Group Policy Management
body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } }
Setting Path:
Explanation
No explanation is available for this setting.
Supported On:
Not available
Windows Restricted Traffic Limited Functionality Baseline
Data collected on: 10/23/2016 7:47:09 AM
General
Details
DomainSecurity.local
OwnerSECURITY\Domain Admins
Created6/10/2016 6:11:34 AM
Modified10/23/2016 7:47:04 AM
User Revisions4 (AD), 4 (SYSVOL)
Computer Revisions24 (AD), 24 (SYSVOL)
Unique ID{4E4481C6-3242-418A-AC5B-14E25A8E3943}
GPO StatusEnabled
Links
LocationEnforcedLink StatusPath
None

This list only includes links in the domain of the GPO.
Security Filtering
The settings in this GPO can only apply to the following groups, users, and computers:
Name
NT AUTHORITY\Authenticated Users
Delegation
These groups and users have the specified permission for this GPO
NameAllowed PermissionsInherited
NT AUTHORITY\Authenticated UsersRead (from Security Filtering)No
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSReadNo
NT AUTHORITY\SYSTEMEdit settings, delete, modify securityNo
SECURITY\Domain AdminsEdit settings, delete, modify securityNo
SECURITY\Enterprise AdminsEdit settings, delete, modify securityNo
Computer Configuration (Enabled)
Policies
Windows Settings
Security Settings
System Services
Microsoft Account Sign-in Assistant (Startup Mode: Disabled)
Permissions
No permissions specified
Auditing
No auditing specified
Windows Firewall with Advanced Security
Global Settings
PolicySetting
Policy versionNot Configured
Disable stateful FTPNot Configured
Disable stateful PPTPNot Configured
IPsec exemptNot Configured
IPsec through NATNot Configured
Preshared key encodingNot Configured
SA idle timeNot Configured
Strong CRL checkNot Configured
Outbound Rules
NameDescription
Block outbound Cortana
This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module
EnabledTrue
Program%windir%\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\searchUI.exe
ActionBlock
Authorized computers
Protocol6
Local portAny
Remote portAny
ICMP settingsAny
Local scopeAny
Remote scopeAny
ProfileAll
Network interface typeAll
ServiceAll programs and services
Group
Connection Security Settings
Administrative Templates
Policy definitions (ADMX files) retrieved from the local computer.
Control Panel/Personalization
PolicySettingComment
Do not display the lock screenEnabled
Force a specific default lock screen and logon imageEnabled
Path to lock screen image:C:\windows\web\screen\lockscreen.jpg
Example: Using a local path: C:\windows\web\screen\lockscreen.jpg
Example: Using a UNC path: \\Server\Share\Corp.jpg
Turn off fun facts, tips, tricks, and more on lock screenEnabled
Control Panel/Regional and Language Options/Handwriting personalization
PolicySettingComment
Turn off automatic learningEnabled
Network/Fonts
PolicySettingComment
Enable Font ProvidersDisabled
Network/TCPIP Settings/IPv6 Transition Technologies
PolicySettingComment
Set Teredo StateEnabled
Select from the following states:Disabled State
Network/WLAN Service/WLAN Settings
PolicySettingComment
Allow Windows to automatically connect to suggested open hotspots, to networks shared by contacts, and to hotspots offering paid servicesDisabled
System/Device Installation
PolicySettingComment
Prevent device metadata retrieval from the InternetEnabled
System/Group Policy
PolicySettingComment
Continue experiences on this deviceDisabled
System/Internet Communication Management/Internet Communication settings
PolicySettingComment
Turn off access to all Windows Update featuresEnabled
Turn off Automatic Root Certificates UpdateEnabled
Turn off Windows Network Connectivity Status Indicator active testsEnabled
System/User Profiles
PolicySettingComment
Turn off the advertising IDEnabled
System/Windows Time Service/Time Providers
PolicySettingComment
Enable Windows NTP ClientDisabled
Windows Components/App Privacy
PolicySettingComment
Let Windows apps access account informationEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access call historyEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access contactsEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access emailEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access locationEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access messagingEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access motionEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access notificationsEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access the calendarEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access the cameraEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access the microphoneEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access trusted devicesEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps control radiosEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps sync with devicesEnabled
Default for all apps:Force Deny
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
Windows Components/Cloud Content
PolicySettingComment
Do not show Windows tipsEnabled
Turn off Microsoft consumer experiencesEnabled
Windows Components/Data Collection and Preview Builds
PolicySettingComment
Allow TelemetryEnabled
0 - Security [Enterprise Only]
PolicySettingComment
Do not show feedback notificationsEnabled
Toggle user control over Insider buildsDisabled
Windows Components/Delivery Optimization
PolicySettingComment
Download ModeEnabled
Download Mode:Bypass
Windows Components/File Explorer
PolicySettingComment
Configure Windows SmartScreenDisabled
Windows Components/Internet Explorer
PolicySettingComment
Allow Microsoft services to provide enhanced suggestions as the user types in the Address barDisabled
Disable Periodic Check for Internet Explorer software updatesEnabled
Turn off browser geolocationEnabled
Turn off the auto-complete feature for web addressesEnabled
Turn on Suggested SitesDisabled
Windows Components/Internet Explorer/Internet Control Panel/Advanced Page
PolicySettingComment
Turn off the flip ahead with page prediction featureEnabled
Windows Components/Location and Sensors
PolicySettingComment
Turn off locationEnabled
Windows Components/Maps
PolicySettingComment
Turn off Automatic Download and Update of Map DataEnabled
Turn off unsolicited network traffic on the Offline Maps settings pageEnabled
Windows Components/Microsoft Edge
PolicySettingComment
Allow web content on New Tab pageDisabled
Configure AutofillDisabled
Configure Do Not TrackEnabled
Configure Home pagesEnabled
Use this format: <support.contoso.com><https://support.microsoft.com/>about:blank
PolicySettingComment
Configure Password ManagerDisabled
Configure search suggestions in Address barDisabled
Configure SmartScreen FilterDisabled
Windows Components/OneDrive
PolicySettingComment
Prevent the usage of OneDrive for file storageEnabled
Windows Components/RSS Feeds
PolicySettingComment
Turn off background synchronization for feeds and Web SlicesEnabled
Windows Components/Search
PolicySettingComment
Allow CortanaDisabled
Allow search and Cortana to use locationDisabled
Do not allow web searchEnabled
Don't search the web or display web results in SearchEnabled
Set what information is shared in SearchEnabled
Type of informationAnonymous info
Windows Components/Software Protection Platform
PolicySettingComment
Turn off KMS Client Online AVS ValidationEnabled
Windows Components/Store
PolicySettingComment
Disable all apps from Windows Store Disabled
Turn off Automatic Download and Install of updatesEnabled
Windows Components/Sync your settings
PolicySettingComment
Do not syncEnabled
Allow users to turn syncing on.Disabled
Windows Components/Windows Defender/MAPS
PolicySettingComment
Join Microsoft MAPSEnabled
Join Microsoft MAPSDisabled
PolicySettingComment
Send file samples when further analysis is requiredEnabled
Send file samples when further analysis is requiredNever send
Windows Components/Windows Defender/Signature Updates
PolicySettingComment
Define file shares for downloading definition updatesDisabled
Define the order of sources for downloading definition updatesEnabled
Define the order of sources for downloading definition updatesFileShares
Windows Components/Windows Mail
PolicySettingComment
Turn off Windows Mail applicationEnabled
Windows Components/Windows Update
PolicySettingComment
Do not connect to any Windows Update Internet locationsEnabled
Specify intranet Microsoft update service locationEnabled
Set the intranet update service for detecting updates:" "
Set the intranet statistics server:" "
(example: http://IntranetUpd01)
Windows Restricted Traffic Custom Policy Settings
PolicySettingComment
Disable Windows Defender enhanced notificationsEnabled
Receive updates to the speech recognition and speech synthesis modelsDisabled
Turn off Malicious Software Removal Tool reportingEnabled
User Configuration (Enabled)
Policies
Administrative Templates
Policy definitions (ADMX files) retrieved from the local computer.
Start Menu and Taskbar/Notifications
PolicySettingComment
Turn off notifications network usageEnabled
Windows Components/Cloud Content
PolicySettingComment
Turn off all Windows spotlight featuresEnabled
Windows Components/Internet Explorer/Security Features/Add-on Management
PolicySettingComment
Turn off automatic download of the ActiveX VersionListEnabled
Windows Restricted Traffic Custom Policy Settings
PolicySettingComment
Allow websites to provide locally relevant content by accessing user's language listDisabled
Messaging cloud syncDisabled