machine account password changes

Determines whether a domain member periodically changes its computer account password. If this setting is enabled, the domain member does not attempt to change its computer account password. If this setting is disabled, the domain member attempts to change its computer account password as specified by the setting for Domain Member: Maximum age for machine account password, which by default is every 30 days.

Default: Disabled.

Notes

This security setting should not be enabled. Computer account passwords are used to establish secure channel communications between members and domain controllers and, within the domain, between the domain controllers themselves. Once it is established, the secure channel is used to transmit sensitive information that is necessary for making authentication and authorization decisions.
This setting should not be used in an attempt to support dual-boot scenarios that use the same computer account. If you want to dual-boot two installations that are joined to the same domain, give the two installations different computer names.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Domain member: Disable machine account password changes</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InteractiveLogon_DisplayUserInformationWhenTheSessionIsLocked</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>Interactive Logon:Display user information when the session is locked
User display name, domain and user names (1)
User display name only (2)
Do not display user information (3)</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="1" high="3"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Interactive logon: Display user information when the session is locked</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InteractiveLogon_DoNotDisplayLastSignedIn</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Interactive logon: Don't display last signed-in
This security setting determines whether the Windows sign-in screen will show the username of the last person who signed in on this PC.
If this policy is enabled, the username will not be shown.

If this policy is disabled, the username will be shown.

Default: Disabled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Interactive logon: Don't display last signed-in</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InteractiveLogon_DoNotDisplayUsernameAtSignIn</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>Interactive logon: Don't display username at sign-in
This security setting determines whether the username of the person signing in to this PC appears at Windows sign-in, after credentials are entered, and before the PC desktop is shown.
If this policy is enabled, the username will not be shown.

If this policy is disabled, the username will be shown.

Default: Disabled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Interactive logon: Don't display username at sign-in</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InteractiveLogon_DoNotRequireCTRLALTDEL</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>Interactive logon: Do not require CTRL+ALT+DEL

This security setting determines whether pressing CTRL+ALT+DEL is required before a user can log on.

If this policy is enabled on a computer, a user is not required to press CTRL+ALT+DEL to log on. Not having to press CTRL+ALT+DEL leaves users susceptible to attacks that attempt to intercept the users' passwords. Requiring CTRL+ALT+DEL before users log on ensures that users are communicating by means of a trusted path when entering their passwords.

If this policy is disabled, any user is required to press CTRL+ALT+DEL before logging on to Windows.

Default on domain-computers: Enabled: At least Windows  8/Disabled: Windows 7 or earlier.
Default on stand-alone computers: Enabled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Interactive logon: Do not require CTRL+ALT+DEL</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InteractiveLogon_MachineInactivityLimit</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Interactive logon: Machine inactivity limit.

Windows notices inactivity of a logon session, and if the amount of inactive time exceeds the inactivity limit, then the screen saver will run, locking the session.

Default: not enforced.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="599940"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Interactive logon: Machine inactivity limit</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InteractiveLogon_MessageTextForUsersAttemptingToLogOn</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>Interactive logon: Message text for users attempting to log on

This security setting specifies a text message that is displayed to users when they log on.

This text is often used for legal reasons, for example, to warn users about the ramifications of misusing company information or to warn them that their actions may be audited.

Default: No message.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Interactive logon: Message text for users attempting to log on</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InteractiveLogon_MessageTitleForUsersAttemptingToLogOn</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>Interactive logon: Message title for users attempting to log on

This security setting allows the specification of a title to appear in the title bar of the window that contains the Interactive logon: Message text for users attempting to log on.

Default: No message.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Interactive logon: Message title for users attempting to log on</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>InteractiveLogon_SmartCardRemovalBehavior</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Interactive logon: Smart card removal behavior

This security setting determines what happens when the smart card for a logged-on user is removed from the smart card reader.

The options are:

 No Action
 Lock Workstation
 Force Logoff
 Disconnect if a Remote Desktop Services session 

If you click Lock Workstation in the Properties dialog box for this policy, the workstation is locked when the smart card is removed, allowing users to leave the area, take their smart card with them, and still maintain a protected session.

If you click Force Logoff in the Properties dialog box for this policy, the user is automatically logged off when the smart card is removed.

If you click Disconnect if a Remote Desktop Services session, removal of the smart card disconnects the session without logging the user off. This allows the user to insert the smart card and resume the session later, or at another smart card reader-equipped computer, without having to log on again. If the session is local, this policy functions identically to Lock Workstation.

Note: Remote Desktop Services was called Terminal Services in previous versions of Windows Server.

Default: This policy is not defined, which means that the system treats it as No action.

On Windows Vista and above: For this setting to work, the Smart Card Removal Policy service must be started.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Interactive logon: Smart card removal behavior</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MicrosoftNetworkClient_DigitallySignCommunicationsIfServerAgrees</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>Microsoft network client: Digitally sign communications (if server agrees)

This security setting determines whether the SMB client attempts to negotiate SMB packet signing.

The server message block (SMB) protocol provides the basis for Microsoft file and print sharing and many other networking operations, such as remote Windows administration. To prevent man-in-the-middle attacks that modify SMB packets in transit, the SMB protocol supports the digital signing of SMB packets. This policy setting determines whether the SMB client component attempts to negotiate SMB packet signing when it connects to an SMB server.

If this setting is enabled, the Microsoft network client will ask the server to perform SMB packet signing upon session setup. If packet signing has been enabled on the server, packet signing will be negotiated. If this policy is disabled, the SMB client will never negotiate SMB packet signing.

Default: Enabled.

Notes

All Windows operating systems support both a client-side SMB component and a server-side SMB component. On Windows 2000 and later, enabling or requiring packet signing for client and server-side SMB components is controlled by the following four policy settings:
Microsoft network client: Digitally sign communications (always) - Controls whether or not the client-side SMB component requires packet signing.
Microsoft network client: Digitally sign communications (if server agrees) - Controls whether or not the client-side SMB component has packet signing enabled.
Microsoft network server: Digitally sign communications (always) - Controls whether or not the server-side SMB component requires packet signing.
Microsoft network server: Digitally sign communications (if client agrees) - Controls whether or not the server-side SMB component has packet signing enabled.
If both client-side and server-side SMB signing is enabled and the client establishes an SMB 1.0 connection to the server, SMB signing will be attempted.
SMB packet signing can significantly degrade SMB performance, depending on dialect version, OS version, file sizes, processor offloading capabilities, and application IO behaviors. This setting only applies to SMB 1.0 connections.
For more information, reference: https://go.microsoft.com/fwlink/?LinkID=787136.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Microsoft network client: Digitally sign communications (if server agrees)</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MicrosoftNetworkClient_SendUnencryptedPasswordToThirdPartySMBServers</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Microsoft network client: Send unencrypted password to connect to third-party SMB servers

If this security setting is enabled, the Server Message Block (SMB) redirector is allowed to send plaintext passwords to non-Microsoft SMB servers that do not support password encryption during authentication.

Sending unencrypted passwords is a security risk.

Default: Disabled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Microsoft network client: Send unencrypted password to third-party SMB servers</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MicrosoftNetworkServer_AmountOfIdleTimeRequiredBeforeSuspendingSession</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>15</DefaultValue>
            <Description>Microsoft network server: Amount of idle time required before suspending a session

This security setting determines the amount of continuous idle time that must pass in a Server Message Block (SMB) session before the session is suspended due to inactivity.

Administrators can use this policy to control when a computer suspends an inactive SMB session. If client activity resumes, the session is automatically reestablished.

For this policy setting, a value of 0 means to disconnect an idle session as quickly as is reasonably possible. The maximum value is 99999, which is 208 days; in effect, this value disables the policy.

Default:This policy is not defined, which means that the system treats it as 15 minutes for servers and undefined for workstations.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="99999"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Microsoft network server: Amount of idle time required before suspending session</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MicrosoftNetworkServer_DigitallySignCommunicationsAlways</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Microsoft network server: Digitally sign communications (always)

This security setting determines whether packet signing is required by the SMB server component.

The server message block (SMB) protocol provides the basis for Microsoft file and print sharing and many other networking operations, such as remote Windows administration. To prevent man-in-the-middle attacks that modify SMB packets in transit, the SMB protocol supports the digital signing of SMB packets. This policy setting determines whether SMB packet signing must be negotiated before further communication with an SMB client is permitted.

If this setting is enabled, the Microsoft network server will not communicate with a Microsoft network client unless that client agrees to perform SMB packet signing. If this setting is disabled, SMB packet signing is negotiated between the client and server.

Default:

Disabled for member servers.
Enabled for domain controllers.

Notes

All Windows operating systems support both a client-side SMB component and a server-side SMB component. On Windows 2000 and later, enabling or requiring packet signing for client and server-side SMB components is controlled by the following four policy settings:
Microsoft network client: Digitally sign communications (always) - Controls whether or not the client-side SMB component requires packet signing.
Microsoft network client: Digitally sign communications (if server agrees) - Controls whether or not the client-side SMB component has packet signing enabled.
Microsoft network server: Digitally sign communications (always) - Controls whether or not the server-side SMB component requires packet signing.
Microsoft network server: Digitally sign communications (if client agrees) - Controls whether or not the server-side SMB component has packet signing enabled.
Similarly, if client-side SMB signing is required, that client will not be able to establish a session with servers that do not have packet signing enabled. By default, server-side SMB signing is enabled only on domain controllers.
If server-side SMB signing is enabled, SMB packet signing will be negotiated with clients that have client-side SMB signing enabled.
SMB packet signing can significantly degrade SMB performance, depending on dialect version, OS version, file sizes, processor offloading capabilities, and application IO behaviors.

Important

For this policy to take effect on computers running Windows 2000, server-side packet signing must also be enabled. To enable server-side SMB packet signing, set the following policy:
Microsoft network server: Digitally sign communications (if server agrees)

For Windows 2000 servers to negotiate signing with Windows NT 4.0 clients, the following registry value must be set to 1 on the Windows 2000 server:
HKLM\System\CurrentControlSet\Services\lanmanserver\parameters\enableW9xsecuritysignature
For more information, reference: https://go.microsoft.com/fwlink/?LinkID=787136.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Microsoft network server: Digitally sign communications (always)</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MicrosoftNetworkServer_DigitallySignCommunicationsIfClientAgrees</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Microsoft network server: Digitally sign communications (if client agrees)

This security setting determines whether the SMB server will negotiate SMB packet signing with clients that request it.

The server message block (SMB) protocol provides the basis for Microsoft file and print sharing and many other networking operations, such as remote Windows administration. To prevent man-in-the-middle attacks that modify SMB packets in transit, the SMB protocol supports the digital signing of SMB packets. This policy setting determines whether the SMB server will negotiate SMB packet signing when an SMB client requests it.

If this setting is enabled, the Microsoft network server will negotiate SMB packet signing as requested by the client. That is, if packet signing has been enabled on the client, packet signing will be negotiated. If this policy is disabled, the SMB client will never negotiate SMB packet signing.

Default: Enabled on domain controllers only.

Important

For Windows 2000 servers to negotiate signing with Windows NT 4.0 clients, the following registry value must be set to 1 on the server running Windows 2000: HKLM\System\CurrentControlSet\Services\lanmanserver\parameters\enableW9xsecuritysignature

Notes

All Windows operating systems support both a client-side SMB component and a server-side SMB component. For Windows 2000 and above, enabling or requiring packet signing for client and server-side SMB components is controlled by the following four policy settings:
Microsoft network client: Digitally sign communications (always) - Controls whether or not the client-side SMB component requires packet signing.
Microsoft network client: Digitally sign communications (if server agrees) - Controls whether or not the client-side SMB component has packet signing enabled.
Microsoft network server: Digitally sign communications (always) - Controls whether or not the server-side SMB component requires packet signing.
Microsoft network server: Digitally sign communications (if client agrees) - Controls whether or not the server-side SMB component has packet signing enabled.
If both client-side and server-side SMB signing is enabled and the client establishes an SMB 1.0 connection to the server, SMB signing will be attempted.
SMB packet signing can significantly degrade SMB performance, depending on dialect version, OS version, file sizes, processor offloading capabilities, and application IO behaviors. This setting only applies to SMB 1.0 connections.
For more information, reference: https://go.microsoft.com/fwlink/?LinkID=787136.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Microsoft network server: Digitally sign communications (if client agrees)</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NetworkAccess_DoNotAllowAnonymousEnumerationOfSAMAccounts</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>Network access: Do not allow anonymous enumeration of SAM accounts

This security setting determines what additional permissions will be granted for anonymous connections to the computer.

Windows allows anonymous users to perform certain activities, such as enumerating the names of domain accounts and network shares. This is convenient, for example, when an administrator wants to grant access to users in a trusted domain that does not maintain a reciprocal trust.

This security option allows additional restrictions to be placed on anonymous connections as follows:

Enabled: Do not allow enumeration of SAM accounts. This option replaces Everyone with Authenticated Users in the security permissions for resources.
Disabled: No additional restrictions. Rely on default permissions.

Default on workstations: Enabled.
Default on server:Enabled.

Important

This policy has no impact on domain controllers.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Network access: Do not allow anonymous enumeration of SAM accounts</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NetworkAccess_DoNotAllowAnonymousEnumerationOfSamAccountsAndShares</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Network access: Do not allow anonymous enumeration of SAM accounts and shares

This security setting determines whether anonymous enumeration of SAM accounts and shares is allowed.

Windows allows anonymous users to perform certain activities, such as enumerating the names of domain accounts and network shares. This is convenient, for example, when an administrator wants to grant access to users in a trusted domain that does not maintain a reciprocal trust. If you do not want to allow anonymous enumeration of SAM accounts and shares, then enable this policy.

Default: Disabled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Network access: Do not allow anonymous enumeration of SAM accounts and shares</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NetworkAccess_RestrictAnonymousAccessToNamedPipesAndShares</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>Network access: Restrict anonymous access to Named Pipes and Shares

When enabled, this security setting restricts anonymous access to shares and pipes to the settings for:

Network access: Named pipes that can be accessed anonymously
Network access: Shares that can be accessed anonymously
Default: Enabled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Network access: Restrict anonymous access to Named Pipes and Shares</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NetworkAccess_RestrictClientsAllowedToMakeRemoteCallsToSAM</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>Network access: Restrict clients allowed to make remote calls to SAM

This policy setting allows you to restrict remote rpc connections to SAM.

If not selected, the default security descriptor will be used.

This policy is supported on at least Windows Server 2016.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Network access: Restrict clients allowed to make remote calls to SAM</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NetworkSecurity_AllowPKU2UAuthenticationRequests</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>Network security: Allow PKU2U authentication requests to this computer to use online identities.

This policy will be turned off by default on domain joined machines. This would prevent online identities from authenticating to the domain joined machine.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Network security: Allow PKU2U authentication requests to this computer to use online identities.</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NetworkSecurity_DoNotStoreLANManagerHashValueOnNextPasswordChange</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>Network security: Do not store LAN Manager hash value on next password change

This security setting determines if, at the next password change, the LAN Manager (LM) hash value for the new password is stored. The LM hash is relatively weak and prone to attack, as compared with the cryptographically stronger Windows NT hash. Since the LM hash is stored on the local computer in the security database the passwords can be compromised if the security database is attacked.


Default on Windows Vista and above: Enabled
Default on Windows XP: Disabled.

Important

Windows 2000 Service Pack 2 (SP2) and above offer compatibility with authentication to previous versions of Windows, such as Microsoft Windows NT 4.0.
This setting can affect the ability of computers running Windows 2000 Server, Windows 2000 Professional, Windows XP, and the Windows Server 2003 family to communicate with computers running Windows 95 and Windows 98.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Network security: Do not store LAN Manager hash value on next password change</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NetworkSecurity_LANManagerAuthenticationLevel</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Network security LAN Manager authentication level

This security setting determines which challenge/response authentication protocol is used for network logons. This choice affects the level of authentication protocol used by clients, the level of session security negotiated, and the level of authentication accepted by servers as follows:

Send LM and NTLM responses: Clients use LM and NTLM authentication and never use NTLMv2 session security; domain controllers accept LM, NTLM, and NTLMv2 authentication.

Send LM and NTLM - use NTLMv2 session security if negotiated: Clients use LM and NTLM authentication and use NTLMv2 session security if the server supports it; domain controllers accept LM, NTLM, and NTLMv2 authentication.

Send NTLM response only: Clients use NTLM authentication only and use NTLMv2 session security if the server supports it; domain controllers accept LM, NTLM, and NTLMv2 authentication.

Send NTLMv2 response only: Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it; domain controllers accept LM, NTLM, and NTLMv2 authentication.

Send NTLMv2 response only\refuse LM: Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it; domain controllers refuse LM (accept only NTLM and NTLMv2 authentication).

Send NTLMv2 response only\refuse LM and NTLM: Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it; domain controllers refuse LM and NTLM (accept only NTLMv2 authentication).

Important

This setting can affect the ability of computers running Windows 2000 Server, Windows 2000 Professional, Windows XP Professional, and the Windows Server 2003 family to communicate with computers running Windows NT 4.0 and earlier over the network. For example, at the time of this writing, computers running Windows NT 4.0 SP4 and earlier did not support NTLMv2. Computers running Windows 95 and Windows 98 did not support NTLM.

Default:

Windows 2000 and windows XP: send LM and NTLM responses

Windows Server 2003: Send NTLM response only

Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2: Send NTLMv2 response only</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="5"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Network security: LAN Manager authentication level</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NetworkSecurity_MinimumSessionSecurityForNTLMSSPBasedServers</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Network security: Minimum session security for NTLM SSP based (including secure RPC) servers

This security setting allows a server to require the negotiation of 128-bit encryption and/or NTLMv2 session security. These values are dependent on the LAN Manager Authentication Level security setting value. The options are:

Require NTLMv2 session security: The connection will fail if message integrity is not negotiated.
Require 128-bit encryption. The connection will fail if strong encryption (128-bit) is not negotiated.

Default:

Windows XP, Windows Vista, Windows 2000 Server, Windows Server 2003, and Windows Server 2008: No requirements.

Windows 7 and Windows Server 2008 R2: Require 128-bit encryption</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="0,524288,536870912,537395200"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Network security: Minimum session security for NTLM SSP based (including secure RPC) servers</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NetworkSecurity_RestrictNTLM_AddRemoteServerExceptionsForNTLMAuthentication</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>Network security: Restrict NTLM: Add remote server exceptions for NTLM authentication

This policy setting allows you to create an exception list of remote servers to which clients are allowed to use NTLM authentication if the  "Network Security: Restrict NTLM: Outgoing NTLM traffic to remote servers" policy setting is configured.

If you configure this policy setting, you can define a list of remote servers to which clients are allowed to use NTLM authentication.

If you do not configure this policy setting, no exceptions will be applied.

The naming format for servers on this exception list is the fully qualified domain name (FQDN) or NetBIOS server name used by the application, listed one per line. To ensure exceptions the name used by all applications needs to be in the list, and to ensure an exception is accurate, the server name should be listed in both naming formats . A single asterisk (*) can be used anywhere in the string as a wildcard character.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Network security: Restrict NTLM: Add remote server exceptions for NTLM authentication</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NetworkSecurity_RestrictNTLM_AuditIncomingNTLMTraffic</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Network security: Restrict NTLM: Audit Incoming NTLM Traffic

This policy setting allows you to audit incoming NTLM traffic.

If you select "Disable", or do not configure this policy setting, the server will not log events for incoming NTLM traffic.

If you select "Enable auditing for domain accounts", the server will log events for NTLM pass-through authentication requests that would be blocked when the "Network Security: Restrict NTLM: Incoming NTLM traffic" policy setting is set to the "Deny all domain accounts" option.

If you select "Enable auditing for all accounts", the server will log events for all NTLM authentication requests that would be blocked when the "Network Security: Restrict NTLM: Incoming NTLM traffic" policy setting is set to the "Deny all accounts" option.

This policy is supported on at least Windows 7 or Windows Server 2008 R2.

Note: Audit events are recorded on this computer in the "Operational" Log located under the Applications and Services Log/Microsoft/Windows/NTLM.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Network security: Restrict NTLM: Audit Incoming NTLM Traffic</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NetworkSecurity_RestrictNTLM_IncomingNTLMTraffic</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Network security: Restrict NTLM: Incoming NTLM traffic

This policy setting allows you to deny or allow incoming NTLM traffic.

If you select "Allow all" or do not configure this policy setting, the server will allow all NTLM authentication requests.

If you select "Deny all domain accounts," the server will deny NTLM authentication requests for domain logon and display an NTLM blocked error, but allow local account logon.

If you select "Deny all accounts," the server will deny NTLM authentication requests from incoming traffic and display an NTLM blocked error.

This policy is supported on at least Windows 7 or Windows Server 2008 R2.

Note: Block events are recorded on this computer in the "Operational" Log located under the Applications and Services Log/Microsoft/Windows/NTLM.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Network security: Restrict NTLM: Incoming NTLM traffic</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NetworkSecurity_RestrictNTLM_OutgoingNTLMTrafficToRemoteServers</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers

This policy setting allows you to deny or audit outgoing NTLM traffic from this Windows 7 or this Windows Server 2008 R2 computer to any Windows remote server.

If you select "Allow all" or do not configure this policy setting, the client computer can authenticate identities to a remote server by using NTLM authentication.

If you select "Audit all," the client computer logs an event for each NTLM authentication request to a remote server. This allows you to identify those servers receiving NTLM authentication requests from the client computer.

If you select "Deny all," the client computer cannot authenticate identities to a remote server by using NTLM authentication. You can use the "Network security: Restrict NTLM: Add remote server exceptions for NTLM authentication" policy setting to define a list of remote servers to which clients are allowed to use NTLM authentication.

This policy is supported on at least Windows 7 or Windows Server 2008 R2.

Note: Audit and block events are recorded on this computer in the "Operational" Log located under the Applications and Services Log/Microsoft/Windows/NTLM.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>Shutdown_AllowSystemToBeShutDownWithoutHavingToLogOn</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>Shutdown: Allow system to be shut down without having to log on

This security setting determines whether a computer can be shut down without having to log on to Windows.

When this policy is enabled, the Shut Down command is available on the Windows logon screen.

When this policy is disabled, the option to shut down the computer does not appear on the Windows logon screen. In this case, users must be able to log on to the computer successfully and have the Shut down the system user right before they can perform a system shutdown.

Default on workstations: Enabled.
Default on servers: Disabled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Shutdown: Allow system to be shut down without having to log on</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>Shutdown_ClearVirtualMemoryPageFile</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Shutdown: Clear virtual memory pagefile

This security setting determines whether the virtual memory pagefile is cleared when the system is shut down.

Virtual memory support uses a system pagefile to swap pages of memory to disk when they are not used. On a running system, this pagefile is opened exclusively by the operating system, and it is well protected. However, systems that are configured to allow booting to other operating systems might have to make sure that the system pagefile is wiped clean when this system shuts down. This ensures that sensitive information from process memory that might go into the pagefile is not available to an unauthorized user who manages to directly access the pagefile.

When this policy is enabled, it causes the system pagefile to be cleared upon clean shutdown. If you enable this security option, the hibernation file (hiberfil.sys) is also zeroed out when hibernation is disabled.

Default: Disabled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>Shutdown: Clear virtual memory pagefile</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UserAccountControl_AllowUIAccessApplicationsToPromptForElevation</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>User Account Control: Allow UIAccess applications to prompt for elevation without using the secure desktop.

This policy setting controls whether User Interface Accessibility (UIAccess or UIA) programs can automatically disable the secure desktop for elevation prompts used by a standard user.

• Enabled: UIA programs, including Windows Remote Assistance, automatically disable the secure desktop for elevation prompts. If you do not disable the "User Account Control: Switch to the secure desktop when prompting for elevation" policy setting, the prompts appear on the interactive user's desktop instead of the secure desktop.

• Disabled: (Default) The secure desktop can be disabled only by the user of the interactive desktop or by disabling the "User Account Control: Switch to the secure desktop when prompting for elevation" policy setting.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>User Account Control: Allow UIAccess applications to prompt for elevation without using the secure desktop</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UserAccountControl_BehaviorOfTheElevationPromptForAdministrators</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>5</DefaultValue>
            <Description>User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode

This policy setting controls the behavior of the elevation prompt for administrators.

The options are:

• Elevate without prompting: Allows privileged accounts to perform an operation that requires elevation without requiring consent or credentials. Note: Use this option only in the most constrained environments.

• Prompt for credentials on the secure desktop: When an operation requires elevation of privilege, the user is prompted on the secure desktop to enter a privileged user name and password. If the user enters valid credentials, the operation continues with the user's highest available privilege.

• Prompt for consent on the secure desktop: When an operation requires elevation of privilege, the user is prompted on the secure desktop to select either Permit or Deny. If the user selects Permit, the operation continues with the user's highest available privilege.

• Prompt for credentials: When an operation requires elevation of privilege, the user is prompted to enter an administrative user name and password. If the user enters valid credentials, the operation continues with the applicable privilege.

• Prompt for consent: When an operation requires elevation of privilege, the user is prompted to select either Permit or Deny. If the user selects Permit, the operation continues with the user's highest available privilege.

• Prompt for consent for non-Windows binaries: (Default) When an operation for a non-Microsoft application requires elevation of privilege, the user is prompted on the secure desktop to select either Permit or Deny. If the user selects Permit, the operation continues with the user's highest available privilege.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="5"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UserAccountControl_BehaviorOfTheElevationPromptForStandardUsers</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>3</DefaultValue>
            <Description>User Account Control: Behavior of the elevation prompt for standard users
This policy setting controls the behavior of the elevation prompt for standard users.

The options are:

• Prompt for credentials: (Default) When an operation requires elevation of privilege, the user is prompted to enter an administrative user name and password. If the user enters valid credentials, the operation continues with the applicable privilege.

• Automatically deny elevation requests: When an operation requires elevation of privilege, a configurable access denied error message is displayed. An enterprise that is running desktops as standard user may choose this setting to reduce help desk calls.

• Prompt for credentials on the secure desktop: When an operation requires elevation of privilege, the user is prompted on the secure desktop to enter a different user name and password. If the user enters valid credentials, the operation continues with the applicable privilege.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="0,1,3"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>User Account Control: Behavior of the elevation prompt for standard users</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UserAccountControl_DetectApplicationInstallationsAndPromptForElevation</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>User Account Control: Detect application installations and prompt for elevation

This policy setting controls the behavior of application installation detection for the computer.

The options are:

Enabled: (Default) When an application installation package is detected that requires elevation of privilege, the user is prompted to enter an administrative user name and password. If the user enters valid credentials, the operation continues with the applicable privilege.

Disabled: Application installation packages are not detected and prompted for elevation. Enterprises that are running standard user desktops and use delegated installation technologies such as Group Policy Software Installation or Systems Management Server (SMS) should disable this policy setting. In this case, installer detection is unnecessary.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>User Account Control: Detect application installations and prompt for elevation</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UserAccountControl_OnlyElevateExecutableFilesThatAreSignedAndValidated</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>User Account Control: Only elevate executable files that are signed and validated

This policy setting enforces public key infrastructure (PKI) signature checks for any interactive applications that request elevation of privilege. Enterprise administrators can control which applications are allowed to run by adding certificates to the Trusted Publishers certificate store on local computers.

The options are:

• Enabled: Enforces the PKI certification path validation for a given executable file before it is permitted to run.

• Disabled: (Default) Does not enforce PKI certification path validation before a given executable file is permitted to run.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>User Account Control: Only elevate executables that are signed and validated</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UserAccountControl_OnlyElevateUIAccessApplicationsThatAreInstalledInSecureLocations</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>User Account Control: Only elevate UIAccess applications that are installed in secure locations

This policy setting controls whether applications that request to run with a User Interface Accessibility (UIAccess) integrity level must reside in a secure location in the file system. Secure locations are limited to the following:

- …\Program Files\, including subfolders
- …\Windows\system32\
- …\Program Files (x86)\, including subfolders for 64-bit versions of Windows

Note: Windows enforces a public key infrastructure (PKI) signature check on any interactive application that requests to run with a UIAccess integrity level regardless of the state of this security setting.

The options are:

• Enabled: (Default) If an application resides in a secure location in the file system, it runs only with UIAccess integrity.

• Disabled: An application runs with UIAccess integrity even if it does not reside in a secure location in the file system.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>User Account Control: Only elevate UIAccess applications that are installed in secure locations</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UserAccountControl_RunAllAdministratorsInAdminApprovalMode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>User Account Control: Turn on Admin Approval Mode

This policy setting controls the behavior of all User Account Control (UAC) policy settings for the computer. If you change this policy setting, you must restart your computer.

The options are:

• Enabled: (Default) Admin Approval Mode is enabled. This policy must be enabled and related UAC policy settings must also be set appropriately to allow the built-in Administrator account and all other users who are members of the Administrators group to run in Admin Approval Mode. 

• Disabled: Admin Approval Mode and all related UAC policy settings are disabled. Note: If this policy setting is disabled, the Security Center notifies you that the overall security of the operating system has been reduced.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>User Account Control: Run all administrators in Admin Approval Mode</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UserAccountControl_SwitchToTheSecureDesktopWhenPromptingForElevation</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>User Account Control: Switch to the secure desktop when prompting for elevation

This policy setting controls whether the elevation request prompt is displayed on the interactive user's desktop or the secure desktop.

The options are:

• Enabled: (Default) All elevation requests go to the secure desktop regardless of prompt behavior policy settings for administrators and standard users.

• Disabled: All elevation requests go to the interactive user's desktop. Prompt behavior policy settings for administrators and standard users are used.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>User Account Control: Switch to the secure desktop when prompting for elevation</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UserAccountControl_UseAdminApprovalMode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>User Account Control: Use Admin Approval Mode for the built-in Administrator account

This policy setting controls the behavior of Admin Approval Mode for the built-in Administrator account.

The options are:

• Enabled: The built-in Administrator account uses Admin Approval Mode. By default, any operation that requires elevation of privilege will prompt the user to approve the operation.

• Disabled: (Default) The built-in Administrator account runs all applications with full administrative privilege.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>User Account Control: Admin Approval Mode for the Built-in Administrator account</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UserAccountControl_VirtualizeFileAndRegistryWriteFailuresToPerUserLocations</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>User Account Control: Virtualize file and registry write failures to per-user locations

This policy setting controls whether application write failures are redirected to defined registry and file system locations. This policy setting mitigates applications that run as administrator and write run-time application data to %ProgramFiles%, %Windir%, %Windir%\system32, or HKLM\Software.

The options are:

• Enabled: (Default) Application write failures are redirected at run time to defined user locations for both the file system and registry.

• Disabled: Applications that write data to protected locations fail.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPRegistryMappedCategory>Windows Settings~Security Settings~Local Policies~Security Options</MSFT:GPRegistryMappedCategory>
            <MSFT:GPRegistryMappedName>User Account Control: Virtualize file and registry write failures to per-user locations</MSFT:GPRegistryMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Location</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>EnableLocation</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>LocationProviderAdm.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>LocationProviderAdm~AT~LocationAndSensors~WindowsLocationProvider</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableWindowsLocationProvider_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>LockDown</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowEdgeSwipe</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>EdgeUI.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>EdgeUI~AT~WindowsComponents~EdgeUI</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowEdgeSwipe</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Maps</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowOfflineMapsDownloadOverMeteredConnection</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>65535</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="0,1,65535"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableOfflineMapsAutoUpdate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>65535</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="0,1,65535"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WinMaps.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WinMaps~AT~WindowsComponents~Maps</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>TurnOffAutoUpdate</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Messaging</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowMessageSync</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This policy setting allows backup and restore of cellular text messages to Microsoft's cloud services.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>messaging.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>messaging~AT~WindowsComponents~Messaging_Category</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowMessageSync</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowMMS</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This policy setting allows you to enable or disable the sending and receiving cellular MMS messages.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>desktop</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowRCS</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This policy setting allows you to enable or disable the sending and receiving of cellular RCS (Rich Communication Services) messages.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>desktop</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>MSSecurityGuide</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>ApplyUACRestrictionsToLocalAccountsOnNetworkLogon</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>SecGuide.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>SecGuide~AT~Cat_SecGuide</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Pol_SecGuide_0201_LATFP</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConfigureSMBV1ClientDriver</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>SecGuide.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>SecGuide~AT~Cat_SecGuide</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Pol_SecGuide_0002_SMBv1_ClientDriver</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConfigureSMBV1Server</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>SecGuide.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>SecGuide~AT~Cat_SecGuide</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Pol_SecGuide_0001_SMBv1_Server</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableStructuredExceptionHandlingOverwriteProtection</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>SecGuide.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>SecGuide~AT~Cat_SecGuide</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Pol_SecGuide_0102_SEHOP</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TurnOnWindowsDefenderProtectionAgainstPotentiallyUnwantedApplications</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>SecGuide.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>SecGuide~AT~Cat_SecGuide</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Pol_SecGuide_0101_WDPUA</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>WDigestAuthentication</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>SecGuide.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>SecGuide~AT~Cat_SecGuide</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Pol_SecGuide_0202_WDigestAuthn</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>MSSLegacy</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowICMPRedirectsToOverrideOSPFGeneratedRoutes</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>mss-legacy.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>Mss-legacy~AT~Cat_MSS</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Pol_MSS_EnableICMPRedirect</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowTheComputerToIgnoreNetBIOSNameReleaseRequestsExceptFromWINSServers</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>mss-legacy.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>Mss-legacy~AT~Cat_MSS</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Pol_MSS_NoNameReleaseOnDemand</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IPSourceRoutingProtectionLevel</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>mss-legacy.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>Mss-legacy~AT~Cat_MSS</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Pol_MSS_DisableIPSourceRouting</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IPv6SourceRoutingProtectionLevel</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>mss-legacy.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>Mss-legacy~AT~Cat_MSS</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Pol_MSS_DisableIPSourceRoutingIPv6</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>NetworkIsolation</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>EnterpriseCloudResources</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>NetworkIsolation.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>WF_NetIsolation_EnterpriseCloudResourcesBox</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>NetworkIsolation~AT~Network~WF_Isolation</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>WF_NetIsolation_EnterpriseCloudResources</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnterpriseInternalProxyServers</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>NetworkIsolation.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>WF_NetIsolation_Intranet_ProxiesBox</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>NetworkIsolation~AT~Network~WF_Isolation</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>WF_NetIsolation_Intranet_Proxies</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnterpriseIPRange</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>NetworkIsolation.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>WF_NetIsolation_PrivateSubnetBox</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>NetworkIsolation~AT~Network~WF_Isolation</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>WF_NetIsolation_PrivateSubnet</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnterpriseIPRangesAreAuthoritative</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>NetworkIsolation.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>NetworkIsolation~AT~Network~WF_Isolation</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>WF_NetIsolation_Authoritative_Subnet</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnterpriseNetworkDomainNames</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnterpriseProxyServers</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>NetworkIsolation.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>WF_NetIsolation_Domain_ProxiesBox</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>NetworkIsolation~AT~Network~WF_Isolation</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>WF_NetIsolation_Domain_Proxies</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnterpriseProxyServersAreAuthoritative</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>NetworkIsolation.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>NetworkIsolation~AT~Network~WF_Isolation</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>WF_NetIsolation_Authoritative_Proxies</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NeutralResources</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>NetworkIsolation.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>WF_NetIsolation_NeutralResourcesBox</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>NetworkIsolation~AT~Network~WF_Isolation</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>WF_NetIsolation_NeutralResources</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Notifications</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>DisallowCloudNotification</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WPN.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WPN~AT~StartMenu~NotificationsCategory</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>NoCloudNotification</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Power</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowStandbyStatesWhenSleepingOnBattery</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>power.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>Power~AT~System~PowerManagementCat~PowerSleepSettingsCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowStandbyStatesDC_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowStandbyWhenSleepingPluggedIn</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>power.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>Power~AT~System~PowerManagementCat~PowerSleepSettingsCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowStandbyStatesAC_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisplayOffTimeoutOnBattery</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>power.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>Power~AT~System~PowerManagementCat~PowerVideoSettingsCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>VideoPowerDownTimeOutDC_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisplayOffTimeoutPluggedIn</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>power.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>Power~AT~System~PowerManagementCat~PowerVideoSettingsCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>VideoPowerDownTimeOutAC_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HibernateTimeoutOnBattery</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>power.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>Power~AT~System~PowerManagementCat~PowerSleepSettingsCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DCHibernateTimeOut_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HibernateTimeoutPluggedIn</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>power.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>Power~AT~System~PowerManagementCat~PowerSleepSettingsCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ACHibernateTimeOut_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RequirePasswordWhenComputerWakesOnBattery</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>power.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>Power~AT~System~PowerManagementCat~PowerSleepSettingsCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DCPromptForPasswordOnResume_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RequirePasswordWhenComputerWakesPluggedIn</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>power.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>Power~AT~System~PowerManagementCat~PowerSleepSettingsCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ACPromptForPasswordOnResume_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>StandbyTimeoutOnBattery</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>power.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>Power~AT~System~PowerManagementCat~PowerSleepSettingsCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DCStandbyTimeOut_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>StandbyTimeoutPluggedIn</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>power.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>Power~AT~System~PowerManagementCat~PowerSleepSettingsCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ACStandbyTimeOut_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Printers</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>PointAndPrintRestrictions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>Printing.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>Printing~AT~ControlPanel~CplPrinters</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>PointAndPrint_Restrictions_Win7</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PublishPrinters</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>Printing2.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>Printing2~AT~Printers</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>PublishPrinters</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Privacy</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowAutoAcceptPairingAndPrivacyConsentPrompts</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowInputPersonalization</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:StartOSVerison>10.0.10240</MSFT:StartOSVerison>
            <MSFT:ADMXMapped>Globalization.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>Globalization~AT~ControlPanel~RegionalOptions</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowInputPersonalization</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableAdvertisingId</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>65535</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="0,1,65535"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>UserProfiles.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>UserProfiles~AT~System~UserProfiles</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableAdvertisingId</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecureZeroHasNoLimits</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableActivityFeed</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>Enables ActivityFeed, which is responsible for mirroring different activity types (as applicable) across device graph of the user.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>OSPolicy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>OSPolicy~AT~System~PolicyPolicies</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>EnableActivityFeed</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessAccountInfo</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy setting specifies whether Windows apps can access account information.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessAccountInfo_Enum</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessAccountInfo</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessAccountInfo_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are allowed access to account information. This setting overrides the default LetAppsAccessAccountInfo policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessAccountInfo_ForceAllowTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessAccountInfo</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessAccountInfo_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are denied access to account information. This setting overrides the default LetAppsAccessAccountInfo policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessAccountInfo_ForceDenyTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessAccountInfo</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessAccountInfo_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. The user is able to control the account information privacy setting for the listed Windows apps. This setting overrides the default LetAppsAccessAccountInfo policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessAccountInfo_UserInControlOfTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessAccountInfo</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCalendar</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy setting specifies whether Windows apps can access the calendar.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessCalendar_Enum</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessCalendar</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCalendar_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are allowed access to the calendar. This setting overrides the default LetAppsAccessCalendar policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessCalendar_ForceAllowTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessCalendar</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCalendar_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are denied access to the calendar. This setting overrides the default LetAppsAccessCalendar policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessCalendar_ForceDenyTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessCalendar</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCalendar_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. The user is able to control the calendar privacy setting for the listed Windows apps. This setting overrides the default LetAppsAccessCalendar policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessCalendar_UserInControlOfTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessCalendar</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCallHistory</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy setting specifies whether Windows apps can access call history.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessCallHistory_Enum</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessCallHistory</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCallHistory_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are allowed access to call history. This setting overrides the default LetAppsAccessCallHistory policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessCallHistory_ForceAllowTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessCallHistory</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCallHistory_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are denied access to call history. This setting overrides the default LetAppsAccessCallHistory policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessCallHistory_ForceDenyTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessCallHistory</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCallHistory_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. The user is able to control the call history privacy setting for the listed Windows apps. This setting overrides the default LetAppsAccessCallHistory policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessCallHistory_UserInControlOfTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessCallHistory</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCamera</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy setting specifies whether Windows apps can access the camera.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessCamera_Enum</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessCamera</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCamera_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are allowed access to the camera. This setting overrides the default LetAppsAccessCamera policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessCamera_ForceAllowTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessCamera</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCamera_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are denied access to the camera. This setting overrides the default LetAppsAccessCamera policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessCamera_ForceDenyTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessCamera</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessCamera_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the camera privacy setting for the listed apps. This setting overrides the default LetAppsAccessCamera policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessCamera_UserInControlOfTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessCamera</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessContacts</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy setting specifies whether Windows apps can access contacts.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessContacts_Enum</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessContacts</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessContacts_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are allowed access to contacts. This setting overrides the default LetAppsAccessContacts policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessContacts_ForceAllowTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessContacts</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessContacts_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are denied access to contacts. This setting overrides the default LetAppsAccessContacts policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessContacts_ForceDenyTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessContacts</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessContacts_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the contacts privacy setting for the listed apps. This setting overrides the default LetAppsAccessContacts policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessContacts_UserInControlOfTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessContacts</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessEmail</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy setting specifies whether Windows apps can access email.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessEmail_Enum</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessEmail</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessEmail_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are allowed access to email. This setting overrides the default LetAppsAccessEmail policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessEmail_ForceAllowTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessEmail</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessEmail_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are denied access to email. This setting overrides the default LetAppsAccessEmail policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessEmail_ForceDenyTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessEmail</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessEmail_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the email privacy setting for the listed apps. This setting overrides the default LetAppsAccessEmail policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessEmail_UserInControlOfTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessEmail</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessGazeInput</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy setting specifies whether Windows apps can access the eye tracker.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessGazeInput_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Windows Store Apps. Listed apps are allowed access to the eye tracker. This setting overrides the default LetAppsAccessGazeInput policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessGazeInput_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Windows Store Apps. Listed apps are denied access to the eye tracker. This setting overrides the default LetAppsAccessGazeInput policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessGazeInput_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Windows Store Apps. The user is able to control the eye tracker privacy setting for the listed apps. This setting overrides the default LetAppsAccessGazeInput policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessLocation</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy setting specifies whether Windows apps can access location.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessLocation_Enum</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessLocation</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessLocation_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are allowed access to location. This setting overrides the default LetAppsAccessLocation policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessLocation_ForceAllowTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessLocation</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessLocation_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are denied access to location. This setting overrides the default LetAppsAccessLocation policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessLocation_ForceDenyTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessLocation</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessLocation_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the location privacy setting for the listed apps. This setting overrides the default LetAppsAccessLocation policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessLocation_UserInControlOfTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessLocation</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessMessaging</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy setting specifies whether Windows apps can read or send messages (text or MMS).</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessMessaging_Enum</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessMessaging</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessMessaging_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are allowed to read or send messages (text or MMS). This setting overrides the default LetAppsAccessMessaging policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessMessaging_ForceAllowTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessMessaging</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessMessaging_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are not allowed to read or send messages (text or MMS). This setting overrides the default LetAppsAccessMessaging policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessMessaging_ForceDenyTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessMessaging</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessMessaging_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the messaging privacy setting for the listed apps. This setting overrides the default LetAppsAccessMessaging policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessMessaging_UserInControlOfTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessMessaging</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessMicrophone</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy setting specifies whether Windows apps can access the microphone.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessMicrophone_Enum</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessMicrophone</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessMicrophone_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are allowed access to the microphone. This setting overrides the default LetAppsAccessMicrophone policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessMicrophone_ForceAllowTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessMicrophone</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessMicrophone_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are denied access to the microphone. This setting overrides the default LetAppsAccessMicrophone policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessMicrophone_ForceDenyTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessMicrophone</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessMicrophone_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the microphone privacy setting for the listed apps. This setting overrides the default LetAppsAccessMicrophone policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessMicrophone_UserInControlOfTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessMicrophone</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessMotion</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy setting specifies whether Windows apps can access motion data.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessMotion_Enum</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessMotion</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessMotion_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are allowed access to motion data. This setting overrides the default LetAppsAccessMotion policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessMotion_ForceAllowTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessMotion</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessMotion_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are denied access to motion data. This setting overrides the default LetAppsAccessMotion policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessMotion_ForceDenyTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessMotion</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessMotion_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the motion privacy setting for the listed apps. This setting overrides the default LetAppsAccessMotion policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessMotion_UserInControlOfTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessMotion</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessNotifications</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy setting specifies whether Windows apps can access notifications.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessNotifications_Enum</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessNotifications</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessNotifications_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are allowed access to notifications. This setting overrides the default LetAppsAccessNotifications policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessNotifications_ForceAllowTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessNotifications</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessNotifications_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are denied access to notifications. This setting overrides the default LetAppsAccessNotifications policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessNotifications_ForceDenyTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessNotifications</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessNotifications_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the notifications privacy setting for the listed apps. This setting overrides the default LetAppsAccessNotifications policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessNotifications_UserInControlOfTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessNotifications</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessPhone</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy setting specifies whether Windows apps can make phone calls</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessPhone_Enum</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessPhone</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessPhone_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are allowed to make phone calls. This setting overrides the default LetAppsAccessPhone policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessPhone_ForceAllowTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessPhone</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessPhone_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are not allowed to make phone calls. This setting overrides the default LetAppsAccessPhone policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessPhone_ForceDenyTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessPhone</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessPhone_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the phone call privacy setting for the listed apps. This setting overrides the default LetAppsAccessPhone policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessPhone_UserInControlOfTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessPhone</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessRadios</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy setting specifies whether Windows apps have access to control radios.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessRadios_Enum</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessRadios</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessRadios_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps will have access to control radios. This setting overrides the default LetAppsAccessRadios policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessRadios_ForceAllowTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessRadios</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessRadios_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps will not have access to control radios. This setting overrides the default LetAppsAccessRadios policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessRadios_ForceDenyTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessRadios</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessRadios_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the radios privacy setting for the listed apps. This setting overrides the default LetAppsAccessRadios policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessRadios_UserInControlOfTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessRadios</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessTasks</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy setting specifies whether Windows apps can access tasks.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessTasks_Enum</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessTasks</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessTasks_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are allowed access to tasks. This setting overrides the default LetAppsAccessTasks policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessTasks_ForceAllowTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessTasks</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessTasks_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are denied access to tasks. This setting overrides the default LetAppsAccessTasks policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessTasks_ForceDenyTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessTasks</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessTasks_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the tasks privacy setting for the listed apps. This setting overrides the default LetAppsAccessTasks policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessTasks_UserInControlOfTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessTasks</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessTrustedDevices</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy setting specifies whether Windows apps can access trusted devices.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessTrustedDevices_Enum</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessTrustedDevices</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessTrustedDevices_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps will have access to trusted devices. This setting overrides the default LetAppsAccessTrustedDevices policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessTrustedDevices_ForceAllowTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessTrustedDevices</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessTrustedDevices_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps will not have access to trusted devices. This setting overrides the default LetAppsAccessTrustedDevices policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessTrustedDevices_ForceDenyTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessTrustedDevices</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsAccessTrustedDevices_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the 'trusted devices' privacy setting for the listed apps. This setting overrides the default LetAppsAccessTrustedDevices policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsAccessTrustedDevices_UserInControlOfTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsAccessTrustedDevices</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsGetDiagnosticInfo</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy setting specifies whether Windows apps can get diagnostic information about other apps, including user names.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsGetDiagnosticInfo_Enum</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsGetDiagnosticInfo</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsGetDiagnosticInfo_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are allowed to get diagnostic information about other apps, including user names. This setting overrides the default LetAppsGetDiagnosticInfo policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsGetDiagnosticInfo_ForceAllowTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsGetDiagnosticInfo</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsGetDiagnosticInfo_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are not allowed to get diagnostic information about other apps, including user names. This setting overrides the default LetAppsGetDiagnosticInfo policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsGetDiagnosticInfo_ForceDenyTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsGetDiagnosticInfo</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsGetDiagnosticInfo_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. The user is able to control the app diagnostics privacy setting for the listed Windows apps. This setting overrides the default LetAppsGetDiagnosticInfo policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsGetDiagnosticInfo_UserInControlOfTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsGetDiagnosticInfo</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsRunInBackground</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy setting specifies whether Windows apps can run in the background.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsRunInBackground_Enum</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsRunInBackground</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsRunInBackground_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are allowed to run in the background. This setting overrides the default LetAppsRunInBackground policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsRunInBackground_ForceAllowTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsRunInBackground</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsRunInBackground_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are not allowed to run in the background. This setting overrides the default LetAppsRunInBackground policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsRunInBackground_ForceDenyTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsRunInBackground</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsRunInBackground_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Windows apps. The user is able to control the background apps privacy setting for the listed Windows apps. This setting overrides the default LetAppsRunInBackground policy setting for the specified Windows apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsRunInBackground_UserInControlOfTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsRunInBackground</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsSyncWithDevices</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy setting specifies whether Windows apps can communicate with unpaired wireless devices.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsSyncWithDevices_Enum</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsSyncWithDevices</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsSyncWithDevices_ForceAllowTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps will be allowed to communicate with unpaired wireless devices. This setting overrides the default LetAppsSyncWithDevices policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsSyncWithDevices_ForceAllowTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsSyncWithDevices</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsSyncWithDevices_ForceDenyTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps will not be allowed to communicate with unpaired wireless devices. This setting overrides the default LetAppsSyncWithDevices policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsSyncWithDevices_ForceDenyTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsSyncWithDevices</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LetAppsSyncWithDevices_UserInControlOfTheseApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the 'Communicate with unpaired wireless devices' privacy setting for the listed apps. This setting overrides the default LetAppsSyncWithDevices policy setting for the specified apps.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>AppPrivacy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LetAppsSyncWithDevices_UserInControlOfTheseApps_List</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>AppPrivacy~AT~WindowsComponents~AppPrivacy</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LetAppsSyncWithDevices</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>;</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PublishUserActivities</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>Allows apps/system to publish 'User Activities' into ActivityFeed.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>OSPolicy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>OSPolicy~AT~System~PolicyPolicies</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>PublishUserActivities</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UploadUserActivities</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>Allows ActivityFeed to upload published 'User Activities'.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>OSPolicy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>OSPolicy~AT~System~PolicyPolicies</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>UploadUserActivities</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>RemoteAssistance</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>CustomizeWarningMessages</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>remoteassistance.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>RemoteAssistance~AT~System~RemoteAssist</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>RA_Options</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SessionLogging</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>remoteassistance.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>RemoteAssistance~AT~System~RemoteAssist</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>RA_Logging</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SolicitedRemoteAssistance</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>remoteassistance.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>RemoteAssistance~AT~System~RemoteAssist</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>RA_Solicit</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UnsolicitedRemoteAssistance</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>remoteassistance.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>RemoteAssistance~AT~System~RemoteAssist</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>RA_Unsolicit</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>RemoteDesktopServices</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowUsersToConnectRemotely</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>terminalserver.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>TerminalServer~AT~WindowsComponents~TS_GP_NODE~TS_TERMINAL_SERVER~TS_CONNECTIONS</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>TS_DISABLE_CONNECTIONS</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ClientConnectionEncryptionLevel</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>terminalserver.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>TerminalServer~AT~WindowsComponents~TS_GP_NODE~TS_TERMINAL_SERVER~TS_SECURITY</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>TS_ENCRYPTION_POLICY</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DoNotAllowDriveRedirection</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>terminalserver.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>TerminalServer~AT~WindowsComponents~TS_GP_NODE~TS_TERMINAL_SERVER~TS_REDIRECTION</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>TS_CLIENT_DRIVE_M</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DoNotAllowPasswordSaving</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>terminalserver.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>TerminalServer~AT~WindowsComponents~TS_GP_NODE~TS_CLIENT</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>TS_CLIENT_DISABLE_PASSWORD_SAVING_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PromptForPasswordUponConnection</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>terminalserver.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>TerminalServer~AT~WindowsComponents~TS_GP_NODE~TS_TERMINAL_SERVER~TS_SECURITY</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>TS_PASSWORD</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RequireSecureRPCCommunication</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>terminalserver.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>TerminalServer~AT~WindowsComponents~TS_GP_NODE~TS_TERMINAL_SERVER~TS_SECURITY</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>TS_RPC_ENCRYPTION</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>RemoteManagement</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowBasicAuthentication_Client</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>WindowsRemoteManagement.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>WindowsRemoteManagement~AT~WindowsComponents~WinRM~WinRMClient</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowBasic_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowBasicAuthentication_Service</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>WindowsRemoteManagement.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>WindowsRemoteManagement~AT~WindowsComponents~WinRM~WinRMService</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowBasic_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowCredSSPAuthenticationClient</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>WindowsRemoteManagement.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>WindowsRemoteManagement~AT~WindowsComponents~WinRMClient</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowCredSSP_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowCredSSPAuthenticationService</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>WindowsRemoteManagement.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>WindowsRemoteManagement~AT~WindowsComponents~WinRM~WinRMService</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowCredSSP_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowRemoteServerManagement</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>WindowsRemoteManagement.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>WindowsRemoteManagement~AT~WindowsComponents~WinRM~WinRMService</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowAutoConfig</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowUnencryptedTraffic_Client</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>WindowsRemoteManagement.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>WindowsRemoteManagement~AT~WindowsComponents~WinRM~WinRMClient</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowUnencrypted_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowUnencryptedTraffic_Service</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>WindowsRemoteManagement.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>WindowsRemoteManagement~AT~WindowsComponents~WinRM~WinRMService</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowUnencrypted_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisallowDigestAuthentication</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>WindowsRemoteManagement.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>WindowsRemoteManagement~AT~WindowsComponents~WinRM~WinRMClient</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisallowDigest</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisallowNegotiateAuthenticationClient</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>WindowsRemoteManagement.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>WindowsRemoteManagement~AT~WindowsComponents~WinRM~WinRMClient</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisallowNegotiate_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisallowNegotiateAuthenticationService</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>WindowsRemoteManagement.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>WindowsRemoteManagement~AT~WindowsComponents~WinRM~WinRMService</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisallowNegotiate_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisallowStoringOfRunAsCredentials</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>WindowsRemoteManagement.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>WindowsRemoteManagement~AT~WindowsComponents~WinRM~WinRMService</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableRunAs</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SpecifyChannelBindingTokenHardeningLevel</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>WindowsRemoteManagement.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>WindowsRemoteManagement~AT~WindowsComponents~WinRM~WinRMService</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>CBTHardeningLevel_1</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TrustedHosts</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>WindowsRemoteManagement.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>WindowsRemoteManagement~AT~WindowsComponents~WinRM~WinRMClient</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>TrustedHosts</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TurnOnCompatibilityHTTPListener</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>WindowsRemoteManagement.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>WindowsRemoteManagement~AT~WindowsComponents~WinRM~WinRMService</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>HttpCompatibilityListener</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TurnOnCompatibilityHTTPSListener</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>WindowsRemoteManagement.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>WindowsRemoteManagement~AT~WindowsComponents~WinRM~WinRMService</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>HttpsCompatibilityListener</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>RemoteProcedureCall</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>RestrictUnauthenticatedRPCClients</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>rpc.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>RPC~AT~System~Rpc</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>RpcRestrictRemoteClients</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RPCEndpointMapperClientAuthentication</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>rpc.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>RPC~AT~System~Rpc</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>RpcEnableAuthEpResolution</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>RemoteShell</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowRemoteShellAccess</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>WindowsRemoteShell.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>WindowsRemoteShell~AT~WindowsComponents~WinRS</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowRemoteShellAccess</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>MaxConcurrentUsers</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>WindowsRemoteShell.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>WindowsRemoteShell~AT~WindowsComponents~WinRS</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>MaxConcurrentUsers</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SpecifyIdleTimeout</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>WindowsRemoteShell.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>WindowsRemoteShell~AT~WindowsComponents~WinRS</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>IdleTimeout</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SpecifyMaxMemory</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>WindowsRemoteShell.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>WindowsRemoteShell~AT~WindowsComponents~WinRS</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>MaxMemoryPerShellMB</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SpecifyMaxProcesses</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>WindowsRemoteShell.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>WindowsRemoteShell~AT~WindowsComponents~WinRS</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>MaxProcessesPerShell</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SpecifyMaxRemoteShells</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>WindowsRemoteShell.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>WindowsRemoteShell~AT~WindowsComponents~WinRS</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>MaxShellsPerUser</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SpecifyShellTimeout</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>WindowsRemoteShell.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>WindowsRemoteShell~AT~WindowsComponents~WinRS</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ShellTimeOut</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>RestrictedGroups</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>ConfigureGroupMembership</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This security setting allows an administrator to define the members of a security-sensitive (restricted) group. When a Restricted Groups Policy is enforced, any current member of a restricted group that is not on the Members list is removed. Any user on the Members list who is not currently a member of the restricted group is added. You can use Restricted Groups policy to control group membership. Using the policy, you can specify what members are part of a group. Any members that are not specified in the policy are removed during configuration or refresh. For example, you can create a Restricted Groups policy to only allow specified users (for example, Alice and John) to be members of the Administrators group. When policy is refreshed, only Alice and John will remain as members of the Administrators group.
Caution: If a Restricted Groups policy is applied, any current member not on the Restricted Groups policy members list is removed. This can include default members, such as administrators. Restricted Groups should be used primarily to configure membership of local groups on workstation or member servers. An empty Members list means that the restricted group has no members.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Search</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowCloudSearch</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>2</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>Search.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>AllowCloudSearch_Dropdown</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>Search~AT~WindowsComponents~Search</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowCloudSearch</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowCortanaInAAD</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This features allows you to show the cortana opt-in page during Windows Setup</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>Search.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>Search~AT~WindowsComponents~Search</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowCortanaInAAD</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowIndexingEncryptedStoresOrItems</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>Search.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>Search~AT~WindowsComponents~Search</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowIndexingEncryptedStoresOrItems</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSearchToUseLocation</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>Search.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>Search~AT~WindowsComponents~Search</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowSearchToUseLocation</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowStoringImagesFromVisionSearch</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowUsingDiacritics</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>Search.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>Search~AT~WindowsComponents~Search</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowUsingDiacritics</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowWindowsIndexer</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>3</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="3"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AlwaysUseAutoLangDetection</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>Search.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>Search~AT~WindowsComponents~Search</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AlwaysUseAutoLangDetection</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableBackoff</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>Search.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>Search~AT~WindowsComponents~Search</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableBackoff</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableRemovableDriveIndexing</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>Search.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>Search~AT~WindowsComponents~Search</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableRemovableDriveIndexing</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DoNotUseWebResults</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>Search.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>Search~AT~WindowsComponents~Search</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DoNotUseWebResults</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventIndexingLowDiskSpaceMB</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>Search.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>Search~AT~WindowsComponents~Search</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>StopIndexingOnLimitedHardDriveSpace</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventRemoteQueries</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>Search.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>Search~AT~WindowsComponents~Search</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>PreventRemoteQueries</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SafeSearchPermissions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>desktop</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Security</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowAddProvisioningPackage</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowManualRootCertificateInstallation</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>desktop</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowRemoveProvisioningPackage</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AntiTheftMode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>desktop</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ClearTPMIfNotReady</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>TPM.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>TPM~AT~System~TPMCategory</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ClearTPMIfNotReady_Name</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConfigureWindowsPasswords</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>2</DefaultValue>
            <Description>Configures the use of passwords for Windows features</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventAutomaticDeviceEncryptionForAzureADJoinedDevices</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RequireDeviceEncryption</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RequireProvisioningPackageSignature</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RequireRetrieveHealthCertificateOnBoot</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Settings</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowAutoPlay</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowDataSense</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowDateTime</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowEditDeviceName</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLanguage</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowOnlineTips</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>ControlPanel.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>CheckBox_AllowOnlineTips</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>ControlPanel~AT~ControlPanel</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowOnlineTips</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPowerSleep</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowRegion</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowSignInOptions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowVPN</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowWorkplace</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowYourAccount</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PageVisibilityList</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>ControlPanel.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>SettingsPageVisibilityBox</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>ControlPanel~AT~ControlPanel</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>SettingsPageVisibility</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>SmartScreen</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>EnableAppInstallControl</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>SmartScreen.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>SmartScreen~AT~WindowsComponents~SmartScreen~Shell</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ConfigureAppInstallControl</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableSmartScreenInShell</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>SmartScreen.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>SmartScreen~AT~WindowsComponents~SmartScreen~Shell</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ShellConfigureSmartScreen</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PreventOverrideForFilesInShell</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>SmartScreen.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>ShellConfigureSmartScreen_Dropdown</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>SmartScreen~AT~WindowsComponents~SmartScreen~Shell</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ShellConfigureSmartScreen</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Speech</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowSpeechModelUpdate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>Speech.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>Speech~AT~WindowsComponents~Speech</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowSpeechModelUpdate</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Start</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowPinnedFolderDocuments</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>65535</DefaultValue>
            <Description>This policy controls the visibility of the Documents shortcut on the Start menu. The possible values are 0 - means that the shortcut should be hidden and grays out the corresponding toggle in the Settings app, 1 - means that the shortcut should be visible and grays out the corresponding toggle in the Settings app, 65535 - means that there is no enforced configuration and the setting can be changed by the user.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="0,1,65535"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPinnedFolderDownloads</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>65535</DefaultValue>
            <Description>This policy controls the visibility of the Downloads shortcut on the Start menu. The possible values are 0 - means that the shortcut should be hidden and grays out the corresponding toggle in the Settings app, 1 - means that the shortcut should be visible and grays out the corresponding toggle in the Settings app, 65535 - means that there is no enforced configuration and the setting can be changed by the user.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="0,1,65535"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPinnedFolderFileExplorer</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>65535</DefaultValue>
            <Description>This policy controls the visibility of the File Explorer shortcut on the Start menu. The possible values are 0 - means that the shortcut should be hidden and grays out the corresponding toggle in the Settings app, 1 - means that the shortcut should be visible and grays out the corresponding toggle in the Settings app, 65535 - means that there is no enforced configuration and the setting can be changed by the user.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="0,1,65535"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPinnedFolderHomeGroup</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>65535</DefaultValue>
            <Description>This policy controls the visibility of the HomeGroup shortcut on the Start menu. The possible values are 0 - means that the shortcut should be hidden and grays out the corresponding toggle in the Settings app, 1 - means that the shortcut should be visible and grays out the corresponding toggle in the Settings app, 65535 - means that there is no enforced configuration and the setting can be changed by the user.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="0,1,65535"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPinnedFolderMusic</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>65535</DefaultValue>
            <Description>This policy controls the visibility of the Music shortcut on the Start menu. The possible values are 0 - means that the shortcut should be hidden and grays out the corresponding toggle in the Settings app, 1 - means that the shortcut should be visible and grays out the corresponding toggle in the Settings app, 65535 - means that there is no enforced configuration and the setting can be changed by the user.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="0,1,65535"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPinnedFolderNetwork</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>65535</DefaultValue>
            <Description>This policy controls the visibility of the Network shortcut on the Start menu. The possible values are 0 - means that the shortcut should be hidden and grays out the corresponding toggle in the Settings app, 1 - means that the shortcut should be visible and grays out the corresponding toggle in the Settings app, 65535 - means that there is no enforced configuration and the setting can be changed by the user.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="0,1,65535"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPinnedFolderPersonalFolder</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>65535</DefaultValue>
            <Description>This policy controls the visibility of the PersonalFolder shortcut on the Start menu. The possible values are 0 - means that the shortcut should be hidden and grays out the corresponding toggle in the Settings app, 1 - means that the shortcut should be visible and grays out the corresponding toggle in the Settings app, 65535 - means that there is no enforced configuration and the setting can be changed by the user.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="0,1,65535"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPinnedFolderPictures</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>65535</DefaultValue>
            <Description>This policy controls the visibility of the Pictures shortcut on the Start menu. The possible values are 0 - means that the shortcut should be hidden and grays out the corresponding toggle in the Settings app, 1 - means that the shortcut should be visible and grays out the corresponding toggle in the Settings app, 65535 - means that there is no enforced configuration and the setting can be changed by the user.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="0,1,65535"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPinnedFolderSettings</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>65535</DefaultValue>
            <Description>This policy controls the visibility of the Settings shortcut on the Start menu. The possible values are 0 - means that the shortcut should be hidden and grays out the corresponding toggle in the Settings app, 1 - means that the shortcut should be visible and grays out the corresponding toggle in the Settings app, 65535 - means that there is no enforced configuration and the setting can be changed by the user.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="0,1,65535"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowPinnedFolderVideos</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>65535</DefaultValue>
            <Description>This policy controls the visibility of the Videos shortcut on the Start menu. The possible values are 0 - means that the shortcut should be hidden and grays out the corresponding toggle in the Settings app, 1 - means that the shortcut should be visible and grays out the corresponding toggle in the Settings app, 65535 - means that there is no enforced configuration and the setting can be changed by the user.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="0,1,65535"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableContextMenus</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Enabling this policy prevents context menus from being invoked in the Start Menu.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>StartMenu.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>StartMenu~AT~StartMenu</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableContextMenusInStart</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ForceStartSize</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideAppList</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Setting the value of this policy to 1 or 2 collapses the app list. Setting the value of this policy to 3 removes the app list entirely. Setting the value of this policy to 2 or 3 disables the corresponding toggle in the Settings app.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="3"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideChangeAccountSettings</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Enabling this policy hides "Change account settings" from appearing in the user tile in the start menu.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideFrequentlyUsedApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Enabling this policy hides the most used apps from appearing on the start menu and disables the corresponding toggle in the Settings app.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideHibernate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Enabling this policy hides "Hibernate" from appearing in the power button in the start menu.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideLock</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Enabling this policy hides "Lock" from appearing in the user tile in the start menu.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HidePowerButton</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Enabling this policy hides the power button from appearing in the start menu.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideRecentJumplists</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Enabling this policy hides recent jumplists from appearing on the start menu/taskbar and disables the corresponding toggle in the Settings app.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideRecentlyAddedApps</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Enabling this policy hides recently added apps from appearing on the start menu and disables the corresponding toggle in the Settings app.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>StartMenu.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>StartMenu~AT~StartMenu</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>HideRecentlyAddedApps</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideRestart</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Enabling this policy hides "Restart/Update and restart" from appearing in the power button in the start menu.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideShutDown</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Enabling this policy hides "Shut down/Update and shut down" from appearing in the power button in the start menu.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideSignOut</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Enabling this policy hides "Sign out" from appearing in the user tile in the start menu.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideSleep</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Enabling this policy hides "Sleep" from appearing in the power button in the start menu.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideSwitchAccount</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Enabling this policy hides "Switch account" from appearing in the user tile in the start menu.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideUserTile</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Enabling this policy hides the user tile from appearing in the start menu.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ImportEdgeAssets</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This policy setting allows you to import Edge assets to be used with StartLayout policy. Start layout can contain secondary tile from Edge app which looks for Edge local asset file. Edge local asset would not exist and cause Edge secondary tile to appear empty in this case. This policy only gets applied when StartLayout policy is modified.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>NoPinningToTaskbar</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy setting allows you to control pinning programs to the Taskbar. If you enable this policy setting, users cannot change the programs currently pinned to the Taskbar. If any programs are already pinned to the Taskbar, these programs continue to show in the Taskbar. However, users cannot unpin these programs already pinned to the Taskbar, and they cannot pin new programs to the Taskbar. If you disable or do not configure this policy setting, users can change the programs currently pinned to the Taskbar.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>StartLayout</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>StartMenu.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>StartMenu~AT~StartMenu</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LockedStartLayout</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Storage</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowDiskHealthModelUpdates</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>StorageHealth.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>StorageHealth~AT~System~StorageHealth</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>SH_AllowDiskHealthModelUpdates</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnhancedStorageDevices</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>enhancedstorage.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>EnhancedStorage~AT~System~EnStorDeviceAccess</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>TCGSecurityActivationDisabled</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>System</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowBuildPreview</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>2</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>AllowBuildPreview.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>AllowBuildPreview~AT~WindowsComponents~DataCollectionAndPreviewBuilds</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowBuildPreview</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowEmbeddedMode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowExperimentation</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowFontProviders</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>GroupPolicy.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>GroupPolicy~AT~Network~NetworkFonts</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>EnableFontProviders</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLocation</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>Sensors.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>Sensors~AT~LocationAndSensors</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableLocation_2</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowStorageCard</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowTelemetry</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>3</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="3"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>DataCollection.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>AllowTelemetry</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DataCollection~AT~WindowsComponents~DataCollectionAndPreviewBuilds</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowTelemetry</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowUserToResetPhone</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>BootStartDriverInitialization</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>earlylauncham.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>EarlyLaunchAM~AT~System~ELAMCategory</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>POL_DriverLoadPolicy_Name</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConfigureTelemetryOptInChangeNotification</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>DataCollection.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>ConfigureTelemetryOptInChangeNotification</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DataCollection~AT~WindowsComponents~DataCollectionAndPreviewBuilds</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ConfigureTelemetryOptInChangeNotification</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConfigureTelemetryOptInSettingsUx</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>DataCollection.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>ConfigureTelemetryOptInSettingsUx</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DataCollection~AT~WindowsComponents~DataCollectionAndPreviewBuilds</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ConfigureTelemetryOptInSettingsUx</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableEnterpriseAuthProxy</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy setting blocks the Connected User Experience and Telemetry service from automatically using an authenticated proxy to send data back to Microsoft on Windows 10. If you disable or do not configure this policy setting, the Connected User Experience and Telemetry service will automatically use an authenticated proxy to send data back to Microsoft. Enabling this policy will block the Connected User Experience and Telemetry service from automatically using an authenticated proxy.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>DataCollection.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>DisableEnterpriseAuthProxy</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DataCollection~AT~WindowsComponents~DataCollectionAndPreviewBuilds</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableEnterpriseAuthProxy</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableOneDriveFileSync</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy setting lets you prevent apps and features from working with files on OneDrive. If you enable this policy setting: users cant access OneDrive from the OneDrive app and file picker; Microsoft Store apps cant access OneDrive using the WinRT API; OneDrive doesnt appear in the navigation pane in File Explorer; OneDrive files arent kept in sync with the cloud; Users cant automatically upload photos and videos from the camera roll folder. If you disable or do not configure this policy setting, apps and features can work with OneDrive file storage.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>SkyDrive.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>SkyDrive~AT~WindowsComponents~OneDrive</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>PreventOnedriveFileSync</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableSystemRestore</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>systemrestore.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>SystemRestore~AT~System~SR</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>SR_DisableSR</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>FeedbackHubAlwaysSaveDiagnosticsLocally</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Diagnostic files created when a feedback is filed in the Feedback Hub app will always be saved locally. If this policy is not present or set to false, users will be presented with the option to save locally. The default is to not save locally.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LimitEnhancedDiagnosticDataWindowsAnalytics</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy setting, in combination with the Allow Telemetry policy setting, enables organizations to send Microsoft a specific set of diagnostic data for IT insights via Windows Analytics services. By configuring this setting, you're not stopping people from changing their Telemetry Settings; however, you are stopping them from choosing a higher level than you've set for the organization. To enable this behavior, you must complete two steps: 1. Enable this policy setting 2. Set Allow Telemetry to level 2 (Enhanced).If you configure these policy settings together, you'll send the Basic level of diagnostic data plus any additional events that are required for Windows Analytics, to Microsoft. The additional events are documented here: https://go.Microsoft.com/fwlink/?linked=847594. If you enable Enhanced diagnostic data in the Allow Telemetry policy setting, but you don't configure this policy setting, you'll send the required events for Windows Analytics, plus any additional Enhanced level telemetry data to Microsoft. This setting has no effect on computers configured to send Full, Basic, or Security level diagnostic data to Microsoft. If you disable or don't configure this policy setting, then the level of diagnostic data sent to Microsoft is determined by the Allow Telemetry policy setting.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>DataCollection.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>LimitEnhancedDiagnosticDataWindowsAnalytics</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DataCollection~AT~WindowsComponents~DataCollectionAndPreviewBuilds</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>LimitEnhancedDiagnosticDataWindowsAnalytics</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TelemetryProxy</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>DataCollection.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>TelemetryProxyName</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>DataCollection~AT~WindowsComponents~DataCollectionAndPreviewBuilds</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>TelemetryProxy</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>SystemServices</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>ConfigureHomeGroupListenerServiceStartupMode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This setting determines whether the service's start type is Automaic(2), Manual(3), Disabled(4). Default: Manual.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="2" high="4"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~System Services</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>HomeGroup Listener</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConfigureHomeGroupProviderServiceStartupMode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This setting determines whether the service's start type is Automaic(2), Manual(3), Disabled(4). Default: Manual.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="2" high="4"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~System Services</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>HomeGroup Provider</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConfigureXboxAccessoryManagementServiceStartupMode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This setting determines whether the service's start type is Automaic(2), Manual(3), Disabled(4). Default: Manual.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="2" high="4"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~System Services</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Xbox Accessory Management Service</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConfigureXboxLiveAuthManagerServiceStartupMode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This setting determines whether the service's start type is Automaic(2), Manual(3), Disabled(4). Default: Manual.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="2" high="4"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~System Services</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Xbox Live Auth Manager</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConfigureXboxLiveGameSaveServiceStartupMode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This setting determines whether the service's start type is Automaic(2), Manual(3), Disabled(4). Default: Manual.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="2" high="4"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~System Services</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Xbox Live Game Save</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConfigureXboxLiveNetworkingServiceStartupMode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This setting determines whether the service's start type is Automaic(2), Manual(3), Disabled(4). Default: Manual.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="2" high="4"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~System Services</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Xbox Live Networking Service</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>TaskScheduler</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>EnableXboxGameSaveTask</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This setting determines whether the specific task is enabled (1) or disabled (0). Default: Enabled.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>TextInput</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowHardwareKeyboardTextSuggestions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowIMELogging</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowIMENetworkAccess</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowInputPanel</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowJapaneseIMESurrogatePairCharacters</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowJapaneseIVSCharacters</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowJapaneseNonPublishingStandardGlyph</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowJapaneseUserDictionary</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowKeyboardTextSuggestions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLanguageFeaturesUninstall</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>TextInput.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>TextInput~AT~WindowsComponents~TextInput</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowLanguageFeaturesUninstall</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLinguisticDataCollection</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>TextInput.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>TextInput~AT~WindowsComponents~TextInput</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowLinguisticDataCollection</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableTouchKeyboardAutoInvokeInDesktopMode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ExcludeJapaneseIMEExceptJIS0208</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ExcludeJapaneseIMEExceptJIS0208andEUDC</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ExcludeJapaneseIMEExceptShiftJIS</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ForceTouchKeyboardDockedState</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TouchKeyboardDictationButtonAvailability</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TouchKeyboardEmojiButtonAvailability</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TouchKeyboardFullModeAvailability</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TouchKeyboardHandwritingModeAvailability</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TouchKeyboardNarrowModeAvailability</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TouchKeyboardSplitModeAvailability</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TouchKeyboardWideModeAvailability</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>TimeLanguageSettings</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowSet24HourClock</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>desktop</MSFT:NotSupportedOnPlatform>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Update</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>ActiveHoursEnd</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>17</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="23"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>ActiveHoursEndTime</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ActiveHours</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ActiveHoursMaxRange</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>18</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="8" high="18"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>ActiveHoursMaxRange</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ActiveHoursMaxRange</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ActiveHoursStart</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>8</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="23"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>ActiveHoursStartTime</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ActiveHours</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowAutoUpdate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>2</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="5"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>AutoUpdateMode</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AutoUpdateCfg</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowAutoWindowsUpdateDownloadOverMeteredNetwork</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowAutoWindowsUpdateDownloadOverMeteredNetwork</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowMUUpdateService</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>AllowMUUpdateServiceId</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AutoUpdateCfg</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowNonMicrosoftSignedUpdate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowUpdateService</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>CorpWuURL</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AutoRestartDeadlinePeriodInDays</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>7</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="2" high="30"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>AutoRestartDeadline</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AutoRestartDeadline</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AutoRestartNotificationSchedule</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>15</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="15,30,60,120,240"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>AutoRestartNotificationSchd</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AutoRestartNotificationConfig</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AutoRestartRequiredNotificationDismissal</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="1" high="2"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>AutoRestartRequiredNotificationDismissal</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AutoRestartRequiredNotificationDismissal</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>BranchReadinessLevel</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>16</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="2,4,8,16,32"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>BranchReadinessLevelId</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat~DeferUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DeferFeatureUpdates</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ConfigureFeatureUpdateUninstallPeriod</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>10</DefaultValue>
            <Description>Enable enterprises/IT admin to configure feature update uninstall period</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="2" high="60"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DeferFeatureUpdatesPeriodInDays</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="365"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>DeferFeatureUpdatesPeriodId</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat~DeferUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DeferFeatureUpdates</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DeferQualityUpdatesPeriodInDays</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="30"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>DeferQualityUpdatesPeriodId</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat~DeferUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DeferQualityUpdates</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DeferUpdatePeriod</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="4"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>DeferUpdatePeriodId</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DeferUpgrade</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DeferUpgradePeriod</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="8"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>DeferUpgradePeriodId</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DeferUpgrade</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DetectionFrequency</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>22</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="1" high="22"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>DetectionFrequency_Hour2</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DetectionFrequency_Title</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableDualScan</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>Do not allow update deferral policies to cause scans against Windows Update</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableDualScan</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EngagedRestartDeadline</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>14</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="2" high="30"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>EngagedRestartDeadline</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>EngagedRestartTransitionSchedule</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EngagedRestartSnoozeSchedule</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>3</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="1" high="3"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>EngagedRestartSnoozeSchedule</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>EngagedRestartTransitionSchedule</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EngagedRestartTransitionSchedule</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>7</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="2" high="30"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>EngagedRestartTransitionSchedule</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>EngagedRestartTransitionSchedule</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ExcludeWUDriversInQualityUpdate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat~DeferUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ExcludeWUDriversInQualityUpdate</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>FillEmptyContentUrls</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>CorpWUFillEmptyContentUrls</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>CorpWuURL</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IgnoreMOAppDownloadLimit</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IgnoreMOUpdateDownloadLimit</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ManagePreviewBuilds</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>3</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="3"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>ManagePreviewBuildsId</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat~DeferUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>ManagePreviewBuilds</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PauseDeferrals</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>PauseDeferralsId</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DeferUpgrade</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PauseFeatureUpdates</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>PauseFeatureUpdatesId</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat~DeferUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DeferFeatureUpdates</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PauseFeatureUpdatesStartTime</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>PauseFeatureUpdatesStartId</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat~DeferUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DeferFeatureUpdates</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PauseQualityUpdates</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>PauseQualityUpdatesId</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat~DeferUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DeferQualityUpdates</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PauseQualityUpdatesStartTime</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>PauseQualityUpdatesStartId</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat~DeferUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DeferQualityUpdates</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>PhoneUpdateRestrictions</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>4</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="4"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RequireDeferUpgrade</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>DeferUpgradePeriodId</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DeferUpgrade</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RequireUpdateApproval</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScheduledInstallDay</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="7"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>AutoUpdateSchDay</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AutoUpdateCfg</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScheduledInstallEveryWeek</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>AutoUpdateSchEveryWeek</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AutoUpdateCfg</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScheduledInstallFirstWeek</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>AutoUpdateSchFirstWeek</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AutoUpdateCfg</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScheduledInstallFourthWeek</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>ScheduledInstallFourthWeek</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AutoUpdateCfg</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScheduledInstallSecondWeek</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>ScheduledInstallSecondWeek</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AutoUpdateCfg</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScheduledInstallThirdWeek</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>ScheduledInstallThirdWeek</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AutoUpdateCfg</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScheduledInstallTime</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>3</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="23"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>AutoUpdateSchTime</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AutoUpdateCfg</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScheduleImminentRestartWarning</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>15</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="15,30,60"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>RestartWarn</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>RestartWarnRemind</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ScheduleRestartWarning</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>4</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues AllowedValues="2,4,8,12,24"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>RestartWarnRemind</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>RestartWarnRemind</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SetAutoRestartNotificationDisable</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>AutoRestartNotificationSchd</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AutoRestartNotificationDisable</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SetEDURestart</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>SetEDURestart</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UpdateServiceUrl</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>CorpWSUS</DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>CorpWUURL_Name</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>CorpWuURL</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>UpdateServiceUrlAlternate</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsUpdate.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>CorpWUContentHost_Name</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsUpdate~AT~WindowsComponents~WindowsUpdateCat</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>CorpWuURL</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>UserRights</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AccessCredentialManagerAsTrustedCaller</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This user right is used by Credential Manager during Backup/Restore. No accounts should have this privilege, as it is only assigned to Winlogon. Users' saved credentials might be compromised if this privilege is given to other entities.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~User Rights Assignment</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Access Credential Manager ase a trusted caller</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AccessFromNetwork</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This user right determines which users and groups are allowed to connect to the computer over the network. Remote Desktop Services are not affected by this user right.Note: Remote Desktop Services was called Terminal Services in previous versions of Windows Server.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~User Rights Assignment</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Access this computer from the network</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ActAsPartOfTheOperatingSystem</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This user right allows a process to impersonate any user without authentication. The process can therefore gain access to the same local resources as that user. Processes that require this privilege should use the LocalSystem account, which already includes this privilege, rather than using a separate user account with this privilege specially assigned. Caution:Assigning this user right can be a security risk. Only assign this user right to trusted users.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~User Rights Assignment</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Act as part of the operating system</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowLocalLogOn</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This user right determines which users can log on to the computer. Note: Modifying this setting may affect compatibility with clients, services, and applications. For compatibility information about this setting, see Allow log on locally (https://go.microsoft.com/fwlink/?LinkId=24268 ) at the Microsoft website. </Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~User Rights Assignment</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Allow log on locally</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>BackupFilesAndDirectories</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This user right determines which users can bypass file, directory, registry, and other persistent objects permissions when backing up files and directories.Specifically, this user right is similar to granting the following permissions to the user or group in question on all files and folders on the system:Traverse Folder/Execute File, Read. Caution: Assigning this user right can be a security risk. Since users with this user right can read any registry settings and files, only assign this user right to trusted users</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~User Rights Assignment</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Back up files and directories</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ChangeSystemTime</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This user right determines which users and groups can change the time and date on the internal clock of the computer. Users that are assigned this user right can affect the appearance of event logs. If the system time is changed, events that are logged will reflect this new time, not the actual time that the events occurred.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~User Rights Assignment</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Change the system time</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>CreateGlobalObjects</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This security setting determines whether users can create global objects that are available to all sessions. Users can still create objects that are specific to their own session if they do not have this user right. Users who can create global objects could affect processes that run under other users' sessions, which could lead to application failure or data corruption. Caution: Assigning this user right can be a security risk. Assign this user right only to trusted users.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~User Rights Assignment</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Create global objects</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>CreatePageFile</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This user right determines which users and groups can call an internal application programming interface (API) to create and change the size of a page file. This user right is used internally by the operating system and usually does not need to be assigned to any users</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~User Rights Assignment</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Create a pagefile</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>CreatePermanentSharedObjects</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This user right determines which accounts can be used by processes to create a directory object using the object manager. This user right is used internally by the operating system and is useful to kernel-mode components that extend the object namespace. Because components that are running in kernel mode already have this user right assigned to them, it is not necessary to specifically assign it.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~User Rights Assignment</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Create permanent shared objects</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>CreateSymbolicLinks</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This user right determines if the user can create a symbolic link from the computer he is logged on to. Caution: This privilege should only be given to trusted users. Symbolic links can expose security vulnerabilities in applications that aren't designed to handle them. Note: This setting can be used in conjunction a symlink filesystem setting that can be manipulated with the command line utility to control the kinds of symlinks that are allowed on the machine. Type 'fsutil behavior set symlinkevaluation /?' at the command line to get more information about fsutil and symbolic links.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~User Rights Assignment</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Create symbolic links</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>CreateToken</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This user right determines which accounts can be used by processes to create a token that can then be used to get access to any local resources when the process uses an internal application programming interface (API) to create an access token. This user right is used internally by the operating system. Unless it is necessary, do not assign this user right to a user, group, or process other than Local System. Caution: Assigning this user right can be a security risk. Do not assign this user right to any user, group, or process that you do not want to take over the system.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~User Rights Assignment</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Create a token object</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DebugPrograms</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This user right determines which users can attach a debugger to any process or to the kernel. Developers who are debugging their own applications do not need to be assigned this user right. Developers who are debugging new system components will need this user right to be able to do so. This user right provides complete access to sensitive and critical operating system components. Caution:Assigning this user right can be a security risk. Only assign this user right to trusted users.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~User Rights Assignment</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Debug programs</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DenyAccessFromNetwork</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This user right determines which users are prevented from accessing a computer over the network. This policy setting supersedes the Access this computer from the network policy setting if a user account is subject to both policies.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~User Rights Assignment</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Deny access to this computer from the network</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DenyLocalLogOn</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This security setting determines which service accounts are prevented from registering a process as a service. Note: This security setting does not apply to the System, Local Service, or Network Service accounts.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~User Rights Assignment</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Deny log on as a service</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DenyRemoteDesktopServicesLogOn</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This user right determines which users and groups are prohibited from logging on as a Remote Desktop Services client.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~User Rights Assignment</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Deny log on through Remote Desktop Services</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableDelegation</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This user right determines which users can set the Trusted for Delegation setting on a user or computer object. The user or object that is granted this privilege must have write access to the account control flags on the user or computer object. A server process running on a computer (or under a user context) that is trusted for delegation can access resources on another computer using delegated credentials of a client, as long as the client account does not have the Account cannot be delegated account control flag set. Caution: Misuse of this user right, or of the Trusted for Delegation setting, could make the network vulnerable to sophisticated attacks using Trojan horse programs that impersonate incoming clients and use their credentials to gain access to network resources.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~User Rights Assignment</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Enable computer and user accounts to be trusted for delegation</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>GenerateSecurityAudits</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This user right determines which accounts can be used by a process to add entries to the security log. The security log is used to trace unauthorized system access. Misuse of this user right can result in the generation of many auditing events, potentially hiding evidence of an attack or causing a denial of service. Shut down system immediately if unable to log security audits security policy setting is enabled.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~User Rights Assignment</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Generate security audits</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ImpersonateClient</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>Assigning this user right to a user allows programs running on behalf of that user to impersonate a client. Requiring this user right for this kind of impersonation prevents an unauthorized user from convincing a client to connect (for example, by remote procedure call (RPC) or named pipes) to a service that they have created and then impersonating that client, which can elevate the unauthorized user's permissions to administrative or system levels. Caution: Assigning this user right can be a security risk. Only assign this user right to trusted users. Note: By default, services that are started by the Service Control Manager have the built-in Service group added to their access tokens. Component Object Model (COM) servers that are started by the COM infrastructure and that are configured to run under a specific account also have the Service group added to their access tokens. As a result, these services get this user right when they are started. In addition, a user can also impersonate an access token if any of the following conditions exist. 
1) The access token that is being impersonated is for this user.
2) The user, in this logon session, created the access token by logging on to the network with explicit credentials.
3) The requested level is less than Impersonate, such as Anonymous or Identify.
Because of these factors, users do not usually need this user right. Warning: If you enable this setting, programs that previously had the Impersonate privilege may lose it, and they may not run.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~User Rights Assignment</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Impersonate a client after authentication</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>IncreaseSchedulingPriority</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This user right determines which accounts can use a process with Write Property access to another process to increase the execution priority assigned to the other process. A user with this privilege can change the scheduling priority of a process through the Task Manager user interface.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~User Rights Assignment</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Increase scheduling priority</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LoadUnloadDeviceDrivers</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This user right determines which users can dynamically load and unload device drivers or other code in to kernel mode. This user right does not apply to Plug and Play device drivers. It is recommended that you do not assign this privilege to other users. Caution: Assigning this user right can be a security risk. Do not assign this user right to any user, group, or process that you do not want to take over the system.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~User Rights Assignment</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Load and unload device drivers</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>LockMemory</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This user right determines which accounts can use a process to keep data in physical memory, which prevents the system from paging the data to virtual memory on disk. Exercising this privilege could significantly affect system performance by decreasing the amount of available random access memory (RAM).</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~User Rights Assignment</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Lock pages in memory</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ManageAuditingAndSecurityLog</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This user right determines which users can specify object access auditing options for individual resources, such as files, Active Directory objects, and registry keys. This security setting does not allow a user to enable file and object access auditing in general. You can view audited events in the security log of the Event Viewer. A user with this privilege can also view and clear the security log.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~User Rights Assignment</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Manage auditing and security log</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ManageVolume</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This user right determines which users and groups can run maintenance tasks on a volume, such as remote defragmentation. Use caution when assigning this user right. Users with this user right can explore disks and extend files in to memory that contains other data. When the extended files are opened, the user might be able to read and modify the acquired data.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~User Rights Assignment</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Perform volume maintenance tasks</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ModifyFirmwareEnvironment</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This user right determines who can modify firmware environment values. Firmware environment variables are settings stored in the nonvolatile RAM of non-x86-based computers. The effect of the setting depends on the processor.On x86-based computers, the only firmware environment value that can be modified by assigning this user right is the Last Known Good Configuration setting, which should only be modified by the system. On Itanium-based computers, boot information is stored in nonvolatile RAM. Users must be assigned this user right to run bootcfg.exe and to change the Default Operating System setting on Startup and Recovery in System Properties. On all computers, this user right is required to install or upgrade Windows.Note: This security setting does not affect who can modify the system environment variables and user environment variables that are displayed on the Advanced tab of System Properties.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~User Rights Assignment</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Modify firmware environment values</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ModifyObjectLabel</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This user right determines which user accounts can modify the integrity label of objects, such as files, registry keys, or processes owned by other users. Processes running under a user account can modify the label of an object owned by that user to a lower level without this privilege.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~User Rights Assignment</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Modify an object label</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>ProfileSingleProcess</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This user right determines which users can use performance monitoring tools to monitor the performance of system processes.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~User Rights Assignment</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Profile single process</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RemoteShutdown</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This user right determines which users are allowed to shut down a computer from a remote location on the network. Misuse of this user right can result in a denial of service.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~User Rights Assignment</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Force shutdown from a remote system</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RestoreFilesAndDirectories</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This user right determines which users can bypass file, directory, registry, and other persistent objects permissions when restoring backed up files and directories, and determines which users can set any valid security principal as the owner of an object. Specifically, this user right is similar to granting the following permissions to the user or group in question on all files and folders on the system:Traverse Folder/Execute File, Write. Caution: Assigning this user right can be a security risk. Since users with this user right can overwrite registry settings, hide data, and gain ownership of system objects, only assign this user right to trusted users.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~User Rights Assignment</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Restore files and directories</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>TakeOwnership</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description>This user right determines which users can take ownership of any securable object in the system, including Active Directory objects, files and folders, printers, registry keys, processes, and threads. Caution: Assigning this user right can be a security risk. Since owners of objects have full control of them, only assign this user right to trusted users.</Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:GPDBMappedCategory>Windows Settings~Security Settings~Local Policies~User Rights Assignment</MSFT:GPDBMappedCategory>
            <MSFT:GPDBMappedName>Take ownership of files or other objects</MSFT:GPDBMappedName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
            <MSFT:SubStringSeparatorChar>0xF000</MSFT:SubStringSeparatorChar>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>Wifi</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowAutoConnectToWiFiSenseHotspots</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>wlansvc.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>wlansvc~AT~Network~WlanSvc_Category~WlanSettings_Category</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>WiFiSense</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowInternetSharing</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>NetworkConnections.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>NetworkConnections~AT~Network~NetworkConnections</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>NC_ShowSharedAccessUI</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowManualWiFiConfiguration</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowWiFi</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowWiFiDirect</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>WLANScanMode</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1000"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>HighestValueMostSecureZeroHasNoLimits</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>WindowsConnectionManager</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>ProhitConnectionToNonDomainNetworksWhenConnectedToDomainAuthenticatedNetwork</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>WCM.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>WCM~AT~Network~WCM_Category</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>WCM_BlockNonDomain</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>WindowsDefenderSecurityCenter</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>CompanyName</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefenderSecurityCenter.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>Presentation_EnterpriseCustomization_CompanyName</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsDefenderSecurityCenter~AT~WindowsComponents~WindowsDefenderSecurityCenter~EnterpriseCustomization</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>EnterpriseCustomization_CompanyName</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableAccountProtectionUI</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefenderSecurityCenter.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsDefenderSecurityCenter~AT~WindowsComponents~WindowsDefenderSecurityCenter~AccountProtection</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AccountProtection_UILockdown</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableAppBrowserUI</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefenderSecurityCenter.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsDefenderSecurityCenter~AT~WindowsComponents~WindowsDefenderSecurityCenter~AppBrowserProtection</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AppBrowserProtection_UILockdown</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableDeviceSecurityUI</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefenderSecurityCenter.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsDefenderSecurityCenter~AT~WindowsComponents~WindowsDefenderSecurityCenter~DeviceSecurity</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DeviceSecurity_UILockdown</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableEnhancedNotifications</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefenderSecurityCenter.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsDefenderSecurityCenter~AT~WindowsComponents~WindowsDefenderSecurityCenter~Notifications</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Notifications_DisableEnhancedNotifications</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableFamilyUI</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefenderSecurityCenter.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsDefenderSecurityCenter~AT~WindowsComponents~WindowsDefenderSecurityCenter~FamilyOptions</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>FamilyOptions_UILockdown</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableHealthUI</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefenderSecurityCenter.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsDefenderSecurityCenter~AT~WindowsComponents~WindowsDefenderSecurityCenter~DevicePerformanceHealth</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DevicePerformanceHealth_UILockdown</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableNetworkUI</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefenderSecurityCenter.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsDefenderSecurityCenter~AT~WindowsComponents~WindowsDefenderSecurityCenter~FirewallNetworkProtection</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>FirewallNetworkProtection_UILockdown</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableNotifications</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefenderSecurityCenter.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsDefenderSecurityCenter~AT~WindowsComponents~WindowsDefenderSecurityCenter~Notifications</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>Notifications_DisableNotifications</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisableVirusUI</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefenderSecurityCenter.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsDefenderSecurityCenter~AT~WindowsComponents~WindowsDefenderSecurityCenter~VirusThreatProtection</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>VirusThreatProtection_UILockdown</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DisallowExploitProtectionOverride</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefenderSecurityCenter.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsDefenderSecurityCenter~AT~WindowsComponents~WindowsDefenderSecurityCenter~AppBrowserProtection</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AppBrowserProtection_DisallowExploitProtectionOverride</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>Email</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefenderSecurityCenter.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>Presentation_EnterpriseCustomization_Email</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsDefenderSecurityCenter~AT~WindowsComponents~WindowsDefenderSecurityCenter~EnterpriseCustomization</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>EnterpriseCustomization_Email</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableCustomizedToasts</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefenderSecurityCenter.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsDefenderSecurityCenter~AT~WindowsComponents~WindowsDefenderSecurityCenter~EnterpriseCustomization</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>EnterpriseCustomization_EnableCustomizedToasts</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnableInAppCustomization</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefenderSecurityCenter.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsDefenderSecurityCenter~AT~WindowsComponents~WindowsDefenderSecurityCenter~EnterpriseCustomization</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>EnterpriseCustomization_EnableInAppCustomization</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideRansomwareDataRecovery</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefenderSecurityCenter.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsDefenderSecurityCenter~AT~WindowsComponents~WindowsDefenderSecurityCenter~VirusThreatProtection</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>VirusThreatProtection_HideRansomwareRecovery</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideSecureBoot</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefenderSecurityCenter.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsDefenderSecurityCenter~AT~WindowsComponents~WindowsDefenderSecurityCenter~DeviceSecurity</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DeviceSecurity_HideSecureBoot</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideTPMTroubleshooting</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefenderSecurityCenter.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsDefenderSecurityCenter~AT~WindowsComponents~WindowsDefenderSecurityCenter~DeviceSecurity</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DeviceSecurity_HideTPMTroubleshooting</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>Phone</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefenderSecurityCenter.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>Presentation_EnterpriseCustomization_Phone</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsDefenderSecurityCenter~AT~WindowsComponents~WindowsDefenderSecurityCenter~EnterpriseCustomization</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>EnterpriseCustomization_Phone</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>URL</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsDefenderSecurityCenter.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>Presentation_EnterpriseCustomization_URL</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsDefenderSecurityCenter~AT~WindowsComponents~WindowsDefenderSecurityCenter~EnterpriseCustomization</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>EnterpriseCustomization_URL</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>WindowsInkWorkspace</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowSuggestedAppsInWindowsInkWorkspace</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsInkWorkspace.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WindowsInkWorkspace~AT~WindowsComponents~WindowsInkWorkspace</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowSuggestedAppsInWindowsInkWorkspace</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowWindowsInkWorkspace</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>2</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="2"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WindowsInkWorkspace.admx</MSFT:ADMXMapped>
            <MSFT:ADMXMappedElement>AllowWindowsInkWorkspaceDropdown</MSFT:ADMXMappedElement>
            <MSFT:ADMXCategory>WindowsInkWorkspace~AT~WindowsComponents~WindowsInkWorkspace</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowWindowsInkWorkspace</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>WindowsLogon</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>DisableLockScreenAppNotifications</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>logon.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>Logon~AT~System~Logon</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DisableLockScreenAppNotifications</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>DontDisplayNetworkSelectionUI</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>logon.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>Logon~AT~System~Logon</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>DontDisplayNetworkSelectionUI</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>EnumerateLocalUsersOnDomainJoinedComputers</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>logon.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>Logon~AT~System~Logon</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>EnumerateLocalUsers</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>HideFastUserSwitching</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy setting allows you to hide the Switch User interface in the Logon UI, the Start menu and the Task Manager. If you enable this policy setting, the Switch User interface is hidden from the user who is attempting to log on or is logged on to the computer that has this policy applied. The locations that Switch User interface appear are in the Logon UI, the Start menu and the Task Manager. If you disable or do not configure this policy setting, the Switch User interface is accessible to the user in the three locations.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>Logon.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>Logon~AT~System~Logon</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>HideFastUserSwitching</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>HighestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>SignInLastInteractiveUserAutomaticallyAfterASystemInitiatedRestart</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>WinLogon.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>WinLogon~AT~WindowsComponents~Logon</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AutomaticRestartSignOn</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>WindowsPowerShell</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>TurnOnPowerShellScriptBlockLogging</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue></DefaultValue>
            <Description></Description>
            <DFFormat>
              <chr/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXBacked>PowerShellExecutionPolicy.admx</MSFT:ADMXBacked>
            <MSFT:ADMXCategory>PowerShellExecutionPolicy~AT~WindowsComponents~PowerShell</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>EnableScriptBlockLogging</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LastWrite</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
      <Node>
        <NodeName>WirelessDisplay</NodeName>
        <DFProperties>
          <AccessType>
            <Get />
          </AccessType>
          <DFFormat>
            <node />
          </DFFormat>
          <Occurrence>
            <One />
          </Occurrence>
          <Scope>
            <Permanent />
          </Scope>
          <DFType>
            <DDFName></DDFName>
          </DFType>
        </DFProperties>
        <Node>
          <NodeName>AllowMdnsAdvertisement</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This policy setting allows you to turn off the Wireless Display multicast DNS service advertisement from a Wireless Display receiver.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowMdnsDiscovery</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This policy setting allows you to turn off discovering the display service advertised over multicast DNS by a Wireless Display receiver.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowProjectionFromPC</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This policy allows you to turn off projection from a PC.
                            If you set it to 0, your PC cannot discover or project to other devices.
                            If you set it to 1, your PC can discover and project to other devices.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowProjectionFromPCOverInfrastructure</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This policy allows you to turn off projection from a PC over infrastructure.
                            If you set it to 0, your PC cannot discover or project to other infrastructure devices, though it may still be possible to discover and project over WiFi Direct.
                            If you set it to 1, your PC can discover and project to other devices over infrastructure.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowProjectionToPC</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This policy setting allows you to turn off projection to a PC
                            If you set it to 0, your PC isn't discoverable and can't be projected to
                            If you set it to 1, your PC is discoverable and can be projected to above the lock screen only. The user has an option to turn it always on or off except for manual launch, too.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:NotSupportedOnPlatform>phone</MSFT:NotSupportedOnPlatform>
            <MSFT:ADMXMapped>WirelessDisplay.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WirelessDisplay~AT~WindowsComponents~Connect</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>AllowProjectionToPC</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowProjectionToPCOverInfrastructure</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description>This policy setting allows you to turn off projection to a PC over infrastructure.
                            If you set it to 0, your PC cannot be discoverable and can't be projected to over infrastructure, though it may still be possible to project over WiFi Direct.
                            If you set it to 1, your PC can be discoverable and can be projected to over infrastructure.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>AllowUserInputFromWirelessDisplayReceiver</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>1</DefaultValue>
            <Description></Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
        <Node>
          <NodeName>RequirePinForPairing</NodeName>
          <DFProperties>
            <AccessType>
              <Get />
            </AccessType>
            <DefaultValue>0</DefaultValue>
            <Description>This policy setting allows you to require a pin for pairing.
                            If you turn this on, the pairing ceremony for new devices will always require a PIN
                            If you turn it off or don't configure it, a pin isn't required for pairing.</Description>
            <DFFormat>
              <int/>
            </DFFormat>
            <Occurrence>
              <One />
            </Occurrence>
            <Scope>
              <Permanent />
            </Scope>
            <DFType>
              <MIME>text/plain</MIME>
            </DFType>
            <MSFT:SupportedValues low="0" high="1"></MSFT:SupportedValues>
            <MSFT:ADMXMapped>WirelessDisplay.admx</MSFT:ADMXMapped>
            <MSFT:ADMXCategory>WirelessDisplay~AT~WindowsComponents~Connect</MSFT:ADMXCategory>
            <MSFT:ADMXPolicyName>RequirePinForPairing</MSFT:ADMXPolicyName>
            <MSFT:ConflictResolution>LowestValueMostSecure</MSFT:ConflictResolution>
          </DFProperties>
        </Node>
      </Node>
    </Node>
  </Node>
</MgmtTree>