diff --git a/.gitattributes b/.gitattributes
new file mode 100644
index 0000000..d8fbe39
--- /dev/null
+++ b/.gitattributes
@@ -0,0 +1,11 @@
+# Squad: union merge for append-only team state files
+.squad/decisions.md merge=union
+.squad/agents/*/history.md merge=union
+.squad/log/** merge=union
+.squad/orchestration-log/** merge=union
+
+# ADMX/ADML: store blob bytes as-is so all delivery paths (git archive,
+# clone autocrlf=false, clone autocrlf=true) reproduce the exact MD5
+# recorded in config/tiermodel-admx.json and config/tiermodel-adml-en-US.json.
+*.admx binary
+*.adml binary
diff --git a/config/admx/DeviceGuard.admx b/config/admx/DeviceGuard.admx
index 7f7eb84..dd6aff6 100644
--- a/config/admx/DeviceGuard.admx
+++ b/config/admx/DeviceGuard.admx
@@ -1,195 +1,195 @@
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
diff --git a/config/admx/GameDVR.admx b/config/admx/GameDVR.admx
index 8f90f87..59a192d 100644
--- a/config/admx/GameDVR.admx
+++ b/config/admx/GameDVR.admx
@@ -1,25 +1,25 @@
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
\ No newline at end of file
diff --git a/config/admx/Kerberos.admx b/config/admx/Kerberos.admx
index a56e5c8..55bf749 100644
--- a/config/admx/Kerberos.admx
+++ b/config/admx/Kerberos.admx
@@ -1,299 +1,299 @@
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
diff --git a/config/admx/LAPS.admx b/config/admx/LAPS.admx
index 8c66f67..144357a 100644
--- a/config/admx/LAPS.admx
+++ b/config/admx/LAPS.admx
@@ -1,348 +1,348 @@
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
diff --git a/config/admx/LanmanServer.admx b/config/admx/LanmanServer.admx
index 590dfce..5c127fd 100644
--- a/config/admx/LanmanServer.admx
+++ b/config/admx/LanmanServer.admx
@@ -1,373 +1,373 @@
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
diff --git a/config/admx/LanmanWorkstation.admx b/config/admx/LanmanWorkstation.admx
index ef81ff8..4aedf90 100644
--- a/config/admx/LanmanWorkstation.admx
+++ b/config/admx/LanmanWorkstation.admx
@@ -1,395 +1,395 @@
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
diff --git a/config/admx/LocalSecurityAuthority.admx b/config/admx/LocalSecurityAuthority.admx
index a900662..54087c6 100644
--- a/config/admx/LocalSecurityAuthority.admx
+++ b/config/admx/LocalSecurityAuthority.admx
@@ -1,49 +1,49 @@
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
diff --git a/config/admx/MSS-legacy.admx b/config/admx/MSS-legacy.admx
index 8d49e96..ecede5a 100644
--- a/config/admx/MSS-legacy.admx
+++ b/config/admx/MSS-legacy.admx
@@ -1,292 +1,292 @@
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- 1
-
-
- 0
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+ 1
+
+
+ 0
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
diff --git a/config/admx/NetworkProvider.admx b/config/admx/NetworkProvider.admx
index 2580c9d..8b80d76 100644
--- a/config/admx/NetworkProvider.admx
+++ b/config/admx/NetworkProvider.admx
@@ -1,28 +1,28 @@
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
diff --git a/config/admx/Printing.admx b/config/admx/Printing.admx
index 5c498d7..b6f70b5 100644
--- a/config/admx/Printing.admx
+++ b/config/admx/Printing.admx
@@ -1,1182 +1,1182 @@
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
diff --git a/config/admx/SecGuide.admx b/config/admx/SecGuide.admx
index 439c99b..1aec2b2 100644
--- a/config/admx/SecGuide.admx
+++ b/config/admx/SecGuide.admx
@@ -1,634 +1,634 @@
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- >
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- Block all Flash activation
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- Block embedded Flash activation only
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- Allow all Flash activation
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- >
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+ >
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+ Block all Flash activation
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+ Block embedded Flash activation only
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+ Allow all Flash activation
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+ >
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
\ No newline at end of file
diff --git a/config/admx/Sudo.admx b/config/admx/Sudo.admx
index d9875df..f0cf16a 100644
--- a/config/admx/Sudo.admx
+++ b/config/admx/Sudo.admx
@@ -1,45 +1,45 @@
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
diff --git a/config/admx/UserProxySettings.admx b/config/admx/UserProxySettings.admx
index 8adbb18..b307837 100644
--- a/config/admx/UserProxySettings.admx
+++ b/config/admx/UserProxySettings.admx
@@ -1,58 +1,58 @@
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
\ No newline at end of file
diff --git a/config/admx/WindowsDefender.admx b/config/admx/WindowsDefender.admx
index 6fa6a3b..039af85 100644
--- a/config/admx/WindowsDefender.admx
+++ b/config/admx/WindowsDefender.admx
@@ -1,1813 +1,1813 @@
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
diff --git a/config/admx/en-US/DeviceGuard.adml b/config/admx/en-US/DeviceGuard.adml
index 5ac0c05..b59ce29 100644
--- a/config/admx/en-US/DeviceGuard.adml
+++ b/config/admx/en-US/DeviceGuard.adml
@@ -1,128 +1,128 @@
-
-
-
- Microsoft Windows Device Guard
- Windows Device Guard Security
-
-
- Device Guard
- Turn On Virtualization Based Security
-
- Specifies whether Virtualization Based Security is enabled.
-
- Virtualization Based Security uses the Windows Hypervisor to provide support for security services. Virtualization Based Security requires Secure Boot, and can optionally be enabled with the use of DMA Protections. DMA protections require hardware support and will only be enabled on correctly configured devices.
-
- Virtualization Based Protection of Code Integrity
-
- This setting enables virtualization based protection of Kernel Mode Code Integrity. When this is enabled, kernel mode memory protections are enforced and the Code Integrity validation path is protected by the Virtualization Based Security feature.
-
- The "Disabled" option turns off Virtualization Based Protection of Code Integrity remotely if it was previously turned on with the "Enabled without lock" option.
-
- The "Enabled with UEFI lock" option ensures that Virtualization Based Protection of Code Integrity cannot be disabled remotely. In order to disable the feature, you must set the Group Policy to "Disabled" as well as remove the security functionality from each computer, with a physically present user, in order to clear configuration persisted in UEFI.
-
- The "Enabled without lock" option allows Virtualization Based Protection of Code Integrity to be disabled remotely by using Group Policy.
-
- The "Not Configured" option leaves the policy setting undefined. Group Policy does not write the policy setting to the registry, and so it has no impact on computers or users. If there is a current setting in the registry it will not be modified.
-
- The "Require UEFI Memory Attributes Table" option will only enable Virtualization Based Protection of Code Integrity on devices with UEFI firmware support for the Memory Attributes Table. Devices without the UEFI Memory Attributes Table may have firmware that is incompatible with Virtualization Based Protection of Code Integrity which in some cases can lead to crashes or data loss or incompatibility with certain plug-in cards. If not setting this option the targeted devices should be tested to ensure compatibility.
-
- Warning: All drivers on the system must be compatible with this feature or the system may crash. Ensure that this policy setting is only deployed to computers which are known to be compatible.
-
- Credential Guard
-
- This setting lets users turn on Credential Guard with virtualization-based security to help protect credentials.
-
- For Windows 11 21H2 and earlier, the "Disabled" option turns off Credential Guard remotely if it was previously turned on with the "Enabled without lock" option. For later versions, the "Disabled" option turns off Credential Guard remotely if it was previously turned on with the "Enabled without lock" option or was "Not Configured".
-
- The "Enabled with UEFI lock" option ensures that Credential Guard cannot be disabled remotely. In order to disable the feature, you must set the Group Policy to "Disabled" as well as remove the security functionality from each computer, with a physically present user, in order to clear configuration persisted in UEFI.
-
- The "Enabled without lock" option allows Credential Guard to be disabled remotely by using Group Policy. The devices that use this setting must be running at least Windows 10 (Version 1511).
-
- For Windows 11 21H2 and earlier, the "Not Configured" option leaves the policy setting undefined. Group Policy does not write the policy setting to the registry, and so it has no impact on computers or users. If there is a current setting in the registry it will not be modified. For later versions, if there is no current setting in the registry, the "Not Configured" option will enable Credential Guard without UEFI lock.
-
- Machine Identity Isolation
-
- This setting controls Credential Guard protection of Active Directory machine accounts. Enabling this policy has certain prerequisites. The prerequisites and more information about this policy can be found at https://go.microsoft.com/fwlink/?linkid=2251066.
-
- The "Not Configured" option leaves the policy setting undefined. Group Policy does not write the policy setting to the registry, and so it has no impact on computers or users. If there is a current setting in the registry it will not be modified.
-
- The "Disabled" option turns off Machine Identity Isolation. If this policy was previously set to "Enabled in audit mode", no further action is needed. If this policy was previously set to “Enabled in enforcement mode”, the device must be unjoined and rejoined to the domain. More details can be found at the link above.
-
- The "Enabled in audit mode" option copies the machine identity into Credential Guard. Both LSA and Credential Guard will have access to the machine identity. This allows users to validate that "Enabled in enforcement mode" will work in their Active Directory Domain.
-
- The "Enabled in enforcement mode" option moves the machine identity into Credential Guard. This makes the machine identity only accessible to Credential Guard.
-
- Secure Launch
-
- This setting sets the configuration of Secure Launch to secure the boot chain.
-
- The "Not Configured" setting is the default, and allows configuration of the feature by Administrative users.
-
- The "Enabled" option turns on Secure Launch on supported hardware.
-
- The "Disabled" option turns off Secure Launch, regardless of hardware support.
-
- Kernel-mode Hardware-enforced Stack Protection
-
- This setting enables Hardware-enforced Stack Protection for kernel-mode code. When this security feature is enabled, kernel-mode data stacks are hardened with hardware-based shadow stacks, which store intended return address targets to ensure that program control flow is not tampered.
-
- This security feature has the following prerequisites:
- 1) The CPU hardware supports hardware-based shadow stacks.
- 2) Virtualization Based Protection of Code Integrity is enabled.
-
- If either prerequisite is not met, this feature will not be enabled, even if an "Enabled" option is selected for this feature. Note that selecting an "Enabled" option for this feature will not automatically enable Virtualization Based Protection of Code Integrity, that needs to be done separately.
-
- Devices that enable this security feature must be running at least Windows 11 (Version 22H2).
-
- The "Disabled" option turns off kernel-mode Hardware-enforced Stack Protection.
-
- The "Enabled in audit mode" option enables kernel-mode Hardware-enforced Stack Protection in audit mode, where shadow stack violations are not fatal and will be logged to the system event log.
-
- The "Enabled in enforcement mode" option enables kernel-mode Hardware-enforced Stack Protection in enforcement mode, where shadow stack violations are fatal.
-
- The "Not Configured" option leaves the policy setting undefined. Group Policy does not write the policy setting to the registry, and so it has no impact on computers or users. If there is a current setting in the registry it will not be modified.
-
- Warning: All drivers on the system must be compatible with this security feature or the system may crash in enforcement mode. Audit mode can be used to discover incompatible drivers. For more information, refer to https://go.microsoft.com/fwlink/?LinkId=2162953.
-
- Secure Boot
- Secure Boot and DMA Protection
- Disabled
- Enabled
- Enabled without lock
- Enabled with UEFI lock
- Enabled in audit mode
- Enabled in enforcement mode
- Not Configured
- Deploy App Control for Business
- Deploy App Control for Business
-
-This policy setting lets you deploy a Code Integrity Policy to a machine to control what is allowed to run on that machine.
-
-If you deploy a Code Integrity Policy, Windows will restrict what can run in both kernel mode and on the Windows Desktop based on the policy. To enable this policy the machine must be rebooted.
-
-The file path must be either a UNC path (for example, \\ServerName\ShareName\SIPolicy.p7b), or a locally valid path (for example, C:\FolderName\SIPolicy.p7b). The local machine account (LOCAL SYSTEM) must have access permission to the policy file.
-
-If using a signed and protected policy then disabling this policy setting doesn't remove the feature from the computer. Instead, you must either:
-
- 1) first update the policy to a non-protected policy and then disable the setting, or
- 2) disable the setting and then remove the policy from each computer, with a physically present user.
-
-
-
-
- Select Platform Security Level:
- Virtualization Based Protection of Code Integrity:
- Require UEFI Memory Attributes Table
- Credential Guard Configuration:
- Machine Identity Isolation Configuration:
- Secure Launch Configuration:
- Kernel-mode Hardware-enforced Stack Protection:
-
-
-
-
-
-
-
-
-
+
+
+
+ Microsoft Windows Device Guard
+ Windows Device Guard Security
+
+
+ Device Guard
+ Turn On Virtualization Based Security
+
+ Specifies whether Virtualization Based Security is enabled.
+
+ Virtualization Based Security uses the Windows Hypervisor to provide support for security services. Virtualization Based Security requires Secure Boot, and can optionally be enabled with the use of DMA Protections. DMA protections require hardware support and will only be enabled on correctly configured devices.
+
+ Virtualization Based Protection of Code Integrity
+
+ This setting enables virtualization based protection of Kernel Mode Code Integrity. When this is enabled, kernel mode memory protections are enforced and the Code Integrity validation path is protected by the Virtualization Based Security feature.
+
+ The "Disabled" option turns off Virtualization Based Protection of Code Integrity remotely if it was previously turned on with the "Enabled without lock" option.
+
+ The "Enabled with UEFI lock" option ensures that Virtualization Based Protection of Code Integrity cannot be disabled remotely. In order to disable the feature, you must set the Group Policy to "Disabled" as well as remove the security functionality from each computer, with a physically present user, in order to clear configuration persisted in UEFI.
+
+ The "Enabled without lock" option allows Virtualization Based Protection of Code Integrity to be disabled remotely by using Group Policy.
+
+ The "Not Configured" option leaves the policy setting undefined. Group Policy does not write the policy setting to the registry, and so it has no impact on computers or users. If there is a current setting in the registry it will not be modified.
+
+ The "Require UEFI Memory Attributes Table" option will only enable Virtualization Based Protection of Code Integrity on devices with UEFI firmware support for the Memory Attributes Table. Devices without the UEFI Memory Attributes Table may have firmware that is incompatible with Virtualization Based Protection of Code Integrity which in some cases can lead to crashes or data loss or incompatibility with certain plug-in cards. If not setting this option the targeted devices should be tested to ensure compatibility.
+
+ Warning: All drivers on the system must be compatible with this feature or the system may crash. Ensure that this policy setting is only deployed to computers which are known to be compatible.
+
+ Credential Guard
+
+ This setting lets users turn on Credential Guard with virtualization-based security to help protect credentials.
+
+ For Windows 11 21H2 and earlier, the "Disabled" option turns off Credential Guard remotely if it was previously turned on with the "Enabled without lock" option. For later versions, the "Disabled" option turns off Credential Guard remotely if it was previously turned on with the "Enabled without lock" option or was "Not Configured".
+
+ The "Enabled with UEFI lock" option ensures that Credential Guard cannot be disabled remotely. In order to disable the feature, you must set the Group Policy to "Disabled" as well as remove the security functionality from each computer, with a physically present user, in order to clear configuration persisted in UEFI.
+
+ The "Enabled without lock" option allows Credential Guard to be disabled remotely by using Group Policy. The devices that use this setting must be running at least Windows 10 (Version 1511).
+
+ For Windows 11 21H2 and earlier, the "Not Configured" option leaves the policy setting undefined. Group Policy does not write the policy setting to the registry, and so it has no impact on computers or users. If there is a current setting in the registry it will not be modified. For later versions, if there is no current setting in the registry, the "Not Configured" option will enable Credential Guard without UEFI lock.
+
+ Machine Identity Isolation
+
+ This setting controls Credential Guard protection of Active Directory machine accounts. Enabling this policy has certain prerequisites. The prerequisites and more information about this policy can be found at https://go.microsoft.com/fwlink/?linkid=2251066.
+
+ The "Not Configured" option leaves the policy setting undefined. Group Policy does not write the policy setting to the registry, and so it has no impact on computers or users. If there is a current setting in the registry it will not be modified.
+
+ The "Disabled" option turns off Machine Identity Isolation. If this policy was previously set to "Enabled in audit mode", no further action is needed. If this policy was previously set to “Enabled in enforcement mode”, the device must be unjoined and rejoined to the domain. More details can be found at the link above.
+
+ The "Enabled in audit mode" option copies the machine identity into Credential Guard. Both LSA and Credential Guard will have access to the machine identity. This allows users to validate that "Enabled in enforcement mode" will work in their Active Directory Domain.
+
+ The "Enabled in enforcement mode" option moves the machine identity into Credential Guard. This makes the machine identity only accessible to Credential Guard.
+
+ Secure Launch
+
+ This setting sets the configuration of Secure Launch to secure the boot chain.
+
+ The "Not Configured" setting is the default, and allows configuration of the feature by Administrative users.
+
+ The "Enabled" option turns on Secure Launch on supported hardware.
+
+ The "Disabled" option turns off Secure Launch, regardless of hardware support.
+
+ Kernel-mode Hardware-enforced Stack Protection
+
+ This setting enables Hardware-enforced Stack Protection for kernel-mode code. When this security feature is enabled, kernel-mode data stacks are hardened with hardware-based shadow stacks, which store intended return address targets to ensure that program control flow is not tampered.
+
+ This security feature has the following prerequisites:
+ 1) The CPU hardware supports hardware-based shadow stacks.
+ 2) Virtualization Based Protection of Code Integrity is enabled.
+
+ If either prerequisite is not met, this feature will not be enabled, even if an "Enabled" option is selected for this feature. Note that selecting an "Enabled" option for this feature will not automatically enable Virtualization Based Protection of Code Integrity, that needs to be done separately.
+
+ Devices that enable this security feature must be running at least Windows 11 (Version 22H2).
+
+ The "Disabled" option turns off kernel-mode Hardware-enforced Stack Protection.
+
+ The "Enabled in audit mode" option enables kernel-mode Hardware-enforced Stack Protection in audit mode, where shadow stack violations are not fatal and will be logged to the system event log.
+
+ The "Enabled in enforcement mode" option enables kernel-mode Hardware-enforced Stack Protection in enforcement mode, where shadow stack violations are fatal.
+
+ The "Not Configured" option leaves the policy setting undefined. Group Policy does not write the policy setting to the registry, and so it has no impact on computers or users. If there is a current setting in the registry it will not be modified.
+
+ Warning: All drivers on the system must be compatible with this security feature or the system may crash in enforcement mode. Audit mode can be used to discover incompatible drivers. For more information, refer to https://go.microsoft.com/fwlink/?LinkId=2162953.
+
+ Secure Boot
+ Secure Boot and DMA Protection
+ Disabled
+ Enabled
+ Enabled without lock
+ Enabled with UEFI lock
+ Enabled in audit mode
+ Enabled in enforcement mode
+ Not Configured
+ Deploy App Control for Business
+ Deploy App Control for Business
+
+This policy setting lets you deploy a Code Integrity Policy to a machine to control what is allowed to run on that machine.
+
+If you deploy a Code Integrity Policy, Windows will restrict what can run in both kernel mode and on the Windows Desktop based on the policy. To enable this policy the machine must be rebooted.
+
+The file path must be either a UNC path (for example, \\ServerName\ShareName\SIPolicy.p7b), or a locally valid path (for example, C:\FolderName\SIPolicy.p7b). The local machine account (LOCAL SYSTEM) must have access permission to the policy file.
+
+If using a signed and protected policy then disabling this policy setting doesn't remove the feature from the computer. Instead, you must either:
+
+ 1) first update the policy to a non-protected policy and then disable the setting, or
+ 2) disable the setting and then remove the policy from each computer, with a physically present user.
+
+
+
+
+ Select Platform Security Level:
+ Virtualization Based Protection of Code Integrity:
+ Require UEFI Memory Attributes Table
+ Credential Guard Configuration:
+ Machine Identity Isolation Configuration:
+ Secure Launch Configuration:
+ Kernel-mode Hardware-enforced Stack Protection:
+
+
+
+
+
+
+
+
+
diff --git a/config/admx/en-US/GameDVR.adml b/config/admx/en-US/GameDVR.adml
index e769ce7..6d75581 100644
--- a/config/admx/en-US/GameDVR.adml
+++ b/config/admx/en-US/GameDVR.adml
@@ -1,19 +1,19 @@
-
-
- Windows Game Recording and Broadcasting
- Manages the Windows Game Recording and Broadcasting states
-
-
- Windows Game Recording and Broadcasting
- Manages the Windows Game Recording and Broadcasting states
- Enables or disables Windows Game Recording and Broadcasting
- Windows 10
-
- Windows Game Recording and Broadcasting.
-
-This setting enables or disables the Windows Game Recording and Broadcasting features. If you disable this setting, Windows Game Recording will not be allowed.
-If the setting is enabled or not configured, then Recording and Broadcasting (streaming) will be allowed.
-
-
-
-
+
+
+ Windows Game Recording and Broadcasting
+ Manages the Windows Game Recording and Broadcasting states
+
+
+ Windows Game Recording and Broadcasting
+ Manages the Windows Game Recording and Broadcasting states
+ Enables or disables Windows Game Recording and Broadcasting
+ Windows 10
+
+ Windows Game Recording and Broadcasting.
+
+This setting enables or disables the Windows Game Recording and Broadcasting features. If you disable this setting, Windows Game Recording will not be allowed.
+If the setting is enabled or not configured, then Recording and Broadcasting (streaming) will be allowed.
+
+
+
+
diff --git a/config/admx/en-US/KDC.adml b/config/admx/en-US/KDC.adml
index 98e5f66..8551748 100644
--- a/config/admx/en-US/KDC.adml
+++ b/config/admx/en-US/KDC.adml
@@ -1,173 +1,173 @@
-
-
-
- KDC Settings
- Configuration settings for the Kerberos Key Distribution Center.
-
-
- KDC
- Use forest search order
- This policy setting defines the list of trusting forests that the Key Distribution Center (KDC) searches when attempting to resolve two-part service principal names (SPNs).
-
-If you enable this policy setting, the KDC will search the forests in this list if it is unable to resolve a two-part SPN in the local forest. The forest search is performed by using a global catalog or name suffix hints. If a match is found, the KDC will return a referral ticket to the client for the appropriate domain.
-
-If you disable or do not configure this policy setting, the KDC will not search the listed forests to resolve the SPN. If the KDC is unable to resolve the SPN because the name is not found, NTLM authentication might be used.
-
-To ensure consistent behavior, this policy setting must be supported and set identically on all domain controllers in the domain.
- Provide information about previous logons to client computers
- This policy setting controls whether the domain controller provides information about previous logons to client computers.
-
-If you enable this policy setting, the domain controller provides the information message about previous logons.
-
-For Windows Logon to leverage this feature, the "Display information about previous logons during user logon" policy setting located in the Windows Logon Options node under Windows Components also needs to be enabled.
-
-If you disable or do not configure this policy setting, the domain controller does not provide information about previous logons unless the "Display information about previous logons during user logon" policy setting is enabled.
-
-Note: Information about previous logons is provided only if the domain functional level is Windows Server 2008. In domains with a domain functional level of Windows Server 2003, Windows 2000 native, or Windows 2000 mixed, domain controllers cannot provide information about previous logons, and enabling this policy setting does not affect anything.
-
- KDC support for claims, compound authentication and Kerberos armoring
- This policy setting allows you to configure a domain controller to support claims and compound authentication for Dynamic Access Control and Kerberos armoring using Kerberos authentication.
-
-If you enable this policy setting, client computers that support claims and compound authentication for Dynamic Access Control and are Kerberos armor-aware will use this feature for Kerberos authentication messages. This policy should be applied to all domain controllers to ensure consistent application of this policy in the domain.
-
-If you disable or do not configure this policy setting, the domain controller does not support claims, compound authentication or armoring.
-
-If you configure the "Not supported" option, the domain controller does not support claims, compound authentication or armoring which is the default behavior for domain controllers running Windows Server 2008 R2 or earlier operating systems.
-
-Note: For the following options of this KDC policy to be effective, the Kerberos Group Policy "Kerberos client support for claims, compound authentication and Kerberos armoring" must be enabled on supported systems. If the Kerberos policy setting is not enabled, Kerberos authentication messages will not use these features.
-
-If you configure "Supported", the domain controller supports claims, compound authentication and Kerberos armoring. The domain controller advertises to Kerberos client computers that the domain is capable of claims and compound authentication for Dynamic Access Control and Kerberos armoring.
-
-Domain functional level requirements
-For the options "Always provide claims" and "Fail unarmored authentication requests", when the domain functional level is set to Windows Server 2008 R2 or earlier then domain controllers behave as if the "Supported" option is selected.
-
-When the domain functional level is set to Windows Server 2012 then the domain controller advertises to Kerberos client computers that the domain is capable of claims and compound authentication for Dynamic Access Control and Kerberos armoring, and:
- - If you set the "Always provide claims" option, always returns claims for accounts and supports the RFC behavior for advertising the flexible authentication secure tunneling (FAST).
- - If you set the "Fail unarmored authentication requests" option, rejects unarmored Kerberos messages.
-
-Warning: When "Fail unarmored authentication requests" is set, then client computers which do not support Kerberos armoring will fail to authenticate to the domain controller.
-
-To ensure this feature is effective, deploy enough domain controllers that support claims and compound authentication for Dynamic Access Control and are Kerberos armor-aware to handle the authentication requests. Insufficient number of domain controllers that support this policy result in authentication failures whenever Dynamic Access Control or Kerberos armoring is required (that is, the "Supported" option is enabled).
-
-Impact on domain controller performance when this policy setting is enabled:
- - Secure Kerberos domain capability discovery is required resulting in additional message exchanges.
- - Claims and compound authentication for Dynamic Access Control increases the size and complexity of the data in the message which results in more processing time and greater Kerberos service ticket size.
- - Kerberos armoring fully encrypts Kerberos messages and signs Kerberos errors which results in increased processing time, but does not change the service ticket size.
-
- Not supported
- Supported
- Always provide claims
- Fail unarmored authentication requests
- Warning for large Kerberos tickets
- This policy setting allows you to configure at what size Kerberos tickets will trigger the warning event issued during Kerberos authentication. The ticket size warnings are logged in the System log.
-
-If you enable this policy setting, you can set the threshold limit for Kerberos ticket which trigger the warning events. If set too high, then authentication failures might be occurring even though warning events are not being logged. If set too low, then there will be too many ticket warnings in the log to be useful for analysis. This value should be set to the same value as the Kerberos policy "Set maximum Kerberos SSPI context token buffer size" or the smallest MaxTokenSize used in your environment if you are not configuring using Group Policy.
-
-If you disable or do not configure this policy setting, the threshold value defaults to 12,000 bytes, which is the default Kerberos MaxTokenSize for Windows 7, Windows Server 2008 R2 and prior versions.
-
- Request compound authentication
- This policy setting allows you to configure a domain controller to request compound authentication.
-
-Note: For a domain controller to request compound authentication, the policy "KDC support for claims, compound authentication, and Kerberos armoring" must be configured and enabled.
-
-If you enable this policy setting, domain controllers will request compound authentication. The returned service ticket will contain compound authentication only when the account is explicitly configured. This policy should be applied to all domain controllers to ensure consistent application of this policy in the domain.
-
-If you disable or do not configure this policy setting, domain controllers will return service tickets that contain compound authentication any time the client sends a compound authentication request regardless of the account configuration.
-
- KDC support for PKInit Freshness Extension
- Support for PKInit Freshness Extension requires Windows Server 2016 domain functional level (DFL). If the domain controller’s domain is not at Windows Server 2016 DFL or higher this policy will not be applied.
-
-This policy setting allows you to configure a domain controller (DC) to support the PKInit Freshness Extension.
-
-If you enable this policy setting, the following options are supported:
-
-Supported: PKInit Freshness Extension is supported on request. Kerberos clients successfully authenticating with the PKInit Freshness Extension will get the fresh public key identity SID.
-
-Required: PKInit Freshness Extension is required for successful authentication. Kerberos clients which do not support the PKInit Freshness Extension will always fail when using public key credentials.
-
-If you disable or not configure this policy setting, then the DC will never offer the PKInit Freshness Extension and accept valid authentication requests without checking for freshness. Users will never receive the fresh public key identity SID.
-
- Disabled
- Supported
- Required
- Configure hash algorithms for certificate logon
- This policy setting controls hash or checksum algorithms used by the Kerberos client when performing certificate authentication.
-
-If you enable this policy, you will be able to configure one of four states for each algorithm:
-
-- “Default” sets the algorithm to the recommended state.
-
-- “Supported” enables usage of the algorithm. Enabling algorithms that have been disabled by default may reduce your security.
-
-- “Audited” enables usage of the algorithm and reports an event (ID 309) every time it is used. This state is intended to verify that the algorithm is not being used and can be safely disabled.
-
-- “Not Supported” disables usage of the algorithm. This state is intended for algorithms that are deemed to be insecure.
-
-If you disable or do not configure this policy, each algorithm will assume the “Default” state.
-More information about the hash and checksum algorithms supported by the Windows Kerberos client and their default states can be found at https://go.microsoft.com/fwlink/?linkid=2169037.
-
-Events generated by this configuration: 309, 310.
-
- Default
- Supported
- Audited
- Not Supported
- Allow name-based strong mappings for certificates
- This policy setting enables the use of alternative, name-based identifiers to strongly map certificates issued to Active Directory user accounts and specifies which certificates map to which accounts. Without this setting enabled, certificates must meet the “strong mapping” criteria specified in aka.ms/StrongCertMapKB, which generally disallow name-based identifiers.
-
-Each mapping specified in this policy must include a policy OID alongside an IssuerSubject and/or a UPN Suffix using the syntax specified below. If a valid mapping for a given certificate cannot be found in this policy, Active Directory will attempt to find a match using the existing strong mapping criteria specified in KB5014754. Certificate mappings which do not conform to either “strong name mapping” criteria (this policy) or the existing “strong mapping” criteria will be considered invalid for authentication.
-
-The general policy format and some examples are listed below. This policy only applies to Active Directory user accounts.
-
-General syntax
-==============
-<thumbprint>; <list of oids>; <name-match methods>
-
-Examples
-==============
-IssuerThumbprint1; oid1, oid2, oid3; UpnSuffix=domain.com
-IssuerThumbprint2; oid1; UpnSuffix=domain.com, UpnSuffix=other.domain.com, IssuerSubject
-IssuerThumbprint3; oid1, oid2; IssuerSubject
-
-The policy must contain exactly one certificate thumbprint per rule, with each rule represented as a tuple. Thumbprints must be unique and cannot be repeated in multiple rules. The sections of each tuple that are separated by semi-colons must be in the stated order, while the fields separated by commas can be in any order. The rules themselves are separated by newlines.
-
-
-
-
- Mode:
-
-
-
-
-
- Syntax:
- Enter the list of forests to be searched when this policy is enabled.
- Use the Fully Qualified Domain Name (FQDN) naming format.
- Separate multiple search entries with a semi-colon ";".
- Details:
- The current forest need not be listed because Forest Search Order uses the global catalog first then searches in the order listed.
- You do not need to separately list all the domains in the forest.
- If a trusting forest is listed, all the domains in that forest will be searched.
- For best performance, list the forests in probability of success order.
-
-
- Claims, compound authentication for Dynamic Access Control and Kerberos armoring options:
-
-
- Ticket Size Threshold
-
-
- PKInit Freshness Extension options:
-
-
- SHA-1
- SHA-256
- SHA-384
- SHA-512
-
-
- Strong Name Match Rules:
-
-
-
-
+
+
+
+ KDC Settings
+ Configuration settings for the Kerberos Key Distribution Center.
+
+
+ KDC
+ Use forest search order
+ This policy setting defines the list of trusting forests that the Key Distribution Center (KDC) searches when attempting to resolve two-part service principal names (SPNs).
+
+If you enable this policy setting, the KDC will search the forests in this list if it is unable to resolve a two-part SPN in the local forest. The forest search is performed by using a global catalog or name suffix hints. If a match is found, the KDC will return a referral ticket to the client for the appropriate domain.
+
+If you disable or do not configure this policy setting, the KDC will not search the listed forests to resolve the SPN. If the KDC is unable to resolve the SPN because the name is not found, NTLM authentication might be used.
+
+To ensure consistent behavior, this policy setting must be supported and set identically on all domain controllers in the domain.
+ Provide information about previous logons to client computers
+ This policy setting controls whether the domain controller provides information about previous logons to client computers.
+
+If you enable this policy setting, the domain controller provides the information message about previous logons.
+
+For Windows Logon to leverage this feature, the "Display information about previous logons during user logon" policy setting located in the Windows Logon Options node under Windows Components also needs to be enabled.
+
+If you disable or do not configure this policy setting, the domain controller does not provide information about previous logons unless the "Display information about previous logons during user logon" policy setting is enabled.
+
+Note: Information about previous logons is provided only if the domain functional level is Windows Server 2008. In domains with a domain functional level of Windows Server 2003, Windows 2000 native, or Windows 2000 mixed, domain controllers cannot provide information about previous logons, and enabling this policy setting does not affect anything.
+
+ KDC support for claims, compound authentication and Kerberos armoring
+ This policy setting allows you to configure a domain controller to support claims and compound authentication for Dynamic Access Control and Kerberos armoring using Kerberos authentication.
+
+If you enable this policy setting, client computers that support claims and compound authentication for Dynamic Access Control and are Kerberos armor-aware will use this feature for Kerberos authentication messages. This policy should be applied to all domain controllers to ensure consistent application of this policy in the domain.
+
+If you disable or do not configure this policy setting, the domain controller does not support claims, compound authentication or armoring.
+
+If you configure the "Not supported" option, the domain controller does not support claims, compound authentication or armoring which is the default behavior for domain controllers running Windows Server 2008 R2 or earlier operating systems.
+
+Note: For the following options of this KDC policy to be effective, the Kerberos Group Policy "Kerberos client support for claims, compound authentication and Kerberos armoring" must be enabled on supported systems. If the Kerberos policy setting is not enabled, Kerberos authentication messages will not use these features.
+
+If you configure "Supported", the domain controller supports claims, compound authentication and Kerberos armoring. The domain controller advertises to Kerberos client computers that the domain is capable of claims and compound authentication for Dynamic Access Control and Kerberos armoring.
+
+Domain functional level requirements
+For the options "Always provide claims" and "Fail unarmored authentication requests", when the domain functional level is set to Windows Server 2008 R2 or earlier then domain controllers behave as if the "Supported" option is selected.
+
+When the domain functional level is set to Windows Server 2012 then the domain controller advertises to Kerberos client computers that the domain is capable of claims and compound authentication for Dynamic Access Control and Kerberos armoring, and:
+ - If you set the "Always provide claims" option, always returns claims for accounts and supports the RFC behavior for advertising the flexible authentication secure tunneling (FAST).
+ - If you set the "Fail unarmored authentication requests" option, rejects unarmored Kerberos messages.
+
+Warning: When "Fail unarmored authentication requests" is set, then client computers which do not support Kerberos armoring will fail to authenticate to the domain controller.
+
+To ensure this feature is effective, deploy enough domain controllers that support claims and compound authentication for Dynamic Access Control and are Kerberos armor-aware to handle the authentication requests. Insufficient number of domain controllers that support this policy result in authentication failures whenever Dynamic Access Control or Kerberos armoring is required (that is, the "Supported" option is enabled).
+
+Impact on domain controller performance when this policy setting is enabled:
+ - Secure Kerberos domain capability discovery is required resulting in additional message exchanges.
+ - Claims and compound authentication for Dynamic Access Control increases the size and complexity of the data in the message which results in more processing time and greater Kerberos service ticket size.
+ - Kerberos armoring fully encrypts Kerberos messages and signs Kerberos errors which results in increased processing time, but does not change the service ticket size.
+
+ Not supported
+ Supported
+ Always provide claims
+ Fail unarmored authentication requests
+ Warning for large Kerberos tickets
+ This policy setting allows you to configure at what size Kerberos tickets will trigger the warning event issued during Kerberos authentication. The ticket size warnings are logged in the System log.
+
+If you enable this policy setting, you can set the threshold limit for Kerberos ticket which trigger the warning events. If set too high, then authentication failures might be occurring even though warning events are not being logged. If set too low, then there will be too many ticket warnings in the log to be useful for analysis. This value should be set to the same value as the Kerberos policy "Set maximum Kerberos SSPI context token buffer size" or the smallest MaxTokenSize used in your environment if you are not configuring using Group Policy.
+
+If you disable or do not configure this policy setting, the threshold value defaults to 12,000 bytes, which is the default Kerberos MaxTokenSize for Windows 7, Windows Server 2008 R2 and prior versions.
+
+ Request compound authentication
+ This policy setting allows you to configure a domain controller to request compound authentication.
+
+Note: For a domain controller to request compound authentication, the policy "KDC support for claims, compound authentication, and Kerberos armoring" must be configured and enabled.
+
+If you enable this policy setting, domain controllers will request compound authentication. The returned service ticket will contain compound authentication only when the account is explicitly configured. This policy should be applied to all domain controllers to ensure consistent application of this policy in the domain.
+
+If you disable or do not configure this policy setting, domain controllers will return service tickets that contain compound authentication any time the client sends a compound authentication request regardless of the account configuration.
+
+ KDC support for PKInit Freshness Extension
+ Support for PKInit Freshness Extension requires Windows Server 2016 domain functional level (DFL). If the domain controller’s domain is not at Windows Server 2016 DFL or higher this policy will not be applied.
+
+This policy setting allows you to configure a domain controller (DC) to support the PKInit Freshness Extension.
+
+If you enable this policy setting, the following options are supported:
+
+Supported: PKInit Freshness Extension is supported on request. Kerberos clients successfully authenticating with the PKInit Freshness Extension will get the fresh public key identity SID.
+
+Required: PKInit Freshness Extension is required for successful authentication. Kerberos clients which do not support the PKInit Freshness Extension will always fail when using public key credentials.
+
+If you disable or not configure this policy setting, then the DC will never offer the PKInit Freshness Extension and accept valid authentication requests without checking for freshness. Users will never receive the fresh public key identity SID.
+
+ Disabled
+ Supported
+ Required
+ Configure hash algorithms for certificate logon
+ This policy setting controls hash or checksum algorithms used by the Kerberos client when performing certificate authentication.
+
+If you enable this policy, you will be able to configure one of four states for each algorithm:
+
+- “Default” sets the algorithm to the recommended state.
+
+- “Supported” enables usage of the algorithm. Enabling algorithms that have been disabled by default may reduce your security.
+
+- “Audited” enables usage of the algorithm and reports an event (ID 309) every time it is used. This state is intended to verify that the algorithm is not being used and can be safely disabled.
+
+- “Not Supported” disables usage of the algorithm. This state is intended for algorithms that are deemed to be insecure.
+
+If you disable or do not configure this policy, each algorithm will assume the “Default” state.
+More information about the hash and checksum algorithms supported by the Windows Kerberos client and their default states can be found at https://go.microsoft.com/fwlink/?linkid=2169037.
+
+Events generated by this configuration: 309, 310.
+
+ Default
+ Supported
+ Audited
+ Not Supported
+ Allow name-based strong mappings for certificates
+ This policy setting enables the use of alternative, name-based identifiers to strongly map certificates issued to Active Directory user accounts and specifies which certificates map to which accounts. Without this setting enabled, certificates must meet the “strong mapping” criteria specified in aka.ms/StrongCertMapKB, which generally disallow name-based identifiers.
+
+Each mapping specified in this policy must include a policy OID alongside an IssuerSubject and/or a UPN Suffix using the syntax specified below. If a valid mapping for a given certificate cannot be found in this policy, Active Directory will attempt to find a match using the existing strong mapping criteria specified in KB5014754. Certificate mappings which do not conform to either “strong name mapping” criteria (this policy) or the existing “strong mapping” criteria will be considered invalid for authentication.
+
+The general policy format and some examples are listed below. This policy only applies to Active Directory user accounts.
+
+General syntax
+==============
+<thumbprint>; <list of oids>; <name-match methods>
+
+Examples
+==============
+IssuerThumbprint1; oid1, oid2, oid3; UpnSuffix=domain.com
+IssuerThumbprint2; oid1; UpnSuffix=domain.com, UpnSuffix=other.domain.com, IssuerSubject
+IssuerThumbprint3; oid1, oid2; IssuerSubject
+
+The policy must contain exactly one certificate thumbprint per rule, with each rule represented as a tuple. Thumbprints must be unique and cannot be repeated in multiple rules. The sections of each tuple that are separated by semi-colons must be in the stated order, while the fields separated by commas can be in any order. The rules themselves are separated by newlines.
+
+
+
+
+ Mode:
+
+
+
+
+
+ Syntax:
+ Enter the list of forests to be searched when this policy is enabled.
+ Use the Fully Qualified Domain Name (FQDN) naming format.
+ Separate multiple search entries with a semi-colon ";".
+ Details:
+ The current forest need not be listed because Forest Search Order uses the global catalog first then searches in the order listed.
+ You do not need to separately list all the domains in the forest.
+ If a trusting forest is listed, all the domains in that forest will be searched.
+ For best performance, list the forests in probability of success order.
+
+
+ Claims, compound authentication for Dynamic Access Control and Kerberos armoring options:
+
+
+ Ticket Size Threshold
+
+
+ PKInit Freshness Extension options:
+
+
+ SHA-1
+ SHA-256
+ SHA-384
+ SHA-512
+
+
+ Strong Name Match Rules:
+
+
+
+
diff --git a/config/admx/en-US/Kerberos.adml b/config/admx/en-US/Kerberos.adml
index 8227bad..3589ad5 100644
--- a/config/admx/en-US/Kerberos.adml
+++ b/config/admx/en-US/Kerberos.adml
@@ -1,283 +1,283 @@
-
-
-
- Kerberos Settings
- Configuration settings for the Kerberos authentication protocol.
-
-
- Kerberos
- Use forest search order
- This policy setting defines the list of trusting forests that the Kerberos client searches when attempting to resolve two-part service principal names (SPNs).
-
-If you enable this policy setting, the Kerberos client searches the forests in this list, if it is unable to resolve a two-part SPN. If a match is found, the Kerberos client requests a referral ticket to the appropriate domain.
-
-If you disable or do not configure this policy setting, the Kerberos client does not search the listed forests to resolve the SPN. If the Kerberos client is unable to resolve the SPN because the name is not found, NTLM authentication might be used.
- Define host name-to-Kerberos realm mappings
- This policy setting allows you to specify which DNS host names and which DNS suffixes are mapped to a Kerberos realm.
-
-If you enable this policy setting, you can view and change the list of DNS host names and DNS suffixes mapped to a Kerberos realm as defined by Group Policy. To view the list of mappings, enable the policy setting and then click the Show button. To add a mapping, enable the policy setting, note the syntax, and then click Show. In the Show Contents dialog box in the Value Name column, type a realm name. In the Value column, type the list of DNS host names and DNS suffixes using the appropriate syntax format. To remove a mapping from the list, click the mapping entry to be removed, and then press the DELETE key. To edit a mapping, remove the current entry from the list and add a new one with different parameters.
-
-If you disable this policy setting, the host name-to-Kerberos realm mappings list defined by Group Policy is deleted.
-
-If you do not configure this policy setting, the system uses the host name-to-Kerberos realm mappings that are defined in the local registry, if they exist.
- Define interoperable Kerberos V5 realm settings
- This policy setting configures the Kerberos client so that it can authenticate with interoperable Kerberos V5 realms, as defined by this policy setting.
-
-If you enable this policy setting, you can view and change the list of interoperable Kerberos V5 realms and their settings. To view the list of interoperable Kerberos V5 realms, enable the policy setting and then click the Show button. To add an interoperable Kerberos V5 realm, enable the policy setting, note the syntax, and then click Show. In the Show Contents dialog box in the Value Name column, type the interoperable Kerberos V5 realm name. In the Value column, type the realm flags and host names of the host KDCs using the appropriate syntax format. To remove an interoperable Kerberos V5 realm Value Name or Value entry from the list, click the entry, and then press the DELETE key. To edit a mapping, remove the current entry from the list and add a new one with different parameters.
-
-If you disable this policy setting, the interoperable Kerberos V5 realm settings defined by Group Policy are deleted.
-
-If you do not configure this policy setting, the system uses the interoperable Kerberos V5 realm settings that are defined in the local registry, if they exist.
- Require strict KDC validation
- This policy setting controls the Kerberos client's behavior in validating the KDC certificate for smart card and system certificate logon.
-
-If you enable this policy setting, the Kerberos client requires that the KDC's X.509 certificate contains the KDC key purpose object identifier in the Extended Key Usage (EKU) extensions, and that the KDC's X.509 certificate contains a dNSName subjectAltName (SAN) extension that matches the DNS name of the domain. If the computer is joined to a domain, the Kerberos client requires that the KDC's X.509 certificate must be signed by a Certificate Authority (CA) in the NTAuth store. If the computer is not joined to a domain, the Kerberos client allows the root CA certificate on the smart card to be used in the path validation of the KDC's X.509 certificate.
-
-If you disable or do not configure this policy setting, the Kerberos client requires only that the KDC certificate contain the Server Authentication purpose object identifier in the EKU extensions which can be issued to any server.
-
- Require strict target SPN match on remote procedure calls
- This policy setting allows you to configure this server so that Kerberos can decrypt a ticket that contains this system-generated SPN. When an application attempts to make a remote procedure call (RPC) to this server with a NULL value for the service principal name (SPN), computers running Windows 7 or later attempt to use Kerberos by generating an SPN.
-
-If you enable this policy setting, only services running as LocalSystem or NetworkService are allowed to accept these connections. Services running as identities different from LocalSystem or NetworkService might fail to authenticate.
-
-If you disable or do not configure this policy setting, any service is allowed to accept incoming connections by using this system-generated SPN.
- Specify KDC proxy servers for Kerberos clients
- This policy setting configures the Kerberos client's mapping to KDC proxy servers for domains based on their DNS suffix names.
-
-If you enable this policy setting, the Kerberos client will use the KDC proxy server for a domain when a domain controller cannot be located based on the configured mappings. To map a KDC proxy server to a domain, enable the policy setting, click Show, and then map the KDC proxy server name(s) to the DNS name for the domain using the syntax described in the options pane. In the Show Contents dialog box in the Value Name column, type a DNS suffix name. In the Value column, type the list of proxy servers using the appropriate syntax format. To view the list of mappings, enable the policy setting and then click the Show button. To remove a mapping from the list, click the mapping entry to be removed, and then press the DELETE key. To edit a mapping, remove the current entry from the list and add a new one with different parameters.
-
-If you disable or do not configure this policy setting, the Kerberos client does not have KDC proxy servers settings defined by Group Policy.
-
- Disable revocation checking for the SSL certificate of KDC proxy servers
- This policy setting allows you to disable revocation check for the SSL certificate of the targeted KDC proxy server.
-
-If you enable this policy setting, revocation check for the SSL certificate of the KDC proxy server is ignored by the Kerberos client. This policy setting should only be used in troubleshooting KDC proxy connections.
-Warning: When revocation check is ignored, the server represented by the certificate is not guaranteed valid.
-
-If you disable or do not configure this policy setting, the Kerberos client enforces the revocation check for the SSL certificate. The connection to the KDC proxy server is not established if the revocation check fails.
-
- Fail authentication requests when Kerberos armoring is not available
- This policy setting controls whether a computer requires that Kerberos message exchanges be armored when communicating with a domain controller.
-
-Warning: When a domain does not support Kerberos armoring by enabling "Support Dynamic Access Control and Kerberos armoring", then all authentication for all its users will fail from computers with this policy setting enabled.
-
-If you enable this policy setting, the client computers in the domain enforce the use of Kerberos armoring in only authentication service (AS) and ticket-granting service (TGS) message exchanges with the domain controllers.
-
-Note: The Kerberos Group Policy "Kerberos client support for claims, compound authentication and Kerberos armoring" must also be enabled to support Kerberos armoring.
-
-If you disable or do not configure this policy setting, the client computers in the domain enforce the use of Kerberos armoring when possible as supported by the target domain.
-
- Support compound authentication
- This policy setting controls configuring the device's Active Directory account for compound authentication.
-
-Support for providing compound authentication which is used for access control will require enough domain controllers in the resource account domains to support the requests. The Domain Administrator must configure the policy "Support Dynamic Access Control and Kerberos armoring" on all the domain controllers to support this policy.
-
-If you enable this policy setting, the device's Active Directory account will be configured for compound authentication by the following options:
-
-Never: Compound authentication is never provided for this computer account.
-
-Automatic: Compound authentication is provided for this computer account when one or more applications are configured for Dynamic Access Control.
-
-Always: Compound authentication is always provided for this computer account.
-
-If you disable this policy setting, Never will be used.
-If you do not configure this policy setting, Automatic will be used.
-
- Never
- Automatic
- Always
-
- Set maximum Kerberos SSPI context token buffer size
- This policy setting allows you to set the value returned to applications which request the maximum size of the SSPI context token buffer size.
-
-The size of the context token buffer determines the maximum size of SSPI context tokens an application expects and allocates. Depending upon authentication request processing and group memberships, the buffer might be smaller than the actual size of the SSPI context token.
-
-If you enable this policy setting, the Kerberos client or server uses the configured value, or the locally allowed maximum value, whichever is smaller.
-
-If you disable or do not configure this policy setting, the Kerberos client or server uses the locally configured value or the default value.
-
-Note: This policy setting configures the existing MaxTokenSize registry value in HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters, which was added in Windows XP and Windows Server 2003, with a default value of 12,000 bytes. Beginning with Windows 8 the default is 48,000 bytes. Due to HTTP's base64 encoding of authentication context tokens, it is not advised to set this value more than 48,000 bytes.
-
-
- Kerberos client support for claims, compound authentication and Kerberos armoring
- This policy setting controls whether a device will request claims and compound authentication for Dynamic Access Control and Kerberos armoring using Kerberos authentication with domains that support these features.
-If you enable this policy setting, the client computers will request claims, provide information required to create compounded authentication and armor Kerberos messages in domains which support claims and compound authentication for Dynamic Access Control and Kerberos armoring.
-
-If you disable or do not configure this policy setting, the client devices will not request claims, provide information required to create compounded authentication and armor Kerberos messages. Services hosted on the device will not be able to retrieve claims for clients using Kerberos protocol transition.
-
- Always send compound authentication first
- This policy setting controls whether a device always sends a compound authentication request when the resource domain requests compound identity.
-
-Note: For a domain controller to request compound authentication, the policies "KDC support for claims, compound authentication, and Kerberos armoring" and "Request compound authentication" must be configured and enabled in the resource account domain.
-
-If you enable this policy setting and the resource domain requests compound authentication, devices that support compound authentication always send a compound authentication request.
-
-If you disable or do not configure this policy setting and the resource domain requests compound authentication, devices will send a non-compounded authentication request first then a compound authentication request when the service requests compound authentication.
-
- Support device authentication using certificate
- Support for device authentication using certificate will require connectivity to a DC in the device account domain which supports certificate authentication for computer accounts.
-
-This policy setting allows you to set support for Kerberos to attempt authentication using the certificate for the device to the domain.
-
-If you enable this policy setting, the devices credentials will be selected based on the following options:
-
-Automatic: Device will attempt to authenticate using its certificate. If the DC does not support computer account authentication using certificates then authentication with password will be attempted.
-
-Force: Device will always authenticate using its certificate. If a DC cannot be found which support computer account authentication using certificates then authentication will fail.
-
-If you disable this policy setting, certificates will never be used.
-If you do not configure this policy setting, Automatic will be used.
-
- Automatic
- Force
- Allow retrieving the Azure AD Kerberos Ticket Granting Ticket during logon
- This policy setting allows retrieving the Azure AD Kerberos Ticket Granting Ticket during logon.
-
-If you disable or do not configure this policy setting, the Azure AD Kerberos Ticket Granting Ticket is not retrieved during logon.
-
-If you enable this policy setting, the Azure AD Kerberos Ticket Granting Ticket is retrieved during logon.
- Configure hash algorithms for certificate logon
- This policy setting controls hash or checksum algorithms used by the Kerberos client when performing certificate authentication.
-
-If you enable this policy, you will be able to configure one of four states for each algorithm:
-
-- “Default” sets the algorithm to the recommended state.
-
-- “Supported” enables usage of the algorithm. Enabling algorithms that have been disabled by default may reduce your security.
-
-- “Audited” enables usage of the algorithm and reports an event (ID 206) every time it is used. This state is intended to verify that the algorithm is not being used and can be safely disabled.
-
-- “Not Supported” disables usage of the algorithm. This state is intended for algorithms that are deemed to be insecure.
-
-If you disable or do not configure this policy, each algorithm will assume the “Default” state.
-More information about the hash and checksum algorithms supported by the Windows Kerberos client and their default states can be found at https://go.microsoft.com/fwlink/?linkid=2169037.
-
-Events generated by this configuration: 205, 206, 207, 208.
-
- Default
- Supported
- Audited
- Not Supported
-
- Enable Delegated Managed Service Account logons
- This policy setting enables or disables delegated managed service account logons for this machine.
-
-If you enable this policy setting, delegated managed service account logons will be supported by the Kerberos client. Note that this policy has certain prerequites. The prerequisites and the directions to create a new delegated managed service account can be found at https://go.microsoft.com/fwlink/?linkid=2250379.
-
-If you disable or do not configure this policy setting, delegated managed service account logons will not be supported.
-
-
-
-
- Define host name-to-realm mappings:
-
- Syntax:
- Enter the Kerberos realm name as the Value Name.
- Enter the host names and DNS suffixes, that you want to
- map to the Kerberos realm, as the Value. To add multiple
- names, separate entries with ";".
-
- Note: To specify a DNS suffix prepend the entry with a '.' period.
- For a host name entry do not specify a leading '.' period.
-
- Example:
- Value Name: MICROSOFT.COM
- Value: .microsoft.com; .ms.com; computer1.fabrikam.com;
-
- In the example above. All principals with either the DNS suffix
- of *.microsoft.com or *.ms.com will be mapped to the
- MICROSOFT.COM Kerberos realm. In addition the host name
- computer1.fabrikam.com will also be mapped to the
- MICROSOFT.COM Kerberos realm.
-
-
- Define interoperable Kerberos V5 realm settings:
-
- Syntax:
- Enter the interoperable Kerberos V5 realm name as the Value Name.
- Enter the realm flags and the host names of the KDCs as
- the Value. Enclose the realm flags with the following
- tags <f> </f>. Enclose the list of KDCs with the tags <k> </k>
- To add multiple KDC names, separate entries with
- a semi-colon ";".
-
- Example:
- Value Name: TEST.COM
- Value: <f>0x00000004</f><k>kdc1.test.com; kdc2.test.com</k>
-
- Another Example:
- Value Name: REALM.FABRIKAM.COM
- Value: <f>0x0000000E</f>
-
-
- Realms:
- Syntax:
- Enter a list of realms where DMSAs might exist.
- Enter both the Fully Qualified Domain Name (FQDN) and the short name.
- Enter one realm per line.
- Details:
- The Kerberos client will attempt to find a DMSA capable Domain Controller for the listed realms.
- If no realms are specified, the Kerberos client will attempt to find a DMSA capable Domain Controller for all realms.
-
-
- Mode:
-
-
-
-
-
- Syntax:
- Enter the list of forests to be searched when this policy is enabled.
- Use the Fully Qualified Domain Name (FQDN) naming format.
- Separate multiple search entries with a semi-colon ";".
- Details:
- The current forest need not be listed because Forest Search Order uses the global catalog first then searches in the order listed.
- You do not need to separately list all the domains in the forest.
- If a trusting forest is listed, all the domains in that forest will be searched.
- For best performance, list the forests in probability of success order.
-
-
- Define KDC proxy servers settings:
-
- Syntax:
-
- Enter the DNS suffix name as the Value Name.
- DNS suffix name allows three formats with decreasing preference order:
- Full Match: host.contoso.com
- Suffix Match: .contoso.com
- Default Match: *
-
- Enter the proxy server names as the Value.
- The proxy server names must be enclosed with tags <https />
- To add multiple proxy server names, separate entries with a space or comma ","
-
- Example:
- Value Name: .contoso.com
- Value: <https proxy1.contoso.com proxy2.contoso.com />
-
- Another Example:
- Value Name: *
- Value: <https proxy.contoso.com />
-
-
-
-
- Support authorization with client device information:
-
-
- Maximum size
-
-
-
-
- Device authentication behavior using certificate:
-
-
- SHA-1
- SHA-256
- SHA-384
- SHA-512
-
-
-
-
+
+
+
+ Kerberos Settings
+ Configuration settings for the Kerberos authentication protocol.
+
+
+ Kerberos
+ Use forest search order
+ This policy setting defines the list of trusting forests that the Kerberos client searches when attempting to resolve two-part service principal names (SPNs).
+
+If you enable this policy setting, the Kerberos client searches the forests in this list, if it is unable to resolve a two-part SPN. If a match is found, the Kerberos client requests a referral ticket to the appropriate domain.
+
+If you disable or do not configure this policy setting, the Kerberos client does not search the listed forests to resolve the SPN. If the Kerberos client is unable to resolve the SPN because the name is not found, NTLM authentication might be used.
+ Define host name-to-Kerberos realm mappings
+ This policy setting allows you to specify which DNS host names and which DNS suffixes are mapped to a Kerberos realm.
+
+If you enable this policy setting, you can view and change the list of DNS host names and DNS suffixes mapped to a Kerberos realm as defined by Group Policy. To view the list of mappings, enable the policy setting and then click the Show button. To add a mapping, enable the policy setting, note the syntax, and then click Show. In the Show Contents dialog box in the Value Name column, type a realm name. In the Value column, type the list of DNS host names and DNS suffixes using the appropriate syntax format. To remove a mapping from the list, click the mapping entry to be removed, and then press the DELETE key. To edit a mapping, remove the current entry from the list and add a new one with different parameters.
+
+If you disable this policy setting, the host name-to-Kerberos realm mappings list defined by Group Policy is deleted.
+
+If you do not configure this policy setting, the system uses the host name-to-Kerberos realm mappings that are defined in the local registry, if they exist.
+ Define interoperable Kerberos V5 realm settings
+ This policy setting configures the Kerberos client so that it can authenticate with interoperable Kerberos V5 realms, as defined by this policy setting.
+
+If you enable this policy setting, you can view and change the list of interoperable Kerberos V5 realms and their settings. To view the list of interoperable Kerberos V5 realms, enable the policy setting and then click the Show button. To add an interoperable Kerberos V5 realm, enable the policy setting, note the syntax, and then click Show. In the Show Contents dialog box in the Value Name column, type the interoperable Kerberos V5 realm name. In the Value column, type the realm flags and host names of the host KDCs using the appropriate syntax format. To remove an interoperable Kerberos V5 realm Value Name or Value entry from the list, click the entry, and then press the DELETE key. To edit a mapping, remove the current entry from the list and add a new one with different parameters.
+
+If you disable this policy setting, the interoperable Kerberos V5 realm settings defined by Group Policy are deleted.
+
+If you do not configure this policy setting, the system uses the interoperable Kerberos V5 realm settings that are defined in the local registry, if they exist.
+ Require strict KDC validation
+ This policy setting controls the Kerberos client's behavior in validating the KDC certificate for smart card and system certificate logon.
+
+If you enable this policy setting, the Kerberos client requires that the KDC's X.509 certificate contains the KDC key purpose object identifier in the Extended Key Usage (EKU) extensions, and that the KDC's X.509 certificate contains a dNSName subjectAltName (SAN) extension that matches the DNS name of the domain. If the computer is joined to a domain, the Kerberos client requires that the KDC's X.509 certificate must be signed by a Certificate Authority (CA) in the NTAuth store. If the computer is not joined to a domain, the Kerberos client allows the root CA certificate on the smart card to be used in the path validation of the KDC's X.509 certificate.
+
+If you disable or do not configure this policy setting, the Kerberos client requires only that the KDC certificate contain the Server Authentication purpose object identifier in the EKU extensions which can be issued to any server.
+
+ Require strict target SPN match on remote procedure calls
+ This policy setting allows you to configure this server so that Kerberos can decrypt a ticket that contains this system-generated SPN. When an application attempts to make a remote procedure call (RPC) to this server with a NULL value for the service principal name (SPN), computers running Windows 7 or later attempt to use Kerberos by generating an SPN.
+
+If you enable this policy setting, only services running as LocalSystem or NetworkService are allowed to accept these connections. Services running as identities different from LocalSystem or NetworkService might fail to authenticate.
+
+If you disable or do not configure this policy setting, any service is allowed to accept incoming connections by using this system-generated SPN.
+ Specify KDC proxy servers for Kerberos clients
+ This policy setting configures the Kerberos client's mapping to KDC proxy servers for domains based on their DNS suffix names.
+
+If you enable this policy setting, the Kerberos client will use the KDC proxy server for a domain when a domain controller cannot be located based on the configured mappings. To map a KDC proxy server to a domain, enable the policy setting, click Show, and then map the KDC proxy server name(s) to the DNS name for the domain using the syntax described in the options pane. In the Show Contents dialog box in the Value Name column, type a DNS suffix name. In the Value column, type the list of proxy servers using the appropriate syntax format. To view the list of mappings, enable the policy setting and then click the Show button. To remove a mapping from the list, click the mapping entry to be removed, and then press the DELETE key. To edit a mapping, remove the current entry from the list and add a new one with different parameters.
+
+If you disable or do not configure this policy setting, the Kerberos client does not have KDC proxy servers settings defined by Group Policy.
+
+ Disable revocation checking for the SSL certificate of KDC proxy servers
+ This policy setting allows you to disable revocation check for the SSL certificate of the targeted KDC proxy server.
+
+If you enable this policy setting, revocation check for the SSL certificate of the KDC proxy server is ignored by the Kerberos client. This policy setting should only be used in troubleshooting KDC proxy connections.
+Warning: When revocation check is ignored, the server represented by the certificate is not guaranteed valid.
+
+If you disable or do not configure this policy setting, the Kerberos client enforces the revocation check for the SSL certificate. The connection to the KDC proxy server is not established if the revocation check fails.
+
+ Fail authentication requests when Kerberos armoring is not available
+ This policy setting controls whether a computer requires that Kerberos message exchanges be armored when communicating with a domain controller.
+
+Warning: When a domain does not support Kerberos armoring by enabling "Support Dynamic Access Control and Kerberos armoring", then all authentication for all its users will fail from computers with this policy setting enabled.
+
+If you enable this policy setting, the client computers in the domain enforce the use of Kerberos armoring in only authentication service (AS) and ticket-granting service (TGS) message exchanges with the domain controllers.
+
+Note: The Kerberos Group Policy "Kerberos client support for claims, compound authentication and Kerberos armoring" must also be enabled to support Kerberos armoring.
+
+If you disable or do not configure this policy setting, the client computers in the domain enforce the use of Kerberos armoring when possible as supported by the target domain.
+
+ Support compound authentication
+ This policy setting controls configuring the device's Active Directory account for compound authentication.
+
+Support for providing compound authentication which is used for access control will require enough domain controllers in the resource account domains to support the requests. The Domain Administrator must configure the policy "Support Dynamic Access Control and Kerberos armoring" on all the domain controllers to support this policy.
+
+If you enable this policy setting, the device's Active Directory account will be configured for compound authentication by the following options:
+
+Never: Compound authentication is never provided for this computer account.
+
+Automatic: Compound authentication is provided for this computer account when one or more applications are configured for Dynamic Access Control.
+
+Always: Compound authentication is always provided for this computer account.
+
+If you disable this policy setting, Never will be used.
+If you do not configure this policy setting, Automatic will be used.
+
+ Never
+ Automatic
+ Always
+
+ Set maximum Kerberos SSPI context token buffer size
+ This policy setting allows you to set the value returned to applications which request the maximum size of the SSPI context token buffer size.
+
+The size of the context token buffer determines the maximum size of SSPI context tokens an application expects and allocates. Depending upon authentication request processing and group memberships, the buffer might be smaller than the actual size of the SSPI context token.
+
+If you enable this policy setting, the Kerberos client or server uses the configured value, or the locally allowed maximum value, whichever is smaller.
+
+If you disable or do not configure this policy setting, the Kerberos client or server uses the locally configured value or the default value.
+
+Note: This policy setting configures the existing MaxTokenSize registry value in HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters, which was added in Windows XP and Windows Server 2003, with a default value of 12,000 bytes. Beginning with Windows 8 the default is 48,000 bytes. Due to HTTP's base64 encoding of authentication context tokens, it is not advised to set this value more than 48,000 bytes.
+
+
+ Kerberos client support for claims, compound authentication and Kerberos armoring
+ This policy setting controls whether a device will request claims and compound authentication for Dynamic Access Control and Kerberos armoring using Kerberos authentication with domains that support these features.
+If you enable this policy setting, the client computers will request claims, provide information required to create compounded authentication and armor Kerberos messages in domains which support claims and compound authentication for Dynamic Access Control and Kerberos armoring.
+
+If you disable or do not configure this policy setting, the client devices will not request claims, provide information required to create compounded authentication and armor Kerberos messages. Services hosted on the device will not be able to retrieve claims for clients using Kerberos protocol transition.
+
+ Always send compound authentication first
+ This policy setting controls whether a device always sends a compound authentication request when the resource domain requests compound identity.
+
+Note: For a domain controller to request compound authentication, the policies "KDC support for claims, compound authentication, and Kerberos armoring" and "Request compound authentication" must be configured and enabled in the resource account domain.
+
+If you enable this policy setting and the resource domain requests compound authentication, devices that support compound authentication always send a compound authentication request.
+
+If you disable or do not configure this policy setting and the resource domain requests compound authentication, devices will send a non-compounded authentication request first then a compound authentication request when the service requests compound authentication.
+
+ Support device authentication using certificate
+ Support for device authentication using certificate will require connectivity to a DC in the device account domain which supports certificate authentication for computer accounts.
+
+This policy setting allows you to set support for Kerberos to attempt authentication using the certificate for the device to the domain.
+
+If you enable this policy setting, the devices credentials will be selected based on the following options:
+
+Automatic: Device will attempt to authenticate using its certificate. If the DC does not support computer account authentication using certificates then authentication with password will be attempted.
+
+Force: Device will always authenticate using its certificate. If a DC cannot be found which support computer account authentication using certificates then authentication will fail.
+
+If you disable this policy setting, certificates will never be used.
+If you do not configure this policy setting, Automatic will be used.
+
+ Automatic
+ Force
+ Allow retrieving the Azure AD Kerberos Ticket Granting Ticket during logon
+ This policy setting allows retrieving the Azure AD Kerberos Ticket Granting Ticket during logon.
+
+If you disable or do not configure this policy setting, the Azure AD Kerberos Ticket Granting Ticket is not retrieved during logon.
+
+If you enable this policy setting, the Azure AD Kerberos Ticket Granting Ticket is retrieved during logon.
+ Configure hash algorithms for certificate logon
+ This policy setting controls hash or checksum algorithms used by the Kerberos client when performing certificate authentication.
+
+If you enable this policy, you will be able to configure one of four states for each algorithm:
+
+- “Default” sets the algorithm to the recommended state.
+
+- “Supported” enables usage of the algorithm. Enabling algorithms that have been disabled by default may reduce your security.
+
+- “Audited” enables usage of the algorithm and reports an event (ID 206) every time it is used. This state is intended to verify that the algorithm is not being used and can be safely disabled.
+
+- “Not Supported” disables usage of the algorithm. This state is intended for algorithms that are deemed to be insecure.
+
+If you disable or do not configure this policy, each algorithm will assume the “Default” state.
+More information about the hash and checksum algorithms supported by the Windows Kerberos client and their default states can be found at https://go.microsoft.com/fwlink/?linkid=2169037.
+
+Events generated by this configuration: 205, 206, 207, 208.
+
+ Default
+ Supported
+ Audited
+ Not Supported
+
+ Enable Delegated Managed Service Account logons
+ This policy setting enables or disables delegated managed service account logons for this machine.
+
+If you enable this policy setting, delegated managed service account logons will be supported by the Kerberos client. Note that this policy has certain prerequites. The prerequisites and the directions to create a new delegated managed service account can be found at https://go.microsoft.com/fwlink/?linkid=2250379.
+
+If you disable or do not configure this policy setting, delegated managed service account logons will not be supported.
+
+
+
+
+ Define host name-to-realm mappings:
+
+ Syntax:
+ Enter the Kerberos realm name as the Value Name.
+ Enter the host names and DNS suffixes, that you want to
+ map to the Kerberos realm, as the Value. To add multiple
+ names, separate entries with ";".
+
+ Note: To specify a DNS suffix prepend the entry with a '.' period.
+ For a host name entry do not specify a leading '.' period.
+
+ Example:
+ Value Name: MICROSOFT.COM
+ Value: .microsoft.com; .ms.com; computer1.fabrikam.com;
+
+ In the example above. All principals with either the DNS suffix
+ of *.microsoft.com or *.ms.com will be mapped to the
+ MICROSOFT.COM Kerberos realm. In addition the host name
+ computer1.fabrikam.com will also be mapped to the
+ MICROSOFT.COM Kerberos realm.
+
+
+ Define interoperable Kerberos V5 realm settings:
+
+ Syntax:
+ Enter the interoperable Kerberos V5 realm name as the Value Name.
+ Enter the realm flags and the host names of the KDCs as
+ the Value. Enclose the realm flags with the following
+ tags <f> </f>. Enclose the list of KDCs with the tags <k> </k>
+ To add multiple KDC names, separate entries with
+ a semi-colon ";".
+
+ Example:
+ Value Name: TEST.COM
+ Value: <f>0x00000004</f><k>kdc1.test.com; kdc2.test.com</k>
+
+ Another Example:
+ Value Name: REALM.FABRIKAM.COM
+ Value: <f>0x0000000E</f>
+
+
+ Realms:
+ Syntax:
+ Enter a list of realms where DMSAs might exist.
+ Enter both the Fully Qualified Domain Name (FQDN) and the short name.
+ Enter one realm per line.
+ Details:
+ The Kerberos client will attempt to find a DMSA capable Domain Controller for the listed realms.
+ If no realms are specified, the Kerberos client will attempt to find a DMSA capable Domain Controller for all realms.
+
+
+ Mode:
+
+
+
+
+
+ Syntax:
+ Enter the list of forests to be searched when this policy is enabled.
+ Use the Fully Qualified Domain Name (FQDN) naming format.
+ Separate multiple search entries with a semi-colon ";".
+ Details:
+ The current forest need not be listed because Forest Search Order uses the global catalog first then searches in the order listed.
+ You do not need to separately list all the domains in the forest.
+ If a trusting forest is listed, all the domains in that forest will be searched.
+ For best performance, list the forests in probability of success order.
+
+
+ Define KDC proxy servers settings:
+
+ Syntax:
+
+ Enter the DNS suffix name as the Value Name.
+ DNS suffix name allows three formats with decreasing preference order:
+ Full Match: host.contoso.com
+ Suffix Match: .contoso.com
+ Default Match: *
+
+ Enter the proxy server names as the Value.
+ The proxy server names must be enclosed with tags <https />
+ To add multiple proxy server names, separate entries with a space or comma ","
+
+ Example:
+ Value Name: .contoso.com
+ Value: <https proxy1.contoso.com proxy2.contoso.com />
+
+ Another Example:
+ Value Name: *
+ Value: <https proxy.contoso.com />
+
+
+
+
+ Support authorization with client device information:
+
+
+ Maximum size
+
+
+
+
+ Device authentication behavior using certificate:
+
+
+ SHA-1
+ SHA-256
+ SHA-384
+ SHA-512
+
+
+
+
diff --git a/config/admx/en-US/LAPS.adml b/config/admx/en-US/LAPS.adml
index a37390e..b4f72a9 100644
--- a/config/admx/en-US/LAPS.adml
+++ b/config/admx/en-US/LAPS.adml
@@ -1,260 +1,260 @@
-
-
-
-
-
-
-
- LAPS
- Configure password backup directory
- Use this setting to configure which directory the local admin account password is backed up to.
-
-The allowable settings are:
-
-0=Disabled (password will not be backed up)
-
-1=Backup the password to Azure Active Directory
-
-2=Backup the password to Active Directory
-
-If not specified, this setting will default to 0 (Disabled).
-
-If this setting is configured to 1, and the managed device is not joined to Azure Active Directory, the local administrator password will not be managed.
-
-If this setting is configured to 2, and the managed device is not joined to Active Directory, the local administrator password will not be managed.
-
-If this setting is disabled or not configured, the local administrator password is not managed.
-
-See https://go.microsoft.com/fwlink/?linkid=2188435 for more information.
-
- Disabled
- Azure Active Directory
- Active Directory
- Password Settings
- Configures password parameters
-
-Password complexity: which characters are used when generating a new password
- Default: Large letters + small letters + numbers + special characters
-
-Password length
- Minimum: 8 characters
- Maximum: 64 characters
- Default: 14 characters
-
-Password age in days
- Minimum: 1 day (7 days when backup directory is configured to be Azure AD)
- Maximum: 365 days
- Default: 30 days
-
-Passphrase length
- Minimum: 3 words
- Maximum: 10 words
- Default: 6 words
-
-See https://go.microsoft.com/fwlink/?linkid=2188435 for more information.
-
-Passphrase list taken from "Deep Dive: EFF's New Wordlists for Random Passphrases" by Electronic Frontier Foundation, and is used under a CC-BY-3.0 Attribution license. See https://go.microsoft.com/fwlink/?linkid=2255471 for more information.
-
- Large letters
- Large letters + small letters
- Large letters + small letters + numbers
- Large letters + small letters + numbers + specials
- Large letters + small letters + numbers + specials (improved readability)
- Passphrase (long words)
- Passphrase (short words)
- Passphrase (short words with unique prefixes)
- Name of administrator account to manage
- This policy setting specifies a custom Administrator account name to manage the password for.
-
-If this policy setting is enabled, LAPS will manage the password for a local account with this name.
-
-If this policy setting is disabled or not configured, LAPS will manage the password for the well known Administrator account.
-
-DO NOT enable this policy setting to manage the built-in administrator account. The built-in administrator account is auto-detected by well-known SID and does not depend on the account name.
-
-See https://go.microsoft.com/fwlink/?linkid=2188435 for more information.
-
- Do not allow password expiration time longer than required by policy
- If this setting is enabled or not configured, planned password expiration longer than the password age dictated by the "Password Settings" policy is NOT allowed. When such expiration is detected, the password is changed immediately and password expiration is set according to policy.
-
-If this setting is disabled, password expiration time may be longer than required by "Password Settings" policy.
-
-See https://go.microsoft.com/fwlink/?linkid=2188435 for more information.
-
- Enable password encryption
- When you enable this setting, the managed password is encrypted before being sent to Active Directory.
-
-Enabling this setting has no effect unless 1) the password has been configured to be backed up to Active Directory and 2) the Active Directory domain functional level is at Windows Server 2016 or above.
-
-If this setting is enabled, and the domain functional level is at or above Windows Server 2016, the managed account password is encrypted.
-
-If this setting is enabled, and the domain functional level is less than Windows Server 2016, the managed account password is not backed up to the directory.
-
-If this setting is disabled, the managed account password is not encrypted.
-
-This setting will default to enabled if not configured.
-
-See https://go.microsoft.com/fwlink/?linkid=2188435 for more information.
-
- Configure authorized password decryptors
- Configure this setting to control the specific user or group who is authorized to decrypt encrypted passwords.
-
-Configuring this setting has no effect unless password encryption has been enabled.
-
-If this setting is enabled, encrypted passwords will be decryptable by the specified group.
-
-If this setting is disabled or not configured, encrypted passwords will be decryptable by the Domain Admins group.
-
-This setting must be configured with either a domain-qualified name of a group or user, or a SID in string format. Valid examples include:
-
-contoso\LAPSAdmins
-
-lapsadmins@contoso.com
-
-S-1-5-21-2127521184-1604012920-1887927527-35197
-
-Do not enclose the user\group name or SID in enclosing quotes or parentheses.
-
-The specified user or group must be resolvable by the managed device, otherwise passwords will not be backed up.
-
-NOTE: this setting is ignored when Directory Services Repair Mode (DSRM) account passwords are backed up on a domain controller. In that scenario, this setting always defaults to the Domain Admins group of the domain controller's domain.
-
-See https://go.microsoft.com/fwlink/?linkid=2188435 for more information.
-
- Configure size of encrypted password history
- Use this setting to configure how many previous encrypted passwords will be stored in Active Directory.
-
-Configuring this setting has no effect unless 1) the password has been configured to be backed up to Active Directory and 2) password encryption has been enabled.
-
-If this setting is enabled, the specified number of older passwords will be stored in Active Directory.
-
-If this setting is disabled or not configured, zero older passwords will be stored in Active Directory.
-
-This setting has a minimum allowed value of 0 passwords.
-
-This setting has a maximum allowed value of 12 passwords.
-
-See https://go.microsoft.com/fwlink/?linkid=2188435 for more information.
-
- Enable password backup for DSRM accounts
- When you enable this setting, the DSRM administrator account password will be managed and backed up to Active Directory.
-
-Enabling this setting has no effect unless the managed device is a domain controller and password encryption is also enabled.
-
-If this setting is enabled, the password for the DSRM administrator account on the domain controller will be backed up to Active Directory.
-
-If this setting is disabled or not configured, the password for the DSRM administrator account on the domain controller will not be backed up to Active Directory.
-
-See https://go.microsoft.com/fwlink/?linkid=2188435 for more information.
-
- Post-authentication actions
- This policy configures post-authentication actions which will be executed after detecting an authentication by the managed account.
-
-Grace period: specifies the amount of time (in hours) to wait after an authentication before executing the specified post-authentication actions.
-
-If this setting is enabled and greater than zero, the specified post-authentication actions will be executed upon expiration of the grace period.
-
-If this setting is disabled or not configured, the specified post-authentication actions will be executed after a default 24 hour grace period.
-
-If this setting is equal to zero, no post-authentication actions will be executed.
-
-Actions: specifies the actions to take upon expiration of the grace period.
-
-Reset password: upon expiration of the grace period, the managed account password is reset.
-
-Reset the password and logoff the managed account: upon expiration of the grace period, the managed account password is reset and any interactive logon sessions using the managed account are logged off.
-
-Reset the password and reboot: upon expiration of the grace period, the managed account password is reset and the managed device is rebooted.
-
-Reset the password, logoff the managed account, and terminate any remaining processes: upon expiration of the grace period, the managed account password is reset, any interactive logon sessions using the managed account are logged off, and any remaining processes are terminated.
-
-(NOTE: after any interactive logon sessions are terminated there may still be other authenticated sessions in use by the managed account. The only robust way to ensure that the previous password is longer in use is to reboot the device.)
-
-If this setting is disabled or not configured, post-authentication actions will default to "Reset the password and logoff the managed account".
-
-Note: the DSRM account on domain controllers cannot be configured for post-authentication actions. This policy has no effect on domain controllers and will be ignored even if configured for a DC.
-
-See https://go.microsoft.com/fwlink/?linkid=2188435 for more information.
-
- Disabled - take no actions
- Reset the password
- Reset the password and logoff the managed account
- Reset the password and reboot the device
- Reset the password, logoff the managed account, and terminate any remaining processes
- Configure automatic account management
- This policy configures automatic account management policy options.
-
-Specify the target account to manage: specifies whether the built-in admin account or a custom account should be managed.
-
-Automatic account name (or name prefix): specifies the name, or name prefix, to use for the managed account.
-
-If this policy setting is configured, Windows LAPS will use it as the account name or name prefix for the target account.
-
-If this policy setting is not configured, Windows LAPS will use "WLapsAdmin" as the account name or name prefix.
-
-Note: this name is treated as a prefix when account name randomization is configured, see comments below.
-
-Enable the managed account: specifies whether the managed account should be enabled or not.
-
-If this policy setting is configured, Windows LAPS will enable the specified managed account.
-
-If this policy setting is not configured, Windows LAPS will disable the specified managed account.
-
-Note: Windows LAPS will regularly maintain and rotate the password of the managed account regardless of whether the account is maintained in an enabled\disabled status.
-
-Randomize the name of the managed account: specifies whether the name of the managed account should be randomized with a random numeric suffix.
-
-If this policy setting is configured, Windows LAPS will add an eight digit random numeric suffix to the managed automatic account name, and will re-randomize the name of the managed account every time the password is rotated.
-
-If this policy setting is not configured, Windows LAPS will use the managed automatic account name as configured.
-
-If the managed automatic account name prefix is configured, Windows LAPS will use up to the first twelve (12) characters of that name as a prefix for the random name. If the managed automatic account name is not configured, Windows LAPS will use "WLapsAdmin" as the name prefix.
-
-Note: the DSRM account on domain controllers cannot be configured for automatic account management. This policy has no effect on domain controllers and will be ignored even if configured for a DC.
-
-See https://go.microsoft.com/fwlink/?linkid=2188435 for more information.
-
- Manage the built-in admin account
- Manage a custom admin account
- Specify the account name or name prefix
- Specifies whether the automatic account name should be randomized.
- At least Microsoft Windows 10 or later
-
-
-
- Backup directory
-
-
- Password Complexity
- Password Length
- Password Age (Days)
- Passphrase Length (words)
-
-
-
-
-
-
-
-
-
-
-
-
- Encrypted password history size
-
-
- Grace period (hours):
- Actions:
-
-
- Specify the target account to manage:
-
-
-
- Enable the managed account
- Randomize the name of the managed account
-
-
-
-
+
+
+
+
+
+
+
+ LAPS
+ Configure password backup directory
+ Use this setting to configure which directory the local admin account password is backed up to.
+
+The allowable settings are:
+
+0=Disabled (password will not be backed up)
+
+1=Backup the password to Azure Active Directory
+
+2=Backup the password to Active Directory
+
+If not specified, this setting will default to 0 (Disabled).
+
+If this setting is configured to 1, and the managed device is not joined to Azure Active Directory, the local administrator password will not be managed.
+
+If this setting is configured to 2, and the managed device is not joined to Active Directory, the local administrator password will not be managed.
+
+If this setting is disabled or not configured, the local administrator password is not managed.
+
+See https://go.microsoft.com/fwlink/?linkid=2188435 for more information.
+
+ Disabled
+ Azure Active Directory
+ Active Directory
+ Password Settings
+ Configures password parameters
+
+Password complexity: which characters are used when generating a new password
+ Default: Large letters + small letters + numbers + special characters
+
+Password length
+ Minimum: 8 characters
+ Maximum: 64 characters
+ Default: 14 characters
+
+Password age in days
+ Minimum: 1 day (7 days when backup directory is configured to be Azure AD)
+ Maximum: 365 days
+ Default: 30 days
+
+Passphrase length
+ Minimum: 3 words
+ Maximum: 10 words
+ Default: 6 words
+
+See https://go.microsoft.com/fwlink/?linkid=2188435 for more information.
+
+Passphrase list taken from "Deep Dive: EFF's New Wordlists for Random Passphrases" by Electronic Frontier Foundation, and is used under a CC-BY-3.0 Attribution license. See https://go.microsoft.com/fwlink/?linkid=2255471 for more information.
+
+ Large letters
+ Large letters + small letters
+ Large letters + small letters + numbers
+ Large letters + small letters + numbers + specials
+ Large letters + small letters + numbers + specials (improved readability)
+ Passphrase (long words)
+ Passphrase (short words)
+ Passphrase (short words with unique prefixes)
+ Name of administrator account to manage
+ This policy setting specifies a custom Administrator account name to manage the password for.
+
+If this policy setting is enabled, LAPS will manage the password for a local account with this name.
+
+If this policy setting is disabled or not configured, LAPS will manage the password for the well known Administrator account.
+
+DO NOT enable this policy setting to manage the built-in administrator account. The built-in administrator account is auto-detected by well-known SID and does not depend on the account name.
+
+See https://go.microsoft.com/fwlink/?linkid=2188435 for more information.
+
+ Do not allow password expiration time longer than required by policy
+ If this setting is enabled or not configured, planned password expiration longer than the password age dictated by the "Password Settings" policy is NOT allowed. When such expiration is detected, the password is changed immediately and password expiration is set according to policy.
+
+If this setting is disabled, password expiration time may be longer than required by "Password Settings" policy.
+
+See https://go.microsoft.com/fwlink/?linkid=2188435 for more information.
+
+ Enable password encryption
+ When you enable this setting, the managed password is encrypted before being sent to Active Directory.
+
+Enabling this setting has no effect unless 1) the password has been configured to be backed up to Active Directory and 2) the Active Directory domain functional level is at Windows Server 2016 or above.
+
+If this setting is enabled, and the domain functional level is at or above Windows Server 2016, the managed account password is encrypted.
+
+If this setting is enabled, and the domain functional level is less than Windows Server 2016, the managed account password is not backed up to the directory.
+
+If this setting is disabled, the managed account password is not encrypted.
+
+This setting will default to enabled if not configured.
+
+See https://go.microsoft.com/fwlink/?linkid=2188435 for more information.
+
+ Configure authorized password decryptors
+ Configure this setting to control the specific user or group who is authorized to decrypt encrypted passwords.
+
+Configuring this setting has no effect unless password encryption has been enabled.
+
+If this setting is enabled, encrypted passwords will be decryptable by the specified group.
+
+If this setting is disabled or not configured, encrypted passwords will be decryptable by the Domain Admins group.
+
+This setting must be configured with either a domain-qualified name of a group or user, or a SID in string format. Valid examples include:
+
+contoso\LAPSAdmins
+
+lapsadmins@contoso.com
+
+S-1-5-21-2127521184-1604012920-1887927527-35197
+
+Do not enclose the user\group name or SID in enclosing quotes or parentheses.
+
+The specified user or group must be resolvable by the managed device, otherwise passwords will not be backed up.
+
+NOTE: this setting is ignored when Directory Services Repair Mode (DSRM) account passwords are backed up on a domain controller. In that scenario, this setting always defaults to the Domain Admins group of the domain controller's domain.
+
+See https://go.microsoft.com/fwlink/?linkid=2188435 for more information.
+
+ Configure size of encrypted password history
+ Use this setting to configure how many previous encrypted passwords will be stored in Active Directory.
+
+Configuring this setting has no effect unless 1) the password has been configured to be backed up to Active Directory and 2) password encryption has been enabled.
+
+If this setting is enabled, the specified number of older passwords will be stored in Active Directory.
+
+If this setting is disabled or not configured, zero older passwords will be stored in Active Directory.
+
+This setting has a minimum allowed value of 0 passwords.
+
+This setting has a maximum allowed value of 12 passwords.
+
+See https://go.microsoft.com/fwlink/?linkid=2188435 for more information.
+
+ Enable password backup for DSRM accounts
+ When you enable this setting, the DSRM administrator account password will be managed and backed up to Active Directory.
+
+Enabling this setting has no effect unless the managed device is a domain controller and password encryption is also enabled.
+
+If this setting is enabled, the password for the DSRM administrator account on the domain controller will be backed up to Active Directory.
+
+If this setting is disabled or not configured, the password for the DSRM administrator account on the domain controller will not be backed up to Active Directory.
+
+See https://go.microsoft.com/fwlink/?linkid=2188435 for more information.
+
+ Post-authentication actions
+ This policy configures post-authentication actions which will be executed after detecting an authentication by the managed account.
+
+Grace period: specifies the amount of time (in hours) to wait after an authentication before executing the specified post-authentication actions.
+
+If this setting is enabled and greater than zero, the specified post-authentication actions will be executed upon expiration of the grace period.
+
+If this setting is disabled or not configured, the specified post-authentication actions will be executed after a default 24 hour grace period.
+
+If this setting is equal to zero, no post-authentication actions will be executed.
+
+Actions: specifies the actions to take upon expiration of the grace period.
+
+Reset password: upon expiration of the grace period, the managed account password is reset.
+
+Reset the password and logoff the managed account: upon expiration of the grace period, the managed account password is reset and any interactive logon sessions using the managed account are logged off.
+
+Reset the password and reboot: upon expiration of the grace period, the managed account password is reset and the managed device is rebooted.
+
+Reset the password, logoff the managed account, and terminate any remaining processes: upon expiration of the grace period, the managed account password is reset, any interactive logon sessions using the managed account are logged off, and any remaining processes are terminated.
+
+(NOTE: after any interactive logon sessions are terminated there may still be other authenticated sessions in use by the managed account. The only robust way to ensure that the previous password is longer in use is to reboot the device.)
+
+If this setting is disabled or not configured, post-authentication actions will default to "Reset the password and logoff the managed account".
+
+Note: the DSRM account on domain controllers cannot be configured for post-authentication actions. This policy has no effect on domain controllers and will be ignored even if configured for a DC.
+
+See https://go.microsoft.com/fwlink/?linkid=2188435 for more information.
+
+ Disabled - take no actions
+ Reset the password
+ Reset the password and logoff the managed account
+ Reset the password and reboot the device
+ Reset the password, logoff the managed account, and terminate any remaining processes
+ Configure automatic account management
+ This policy configures automatic account management policy options.
+
+Specify the target account to manage: specifies whether the built-in admin account or a custom account should be managed.
+
+Automatic account name (or name prefix): specifies the name, or name prefix, to use for the managed account.
+
+If this policy setting is configured, Windows LAPS will use it as the account name or name prefix for the target account.
+
+If this policy setting is not configured, Windows LAPS will use "WLapsAdmin" as the account name or name prefix.
+
+Note: this name is treated as a prefix when account name randomization is configured, see comments below.
+
+Enable the managed account: specifies whether the managed account should be enabled or not.
+
+If this policy setting is configured, Windows LAPS will enable the specified managed account.
+
+If this policy setting is not configured, Windows LAPS will disable the specified managed account.
+
+Note: Windows LAPS will regularly maintain and rotate the password of the managed account regardless of whether the account is maintained in an enabled\disabled status.
+
+Randomize the name of the managed account: specifies whether the name of the managed account should be randomized with a random numeric suffix.
+
+If this policy setting is configured, Windows LAPS will add an eight digit random numeric suffix to the managed automatic account name, and will re-randomize the name of the managed account every time the password is rotated.
+
+If this policy setting is not configured, Windows LAPS will use the managed automatic account name as configured.
+
+If the managed automatic account name prefix is configured, Windows LAPS will use up to the first twelve (12) characters of that name as a prefix for the random name. If the managed automatic account name is not configured, Windows LAPS will use "WLapsAdmin" as the name prefix.
+
+Note: the DSRM account on domain controllers cannot be configured for automatic account management. This policy has no effect on domain controllers and will be ignored even if configured for a DC.
+
+See https://go.microsoft.com/fwlink/?linkid=2188435 for more information.
+
+ Manage the built-in admin account
+ Manage a custom admin account
+ Specify the account name or name prefix
+ Specifies whether the automatic account name should be randomized.
+ At least Microsoft Windows 10 or later
+
+
+
+ Backup directory
+
+
+ Password Complexity
+ Password Length
+ Password Age (Days)
+ Passphrase Length (words)
+
+
+
+
+
+
+
+
+
+
+
+
+ Encrypted password history size
+
+
+ Grace period (hours):
+ Actions:
+
+
+ Specify the target account to manage:
+
+
+
+ Enable the managed account
+ Randomize the name of the managed account
+
+
+
+
diff --git a/config/admx/en-US/LanmanServer.adml b/config/admx/en-US/LanmanServer.adml
index b152c43..210f7d6 100644
--- a/config/admx/en-US/LanmanServer.adml
+++ b/config/admx/en-US/LanmanServer.adml
@@ -1,228 +1,228 @@
-
-
-
- enter display name here
- enter description here
-
-
- Lanman Server
- Allow hash publication only for shared folders on which BranchCache is enabled
- Disallow hash publication on all shared folders
- Allow hash publication for all shared folders
- Hash Publication for BranchCache
- This policy setting specifies whether a hash generation service generates hashes, also called content information, for data that is stored in shared folders. This policy setting must be applied to server computers that have the File Services role and both the File Server and the BranchCache for Network Files role services installed.
-
-Policy configuration
-
-Select one of the following:
-
-- Not Configured. With this selection, hash publication settings are not applied to file servers. In the circumstance where file servers are domain members but you do not want to enable BranchCache on all file servers, you can specify Not Configured for this domain Group Policy setting, and then configure local machine policy to enable BranchCache on individual file servers. Because the domain Group Policy setting is not configured, it will not over-write the enabled setting that you use on individual servers where you want to enable BranchCache.
-
-- Enabled. With this selection, hash publication is turned on for all file servers where Group Policy is applied. For example, if Hash Publication for BranchCache is enabled in domain Group Policy, hash publication is turned on for all domain member file servers to which the policy is applied. The file servers are then able to create content information for all content that is stored in BranchCache-enabled file shares.
-
-- Disabled. With this selection, hash publication is turned off for all file servers where Group Policy is applied.
-
-In circumstances where this policy setting is enabled, you can also select the following configuration options:
-
-- Allow hash publication for all shared folders. With this option, BranchCache generates content information for all content in all shares on the file server.
-
-- Allow hash publication only for shared folders on which BranchCache is enabled. With this option, content information is generated only for shared folders on which BranchCache is enabled. If you use this setting, you must enable BranchCache for individual shares in Share and Storage Management on the file server.
-
-- Disallow hash publication on all shared folders. With this option, BranchCache does not generate content information for any shares on the computer and does not send content information to client computers that request content.
-
- Supports V1 hash version only
- Supports V2 hash version only
- Supports V1 as well as V2 versions
- Hash Version support for BranchCache
- This policy setting specifies whether the BranchCache hash generation service supports version 1 (V1) hashes, version 2 (V2) hashes, or both V1 and V2 hashes. Hashes, also called content information, are created based on the data in shared folders where BranchCache is enabled.
-
-If you specify only one version that is supported, content information for that version is the only type that is generated by BranchCache, and it is the only type of content information that can be retrieved by client computers. For example, if you enable support for V1 hashes, BranchCache generates only V1 hashes and client computers can retrieve only V1 hashes.
-
-Policy configuration
-
-Select one of the following:
-
-- Not Configured. With this selection, BranchCache settings are not applied to client computers by this policy setting. In this circumstance, which is the default, both V1 and V2 hash generation and retrieval are supported.
-
-- Enabled. With this selection, the policy setting is applied and the hash version(s) that are specified in "Hash version supported" are generated and retrieved.
-
-- Disabled. With this selection, both V1 and V2 hash generation and retrieval are supported.
-
-In circumstances where this setting is enabled, you can also select and configure the following option:
-
-Hash version supported:
-
-- To support V1 content information only, configure "Hash version supported" with the value of 1.
-
-- To support V2 content information only, configure "Hash version supported" with the value of 2.
-
-- To support both V1 and V2 content information, configure "Hash version supported" with the value of 3.
- Cipher suite order
- This policy setting determines the cipher suites used by the SMB server.
-
-If you enable this policy setting, cipher suites are prioritized in the order specified.
-
-If you enable this policy setting and do not specify at least one supported cipher suite, or if you disable or do not configure this policy setting, the default cipher suite order is used.
-
-SMB 3.11 cipher suites:
-
-AES_128_GCM
-AES_128_CCM
-AES_256_GCM
-AES_256_CCM
-
-SMB 3.0 and 3.02 cipher suites:
-
-AES_128_CCM
-
-How to modify this setting:
-
-Arrange the desired cipher suites in the edit box, one cipher suite per line, in order from most to least preferred, with the most preferred cipher suite at the top. Remove any cipher suites you don't want to use.
-
-Note: When configuring this security setting, changes will not take effect until you restart Windows.
- Honor cipher suite order
- This policy setting determines how the SMB server selects a cipher suite when negotiating a new connection with an SMB client.
-
-If you enable this policy setting, the SMB server will select the cipher suite it most prefers from the SMB client's cipher suites, ignoring the client's cipher suite preferences.
-
-If you disable or do not configure this policy setting, the SMB server will select the cipher suite the SMB client most prefers from the server's cipher suites.
-
-Note: When configuring this security setting, changes will not take effect until you restart Windows.
- Honor cipher suite order
- This policy setting determines how the SMB server selects a cipher suite when negotiating a new connection with an SMB client.
-
-If you enable this policy setting, the SMB server will select the cipher suite it most prefers from the list of client-supported cipher suites, ignoring the client's preferences.
-
-If you disable or do not configure this policy setting, the SMB server will select the cipher suite the client most prefers from the list of server-supported cipher suites.
-
-Note: When configuring this security setting, changes will not take effect until you restart Windows.
- At least Windows Server 2022, Windows 11
- At least Windows Server 2025, Windows 11
- At least Windows Server 2025, Windows 11 24H2
- Request traffic compression for all shares
- This policy controls whether the SMB server requests SMB client to use traffic compression for all SMB shares.
-
-If you enable this policy setting, the SMB server will by default request the SMB client to compress traffic when SMB compression is enabled. See notes below.
-
-If you disable or do not configure this policy setting, the SMB server will not by default request the SMB client to compress traffic. However traffic compression may be requested by other means. See notes below.
-
-Note: If this policy is disabled, traffic compression may be requested by server-side per-share properties or by the SMB Client. If this is undesired, and one wishes to completely disable compression, configure the accompanying 'Disable SMB compression' policy instead.
-
-Note: Traffic compression can only be used when both the SMB client and SMB server support and enable traffic compression.
-
- Disable SMB compression
- This policy controls whether the SMB server will disable (completely prevent) traffic compression.
-
-If you enable this policy setting, the SMB server will never compress data, irrespective of other policies (such as the 'Use SMB compression by default' policy or per-share property).
-
-If you disable or do not configure this policy setting, the SMB server may compress traffic (depending on a combination of other policies and conditions).
-
- Mandate the maximum version of SMB
- This policy controls the maximum version of SMB protocol
-
-Note: This group policy does not prevent use of SMB 1 if that component is still installed and enabled.
-
- Mandate the minimum version of SMB
- This policy controls the minimum version of SMB protocol
-
-Note: This group policy does not prevent use of SMB 1 if that component is still installed and enabled.
-
- SMB 2.0.2
- SMB 2.1.0
- SMB 3.0.0
- SMB 3.0.2
- SMB 3.1.1
-
- Enable remote mailslots
- This policy controls whether the SMB server will enable or disable remote mailslots over the computer browser service.
-
-If you disable this policy setting, the computer browser service will no longer run as expected.
-
-If you do not configure this policy setting, the computer browser may still be working with remote mailslots enabled.
-
-Note: This policy requires a Windows reboot to take effect.
-
-
- Enable authentication rate limiter
- This policy controls whether the SMB server will enable or disable the authentication rate limiter.
-
-If you disable this policy setting, the authentication rate limiter will not be enabled.
-
-If you do not configure this policy setting, the authentication rate limiter may still be working depending on the delay settings (the recommended delay value is 2000ms).
-
- Audit client does not support encryption
- This policy controls whether the SMB server will log the event when the SMB client doesn't support encryption.
-
-If you enable this policy setting, the SMB server will log the event when the SMB client doesn't support encryption.
-
-If you disable or do not configure this policy setting, the SMB server will not log the event.
-
- Audit client does not support signing
- This policy controls whether the SMB server will log the event when the SMB client doesn't support signing.
-
-If you enable this policy setting, the SMB server will log the event when the SMB client doesn't support signing.
-
- Audit insecure guest logon
- This policy controls whether the SMB server will enable the audit event when the client is logged on as guest account.
-
-If you enable this policy setting, the SMB server will log the event when the client is logged on as guest account.
-
-If you disable or do not configure this policy setting, the SMB server will not log the event.
-
- Enable SMB over QUIC
- This policy setting controls whether the SMB server will enable SMB over QUIC.
-
-If you disable this policy setting, the SMB server will not accept connections over QUIC.
-
-If you do not configure this policy setting, the SMB server may accept connections over QUIC.
-
- Set authentication rate limiter delay (milliseconds)
- This policy controls whether the SMB server will use a default value in milliseconds for the invalid authentication delay.
-
-If you configure this policy setting, the authentication rate limiter will use the specified value for delaying invalid authentication attempts.
-
-If you do not configure this policy setting, the authentication rate limiter will use the default value or the value from local registry under HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters.
-
- Audit SMB client SPN support
- This policy controls whether the SMB server audits the Service Principal Name (SPN) provided by SMB clients during authentication.
-
-If you enable this policy setting, the SMB server will log an event whenever an SMB client doesn't send SPN or sends an invalid SPN during authentication. This audit data can help identify clients that may be incompatible with SPN validation before enforcement is enabled on SMB server.
-
-If you disable or do not configure this policy setting, the SMB server will not log the event.
-
-
-
-
- Values:
- 0 = Allow hash publication only for shared folders on which BranchCache is enabled
- 1 = Disallow hash publication on all shared folders
- 2 = Allow hash publication for all shared folders
- Hash publication actions:
-
-
-
- Values:
- 1 = Support V1 hashes
- 2 = Support V2 hashes
- 3 = Support V1 and V2 hashes
- Hash version supported:
-
-
-
- Cipher suites:
-
-
-
- Select SMB version:
- Version:
-
-
- Select SMB version:
- Version:
-
-
- Value (milliseconds):
-
-
-
-
+
+
+
+ enter display name here
+ enter description here
+
+
+ Lanman Server
+ Allow hash publication only for shared folders on which BranchCache is enabled
+ Disallow hash publication on all shared folders
+ Allow hash publication for all shared folders
+ Hash Publication for BranchCache
+ This policy setting specifies whether a hash generation service generates hashes, also called content information, for data that is stored in shared folders. This policy setting must be applied to server computers that have the File Services role and both the File Server and the BranchCache for Network Files role services installed.
+
+Policy configuration
+
+Select one of the following:
+
+- Not Configured. With this selection, hash publication settings are not applied to file servers. In the circumstance where file servers are domain members but you do not want to enable BranchCache on all file servers, you can specify Not Configured for this domain Group Policy setting, and then configure local machine policy to enable BranchCache on individual file servers. Because the domain Group Policy setting is not configured, it will not over-write the enabled setting that you use on individual servers where you want to enable BranchCache.
+
+- Enabled. With this selection, hash publication is turned on for all file servers where Group Policy is applied. For example, if Hash Publication for BranchCache is enabled in domain Group Policy, hash publication is turned on for all domain member file servers to which the policy is applied. The file servers are then able to create content information for all content that is stored in BranchCache-enabled file shares.
+
+- Disabled. With this selection, hash publication is turned off for all file servers where Group Policy is applied.
+
+In circumstances where this policy setting is enabled, you can also select the following configuration options:
+
+- Allow hash publication for all shared folders. With this option, BranchCache generates content information for all content in all shares on the file server.
+
+- Allow hash publication only for shared folders on which BranchCache is enabled. With this option, content information is generated only for shared folders on which BranchCache is enabled. If you use this setting, you must enable BranchCache for individual shares in Share and Storage Management on the file server.
+
+- Disallow hash publication on all shared folders. With this option, BranchCache does not generate content information for any shares on the computer and does not send content information to client computers that request content.
+
+ Supports V1 hash version only
+ Supports V2 hash version only
+ Supports V1 as well as V2 versions
+ Hash Version support for BranchCache
+ This policy setting specifies whether the BranchCache hash generation service supports version 1 (V1) hashes, version 2 (V2) hashes, or both V1 and V2 hashes. Hashes, also called content information, are created based on the data in shared folders where BranchCache is enabled.
+
+If you specify only one version that is supported, content information for that version is the only type that is generated by BranchCache, and it is the only type of content information that can be retrieved by client computers. For example, if you enable support for V1 hashes, BranchCache generates only V1 hashes and client computers can retrieve only V1 hashes.
+
+Policy configuration
+
+Select one of the following:
+
+- Not Configured. With this selection, BranchCache settings are not applied to client computers by this policy setting. In this circumstance, which is the default, both V1 and V2 hash generation and retrieval are supported.
+
+- Enabled. With this selection, the policy setting is applied and the hash version(s) that are specified in "Hash version supported" are generated and retrieved.
+
+- Disabled. With this selection, both V1 and V2 hash generation and retrieval are supported.
+
+In circumstances where this setting is enabled, you can also select and configure the following option:
+
+Hash version supported:
+
+- To support V1 content information only, configure "Hash version supported" with the value of 1.
+
+- To support V2 content information only, configure "Hash version supported" with the value of 2.
+
+- To support both V1 and V2 content information, configure "Hash version supported" with the value of 3.
+ Cipher suite order
+ This policy setting determines the cipher suites used by the SMB server.
+
+If you enable this policy setting, cipher suites are prioritized in the order specified.
+
+If you enable this policy setting and do not specify at least one supported cipher suite, or if you disable or do not configure this policy setting, the default cipher suite order is used.
+
+SMB 3.11 cipher suites:
+
+AES_128_GCM
+AES_128_CCM
+AES_256_GCM
+AES_256_CCM
+
+SMB 3.0 and 3.02 cipher suites:
+
+AES_128_CCM
+
+How to modify this setting:
+
+Arrange the desired cipher suites in the edit box, one cipher suite per line, in order from most to least preferred, with the most preferred cipher suite at the top. Remove any cipher suites you don't want to use.
+
+Note: When configuring this security setting, changes will not take effect until you restart Windows.
+ Honor cipher suite order
+ This policy setting determines how the SMB server selects a cipher suite when negotiating a new connection with an SMB client.
+
+If you enable this policy setting, the SMB server will select the cipher suite it most prefers from the SMB client's cipher suites, ignoring the client's cipher suite preferences.
+
+If you disable or do not configure this policy setting, the SMB server will select the cipher suite the SMB client most prefers from the server's cipher suites.
+
+Note: When configuring this security setting, changes will not take effect until you restart Windows.
+ Honor cipher suite order
+ This policy setting determines how the SMB server selects a cipher suite when negotiating a new connection with an SMB client.
+
+If you enable this policy setting, the SMB server will select the cipher suite it most prefers from the list of client-supported cipher suites, ignoring the client's preferences.
+
+If you disable or do not configure this policy setting, the SMB server will select the cipher suite the client most prefers from the list of server-supported cipher suites.
+
+Note: When configuring this security setting, changes will not take effect until you restart Windows.
+ At least Windows Server 2022, Windows 11
+ At least Windows Server 2025, Windows 11
+ At least Windows Server 2025, Windows 11 24H2
+ Request traffic compression for all shares
+ This policy controls whether the SMB server requests SMB client to use traffic compression for all SMB shares.
+
+If you enable this policy setting, the SMB server will by default request the SMB client to compress traffic when SMB compression is enabled. See notes below.
+
+If you disable or do not configure this policy setting, the SMB server will not by default request the SMB client to compress traffic. However traffic compression may be requested by other means. See notes below.
+
+Note: If this policy is disabled, traffic compression may be requested by server-side per-share properties or by the SMB Client. If this is undesired, and one wishes to completely disable compression, configure the accompanying 'Disable SMB compression' policy instead.
+
+Note: Traffic compression can only be used when both the SMB client and SMB server support and enable traffic compression.
+
+ Disable SMB compression
+ This policy controls whether the SMB server will disable (completely prevent) traffic compression.
+
+If you enable this policy setting, the SMB server will never compress data, irrespective of other policies (such as the 'Use SMB compression by default' policy or per-share property).
+
+If you disable or do not configure this policy setting, the SMB server may compress traffic (depending on a combination of other policies and conditions).
+
+ Mandate the maximum version of SMB
+ This policy controls the maximum version of SMB protocol
+
+Note: This group policy does not prevent use of SMB 1 if that component is still installed and enabled.
+
+ Mandate the minimum version of SMB
+ This policy controls the minimum version of SMB protocol
+
+Note: This group policy does not prevent use of SMB 1 if that component is still installed and enabled.
+
+ SMB 2.0.2
+ SMB 2.1.0
+ SMB 3.0.0
+ SMB 3.0.2
+ SMB 3.1.1
+
+ Enable remote mailslots
+ This policy controls whether the SMB server will enable or disable remote mailslots over the computer browser service.
+
+If you disable this policy setting, the computer browser service will no longer run as expected.
+
+If you do not configure this policy setting, the computer browser may still be working with remote mailslots enabled.
+
+Note: This policy requires a Windows reboot to take effect.
+
+
+ Enable authentication rate limiter
+ This policy controls whether the SMB server will enable or disable the authentication rate limiter.
+
+If you disable this policy setting, the authentication rate limiter will not be enabled.
+
+If you do not configure this policy setting, the authentication rate limiter may still be working depending on the delay settings (the recommended delay value is 2000ms).
+
+ Audit client does not support encryption
+ This policy controls whether the SMB server will log the event when the SMB client doesn't support encryption.
+
+If you enable this policy setting, the SMB server will log the event when the SMB client doesn't support encryption.
+
+If you disable or do not configure this policy setting, the SMB server will not log the event.
+
+ Audit client does not support signing
+ This policy controls whether the SMB server will log the event when the SMB client doesn't support signing.
+
+If you enable this policy setting, the SMB server will log the event when the SMB client doesn't support signing.
+
+ Audit insecure guest logon
+ This policy controls whether the SMB server will enable the audit event when the client is logged on as guest account.
+
+If you enable this policy setting, the SMB server will log the event when the client is logged on as guest account.
+
+If you disable or do not configure this policy setting, the SMB server will not log the event.
+
+ Enable SMB over QUIC
+ This policy setting controls whether the SMB server will enable SMB over QUIC.
+
+If you disable this policy setting, the SMB server will not accept connections over QUIC.
+
+If you do not configure this policy setting, the SMB server may accept connections over QUIC.
+
+ Set authentication rate limiter delay (milliseconds)
+ This policy controls whether the SMB server will use a default value in milliseconds for the invalid authentication delay.
+
+If you configure this policy setting, the authentication rate limiter will use the specified value for delaying invalid authentication attempts.
+
+If you do not configure this policy setting, the authentication rate limiter will use the default value or the value from local registry under HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters.
+
+ Audit SMB client SPN support
+ This policy controls whether the SMB server audits the Service Principal Name (SPN) provided by SMB clients during authentication.
+
+If you enable this policy setting, the SMB server will log an event whenever an SMB client doesn't send SPN or sends an invalid SPN during authentication. This audit data can help identify clients that may be incompatible with SPN validation before enforcement is enabled on SMB server.
+
+If you disable or do not configure this policy setting, the SMB server will not log the event.
+
+
+
+
+ Values:
+ 0 = Allow hash publication only for shared folders on which BranchCache is enabled
+ 1 = Disallow hash publication on all shared folders
+ 2 = Allow hash publication for all shared folders
+ Hash publication actions:
+
+
+
+ Values:
+ 1 = Support V1 hashes
+ 2 = Support V2 hashes
+ 3 = Support V1 and V2 hashes
+ Hash version supported:
+
+
+
+ Cipher suites:
+
+
+
+ Select SMB version:
+ Version:
+
+
+ Select SMB version:
+ Version:
+
+
+ Value (milliseconds):
+
+
+
+
diff --git a/config/admx/en-US/LanmanWorkstation.adml b/config/admx/en-US/LanmanWorkstation.adml
index f11776f..3e5e744 100644
--- a/config/admx/en-US/LanmanWorkstation.adml
+++ b/config/admx/en-US/LanmanWorkstation.adml
@@ -1,220 +1,220 @@
-
-
-
- enter display name here
- enter description here
-
-
- Lanman Workstation
- Cipher suite order
- This policy setting determines the cipher suites used by the SMB client.
-
-If you enable this policy setting, cipher suites are prioritized in the order specified.
-
-If you enable this policy setting and do not specify at least one supported cipher suite, or if you disable or do not configure this policy setting, the default cipher suite order is used.
-
-SMB 3.11 cipher suites:
-
-AES_128_GCM
-AES_128_CCM
-AES_256_GCM
-AES_256_CCM
-
-SMB 3.0 and 3.02 cipher suites:
-
-AES_128_CCM
-
-How to modify this setting:
-
-Arrange the desired cipher suites in the edit box, one cipher suite per line, in order from most to least preferred, with the most preferred cipher suite at the top. Remove any cipher suites you don't want to use.
-
-Note: When configuring this security setting, changes will not take effect until you restart Windows.
- Enable insecure guest logons
- This policy setting determines if the SMB client will allow insecure guest logons to an SMB server.
-
-If you enable this policy setting or if you do not configure this policy setting, the SMB client will allow insecure guest logons.
-
-If you disable this policy setting, the SMB client will reject insecure guest logons.
-
-If you enable signing, the SMB client will reject insecure guest logons.
-
-Insecure guest logons are used by file servers to allow unauthenticated access to shared folders. While uncommon in an enterprise environment, insecure guest logons are frequently used by consumer Network Attached Storage (NAS) appliances acting as file servers. Windows file servers require authentication and do not use insecure guest logons by default. Since insecure guest logons are unauthenticated, important security features such as SMB Signing and SMB Encryption are disabled. As a result, clients that allow insecure guest logons are vulnerable to a variety of man-in-the-middle attacks that can result in data loss, data corruption, and exposure to malware. Additionally, any data written to a file server using an insecure guest logon is potentially accessible to anyone on the network. Microsoft recommends disabling insecure guest logons and configuring file servers to require authenticated access."
-
-
- Offline Files Availability on Continuous Availability Shares
-
- This policy setting determines the behavior of Offline Files on clients connecting to an SMB share where the Continuous Availability (CA) flag is enabled.
-
- If you enable this policy setting, the "Always Available offline" option will appear in the File Explorer menu on a Windows computer when connecting to a CA-enabled share. Pinning of files on CA-enabled shares using client-side caching will also be possible.
-
- If you disable or do not configure this policy setting, Windows will prevent use of Offline Files with CA-enabled shares.
-
- Note: Microsoft does not recommend enabling this group policy. Use of CA with Offline Files will lead to very long transition times between the online and offline states.
-
-
- Handle Caching on Continuous Availability Shares
-
- This policy setting determines the behavior of SMB handle caching for clients connecting to an SMB share where the Continuous Availability (CA) flag is enabled.
-
- If you enable this policy setting, the SMB client will allow cached handles to files on CA shares. This may lead to better performance when repeatedly accessing a large number of unstructured data files on CA shares running in Microsoft Azure Files.
-
- If you disable or do not configure this policy setting, Windows will prevent use of cached handles to files opened through CA shares.
-
- Note: This policy has no effect when connecting Scale-out File Server shares provided by a Windows Server. Microsoft does not recommend enabling this policy for clients that routinely connect to files hosted on a Windows Failover Cluster with the File Server for General Use role, as it can lead to adverse failover times and increased memory and CPU usage.
-
- At least Windows Server 2022, Windows 11
- At least Windows Server 2025, Windows 11
- Use SMB compression by default
- This policy controls whether the SMB client uses traffic compression by default.
-
-If you enable this policy setting, the SMB client will attempt to compress traffic by default when SMB compression is enabled.
-
-If you disable or do not configure this policy setting, the SMB client will not by default attempt to compress traffic. However traffic compression may be requested by other means. See notes below.
-
-Note: This policy is combined with per-share and per-file handle properties, through which traffic compression may be requested. As well, the SMB server must support and enable compression. For example, should this policy be disabled (or not configured), the SMB client may still perform compression if an SMB server share has compression requested. If this is undesired, and one wishes to completely disable compression, configure the accompanying 'Disable SMB compression' policy instead.
-
- Disable SMB compression
- This policy controls whether the SMB client will disable (completely prevent) traffic compression.
-
-If you enable this policy setting, the SMB client will never compress data, irrespective of other policies (such as the 'Use SMB compression by default' policy or per-share property).
-
-If you disable or do not configure this policy setting, the SMB client may compress traffic (depending on a combination of other policies and conditions).
-
- Mandate the maximum version of SMB
- This policy controls the maximum version of SMB protocol
-
-Note: This group policy does not prevent use of SMB 1 if that component is still installed and enabled.
-
- Mandate the minimum version of SMB
- This policy controls the minimum version of SMB protocol
-
-Note: This group policy does not prevent use of SMB 1 if that component is still installed and enabled.
-
- SMB 2.0.2
- SMB 2.1.0
- SMB 3.0.0
- SMB 3.0.2
- SMB 3.1.1
- Block NTLM (LM, NTLM, NTLMv2)
- This policy controls if the SMB client will block NTLM for remote connection authentication.
-
-If you enable this policy setting, the SMB client won't use NTLM for remote connection authentication.
-
-If you disable or do not configure this policy setting, the SMB client can still use NTLM.
-
- Block NTLM Server Exception List
- This policy setting determines if NTLM can be used to access specified servers.
-
-If you enable this policy setting (valid only if NTLM (LM, NTLM, NTLMv2) is blocked), NTLM can be used to access servers specified. Please enter the desired servers (DNS name, IP address or NetBIOS name) in the edit box, one server name per line.
-
-If you disable or do not configure this policy setting, the NTLM access to servers will be determined by other settings.
-
- Enable remote mailslots
- This policy controls whether the SMB client will enable or disable remote mailslots over MUP.
-
-If you disable this policy setting, remote mailslots will not function over MUP, hence they will not go through the SMB client redirector.
-
-If you do not configure this policy setting, remote mailslots may be allowed through MUP.
-
- Require Encryption
- This policy controls whether the SMB client will require encryption.
-
-If you enable this policy setting, the SMB client will require the SMB server to support encryption and encrypt the data.
-
-If you disable or do not configure this policy setting, the SMB client will not require encryption. However, SMB encryption may still be required; see notes below.
-
-Note: This policy is combined with per-share, per-server, and per mapped drive connection properties, through which SMB encryption may be required. The SMB server must support and enable SMB encryption. For example, should this policy be disabled (or not configured), the SMB client may still perform encryption if an SMB server share has required encryption.
-
-Important: SMB encryption requires SMB 3.0 or later
-
- Enable Alternative Ports
- This policy controls whether the SMB client will enable or disable alternative ports.
-
-If you disable this policy setting, alternative ports will not be used by the SMB client.
-
-If you do not configure this policy setting, alternative ports may be used by the SMB client.
-
- Audit server does not support encryption
- This policy controls whether the SMB client will enable the audit event when the SMB server doesn't support encryption.
-
-If you enable this policy setting, the SMB client will log the event when the SMB server doesn't support encryption.
-
-If you disable or do not configure this policy setting, the SMB client will not log the event.
-
- Audit server does not support signing
- This policy controls whether the SMB client will enable the audit event when the SMB server doesn't support signing.
-
-If you enable this policy setting, the SMB client will log the event when the SMB server doesn't support signing.
-
-If you disable or do not configure this policy setting, the SMB client will not log the event.
-
- Audit insecure guest logon
- This policy controls whether the SMB client will enable the audit event when the client is logged on as guest account.
-
-If you enable this policy setting, the SMB client will log the event when the client is logged on as guest account.
-
-If you disable or do not configure this policy setting, the SMB client will not log the event.
-
- Alternative Port Mappings
- This policy setting determines the alternative port registry mappings used by the SMB client.
-
-If you enable this policy setting, the first valid mapping will be used if the mapping's server name matches the targeted server name for connectivity.
-
-If you enable this policy setting and do not specify at least one valid mapping, or if you disable or do not configure this policy setting, then the SMB client will refer to other methods of determining alternative port usage such as with the NET USE or New-SmbMapping commands.
-
-Examples:
-
-contososa.file.core.windows.net:tcp:448
-edgesrv1.corp.contoso.com:quic:450
-
-How to modify this setting:
-
-Arrange the desired alternative port mappings in the edit box with one mapping entry per line.
-
-The format of each mapping entry specifies a server name, transport type, and port number separated by colons as done so in the example above.
-
-Note: This policy does not require a Windows reboot to take effect.
-
- Enable SMB over QUIC
- This policy setting controls whether the SMB client will enable SMB over QUIC.
-
-If you disable this policy setting, the SMB client will not allow initiating connections over QUIC. In this case, if the user attempts to connect over QUIC, SMB client will attempt to connect over TCP.
-
-If you do not configure this policy setting, the SMB client may allow initiating connections over QUIC.
-
- Disabled SMB over QUIC Server Exception List
- This policy setting specifies the servers the SMB client can connect to over QUIC.
-
-If you enable this policy setting (valid only if SMB over QUIC is disabled), the SMB client can connect to the specified servers over QUIC. Please enter the desired servers (DNS name, IP address or NetBIOS name) in the edit box, one server name per line.
-
-If you disable or do not configure this policy setting, the SMB client's ability to connect to servers over QUIC will be determined by other settings.
-
-
-
-
- Cipher suites:
-
-
-
- Select SMB version:
- Version:
-
-
- Select SMB version:
- Version:
-
-
- Block NTLM Server Exception List:
-
-
-
- Alternative Port Registry Mappings:
-
-
-
- Disabled SMB over QUIC Server Exception List:
-
-
-
-
-
+
+
+
+ enter display name here
+ enter description here
+
+
+ Lanman Workstation
+ Cipher suite order
+ This policy setting determines the cipher suites used by the SMB client.
+
+If you enable this policy setting, cipher suites are prioritized in the order specified.
+
+If you enable this policy setting and do not specify at least one supported cipher suite, or if you disable or do not configure this policy setting, the default cipher suite order is used.
+
+SMB 3.11 cipher suites:
+
+AES_128_GCM
+AES_128_CCM
+AES_256_GCM
+AES_256_CCM
+
+SMB 3.0 and 3.02 cipher suites:
+
+AES_128_CCM
+
+How to modify this setting:
+
+Arrange the desired cipher suites in the edit box, one cipher suite per line, in order from most to least preferred, with the most preferred cipher suite at the top. Remove any cipher suites you don't want to use.
+
+Note: When configuring this security setting, changes will not take effect until you restart Windows.
+ Enable insecure guest logons
+ This policy setting determines if the SMB client will allow insecure guest logons to an SMB server.
+
+If you enable this policy setting or if you do not configure this policy setting, the SMB client will allow insecure guest logons.
+
+If you disable this policy setting, the SMB client will reject insecure guest logons.
+
+If you enable signing, the SMB client will reject insecure guest logons.
+
+Insecure guest logons are used by file servers to allow unauthenticated access to shared folders. While uncommon in an enterprise environment, insecure guest logons are frequently used by consumer Network Attached Storage (NAS) appliances acting as file servers. Windows file servers require authentication and do not use insecure guest logons by default. Since insecure guest logons are unauthenticated, important security features such as SMB Signing and SMB Encryption are disabled. As a result, clients that allow insecure guest logons are vulnerable to a variety of man-in-the-middle attacks that can result in data loss, data corruption, and exposure to malware. Additionally, any data written to a file server using an insecure guest logon is potentially accessible to anyone on the network. Microsoft recommends disabling insecure guest logons and configuring file servers to require authenticated access."
+
+
+ Offline Files Availability on Continuous Availability Shares
+
+ This policy setting determines the behavior of Offline Files on clients connecting to an SMB share where the Continuous Availability (CA) flag is enabled.
+
+ If you enable this policy setting, the "Always Available offline" option will appear in the File Explorer menu on a Windows computer when connecting to a CA-enabled share. Pinning of files on CA-enabled shares using client-side caching will also be possible.
+
+ If you disable or do not configure this policy setting, Windows will prevent use of Offline Files with CA-enabled shares.
+
+ Note: Microsoft does not recommend enabling this group policy. Use of CA with Offline Files will lead to very long transition times between the online and offline states.
+
+
+ Handle Caching on Continuous Availability Shares
+
+ This policy setting determines the behavior of SMB handle caching for clients connecting to an SMB share where the Continuous Availability (CA) flag is enabled.
+
+ If you enable this policy setting, the SMB client will allow cached handles to files on CA shares. This may lead to better performance when repeatedly accessing a large number of unstructured data files on CA shares running in Microsoft Azure Files.
+
+ If you disable or do not configure this policy setting, Windows will prevent use of cached handles to files opened through CA shares.
+
+ Note: This policy has no effect when connecting Scale-out File Server shares provided by a Windows Server. Microsoft does not recommend enabling this policy for clients that routinely connect to files hosted on a Windows Failover Cluster with the File Server for General Use role, as it can lead to adverse failover times and increased memory and CPU usage.
+
+ At least Windows Server 2022, Windows 11
+ At least Windows Server 2025, Windows 11
+ Use SMB compression by default
+ This policy controls whether the SMB client uses traffic compression by default.
+
+If you enable this policy setting, the SMB client will attempt to compress traffic by default when SMB compression is enabled.
+
+If you disable or do not configure this policy setting, the SMB client will not by default attempt to compress traffic. However traffic compression may be requested by other means. See notes below.
+
+Note: This policy is combined with per-share and per-file handle properties, through which traffic compression may be requested. As well, the SMB server must support and enable compression. For example, should this policy be disabled (or not configured), the SMB client may still perform compression if an SMB server share has compression requested. If this is undesired, and one wishes to completely disable compression, configure the accompanying 'Disable SMB compression' policy instead.
+
+ Disable SMB compression
+ This policy controls whether the SMB client will disable (completely prevent) traffic compression.
+
+If you enable this policy setting, the SMB client will never compress data, irrespective of other policies (such as the 'Use SMB compression by default' policy or per-share property).
+
+If you disable or do not configure this policy setting, the SMB client may compress traffic (depending on a combination of other policies and conditions).
+
+ Mandate the maximum version of SMB
+ This policy controls the maximum version of SMB protocol
+
+Note: This group policy does not prevent use of SMB 1 if that component is still installed and enabled.
+
+ Mandate the minimum version of SMB
+ This policy controls the minimum version of SMB protocol
+
+Note: This group policy does not prevent use of SMB 1 if that component is still installed and enabled.
+
+ SMB 2.0.2
+ SMB 2.1.0
+ SMB 3.0.0
+ SMB 3.0.2
+ SMB 3.1.1
+ Block NTLM (LM, NTLM, NTLMv2)
+ This policy controls if the SMB client will block NTLM for remote connection authentication.
+
+If you enable this policy setting, the SMB client won't use NTLM for remote connection authentication.
+
+If you disable or do not configure this policy setting, the SMB client can still use NTLM.
+
+ Block NTLM Server Exception List
+ This policy setting determines if NTLM can be used to access specified servers.
+
+If you enable this policy setting (valid only if NTLM (LM, NTLM, NTLMv2) is blocked), NTLM can be used to access servers specified. Please enter the desired servers (DNS name, IP address or NetBIOS name) in the edit box, one server name per line.
+
+If you disable or do not configure this policy setting, the NTLM access to servers will be determined by other settings.
+
+ Enable remote mailslots
+ This policy controls whether the SMB client will enable or disable remote mailslots over MUP.
+
+If you disable this policy setting, remote mailslots will not function over MUP, hence they will not go through the SMB client redirector.
+
+If you do not configure this policy setting, remote mailslots may be allowed through MUP.
+
+ Require Encryption
+ This policy controls whether the SMB client will require encryption.
+
+If you enable this policy setting, the SMB client will require the SMB server to support encryption and encrypt the data.
+
+If you disable or do not configure this policy setting, the SMB client will not require encryption. However, SMB encryption may still be required; see notes below.
+
+Note: This policy is combined with per-share, per-server, and per mapped drive connection properties, through which SMB encryption may be required. The SMB server must support and enable SMB encryption. For example, should this policy be disabled (or not configured), the SMB client may still perform encryption if an SMB server share has required encryption.
+
+Important: SMB encryption requires SMB 3.0 or later
+
+ Enable Alternative Ports
+ This policy controls whether the SMB client will enable or disable alternative ports.
+
+If you disable this policy setting, alternative ports will not be used by the SMB client.
+
+If you do not configure this policy setting, alternative ports may be used by the SMB client.
+
+ Audit server does not support encryption
+ This policy controls whether the SMB client will enable the audit event when the SMB server doesn't support encryption.
+
+If you enable this policy setting, the SMB client will log the event when the SMB server doesn't support encryption.
+
+If you disable or do not configure this policy setting, the SMB client will not log the event.
+
+ Audit server does not support signing
+ This policy controls whether the SMB client will enable the audit event when the SMB server doesn't support signing.
+
+If you enable this policy setting, the SMB client will log the event when the SMB server doesn't support signing.
+
+If you disable or do not configure this policy setting, the SMB client will not log the event.
+
+ Audit insecure guest logon
+ This policy controls whether the SMB client will enable the audit event when the client is logged on as guest account.
+
+If you enable this policy setting, the SMB client will log the event when the client is logged on as guest account.
+
+If you disable or do not configure this policy setting, the SMB client will not log the event.
+
+ Alternative Port Mappings
+ This policy setting determines the alternative port registry mappings used by the SMB client.
+
+If you enable this policy setting, the first valid mapping will be used if the mapping's server name matches the targeted server name for connectivity.
+
+If you enable this policy setting and do not specify at least one valid mapping, or if you disable or do not configure this policy setting, then the SMB client will refer to other methods of determining alternative port usage such as with the NET USE or New-SmbMapping commands.
+
+Examples:
+
+contososa.file.core.windows.net:tcp:448
+edgesrv1.corp.contoso.com:quic:450
+
+How to modify this setting:
+
+Arrange the desired alternative port mappings in the edit box with one mapping entry per line.
+
+The format of each mapping entry specifies a server name, transport type, and port number separated by colons as done so in the example above.
+
+Note: This policy does not require a Windows reboot to take effect.
+
+ Enable SMB over QUIC
+ This policy setting controls whether the SMB client will enable SMB over QUIC.
+
+If you disable this policy setting, the SMB client will not allow initiating connections over QUIC. In this case, if the user attempts to connect over QUIC, SMB client will attempt to connect over TCP.
+
+If you do not configure this policy setting, the SMB client may allow initiating connections over QUIC.
+
+ Disabled SMB over QUIC Server Exception List
+ This policy setting specifies the servers the SMB client can connect to over QUIC.
+
+If you enable this policy setting (valid only if SMB over QUIC is disabled), the SMB client can connect to the specified servers over QUIC. Please enter the desired servers (DNS name, IP address or NetBIOS name) in the edit box, one server name per line.
+
+If you disable or do not configure this policy setting, the SMB client's ability to connect to servers over QUIC will be determined by other settings.
+
+
+
+
+ Cipher suites:
+
+
+
+ Select SMB version:
+ Version:
+
+
+ Select SMB version:
+ Version:
+
+
+ Block NTLM Server Exception List:
+
+
+
+ Alternative Port Registry Mappings:
+
+
+
+ Disabled SMB over QUIC Server Exception List:
+
+
+
+
+
diff --git a/config/admx/en-US/LocalSecurityAuthority.adml b/config/admx/en-US/LocalSecurityAuthority.adml
index d13ad26..3e3899b 100644
--- a/config/admx/en-US/LocalSecurityAuthority.adml
+++ b/config/admx/en-US/LocalSecurityAuthority.adml
@@ -1,39 +1,39 @@
-
-
-
- Local Security Authority Settings
- Settings for the Local Security Authority
-
-
- Local Security Authority
-
- Allow Custom SSPs and APs to be loaded into LSASS
- This policy controls the configuration under which LSASS loads custom SSPs and APs.
-
-If you enable this setting or do not configure it, LSA allows custom SSPs and APs to be loaded.
-
-If you disable this setting, LSA does not load custom SSPs and APs.
-
- Configures LSASS to run as a protected process
- This policy controls the configuration under which LSASS is run.
-
-If you do not configure this policy and there is no current setting in the registry, LSA will run as protected process for clean installed, HVCI capable, client SKUs that are domain or cloud domain joined devices. This configuration is not UEFI locked. This can be overridden if the policy is configured.
-
-If you configure and set this policy setting to "Disabled", LSA will not run as a protected process.
-
-If you configure and set this policy setting to "EnabledWithUEFILock," LSA will run as a protected process and this configuration is UEFI locked.
-
-If you configure and set this policy setting to "EnabledWithoutUEFILock", LSA will run as a protected process and this configuration is not UEFI locked.
-
- Disabled
- Enabled with UEFI Lock
- Enabled without UEFI Lock
-
-
-
-
- Configure LSA to run as a protected process
-
-
-
-
+
+
+
+ Local Security Authority Settings
+ Settings for the Local Security Authority
+
+
+ Local Security Authority
+
+ Allow Custom SSPs and APs to be loaded into LSASS
+ This policy controls the configuration under which LSASS loads custom SSPs and APs.
+
+If you enable this setting or do not configure it, LSA allows custom SSPs and APs to be loaded.
+
+If you disable this setting, LSA does not load custom SSPs and APs.
+
+ Configures LSASS to run as a protected process
+ This policy controls the configuration under which LSASS is run.
+
+If you do not configure this policy and there is no current setting in the registry, LSA will run as protected process for clean installed, HVCI capable, client SKUs that are domain or cloud domain joined devices. This configuration is not UEFI locked. This can be overridden if the policy is configured.
+
+If you configure and set this policy setting to "Disabled", LSA will not run as a protected process.
+
+If you configure and set this policy setting to "EnabledWithUEFILock," LSA will run as a protected process and this configuration is UEFI locked.
+
+If you configure and set this policy setting to "EnabledWithoutUEFILock", LSA will run as a protected process and this configuration is not UEFI locked.
+
+ Disabled
+ Enabled with UEFI Lock
+ Enabled without UEFI Lock
+
+
+
+
+ Configure LSA to run as a protected process
+
+
+
+
diff --git a/config/admx/en-US/MSS-legacy.adml b/config/admx/en-US/MSS-legacy.adml
index 8962761..fe43165 100644
--- a/config/admx/en-US/MSS-legacy.adml
+++ b/config/admx/en-US/MSS-legacy.adml
@@ -1,173 +1,173 @@
-
- MSS (Legacy)
- The legacy "MSS" settings that had been exposed in Secpol, Security Options, using LocalGPO.wsf /ConfigSCE.
-
-
- MSS (Legacy)
-
- MSS: (AutoShareWks) Enable Administrative Shares
- MSS: (AutoShareWks) Enable Administrative Shares
- MSS: (AutoShareServer) Enable Administrative Shares
- MSS: (AutoShareServer) Enable Administrative Shares
- MSS: (AutoReboot) Allow Windows to automatically restart after a system crash
- MSS: (AutoReboot) Allow Windows to automatically restart after a system crash
- MSS: (AutoAdminLogon) Enable Automatic Logon
- MSS: (AutoAdminLogon) Enable Automatic Logon
- MSS: (DisableIPSourceRouting) IP source routing protection level
- MSS: (DisableIPSourceRouting) IP source routing protection level
- No additional protection, source routed packets are allowed
- Medium, source routed packets ignored when IP forwarding is enabled
- Highest protection, source routing is completely disabled
- MSS: (DisableIPSourceRouting IPv6) IP source routing protection level
- MSS: (DisableIPSourceRouting IPv6) IP source routing protection level
- MSS: (DisableSavePassword) Prevent the dial-up passsword from being saved
- MSS: (DisableSavePassword) Prevent the dial-up passsword from being saved
- MSS: (EnableDeadGWDetect) Allow automatic detection of dead network gateways
- MSS: (EnableDeadGWDetect) Allow automatic detection of dead network gateways
- MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes
- MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes
- MSS: (Hidden) Hide Computer From the Browse List
- MSS: (Hidden) Hide Computer From the Browse List
- MSS: (KeepAliveTime) How often keep-alive packets are sent in milliseconds
- MSS: (KeepAliveTime) How often keep-alive packets are sent in milliseconds
- 150000 or 2.5 minutes
- 300000 or 5 minutes (recommended)
- 600000 or 10 minutes
- 1200000 or 20 minutes
- 2400000 or 40 minutes
- 3600000 or 1 hour
- 7200000 or 2 hours (default value)
- MSS: (NoDefaultExempt) Configure IPSec exemptions for various types of network traffic.
- MSS: (NoDefaultExempt) Configure IPSec exemptions for various types of network traffic.
- Allow all exemptions.
- Multicast, broadcast, & ISAKMP exempt.
- RSVP, Kerberos, and ISAKMP are exempt.
- Only ISAKMP is exempt.
- MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers
- MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers
- MSS: (NtfsDisable8dot3NameCreation) Enable the computer to stop generating 8.3 style filenames
- MSS: (NtfsDisable8dot3NameCreation) Enable the computer to stop generating 8.3 style filenames
- Enable 8Dot3 Creation on all Volumes
- Disable 8Dot3 Creation on all Volumes
- Set 8dot3 name creation per volume using FSUTIL
- Disable 8Dot3 name creation on all volumes except system volume
- MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses
- MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses
- MSS: (SafeDllSearchMode) Enable Safe DLL search mode
- MSS: (SafeDllSearchMode) Enable Safe DLL search mode
- MSS: (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires
- MSS: (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires
- MSS: (SynAttackProtect) Syn attack protection level
- MSS: (SynAttackProtect) Syn attack protection level
- No additional protection, use default settings
- Connections time out sooner if a SYN attack is detected
- MSS: (TcpMaxConnectResponseRetransmissions) SYN-ACK retransmissions when a connection request is not acknowledged
- MSS: (TcpMaxConnectResponseRetransmissions) SYN-ACK retransmissions when a connection request is not acknowledged
- No retransmission, half-open connections dropped after 3 seconds
- 3 seconds, half-open connections dropped after 9 seconds
- 3 & 6 seconds, half-open connections dropped after 21 seconds
- 3, 6, & 9 seconds, half-open connections dropped after 45 seconds
- MSS: (TcpMaxDataRetransmissions) How many times unacknowledged data is retransmitted
- MSS: (TcpMaxDataRetransmissions) How many times unacknowledged data is retransmitted
- MSS: (TcpMaxDataRetransmissions IPv6) How many times unacknowledged data is retransmitted
- MSS: (TcpMaxDataRetransmissions IPv6) How many times unacknowledged data is retransmitted
- MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning
- MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning
- 50%
- 60%
- 70%
- 80%
- 90%
-
-
-
-
-
- DisableIPSourceRouting
-
-
- DisableIPSourceRoutingIPv6
-
-
- KeepAliveTime
-
-
- NoDefaultExempt
-
-
- NtfsDisable8dot3NameCreation
-
-
- ScreenSaverGracePeriod
-
-
- SynAttackProtect
-
-
- TcpMaxConnectResponseRetransmissions
-
-
- TcpMaxDataRetransmissions
-
-
- WarningLevel
-
-
-
-
-
-
+
+ MSS (Legacy)
+ The legacy "MSS" settings that had been exposed in Secpol, Security Options, using LocalGPO.wsf /ConfigSCE.
+
+
+ MSS (Legacy)
+
+ MSS: (AutoShareWks) Enable Administrative Shares
+ MSS: (AutoShareWks) Enable Administrative Shares
+ MSS: (AutoShareServer) Enable Administrative Shares
+ MSS: (AutoShareServer) Enable Administrative Shares
+ MSS: (AutoReboot) Allow Windows to automatically restart after a system crash
+ MSS: (AutoReboot) Allow Windows to automatically restart after a system crash
+ MSS: (AutoAdminLogon) Enable Automatic Logon
+ MSS: (AutoAdminLogon) Enable Automatic Logon
+ MSS: (DisableIPSourceRouting) IP source routing protection level
+ MSS: (DisableIPSourceRouting) IP source routing protection level
+ No additional protection, source routed packets are allowed
+ Medium, source routed packets ignored when IP forwarding is enabled
+ Highest protection, source routing is completely disabled
+ MSS: (DisableIPSourceRouting IPv6) IP source routing protection level
+ MSS: (DisableIPSourceRouting IPv6) IP source routing protection level
+ MSS: (DisableSavePassword) Prevent the dial-up passsword from being saved
+ MSS: (DisableSavePassword) Prevent the dial-up passsword from being saved
+ MSS: (EnableDeadGWDetect) Allow automatic detection of dead network gateways
+ MSS: (EnableDeadGWDetect) Allow automatic detection of dead network gateways
+ MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes
+ MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes
+ MSS: (Hidden) Hide Computer From the Browse List
+ MSS: (Hidden) Hide Computer From the Browse List
+ MSS: (KeepAliveTime) How often keep-alive packets are sent in milliseconds
+ MSS: (KeepAliveTime) How often keep-alive packets are sent in milliseconds
+ 150000 or 2.5 minutes
+ 300000 or 5 minutes (recommended)
+ 600000 or 10 minutes
+ 1200000 or 20 minutes
+ 2400000 or 40 minutes
+ 3600000 or 1 hour
+ 7200000 or 2 hours (default value)
+ MSS: (NoDefaultExempt) Configure IPSec exemptions for various types of network traffic.
+ MSS: (NoDefaultExempt) Configure IPSec exemptions for various types of network traffic.
+ Allow all exemptions.
+ Multicast, broadcast, & ISAKMP exempt.
+ RSVP, Kerberos, and ISAKMP are exempt.
+ Only ISAKMP is exempt.
+ MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers
+ MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers
+ MSS: (NtfsDisable8dot3NameCreation) Enable the computer to stop generating 8.3 style filenames
+ MSS: (NtfsDisable8dot3NameCreation) Enable the computer to stop generating 8.3 style filenames
+ Enable 8Dot3 Creation on all Volumes
+ Disable 8Dot3 Creation on all Volumes
+ Set 8dot3 name creation per volume using FSUTIL
+ Disable 8Dot3 name creation on all volumes except system volume
+ MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses
+ MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses
+ MSS: (SafeDllSearchMode) Enable Safe DLL search mode
+ MSS: (SafeDllSearchMode) Enable Safe DLL search mode
+ MSS: (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires
+ MSS: (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires
+ MSS: (SynAttackProtect) Syn attack protection level
+ MSS: (SynAttackProtect) Syn attack protection level
+ No additional protection, use default settings
+ Connections time out sooner if a SYN attack is detected
+ MSS: (TcpMaxConnectResponseRetransmissions) SYN-ACK retransmissions when a connection request is not acknowledged
+ MSS: (TcpMaxConnectResponseRetransmissions) SYN-ACK retransmissions when a connection request is not acknowledged
+ No retransmission, half-open connections dropped after 3 seconds
+ 3 seconds, half-open connections dropped after 9 seconds
+ 3 & 6 seconds, half-open connections dropped after 21 seconds
+ 3, 6, & 9 seconds, half-open connections dropped after 45 seconds
+ MSS: (TcpMaxDataRetransmissions) How many times unacknowledged data is retransmitted
+ MSS: (TcpMaxDataRetransmissions) How many times unacknowledged data is retransmitted
+ MSS: (TcpMaxDataRetransmissions IPv6) How many times unacknowledged data is retransmitted
+ MSS: (TcpMaxDataRetransmissions IPv6) How many times unacknowledged data is retransmitted
+ MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning
+ MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning
+ 50%
+ 60%
+ 70%
+ 80%
+ 90%
+
+
+
+
+
+ DisableIPSourceRouting
+
+
+ DisableIPSourceRoutingIPv6
+
+
+ KeepAliveTime
+
+
+ NoDefaultExempt
+
+
+ NtfsDisable8dot3NameCreation
+
+
+ ScreenSaverGracePeriod
+
+
+ SynAttackProtect
+
+
+ TcpMaxConnectResponseRetransmissions
+
+
+ TcpMaxDataRetransmissions
+
+
+ WarningLevel
+
+
+
+
+
+
diff --git a/config/admx/en-US/NetworkProvider.adml b/config/admx/en-US/NetworkProvider.adml
index 1adeaea..4aa9595 100644
--- a/config/admx/en-US/NetworkProvider.adml
+++ b/config/admx/en-US/NetworkProvider.adml
@@ -1,36 +1,36 @@
-
-
-
- NetworkProvider
- Policy Definitions for the Multiple UNC Provider
-
-
- Network Provider
- Hardened UNC Paths
- This policy setting configures secure access to UNC paths.
-
-If you enable this policy, Windows only allows access to the specified UNC paths after fulfilling additional security requirements.
-
-
-
-
- Specify hardened network paths.
-In the name field, type a fully-qualified UNC path for each network resource.
-To secure all access to a share with a particular name, regardless of the server name, specify a server name of '*' (asterisk). For example, "\\*\NETLOGON".
-To secure all access to all shares hosted on a server, the share name portion of the UNC path may be omitted. For example, "\\SERVER".
-
-In the value field, specify one or more of the following options, separated by commas:
- 'RequireMutualAuthentication=1': Mutual authentication between the client and server is required to ensure the client connects to the correct server.
- 'RequireIntegrity=1': Communication between the client and server must employ an integrity mechanism to prevent data tampering.
- 'RequirePrivacy=1': Communication between the client and the server must be encrypted to prevent third parties from observing sensitive data.
- Hardened UNC Paths:
-
- You should require both Integrity and Mutual Authentication for any UNC paths that host executable programs, script files, or files that control security policies.
-
-Consider hosting files that do not require Integrity or Privacy on separate shares from those that absolutely need such security for optimal performance.
-
-For additional details on configuring Windows computers to require additional security when accessing specific UNC paths, visit http://support.microsoft.com/kb/3000483.
-
-
-
-
+
+
+
+ NetworkProvider
+ Policy Definitions for the Multiple UNC Provider
+
+
+ Network Provider
+ Hardened UNC Paths
+ This policy setting configures secure access to UNC paths.
+
+If you enable this policy, Windows only allows access to the specified UNC paths after fulfilling additional security requirements.
+
+
+
+
+ Specify hardened network paths.
+In the name field, type a fully-qualified UNC path for each network resource.
+To secure all access to a share with a particular name, regardless of the server name, specify a server name of '*' (asterisk). For example, "\\*\NETLOGON".
+To secure all access to all shares hosted on a server, the share name portion of the UNC path may be omitted. For example, "\\SERVER".
+
+In the value field, specify one or more of the following options, separated by commas:
+ 'RequireMutualAuthentication=1': Mutual authentication between the client and server is required to ensure the client connects to the correct server.
+ 'RequireIntegrity=1': Communication between the client and server must employ an integrity mechanism to prevent data tampering.
+ 'RequirePrivacy=1': Communication between the client and the server must be encrypted to prevent third parties from observing sensitive data.
+ Hardened UNC Paths:
+
+ You should require both Integrity and Mutual Authentication for any UNC paths that host executable programs, script files, or files that control security policies.
+
+Consider hosting files that do not require Integrity or Privacy on separate shares from those that absolutely need such security for optimal performance.
+
+For additional details on configuring Windows computers to require additional security when accessing specific UNC paths, visit http://support.microsoft.com/kb/3000483.
+
+
+
+
diff --git a/config/admx/en-US/Printing.adml b/config/admx/en-US/Printing.adml
index 34d568b..f6158fd 100644
--- a/config/admx/en-US/Printing.adml
+++ b/config/admx/en-US/Printing.adml
@@ -1,606 +1,606 @@
-
-
-
- enter display name here
- enter description here
-
-
- Activate Internet printing
- Internet printing lets you display printers on Web pages so that printers can be viewed, managed, and used across the Internet or an intranet.
-
- If you enable this policy setting, Internet printing is activated on this server.
-
- If you disable this policy setting or do not configure it, Internet printing is not activated.
-
- Internet printing is an extension of Internet Information Services (IIS). To use Internet printing, IIS must be installed, and printing support and this setting must be enabled.
-
- Note: This setting affects the server side of Internet printing only. It does not prevent the print client on the computer from printing across the Internet.
-
- Also, see the "Custom support URL in the Printers folder's left pane" setting in this folder and the "Browse a common Web site to find printers" setting in User Configuration\Administrative Templates\Control Panel\Printers.
- Isolate print drivers from applications
- Determines if print driver components are isolated from applications instead of normally loading them into applications. Isolating print drivers greatly reduces the risk of a print driver failure causing an application crash.
-
-Not all applications support driver isolation. By default, Microsoft Excel 2007, Excel 2010, Word 2007, Word 2010 and certain other applications are configured to support it. Other applications may also be capable of isolating print drivers, depending on whether they are configured for it.
-
-If you enable or do not configure this policy setting, then applications that are configured to support driver isolation will be isolated.
-
-If you disable this policy setting, then print drivers will be loaded within all associated application processes.
-
-Notes:
--This policy setting applies only to applications opted into isolation.
--This policy setting applies only to print drivers loaded by applications. Print drivers loaded by the print spooler are not affected.
--This policy setting is only checked once during the lifetime of a process. After changing the policy, a running application must be relaunched before settings take effect.
- Printers
- Manages network printer configuration and publishing options.
- Custom support URL in the Printers folder's left pane
- By default, the Printers folder includes a link to the Microsoft Support Web page called "Get help with printing". It can also include a link to a Web page supplied by the vendor of the currently selected printer.
-
- If you enable this policy setting, you replace the "Get help with printing" default link with a link to a Web page customized for your enterprise.
-
- If you disable this setting or do not configure it, or if you do not enter an alternate Internet address, the default link will appear in the Printers folder.
-
- Note: Web pages links only appear in the Printers folder when Web view is enabled. If Web view is disabled, the setting has no effect. (To enable Web view, open the Printers folder, and, on the Tools menu, click Folder Options, click the General tab, and then click "Enable Web content in folders.")
-
- Also, see the "Activate Internet printing" setting in this setting folder and the "Browse a common web site to find printers" setting in User Configuration\Administrative Templates\Control Panel\Printers.
-
- Web view is affected by the "Turn on Classic Shell" and "Do not allow Folder Options to be opened from the Options button on the View tab of the ribbon" settings in User Configuration\Administrative Templates\Windows Components\Windows Explorer, and by the "Enable Active Desktop" setting in User Configuration\Administrative Templates\Desktop\Active Desktop.
- If you enable this policy setting, it sets the maximum number of printers (of each type) that the Add Printer wizard will display on a computer on a managed network (when the computer is able to reach a domain controller, e.g. a domain-joined laptop on a corporate network.)
-
- If this policy setting is disabled, the network scan page will not be displayed.
-
- If this policy setting is not configured, the Add Printer wizard will display the default number of printers of each type:
- Directory printers: 20
- TCP/IP printers: 0
- Web Services printers: 0
- Bluetooth printers: 10
- Shared printers: 0
-
- In order to view available Web Services printers on your network, ensure that network discovery is turned on. To turn on network discovery, click "Start", click "Control Panel", and then click "Network and Internet". On the "Network and Internet" page, click "Network and Sharing Center". On the Network and Sharing Center page, click "Change advanced sharing settings". On the Advanced sharing settings page, click the arrow next to "Domain" arrow, click "turn on network discovery", and then click "Save changes".
-
- If you would like to not display printers of a certain type, enable this policy and set the number of printers to display to 0.
-
- In Windows 10 and later, only TCP/IP printers can be shown in the wizard. If you enable this policy setting, only TCP/IP printer limits are applicable. On Windows 10 only, if you disable or do not configure this policy setting, the default limit is applied.
-
- In Windows 8 and later, Bluetooth printers are not shown so its limit does not apply to those versions of Windows.
-
- Add Printer wizard - Network scan page (Managed network)
- Browse the network to find printers
- Allows users to use the Add Printer Wizard to search the network for shared printers.
-
-If you enable this setting or do not configure it, when users choose to add a network printer by selecting the "A network printer, or a printer attached to another computer" radio button on Add Printer Wizard's page 2, and also check the "Connect to this printer (or to browse for a printer, select this option and click Next)" radio button on Add Printer Wizard's page 3, and do not specify a printer name in the adjacent "Name" edit box, then Add Printer Wizard displays the list of shared printers on the network and invites to choose a printer from the shown list.
-
-If you disable this setting, the network printer browse page is removed from within the Add Printer Wizard, and users cannot search the network but must type a printer name.
-
-Note: This setting affects the Add Printer Wizard only. It does not prevent users from using other programs to search for shared printers or to connect to network printers.
- Always render print jobs on the server
- When printing through a print server, determines whether the print spooler on the client will process print jobs itself, or pass them on to the server to do the work.
-
-This policy setting only effects printing to a Windows print server.
-
-If you enable this policy setting on a client machine, the client spooler will not process print jobs before sending them to the print server. This decreases the workload on the client at the expense of increasing the load on the server.
-
-If you disable this policy setting on a client machine, the client itself will process print jobs into printer device commands. These commands will then be sent to the print server, and the server will simply pass the commands to the printer. This increases the workload of the client while decreasing the load on the server.
-
-If you do not enable this policy setting, the behavior is the same as disabling it.
-
-Note: This policy does not determine whether offline printing will be available to the client. The client print spooler can always queue print jobs when not connected to the print server. Upon reconnecting to the server, the client will submit any pending print jobs.
-
-Note: Some printer drivers require a custom print processor. In some cases the custom print processor may not be installed on the client machine, such as when the print server does not support transferring print processors during point-and-print. In the case of a print processor mismatch, the client spooler will always send jobs to the print server for rendering. Disabling the above policy setting does not override this behavior.
-
-Note: In cases where the client print driver does not match the server print driver (mismatched connection), the client will always process the print job, regardless of the setting of this policy.
- Always rasterize content to be printed using a software rasterizer
- Determines whether the XPS Rasterization Service or the XPS-to-GDI conversion (XGC) is forced to use a software rasterizer instead of a Graphics Processing Unit (GPU) to rasterize pages.
-
-This setting may improve the performance of the XPS Rasterization Service or the XPS-to-GDI conversion (XGC) on machines that have a relatively powerful CPU as compared to the machine’s GPU.
- Browse a common web site to find printers
- Adds a link to an Internet or intranet Web page to the Add Printer Wizard.
-
- You can use this setting to direct users to a Web page from which they can install printers.
-
- If you enable this setting and type an Internet or intranet address in the text box, the system adds a Browse button to the "Specify a Printer" page in the Add Printer Wizard. The Browse button appears beside the "Connect to a printer on the Internet or on a home or office network" option. When users click Browse, the system opens an Internet browser and navigates to the specified URL address to display the available printers.
-
- This setting makes it easy for users to find the printers you want them to add.
-
- Also, see the "Custom support URL in the Printers folder's left pane" and "Activate Internet printing" settings in "Computer Configuration\Administrative Templates\Printers."
- Disallow installation of printers using kernel-mode drivers
- Determines whether printers using kernel-mode drivers may be installed on the local computer. Kernel-mode drivers have access to system-wide memory, and therefore poorly-written kernel-mode drivers can cause stop errors.
-
-If you disable this setting, or do not configure it, then printers using a kernel-mode drivers may be installed on the local computer running Windows XP Home Edition and Windows XP Professional.
-
-If you do not configure this setting on Windows Server 2003 family products, the installation of kernel-mode printer drivers will be blocked.
-
-If you enable this setting, installation of a printer using a kernel-mode driver will not be allowed.
-
-Note: By applying this policy, existing kernel-mode drivers will be disabled upon installation of service packs or reinstallation of the Windows XP operating system. This policy does not apply to 64-bit kernel-mode printer drivers as they cannot be installed and associated with a print queue.
- Prevent addition of printers
- Prevents users from using familiar methods to add local and network printers.
-
- If this policy setting is enabled, it removes the Add Printer option from the Start menu. (To find the Add Printer option, click Start, click Printers, and then click Add Printer.) This setting also removes Add Printer from the Printers folder in Control Panel.
-
- Also, users cannot add printers by dragging a printer icon into the Printers folder. If they try, a message appears explaining that the setting prevents the action.
-
- However, this setting does not prevent users from using the Add Hardware Wizard to add a printer. Nor does it prevent users from running other programs to add printers.
-
- This setting does not delete printers that users have already added. However, if users have not added a printer when this setting is applied, they cannot print.
-
- Note: You can use printer permissions to restrict the use of printers without specifying a setting. In the Printers folder, right-click a printer, click Properties, and then click the Security tab.
-
- If this policy is disabled, or not configured, users can add printers using the methods described above.
- Prevent deletion of printers
- If this policy setting is enabled, it prevents users from deleting local and network printers.
-
- If a user tries to delete a printer, such as by using the Delete option in Printers in Control Panel, a message appears explaining that a setting prevents the action.
-
- This setting does not prevent users from running other programs to delete a printer.
-
- If this policy is disabled, or not configured, users can delete printers using the methods described above.
- This policy sets the maximum number of printers (of each type) that the Add Printer wizard will display on a computer on an unmanaged network (when the computer is not able to reach a domain controller, e.g. a domain-joined laptop on a home network.)
-
-If this setting is disabled, the network scan page will not be displayed.
-
-If this setting is not configured, the Add Printer wizard will display the default number of printers of each type:
-TCP/IP printers: 50
-Web Services printers: 50
-Bluetooth printers: 10
-Shared printers: 50
-
-If you would like to not display printers of a certain type, enable this policy and set the number of printers to display to 0.
-
-In Windows 10 and later, only TCP/IP printers can be shown in the wizard. If you enable this policy setting, only TCP/IP printer limits are applicable. On Windows 10 only, if you disable or do not configure this policy setting, the default limit is applied.
-
-In Windows 8 and later, Bluetooth printers are not shown so its limit does not apply to those versions of Windows.
- Add Printer wizard - Network scan page (Unmanaged network)
- Only use Package Point and print
- This policy restricts clients computers to use package point and print only.
-
-If this setting is enabled, users will only be able to point and print to printers that use package-aware drivers. When using package point and print, client computers will check the driver signature of all drivers that are downloaded from print servers.
-
-If this setting is disabled, or not configured, users will not be restricted to package-aware point and print only.
- Supported Windows XP SP1 through Windows Server 2008 RTM
- Package Point and print - Approved servers
- Restricts package point and print to approved servers.
-
-This policy setting restricts package point and print connections to approved servers. This setting only applies to Package Point and Print connections, and is completely independent from the "Point and Print Restrictions" policy that governs the behavior of non-package point and print connections.
-
-Windows Vista and later clients will attempt to make a non-package point and print connection anytime a package point and print connection fails, including attempts that are blocked by this policy. Administrators may need to set both policies to block all print connections to a specific print server.
-
-If this setting is enabled, users will only be able to package point and print to print servers approved by the network administrator. When using package point and print, client computers will check the driver signature of all drivers that are downloaded from print servers.
-
-If this setting is disabled, or not configured, package point and print will not be restricted to specific print servers.
- Computer location
- If this policy setting is enabled, it specifies the default location criteria used when searching for printers.
-
- This setting is a component of the Location Tracking feature of Windows printers. To use this setting, enable Location Tracking by enabling the "Pre-populate printer search location text" setting.
-
- When Location Tracking is enabled, the system uses the specified location as a criterion when users search for printers. The value you type here overrides the actual location of the computer conducting the search.
-
- Type the location of the user's computer. When users search for printers, the system uses the specified location (and other search criteria) to find a printer nearby. You can also use this setting to direct users to a particular printer or group of printers that you want them to use.
-
- If you disable this setting or do not configure it, and the user does not type a location as a search criterion, the system searches for a nearby printer based on the IP address and subnet mask of the user's computer.
- Pre-populate printer search location text
- Enables the physical Location Tracking setting for Windows printers.
-
-Use Location Tracking to design a location scheme for your enterprise and assign computers and printers to locations in the scheme. Location Tracking overrides the standard method used to locate and associate computers and printers. The standard method uses a printer's IP address and subnet mask to estimate its physical location and proximity to computers.
-
-If you enable this setting, users can browse for printers by location without knowing the printer's location or location naming scheme. Enabling Location Tracking adds a Browse button in the Add Printer wizard's Printer Name and Sharing Location screen and to the General tab in the Printer Properties dialog box. If you enable the Group Policy Computer location setting, the default location you entered appears in the Location field by default.
-
-If you disable this setting or do not configure it, Location Tracking is disabled. Printer proximity is estimated using the standard method (that is, based on IP address and subnet mask).
- Point and Print Restrictions
- This policy setting controls the client Point and Print behavior, including the security prompts for Windows Vista computers. The policy setting applies only to non-Print Administrator clients, and only to computers that are members of a domain.
-
- If you enable this policy setting:
- -Windows XP and later clients will only download print driver components from a list of explicitly named servers. If a compatible print driver is available on the client, a printer connection will be made. If a compatible print driver is not available on the client, no connection will be made.
- -You can configure Windows Vista clients so that security warnings and elevated command prompts do not appear when users Point and Print, or when printer connection drivers need to be updated.
-
- If you do not configure this policy setting:
- -Windows Vista client computers can point and print to any server.
- -Windows Vista computers will show a warning and an elevated command prompt when users create a printer connection to any server using Point and Print.
- -Windows Vista computers will show a warning and an elevated command prompt when an existing printer connection driver needs to be updated.
- -Windows Server 2003 and Windows XP client computers can create a printer connection to any server in their forest using Point and Print.
-
- If you disable this policy setting:
- -Windows Vista client computers can create a printer connection to any server using Point and Print.
- -Windows Vista computers will not show a warning or an elevated command prompt when users create a printer connection to any server using Point and Print.
- -Windows Vista computers will not show a warning or an elevated command prompt when an existing printer connection driver needs to be updated.
- -Windows Server 2003 and Windows XP client computers can create a printer connection to any server using Point and Print.
- -The "Users can only point and print to computers in their forest" setting applies only to Windows Server 2003 and Windows XP SP1 (and later service packs).
- Show warning and elevation prompt
- Do not show warning or elevation prompt
- Show warning only
- Default Active Directory path when searching for printers
- Specifies the Active Directory location where searches for printers begin.
-
- The Add Printer Wizard gives users the option of searching Active Directory for a shared printer.
-
- If you enable this policy setting, these searches begin at the location you specify in the "Default Active Directory path" box. Otherwise, searches begin at the root of Active Directory.
-
- This setting only provides a starting point for Active Directory searches for printers. It does not restrict user searches through Active Directory.
- Printer browsing
- Announces the presence of shared printers to print browse master servers for the domain.
-
-On domains with Active Directory, shared printer resources are available in Active Directory and are not announced.
-
-If you enable this setting, the print spooler announces shared printers to the print browse master servers.
-
-If you disable this setting, shared printers are not announced to print browse master servers, even if Active Directory is not available.
-
-If you do not configure this setting, shared printers are announced to browse master servers only when Active Directory is not available.
-
-Note: A client license is used each time a client computer announces a printer to a print browse master on the domain.
- Execute print drivers in isolated processes
- This policy setting determines whether the print spooler will execute print drivers in an isolated or separate process. When print drivers are loaded in an isolated process (or isolated processes), a print driver failure will not cause the print spooler service to fail.
-
-If you enable or do not configure this policy setting, the print spooler will execute print drivers in an isolated process by default.
-
-If you disable this policy setting, the print spooler will execute print drivers in the print spooler process.
-
-
-Notes:
--Other system or driver policy settings may alter the process in which a print driver is executed.
--This policy setting applies only to print drivers loaded by the print spooler. Print drivers loaded by applications are not affected.
--This policy setting takes effect without restarting the print spooler service.
- Override print driver execution compatibility setting reported by print driver
- This policy setting determines whether the print spooler will override the Driver Isolation compatibility reported by the print driver. This enables executing print drivers in an isolated process, even if the driver does not report compatibility.
-
-If you enable this policy setting, the print spooler isolates all print drivers that do not explicitly opt out of Driver Isolation.
-
-If you disable or do not configure this policy setting, the print spooler uses the Driver Isolation compatibility flag value reported by the print driver.
-
-Notes:
--Other system or driver policy settings may alter the process in which a print driver is executed.
--This policy setting applies only to print drivers loaded by the print spooler. Print drivers loaded by applications are not affected.
--This policy setting takes effect without restarting the print spooler service.
- Allow job name in event logs
-
- This policy controls whether the print job name will be included in print event logs.
-
- If you disable or do not configure this policy setting, the print job name will not be included.
-
- If you enable this policy setting, the print job name will be included in new log entries.
-
- Note: This setting does not apply to Branch Office Direct Printing jobs.
-
- Extend Point and Print connection to search Windows Update
- This policy setting allows you to manage where client computers search for Point and Printer drivers.
-
-If you enable this policy setting, the client computer will continue to search for compatible Point and Print drivers from Windows Update after it fails to find the compatible driver from the local driver store and the server driver cache.
-
-If you disable this policy setting, the client computer will only search the local driver store and server driver cache for compatible Point and Print drivers. If it is unable to find a compatible driver, then the Point and Print connection will fail.
-
-This policy setting is not configured by default, and the behavior depends on the version of Windows that you are using.
-By default, Windows Ultimate, Professional and Home SKUs will continue to search for compatible Point and Print drivers from Windows Update, if needed. However, you must explicitly enable this policy setting for other versions of Windows (for example Windows Enterprise, and all versions of Windows Server 2008 R2 and later) to have the same behavior.
- Do not allow v4 printer drivers to show printer extensions
- This policy determines if v4 printer drivers are allowed to run printer extensions.
-
- V4 printer drivers may include an optional, customized user interface known as a printer extension. These extensions may provide access to more device features, but this may not be appropriate for all enterprises.
-
- If you enable this policy setting, then all printer extensions will not be allowed to run.
-
- If you disable this policy setting or do not configure it, then all printer extensions that have been installed will be allowed to run.
- Change Microsoft XPS Document Writer (MXDW) default output format to the legacy Microsoft XPS format (*.xps)
- Microsoft XPS Document Writer (MXDW) generates OpenXPS (*.oxps) files by default in Windows 10, Windows 10 and Windows Server 2025.
-
- If you enable this group policy setting, the default MXDW output format is the legacy Microsoft XPS (*.xps).
-
- If you disable or do not configure this policy setting, the default MXDW output format is OpenXPS (*.oxps).
- Turn off Windows default printer management
- This preference allows you to change default printer management.
-
-If you enable this setting, Windows will not manage the default printer.
-
-If you disable this setting, Windows will manage the default printer.
-
-If you do not configure this setting, default printer management will not change.
- Enable Device Control Printing Restrictions
-
-Determines whether Device Control Printing Restrictions are enforced for printing on this computer.
-
-By default, there are no restrictions to printing based on connection type or printer Make/Model.
-
-If you enable this setting, the computer will restrict printing to printer connections on the corporate network or approved USB-connected printers.
-
-If you disable this setting or do not configure it, there are no restrictions to printing based on connection type or printer Make/Model.
- List of Approved USB-connected print devices
-
-
-This setting is a component of the Device Control Printing Restrictions. To use this setting, enable Device Control Printing by enabling the "Enable Device Control Printing Restrictions" setting.
-
-When Device Control Printing is enabled, the system uses the specified list of vid/pid values to determine if the current USB connected printer is approved for local printing.
-
-Type all the approved vid/pid combinations (separated by commas) that correspond to approved USB printer models. When a user tries to print to a USB printer queue the device vid/pid will be compared to the approved list.
-
- Limits print driver installation to Administrators
-
-Determines whether users that aren't Administrators can install print drivers on this computer.
-
-By default, users that aren't Administrators can't install print drivers on this computer.
-
-If you enable this setting or do not configure it, the system will limit installation of print drivers to Administrators of this computer.
-
-If you disable this setting, the system won't limit installation of print drivers to this computer.
-
- Manage processing of Queue-specific files
- Allow all Queue-specfic files
- Do not allow Queue-specific files
-
-Manages how Queue-specific files are processed during printer installation. At printer installation time, a vendor-supplied installation application can specify a set of files, of any type, to be associated with a particular print queue. The files are downloaded to each client that connects to the print server.
-
-You can enable this setting to change the default behavior involving queue-specific files. To use this setting, select one of the options below from the "Manage processing of Queue-specific files" box.
-
-If you disable or do not configure this policy setting, the default behavior is "Limit Queue-specific files to Color profiles".
-
--- "Do not allow Queue-specific files" specifies that no queue-specific files will be allowed/processed during print queue/printer connection installation.
-
--- "Limit Queue-specific files to Color profiles" specifies that only queue-specific files that adhere to the standard color profile scheme will be allowed. This means entries using the Registry Key CopyFiles\ICM, containing a Directory value of COLOR and supporting mscms.dll as the Module value. "Limit Queue-specific files to Color profiles" is the default behavior.
-
--- "Allow all Queue-specific files" specifies that all queue-specific files will be allowed/processed during print queue/printer connection installation.
-
- Limit Queue-specific files to Color profiles
- Require inbox signed drivers
- Allow all validly signed drivers
- Allow inbox and Print Drivers Trusted Store signed drivers
- Allow inbox, Print Drivers Trusted Store, WHQL, and Trusted Publisher Store signed drivers
- Allow inbox, Print Drivers Trusted Store, and WHQL signed drivers
- Manage Print Driver signature validation
-
- This policy setting controls the print driver signature validation mechanism. This policy controls the type of digital signature that is required for a print driver to be considered valid and installed on the system.
-
- As part of this validation the catalog/embedded signature is verified and all files in the driver must be a part of the catalog or have their own embedded signature that can be used for validation.
-
- You can enable this setting to change the default signature validation method. To use this setting, select one of the options below from the "Select the driver signature mechanism for this computer" box.
-
- If you disable or do not configure this policy setting, the default method is "Allow all validly signed drivers".
-
- -- "Require inbox signed drivers" specifies only drivers that are shipped as part of a Windows image are allowed on this computer.
-
- -- "Allow inbox and PrintDrivers Trusted Store signed drivers" specifies only drivers that are shipped as part of a Windows image or drivers that are signed by certificates installed in the 'PrintDrivers' certificate store are allowed on this computer.
-
- -- "Allow inbox, PrintDrivers Trusted Store, and WHQL signed drivers" specifies the only drivers allowed on this computer are those that are: shipped as part of a Windows image, signed by certificates installed in the 'PrintDrivers' certificate store, or signed by the Windows Hardware Quality Lab (WHQL).
-
- -- "Allow inbox, PrintDrivers Trusted Store, WHQL, and Trusted Publishers Store signed drivers" specifies the only drivers allowed on this computer are those that are: shipped as part of a Windows image, signed by certificates installed in the 'PrintDrivers' certificate store, signed by the Windows Hardware Quality Lab (WHQL), or signed by certificates installed in the 'Trusted Publishers' certificate store.
-
- -- "Allow all validly signed drivers" specfies that any print driver that has a valid embedded signature or can be validated against the print driver catalog can be installed on this computer.
-
- The 'PrintDrivers' certificate store needs to be created by an administrator under the local machine store location.
-
- The 'Trusted Publishers' certificate store can contain certificates from sources that are not related to print drivers.
-
-
- Select the driver signature mechanism for this computer
- Manage Print Driver exclusion list
-
-This policy setting controls the print driver exclusion list. The exclusion list allows an administrator to curate a list of printer drivers that are not allowed to be installed on the system.
-
-This checks outranks the signature check and allows drivers that have a valid signature level for the Print Driver signature validation policy to be excluded.
-
-Entries in the exclusion list consist of a SHA256 hash (or SHA1 hash for Win7) of the INF file and/or main driver DLL file of the driver and the name of the file.
-
-If you disable or do not configure this policy setting, the registry key and values associated with this policy setting will be deleted, if currently set to a value.
-
-
- Configure RPC listener settings
- RPC over named pipes
- RPC over TCP
- RPC over named pipes and TCP
- Negotiate
- Kerberos
-
-This policy setting controls which protocols incoming RPC connections to the print spooler are allowed to use.
-
-By default, RPC over TCP is enabled and Negotiate is used for the authentication protocol.
-
-Protocols to allow for incoming RPC connections:
- -- "RPC over named pipes": Incoming RPC connections are only allowed over named pipes
- -- "RPC over TCP": Incoming RPC connections are only allowed over TCP (the default option)
- -- "RPC over named pipes and TCP": Incoming RPC connections will be allowed over TCP and named pipes
-
-Authentication protocol to use for incoming RPC connections:
- -- "Negotiate": Use the Negotiate authentication protocol (the default option)
- -- "Kerberos": Use the Kerberos authentication protocol
-
-If you disable or do not configure this policy setting, the above defaults will be used.
-
- Configure RPC connection settings
- Default
- Authentication enabled
- Authentication disabled
-
-This policy setting controls which protocol and protocol settings to use for outgoing RPC connections to a remote print spooler.
-
-By default, RPC over TCP is used and authentication is always enabled. For RPC over named pipes, authentication is always enabled for domain joined machines but disabled for non domain joined machines.
-
-Protocol to use for outgoing RPC connections:
- -- "RPC over TCP": Use RPC over TCP for outgoing RPC connections to a remote print spooler
- -- "RPC over named pipes": Use RPC over named pipes for outgoing RPC connections to a remote print spooler
-
-Use authentication for outgoing RPC over named pipes connections:
- -- "Default": By default domain joined computers enable RPC authentication for RPC over named pipes while non domain joined computers disable RPC authentication for RPC over named pipes
- -- "Authentication enabled": RPC authentication will be used for outgoing RPC over named pipes connections
- -- "Authentication disabled": RPC authentication will not be used for outgoing RPC over named pipes connections
-
-If you disable or do not configure this policy setting, the above defaults will be used.
-
- Configure RPC over TCP port
-
-This policy setting controls which port is used for RPC over TCP for incoming connections to the print spooler and outgoing connections to remote print spoolers.
-
-By default dynamic TCP ports are used.
-
-RPC over TCP port:
- -- The port to use for RPC over TCP. A value of 0 is the default and indicates that dynamic TCP ports will be used
-
-If you disable or do not configure this policy setting, dynamic TCP ports are used.
-
- Configure RPC packet level privacy setting for incoming connections
-
-This policy setting controls whether packet level privacy is enabled for RPC for incoming connections.
-
-By default packet level privacy is enabled for RPC for incoming connections.
-
-If you enable or do not configure this policy setting, packet level privacy is enabled for RPC for incoming connections.
-
- Always send job page count information for IPP printers
-
-Determines whether to always send page count information for accounting purposes for printers using the Microsoft IPP Class Driver.
-
-By default, pages are sent to the printer as soon as they are rendered and page count information is not sent to the printer unless pages must be reordered.
-
-If you enable this setting the system will render all print job pages up front and send the printer the total page count for the print job.
-
-If you disable this setting or do not configure it, pages are printed as soon as they are rendered and page counts are only sent when page reordering is required to process the job.
-
- Require IPPS for IPP printers
- Determines whether communication with printers using the Microsoft IPP Class Driver must use IPPS (which uses TLS for secure communication).
-
-If you enable this policy setting, then only IPP printers which support IPPS can be installed.
-
-If you disable this setting or do not configure it, the default is to allow installation of IPP printers which do not support IPPS.
-
- Set TLS/SSL security policy for IPP printers
-
-Determines the TLS/SSL security policy (WINHTTP_OPTION_SECURITY_FLAGS) for printers using the Microsoft IPP Class Driver.
-
-By default, security policy is set to ignore all certificate errors, allowing use of self-signed certificates for printers.
-
-If you enable this setting the system defaults to enabling all certificate checking, disallowing certificate errors. Specific certificate checking can be set with the given checkboxes.
-
-If you disable this setting or do not configure it, the default is to ignore all certificate errors (all checkboxes unchecked).
-
- Configure Redirection Guard
- Redirection Guard Disabled
- Redirection Guard Enabled
- Redirection Guard Audit Only
-
-Determines whether Redirection Guard is enabled for the print spooler.
-
-You can enable this setting to configure the Redirection Guard policy being applied to spooler.
-
-If you disable or do not configure this policy setting, Redirection Guard will default to being 'Enabled'.
-
-If you enable this setting you may select the following options:
-
--- Enabled : Redirection Guard will prevent any file redirections from being followed
-
--- Disabed : Redirection Guard will not be enabled and file redirections may be used within the spooler process
-
--- Audit : Redirection Guard will log events as though it were enabled but will not actually prevent file redirections from being used within the spooler.
-
- Configure Windows protected print
-
-Determines whether Windows protected print is enabled on this computer.
-
-By default, Windows protected print is not enabled and there are not any restrictions on the print drivers that can be installed or print functionality.
-
-If you enable this setting, the computer will operate in Windows protected print mode which only allows printing to printers that support a subset of inbox Windows print drivers.
-
-If you disable this setting or do not configure it, there are not any restrictions on the print drivers that can be installed or print functionality.
-
-For more information, please see https://learn.microsoft.com/en-us/windows-hardware/drivers/print/windows-protected-print-mode
-
-
-
-
- Specify the URL. For example, the url would be: http://www.microsoft.com/support
-
-
-
-
-
- Number of directory printers
- Number of TCP/IP printers
- Number of Web Services Printers
- Number of Bluetooth printers
- Number of shared printers
-
-
- Enable this option to add a browse button for Internet printers
- in the Add Printer Wizard. Use this setting to allow users browsing
- the company's Intranet for printers. For example, you can
- specify a URL like: http://www.company.com/printers.
- To enable this option, the edit box below should not be empty.
-
-
-
-
-
- Number of TCP/IP printers
- Number of Web Services Printers
- Number of Bluetooth printers
- Number of shared printers
-
-
- Enter fully qualified server names
-
-
- Enter the location of this computer
- For example: CityName/Building 2/Floor 1/Office 1800
-
-
-
-
-
- Users can only point and print to these servers:
-
-
-
- Users can only point and print to machines in their forest
-
- Security Prompts:
- When installing drivers for a new connection:
- When updating drivers for an existing connection:
- This setting only applies to:
- Windows Vista and later
-
-
-
-
-
- example --> LDAP://DC=Domain1,DC=MyCompany,DC=com.
-
-
- Specify the list of approved USB-connected printer devices.
- The list is a comma separated list of USB vid/pid values. Example: 0351/0872,135E/2179
-
-
-
-
-
- Select the method by which Queue-specific files will be processed.
- Manage processing of Queue-Specific files:
-
-
- Select the driver signature mechanism for this computer:
-
-
-
- Enter a File Hash paired with the name of the file the Hash represents below.
-
- File Hash File Name:
-
-
- Configure protocol options for incoming RPC connections.
- Protocols to allow for incoming RPC connections:
- Authentication protocol to use for incoming RPC connections:
-
-
- Configure protocol options for outgoing RPC connections.
- Protocol to use for outgoing RPC connections:
- Use authentication for outgoing RPC connections:
-
-
- Configure port to use for RPC over TCP.
- RPC over TCP port:
-
-
- Disallow invalid certificate authority
- Disallow non-server certificates
- Disallow invalid certificate common name
- Disallow invalid certificate date
-
-
- Configure options for Redirection Guard
- Redirection Guard Options
-
-
-
-
+
+
+
+ enter display name here
+ enter description here
+
+
+ Activate Internet printing
+ Internet printing lets you display printers on Web pages so that printers can be viewed, managed, and used across the Internet or an intranet.
+
+ If you enable this policy setting, Internet printing is activated on this server.
+
+ If you disable this policy setting or do not configure it, Internet printing is not activated.
+
+ Internet printing is an extension of Internet Information Services (IIS). To use Internet printing, IIS must be installed, and printing support and this setting must be enabled.
+
+ Note: This setting affects the server side of Internet printing only. It does not prevent the print client on the computer from printing across the Internet.
+
+ Also, see the "Custom support URL in the Printers folder's left pane" setting in this folder and the "Browse a common Web site to find printers" setting in User Configuration\Administrative Templates\Control Panel\Printers.
+ Isolate print drivers from applications
+ Determines if print driver components are isolated from applications instead of normally loading them into applications. Isolating print drivers greatly reduces the risk of a print driver failure causing an application crash.
+
+Not all applications support driver isolation. By default, Microsoft Excel 2007, Excel 2010, Word 2007, Word 2010 and certain other applications are configured to support it. Other applications may also be capable of isolating print drivers, depending on whether they are configured for it.
+
+If you enable or do not configure this policy setting, then applications that are configured to support driver isolation will be isolated.
+
+If you disable this policy setting, then print drivers will be loaded within all associated application processes.
+
+Notes:
+-This policy setting applies only to applications opted into isolation.
+-This policy setting applies only to print drivers loaded by applications. Print drivers loaded by the print spooler are not affected.
+-This policy setting is only checked once during the lifetime of a process. After changing the policy, a running application must be relaunched before settings take effect.
+ Printers
+ Manages network printer configuration and publishing options.
+ Custom support URL in the Printers folder's left pane
+ By default, the Printers folder includes a link to the Microsoft Support Web page called "Get help with printing". It can also include a link to a Web page supplied by the vendor of the currently selected printer.
+
+ If you enable this policy setting, you replace the "Get help with printing" default link with a link to a Web page customized for your enterprise.
+
+ If you disable this setting or do not configure it, or if you do not enter an alternate Internet address, the default link will appear in the Printers folder.
+
+ Note: Web pages links only appear in the Printers folder when Web view is enabled. If Web view is disabled, the setting has no effect. (To enable Web view, open the Printers folder, and, on the Tools menu, click Folder Options, click the General tab, and then click "Enable Web content in folders.")
+
+ Also, see the "Activate Internet printing" setting in this setting folder and the "Browse a common web site to find printers" setting in User Configuration\Administrative Templates\Control Panel\Printers.
+
+ Web view is affected by the "Turn on Classic Shell" and "Do not allow Folder Options to be opened from the Options button on the View tab of the ribbon" settings in User Configuration\Administrative Templates\Windows Components\Windows Explorer, and by the "Enable Active Desktop" setting in User Configuration\Administrative Templates\Desktop\Active Desktop.
+ If you enable this policy setting, it sets the maximum number of printers (of each type) that the Add Printer wizard will display on a computer on a managed network (when the computer is able to reach a domain controller, e.g. a domain-joined laptop on a corporate network.)
+
+ If this policy setting is disabled, the network scan page will not be displayed.
+
+ If this policy setting is not configured, the Add Printer wizard will display the default number of printers of each type:
+ Directory printers: 20
+ TCP/IP printers: 0
+ Web Services printers: 0
+ Bluetooth printers: 10
+ Shared printers: 0
+
+ In order to view available Web Services printers on your network, ensure that network discovery is turned on. To turn on network discovery, click "Start", click "Control Panel", and then click "Network and Internet". On the "Network and Internet" page, click "Network and Sharing Center". On the Network and Sharing Center page, click "Change advanced sharing settings". On the Advanced sharing settings page, click the arrow next to "Domain" arrow, click "turn on network discovery", and then click "Save changes".
+
+ If you would like to not display printers of a certain type, enable this policy and set the number of printers to display to 0.
+
+ In Windows 10 and later, only TCP/IP printers can be shown in the wizard. If you enable this policy setting, only TCP/IP printer limits are applicable. On Windows 10 only, if you disable or do not configure this policy setting, the default limit is applied.
+
+ In Windows 8 and later, Bluetooth printers are not shown so its limit does not apply to those versions of Windows.
+
+ Add Printer wizard - Network scan page (Managed network)
+ Browse the network to find printers
+ Allows users to use the Add Printer Wizard to search the network for shared printers.
+
+If you enable this setting or do not configure it, when users choose to add a network printer by selecting the "A network printer, or a printer attached to another computer" radio button on Add Printer Wizard's page 2, and also check the "Connect to this printer (or to browse for a printer, select this option and click Next)" radio button on Add Printer Wizard's page 3, and do not specify a printer name in the adjacent "Name" edit box, then Add Printer Wizard displays the list of shared printers on the network and invites to choose a printer from the shown list.
+
+If you disable this setting, the network printer browse page is removed from within the Add Printer Wizard, and users cannot search the network but must type a printer name.
+
+Note: This setting affects the Add Printer Wizard only. It does not prevent users from using other programs to search for shared printers or to connect to network printers.
+ Always render print jobs on the server
+ When printing through a print server, determines whether the print spooler on the client will process print jobs itself, or pass them on to the server to do the work.
+
+This policy setting only effects printing to a Windows print server.
+
+If you enable this policy setting on a client machine, the client spooler will not process print jobs before sending them to the print server. This decreases the workload on the client at the expense of increasing the load on the server.
+
+If you disable this policy setting on a client machine, the client itself will process print jobs into printer device commands. These commands will then be sent to the print server, and the server will simply pass the commands to the printer. This increases the workload of the client while decreasing the load on the server.
+
+If you do not enable this policy setting, the behavior is the same as disabling it.
+
+Note: This policy does not determine whether offline printing will be available to the client. The client print spooler can always queue print jobs when not connected to the print server. Upon reconnecting to the server, the client will submit any pending print jobs.
+
+Note: Some printer drivers require a custom print processor. In some cases the custom print processor may not be installed on the client machine, such as when the print server does not support transferring print processors during point-and-print. In the case of a print processor mismatch, the client spooler will always send jobs to the print server for rendering. Disabling the above policy setting does not override this behavior.
+
+Note: In cases where the client print driver does not match the server print driver (mismatched connection), the client will always process the print job, regardless of the setting of this policy.
+ Always rasterize content to be printed using a software rasterizer
+ Determines whether the XPS Rasterization Service or the XPS-to-GDI conversion (XGC) is forced to use a software rasterizer instead of a Graphics Processing Unit (GPU) to rasterize pages.
+
+This setting may improve the performance of the XPS Rasterization Service or the XPS-to-GDI conversion (XGC) on machines that have a relatively powerful CPU as compared to the machine’s GPU.
+ Browse a common web site to find printers
+ Adds a link to an Internet or intranet Web page to the Add Printer Wizard.
+
+ You can use this setting to direct users to a Web page from which they can install printers.
+
+ If you enable this setting and type an Internet or intranet address in the text box, the system adds a Browse button to the "Specify a Printer" page in the Add Printer Wizard. The Browse button appears beside the "Connect to a printer on the Internet or on a home or office network" option. When users click Browse, the system opens an Internet browser and navigates to the specified URL address to display the available printers.
+
+ This setting makes it easy for users to find the printers you want them to add.
+
+ Also, see the "Custom support URL in the Printers folder's left pane" and "Activate Internet printing" settings in "Computer Configuration\Administrative Templates\Printers."
+ Disallow installation of printers using kernel-mode drivers
+ Determines whether printers using kernel-mode drivers may be installed on the local computer. Kernel-mode drivers have access to system-wide memory, and therefore poorly-written kernel-mode drivers can cause stop errors.
+
+If you disable this setting, or do not configure it, then printers using a kernel-mode drivers may be installed on the local computer running Windows XP Home Edition and Windows XP Professional.
+
+If you do not configure this setting on Windows Server 2003 family products, the installation of kernel-mode printer drivers will be blocked.
+
+If you enable this setting, installation of a printer using a kernel-mode driver will not be allowed.
+
+Note: By applying this policy, existing kernel-mode drivers will be disabled upon installation of service packs or reinstallation of the Windows XP operating system. This policy does not apply to 64-bit kernel-mode printer drivers as they cannot be installed and associated with a print queue.
+ Prevent addition of printers
+ Prevents users from using familiar methods to add local and network printers.
+
+ If this policy setting is enabled, it removes the Add Printer option from the Start menu. (To find the Add Printer option, click Start, click Printers, and then click Add Printer.) This setting also removes Add Printer from the Printers folder in Control Panel.
+
+ Also, users cannot add printers by dragging a printer icon into the Printers folder. If they try, a message appears explaining that the setting prevents the action.
+
+ However, this setting does not prevent users from using the Add Hardware Wizard to add a printer. Nor does it prevent users from running other programs to add printers.
+
+ This setting does not delete printers that users have already added. However, if users have not added a printer when this setting is applied, they cannot print.
+
+ Note: You can use printer permissions to restrict the use of printers without specifying a setting. In the Printers folder, right-click a printer, click Properties, and then click the Security tab.
+
+ If this policy is disabled, or not configured, users can add printers using the methods described above.
+ Prevent deletion of printers
+ If this policy setting is enabled, it prevents users from deleting local and network printers.
+
+ If a user tries to delete a printer, such as by using the Delete option in Printers in Control Panel, a message appears explaining that a setting prevents the action.
+
+ This setting does not prevent users from running other programs to delete a printer.
+
+ If this policy is disabled, or not configured, users can delete printers using the methods described above.
+ This policy sets the maximum number of printers (of each type) that the Add Printer wizard will display on a computer on an unmanaged network (when the computer is not able to reach a domain controller, e.g. a domain-joined laptop on a home network.)
+
+If this setting is disabled, the network scan page will not be displayed.
+
+If this setting is not configured, the Add Printer wizard will display the default number of printers of each type:
+TCP/IP printers: 50
+Web Services printers: 50
+Bluetooth printers: 10
+Shared printers: 50
+
+If you would like to not display printers of a certain type, enable this policy and set the number of printers to display to 0.
+
+In Windows 10 and later, only TCP/IP printers can be shown in the wizard. If you enable this policy setting, only TCP/IP printer limits are applicable. On Windows 10 only, if you disable or do not configure this policy setting, the default limit is applied.
+
+In Windows 8 and later, Bluetooth printers are not shown so its limit does not apply to those versions of Windows.
+ Add Printer wizard - Network scan page (Unmanaged network)
+ Only use Package Point and print
+ This policy restricts clients computers to use package point and print only.
+
+If this setting is enabled, users will only be able to point and print to printers that use package-aware drivers. When using package point and print, client computers will check the driver signature of all drivers that are downloaded from print servers.
+
+If this setting is disabled, or not configured, users will not be restricted to package-aware point and print only.
+ Supported Windows XP SP1 through Windows Server 2008 RTM
+ Package Point and print - Approved servers
+ Restricts package point and print to approved servers.
+
+This policy setting restricts package point and print connections to approved servers. This setting only applies to Package Point and Print connections, and is completely independent from the "Point and Print Restrictions" policy that governs the behavior of non-package point and print connections.
+
+Windows Vista and later clients will attempt to make a non-package point and print connection anytime a package point and print connection fails, including attempts that are blocked by this policy. Administrators may need to set both policies to block all print connections to a specific print server.
+
+If this setting is enabled, users will only be able to package point and print to print servers approved by the network administrator. When using package point and print, client computers will check the driver signature of all drivers that are downloaded from print servers.
+
+If this setting is disabled, or not configured, package point and print will not be restricted to specific print servers.
+ Computer location
+ If this policy setting is enabled, it specifies the default location criteria used when searching for printers.
+
+ This setting is a component of the Location Tracking feature of Windows printers. To use this setting, enable Location Tracking by enabling the "Pre-populate printer search location text" setting.
+
+ When Location Tracking is enabled, the system uses the specified location as a criterion when users search for printers. The value you type here overrides the actual location of the computer conducting the search.
+
+ Type the location of the user's computer. When users search for printers, the system uses the specified location (and other search criteria) to find a printer nearby. You can also use this setting to direct users to a particular printer or group of printers that you want them to use.
+
+ If you disable this setting or do not configure it, and the user does not type a location as a search criterion, the system searches for a nearby printer based on the IP address and subnet mask of the user's computer.
+ Pre-populate printer search location text
+ Enables the physical Location Tracking setting for Windows printers.
+
+Use Location Tracking to design a location scheme for your enterprise and assign computers and printers to locations in the scheme. Location Tracking overrides the standard method used to locate and associate computers and printers. The standard method uses a printer's IP address and subnet mask to estimate its physical location and proximity to computers.
+
+If you enable this setting, users can browse for printers by location without knowing the printer's location or location naming scheme. Enabling Location Tracking adds a Browse button in the Add Printer wizard's Printer Name and Sharing Location screen and to the General tab in the Printer Properties dialog box. If you enable the Group Policy Computer location setting, the default location you entered appears in the Location field by default.
+
+If you disable this setting or do not configure it, Location Tracking is disabled. Printer proximity is estimated using the standard method (that is, based on IP address and subnet mask).
+ Point and Print Restrictions
+ This policy setting controls the client Point and Print behavior, including the security prompts for Windows Vista computers. The policy setting applies only to non-Print Administrator clients, and only to computers that are members of a domain.
+
+ If you enable this policy setting:
+ -Windows XP and later clients will only download print driver components from a list of explicitly named servers. If a compatible print driver is available on the client, a printer connection will be made. If a compatible print driver is not available on the client, no connection will be made.
+ -You can configure Windows Vista clients so that security warnings and elevated command prompts do not appear when users Point and Print, or when printer connection drivers need to be updated.
+
+ If you do not configure this policy setting:
+ -Windows Vista client computers can point and print to any server.
+ -Windows Vista computers will show a warning and an elevated command prompt when users create a printer connection to any server using Point and Print.
+ -Windows Vista computers will show a warning and an elevated command prompt when an existing printer connection driver needs to be updated.
+ -Windows Server 2003 and Windows XP client computers can create a printer connection to any server in their forest using Point and Print.
+
+ If you disable this policy setting:
+ -Windows Vista client computers can create a printer connection to any server using Point and Print.
+ -Windows Vista computers will not show a warning or an elevated command prompt when users create a printer connection to any server using Point and Print.
+ -Windows Vista computers will not show a warning or an elevated command prompt when an existing printer connection driver needs to be updated.
+ -Windows Server 2003 and Windows XP client computers can create a printer connection to any server using Point and Print.
+ -The "Users can only point and print to computers in their forest" setting applies only to Windows Server 2003 and Windows XP SP1 (and later service packs).
+ Show warning and elevation prompt
+ Do not show warning or elevation prompt
+ Show warning only
+ Default Active Directory path when searching for printers
+ Specifies the Active Directory location where searches for printers begin.
+
+ The Add Printer Wizard gives users the option of searching Active Directory for a shared printer.
+
+ If you enable this policy setting, these searches begin at the location you specify in the "Default Active Directory path" box. Otherwise, searches begin at the root of Active Directory.
+
+ This setting only provides a starting point for Active Directory searches for printers. It does not restrict user searches through Active Directory.
+ Printer browsing
+ Announces the presence of shared printers to print browse master servers for the domain.
+
+On domains with Active Directory, shared printer resources are available in Active Directory and are not announced.
+
+If you enable this setting, the print spooler announces shared printers to the print browse master servers.
+
+If you disable this setting, shared printers are not announced to print browse master servers, even if Active Directory is not available.
+
+If you do not configure this setting, shared printers are announced to browse master servers only when Active Directory is not available.
+
+Note: A client license is used each time a client computer announces a printer to a print browse master on the domain.
+ Execute print drivers in isolated processes
+ This policy setting determines whether the print spooler will execute print drivers in an isolated or separate process. When print drivers are loaded in an isolated process (or isolated processes), a print driver failure will not cause the print spooler service to fail.
+
+If you enable or do not configure this policy setting, the print spooler will execute print drivers in an isolated process by default.
+
+If you disable this policy setting, the print spooler will execute print drivers in the print spooler process.
+
+
+Notes:
+-Other system or driver policy settings may alter the process in which a print driver is executed.
+-This policy setting applies only to print drivers loaded by the print spooler. Print drivers loaded by applications are not affected.
+-This policy setting takes effect without restarting the print spooler service.
+ Override print driver execution compatibility setting reported by print driver
+ This policy setting determines whether the print spooler will override the Driver Isolation compatibility reported by the print driver. This enables executing print drivers in an isolated process, even if the driver does not report compatibility.
+
+If you enable this policy setting, the print spooler isolates all print drivers that do not explicitly opt out of Driver Isolation.
+
+If you disable or do not configure this policy setting, the print spooler uses the Driver Isolation compatibility flag value reported by the print driver.
+
+Notes:
+-Other system or driver policy settings may alter the process in which a print driver is executed.
+-This policy setting applies only to print drivers loaded by the print spooler. Print drivers loaded by applications are not affected.
+-This policy setting takes effect without restarting the print spooler service.
+ Allow job name in event logs
+
+ This policy controls whether the print job name will be included in print event logs.
+
+ If you disable or do not configure this policy setting, the print job name will not be included.
+
+ If you enable this policy setting, the print job name will be included in new log entries.
+
+ Note: This setting does not apply to Branch Office Direct Printing jobs.
+
+ Extend Point and Print connection to search Windows Update
+ This policy setting allows you to manage where client computers search for Point and Printer drivers.
+
+If you enable this policy setting, the client computer will continue to search for compatible Point and Print drivers from Windows Update after it fails to find the compatible driver from the local driver store and the server driver cache.
+
+If you disable this policy setting, the client computer will only search the local driver store and server driver cache for compatible Point and Print drivers. If it is unable to find a compatible driver, then the Point and Print connection will fail.
+
+This policy setting is not configured by default, and the behavior depends on the version of Windows that you are using.
+By default, Windows Ultimate, Professional and Home SKUs will continue to search for compatible Point and Print drivers from Windows Update, if needed. However, you must explicitly enable this policy setting for other versions of Windows (for example Windows Enterprise, and all versions of Windows Server 2008 R2 and later) to have the same behavior.
+ Do not allow v4 printer drivers to show printer extensions
+ This policy determines if v4 printer drivers are allowed to run printer extensions.
+
+ V4 printer drivers may include an optional, customized user interface known as a printer extension. These extensions may provide access to more device features, but this may not be appropriate for all enterprises.
+
+ If you enable this policy setting, then all printer extensions will not be allowed to run.
+
+ If you disable this policy setting or do not configure it, then all printer extensions that have been installed will be allowed to run.
+ Change Microsoft XPS Document Writer (MXDW) default output format to the legacy Microsoft XPS format (*.xps)
+ Microsoft XPS Document Writer (MXDW) generates OpenXPS (*.oxps) files by default in Windows 10, Windows 10 and Windows Server 2025.
+
+ If you enable this group policy setting, the default MXDW output format is the legacy Microsoft XPS (*.xps).
+
+ If you disable or do not configure this policy setting, the default MXDW output format is OpenXPS (*.oxps).
+ Turn off Windows default printer management
+ This preference allows you to change default printer management.
+
+If you enable this setting, Windows will not manage the default printer.
+
+If you disable this setting, Windows will manage the default printer.
+
+If you do not configure this setting, default printer management will not change.
+ Enable Device Control Printing Restrictions
+
+Determines whether Device Control Printing Restrictions are enforced for printing on this computer.
+
+By default, there are no restrictions to printing based on connection type or printer Make/Model.
+
+If you enable this setting, the computer will restrict printing to printer connections on the corporate network or approved USB-connected printers.
+
+If you disable this setting or do not configure it, there are no restrictions to printing based on connection type or printer Make/Model.
+ List of Approved USB-connected print devices
+
+
+This setting is a component of the Device Control Printing Restrictions. To use this setting, enable Device Control Printing by enabling the "Enable Device Control Printing Restrictions" setting.
+
+When Device Control Printing is enabled, the system uses the specified list of vid/pid values to determine if the current USB connected printer is approved for local printing.
+
+Type all the approved vid/pid combinations (separated by commas) that correspond to approved USB printer models. When a user tries to print to a USB printer queue the device vid/pid will be compared to the approved list.
+
+ Limits print driver installation to Administrators
+
+Determines whether users that aren't Administrators can install print drivers on this computer.
+
+By default, users that aren't Administrators can't install print drivers on this computer.
+
+If you enable this setting or do not configure it, the system will limit installation of print drivers to Administrators of this computer.
+
+If you disable this setting, the system won't limit installation of print drivers to this computer.
+
+ Manage processing of Queue-specific files
+ Allow all Queue-specfic files
+ Do not allow Queue-specific files
+
+Manages how Queue-specific files are processed during printer installation. At printer installation time, a vendor-supplied installation application can specify a set of files, of any type, to be associated with a particular print queue. The files are downloaded to each client that connects to the print server.
+
+You can enable this setting to change the default behavior involving queue-specific files. To use this setting, select one of the options below from the "Manage processing of Queue-specific files" box.
+
+If you disable or do not configure this policy setting, the default behavior is "Limit Queue-specific files to Color profiles".
+
+-- "Do not allow Queue-specific files" specifies that no queue-specific files will be allowed/processed during print queue/printer connection installation.
+
+-- "Limit Queue-specific files to Color profiles" specifies that only queue-specific files that adhere to the standard color profile scheme will be allowed. This means entries using the Registry Key CopyFiles\ICM, containing a Directory value of COLOR and supporting mscms.dll as the Module value. "Limit Queue-specific files to Color profiles" is the default behavior.
+
+-- "Allow all Queue-specific files" specifies that all queue-specific files will be allowed/processed during print queue/printer connection installation.
+
+ Limit Queue-specific files to Color profiles
+ Require inbox signed drivers
+ Allow all validly signed drivers
+ Allow inbox and Print Drivers Trusted Store signed drivers
+ Allow inbox, Print Drivers Trusted Store, WHQL, and Trusted Publisher Store signed drivers
+ Allow inbox, Print Drivers Trusted Store, and WHQL signed drivers
+ Manage Print Driver signature validation
+
+ This policy setting controls the print driver signature validation mechanism. This policy controls the type of digital signature that is required for a print driver to be considered valid and installed on the system.
+
+ As part of this validation the catalog/embedded signature is verified and all files in the driver must be a part of the catalog or have their own embedded signature that can be used for validation.
+
+ You can enable this setting to change the default signature validation method. To use this setting, select one of the options below from the "Select the driver signature mechanism for this computer" box.
+
+ If you disable or do not configure this policy setting, the default method is "Allow all validly signed drivers".
+
+ -- "Require inbox signed drivers" specifies only drivers that are shipped as part of a Windows image are allowed on this computer.
+
+ -- "Allow inbox and PrintDrivers Trusted Store signed drivers" specifies only drivers that are shipped as part of a Windows image or drivers that are signed by certificates installed in the 'PrintDrivers' certificate store are allowed on this computer.
+
+ -- "Allow inbox, PrintDrivers Trusted Store, and WHQL signed drivers" specifies the only drivers allowed on this computer are those that are: shipped as part of a Windows image, signed by certificates installed in the 'PrintDrivers' certificate store, or signed by the Windows Hardware Quality Lab (WHQL).
+
+ -- "Allow inbox, PrintDrivers Trusted Store, WHQL, and Trusted Publishers Store signed drivers" specifies the only drivers allowed on this computer are those that are: shipped as part of a Windows image, signed by certificates installed in the 'PrintDrivers' certificate store, signed by the Windows Hardware Quality Lab (WHQL), or signed by certificates installed in the 'Trusted Publishers' certificate store.
+
+ -- "Allow all validly signed drivers" specfies that any print driver that has a valid embedded signature or can be validated against the print driver catalog can be installed on this computer.
+
+ The 'PrintDrivers' certificate store needs to be created by an administrator under the local machine store location.
+
+ The 'Trusted Publishers' certificate store can contain certificates from sources that are not related to print drivers.
+
+
+ Select the driver signature mechanism for this computer
+ Manage Print Driver exclusion list
+
+This policy setting controls the print driver exclusion list. The exclusion list allows an administrator to curate a list of printer drivers that are not allowed to be installed on the system.
+
+This checks outranks the signature check and allows drivers that have a valid signature level for the Print Driver signature validation policy to be excluded.
+
+Entries in the exclusion list consist of a SHA256 hash (or SHA1 hash for Win7) of the INF file and/or main driver DLL file of the driver and the name of the file.
+
+If you disable or do not configure this policy setting, the registry key and values associated with this policy setting will be deleted, if currently set to a value.
+
+
+ Configure RPC listener settings
+ RPC over named pipes
+ RPC over TCP
+ RPC over named pipes and TCP
+ Negotiate
+ Kerberos
+
+This policy setting controls which protocols incoming RPC connections to the print spooler are allowed to use.
+
+By default, RPC over TCP is enabled and Negotiate is used for the authentication protocol.
+
+Protocols to allow for incoming RPC connections:
+ -- "RPC over named pipes": Incoming RPC connections are only allowed over named pipes
+ -- "RPC over TCP": Incoming RPC connections are only allowed over TCP (the default option)
+ -- "RPC over named pipes and TCP": Incoming RPC connections will be allowed over TCP and named pipes
+
+Authentication protocol to use for incoming RPC connections:
+ -- "Negotiate": Use the Negotiate authentication protocol (the default option)
+ -- "Kerberos": Use the Kerberos authentication protocol
+
+If you disable or do not configure this policy setting, the above defaults will be used.
+
+ Configure RPC connection settings
+ Default
+ Authentication enabled
+ Authentication disabled
+
+This policy setting controls which protocol and protocol settings to use for outgoing RPC connections to a remote print spooler.
+
+By default, RPC over TCP is used and authentication is always enabled. For RPC over named pipes, authentication is always enabled for domain joined machines but disabled for non domain joined machines.
+
+Protocol to use for outgoing RPC connections:
+ -- "RPC over TCP": Use RPC over TCP for outgoing RPC connections to a remote print spooler
+ -- "RPC over named pipes": Use RPC over named pipes for outgoing RPC connections to a remote print spooler
+
+Use authentication for outgoing RPC over named pipes connections:
+ -- "Default": By default domain joined computers enable RPC authentication for RPC over named pipes while non domain joined computers disable RPC authentication for RPC over named pipes
+ -- "Authentication enabled": RPC authentication will be used for outgoing RPC over named pipes connections
+ -- "Authentication disabled": RPC authentication will not be used for outgoing RPC over named pipes connections
+
+If you disable or do not configure this policy setting, the above defaults will be used.
+
+ Configure RPC over TCP port
+
+This policy setting controls which port is used for RPC over TCP for incoming connections to the print spooler and outgoing connections to remote print spoolers.
+
+By default dynamic TCP ports are used.
+
+RPC over TCP port:
+ -- The port to use for RPC over TCP. A value of 0 is the default and indicates that dynamic TCP ports will be used
+
+If you disable or do not configure this policy setting, dynamic TCP ports are used.
+
+ Configure RPC packet level privacy setting for incoming connections
+
+This policy setting controls whether packet level privacy is enabled for RPC for incoming connections.
+
+By default packet level privacy is enabled for RPC for incoming connections.
+
+If you enable or do not configure this policy setting, packet level privacy is enabled for RPC for incoming connections.
+
+ Always send job page count information for IPP printers
+
+Determines whether to always send page count information for accounting purposes for printers using the Microsoft IPP Class Driver.
+
+By default, pages are sent to the printer as soon as they are rendered and page count information is not sent to the printer unless pages must be reordered.
+
+If you enable this setting the system will render all print job pages up front and send the printer the total page count for the print job.
+
+If you disable this setting or do not configure it, pages are printed as soon as they are rendered and page counts are only sent when page reordering is required to process the job.
+
+ Require IPPS for IPP printers
+ Determines whether communication with printers using the Microsoft IPP Class Driver must use IPPS (which uses TLS for secure communication).
+
+If you enable this policy setting, then only IPP printers which support IPPS can be installed.
+
+If you disable this setting or do not configure it, the default is to allow installation of IPP printers which do not support IPPS.
+
+ Set TLS/SSL security policy for IPP printers
+
+Determines the TLS/SSL security policy (WINHTTP_OPTION_SECURITY_FLAGS) for printers using the Microsoft IPP Class Driver.
+
+By default, security policy is set to ignore all certificate errors, allowing use of self-signed certificates for printers.
+
+If you enable this setting the system defaults to enabling all certificate checking, disallowing certificate errors. Specific certificate checking can be set with the given checkboxes.
+
+If you disable this setting or do not configure it, the default is to ignore all certificate errors (all checkboxes unchecked).
+
+ Configure Redirection Guard
+ Redirection Guard Disabled
+ Redirection Guard Enabled
+ Redirection Guard Audit Only
+
+Determines whether Redirection Guard is enabled for the print spooler.
+
+You can enable this setting to configure the Redirection Guard policy being applied to spooler.
+
+If you disable or do not configure this policy setting, Redirection Guard will default to being 'Enabled'.
+
+If you enable this setting you may select the following options:
+
+-- Enabled : Redirection Guard will prevent any file redirections from being followed
+
+-- Disabed : Redirection Guard will not be enabled and file redirections may be used within the spooler process
+
+-- Audit : Redirection Guard will log events as though it were enabled but will not actually prevent file redirections from being used within the spooler.
+
+ Configure Windows protected print
+
+Determines whether Windows protected print is enabled on this computer.
+
+By default, Windows protected print is not enabled and there are not any restrictions on the print drivers that can be installed or print functionality.
+
+If you enable this setting, the computer will operate in Windows protected print mode which only allows printing to printers that support a subset of inbox Windows print drivers.
+
+If you disable this setting or do not configure it, there are not any restrictions on the print drivers that can be installed or print functionality.
+
+For more information, please see https://learn.microsoft.com/en-us/windows-hardware/drivers/print/windows-protected-print-mode
+
+
+
+
+ Specify the URL. For example, the url would be: http://www.microsoft.com/support
+
+
+
+
+
+ Number of directory printers
+ Number of TCP/IP printers
+ Number of Web Services Printers
+ Number of Bluetooth printers
+ Number of shared printers
+
+
+ Enable this option to add a browse button for Internet printers
+ in the Add Printer Wizard. Use this setting to allow users browsing
+ the company's Intranet for printers. For example, you can
+ specify a URL like: http://www.company.com/printers.
+ To enable this option, the edit box below should not be empty.
+
+
+
+
+
+ Number of TCP/IP printers
+ Number of Web Services Printers
+ Number of Bluetooth printers
+ Number of shared printers
+
+
+ Enter fully qualified server names
+
+
+ Enter the location of this computer
+ For example: CityName/Building 2/Floor 1/Office 1800
+
+
+
+
+
+ Users can only point and print to these servers:
+
+
+
+ Users can only point and print to machines in their forest
+
+ Security Prompts:
+ When installing drivers for a new connection:
+ When updating drivers for an existing connection:
+ This setting only applies to:
+ Windows Vista and later
+
+
+
+
+
+ example --> LDAP://DC=Domain1,DC=MyCompany,DC=com.
+
+
+ Specify the list of approved USB-connected printer devices.
+ The list is a comma separated list of USB vid/pid values. Example: 0351/0872,135E/2179
+
+
+
+
+
+ Select the method by which Queue-specific files will be processed.
+ Manage processing of Queue-Specific files:
+
+
+ Select the driver signature mechanism for this computer:
+
+
+
+ Enter a File Hash paired with the name of the file the Hash represents below.
+
+ File Hash File Name:
+
+
+ Configure protocol options for incoming RPC connections.
+ Protocols to allow for incoming RPC connections:
+ Authentication protocol to use for incoming RPC connections:
+
+
+ Configure protocol options for outgoing RPC connections.
+ Protocol to use for outgoing RPC connections:
+ Use authentication for outgoing RPC connections:
+
+
+ Configure port to use for RPC over TCP.
+ RPC over TCP port:
+
+
+ Disallow invalid certificate authority
+ Disallow non-server certificates
+ Disallow invalid certificate common name
+ Disallow invalid certificate date
+
+
+ Configure options for Redirection Guard
+ Redirection Guard Options
+
+
+
+
diff --git a/config/admx/en-US/SecGuide.adml b/config/admx/en-US/SecGuide.adml
index a7c86c7..64601f5 100644
--- a/config/admx/en-US/SecGuide.adml
+++ b/config/admx/en-US/SecGuide.adml
@@ -1,259 +1,259 @@
-
-
-
- MS Security Guide
- MS Security Guide mitigations
-
-
-
- Only Windows 7, Windows Server 2008, Windows Server 2008R2, Windows Server 2012
- Windows Server 2008 and newer
-
- MS Security Guide
- Apply UAC restrictions to local accounts on network logons
- This setting controls whether local accounts can be used for remote administration via network logon (e.g., NET USE, connecting to C$, etc.). Local accounts are at high risk for credential theft when the same account and password is configured on multiple systems. Enabling this policy significantly reduces that risk.
-
-Enabled (recommended): Applies UAC token-filtering to local accounts on network logons. Membership in powerful group such as Administrators is disabled and powerful privileges are removed from the resulting access token. This configures the LocalAccountTokenFilterPolicy registry value to 0. This is the default behavior for Windows.
-
-Disabled: Allows local accounts to have full administrative rights when authenticating via network logon, by configuring the LocalAccountTokenFilterPolicy registry value to 1.
-
-For more information about local accounts and credential theft, see "Mitigating Pass-the-Hash (PtH) Attacks and Other Credential Theft Techniques": http://www.microsoft.com/en-us/download/details.aspx?id=36036.
-
-For more information about LocalAccountTokenFilterPolicy, see http://support.microsoft.com/kb/951016.
-
- WDigest Authentication (disabling may require KB2871997)
- When WDigest authentication is enabled, Lsass.exe retains a copy of the user's plaintext password in memory, where it can be at risk of theft. Microsoft recommends disabling WDigest authentication unless it is needed.
-
-If this setting is not configured, WDigest authentication is disabled in Windows 8.1 and in Windows Server 2012 R2; it is enabled by default in earlier versions of Windows and Windows Server.
-
-Update KB2871997 must first be installed to disable WDigest authentication using this setting in Windows 7, Windows 8, Windows Server 2008 R2 and Windows Server 2012.
-
-Enabled: Enables WDigest authentication.
-
-Disabled (recommended): Disables WDigest authentication. For this setting to work on Windows 7, Windows 8, Windows Server 2008 R2 or Windows Server 2012, KB2871997 must first be installed.
-
-For more information, see http://support.microsoft.com/kb/2871997 and http://blogs.technet.com/b/srd/archive/2014/06/05/an-overview-of-kb2871997.aspx .
-
- Lsass.exe audit mode
- Enable auditing of Lsass.exe to evaluate feasibility of enabling LSA protection. For more information, see http://technet.microsoft.com/en-us/library/dn408187.aspx
- LSA Protection
- For Windows 11, version 22H2 and beyond a new setting is used to configure this. IT can be located at 'System\Local Security Authority\Configures LSASS to run as a protected process' which provides additional configuration options.
-
-Enable LSA protection.
-
-For more information, see http://technet.microsoft.com/en-us/library/dn408187.aspx
- Remove "Run As Different User" from context menus
- This setting controls whether "Run As Different User" appears on the Shift+RightClick context menu for .bat, .cmd, .exe, and .msc files.
-
-Enabled (recommended): Keeps "Run As Different User" from appearing in the context menu when the user holds Shift while right-clicking on a .bat, .cmd, .exe, or .msc file in Explorer.
-
-Disabled: Restores the Windows default behavior for "Run As Different User."
-
-
- Turn on Windows Defender protection against Potentially Unwanted Applications (DEPRECATED)
- Beginning with Windows 10 v1809 and Windows Server v1809, this functionality should instead be configured through the following Group Policy setting:
-Computer Configuration\Administrative Templates\Windows Components\Windows Defender Antivirus\Configure detection for potentially unwanted applications.
-
-
- Enable Structured Exception Handling Overwrite Protection (SEHOP)
- If this setting is enabled, SEHOP is enforced. For more information, see https://support.microsoft.com/en-us/help/956607/how-to-enable-structured-exception-handling-overwrite-protection-sehop-in-windows-operating-systems.
-
-If this setting is disabled or not configured, SEHOP is not enforced for 32-bit processes.
-
- Limits print driver installation to Administrators (DEPRECATED)
-
-This setting has moved to a new inbox location which can be found at Printers\Limits print driver installation to Administrators.
-
-NOTE - This derecated setting shares the same registry entry as the new one.
-
-Determines whether users that aren't Administrator can install print drivers on this computer.
-
-By default, users that aren't Administrators can't install print drivers on this computer.
-
-If you enable this setting or do not configure it, the system will limit installation of print drivers to Administrators of this computer.
-
-If you disable this setting, the system will not limit installation of print drivers to this computer.
-
-Additional Information: https://support.microsoft.com/en-us/topic/kb5005010-restricting-installation-of-new-printer-drivers-after-applying-the-july-6-2021-updates-31b91c02-05bc-4ada-a7ea-183b129578a7 for additional information.
-
- Configure SMB v1 server
- Disabling this setting disables server-side processing of the SMBv1 protocol. (Recommended.)
-
-Enabling this setting enables server-side processing of the SMBv1 protocol. (Default.)
-
-Changes to this setting require a reboot to take effect.
-
-For more information, see https://support.microsoft.com/kb/2696547
-
- Configure SMB v1 client driver
- Configures the SMB v1 client driver's start type.
-
-To disable client-side processing of the SMBv1 protocol, select the "Enabled" radio button, then select "Disable driver" from the dropdown.
-WARNING: DO NOT SELECT THE "DISABLED" RADIO BUTTON UNDER ANY CIRCUMSTANCES!
-
-For Windows 7 and Servers 2008, 2008R2, and 2012, you must also configure the "Configure SMB v1 client (extra setting needed for pre-Win8.1/2012R2)" setting.
-
-To restore default SMBv1 client-side behavior, select "Enabled" and choose the correct default from the dropdown:
-* "Manual start" for Windows 7 and Windows Servers 2008, 2008R2, and 2012;
-* "Automatic start" for Windows 8.1 and Windows Server 2012R2 and newer.
-
-Changes to this setting require a reboot to take effect.
-
-For more information, see https://support.microsoft.com/kb/2696547
-
- Configure SMB v1 client (extra setting needed for pre-Win8.1/2012R2)
- APPLIES ONLY TO: Windows 7 and Windows Servers 2008, 2008R2 and 2012 (NOT 2012R2):
-
-To disable client-side processing of the SMBv1 protocol (recommended), do ALL of the following:
-* Set the SMBv1 client driver to "Disable driver" using the "Configure SMB v1 client driver" setting;
-* Enable this setting;
-* In the "Configure LanmanWorkstation dependencies" text box, enter the following three lines of text:
-Bowser
-MRxSmb20
-NSI
-
-To restore the default behavior for client-side SMBv1 protocol processing, do ALL of the following:
-* Set the SMBv1 client driver to "Manual start" using the "Configure SMB v1 client driver" setting;
-* Enable this setting;
-* In the "Configure LanmanWorkstation dependencies" text box, enter the following four lines of text:
-Bowser
-MRxSmb10
-MRxSmb20
-NSI
-
-WARNING: DO NOT SELECT THE "DISABLED" RADIO BUTTON UNDER ANY CIRCUMSTANCES!
-
-Changes to this setting require a reboot to take effect.
-
-For more information, see https://support.microsoft.com/kb/2696547
-
- Disable driver (recommended)
- Manual start (default for Win7/2008/2008R2/2012)
- Automatic start (default for Win8.1/2012R2/newer)
-
-
-
-NetBT NodeType configuration
-The NetBT NodeType setting determines what methods NetBT uses to register and resolve names:
-* A B-node computer uses broadcasts.
-* A P-node computer uses only point-to-point name queries to a name server (WINS).
-* An M-node computer broadcasts first, and then queries the name server.
-* An H-node computer queries the name server first, and then broadcasts.
-Resolution through LMHOSTS or DNS follows these methods. If the NodeType value is present, it overrides any DhcpNodeType value.
-If neither NodeType nor DhcpNodeType is present, the computer uses B-node if there are no WINS servers configured for the network, or H-node if there is at least one WINS server configured.
-
-B-node
-P-node (recommended)
-M-node
-H-node
-
-
-
-Extended Protection for LDAP Authentication (Domain Controllers only) (DEPRECATED)
-Beginning with the Windows 10 and Windows Server v2004 security baseline this setting has been moved to Security Options\Domain controller: LDAP server channel binding token requirements.
-
-Enabled, always (recommended)
-Enabled, when supported
-Disabled
-
-
- Block Flash activation in Office documents
- This policy setting controls whether the Adobe Flash control can be activated by Office documents. Note that activation blocking applies only within Office processes.
-
-If you enable this policy setting, you can choose from three options to control whether and how Flash is blocked from activation:
-
-1. "Block all activation" prevents the Flash control from being loaded, whether directly referenced by the document or indirectly by another embedded object.
-
-2. "Block embedding/linking, allow other activation" prevents the Flash control from being loaded when directly referenced by the document, but does not prevent activation through another object.
-
-3. "Allow all activation" restores Office's default behavior, allowing the Flash control to be activated.
-
-Because this setting is not a true Group Policy setting and "tattoos" the registry, enabling the "Allow all activation" option is the only way to restore default behavior after either of the "Block" options has been applied. We do not recommend configuring this setting to "Disabled," nor to "Not Configured" after it has been enabled.
-
- Block all activation
- Block embedding/linking, allow other activation
- Allow all activation
- Restrict legacy JScript execution for Office
- This policy setting controls JScript execution per Security Zone within Internet Explorer and WebBrowser Control (WebOC) for Office applications.
-
-It's important to determine whether legacy JScript is being used to provide business-critical functionality before you enable this setting.
-
-If Enabled, Office applications will not execute legacy JScript for the Internet or Restricted Sites zones and users aren’t notified by the application that legacy JScript execution is restricted. Modern JScript9 will continue to function for all zones.
-
-If Disabled or Not Configured JScript will function without any restrictions.
-
-The values are set in hexadecimal and should be converted prior to changing the setting value. To learn more about Internet Explorer Feature Control Key and the Restrict JScript process-level policy for Windows, please refer to: https://docs.microsoft.com/en-us/previous-versions/windows/internet-explorer/ie-developer/general-info/ee330734(v=vs.85)#restrict-jscript-at-a-process-level
-
- Configure RPC packet level privacy setting for incoming connections
-
-This policy setting controls whether packet level privacy is enabled for RPC for incoming connections.
-
-By default packet level privacy is enabled for RPC for incoming connections.
-
-If you enable or do not configure this policy setting, packet level privacy is enabled for RPC for incoming connections.
-
- Manage processing of Queue-specific files (DEPRECATED)
- Allow all Queue-specfic files
- Do not allow Queue-specific files
-
-This setting has moved to a new inbox location which can be found at Printers\Manage processing of Queue-specific files.
-
-Manages how Queue-specific files are processed during printer installation. At printer installation time, a vendor-supplied installation application can specify a set of files, of any type, to be associated with a particular print queue. The files are downloaded to each client that connects to the print server.
-
-You can enable this setting to change the default behavior involving queue-specific files. To use this setting, select one of the options below from the "Manage processing of Queue-specific files" box.
-
-If you disable or do not configure this policy setting, the default behavior is "Limit Queue-specific files to Color profiles".
-
--- "Do not allow Queue-specific files" specifies that no queue-specific files will be allowed/processed during print queue/printer connection installation.
-
--- "Limit Queue-specific files to Color profiles" specifies that only queue-specific files that adhere to the standard color profile scheme will be allowed. This means entries using the Registry Key CopyFiles\ICM, containing a Directory value of COLOR and supporting mscms.dll as the Module value. "Limit Queue-specific files to Color profiles" is the default behavior.
-
--- "Allow all Queue-specific files" specifies that all queue-specific files will be allowed/processed during print queue/printer connection installation.
-
- Limit Queue-specific files to Color profiles
-
-
- Enable Certificate Padding
- Enabling this setting will cause the WinVerifyTrust function to perform strict Windows Authenticode signature verification for Portable Executable files (PE files). After you opt in, PE files will be considered "unsigned" if Windows identifies content in them that does not conform to the Authenticode specification. This may impact some installers. If you are using an installer that is impacted, Microsoft recommends using an installer that only extracts content from validated portions of the signed file.
-
-Reference: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2013-3900
-
-
-
-
-
-
- Configure MrxSmb10 driver
-
-
- Configure LanmanWorkstation dependencies
-
-
- Configure NetBT NodeType
-
-
- Configure LdapEnforceChannelBinding
-
-
- Block Flash player in Office
-
-
- Excel:
- Publisher:
- PowerPoint:
- OneNote:
- Visio:
- Project:
- Word:
- Outlook:
- Access:
-
-
- Select the method by which Queue-specific files will be processed.
- Manage processing of Queue-Specific files:
-
-
-
-
-
-
+
+
+
+ MS Security Guide
+ MS Security Guide mitigations
+
+
+
+ Only Windows 7, Windows Server 2008, Windows Server 2008R2, Windows Server 2012
+ Windows Server 2008 and newer
+
+ MS Security Guide
+ Apply UAC restrictions to local accounts on network logons
+ This setting controls whether local accounts can be used for remote administration via network logon (e.g., NET USE, connecting to C$, etc.). Local accounts are at high risk for credential theft when the same account and password is configured on multiple systems. Enabling this policy significantly reduces that risk.
+
+Enabled (recommended): Applies UAC token-filtering to local accounts on network logons. Membership in powerful group such as Administrators is disabled and powerful privileges are removed from the resulting access token. This configures the LocalAccountTokenFilterPolicy registry value to 0. This is the default behavior for Windows.
+
+Disabled: Allows local accounts to have full administrative rights when authenticating via network logon, by configuring the LocalAccountTokenFilterPolicy registry value to 1.
+
+For more information about local accounts and credential theft, see "Mitigating Pass-the-Hash (PtH) Attacks and Other Credential Theft Techniques": http://www.microsoft.com/en-us/download/details.aspx?id=36036.
+
+For more information about LocalAccountTokenFilterPolicy, see http://support.microsoft.com/kb/951016.
+
+ WDigest Authentication (disabling may require KB2871997)
+ When WDigest authentication is enabled, Lsass.exe retains a copy of the user's plaintext password in memory, where it can be at risk of theft. Microsoft recommends disabling WDigest authentication unless it is needed.
+
+If this setting is not configured, WDigest authentication is disabled in Windows 8.1 and in Windows Server 2012 R2; it is enabled by default in earlier versions of Windows and Windows Server.
+
+Update KB2871997 must first be installed to disable WDigest authentication using this setting in Windows 7, Windows 8, Windows Server 2008 R2 and Windows Server 2012.
+
+Enabled: Enables WDigest authentication.
+
+Disabled (recommended): Disables WDigest authentication. For this setting to work on Windows 7, Windows 8, Windows Server 2008 R2 or Windows Server 2012, KB2871997 must first be installed.
+
+For more information, see http://support.microsoft.com/kb/2871997 and http://blogs.technet.com/b/srd/archive/2014/06/05/an-overview-of-kb2871997.aspx .
+
+ Lsass.exe audit mode
+ Enable auditing of Lsass.exe to evaluate feasibility of enabling LSA protection. For more information, see http://technet.microsoft.com/en-us/library/dn408187.aspx
+ LSA Protection
+ For Windows 11, version 22H2 and beyond a new setting is used to configure this. IT can be located at 'System\Local Security Authority\Configures LSASS to run as a protected process' which provides additional configuration options.
+
+Enable LSA protection.
+
+For more information, see http://technet.microsoft.com/en-us/library/dn408187.aspx
+ Remove "Run As Different User" from context menus
+ This setting controls whether "Run As Different User" appears on the Shift+RightClick context menu for .bat, .cmd, .exe, and .msc files.
+
+Enabled (recommended): Keeps "Run As Different User" from appearing in the context menu when the user holds Shift while right-clicking on a .bat, .cmd, .exe, or .msc file in Explorer.
+
+Disabled: Restores the Windows default behavior for "Run As Different User."
+
+
+ Turn on Windows Defender protection against Potentially Unwanted Applications (DEPRECATED)
+ Beginning with Windows 10 v1809 and Windows Server v1809, this functionality should instead be configured through the following Group Policy setting:
+Computer Configuration\Administrative Templates\Windows Components\Windows Defender Antivirus\Configure detection for potentially unwanted applications.
+
+
+ Enable Structured Exception Handling Overwrite Protection (SEHOP)
+ If this setting is enabled, SEHOP is enforced. For more information, see https://support.microsoft.com/en-us/help/956607/how-to-enable-structured-exception-handling-overwrite-protection-sehop-in-windows-operating-systems.
+
+If this setting is disabled or not configured, SEHOP is not enforced for 32-bit processes.
+
+ Limits print driver installation to Administrators (DEPRECATED)
+
+This setting has moved to a new inbox location which can be found at Printers\Limits print driver installation to Administrators.
+
+NOTE - This derecated setting shares the same registry entry as the new one.
+
+Determines whether users that aren't Administrator can install print drivers on this computer.
+
+By default, users that aren't Administrators can't install print drivers on this computer.
+
+If you enable this setting or do not configure it, the system will limit installation of print drivers to Administrators of this computer.
+
+If you disable this setting, the system will not limit installation of print drivers to this computer.
+
+Additional Information: https://support.microsoft.com/en-us/topic/kb5005010-restricting-installation-of-new-printer-drivers-after-applying-the-july-6-2021-updates-31b91c02-05bc-4ada-a7ea-183b129578a7 for additional information.
+
+ Configure SMB v1 server
+ Disabling this setting disables server-side processing of the SMBv1 protocol. (Recommended.)
+
+Enabling this setting enables server-side processing of the SMBv1 protocol. (Default.)
+
+Changes to this setting require a reboot to take effect.
+
+For more information, see https://support.microsoft.com/kb/2696547
+
+ Configure SMB v1 client driver
+ Configures the SMB v1 client driver's start type.
+
+To disable client-side processing of the SMBv1 protocol, select the "Enabled" radio button, then select "Disable driver" from the dropdown.
+WARNING: DO NOT SELECT THE "DISABLED" RADIO BUTTON UNDER ANY CIRCUMSTANCES!
+
+For Windows 7 and Servers 2008, 2008R2, and 2012, you must also configure the "Configure SMB v1 client (extra setting needed for pre-Win8.1/2012R2)" setting.
+
+To restore default SMBv1 client-side behavior, select "Enabled" and choose the correct default from the dropdown:
+* "Manual start" for Windows 7 and Windows Servers 2008, 2008R2, and 2012;
+* "Automatic start" for Windows 8.1 and Windows Server 2012R2 and newer.
+
+Changes to this setting require a reboot to take effect.
+
+For more information, see https://support.microsoft.com/kb/2696547
+
+ Configure SMB v1 client (extra setting needed for pre-Win8.1/2012R2)
+ APPLIES ONLY TO: Windows 7 and Windows Servers 2008, 2008R2 and 2012 (NOT 2012R2):
+
+To disable client-side processing of the SMBv1 protocol (recommended), do ALL of the following:
+* Set the SMBv1 client driver to "Disable driver" using the "Configure SMB v1 client driver" setting;
+* Enable this setting;
+* In the "Configure LanmanWorkstation dependencies" text box, enter the following three lines of text:
+Bowser
+MRxSmb20
+NSI
+
+To restore the default behavior for client-side SMBv1 protocol processing, do ALL of the following:
+* Set the SMBv1 client driver to "Manual start" using the "Configure SMB v1 client driver" setting;
+* Enable this setting;
+* In the "Configure LanmanWorkstation dependencies" text box, enter the following four lines of text:
+Bowser
+MRxSmb10
+MRxSmb20
+NSI
+
+WARNING: DO NOT SELECT THE "DISABLED" RADIO BUTTON UNDER ANY CIRCUMSTANCES!
+
+Changes to this setting require a reboot to take effect.
+
+For more information, see https://support.microsoft.com/kb/2696547
+
+ Disable driver (recommended)
+ Manual start (default for Win7/2008/2008R2/2012)
+ Automatic start (default for Win8.1/2012R2/newer)
+
+
+
+NetBT NodeType configuration
+The NetBT NodeType setting determines what methods NetBT uses to register and resolve names:
+* A B-node computer uses broadcasts.
+* A P-node computer uses only point-to-point name queries to a name server (WINS).
+* An M-node computer broadcasts first, and then queries the name server.
+* An H-node computer queries the name server first, and then broadcasts.
+Resolution through LMHOSTS or DNS follows these methods. If the NodeType value is present, it overrides any DhcpNodeType value.
+If neither NodeType nor DhcpNodeType is present, the computer uses B-node if there are no WINS servers configured for the network, or H-node if there is at least one WINS server configured.
+
+B-node
+P-node (recommended)
+M-node
+H-node
+
+
+
+Extended Protection for LDAP Authentication (Domain Controllers only) (DEPRECATED)
+Beginning with the Windows 10 and Windows Server v2004 security baseline this setting has been moved to Security Options\Domain controller: LDAP server channel binding token requirements.
+
+Enabled, always (recommended)
+Enabled, when supported
+Disabled
+
+
+ Block Flash activation in Office documents
+ This policy setting controls whether the Adobe Flash control can be activated by Office documents. Note that activation blocking applies only within Office processes.
+
+If you enable this policy setting, you can choose from three options to control whether and how Flash is blocked from activation:
+
+1. "Block all activation" prevents the Flash control from being loaded, whether directly referenced by the document or indirectly by another embedded object.
+
+2. "Block embedding/linking, allow other activation" prevents the Flash control from being loaded when directly referenced by the document, but does not prevent activation through another object.
+
+3. "Allow all activation" restores Office's default behavior, allowing the Flash control to be activated.
+
+Because this setting is not a true Group Policy setting and "tattoos" the registry, enabling the "Allow all activation" option is the only way to restore default behavior after either of the "Block" options has been applied. We do not recommend configuring this setting to "Disabled," nor to "Not Configured" after it has been enabled.
+
+ Block all activation
+ Block embedding/linking, allow other activation
+ Allow all activation
+ Restrict legacy JScript execution for Office
+ This policy setting controls JScript execution per Security Zone within Internet Explorer and WebBrowser Control (WebOC) for Office applications.
+
+It's important to determine whether legacy JScript is being used to provide business-critical functionality before you enable this setting.
+
+If Enabled, Office applications will not execute legacy JScript for the Internet or Restricted Sites zones and users aren’t notified by the application that legacy JScript execution is restricted. Modern JScript9 will continue to function for all zones.
+
+If Disabled or Not Configured JScript will function without any restrictions.
+
+The values are set in hexadecimal and should be converted prior to changing the setting value. To learn more about Internet Explorer Feature Control Key and the Restrict JScript process-level policy for Windows, please refer to: https://docs.microsoft.com/en-us/previous-versions/windows/internet-explorer/ie-developer/general-info/ee330734(v=vs.85)#restrict-jscript-at-a-process-level
+
+ Configure RPC packet level privacy setting for incoming connections
+
+This policy setting controls whether packet level privacy is enabled for RPC for incoming connections.
+
+By default packet level privacy is enabled for RPC for incoming connections.
+
+If you enable or do not configure this policy setting, packet level privacy is enabled for RPC for incoming connections.
+
+ Manage processing of Queue-specific files (DEPRECATED)
+ Allow all Queue-specfic files
+ Do not allow Queue-specific files
+
+This setting has moved to a new inbox location which can be found at Printers\Manage processing of Queue-specific files.
+
+Manages how Queue-specific files are processed during printer installation. At printer installation time, a vendor-supplied installation application can specify a set of files, of any type, to be associated with a particular print queue. The files are downloaded to each client that connects to the print server.
+
+You can enable this setting to change the default behavior involving queue-specific files. To use this setting, select one of the options below from the "Manage processing of Queue-specific files" box.
+
+If you disable or do not configure this policy setting, the default behavior is "Limit Queue-specific files to Color profiles".
+
+-- "Do not allow Queue-specific files" specifies that no queue-specific files will be allowed/processed during print queue/printer connection installation.
+
+-- "Limit Queue-specific files to Color profiles" specifies that only queue-specific files that adhere to the standard color profile scheme will be allowed. This means entries using the Registry Key CopyFiles\ICM, containing a Directory value of COLOR and supporting mscms.dll as the Module value. "Limit Queue-specific files to Color profiles" is the default behavior.
+
+-- "Allow all Queue-specific files" specifies that all queue-specific files will be allowed/processed during print queue/printer connection installation.
+
+ Limit Queue-specific files to Color profiles
+
+
+ Enable Certificate Padding
+ Enabling this setting will cause the WinVerifyTrust function to perform strict Windows Authenticode signature verification for Portable Executable files (PE files). After you opt in, PE files will be considered "unsigned" if Windows identifies content in them that does not conform to the Authenticode specification. This may impact some installers. If you are using an installer that is impacted, Microsoft recommends using an installer that only extracts content from validated portions of the signed file.
+
+Reference: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2013-3900
+
+
+
+
+
+
+ Configure MrxSmb10 driver
+
+
+ Configure LanmanWorkstation dependencies
+
+
+ Configure NetBT NodeType
+
+
+ Configure LdapEnforceChannelBinding
+
+
+ Block Flash player in Office
+
+
+ Excel:
+ Publisher:
+ PowerPoint:
+ OneNote:
+ Visio:
+ Project:
+ Word:
+ Outlook:
+ Access:
+
+
+ Select the method by which Queue-specific files will be processed.
+ Manage processing of Queue-Specific files:
+
+
+
+
+
+
diff --git a/config/admx/en-US/Sudo.adml b/config/admx/en-US/Sudo.adml
index 0a94650..3ebde3f 100644
--- a/config/admx/en-US/Sudo.adml
+++ b/config/admx/en-US/Sudo.adml
@@ -1,34 +1,34 @@
-
-
-
- enter display name here
- enter description here
-
-
- Configure the behavior of the sudo command
- This policy setting controls use of the sudo.exe command line tool.
-
-If you enable this policy setting, then you may set a maximum allowed mode to run sudo in. This restricts the ways in which users may interact with command-line applications run with sudo. You may pick one of the following modes to allow sudo to run in:
-
-"Disabled": sudo is entirely disabled on this machine. When the user tries to run sudo, sudo will print an error message and exit.
-
-"Force new window": When sudo launches a command line application, it will launch that app in a new console window.
-
-"Disable input": When sudo launches a command line application, it will launch the app in the current console window, but the user will not be able to type input to the command line app. The user may also choose to run sudo in "Force new window" mode.
-
-"Normal": When sudo launches a command line application, it will launch the app in the current console window. The user may also choose to run sudo in "Force new window" or "Disable input" mode.
-
-If you disable this policy or do not configure it, the user will be able to run sudo.exe normally (after enabling the setting in the Settings app).
- Disabled
- Force new window
- Disable input
- Normal
-
-
-
-
- Maximum allowed sudo mode
-
-
-
-
+
+
+
+ enter display name here
+ enter description here
+
+
+ Configure the behavior of the sudo command
+ This policy setting controls use of the sudo.exe command line tool.
+
+If you enable this policy setting, then you may set a maximum allowed mode to run sudo in. This restricts the ways in which users may interact with command-line applications run with sudo. You may pick one of the following modes to allow sudo to run in:
+
+"Disabled": sudo is entirely disabled on this machine. When the user tries to run sudo, sudo will print an error message and exit.
+
+"Force new window": When sudo launches a command line application, it will launch that app in a new console window.
+
+"Disable input": When sudo launches a command line application, it will launch the app in the current console window, but the user will not be able to type input to the command line app. The user may also choose to run sudo in "Force new window" mode.
+
+"Normal": When sudo launches a command line application, it will launch the app in the current console window. The user may also choose to run sudo in "Force new window" or "Disable input" mode.
+
+If you disable this policy or do not configure it, the user will be able to run sudo.exe normally (after enabling the setting in the Settings app).
+ Disabled
+ Force new window
+ Disable input
+ Normal
+
+
+
+
+ Maximum allowed sudo mode
+
+
+
+
diff --git a/config/admx/en-US/UserProxySettings.adml b/config/admx/en-US/UserProxySettings.adml
index 519096b..1c09680 100644
--- a/config/admx/en-US/UserProxySettings.adml
+++ b/config/admx/en-US/UserProxySettings.adml
@@ -1,37 +1,37 @@
-
-
-
-
-
-
- Internet Proxy Settings
- Automatic configuration
- Proxy server
- Disabled
- Enabled
- Enabled
- Disabled
- Configure the automatic proxy configuration settings, including: Checkbox to automatically detect settings Automatic configuration script URL (example: http://proxy.example:8080/proxy.pac). Leave URL blank to disable auto-config script.
- Configure the proxy server settings, including: Checkbox to use a proxy server; proxy server address and port number (example: server:port) Proxy exceptions/bypass list (example: *.microsoft.com;*.windowsazure.com;<local>). Note: Include <local> in the bypass list to bypass the proxy for local addresses.
- ADMX Migrator encountered a string that is not present in the source ADM string table.
- ADMX Migrator encountered a policy that does not have a supportedOn value.
-
-
-
- Automatically detect settings
-
-
-
-
-
- Use a proxy server
-
-
-
-
-
-
-
-
-
+
+
+
+
+
+
+ Internet Proxy Settings
+ Automatic configuration
+ Proxy server
+ Disabled
+ Enabled
+ Enabled
+ Disabled
+ Configure the automatic proxy configuration settings, including: Checkbox to automatically detect settings Automatic configuration script URL (example: http://proxy.example:8080/proxy.pac). Leave URL blank to disable auto-config script.
+ Configure the proxy server settings, including: Checkbox to use a proxy server; proxy server address and port number (example: server:port) Proxy exceptions/bypass list (example: *.microsoft.com;*.windowsazure.com;<local>). Note: Include <local> in the bypass list to bypass the proxy for local addresses.
+ ADMX Migrator encountered a string that is not present in the source ADM string table.
+ ADMX Migrator encountered a policy that does not have a supportedOn value.
+
+
+
+ Automatically detect settings
+
+
+
+
+
+ Use a proxy server
+
+
+
+
+
+
+
+
+
\ No newline at end of file
diff --git a/config/admx/en-US/WindowsDefender.adml b/config/admx/en-US/WindowsDefender.adml
index b5637e1..9577ad8 100644
--- a/config/admx/en-US/WindowsDefender.adml
+++ b/config/admx/en-US/WindowsDefender.adml
@@ -1,1617 +1,1617 @@
-
-enter display name here
-enter description here
-
-
- Microsoft Defender Antivirus
- Endpoint Protection
- Exclusions
- Features
- Device Control
- Microsoft Defender Exploit Guard
- Attack Surface Reduction
- Controlled Folder Access
- Network Protection
- Network Inspection System
- Exclusions
- Quarantine
- Real-time Protection
- Remediation
- Behavioral Network Blocks
- Remote Encryption Protection
- Brute-Force Protection
- Reporting
- Scan
- Security Intelligence Updates
- MAPS
- Threats
- Client Interface
- MpEngine
- Allow antimalware service to startup with normal priority
- This policy setting controls the load priority for the antimalware service. Increasing the load priority will allow for faster service startup, but may impact performance.
-
- If you enable or do not configure this setting, the antimalware service will load as a normal priority task.
-
- If you disable this setting, the antimalware service will load as a low priority task.
-
- Allows Microsoft Defender Antivirus to update and communicate over a metered connection.
-
- Disabled (Default):
- Updates and communications are not allowed over metered connections.
-
- Enabled:
- Allow managed devices to update through metered connections. Data charges may apply.
- Control whether or not exclusions are visible to Local Admins
-
- This policy setting controls whether or not exclusions are visible to Local Admins. For end users (that are not Local Admins) exclusions are not visible, whether or not this setting is enabled.
- Disabled(Default):
- If you disable or do not configure this setting, Local Admins will be able to see exclusions in the Windows Security App or via PowerShell.
-
- Enabled:
- If you enable this setting, Local Admins will no longer be able to see the exclusion list in Windows Security App or via PowerShell.
- Note: Applying this setting will not remove exclusions, it will only prevent them from being visible to Local Admins. This is reflected in Get-MpPreference.
- Control whether exclusions are visible to local users
-
- This policy setting controls whether exclusions are visible to local users on the device.
- Use the policy setting HideExclusionsFromLocalAdmins to hide exclusions from both standard and administrative local users.
- This settings controls whether Network Protection is allowed to be configured into block or audit mode on Windows Server.
-
- Disabled (Default):
- If Not Configured or Disabled, network protection is not allowed to be configured into block or audit mode on Windows Server.
-
- Enabled:
- If Enabled, administrators can control whether Network Protection is allowed to be configured into block or audit mode on Windows Server.
- Note, that this configuration is dependent on the EnableNetworkProtection configuration. If this configuration is false, EnableNetworkProtection will be ignored, otherwise network protection will start on Windows Server depending on the value of EnableNetworkProtection.
- This setting controls datagram processing for network protection.
-
- Disabled (Default):
- If Not Configured or Disabled, datagram processing will be enabled for network protection.
-
- Enabled:
- If Enabled, datagram processing will be disabled for network protection.
- Convert warn verdict to block
-
- Network protection inspects network traffic and determines whether it allows or blocks traffic or displays a warning.
-
- Disabled (Default):
- If Not Configured or Disabled, network protection will display a warning for warn verdicts.
-
- Enabled:
- If this setting is Enabled, network protection blocks network traffic instead of displaying a warning.
- Turn on asynchronous inspection
-
- Control whether network protection can improve performance by switching from real-time inspection to asynchronous inspection.
-
- Disabled (Default):
- If Not Configured or Disabled, asynchronous inspection will not be enabled for network protection.
-
- Enabled:
- If Enabled, switching to asynchronous inspection will be allowed for network protection.
- Turn off Auto Exclusions
-
- Allows an administrator to specify if Automatic Exclusions feature for Server SKUs should be turned off.
-
- Disabled (Default):
- Microsoft Defender will exclude pre-defined list of paths from the scan to improve performance.
-
- Enabled:
- Microsoft Defender will not exclude pre-defined list of paths from scans. This can impact machine performance in some scenarios.
-
- Not configured:
- Same as Disabled.
-
- Turn off Endpoint Protection
- This policy setting turns off Endpoint Protection.
-
- If you enable this policy setting, Endpoint Protection does not run, and computers are not scanned for malware or other potentially unwanted software.
-
- If you disable or do not configure this policy setting, by default Endpoint Protection runs and computers are scanned for malware and other potentially unwanted software.
-
- Turn off Microsoft Defender Antivirus
- This policy setting turns off Microsoft Defender Antivirus.
-
- If you enable this policy setting, Microsoft Defender Antivirus does not run, and will not scan computers for malware or other potentially unwanted software.
-
- If you disable this policy setting, Microsoft Defender Antivirus will run regardless of any other installed antivirus product.
-
- If you do not configure this policy setting, Windows will internally manage Microsoft Defender Antivirus. If you install another antivirus program, Windows automatically disables Microsoft Defender Antivirus. Otherwise, Microsoft Defender Antivirus will scan your computers for malware and other potentially unwanted software.
-
- Enabling or disabling this policy may lead to unexpected or unsupported behavior. It is recommended that you leave this policy setting unconfigured.
- Configure local administrator merge behavior for lists
- This policy setting controls whether or not complex list settings configured by a local administrator are merged with Group Policy settings. This setting applies to lists such as threats and Exclusions.
-
- If you disable or do not configure this setting, unique items defined in Group Policy and in preference settings configured by the local administrator will be merged into the resulting effective policy. In the case of conflicts, Group policy Settings will override preference settings.
-
- If you enable this setting, only items defined by Group Policy will be used in the resulting effective policy. Group Policy settings will override preference settings configured by the local administrator.
- Turn off routine remediation
-
- This policy setting allows you to configure whether Microsoft Defender Antivirus automatically takes action on all detected threats. The action to be taken on a particular threat is determined by the combination of the policy-defined action, user-defined action, and the signature-defined action.
-
- If you enable this policy setting, Microsoft Defender Antivirus does not automatically take action on the detected threats, but prompts users to choose from the actions available for each threat.
-
- If you disable or do not configure this policy setting, Microsoft Defender Antivirus automatically takes action on all detected threats after a nonconfigurable delay of approximately five seconds.
-
- This policy setting allows you to configure whether Endpoint Protection automatically takes action on all detected threats. The action to be taken on a particular threat is determined by the combination of the policy-defined action, user-defined action, and the signature-defined action.
-
- If you enable this policy setting, Endpoint Protection does not automatically take action on the detected threats, but prompts users to choose from the actions available for each threat.
-
- If you disable or do not configure this policy setting, Endpoint Protection automatically takes action on all detected threats after a nonconfigurable delay of approximately five seconds.
-
- Define addresses to bypass proxy server
- This policy, if defined, will prevent antimalware from using the configured proxy server when communicating with the specified IP addresses. The address value should be entered as a valid URL.
-
- If you enable this setting, the proxy server will be bypassed for the specified addresses.
-
- If you disable or do not configure this setting, the proxy server will not be bypassed for the specified addresses.
- Define proxy auto-config (.pac) for connecting to the network
- This policy setting defines the URL of a proxy .pac file that should be used when the client attempts to connect the network for security intelligence updates and MAPS reporting. If the proxy auto-config fails or if there is no proxy auto-config specified, the client will fall back to the alternative options (in order):
- 1. Proxy server (if specified)
- 2. Proxy .pac URL (if specified)
- 3. None
- 4. Internet Explorer proxy settings
- 5. Autodetect
-
- If you enable this setting, the proxy setting will be set to use the specified proxy .pac according to the order specified above.
-
- If you disable or do not configure this setting, the proxy will skip over this fallback step according to the order specified above.
- Define proxy server for connecting to the network
- This policy setting allows you to configure the named proxy that should be used when the client attempts to connect to the network for security intelligence updates and MAPS reporting. If the named proxy fails or if there is no proxy specified, the client will fall back to the alternative options (in order):
- 1. Proxy server (if specified)
- 2. Proxy .pac URL (if specified)
- 3. None
- 4. Internet Explorer proxy settings
- 5. Autodetect
-
- If you enable this setting, the proxy will be set to the specified URL according to the order specified above. The URL should be proceeded with either http:// or https://.
-
- If you disable or do not configure this setting, the proxy will skip over this fallback step according to the order specified above.
-
- Randomize scheduled task times
- This policy setting allows you to configure the randomization of the scheduled scan start time and the scheduled definition update start time.
-
- If you enable or do not configure this policy setting, and did not set a randomization window in the Configure scheduled task time randomization window setting , then randomization will be added between 0-4 hours.
- If you enable or do not configure this policy setting, and set a randomization window in the Configure scheduled task time randomization window setting, the configured randomization window will be used.
- If you disable this policy setting, but configured the scheduled task time randomization window, randomization will not be done.
-
- Configure scheduled task times randomization window
- This policy setting allows you to configure scheduled task scan start time and the scheduled security intelligence update start time window in hours. This setting affects the Randomize scheduled task times configuration.
-
- If you enable this setting, you must pick a randomization window in hours. The possible randomization window interval is between 1 and 23 hours. The randomization interval implemented is between 0 and the configured value.
- When you enable this setting, Randomize scheduled task times settings uses the randomization window specified in this configuration setting.
- If you disable or do not configure this policy setting, Randomize scheduled task times settings will randomize scheduled task times between 0-4 hours.
-
- Allow antimalware service to remain running always
- This policy setting allows you to configure whether or not the antimalware service remains running when antivirus and antispyware security intelligence is disabled. It is recommended that this setting remain disabled.
-
- If you enable this setting, the antimalware service will always remain running even if both antivirus and antispyware security intelligence is disabled.
-
- If you disable or do not configure this setting, the antimalware service will be stopped when both antivirus and antispyware security intelligence is disabled. If the computer is restarted, the service will be started if it is set to Automatic startup. After the service has started, there will be a check to see if antivirus and antispyware security intelligence is enabled. If at least one is enabled, the service will remain running. If both are disabled, the service will be stopped.
- Configure detection for potentially unwanted applications
-
- Enable or disable detection for potentially unwanted applications. You can choose to block, audit, or allow when potentially unwanted software is being downloaded or attempts to install itself on your computer.
-
- Enabled:
- Specify the mode in the Options section:
- -Block: Potentially unwanted software will be blocked.
- -Audit Mode: Potentially unwanted software will not be blocked, however if this feature would have blocked access if it were set to Block, then a record of the event will be in the event logs.
-
- Disabled:
- Potentially unwanted software will not be blocked.
-
- Not configured:
- Same as Disabled.
-
- Define the directory path to copy support log files
- This policy setting allows you to configure the directory path where the support log files would be copied to. The value of this setting should be a valid directory path.
-
- If you enable this setting, the support log files will be copied to the specified support log location path.
-
- If you disable or do not configure this setting, the support logs files will not be copied to any location.
- Extension Exclusions
- This policy setting allows you specify a list of file types that should be excluded from scheduled, custom, and real-time scanning. File types should be added under the Options for this setting. Each entry must be listed as a name value pair, where the name should be a string representation of the file type extension (such as "obj" or "lib"). The value is not used and it is recommended that this be set to 0.
- Path Exclusions
- This policy setting allows you to disable scheduled and real-time scanning for files under the paths specified or for the fully qualified resources specified. Paths should be added under the Options for this setting. Each entry must be listed as a name value pair, where the name should be a string representation of a path or a fully qualified resource name. As an example, a path might be defined as: "c:\Windows" to exclude all files in this directory. A fully qualified resource name might be defined as: "C:\Windows\App.exe". The value is not used and it is recommended that this be set to 0.
- Process Exclusions
- This policy setting allows you to disable real-time scanning for any file opened by any of the specified processes. This policy does not apply to scheduled scans. The process itself will not be excluded. To exclude the process, use the Path exclusion. Processes should be added under the Options for this setting. Each entry must be listed as a name value pair, where the name should be a string representation of the path to the process image. Note that only executables can be excluded. For example, a process might be defined as: "c:\windows\app.exe". The value is not used and it is recommended that this be set to 0.
- Ip Address Exclusions
- Allows an administrator to explicitly disable network packet inspection made by wdnisdrv on a particular set of IP addresses.
- Turn on protocol recognition
- This policy setting allows you to configure protocol recognition for network protection against exploits of known vulnerabilities.
-
- If you enable or do not configure this setting, protocol recognition will be enabled.
-
- If you disable this setting, protocol recognition will be disabled.
- Turn on definition retirement
- This policy setting allows you to configure definition retirement for network protection against exploits of known vulnerabilities. Definition retirement checks to see if a computer has the required security updates necessary to protect it against a particular vulnerability. If the system is not vulnerable to the exploit detected by a definition, then that definition is "retired". If all security intelligence for a given protocal are retired then that protocol is no longer parsed. Enabling this feature helps to improve performance. On a computer that is up-to-date with all the latest security updates, network protection will have no impact on network performance.
-
- If you enable or do not configure this setting, definition retirement will be enabled.
-
- If you disable this setting, definition retirement will be disabled.
- Specify additional definition sets for network traffic inspection
- This policy setting defines additional definition sets to enable for network traffic inspection. Definition set GUIDs should be added under the Options for this setting. Each entry must be listed as a name value pair, where the name should be a string representation of a definition set GUID. As an example, the definition set GUID to enable test security intelligence is defined as: “{b54b6ac9-a737-498e-9120-6616ad3bf590}”. The value is not used and it is recommended that this be set to 0.
- Configure local setting override for the removal of items from Quarantine folder
- This policy setting configures a local override for the configuration of the number of days items should be kept in the Quarantine folder before being removed. This setting can only be set by Group Policy.
-
- If you enable this setting, the local preference setting will take priority over Group Policy.
-
- If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.
- Configure removal of items from Quarantine folder
- This policy setting defines the number of days items should be kept in the Quarantine folder before being removed.
-
- If you enable this setting, items will be removed from the Quarantine folder after the number of days specified.
-
- If you disable or do not configure this setting, items will be kept in the quarantine folder indefinitely and will not be automatically removed.
-
- Turn on script scanning
- This policy setting allows you to configure script scanning.
-
- If you enable or do not configure this setting, script scanning will be enabled.
-
- If you disable this setting, script scanning will be disabled.
-
- Configure real-time protection and Security Intelligence Updates during OOBE
- This policy setting allows you to configure whether real-time protection and Security Intelligence Updates are enabled during OOBE (Out of Box experience).
-
- If you enable this setting, real-time protection and Security Intelligence Updates are enabled during OOBE.
-
- If you either disable or do not configure this policy setting, real-time protection and Security Intelligence Updates during OOBE is not enabled.
-
- Configure performance mode status
- This policy controls Microsoft Defender Antivirus performance mode for Dev Drives.
-
- A Dev Drive is a disk drive optimized for higher performance in software development scenarios. When this policy is Enabled or not configured, Performance mode is turned on for Microsoft Defender Antivirus. In Performance mode, Microsoft Defender Antivirus security checks of content stored on Dev Drives are conducted asynchronously to enhance performance. Performance mode requires the following policies also be enabled: “Enable dev drive”, and “Dev drive filter attach policy”.
-
- If you either Enable or do not configure this policy setting, Performance mode is turned on.
-
- If you Disable this policy setting, Performance mode is turned off and Microsoft Defender Antivirus will protect a Dev Drive in the same way as other drives.
-
- Turn on behavior monitoring
- This policy setting allows you to configure behavior monitoring.
-
- If you enable or do not configure this setting, behavior monitoring will be enabled.
-
- If you disable this setting, behavior monitoring will be disabled.
- Scan all downloaded files and attachments
- This policy setting allows you to configure scanning for all downloaded files and attachments.
-
- If you enable or do not configure this setting, scanning for all downloaded files and attachments will be enabled.
-
- If you disable this setting, scanning for all downloaded files and attachments will be disabled.
- Monitor file and program activity on your computer
- This policy setting allows you to configure monitoring for file and program activity.
-
- If you enable or do not configure this setting, monitoring for file and program activity will be enabled.
-
- If you disable this setting, monitoring for file and program activity will be disabled.
- Turn on raw volume write notifications
- This policy setting controls whether raw volume write notifications are sent to behavior monitoring.
-
- If you enable or do not configure this setting, raw write notifications will be enabled.
-
- If you disable this setting, raw write notifications be disabled.
- Turn off real-time protection
- This policy turns off real-time protection in Microsoft Defender Antivirus.
-
- Real-time protection consists of always-on scanning with file and process behavior monitoring and heuristics. When real-time protection is on, Microsoft Defender Antivirus detects malware and potentially unwanted software that attempts to install itself or run on your device, and prompts you to take action on malware detections.
-
- If you enable this policy setting, real-time protection is turned off.
-
- If you either disable or do not configure this policy setting, real-time protection is turned on.
-
- This policy setting turns off real-time protection prompts for known malware detection.
-
- Endpoint Protection alerts you when malware or potentially unwanted software attempts to install itself or to run on your computer.
-
- If you enable this policy setting, Endpoint Protection will not prompt users to take actions on malware detections.
-
- If you disable or do not configure this policy setting, Endpoint Protection will prompt users to take actions on malware detections.
-
- Turn on process scanning whenever real-time protection is enabled
- This policy setting allows you to configure process scanning when real-time protection is turned on. This helps to catch malware which could start when real-time protection is turned off.
-
- If you enable or do not configure this setting, a process scan will be initiated when real-time protection is turned on.
-
- If you disable this setting, a process scan will not be initiated when real-time protection is turned on.
- Define the maximum size of downloaded files and attachments to be scanned
- This policy setting defines the maximum size (in kilobytes) of downloaded files and attachments that will be scanned.
-
- If you enable this setting, downloaded files and attachments smaller than the size specified will be scanned.
-
- If you disable or do not configure this setting, a default size will be applied.
- Configure local setting override for turn on behavior monitoring
- This policy setting configures a local override for the configuration of behavior monitoring. This setting can only be set by Group Policy.
-
- If you enable this setting, the local preference setting will take priority over Group Policy.
-
- If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.
- Configure local setting override for monitoring file and program activity on your computer
- This policy setting configures a local override for the configuration of monitoring for file and program activity on your computer. This setting can only be set by Group Policy.
-
- If you enable this setting, the local preference setting will take priority over Group Policy.
-
- If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.
- Configure local setting override for scanning all downloaded files and attachments
- This policy setting configures a local override for the configuration of scanning for all downloaded files and attachments. This setting can only be set by Group Policy.
-
- If you enable this setting, the local preference setting will take priority over Group Policy.
-
- If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.
- Configure local setting override to turn on real-time protection
- This policy setting configures a local override for the configuration to turn on real-time protection. This setting can only be set by Group Policy.
-
- If you enable this setting, the local preference setting will take priority over Group Policy.
-
- If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.
- Configure local setting override for monitoring for incoming and outgoing file activity
- This policy setting configures a local override for the configuration of monitoring for incoming and outgoing file activity. This setting can only be set by Group Policy.
-
- If you enable this setting, the local preference setting will take priority over Group Policy.
-
- If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.
- Configure monitoring for incoming and outgoing file and program activity
- This policy setting allows you to configure monitoring for incoming and outgoing files, without having to turn off monitoring entirely. It is recommended for use on servers where there is a lot of incoming and outgoing file activity but for performance reasons need to have scanning disabled for a particular scan direction. The appropriate configuration should be evaluated based on the server role.
-
- Note that this configuration is only honored for NTFS volumes. For any other file system type, full monitoring of file and program activity will be present on those volumes.
-
- The options for this setting are mutually exclusive:
- 0 = Scan incoming and outgoing files (default)
- 1 = Scan incoming files only
- 2 = Scan outgoing files only
-
- Any other value, or if the value does not exist, resolves to the default (0).
-
- If you enable this setting, the specified type of monitoring will be enabled.
-
- If you disable or do not configure this setting, monitoring for incoming and outgoing files will be enabled.
- bi-directional (full on-access)
- scan only incoming (disable on-open)
- scan only outgoing (disable on-close)
- Configure local setting override for the time of day to run a scheduled full scan to complete remediation
- This policy setting configures a local override for the configuration of the time to run a scheduled full scan to complete remediation. This setting can only be set by Group Policy.
-
- If you enable this setting, the local preference setting will take priority over Group Policy.
-
- If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.
- Specify the day of the week to run a scheduled full scan to complete remediation
- This policy setting allows you to specify the day of the week on which to perform a scheduled full scan in order to complete remediation. The scan can also be configured to run every day or to never run at all.
-
- This setting can be configured with the following ordinal number values:
- (0x0) Every Day
- (0x1) Sunday
- (0x2) Monday
- (0x3) Tuesday
- (0x4) Wednesday
- (0x5) Thursday
- (0x6) Friday
- (0x7) Saturday
- (0x8) Never (default)
-
- If you enable this setting, a scheduled full scan to complete remediation will run at the frequency specified.
-
- If you disable or do not configure this setting, a scheduled full scan to complete remediation will run at a default frequency.
- Never
- Every Day
- Sunday
- Monday
- Tuesday
- Wednesday
- Thursday
- Friday
- Saturday
- Specify the time of day to run a scheduled full scan to complete remediation
- This policy setting allows you to specify the time of day at which to perform a scheduled full scan in order to complete remediation. The time value is represented as the number of minutes past midnight (00:00). For example, 120 (0x78) is equivalent to 02:00 AM. The schedule is based on local time on the computer where the scan is executing.
-
- If you enable this setting, a scheduled full scan to complete remediation will run at the time of day specified.
-
- If you disable or do not configure this setting, a scheduled full scan to complete remediation will run at a default time.
- Configure Remote Encryption Protection Mode
-
- Set the mode for Remote Encryption Protection in Microsoft Defender Antivirus, which can detect and block attempts to replace local files with encrypted versions from another device.
-
- Supported settings:
- * 0 - Not configured or Default: Apply defaults, which can vary depending on the antivirus engine version and the platform
- * 1 - Block: Prevent suspicious and malicious behaviors
- * 2 - Audit: Generate EDR detections without blocking
- * 4 - Off: Feature is off with no performance impact
-
- Default
- Block
- Audit
- Off
- Configure Remote Encryption Protection blocking time
-
- Set the maximum time an IP address is blocked by Remote Encryption Protection. After this time, blocked IP addresses will be able to reinitiate connections.
-
- Supported settings:
- * 0 - None: Internal feature logic will determine the actual blocking time
- * Specify other times in 15-minute increments
-
- Configure how aggressively Remote Encryption Protection blocks threats
-
- Set the criteria for when remote encryption preventionprotection blocks IP addresses.
-
- Supported settings:
- *0 - Low: Block only when confidence level is 100% (Default)
- *1 - Medium: Use cloud aggregation and block when confidence level is above 99%
- *2 - High: Use cloud intel and context, and block when confidence level is above 90%
-
- Low
- Medium
- High
- Set exclusions from Remote Encryption Protection
-
- Specify IP addresses, subnets, and domain names to exclude from Remote Encryption Protection. Note that attackers can spoof excluded addresses and names to bypass protection.
-
- Enter each address or subnet on a new line as a name-value pair:
- - Name column: Enter an IP address or subnet name. For example, ""1.1.127.0"" will exclude this IP address from getting blocked.
- - Value column: Enter ""0"" for each item
-
- Configure Brute-Force Protection mode
-
- Set the mode for Brute-Force Protection in Microsoft Defender Antivirus, which can detect and block attempts to forcibly initiate sign in and initiate sessions.
-
- Supported settings:
- * 0 - Not configured or Default: Apply defaults, which can vary depending on the antivirus engine version and the platform
- * 1 - Block: Prevent suspicious and malicious behaviors
- * 2 - Audit: Generate EDR detections without blocking
- * 4 - Off: Feature is off with no performance impact
-
- Default
- Block
- Audit
- Off
- Configure Brute-Force Protection blocking time
-
- Set the maximum time an IP address is blocked by Brute-Force Protection. After this time, blocked IP addresses will be able to sign-in and initiate sessions.
-
- Supported settings:
- * 0 - None: Internal feature logic will determine the actual blocking time
- * Specify other times in 15-minute increments
-
- Configure Brute-Force Protection aggressiveness
-
- Set the criteria for when Brute-Force Protection blocks IP addresses.
-
- Supported settings:
- *0 - Low: Block only when confidence level is 100% (Default)
- *1 - Medium: Use cloud aggregation and block when confidence level is above 99%
- *2 - High: Use cloud intel and context, and block when confidence level is above 90%
-
- Low
- Medium
- High
- Set exclusions from Brute-Force Protection
-
- Specify IP addresses, subnets or workstation names to exclude from Brute-Force Protection. Excluded IP addresses will not be checked for possible brute force activity.
-
- Note that attackers can spoof excluded addresses and names to bypass protection. Ensure the names are unique and unlikely to be guessed by attackers.
-
- Enter each address or subnet on a new line as a name-value pair:
- - Name column: Enter an IP address, subnet name, or workstation name. For example, "1.1.127.0" will exclude this IP address from getting blocked by BFP.
- - Value column: Enter "0" for each item
-
- Configure time out for detections requiring additional action
- This policy setting configures the time in minutes before a detection in the "additional action" state moves to the "cleared" state.
- Configure time out for detections in critically failed state
- This policy setting configures the time in minutes before a detection in the “critically failed” state to moves to either the “additional action” state or the “cleared” state.
- Configure Watson events
- This policy setting allows you to configure whether or not Watson events are sent.
-
- If you enable or do not configure this setting, Watson events will be sent.
-
- If you disable this setting, Watson events will not be sent.
- Configure time out for detections in non-critical failed state
- This policy setting configures the time in minutes before a detection in the "non-critically failed" state moves to the "cleared" state.
- Configure time out for detections in recently remediated state
- This policy setting configures the time in minutes before a detection in the "completed" state moves to the "cleared" state.
- Configure Windows software trace preprocessor components
- This policy configures Windows software trace preprocessor (WPP Software Tracing) components.
- Configure WPP tracing level
- This policy allows you to configure tracing levels for Windows software trace preprocessor (WPP Software Tracing).
- Tracing levels are defined as:
- 1 - Error
- 2 - Warning
- 3 - Info
- 4 - Debug
- Turn off enhanced notifications
-
- Use this policy setting to specify if you want Microsoft Defender Antivirus enhanced notifications to display on clients.
-
- If you disable or do not configure this setting, Microsoft Defender Antivirus enhanced notifications will display on clients.
-
- If you enable this setting, Microsoft Defender Antivirus enhanced notifications will not display on clients.
-
- Configure time interval for service health reports
- This policy setting configures the time interval (in minutes) for the service health reports to be sent from endpoints.
-
- If you disable or do not configure this setting, the default value will be applied. The default value is set at 60 minutes (1 hour).
-
- If you configure this setting to 0, no service health reports will be sent.
-
- The maximum value allowed to be set is 14400 minutes (10 days).
- Configure whether to report Dynamic Signature dropped events
- This policy setting configures whether to report Dynamic Signature dropped events.
-
- If you do not configure this setting, the default value will be applied. The default value is set to disabled (such events are not reported).
- If you configure this setting to enabled, Dynamic Signature dropped events will be reported.
- If you configure this setting to disabled, Dynamic Signature dropped events will not be reported.
- Allow users to pause scan
- This policy setting allows you to manage whether or not end users can pause a scan in progress.
-
- If you enable or do not configure this setting, a new context menu will be added to the task tray icon to allow the user to pause a scan.
-
- If you disable this setting, users will not be able to pause scans.
- Specify the maximum depth to scan archive files
- This policy setting allows you to configure the maximum directory depth level into which archive files such as .ZIP or .CAB are unpacked during scanning. The default directory depth level is 0.
-
- If you enable this setting, archive files will be scanned to the directory depth level specified.
-
- If you disable or do not configure this setting, archive files will be scanned to the default directory depth level.
- Specify the maximum size of archive files to be scanned
- This policy setting allows you to configure the maximum size of archive files such as .ZIP or .CAB that will be scanned. The value represents file size in kilobytes (KB). The default value is 0 and represents no limit to archive size for scanning.
-
- If you enable this setting, archive files less than or equal to the size specified will be scanned.
-
- If you disable or do not configure this setting, archive files will be scanned according to the default value.
- Specify the maximum percentage of CPU utilization during a scan
- This policy setting allows you to configure the maximum percentage CPU utilization permitted during a scan. Valid values for this setting are a percentage represented by the integers 5 to 100. A value of 0 indicates that there should be no throttling of CPU utilization. The default value is 50.
-
- If you enable this setting, CPU utilization will not exceed the percentage specified.
-
- If you disable or do not configure this setting, CPU utilization will not exceed the default value.
- Check for the latest virus and spyware security intelligence before running a scheduled scan
- This policy setting allows you to manage whether a check for new virus and spyware security intelligence will occur before running a scan.
-
- This setting applies to scheduled scans, but it has no effect on scans initiated manually from the user interface or to the ones started from the command line using "mpcmdrun -Scan".
-
- If you enable this setting, a check for new security intelligence will occur before running a scan.
-
- If you disable this setting or do not configure this setting, the scan will start using the existing security intelligence.
- Scan archive files
- This policy setting allows you to configure scans for malicious software and unwanted software in archive files such as .ZIP or .CAB files.
-
- If you enable or do not configure this setting, archive files will be scanned.
-
- If you disable this setting, archive files will not be scanned. However, archives are always scanned during directed scans.
- Turn on catch-up full scan
- This policy setting allows you to configure catch-up scans for scheduled full scans. A catch-up scan is a scan that is initiated because a regularly scheduled scan was missed. Usually these scheduled scans are missed because the computer was turned off at the scheduled time.
-
- If you enable this setting, catch-up scans for scheduled full scans will be turned on. If a computer is offline for two consecutive scheduled scans, a catch-up scan is started the next time someone logs on to the computer. If there is no scheduled scan configured, there will be no catch-up scan run.
-
- If you disable or do not configure this setting, catch-up scans for scheduled full scans will be turned off.
- CPU throttling type
- This policy setting determines whether the maximum percentage CPU utilization permitted during a scan applies only to scheduled scans, or to both scheduled and custom scans (but not real-time protection). The maximum CPU utilization limit is also referred to as CPU throttling, or a CPU usage limit.
-
- The default value for this policy setting is True, which means CPU throttling is applied only to scheduled scans.
-
- If you either enable or do not configure this setting, CPU throttling will apply only to scheduled scans.
-
- If you disable this setting, CPU throttling will apply to scheduled and custom scans.
- Turn on catch-up quick scan
- This policy setting allows you to configure catch-up scans for scheduled quick scans. A catch-up scan is a scan that is initiated because a regularly scheduled scan was missed. Usually these scheduled scans are missed because the computer was turned off at the scheduled time.
-
- If you enable this setting, catch-up scans for scheduled quick scans will be turned on. If a computer is offline for two consecutive scheduled scans, a catch-up scan is started the next time someone logs on to the computer. If there is no scheduled scan configured, there will be no catch-up scan run.
-
- If you disable or do not configure this setting, catch-up scans for scheduled quick scans will be turned off.
- Trigger a quick scan after X days without any scans
- This policy setting defines the number of days that can pass since the last scan before an aggresive catchup quick scan is automatically triggered. The value represents the number of days that can pass without any scans being performed before an agressive quick scan will be triggered.
-
- Valid values range from 7 to 60 days. If not configured, aggressive quick scans will be disabled. By default, the value is set to 25 days when enabled.
- Turn on e-mail scanning
- This policy setting allows you to configure e-mail scanning. When e-mail scanning is enabled, the engine will parse the mailbox and mail files, according to their specific format, in order to analyze the mail bodies and attachments. Several e-mail formats are currently supported, for example: pst (Outlook), dbx, mbx, mime (Outlook Express), binhex (Mac). Email scanning is not supported on modern email clients.
-
- If you enable this setting, e-mail scanning will be enabled.
-
- If you disable or do not configure this setting, e-mail scanning will be disabled.
- Turn on heuristics
- This policy setting allows you to configure heuristics. Suspicious detections will be suppressed right before reporting to the engine client. Turning off heuristics will reduce the capability to flag new threats. It is recommended that you do not turn off heuristics.
-
- If you enable or do not configure this setting, heuristics will be enabled.
-
- If you disable this setting, heuristics will be disabled.
- Scan packed executables
- This policy setting allows you to configure scanning for packed executables. It is recommended that this type of scanning remain enabled.
-
- If you enable or do not configure this setting, packed executables will be scanned.
-
- If you disable this setting, packed executables will not be scanned.
- Scan removable drives
- This policy setting allows you to manage whether or not to scan for malicious software and unwanted software in the contents of removable drives, such as USB flash drives, when running a full scan.
-
- If you enable this setting, removable drives will be scanned during any type of scan.
-
- If you disable or do not configure this setting, removable drives will not be scanned during a full scan. Removable drives may still be scanned during quick scan and custom scan.
- Turn on reparse point scanning
- This policy setting allows you to configure reparse point scanning. If you allow reparse points to be scanned, there is a possible risk of recursion. However, the engine supports following reparse points to a maximum depth so at worst scanning could be slowed. Reparse point scanning is disabled by default and this is the recommended state for this functionality.
-
- If you enable this setting, reparse point scanning will be enabled.
-
- If you disable or do not configure this setting, reparse point scanning will be disabled.
- Create a system restore point
- This policy setting allows you to create a system restore point on the computer on a daily basis prior to cleaning.
-
- If you enable this setting, a system restore point will be created.
-
- If you disable or do not configure this setting, a system restore point will not be created.
- Run full scan on mapped network drives
- This policy setting allows you to configure scanning mapped network drives.
-
- If you enable this setting, mapped network drives will be scanned.
-
- If you disable or do not configure this setting, mapped network drives will not be scanned.
- Configure scanning of network files
- This policy setting allows the scanning of network files using on access protection. The default is enabled. Recommended to remain enabled in most cases.
-
- If you enable or do not configure this setting, network files will be scanned.
-
- If you disable this setting, network files will not be scanned.
- Configure local setting override for maximum percentage of CPU utilization
- This policy setting configures a local override for the configuration of maximum percentage of CPU utilization during scan. This setting can only be set by Group Policy.
-
- If you enable this setting, the local preference setting will take priority over Group Policy.
-
- If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.
- Configure local setting override for the scan type to use for a scheduled scan
- This policy setting configures a local override for the configuration of the scan type to use during a scheduled scan. This setting can only be set by Group Policy.
-
- If you enable this setting, the local preference setting will take priority over Group Policy.
-
- If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.
- Configure local setting override for schedule scan day
- This policy setting configures a local override for the configuration of scheduled scan day. This setting can only be set by Group Policy.
-
- If you enable this setting, the local preference setting will take priority over Group Policy.
-
- If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.
- Configure local setting override for scheduled quick scan time
- This policy setting configures a local override for the configuration of scheduled quick scan time. This setting can only be set by Group Policy.
-
- If you enable this setting, the local preference setting will take priority over Group Policy.
-
- If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.
- Configure local setting override for scheduled scan time
- This policy setting configures a local override for the configuration of scheduled scan time. This setting can only be set by Group Policy.
-
- If you enable this setting, the local preference setting will take priority over Group Policy.
-
- If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.
- Turn on removal of items from scan history folder
- This policy setting defines the number of days items should be kept in the scan history folder before being permanently removed. The value represents the number of days to keep items in the folder. If set to zero, items will be kept forever and will not be automatically removed. By default, the value is set to 30 days.
-
- If you enable this setting, items will be removed from the scan history folder after the number of days specified.
-
- If you disable or do not configure this setting, items will be kept in the scan history folder for the default number of days.
- Specify the interval to run quick scans per day
- This policy setting allows you to specify an interval at which to perform a quick scan. The time value is represented as the number of hours between quick scans. Valid values range from 1 (every hour) to 24 (once per day). If set to zero, interval quick scans will not occur. By default, this setting is set to 0.
-
- If you enable this setting, a quick scan will run at the interval specified.
-
- If you disable or do not configure this setting, quick scan controlled by this config will not be run.
- Start the scheduled scan only when computer is on but not in use
- This policy setting allows you to configure scheduled scans to start only when your computer is on but not in use.
-
- If you enable or do not configure this setting, scheduled scans will only run when the computer is on but not in use.
-
- If you disable this setting, scheduled scans will run at the scheduled time.
- Specify the scan type to use for a scheduled scan
- This policy setting allows you to specify the scan type to use during a scheduled scan. Scan type options are:
- 1 = Quick Scan (default)
- 2 = Full Scan
-
- If you enable this setting, the scan type will be set to the specified value.
-
- If you disable or do not configure this setting, the default scan type will used.
- Quick scan
- Full system scan
- Specify the day of the week to run a scheduled scan
- This policy setting allows you to specify the day of the week on which to perform a scheduled scan. The scan can also be configured to run every day or to never run at all.
-
- This setting can be configured with the following ordinal number values:
- (0x0) Every Day
- (0x1) Sunday
- (0x2) Monday
- (0x3) Tuesday
- (0x4) Wednesday
- (0x5) Thursday
- (0x6) Friday
- (0x7) Saturday
- (0x8) Never (default)
-
- If you enable this setting, a scheduled scan will run at the frequency specified.
-
- If you disable or do not configure this setting, a scheduled scan will run at a default frequency.
- Never
- Every Day
- Sunday
- Monday
- Tuesday
- Wednesday
- Thursday
- Friday
- Saturday
- Specify the time for a daily quick scan
- This policy setting allows you to specify the time of day at which to perform a daily quick scan. The time value is represented as the number of minutes past midnight (00:00). For example, 120 (0x78) is equivalent to 02:00 AM. By default, this setting is set to disabled. The schedule is based on local time on the computer where the scan is executing.
-
- If you enable this setting, a daily quick scan will run at the time of day specified.
-
- If you disable or do not configure this setting, daily quick scan controlled by this config will not be run.
- Specify the time of day to run a scheduled scan
- This policy setting allows you to specify the time of day at which to perform a scheduled scan. The time value is represented as the number of minutes past midnight (00:00). For example, 120 (0x78) is equivalent to 02:00 AM. By default, this setting is set to a time value of 2:00 AM. The schedule is based on local time on the computer where the scan is executing.
-
- If you enable this setting, a scheduled scan will run at the time of day specified.
-
- If you disable or do not configure this setting, a scheduled scan will run at a default time.
- Define the number of days after which a catch-up scan is forced
-
- This policy setting allows you to define the number of consecutive scheduled scans that can be missed after which a catch-up scan will be forced. By default, the value of this setting is 2 consecutive scheduled scans.
-
- If you enable this setting, a catch-up scan will occur after the specified number consecutive missed scheduled scans.
-
- If you disable or do not configure this setting, a catch-up scan will occur after the 2 consecutive missed scheduled scans.
- Configure low CPU priority for scheduled scans
-
- This policy setting allows you to enable or disable low CPU priority for scheduled scans.
-
- If you enable this setting, low CPU priority will be used during scheduled scans.
-
- If you disable or do not configure this setting, not changes will be made to CPU priority for scheduled scans.
-
-
- Scan excluded files and directories during quick scans
-
- This policy setting allows you to scan excluded files and directories during quick scans.
-
- If you set this policy setting to 1, all files and directories that are excluded from real-time protection using contextual exclusions are scanned during a quick scan.
-
- If you set this policy to 0 or do not configure it, exclusions are not scanned during quick scans.
-
- 0
- 1
-
- Define the number of days before spyware security intelligence is considered out of date
- This policy setting allows you to define the number of days that must pass before spyware security intelligence is considered out of date. If security intelligence is determined to be out of date, this state may trigger several additional actions, including falling back to an alternative update source or displaying a warning icon in the user interface. By default, this value is set to 7 days.
-
- If you enable this setting, spyware security intelligence will be considered out of date after the number of days specified have passed without an update.
-
- If you disable or do not configure this setting, spyware security intelligence will be considered out of date after the default number of days have passed without an update.
- Define the number of days before virus security intelligence is considered out of date
- This policy setting allows you to define the number of days that must pass before virus security intelligence is considered out of date. If security intelligence is determined to be out of date, this state may trigger several additional actions, including falling back to an alternative update source or displaying a warning icon in the user interface. By default, this value is set to 7 days.
-
- If you enable this setting, virus security intelligence will be considered out of date after the number of days specified have passed without an update.
-
- If you disable or do not configure this setting, virus security intelligence will be considered out of date after the default number of days have passed without an update.
- Define file shares for downloading security intelligence updates
- This policy setting allows you to configure UNC file share sources for downloading security intelligence updates. Sources will be contacted in the order specified. The value of this setting should be entered as a pipe-separated string enumerating the security intelligence update sources. For example: "{\\unc1 | \\unc2 }". The list is empty by default.
-
- If you enable this setting, the specified sources will be contacted for security intelligence updates. Once security intelligence updates have been successfully downloaded from one specified source, the remaining sources in the list will not be contacted.
-
- If you disable or do not configure this setting, the list will remain empty by default and no sources will be contacted.
- Define security intelligence location for VDI clients.
- This policy setting allows you to define the security intelligence location for VDI-configured computers.
-
- If you disable or do not configure this setting, security intelligence will be referred from the default local source.
- Configure security intelligence updates according to the scheduler for VDI clients.
- This policy setting allows you to configure security intelligence updates according to the scheduler for VDI-configured computers. It is used together with the shared security intelligence location (SharedSignaturesLocation).
-
- If you enable this policy setting and configure SharedSignaturesLocation, updates from the configured location occur only at the previously configured scheduled update time.
-
- If you either disable or do not configure this policy setting, updates occur whenever a new security intelligence update is detected at the location that is specified by SharedSignaturesLocation.
-
- Turn on scan after security intelligence update
- This policy setting allows you to configure the automatic scan which starts after a security intelligence update has occurred.
-
- If you enable or do not configure this setting, a scan will start following a security intelligence update.
-
- If you disable this setting, a scan will not start following a security intelligence update.
- Allow security intelligence updates when running on battery power
- This policy setting allows you to configure security intelligence updates when the computer is running on battery power.
-
- If you enable or do not configure this setting, security intelligence updates will occur as usual regardless of power state.
-
- If you disable this setting, security intelligence updates will be turned off while the computer is running on battery power.
- Initiate security intelligence update on startup
- This policy setting allows you to configure security intelligence updates on startup when there is no antimalware engine present.
-
- If you enable or do not configure this setting, security intelligence updates will be initiated on startup when there is no antimalware engine present.
-
- If you disable this setting, security intelligence updates will not be initiated on startup when there is no antimalware engine present.
- Define the order of sources for downloading security intelligence updates
- This policy setting allows you to define the order in which different security intelligence update sources should be contacted. The value of this setting should be entered as a pipe-separated string enumerating the security intelligence update sources in order. Possible values are: “InternalDefinitionUpdateServer”, “MicrosoftUpdateServer”, “MMPC”, and “FileShares”
-
- For example: { InternalDefinitionUpdateServer | MicrosoftUpdateServer | MMPC }
-
- If you enable this setting, security intelligence update sources will be contacted in the order specified. Once security intelligence updates have been successfully downloaded from one specified source, the remaining sources in the list will not be contacted.
-
- If you disable or do not configure this setting, security intelligence update sources will be contacted in a default order.
- Allow security intelligence updates from Microsoft Update
- This policy setting allows you to enable download of security intelligence updates from Microsoft Update even if the Automatic Updates default server is configured to another download source such as Windows Update.
-
- If you enable this setting, security intelligence updates will be downloaded from Microsoft Update.
-
- If you disable or do not configure this setting, security intelligence updates will be downloaded from the configured download source.
- Allow real-time security intelligence updates based on reports to Microsoft MAPS
- This policy setting allows you to enable real-time security intelligence updates in response to reports sent to Microsoft MAPS. If the service reports a file as an unknown and Microsoft MAPS finds that the latest security intelligence update has security intelligence for a threat involving that file, the service will receive all of the latest security intelligence for that threat immediately. You must have configured your computer to join Microsoft MAPS for this functionality to work.
-
- If you enable or do not configure this setting, real-time security intelligence updates will be enabled.
-
- If you disable this setting, real-time security intelligence updates will disabled.
- Specify the day of the week to check for security intelligence updates
- This policy setting allows you to specify the day of the week on which to check for security intelligence updates. The check can also be configured to run every day or to never run at all.
-
- This setting can be configured with the following ordinal number values:
- (0x0) Every Day (default)
- (0x1) Sunday
- (0x2) Monday
- (0x3) Tuesday
- (0x4) Wednesday
- (0x5) Thursday
- (0x6) Friday
- (0x7) Saturday
- (0x8) Never
-
- If you enable this setting, the check for security intelligence updates will occur at the frequency specified.
-
- If you disable or do not configure this setting, the check for security intelligence updates will occur at a default frequency.
- Never
- Every Day
- Sunday
- Monday
- Tuesday
- Wednesday
- Thursday
- Friday
- Saturday
- Specify the time to check for security intelligence updates
- This policy setting allows you to specify the time of day at which to check for security intelligence updates. The time value is represented as the number of minutes past midnight (00:00). For example, 120 (0x78) is equivalent to 02:00 AM. By default this setting is configured to check for security intelligence updates 15 minutes before the scheduled scan time. The schedule is based on local time on the computer where the check is occurring.
-
- If you enable this setting, the check for security intelligence updates will occur at the time of day specified.
-
- If you disable or do not configure this setting, the check for security intelligence updates will occur at the default time.
- Allow notifications to disable security intelligence based reports to Microsoft MAPS
- This policy setting allows you to configure the antimalware service to receive notifications to disable individual security intelligence in response to reports it sends to Microsoft MAPS. Microsoft MAPS uses these notifications to disable security intelligence that are causing false positive reports. You must have configured your computer to join Microsoft MAPS for this functionality to work.
-
- If you enable this setting or do not configure, the antimalware service will receive notifications to disable security intelligence.
-
- If you disable this setting, the antimalware service will not receive notifications to disable security intelligence.
- Define the number of days after which a catch-up security intelligence update is required
- This policy setting allows you to define the number of days after which a catch-up security intelligence update will be required. By default, the value of this setting is 1 day.
-
- If you enable this setting, a catch-up security intelligence update will occur after the specified number of days.
-
- If you disable or do not configure this setting, a catch-up security intelligence update will be required after the default number of days.
- Specify the interval for expiry notification
-
- This policy setting allows you to specify an interval(in days) for expiry notification.
- If a signature expiry or platform expiry is impending, this value tells how soon AM UI will notify customers.
-
- Value should be greater than zero for the policy to be active.
-
- Specify the interval to check for security intelligence updates
- This policy setting allows you to specify an interval at which to check for security intelligence updates. The time value is represented as the number of hours between update checks. Valid values range from 1 (every hour) to 24 (once per day).
-
- If you enable this setting, checks for security intelligence updates will occur at the interval specified.
-
- If you disable or do not configure this setting, checks for security intelligence updates will occur at the default interval.
- Check for the latest virus and spyware security intelligence on startup
- This policy setting allows you to manage whether a check for new virus and spyware security intelligence will occur immediately after service startup.
-
- If you enable this setting, a check for new security intelligence will occur after service startup.
-
- If you disable this setting or do not configure this setting, a check for new security intelligence will not occur after service startup.
- Configure the 'Block at First Sight' feature
- This feature ensures the device checks in real time with the Microsoft Active Protection Service (MAPS) before allowing certain content to be run or accessed. If this feature is disabled, the check will not occur, which will lower the protection state of the device.
- Enabled – The Block at First Sight setting is turned on.
- Disabled – The Block at First Sight setting is turned off.
-
- This feature requires these Group Policy settings to be set as follows:
- MAPS -> The “Join Microsoft MAPS” must be enabled or the “Block at First Sight” feature will not function.
- MAPS -> The “Send file samples when further analysis is required” should be set to 1 (Send safe samples) or 3 (Send all samples). Setting to 0 (Always Prompt) will lower the protection state of the device. Setting to 2 (Never send) means the “Block at First Sight” feature will not function.
- Real-time Protection -> The “Scan all downloaded files and attachments” policy must be enabled or the “Block at First Sight” feature will not function.
- Real-time Protection -> Do not enable the “Turn off real-time protection” policy or the “Block at First Sight” feature will not function.
- Configure local setting override for reporting to Microsoft MAPS
- This policy setting configures a local override for the configuration to join Microsoft MAPS. This setting can only be set by Group Policy.
-
- If you enable this setting, the local preference setting will take priority over Group Policy.
-
- If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.
- Send file samples when further analysis is required
-
- This policy setting configures behaviour of samples submission when opt-in for MAPS telemetry is set.
-
- Possible options are:
- (0x0) Always prompt
- (0x1) Send safe samples automatically
- (0x2) Never send
- (0x3) Send all samples automatically
-
-
- Always prompt
- Send safe samples
- Never send
- Send all samples
-
- Join Microsoft MAPS
- This policy setting allows you to join Microsoft MAPS. Microsoft MAPS is the online community that helps you choose how to respond to potential threats. The community also helps stop the spread of new malicious software infections.
-
- You can choose to send basic or additional information about detected software. Additional information helps Microsoft create new security intelligence and help it to protect your computer. This information can include things like location of detected items on your computer if harmful software was removed. The information will be automatically collected and sent. In some instances, personal information might unintentionally be sent to Microsoft. However, Microsoft will not use this information to identify you or contact you.
-
- Possible options are:
- (0x0) Disabled (default)
- (0x1) Basic membership
- (0x2) Advanced membership
-
- Basic membership will send basic information to Microsoft about software that has been detected, including where the software came from, the actions that you apply or that are applied automatically, and whether the actions were successful.
-
- Advanced membership, in addition to basic information, will send more information to Microsoft about malicious software, spyware, and potentially unwanted software, including the location of the software, file names, how the software operates, and how it has impacted your computer.
-
- If you enable this setting, you will join Microsoft MAPS with the membership specified.
-
- If you disable or do not configure this setting, you will not join Microsoft MAPS.
-
- In Windows 10, Basic membership is no longer available, so setting the value to 1 or 2 enrolls the device into Advanced membership.
- Disabled
- Basic MAPS
- Advanced MAPS
- Specify threats upon which default action should not be taken when detected
- This policy setting customize which remediation action will be taken for each listed Threat ID when it is detected during a scan. Threats should be added under the Options for this setting. Each entry must be listed as a name value pair. The name defines a valid Threat ID, while the value contains the action ID for the remediation action that should be taken.
-
- Valid remediation action values are:
- 2 = Quarantine
- 3 = Remove
- 6 = Ignore
- Specify threat alert levels at which default action should not be taken when detected
- This policy setting allows you to customize which automatic remediation action will be taken for each threat alert level.Threat alert levels should be added under the Options for this setting. Each entry must be listed as a name value pair. The name defines a threat alert level. The value contains the action ID for the remediation action that should be taken.
-
- Valid threat alert levels are:
- 1 = Low
- 2 = Medium
- 4 = High
- 5 = Severe
-
- Valid remediation action values are:
- 2 = Quarantine
- 3 = Remove
- 6 = Ignore
- Enable headless UI mode
-
- This policy setting allows you to configure whether or not to display AM UI to the users.
- If you enable this setting AM UI won't be available to users.
-
- Suppresses reboot notifications
-
- This policy setting allows user to supress reboot notifications in UI only mode (for cases where UI can't be in lockdown mode).
-
- If you enable this setting AM UI won't show reboot notifications.
-
- Suppress all notifications
- Use this policy setting to specify if you want Microsoft Defender Antivirus notifications to display on clients.
- If you disable or do not configure this setting, Microsoft Defender Antivirus notifications will display on clients.
-
- If you enable this setting, Microsoft Defender Antivirus notifications will not display on clients.
-
- Select cloud protection level
-
- This policy setting determines how aggressive Microsoft Defender Antivirus will be in blocking and scanning suspicious files.
-
- If this setting is on, Microsoft Defender Antivirus will be more aggressive when identifying suspicious files to block and scan; otherwise, it will be less aggressive and therefore block and scan with less frequency.
-
- For more information about specific values that are supported, see the Microsoft Defender Antivirus documentation site.
-
- Note: This feature requires the "Join Microsoft MAPS" setting enabled in order to function.
-
- Possible options are:
- (0x0) Default Microsoft Defender Antivirus blocking level
- (0x1) Moderate Microsoft Defender Antivirus blocking level, delivers verdict only for high confidence detections
- (0x2) High blocking level - aggressively block unknowns while optimizing client performance (greater chance of false positives)
- (0x4) High+ blocking level – aggressively block unknowns and apply additional protection measures (may impact client performance)
- (0x6) Zero tolerance blocking level – block all unknown executables
-
- Default blocking level
- Moderate blocking level
- High blocking level
- High+ blocking level
- Zero tolerance blocking level
- Configure extended cloud check
-
- This feature allows Microsoft Defender Antivirus to block a suspicious file for up to 60 seconds, and scan it in the cloud to make sure it's safe.
-
- The typical cloud check timeout is 10 seconds. To enable the extended cloud check feature, specify the extended time in seconds, up to an additional 50 seconds.
-
- For example, if the desired timeout is 60 seconds, specify 50 seconds in this setting, which will enable the extended cloud check feature, and will raise the total time to 60 seconds.
-
- Note: This feature depends on three other MAPS settings - "Configure the 'Block at First Sight' feature; "Join Microsoft MAPS"; "Send file samples when further analysis is required" all need to be enabled.
-
- Enable file hash computation feature
-
- Enable or disable file hash computation feature.
-
- Enabled:
- When this feature is enabled Microsoft Defender will compute hash value for files it scans.
-
- Disabled:
- File hash value is not computed
-
- Not configured:
- Same as Disabled.
-
- Prevent users and apps from accessing dangerous websites
-
- Enable or disable Microsoft Defender Exploit Guard network protection to prevent employees from using any application to access dangerous domains that may host phishing scams, exploit-hosting sites, and other malicious content on the Internet.
-
- Enabled:
- Specify the mode in the Options section:
- -Block: Users and applications will not be able to access dangerous domains
- -Audit Mode: Users and applications can connect to dangerous domains, however if this feature would have blocked access if it were set to Block, then a record of the event will be in the event logs.
-
- Disabled:
- Users and applications will not be blocked from connecting to dangerous domains.
-
- Not configured:
- Same as Disabled.
-
- Exclude files and paths from Attack Surface Reduction Rules
-
- Exclude files and paths from Attack Surface Reduction (ASR) rules.
-
- Enabled:
- Specify the folders or files and resources that should be excluded from ASR rules in the Options section.
- Enter each rule on a new line as a name-value pair:
- - Name column: Enter a folder path or a fully qualified resource name. For example, ""C:\Windows"" will exclude all files in that directory. ""C:\Windows\App.exe"" will exclude only that specific file in that specific folder
- - Value column: Enter ""0"" for each item
-
- Disabled:
- No exclusions will be applied to the ASR rules.
-
- Not configured:
- Same as Disabled.
-
- You can configure ASR rules in the Configure Attack Surface Reduction rules GP setting.
-
- Apply a list of exclusions to specific attack surface reduction (ASR) rulesd
-
- This policy allows an administrator to specify a list of exclusions for specific ASR rules.
- Each entry is a name-value pair. The key indicates the rule GUID, and the value is a set of full paths separated by the > character, indicating the exclusions for that particular ASR rule.
-
- NOTE: The GUID is a KEY, not a value.
-
- Example:
- KEY: "{75668C1F-73B5-4CF0-BB93-3ECF5DB7C484}"
- VALUE: "C:\Notepad.exe>c:\regedit.exe>C:\SomeFolder\test.exe"
-
- Configure Attack Surface Reduction rules
-
- Set the state for each Attack Surface Reduction (ASR) rule.
-
- After enabling this setting, you can set each rule to the following in the Options section:
- - Block: the rule will be applied
- - Audit Mode: if the rule would normally cause an event, then it will be recorded (although the rule will not actually be applied)
- - Off: the rule will not be applied
- - Not Configured: the rule is enabled with default values
- - Warn: the rule will be applied and the end-user will have the option to bypass the block
-
- Unless the ASR rule is disabled, a subsample of audit events are collected for ASR rules will the value of not configured.
-
- Enabled:
- Specify the state for each ASR rule under the Options section for this setting.
- Enter each rule on a new line as a name-value pair:
- - Name column: Enter a valid ASR rule ID
- - Value column: Enter the status ID that relates to state you want to specify for the associated rule
-
- The following status IDs are permitted under the value column:
- - 1 (Block)
- - 0 (Off)
- - 2 (Audit)
- - 5 (Not Configured)
- - 6 (Warn)
-
-
- Example:
- xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx 0
- xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx 1
- xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx 2
-
- Disabled:
- No ASR rules will be configured.
-
- Not configured:
- Same as Disabled.
-
- You can exclude folders or files in the ""Exclude files and paths from Attack Surface Reduction Rules"" GP setting.
-
- Configure Controlled folder access
-
- Enable or disable controlled folder access for untrusted applications. You can choose to block, audit, or allow attempts by untrusted apps to:
- - Modify or delete files in protected folders, such as the Documents folder
- - Write to disk sectors
-
- You can also choose to only block or audit writes to disk sectors while still allowing the modification or deletion of files in protected folders.
-
- Microsoft Defender Antivirus automatically determines which applications can be trusted. You can add additional trusted applications in the Configure allowed applications GP setting.
- Default system folders are automatically protected, but you can add folders in the Configure protected folders GP setting.
-
- Block:
- The following will be blocked:
- - Attempts by untrusted apps to modify or delete files in protected folders
- - Attempts by untrusted apps to write to disk sectors
- The Windows event log will record these blocks under Applications and Services Logs > Microsoft > Windows > Windows Defender > Operational > ID 1123.
-
-
- Disabled:
- The following will not be blocked and will be allowed to run:
- - Attempts by untrusted apps to modify or delete files in protected folders
- - Attempts by untrusted apps to write to disk sectors
- These attempts will not be recorded in the Windows event log.
-
-
- Audit Mode:
- The following will not be blocked and will be allowed to run:
- - Attempts by untrusted apps to modify or delete files in protected folders
- - Attempts by untrusted apps to write to disk sectors
- The Windows event log will record these attempts under Applications and Services Logs > Microsoft > Windows > Windows Defender > Operational > ID 1124.
-
-
- Block disk modification only:
- The following will be blocked:
- - Attempts by untrusted apps to write to disk sectors
- The Windows event log will record these attempts under Applications and Services Logs > Microsoft > Windows > Windows Defender > Operational > ID 1123.
-
- The following will not be blocked and will be allowed to run:
- - Attempts by untrusted apps to modify or delete files in protected folders
- These attempts will not be recorded in the Windows event log.
-
-
- Audit disk modification only:
- The following will not be blocked and will be allowed to run:
- - Attempts by untrusted apps to write to disk sectors
- - Attempts by untrusted apps to modify or delete files in protected folders
- Only attempts to write to protected disk sectors will be recorded in the Windows event log (under Applications and Services Logs > Microsoft > Windows > Windows Defender > Operational > ID 1124).
- Attempts to modify or delete files in protected folders will not be recorded.
-
- Not configured:
- Same as Disabled.
-
- Disable (Default)
- Block
- Audit Mode
- Block disk modification only
- Audit disk modification only
- Configure allowed applications
-
- Add additional applications that should be considered "trusted" by controlled folder access.
-
- These applications are allowed to modify or delete files in controlled folder access folders.
-
- Microsoft Defender Antivirus automatically determines which applications should be trusted. You can configure this setting to add additional applications.
-
- Enabled:
- Specify additional allowed applications in the Options section..
-
- Disabled:
- No additional applications will be added to the trusted list.
-
- Not configured:
- Same as Disabled.
-
- You can enable controlled folder access in the Configure controlled folder access GP setting.
-
- Default system folders are automatically guarded, but you can add folders in the configure protected folders GP setting.
-
- Configure protected folders
-
- Specify additional folders that should be guarded by the Controlled folder access feature.
-
- Files in these folders cannot be modified or deleted by untrusted applications.
-
- Default system folders are automatically protected. You can configure this setting to add additional folders.
- The list of default system folders that are protected is shown in Windows Security.
-
- Enabled:
- Specify additional folders that should be protected in the Options section.
-
- Disabled:
- No additional folders will be protected.
-
- Not configured:
- Same as Disabled.
-
- You can enable controlled folder access in the Configure controlled folder access GP setting.
-
- Microsoft Defender Antivirus automatically determines which applications can be trusted. You can add additional trusted applications in the Configure allowed applications GP setting.
-
- Define device control policy groups
-
- Please follow the device control policy groups xml schema to fill out the policy groups data.
- Alternatively you could use a file path containing the XML groups data.
-
- Define device control policy rules
-
- Please follow the device control policy rules xml schema to fill out the policy rules data.
- Alternatively you could use a file path containing the XML rules data.
-
- Select the channel for Microsoft Defender monthly platform updates
- Enable this policy to specify when devices receive Microsoft Defender platform updates during the monthly gradual rollout.
-
- Beta Channel: Devices set to this channel will be the first to receive new updates. Select Beta Channel to participate in identifying and reporting issues to Microsoft. Devices in the Windows Insider Program are subscribed to this channel by default. For use in (manual) test environments only and a limited number of devices.
- Current Channel (Preview): Devices set to this channel will be offered updates earliest during the monthly gradual release cycle. Suggested for pre-production/validation environments.
- Current Channel (Staged): Devices will be offered updates after the monthly gradual release cycle. Suggested to apply to a small, representative part of your production population (~10%).
- Current Channel (Broad): Devices will be offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in your production population (~10-100%).
- Critical - Time delay: Devices will be offered updates with a 48-hour delay. Suggested for critical environments only.
-
- If you disable or do not configure this policy, the device will stay up to date automatically during the gradual release cycle. Suitable for most devices.
-
- Select the channel for Microsoft Defender monthly engine updates
- Enable this policy to specify when devices receive Microsoft Defender engine updates during the monthly gradual rollout.
-
- Beta Channel: Devices set to this channel will be the first to receive new updates. Select Beta Channel to participate in identifying and reporting issues to Microsoft. Devices in the Windows Insider Program are subscribed to this channel by default. For use in (manual) test environments only and a limited number of devices.
- Current Channel (Preview): Devices set to this channel will be offered updates earliest during the monthly gradual release cycle. Suggested for pre-production/validation environments.
- Current Channel (Staged): Devices will be offered updates after the monthly gradual release cycle. Suggested to apply to a small, representative part of your production population (~10%).
- Current Channel (Broad): Devices will be offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in your production population (~10-100%).
- Critical - Time delay: Devices will be offered updates with a 48-hour delay. Suggested for critical environments only.
-
- If you disable or do not configure this policy, the device will stay up to date automatically during the gradual release cycle. Suitable for most devices.
-
- Select the channel for Microsoft Defender daily security intelligence updates
- Enable this policy to specify when devices receive Microsoft Defender security intelligence updates during the daily gradual rollout.
-
- Current Channel (Staged): Devices will be offered updates after the release cycle. Suggested to apply to a small, representative part of production population (~10%).
- Current Channel (Broad): Devices will be offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in your production population (~10-100%).
- Critical - Time delay: Devices will be offered updates with a 48-hour delay. Suggested for critical environments only.
-
- If you disable or do not configure this policy, the device will stay up to date automatically during the daily release cycle. Suitable for most devices.
-
- Beta Channel
- Current Channel (Preview)
- Current Channel (Staged)
- Current Channel (Broad)
- Critical - Time delay
- Disable gradual rollout of Microsoft Defender updates.
- Enable this policy to disable gradual rollout of Defender updates.
-
- Current Channel (Broad): Devices set to this channel will be offered updates last during the gradual release cycle. Best for datacenter machines that only receive limited updates.
-
- Note: This setting applies to both monthly as well as daily Defender updates and will override any previously configured channel selections for platform and engine updates.
-
- If you disable or do not configure this policy, the device will remain in Current Channel (Default) unless specified otherwise in specific channels for platform and engine updates. Stay up to date automatically during the gradual release cycle. Suitable for most devices.
- Select Device Control Default Enforcement Policy
-
- Default Allow: Choosing this default enforcement, will Allow any operations to occur on the attached devices if no policy rules are found to match.
- Default Deny: Choosing this default enforcement, will Deny any operations to occur on the attached devices if no policy rules are found to match.
-
- Default Enforcement will establish what decision should be made during the Device Control access checks when none of the policy rules match.
-
- Default Allow
- Default Deny
- Define Device Control evidence data remote location
-
- Define evidence file remote location, where Device Control service will move evidence data captured.
-
- When configuring this setting, ensure that Device Control is Enabled and that the provided path is a remote path the user can access.
-
- Set the retention period for files in the local device control cache
-
- This policy setting determines how long device control retains files for evidence in its local cache on the device. Device control keeps a file in its local cache only if it is unable to upload the file to a designated network share or Azure storage.
-
- By default, device control retains files in its local cache for 60 days.
-
- Turn on device control for specific device types
-
- This policy setting controls which device types, identified by their PrimaryIds, will have device control protection turned on. If you enable this setting for certain device types, device control will regulate access to those devices based on the corresponding custom policy. Device control will be turned off for all other types of supported devices, even if custom protection policies are configured for those devices.
-
- This setting currently supports these device types: RemovableMediaDevices, CdRomDevices, WpdDevices, and PrinterDevices.
-
- If you enable this policy setting but do not specify any PrimaryIds, device control will be turned off across all supported device types.
-
- If you disable or don’t configure this policy setting, device control will be enforced on all supported devicesbased on their corresponding custom policies.
-
- Set up a support link for device control notifications
-
- This setting enables your organization to specify the ‘Get Support’ link in device control notifications.
-
- When configured, the ‘Get Support” button automatically navigates to the specified link.
-
- Set the policy refresh rate
-
- This setting defines the interval, in minutes, at which the device will retry loading the policy configuration in the case that an error has occurred and the policy could not load.
-
- Set the Azure AD refresh rate
-
- This setting defines the interval, in minutes, at which the device will query Azure AD to update related settings, configuration, and group memberships.
-
- Set the data duplication limit (MB)
-
- This setting defines the maximum amount of data that can be duplicated for device control.
-
- When the limit is reached, files that are copied to removable storage will not be duplicated on the machine.
-
- Device Control
-
- Enable or Disable Defender Device Control on this machine.
- Note: You must be enrolled as E3 or E5 in order for Device Control to be enabled.
-
- Intel TDT Integration Level
- This policy setting configures the Intel TDT integration level for Intel TDT-capable devices.
-
- If you do not configure this setting, the default value will be applied. The default value is controlled by Microsoft security intelligence updates. Microsoft will enable Intel TDT if there is a known threat.
- If you configure this setting to enabled, Intel TDT integration will turn on.
- If you configure this setting to disabled, Intel TDT integration will turn off.
- Enable EDR in block mode
- This policy setting enables or disables EDR in block mode (also known as "passive remediation"). EDR in block mode is recommended for devices running Microsoft Defender Antivirus in passive mode. Available with platform release: 4.18.2202.X
-
- The data type is integer
-
- Supported values:
-
- 1: Turn EDR in block mode on
- 0: Turn EDR in block mode off
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- Extension Exclusions
-
-
- Path Exclusions
-
-
- Process Exclusions
-
-
- IP Address Exclusions
-
-
- Specify additional definition sets for network traffic inspection
-
-
- Configure removal of items from Quarantine folder
-
-
- Define the maximum size of downloaded files and attachments to be scanned
-
-
- Configure monitoring for incoming and outgoing file and program activity
-
-
- Specify the state of Remote Encryption Protection
-
-
- Specify how long to block detections for, in minutes
-
-
- Specify how aggressively Remote Encryption Protection blocks threats
-
-
- Remote Encryption Protection Exclusions
-
-
- Specify the state of Brute-Force Protection
-
-
- Specify how long to block detections for, in minutes
-
-
- Specify how aggressively Brute-Force Protection blocks threats
-
-
- Brute-Force Protection Exclusions
-
-
- Specify the day of the week to run a scheduled full scan to complete remediation
-
-
- Specify the time of day to run a scheduled full scan to complete remediation
-
-
- Specify how many days without scans should pass before an aggressive quick scan is triggered
-
-
- Define the number of scheduled scans that can be missed after which a catch-up scan is forced
-
-
- Configure time out for detections requiring additional action
-
-
- Configure time out for detections in critically failed state
-
-
- Configure time out for detections in non-critical failed state
-
-
- Configure time out for detections in recently remediated state
-
-
- Configure Windows software trace preprocessor components
-
-
- Configure WPP tracing level
-
-
- Configure time interval for service health reports
-
-
- Specify the maximum depth to scan archive files
-
-
- Specify the maximum size of archive files to be scanned
-
-
- Specify the maximum percentage of CPU utilization during a scan
-
-
- Turn on removal of items from scan history folder
-
-
- Specify the interval to run quick scans per day
-
-
- Specify the scan type to use for a scheduled scan
-
-
- Specify the day of the week to run a scheduled scan
-
-
- Specify the time for a daily quick scan
-
-
- Specify the time of day to run a scheduled scan
-
-
- Define the number of days before spyware security intelligence is considered out of date
-
-
- Define the number of days before virus security intelligence is considered out of date
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- Specify the day of the week to check for security intelligence updates
-
-
- Specify the time to check for security intelligence updates
-
-
- Define the number of days after which a catch-up security intelligence update is required
-
-
- Specify the interval to check for security intelligence updates
-
-
- Join Microsoft MAPS
-
-
- Send file samples when further analysis is required
-
-
- Specify threats upon which default action should not be taken when detected
-
-
- Specify threat alert levels at which default action should not be taken when detected
-
-
- Specify the interval for expiry notification
-
-
- Select cloud blocking level
-
-
- Specify the extended cloud check time in seconds
-
-
- Configure the guard my folders feature
-
-
- Exclusions from ASR rules:
-
-
- Exclusions for each ASR rules:
-
-
- Set the state for each ASR rule:
-
-
- Enter the applications that should be trusted:
-
-
- Enter the folders that should be guarded:
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- Specify scheduler randomization window in hours.
-
-
- Select the channel for Microsoft Defender monthly platform updates:
-
-
- Select the channel for Microsoft Defender monthly engine updates:
-
-
- Select the channel for Microsoft Defender daily security intelligence updates:
-
-
- Select Device Control Default Enforcement Policy
-
-
-
-
-
-
-
- Set the retention period for files in the local device control cache
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
+
+enter display name here
+enter description here
+
+
+ Microsoft Defender Antivirus
+ Endpoint Protection
+ Exclusions
+ Features
+ Device Control
+ Microsoft Defender Exploit Guard
+ Attack Surface Reduction
+ Controlled Folder Access
+ Network Protection
+ Network Inspection System
+ Exclusions
+ Quarantine
+ Real-time Protection
+ Remediation
+ Behavioral Network Blocks
+ Remote Encryption Protection
+ Brute-Force Protection
+ Reporting
+ Scan
+ Security Intelligence Updates
+ MAPS
+ Threats
+ Client Interface
+ MpEngine
+ Allow antimalware service to startup with normal priority
+ This policy setting controls the load priority for the antimalware service. Increasing the load priority will allow for faster service startup, but may impact performance.
+
+ If you enable or do not configure this setting, the antimalware service will load as a normal priority task.
+
+ If you disable this setting, the antimalware service will load as a low priority task.
+
+ Allows Microsoft Defender Antivirus to update and communicate over a metered connection.
+
+ Disabled (Default):
+ Updates and communications are not allowed over metered connections.
+
+ Enabled:
+ Allow managed devices to update through metered connections. Data charges may apply.
+ Control whether or not exclusions are visible to Local Admins
+
+ This policy setting controls whether or not exclusions are visible to Local Admins. For end users (that are not Local Admins) exclusions are not visible, whether or not this setting is enabled.
+ Disabled(Default):
+ If you disable or do not configure this setting, Local Admins will be able to see exclusions in the Windows Security App or via PowerShell.
+
+ Enabled:
+ If you enable this setting, Local Admins will no longer be able to see the exclusion list in Windows Security App or via PowerShell.
+ Note: Applying this setting will not remove exclusions, it will only prevent them from being visible to Local Admins. This is reflected in Get-MpPreference.
+ Control whether exclusions are visible to local users
+
+ This policy setting controls whether exclusions are visible to local users on the device.
+ Use the policy setting HideExclusionsFromLocalAdmins to hide exclusions from both standard and administrative local users.
+ This settings controls whether Network Protection is allowed to be configured into block or audit mode on Windows Server.
+
+ Disabled (Default):
+ If Not Configured or Disabled, network protection is not allowed to be configured into block or audit mode on Windows Server.
+
+ Enabled:
+ If Enabled, administrators can control whether Network Protection is allowed to be configured into block or audit mode on Windows Server.
+ Note, that this configuration is dependent on the EnableNetworkProtection configuration. If this configuration is false, EnableNetworkProtection will be ignored, otherwise network protection will start on Windows Server depending on the value of EnableNetworkProtection.
+ This setting controls datagram processing for network protection.
+
+ Disabled (Default):
+ If Not Configured or Disabled, datagram processing will be enabled for network protection.
+
+ Enabled:
+ If Enabled, datagram processing will be disabled for network protection.
+ Convert warn verdict to block
+
+ Network protection inspects network traffic and determines whether it allows or blocks traffic or displays a warning.
+
+ Disabled (Default):
+ If Not Configured or Disabled, network protection will display a warning for warn verdicts.
+
+ Enabled:
+ If this setting is Enabled, network protection blocks network traffic instead of displaying a warning.
+ Turn on asynchronous inspection
+
+ Control whether network protection can improve performance by switching from real-time inspection to asynchronous inspection.
+
+ Disabled (Default):
+ If Not Configured or Disabled, asynchronous inspection will not be enabled for network protection.
+
+ Enabled:
+ If Enabled, switching to asynchronous inspection will be allowed for network protection.
+ Turn off Auto Exclusions
+
+ Allows an administrator to specify if Automatic Exclusions feature for Server SKUs should be turned off.
+
+ Disabled (Default):
+ Microsoft Defender will exclude pre-defined list of paths from the scan to improve performance.
+
+ Enabled:
+ Microsoft Defender will not exclude pre-defined list of paths from scans. This can impact machine performance in some scenarios.
+
+ Not configured:
+ Same as Disabled.
+
+ Turn off Endpoint Protection
+ This policy setting turns off Endpoint Protection.
+
+ If you enable this policy setting, Endpoint Protection does not run, and computers are not scanned for malware or other potentially unwanted software.
+
+ If you disable or do not configure this policy setting, by default Endpoint Protection runs and computers are scanned for malware and other potentially unwanted software.
+
+ Turn off Microsoft Defender Antivirus
+ This policy setting turns off Microsoft Defender Antivirus.
+
+ If you enable this policy setting, Microsoft Defender Antivirus does not run, and will not scan computers for malware or other potentially unwanted software.
+
+ If you disable this policy setting, Microsoft Defender Antivirus will run regardless of any other installed antivirus product.
+
+ If you do not configure this policy setting, Windows will internally manage Microsoft Defender Antivirus. If you install another antivirus program, Windows automatically disables Microsoft Defender Antivirus. Otherwise, Microsoft Defender Antivirus will scan your computers for malware and other potentially unwanted software.
+
+ Enabling or disabling this policy may lead to unexpected or unsupported behavior. It is recommended that you leave this policy setting unconfigured.
+ Configure local administrator merge behavior for lists
+ This policy setting controls whether or not complex list settings configured by a local administrator are merged with Group Policy settings. This setting applies to lists such as threats and Exclusions.
+
+ If you disable or do not configure this setting, unique items defined in Group Policy and in preference settings configured by the local administrator will be merged into the resulting effective policy. In the case of conflicts, Group policy Settings will override preference settings.
+
+ If you enable this setting, only items defined by Group Policy will be used in the resulting effective policy. Group Policy settings will override preference settings configured by the local administrator.
+ Turn off routine remediation
+
+ This policy setting allows you to configure whether Microsoft Defender Antivirus automatically takes action on all detected threats. The action to be taken on a particular threat is determined by the combination of the policy-defined action, user-defined action, and the signature-defined action.
+
+ If you enable this policy setting, Microsoft Defender Antivirus does not automatically take action on the detected threats, but prompts users to choose from the actions available for each threat.
+
+ If you disable or do not configure this policy setting, Microsoft Defender Antivirus automatically takes action on all detected threats after a nonconfigurable delay of approximately five seconds.
+
+ This policy setting allows you to configure whether Endpoint Protection automatically takes action on all detected threats. The action to be taken on a particular threat is determined by the combination of the policy-defined action, user-defined action, and the signature-defined action.
+
+ If you enable this policy setting, Endpoint Protection does not automatically take action on the detected threats, but prompts users to choose from the actions available for each threat.
+
+ If you disable or do not configure this policy setting, Endpoint Protection automatically takes action on all detected threats after a nonconfigurable delay of approximately five seconds.
+
+ Define addresses to bypass proxy server
+ This policy, if defined, will prevent antimalware from using the configured proxy server when communicating with the specified IP addresses. The address value should be entered as a valid URL.
+
+ If you enable this setting, the proxy server will be bypassed for the specified addresses.
+
+ If you disable or do not configure this setting, the proxy server will not be bypassed for the specified addresses.
+ Define proxy auto-config (.pac) for connecting to the network
+ This policy setting defines the URL of a proxy .pac file that should be used when the client attempts to connect the network for security intelligence updates and MAPS reporting. If the proxy auto-config fails or if there is no proxy auto-config specified, the client will fall back to the alternative options (in order):
+ 1. Proxy server (if specified)
+ 2. Proxy .pac URL (if specified)
+ 3. None
+ 4. Internet Explorer proxy settings
+ 5. Autodetect
+
+ If you enable this setting, the proxy setting will be set to use the specified proxy .pac according to the order specified above.
+
+ If you disable or do not configure this setting, the proxy will skip over this fallback step according to the order specified above.
+ Define proxy server for connecting to the network
+ This policy setting allows you to configure the named proxy that should be used when the client attempts to connect to the network for security intelligence updates and MAPS reporting. If the named proxy fails or if there is no proxy specified, the client will fall back to the alternative options (in order):
+ 1. Proxy server (if specified)
+ 2. Proxy .pac URL (if specified)
+ 3. None
+ 4. Internet Explorer proxy settings
+ 5. Autodetect
+
+ If you enable this setting, the proxy will be set to the specified URL according to the order specified above. The URL should be proceeded with either http:// or https://.
+
+ If you disable or do not configure this setting, the proxy will skip over this fallback step according to the order specified above.
+
+ Randomize scheduled task times
+ This policy setting allows you to configure the randomization of the scheduled scan start time and the scheduled definition update start time.
+
+ If you enable or do not configure this policy setting, and did not set a randomization window in the Configure scheduled task time randomization window setting , then randomization will be added between 0-4 hours.
+ If you enable or do not configure this policy setting, and set a randomization window in the Configure scheduled task time randomization window setting, the configured randomization window will be used.
+ If you disable this policy setting, but configured the scheduled task time randomization window, randomization will not be done.
+
+ Configure scheduled task times randomization window
+ This policy setting allows you to configure scheduled task scan start time and the scheduled security intelligence update start time window in hours. This setting affects the Randomize scheduled task times configuration.
+
+ If you enable this setting, you must pick a randomization window in hours. The possible randomization window interval is between 1 and 23 hours. The randomization interval implemented is between 0 and the configured value.
+ When you enable this setting, Randomize scheduled task times settings uses the randomization window specified in this configuration setting.
+ If you disable or do not configure this policy setting, Randomize scheduled task times settings will randomize scheduled task times between 0-4 hours.
+
+ Allow antimalware service to remain running always
+ This policy setting allows you to configure whether or not the antimalware service remains running when antivirus and antispyware security intelligence is disabled. It is recommended that this setting remain disabled.
+
+ If you enable this setting, the antimalware service will always remain running even if both antivirus and antispyware security intelligence is disabled.
+
+ If you disable or do not configure this setting, the antimalware service will be stopped when both antivirus and antispyware security intelligence is disabled. If the computer is restarted, the service will be started if it is set to Automatic startup. After the service has started, there will be a check to see if antivirus and antispyware security intelligence is enabled. If at least one is enabled, the service will remain running. If both are disabled, the service will be stopped.
+ Configure detection for potentially unwanted applications
+
+ Enable or disable detection for potentially unwanted applications. You can choose to block, audit, or allow when potentially unwanted software is being downloaded or attempts to install itself on your computer.
+
+ Enabled:
+ Specify the mode in the Options section:
+ -Block: Potentially unwanted software will be blocked.
+ -Audit Mode: Potentially unwanted software will not be blocked, however if this feature would have blocked access if it were set to Block, then a record of the event will be in the event logs.
+
+ Disabled:
+ Potentially unwanted software will not be blocked.
+
+ Not configured:
+ Same as Disabled.
+
+ Define the directory path to copy support log files
+ This policy setting allows you to configure the directory path where the support log files would be copied to. The value of this setting should be a valid directory path.
+
+ If you enable this setting, the support log files will be copied to the specified support log location path.
+
+ If you disable or do not configure this setting, the support logs files will not be copied to any location.
+ Extension Exclusions
+ This policy setting allows you specify a list of file types that should be excluded from scheduled, custom, and real-time scanning. File types should be added under the Options for this setting. Each entry must be listed as a name value pair, where the name should be a string representation of the file type extension (such as "obj" or "lib"). The value is not used and it is recommended that this be set to 0.
+ Path Exclusions
+ This policy setting allows you to disable scheduled and real-time scanning for files under the paths specified or for the fully qualified resources specified. Paths should be added under the Options for this setting. Each entry must be listed as a name value pair, where the name should be a string representation of a path or a fully qualified resource name. As an example, a path might be defined as: "c:\Windows" to exclude all files in this directory. A fully qualified resource name might be defined as: "C:\Windows\App.exe". The value is not used and it is recommended that this be set to 0.
+ Process Exclusions
+ This policy setting allows you to disable real-time scanning for any file opened by any of the specified processes. This policy does not apply to scheduled scans. The process itself will not be excluded. To exclude the process, use the Path exclusion. Processes should be added under the Options for this setting. Each entry must be listed as a name value pair, where the name should be a string representation of the path to the process image. Note that only executables can be excluded. For example, a process might be defined as: "c:\windows\app.exe". The value is not used and it is recommended that this be set to 0.
+ Ip Address Exclusions
+ Allows an administrator to explicitly disable network packet inspection made by wdnisdrv on a particular set of IP addresses.
+ Turn on protocol recognition
+ This policy setting allows you to configure protocol recognition for network protection against exploits of known vulnerabilities.
+
+ If you enable or do not configure this setting, protocol recognition will be enabled.
+
+ If you disable this setting, protocol recognition will be disabled.
+ Turn on definition retirement
+ This policy setting allows you to configure definition retirement for network protection against exploits of known vulnerabilities. Definition retirement checks to see if a computer has the required security updates necessary to protect it against a particular vulnerability. If the system is not vulnerable to the exploit detected by a definition, then that definition is "retired". If all security intelligence for a given protocal are retired then that protocol is no longer parsed. Enabling this feature helps to improve performance. On a computer that is up-to-date with all the latest security updates, network protection will have no impact on network performance.
+
+ If you enable or do not configure this setting, definition retirement will be enabled.
+
+ If you disable this setting, definition retirement will be disabled.
+ Specify additional definition sets for network traffic inspection
+ This policy setting defines additional definition sets to enable for network traffic inspection. Definition set GUIDs should be added under the Options for this setting. Each entry must be listed as a name value pair, where the name should be a string representation of a definition set GUID. As an example, the definition set GUID to enable test security intelligence is defined as: “{b54b6ac9-a737-498e-9120-6616ad3bf590}”. The value is not used and it is recommended that this be set to 0.
+ Configure local setting override for the removal of items from Quarantine folder
+ This policy setting configures a local override for the configuration of the number of days items should be kept in the Quarantine folder before being removed. This setting can only be set by Group Policy.
+
+ If you enable this setting, the local preference setting will take priority over Group Policy.
+
+ If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.
+ Configure removal of items from Quarantine folder
+ This policy setting defines the number of days items should be kept in the Quarantine folder before being removed.
+
+ If you enable this setting, items will be removed from the Quarantine folder after the number of days specified.
+
+ If you disable or do not configure this setting, items will be kept in the quarantine folder indefinitely and will not be automatically removed.
+
+ Turn on script scanning
+ This policy setting allows you to configure script scanning.
+
+ If you enable or do not configure this setting, script scanning will be enabled.
+
+ If you disable this setting, script scanning will be disabled.
+
+ Configure real-time protection and Security Intelligence Updates during OOBE
+ This policy setting allows you to configure whether real-time protection and Security Intelligence Updates are enabled during OOBE (Out of Box experience).
+
+ If you enable this setting, real-time protection and Security Intelligence Updates are enabled during OOBE.
+
+ If you either disable or do not configure this policy setting, real-time protection and Security Intelligence Updates during OOBE is not enabled.
+
+ Configure performance mode status
+ This policy controls Microsoft Defender Antivirus performance mode for Dev Drives.
+
+ A Dev Drive is a disk drive optimized for higher performance in software development scenarios. When this policy is Enabled or not configured, Performance mode is turned on for Microsoft Defender Antivirus. In Performance mode, Microsoft Defender Antivirus security checks of content stored on Dev Drives are conducted asynchronously to enhance performance. Performance mode requires the following policies also be enabled: “Enable dev drive”, and “Dev drive filter attach policy”.
+
+ If you either Enable or do not configure this policy setting, Performance mode is turned on.
+
+ If you Disable this policy setting, Performance mode is turned off and Microsoft Defender Antivirus will protect a Dev Drive in the same way as other drives.
+
+ Turn on behavior monitoring
+ This policy setting allows you to configure behavior monitoring.
+
+ If you enable or do not configure this setting, behavior monitoring will be enabled.
+
+ If you disable this setting, behavior monitoring will be disabled.
+ Scan all downloaded files and attachments
+ This policy setting allows you to configure scanning for all downloaded files and attachments.
+
+ If you enable or do not configure this setting, scanning for all downloaded files and attachments will be enabled.
+
+ If you disable this setting, scanning for all downloaded files and attachments will be disabled.
+ Monitor file and program activity on your computer
+ This policy setting allows you to configure monitoring for file and program activity.
+
+ If you enable or do not configure this setting, monitoring for file and program activity will be enabled.
+
+ If you disable this setting, monitoring for file and program activity will be disabled.
+ Turn on raw volume write notifications
+ This policy setting controls whether raw volume write notifications are sent to behavior monitoring.
+
+ If you enable or do not configure this setting, raw write notifications will be enabled.
+
+ If you disable this setting, raw write notifications be disabled.
+ Turn off real-time protection
+ This policy turns off real-time protection in Microsoft Defender Antivirus.
+
+ Real-time protection consists of always-on scanning with file and process behavior monitoring and heuristics. When real-time protection is on, Microsoft Defender Antivirus detects malware and potentially unwanted software that attempts to install itself or run on your device, and prompts you to take action on malware detections.
+
+ If you enable this policy setting, real-time protection is turned off.
+
+ If you either disable or do not configure this policy setting, real-time protection is turned on.
+
+ This policy setting turns off real-time protection prompts for known malware detection.
+
+ Endpoint Protection alerts you when malware or potentially unwanted software attempts to install itself or to run on your computer.
+
+ If you enable this policy setting, Endpoint Protection will not prompt users to take actions on malware detections.
+
+ If you disable or do not configure this policy setting, Endpoint Protection will prompt users to take actions on malware detections.
+
+ Turn on process scanning whenever real-time protection is enabled
+ This policy setting allows you to configure process scanning when real-time protection is turned on. This helps to catch malware which could start when real-time protection is turned off.
+
+ If you enable or do not configure this setting, a process scan will be initiated when real-time protection is turned on.
+
+ If you disable this setting, a process scan will not be initiated when real-time protection is turned on.
+ Define the maximum size of downloaded files and attachments to be scanned
+ This policy setting defines the maximum size (in kilobytes) of downloaded files and attachments that will be scanned.
+
+ If you enable this setting, downloaded files and attachments smaller than the size specified will be scanned.
+
+ If you disable or do not configure this setting, a default size will be applied.
+ Configure local setting override for turn on behavior monitoring
+ This policy setting configures a local override for the configuration of behavior monitoring. This setting can only be set by Group Policy.
+
+ If you enable this setting, the local preference setting will take priority over Group Policy.
+
+ If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.
+ Configure local setting override for monitoring file and program activity on your computer
+ This policy setting configures a local override for the configuration of monitoring for file and program activity on your computer. This setting can only be set by Group Policy.
+
+ If you enable this setting, the local preference setting will take priority over Group Policy.
+
+ If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.
+ Configure local setting override for scanning all downloaded files and attachments
+ This policy setting configures a local override for the configuration of scanning for all downloaded files and attachments. This setting can only be set by Group Policy.
+
+ If you enable this setting, the local preference setting will take priority over Group Policy.
+
+ If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.
+ Configure local setting override to turn on real-time protection
+ This policy setting configures a local override for the configuration to turn on real-time protection. This setting can only be set by Group Policy.
+
+ If you enable this setting, the local preference setting will take priority over Group Policy.
+
+ If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.
+ Configure local setting override for monitoring for incoming and outgoing file activity
+ This policy setting configures a local override for the configuration of monitoring for incoming and outgoing file activity. This setting can only be set by Group Policy.
+
+ If you enable this setting, the local preference setting will take priority over Group Policy.
+
+ If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.
+ Configure monitoring for incoming and outgoing file and program activity
+ This policy setting allows you to configure monitoring for incoming and outgoing files, without having to turn off monitoring entirely. It is recommended for use on servers where there is a lot of incoming and outgoing file activity but for performance reasons need to have scanning disabled for a particular scan direction. The appropriate configuration should be evaluated based on the server role.
+
+ Note that this configuration is only honored for NTFS volumes. For any other file system type, full monitoring of file and program activity will be present on those volumes.
+
+ The options for this setting are mutually exclusive:
+ 0 = Scan incoming and outgoing files (default)
+ 1 = Scan incoming files only
+ 2 = Scan outgoing files only
+
+ Any other value, or if the value does not exist, resolves to the default (0).
+
+ If you enable this setting, the specified type of monitoring will be enabled.
+
+ If you disable or do not configure this setting, monitoring for incoming and outgoing files will be enabled.
+ bi-directional (full on-access)
+ scan only incoming (disable on-open)
+ scan only outgoing (disable on-close)
+ Configure local setting override for the time of day to run a scheduled full scan to complete remediation
+ This policy setting configures a local override for the configuration of the time to run a scheduled full scan to complete remediation. This setting can only be set by Group Policy.
+
+ If you enable this setting, the local preference setting will take priority over Group Policy.
+
+ If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.
+ Specify the day of the week to run a scheduled full scan to complete remediation
+ This policy setting allows you to specify the day of the week on which to perform a scheduled full scan in order to complete remediation. The scan can also be configured to run every day or to never run at all.
+
+ This setting can be configured with the following ordinal number values:
+ (0x0) Every Day
+ (0x1) Sunday
+ (0x2) Monday
+ (0x3) Tuesday
+ (0x4) Wednesday
+ (0x5) Thursday
+ (0x6) Friday
+ (0x7) Saturday
+ (0x8) Never (default)
+
+ If you enable this setting, a scheduled full scan to complete remediation will run at the frequency specified.
+
+ If you disable or do not configure this setting, a scheduled full scan to complete remediation will run at a default frequency.
+ Never
+ Every Day
+ Sunday
+ Monday
+ Tuesday
+ Wednesday
+ Thursday
+ Friday
+ Saturday
+ Specify the time of day to run a scheduled full scan to complete remediation
+ This policy setting allows you to specify the time of day at which to perform a scheduled full scan in order to complete remediation. The time value is represented as the number of minutes past midnight (00:00). For example, 120 (0x78) is equivalent to 02:00 AM. The schedule is based on local time on the computer where the scan is executing.
+
+ If you enable this setting, a scheduled full scan to complete remediation will run at the time of day specified.
+
+ If you disable or do not configure this setting, a scheduled full scan to complete remediation will run at a default time.
+ Configure Remote Encryption Protection Mode
+
+ Set the mode for Remote Encryption Protection in Microsoft Defender Antivirus, which can detect and block attempts to replace local files with encrypted versions from another device.
+
+ Supported settings:
+ * 0 - Not configured or Default: Apply defaults, which can vary depending on the antivirus engine version and the platform
+ * 1 - Block: Prevent suspicious and malicious behaviors
+ * 2 - Audit: Generate EDR detections without blocking
+ * 4 - Off: Feature is off with no performance impact
+
+ Default
+ Block
+ Audit
+ Off
+ Configure Remote Encryption Protection blocking time
+
+ Set the maximum time an IP address is blocked by Remote Encryption Protection. After this time, blocked IP addresses will be able to reinitiate connections.
+
+ Supported settings:
+ * 0 - None: Internal feature logic will determine the actual blocking time
+ * Specify other times in 15-minute increments
+
+ Configure how aggressively Remote Encryption Protection blocks threats
+
+ Set the criteria for when remote encryption preventionprotection blocks IP addresses.
+
+ Supported settings:
+ *0 - Low: Block only when confidence level is 100% (Default)
+ *1 - Medium: Use cloud aggregation and block when confidence level is above 99%
+ *2 - High: Use cloud intel and context, and block when confidence level is above 90%
+
+ Low
+ Medium
+ High
+ Set exclusions from Remote Encryption Protection
+
+ Specify IP addresses, subnets, and domain names to exclude from Remote Encryption Protection. Note that attackers can spoof excluded addresses and names to bypass protection.
+
+ Enter each address or subnet on a new line as a name-value pair:
+ - Name column: Enter an IP address or subnet name. For example, ""1.1.127.0"" will exclude this IP address from getting blocked.
+ - Value column: Enter ""0"" for each item
+
+ Configure Brute-Force Protection mode
+
+ Set the mode for Brute-Force Protection in Microsoft Defender Antivirus, which can detect and block attempts to forcibly initiate sign in and initiate sessions.
+
+ Supported settings:
+ * 0 - Not configured or Default: Apply defaults, which can vary depending on the antivirus engine version and the platform
+ * 1 - Block: Prevent suspicious and malicious behaviors
+ * 2 - Audit: Generate EDR detections without blocking
+ * 4 - Off: Feature is off with no performance impact
+
+ Default
+ Block
+ Audit
+ Off
+ Configure Brute-Force Protection blocking time
+
+ Set the maximum time an IP address is blocked by Brute-Force Protection. After this time, blocked IP addresses will be able to sign-in and initiate sessions.
+
+ Supported settings:
+ * 0 - None: Internal feature logic will determine the actual blocking time
+ * Specify other times in 15-minute increments
+
+ Configure Brute-Force Protection aggressiveness
+
+ Set the criteria for when Brute-Force Protection blocks IP addresses.
+
+ Supported settings:
+ *0 - Low: Block only when confidence level is 100% (Default)
+ *1 - Medium: Use cloud aggregation and block when confidence level is above 99%
+ *2 - High: Use cloud intel and context, and block when confidence level is above 90%
+
+ Low
+ Medium
+ High
+ Set exclusions from Brute-Force Protection
+
+ Specify IP addresses, subnets or workstation names to exclude from Brute-Force Protection. Excluded IP addresses will not be checked for possible brute force activity.
+
+ Note that attackers can spoof excluded addresses and names to bypass protection. Ensure the names are unique and unlikely to be guessed by attackers.
+
+ Enter each address or subnet on a new line as a name-value pair:
+ - Name column: Enter an IP address, subnet name, or workstation name. For example, "1.1.127.0" will exclude this IP address from getting blocked by BFP.
+ - Value column: Enter "0" for each item
+
+ Configure time out for detections requiring additional action
+ This policy setting configures the time in minutes before a detection in the "additional action" state moves to the "cleared" state.
+ Configure time out for detections in critically failed state
+ This policy setting configures the time in minutes before a detection in the “critically failed” state to moves to either the “additional action” state or the “cleared” state.
+ Configure Watson events
+ This policy setting allows you to configure whether or not Watson events are sent.
+
+ If you enable or do not configure this setting, Watson events will be sent.
+
+ If you disable this setting, Watson events will not be sent.
+ Configure time out for detections in non-critical failed state
+ This policy setting configures the time in minutes before a detection in the "non-critically failed" state moves to the "cleared" state.
+ Configure time out for detections in recently remediated state
+ This policy setting configures the time in minutes before a detection in the "completed" state moves to the "cleared" state.
+ Configure Windows software trace preprocessor components
+ This policy configures Windows software trace preprocessor (WPP Software Tracing) components.
+ Configure WPP tracing level
+ This policy allows you to configure tracing levels for Windows software trace preprocessor (WPP Software Tracing).
+ Tracing levels are defined as:
+ 1 - Error
+ 2 - Warning
+ 3 - Info
+ 4 - Debug
+ Turn off enhanced notifications
+
+ Use this policy setting to specify if you want Microsoft Defender Antivirus enhanced notifications to display on clients.
+
+ If you disable or do not configure this setting, Microsoft Defender Antivirus enhanced notifications will display on clients.
+
+ If you enable this setting, Microsoft Defender Antivirus enhanced notifications will not display on clients.
+
+ Configure time interval for service health reports
+ This policy setting configures the time interval (in minutes) for the service health reports to be sent from endpoints.
+
+ If you disable or do not configure this setting, the default value will be applied. The default value is set at 60 minutes (1 hour).
+
+ If you configure this setting to 0, no service health reports will be sent.
+
+ The maximum value allowed to be set is 14400 minutes (10 days).
+ Configure whether to report Dynamic Signature dropped events
+ This policy setting configures whether to report Dynamic Signature dropped events.
+
+ If you do not configure this setting, the default value will be applied. The default value is set to disabled (such events are not reported).
+ If you configure this setting to enabled, Dynamic Signature dropped events will be reported.
+ If you configure this setting to disabled, Dynamic Signature dropped events will not be reported.
+ Allow users to pause scan
+ This policy setting allows you to manage whether or not end users can pause a scan in progress.
+
+ If you enable or do not configure this setting, a new context menu will be added to the task tray icon to allow the user to pause a scan.
+
+ If you disable this setting, users will not be able to pause scans.
+ Specify the maximum depth to scan archive files
+ This policy setting allows you to configure the maximum directory depth level into which archive files such as .ZIP or .CAB are unpacked during scanning. The default directory depth level is 0.
+
+ If you enable this setting, archive files will be scanned to the directory depth level specified.
+
+ If you disable or do not configure this setting, archive files will be scanned to the default directory depth level.
+ Specify the maximum size of archive files to be scanned
+ This policy setting allows you to configure the maximum size of archive files such as .ZIP or .CAB that will be scanned. The value represents file size in kilobytes (KB). The default value is 0 and represents no limit to archive size for scanning.
+
+ If you enable this setting, archive files less than or equal to the size specified will be scanned.
+
+ If you disable or do not configure this setting, archive files will be scanned according to the default value.
+ Specify the maximum percentage of CPU utilization during a scan
+ This policy setting allows you to configure the maximum percentage CPU utilization permitted during a scan. Valid values for this setting are a percentage represented by the integers 5 to 100. A value of 0 indicates that there should be no throttling of CPU utilization. The default value is 50.
+
+ If you enable this setting, CPU utilization will not exceed the percentage specified.
+
+ If you disable or do not configure this setting, CPU utilization will not exceed the default value.
+ Check for the latest virus and spyware security intelligence before running a scheduled scan
+ This policy setting allows you to manage whether a check for new virus and spyware security intelligence will occur before running a scan.
+
+ This setting applies to scheduled scans, but it has no effect on scans initiated manually from the user interface or to the ones started from the command line using "mpcmdrun -Scan".
+
+ If you enable this setting, a check for new security intelligence will occur before running a scan.
+
+ If you disable this setting or do not configure this setting, the scan will start using the existing security intelligence.
+ Scan archive files
+ This policy setting allows you to configure scans for malicious software and unwanted software in archive files such as .ZIP or .CAB files.
+
+ If you enable or do not configure this setting, archive files will be scanned.
+
+ If you disable this setting, archive files will not be scanned. However, archives are always scanned during directed scans.
+ Turn on catch-up full scan
+ This policy setting allows you to configure catch-up scans for scheduled full scans. A catch-up scan is a scan that is initiated because a regularly scheduled scan was missed. Usually these scheduled scans are missed because the computer was turned off at the scheduled time.
+
+ If you enable this setting, catch-up scans for scheduled full scans will be turned on. If a computer is offline for two consecutive scheduled scans, a catch-up scan is started the next time someone logs on to the computer. If there is no scheduled scan configured, there will be no catch-up scan run.
+
+ If you disable or do not configure this setting, catch-up scans for scheduled full scans will be turned off.
+ CPU throttling type
+ This policy setting determines whether the maximum percentage CPU utilization permitted during a scan applies only to scheduled scans, or to both scheduled and custom scans (but not real-time protection). The maximum CPU utilization limit is also referred to as CPU throttling, or a CPU usage limit.
+
+ The default value for this policy setting is True, which means CPU throttling is applied only to scheduled scans.
+
+ If you either enable or do not configure this setting, CPU throttling will apply only to scheduled scans.
+
+ If you disable this setting, CPU throttling will apply to scheduled and custom scans.
+ Turn on catch-up quick scan
+ This policy setting allows you to configure catch-up scans for scheduled quick scans. A catch-up scan is a scan that is initiated because a regularly scheduled scan was missed. Usually these scheduled scans are missed because the computer was turned off at the scheduled time.
+
+ If you enable this setting, catch-up scans for scheduled quick scans will be turned on. If a computer is offline for two consecutive scheduled scans, a catch-up scan is started the next time someone logs on to the computer. If there is no scheduled scan configured, there will be no catch-up scan run.
+
+ If you disable or do not configure this setting, catch-up scans for scheduled quick scans will be turned off.
+ Trigger a quick scan after X days without any scans
+ This policy setting defines the number of days that can pass since the last scan before an aggresive catchup quick scan is automatically triggered. The value represents the number of days that can pass without any scans being performed before an agressive quick scan will be triggered.
+
+ Valid values range from 7 to 60 days. If not configured, aggressive quick scans will be disabled. By default, the value is set to 25 days when enabled.
+ Turn on e-mail scanning
+ This policy setting allows you to configure e-mail scanning. When e-mail scanning is enabled, the engine will parse the mailbox and mail files, according to their specific format, in order to analyze the mail bodies and attachments. Several e-mail formats are currently supported, for example: pst (Outlook), dbx, mbx, mime (Outlook Express), binhex (Mac). Email scanning is not supported on modern email clients.
+
+ If you enable this setting, e-mail scanning will be enabled.
+
+ If you disable or do not configure this setting, e-mail scanning will be disabled.
+ Turn on heuristics
+ This policy setting allows you to configure heuristics. Suspicious detections will be suppressed right before reporting to the engine client. Turning off heuristics will reduce the capability to flag new threats. It is recommended that you do not turn off heuristics.
+
+ If you enable or do not configure this setting, heuristics will be enabled.
+
+ If you disable this setting, heuristics will be disabled.
+ Scan packed executables
+ This policy setting allows you to configure scanning for packed executables. It is recommended that this type of scanning remain enabled.
+
+ If you enable or do not configure this setting, packed executables will be scanned.
+
+ If you disable this setting, packed executables will not be scanned.
+ Scan removable drives
+ This policy setting allows you to manage whether or not to scan for malicious software and unwanted software in the contents of removable drives, such as USB flash drives, when running a full scan.
+
+ If you enable this setting, removable drives will be scanned during any type of scan.
+
+ If you disable or do not configure this setting, removable drives will not be scanned during a full scan. Removable drives may still be scanned during quick scan and custom scan.
+ Turn on reparse point scanning
+ This policy setting allows you to configure reparse point scanning. If you allow reparse points to be scanned, there is a possible risk of recursion. However, the engine supports following reparse points to a maximum depth so at worst scanning could be slowed. Reparse point scanning is disabled by default and this is the recommended state for this functionality.
+
+ If you enable this setting, reparse point scanning will be enabled.
+
+ If you disable or do not configure this setting, reparse point scanning will be disabled.
+ Create a system restore point
+ This policy setting allows you to create a system restore point on the computer on a daily basis prior to cleaning.
+
+ If you enable this setting, a system restore point will be created.
+
+ If you disable or do not configure this setting, a system restore point will not be created.
+ Run full scan on mapped network drives
+ This policy setting allows you to configure scanning mapped network drives.
+
+ If you enable this setting, mapped network drives will be scanned.
+
+ If you disable or do not configure this setting, mapped network drives will not be scanned.
+ Configure scanning of network files
+ This policy setting allows the scanning of network files using on access protection. The default is enabled. Recommended to remain enabled in most cases.
+
+ If you enable or do not configure this setting, network files will be scanned.
+
+ If you disable this setting, network files will not be scanned.
+ Configure local setting override for maximum percentage of CPU utilization
+ This policy setting configures a local override for the configuration of maximum percentage of CPU utilization during scan. This setting can only be set by Group Policy.
+
+ If you enable this setting, the local preference setting will take priority over Group Policy.
+
+ If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.
+ Configure local setting override for the scan type to use for a scheduled scan
+ This policy setting configures a local override for the configuration of the scan type to use during a scheduled scan. This setting can only be set by Group Policy.
+
+ If you enable this setting, the local preference setting will take priority over Group Policy.
+
+ If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.
+ Configure local setting override for schedule scan day
+ This policy setting configures a local override for the configuration of scheduled scan day. This setting can only be set by Group Policy.
+
+ If you enable this setting, the local preference setting will take priority over Group Policy.
+
+ If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.
+ Configure local setting override for scheduled quick scan time
+ This policy setting configures a local override for the configuration of scheduled quick scan time. This setting can only be set by Group Policy.
+
+ If you enable this setting, the local preference setting will take priority over Group Policy.
+
+ If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.
+ Configure local setting override for scheduled scan time
+ This policy setting configures a local override for the configuration of scheduled scan time. This setting can only be set by Group Policy.
+
+ If you enable this setting, the local preference setting will take priority over Group Policy.
+
+ If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.
+ Turn on removal of items from scan history folder
+ This policy setting defines the number of days items should be kept in the scan history folder before being permanently removed. The value represents the number of days to keep items in the folder. If set to zero, items will be kept forever and will not be automatically removed. By default, the value is set to 30 days.
+
+ If you enable this setting, items will be removed from the scan history folder after the number of days specified.
+
+ If you disable or do not configure this setting, items will be kept in the scan history folder for the default number of days.
+ Specify the interval to run quick scans per day
+ This policy setting allows you to specify an interval at which to perform a quick scan. The time value is represented as the number of hours between quick scans. Valid values range from 1 (every hour) to 24 (once per day). If set to zero, interval quick scans will not occur. By default, this setting is set to 0.
+
+ If you enable this setting, a quick scan will run at the interval specified.
+
+ If you disable or do not configure this setting, quick scan controlled by this config will not be run.
+ Start the scheduled scan only when computer is on but not in use
+ This policy setting allows you to configure scheduled scans to start only when your computer is on but not in use.
+
+ If you enable or do not configure this setting, scheduled scans will only run when the computer is on but not in use.
+
+ If you disable this setting, scheduled scans will run at the scheduled time.
+ Specify the scan type to use for a scheduled scan
+ This policy setting allows you to specify the scan type to use during a scheduled scan. Scan type options are:
+ 1 = Quick Scan (default)
+ 2 = Full Scan
+
+ If you enable this setting, the scan type will be set to the specified value.
+
+ If you disable or do not configure this setting, the default scan type will used.
+ Quick scan
+ Full system scan
+ Specify the day of the week to run a scheduled scan
+ This policy setting allows you to specify the day of the week on which to perform a scheduled scan. The scan can also be configured to run every day or to never run at all.
+
+ This setting can be configured with the following ordinal number values:
+ (0x0) Every Day
+ (0x1) Sunday
+ (0x2) Monday
+ (0x3) Tuesday
+ (0x4) Wednesday
+ (0x5) Thursday
+ (0x6) Friday
+ (0x7) Saturday
+ (0x8) Never (default)
+
+ If you enable this setting, a scheduled scan will run at the frequency specified.
+
+ If you disable or do not configure this setting, a scheduled scan will run at a default frequency.
+ Never
+ Every Day
+ Sunday
+ Monday
+ Tuesday
+ Wednesday
+ Thursday
+ Friday
+ Saturday
+ Specify the time for a daily quick scan
+ This policy setting allows you to specify the time of day at which to perform a daily quick scan. The time value is represented as the number of minutes past midnight (00:00). For example, 120 (0x78) is equivalent to 02:00 AM. By default, this setting is set to disabled. The schedule is based on local time on the computer where the scan is executing.
+
+ If you enable this setting, a daily quick scan will run at the time of day specified.
+
+ If you disable or do not configure this setting, daily quick scan controlled by this config will not be run.
+ Specify the time of day to run a scheduled scan
+ This policy setting allows you to specify the time of day at which to perform a scheduled scan. The time value is represented as the number of minutes past midnight (00:00). For example, 120 (0x78) is equivalent to 02:00 AM. By default, this setting is set to a time value of 2:00 AM. The schedule is based on local time on the computer where the scan is executing.
+
+ If you enable this setting, a scheduled scan will run at the time of day specified.
+
+ If you disable or do not configure this setting, a scheduled scan will run at a default time.
+ Define the number of days after which a catch-up scan is forced
+
+ This policy setting allows you to define the number of consecutive scheduled scans that can be missed after which a catch-up scan will be forced. By default, the value of this setting is 2 consecutive scheduled scans.
+
+ If you enable this setting, a catch-up scan will occur after the specified number consecutive missed scheduled scans.
+
+ If you disable or do not configure this setting, a catch-up scan will occur after the 2 consecutive missed scheduled scans.
+ Configure low CPU priority for scheduled scans
+
+ This policy setting allows you to enable or disable low CPU priority for scheduled scans.
+
+ If you enable this setting, low CPU priority will be used during scheduled scans.
+
+ If you disable or do not configure this setting, not changes will be made to CPU priority for scheduled scans.
+
+
+ Scan excluded files and directories during quick scans
+
+ This policy setting allows you to scan excluded files and directories during quick scans.
+
+ If you set this policy setting to 1, all files and directories that are excluded from real-time protection using contextual exclusions are scanned during a quick scan.
+
+ If you set this policy to 0 or do not configure it, exclusions are not scanned during quick scans.
+
+ 0
+ 1
+
+ Define the number of days before spyware security intelligence is considered out of date
+ This policy setting allows you to define the number of days that must pass before spyware security intelligence is considered out of date. If security intelligence is determined to be out of date, this state may trigger several additional actions, including falling back to an alternative update source or displaying a warning icon in the user interface. By default, this value is set to 7 days.
+
+ If you enable this setting, spyware security intelligence will be considered out of date after the number of days specified have passed without an update.
+
+ If you disable or do not configure this setting, spyware security intelligence will be considered out of date after the default number of days have passed without an update.
+ Define the number of days before virus security intelligence is considered out of date
+ This policy setting allows you to define the number of days that must pass before virus security intelligence is considered out of date. If security intelligence is determined to be out of date, this state may trigger several additional actions, including falling back to an alternative update source or displaying a warning icon in the user interface. By default, this value is set to 7 days.
+
+ If you enable this setting, virus security intelligence will be considered out of date after the number of days specified have passed without an update.
+
+ If you disable or do not configure this setting, virus security intelligence will be considered out of date after the default number of days have passed without an update.
+ Define file shares for downloading security intelligence updates
+ This policy setting allows you to configure UNC file share sources for downloading security intelligence updates. Sources will be contacted in the order specified. The value of this setting should be entered as a pipe-separated string enumerating the security intelligence update sources. For example: "{\\unc1 | \\unc2 }". The list is empty by default.
+
+ If you enable this setting, the specified sources will be contacted for security intelligence updates. Once security intelligence updates have been successfully downloaded from one specified source, the remaining sources in the list will not be contacted.
+
+ If you disable or do not configure this setting, the list will remain empty by default and no sources will be contacted.
+ Define security intelligence location for VDI clients.
+ This policy setting allows you to define the security intelligence location for VDI-configured computers.
+
+ If you disable or do not configure this setting, security intelligence will be referred from the default local source.
+ Configure security intelligence updates according to the scheduler for VDI clients.
+ This policy setting allows you to configure security intelligence updates according to the scheduler for VDI-configured computers. It is used together with the shared security intelligence location (SharedSignaturesLocation).
+
+ If you enable this policy setting and configure SharedSignaturesLocation, updates from the configured location occur only at the previously configured scheduled update time.
+
+ If you either disable or do not configure this policy setting, updates occur whenever a new security intelligence update is detected at the location that is specified by SharedSignaturesLocation.
+
+ Turn on scan after security intelligence update
+ This policy setting allows you to configure the automatic scan which starts after a security intelligence update has occurred.
+
+ If you enable or do not configure this setting, a scan will start following a security intelligence update.
+
+ If you disable this setting, a scan will not start following a security intelligence update.
+ Allow security intelligence updates when running on battery power
+ This policy setting allows you to configure security intelligence updates when the computer is running on battery power.
+
+ If you enable or do not configure this setting, security intelligence updates will occur as usual regardless of power state.
+
+ If you disable this setting, security intelligence updates will be turned off while the computer is running on battery power.
+ Initiate security intelligence update on startup
+ This policy setting allows you to configure security intelligence updates on startup when there is no antimalware engine present.
+
+ If you enable or do not configure this setting, security intelligence updates will be initiated on startup when there is no antimalware engine present.
+
+ If you disable this setting, security intelligence updates will not be initiated on startup when there is no antimalware engine present.
+ Define the order of sources for downloading security intelligence updates
+ This policy setting allows you to define the order in which different security intelligence update sources should be contacted. The value of this setting should be entered as a pipe-separated string enumerating the security intelligence update sources in order. Possible values are: “InternalDefinitionUpdateServer”, “MicrosoftUpdateServer”, “MMPC”, and “FileShares”
+
+ For example: { InternalDefinitionUpdateServer | MicrosoftUpdateServer | MMPC }
+
+ If you enable this setting, security intelligence update sources will be contacted in the order specified. Once security intelligence updates have been successfully downloaded from one specified source, the remaining sources in the list will not be contacted.
+
+ If you disable or do not configure this setting, security intelligence update sources will be contacted in a default order.
+ Allow security intelligence updates from Microsoft Update
+ This policy setting allows you to enable download of security intelligence updates from Microsoft Update even if the Automatic Updates default server is configured to another download source such as Windows Update.
+
+ If you enable this setting, security intelligence updates will be downloaded from Microsoft Update.
+
+ If you disable or do not configure this setting, security intelligence updates will be downloaded from the configured download source.
+ Allow real-time security intelligence updates based on reports to Microsoft MAPS
+ This policy setting allows you to enable real-time security intelligence updates in response to reports sent to Microsoft MAPS. If the service reports a file as an unknown and Microsoft MAPS finds that the latest security intelligence update has security intelligence for a threat involving that file, the service will receive all of the latest security intelligence for that threat immediately. You must have configured your computer to join Microsoft MAPS for this functionality to work.
+
+ If you enable or do not configure this setting, real-time security intelligence updates will be enabled.
+
+ If you disable this setting, real-time security intelligence updates will disabled.
+ Specify the day of the week to check for security intelligence updates
+ This policy setting allows you to specify the day of the week on which to check for security intelligence updates. The check can also be configured to run every day or to never run at all.
+
+ This setting can be configured with the following ordinal number values:
+ (0x0) Every Day (default)
+ (0x1) Sunday
+ (0x2) Monday
+ (0x3) Tuesday
+ (0x4) Wednesday
+ (0x5) Thursday
+ (0x6) Friday
+ (0x7) Saturday
+ (0x8) Never
+
+ If you enable this setting, the check for security intelligence updates will occur at the frequency specified.
+
+ If you disable or do not configure this setting, the check for security intelligence updates will occur at a default frequency.
+ Never
+ Every Day
+ Sunday
+ Monday
+ Tuesday
+ Wednesday
+ Thursday
+ Friday
+ Saturday
+ Specify the time to check for security intelligence updates
+ This policy setting allows you to specify the time of day at which to check for security intelligence updates. The time value is represented as the number of minutes past midnight (00:00). For example, 120 (0x78) is equivalent to 02:00 AM. By default this setting is configured to check for security intelligence updates 15 minutes before the scheduled scan time. The schedule is based on local time on the computer where the check is occurring.
+
+ If you enable this setting, the check for security intelligence updates will occur at the time of day specified.
+
+ If you disable or do not configure this setting, the check for security intelligence updates will occur at the default time.
+ Allow notifications to disable security intelligence based reports to Microsoft MAPS
+ This policy setting allows you to configure the antimalware service to receive notifications to disable individual security intelligence in response to reports it sends to Microsoft MAPS. Microsoft MAPS uses these notifications to disable security intelligence that are causing false positive reports. You must have configured your computer to join Microsoft MAPS for this functionality to work.
+
+ If you enable this setting or do not configure, the antimalware service will receive notifications to disable security intelligence.
+
+ If you disable this setting, the antimalware service will not receive notifications to disable security intelligence.
+ Define the number of days after which a catch-up security intelligence update is required
+ This policy setting allows you to define the number of days after which a catch-up security intelligence update will be required. By default, the value of this setting is 1 day.
+
+ If you enable this setting, a catch-up security intelligence update will occur after the specified number of days.
+
+ If you disable or do not configure this setting, a catch-up security intelligence update will be required after the default number of days.
+ Specify the interval for expiry notification
+
+ This policy setting allows you to specify an interval(in days) for expiry notification.
+ If a signature expiry or platform expiry is impending, this value tells how soon AM UI will notify customers.
+
+ Value should be greater than zero for the policy to be active.
+
+ Specify the interval to check for security intelligence updates
+ This policy setting allows you to specify an interval at which to check for security intelligence updates. The time value is represented as the number of hours between update checks. Valid values range from 1 (every hour) to 24 (once per day).
+
+ If you enable this setting, checks for security intelligence updates will occur at the interval specified.
+
+ If you disable or do not configure this setting, checks for security intelligence updates will occur at the default interval.
+ Check for the latest virus and spyware security intelligence on startup
+ This policy setting allows you to manage whether a check for new virus and spyware security intelligence will occur immediately after service startup.
+
+ If you enable this setting, a check for new security intelligence will occur after service startup.
+
+ If you disable this setting or do not configure this setting, a check for new security intelligence will not occur after service startup.
+ Configure the 'Block at First Sight' feature
+ This feature ensures the device checks in real time with the Microsoft Active Protection Service (MAPS) before allowing certain content to be run or accessed. If this feature is disabled, the check will not occur, which will lower the protection state of the device.
+ Enabled – The Block at First Sight setting is turned on.
+ Disabled – The Block at First Sight setting is turned off.
+
+ This feature requires these Group Policy settings to be set as follows:
+ MAPS -> The “Join Microsoft MAPS” must be enabled or the “Block at First Sight” feature will not function.
+ MAPS -> The “Send file samples when further analysis is required” should be set to 1 (Send safe samples) or 3 (Send all samples). Setting to 0 (Always Prompt) will lower the protection state of the device. Setting to 2 (Never send) means the “Block at First Sight” feature will not function.
+ Real-time Protection -> The “Scan all downloaded files and attachments” policy must be enabled or the “Block at First Sight” feature will not function.
+ Real-time Protection -> Do not enable the “Turn off real-time protection” policy or the “Block at First Sight” feature will not function.
+ Configure local setting override for reporting to Microsoft MAPS
+ This policy setting configures a local override for the configuration to join Microsoft MAPS. This setting can only be set by Group Policy.
+
+ If you enable this setting, the local preference setting will take priority over Group Policy.
+
+ If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.
+ Send file samples when further analysis is required
+
+ This policy setting configures behaviour of samples submission when opt-in for MAPS telemetry is set.
+
+ Possible options are:
+ (0x0) Always prompt
+ (0x1) Send safe samples automatically
+ (0x2) Never send
+ (0x3) Send all samples automatically
+
+
+ Always prompt
+ Send safe samples
+ Never send
+ Send all samples
+
+ Join Microsoft MAPS
+ This policy setting allows you to join Microsoft MAPS. Microsoft MAPS is the online community that helps you choose how to respond to potential threats. The community also helps stop the spread of new malicious software infections.
+
+ You can choose to send basic or additional information about detected software. Additional information helps Microsoft create new security intelligence and help it to protect your computer. This information can include things like location of detected items on your computer if harmful software was removed. The information will be automatically collected and sent. In some instances, personal information might unintentionally be sent to Microsoft. However, Microsoft will not use this information to identify you or contact you.
+
+ Possible options are:
+ (0x0) Disabled (default)
+ (0x1) Basic membership
+ (0x2) Advanced membership
+
+ Basic membership will send basic information to Microsoft about software that has been detected, including where the software came from, the actions that you apply or that are applied automatically, and whether the actions were successful.
+
+ Advanced membership, in addition to basic information, will send more information to Microsoft about malicious software, spyware, and potentially unwanted software, including the location of the software, file names, how the software operates, and how it has impacted your computer.
+
+ If you enable this setting, you will join Microsoft MAPS with the membership specified.
+
+ If you disable or do not configure this setting, you will not join Microsoft MAPS.
+
+ In Windows 10, Basic membership is no longer available, so setting the value to 1 or 2 enrolls the device into Advanced membership.
+ Disabled
+ Basic MAPS
+ Advanced MAPS
+ Specify threats upon which default action should not be taken when detected
+ This policy setting customize which remediation action will be taken for each listed Threat ID when it is detected during a scan. Threats should be added under the Options for this setting. Each entry must be listed as a name value pair. The name defines a valid Threat ID, while the value contains the action ID for the remediation action that should be taken.
+
+ Valid remediation action values are:
+ 2 = Quarantine
+ 3 = Remove
+ 6 = Ignore
+ Specify threat alert levels at which default action should not be taken when detected
+ This policy setting allows you to customize which automatic remediation action will be taken for each threat alert level.Threat alert levels should be added under the Options for this setting. Each entry must be listed as a name value pair. The name defines a threat alert level. The value contains the action ID for the remediation action that should be taken.
+
+ Valid threat alert levels are:
+ 1 = Low
+ 2 = Medium
+ 4 = High
+ 5 = Severe
+
+ Valid remediation action values are:
+ 2 = Quarantine
+ 3 = Remove
+ 6 = Ignore
+ Enable headless UI mode
+
+ This policy setting allows you to configure whether or not to display AM UI to the users.
+ If you enable this setting AM UI won't be available to users.
+
+ Suppresses reboot notifications
+
+ This policy setting allows user to supress reboot notifications in UI only mode (for cases where UI can't be in lockdown mode).
+
+ If you enable this setting AM UI won't show reboot notifications.
+
+ Suppress all notifications
+ Use this policy setting to specify if you want Microsoft Defender Antivirus notifications to display on clients.
+ If you disable or do not configure this setting, Microsoft Defender Antivirus notifications will display on clients.
+
+ If you enable this setting, Microsoft Defender Antivirus notifications will not display on clients.
+
+ Select cloud protection level
+
+ This policy setting determines how aggressive Microsoft Defender Antivirus will be in blocking and scanning suspicious files.
+
+ If this setting is on, Microsoft Defender Antivirus will be more aggressive when identifying suspicious files to block and scan; otherwise, it will be less aggressive and therefore block and scan with less frequency.
+
+ For more information about specific values that are supported, see the Microsoft Defender Antivirus documentation site.
+
+ Note: This feature requires the "Join Microsoft MAPS" setting enabled in order to function.
+
+ Possible options are:
+ (0x0) Default Microsoft Defender Antivirus blocking level
+ (0x1) Moderate Microsoft Defender Antivirus blocking level, delivers verdict only for high confidence detections
+ (0x2) High blocking level - aggressively block unknowns while optimizing client performance (greater chance of false positives)
+ (0x4) High+ blocking level – aggressively block unknowns and apply additional protection measures (may impact client performance)
+ (0x6) Zero tolerance blocking level – block all unknown executables
+
+ Default blocking level
+ Moderate blocking level
+ High blocking level
+ High+ blocking level
+ Zero tolerance blocking level
+ Configure extended cloud check
+
+ This feature allows Microsoft Defender Antivirus to block a suspicious file for up to 60 seconds, and scan it in the cloud to make sure it's safe.
+
+ The typical cloud check timeout is 10 seconds. To enable the extended cloud check feature, specify the extended time in seconds, up to an additional 50 seconds.
+
+ For example, if the desired timeout is 60 seconds, specify 50 seconds in this setting, which will enable the extended cloud check feature, and will raise the total time to 60 seconds.
+
+ Note: This feature depends on three other MAPS settings - "Configure the 'Block at First Sight' feature; "Join Microsoft MAPS"; "Send file samples when further analysis is required" all need to be enabled.
+
+ Enable file hash computation feature
+
+ Enable or disable file hash computation feature.
+
+ Enabled:
+ When this feature is enabled Microsoft Defender will compute hash value for files it scans.
+
+ Disabled:
+ File hash value is not computed
+
+ Not configured:
+ Same as Disabled.
+
+ Prevent users and apps from accessing dangerous websites
+
+ Enable or disable Microsoft Defender Exploit Guard network protection to prevent employees from using any application to access dangerous domains that may host phishing scams, exploit-hosting sites, and other malicious content on the Internet.
+
+ Enabled:
+ Specify the mode in the Options section:
+ -Block: Users and applications will not be able to access dangerous domains
+ -Audit Mode: Users and applications can connect to dangerous domains, however if this feature would have blocked access if it were set to Block, then a record of the event will be in the event logs.
+
+ Disabled:
+ Users and applications will not be blocked from connecting to dangerous domains.
+
+ Not configured:
+ Same as Disabled.
+
+ Exclude files and paths from Attack Surface Reduction Rules
+
+ Exclude files and paths from Attack Surface Reduction (ASR) rules.
+
+ Enabled:
+ Specify the folders or files and resources that should be excluded from ASR rules in the Options section.
+ Enter each rule on a new line as a name-value pair:
+ - Name column: Enter a folder path or a fully qualified resource name. For example, ""C:\Windows"" will exclude all files in that directory. ""C:\Windows\App.exe"" will exclude only that specific file in that specific folder
+ - Value column: Enter ""0"" for each item
+
+ Disabled:
+ No exclusions will be applied to the ASR rules.
+
+ Not configured:
+ Same as Disabled.
+
+ You can configure ASR rules in the Configure Attack Surface Reduction rules GP setting.
+
+ Apply a list of exclusions to specific attack surface reduction (ASR) rulesd
+
+ This policy allows an administrator to specify a list of exclusions for specific ASR rules.
+ Each entry is a name-value pair. The key indicates the rule GUID, and the value is a set of full paths separated by the > character, indicating the exclusions for that particular ASR rule.
+
+ NOTE: The GUID is a KEY, not a value.
+
+ Example:
+ KEY: "{75668C1F-73B5-4CF0-BB93-3ECF5DB7C484}"
+ VALUE: "C:\Notepad.exe>c:\regedit.exe>C:\SomeFolder\test.exe"
+
+ Configure Attack Surface Reduction rules
+
+ Set the state for each Attack Surface Reduction (ASR) rule.
+
+ After enabling this setting, you can set each rule to the following in the Options section:
+ - Block: the rule will be applied
+ - Audit Mode: if the rule would normally cause an event, then it will be recorded (although the rule will not actually be applied)
+ - Off: the rule will not be applied
+ - Not Configured: the rule is enabled with default values
+ - Warn: the rule will be applied and the end-user will have the option to bypass the block
+
+ Unless the ASR rule is disabled, a subsample of audit events are collected for ASR rules will the value of not configured.
+
+ Enabled:
+ Specify the state for each ASR rule under the Options section for this setting.
+ Enter each rule on a new line as a name-value pair:
+ - Name column: Enter a valid ASR rule ID
+ - Value column: Enter the status ID that relates to state you want to specify for the associated rule
+
+ The following status IDs are permitted under the value column:
+ - 1 (Block)
+ - 0 (Off)
+ - 2 (Audit)
+ - 5 (Not Configured)
+ - 6 (Warn)
+
+
+ Example:
+ xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx 0
+ xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx 1
+ xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx 2
+
+ Disabled:
+ No ASR rules will be configured.
+
+ Not configured:
+ Same as Disabled.
+
+ You can exclude folders or files in the ""Exclude files and paths from Attack Surface Reduction Rules"" GP setting.
+
+ Configure Controlled folder access
+
+ Enable or disable controlled folder access for untrusted applications. You can choose to block, audit, or allow attempts by untrusted apps to:
+ - Modify or delete files in protected folders, such as the Documents folder
+ - Write to disk sectors
+
+ You can also choose to only block or audit writes to disk sectors while still allowing the modification or deletion of files in protected folders.
+
+ Microsoft Defender Antivirus automatically determines which applications can be trusted. You can add additional trusted applications in the Configure allowed applications GP setting.
+ Default system folders are automatically protected, but you can add folders in the Configure protected folders GP setting.
+
+ Block:
+ The following will be blocked:
+ - Attempts by untrusted apps to modify or delete files in protected folders
+ - Attempts by untrusted apps to write to disk sectors
+ The Windows event log will record these blocks under Applications and Services Logs > Microsoft > Windows > Windows Defender > Operational > ID 1123.
+
+
+ Disabled:
+ The following will not be blocked and will be allowed to run:
+ - Attempts by untrusted apps to modify or delete files in protected folders
+ - Attempts by untrusted apps to write to disk sectors
+ These attempts will not be recorded in the Windows event log.
+
+
+ Audit Mode:
+ The following will not be blocked and will be allowed to run:
+ - Attempts by untrusted apps to modify or delete files in protected folders
+ - Attempts by untrusted apps to write to disk sectors
+ The Windows event log will record these attempts under Applications and Services Logs > Microsoft > Windows > Windows Defender > Operational > ID 1124.
+
+
+ Block disk modification only:
+ The following will be blocked:
+ - Attempts by untrusted apps to write to disk sectors
+ The Windows event log will record these attempts under Applications and Services Logs > Microsoft > Windows > Windows Defender > Operational > ID 1123.
+
+ The following will not be blocked and will be allowed to run:
+ - Attempts by untrusted apps to modify or delete files in protected folders
+ These attempts will not be recorded in the Windows event log.
+
+
+ Audit disk modification only:
+ The following will not be blocked and will be allowed to run:
+ - Attempts by untrusted apps to write to disk sectors
+ - Attempts by untrusted apps to modify or delete files in protected folders
+ Only attempts to write to protected disk sectors will be recorded in the Windows event log (under Applications and Services Logs > Microsoft > Windows > Windows Defender > Operational > ID 1124).
+ Attempts to modify or delete files in protected folders will not be recorded.
+
+ Not configured:
+ Same as Disabled.
+
+ Disable (Default)
+ Block
+ Audit Mode
+ Block disk modification only
+ Audit disk modification only
+ Configure allowed applications
+
+ Add additional applications that should be considered "trusted" by controlled folder access.
+
+ These applications are allowed to modify or delete files in controlled folder access folders.
+
+ Microsoft Defender Antivirus automatically determines which applications should be trusted. You can configure this setting to add additional applications.
+
+ Enabled:
+ Specify additional allowed applications in the Options section..
+
+ Disabled:
+ No additional applications will be added to the trusted list.
+
+ Not configured:
+ Same as Disabled.
+
+ You can enable controlled folder access in the Configure controlled folder access GP setting.
+
+ Default system folders are automatically guarded, but you can add folders in the configure protected folders GP setting.
+
+ Configure protected folders
+
+ Specify additional folders that should be guarded by the Controlled folder access feature.
+
+ Files in these folders cannot be modified or deleted by untrusted applications.
+
+ Default system folders are automatically protected. You can configure this setting to add additional folders.
+ The list of default system folders that are protected is shown in Windows Security.
+
+ Enabled:
+ Specify additional folders that should be protected in the Options section.
+
+ Disabled:
+ No additional folders will be protected.
+
+ Not configured:
+ Same as Disabled.
+
+ You can enable controlled folder access in the Configure controlled folder access GP setting.
+
+ Microsoft Defender Antivirus automatically determines which applications can be trusted. You can add additional trusted applications in the Configure allowed applications GP setting.
+
+ Define device control policy groups
+
+ Please follow the device control policy groups xml schema to fill out the policy groups data.
+ Alternatively you could use a file path containing the XML groups data.
+
+ Define device control policy rules
+
+ Please follow the device control policy rules xml schema to fill out the policy rules data.
+ Alternatively you could use a file path containing the XML rules data.
+
+ Select the channel for Microsoft Defender monthly platform updates
+ Enable this policy to specify when devices receive Microsoft Defender platform updates during the monthly gradual rollout.
+
+ Beta Channel: Devices set to this channel will be the first to receive new updates. Select Beta Channel to participate in identifying and reporting issues to Microsoft. Devices in the Windows Insider Program are subscribed to this channel by default. For use in (manual) test environments only and a limited number of devices.
+ Current Channel (Preview): Devices set to this channel will be offered updates earliest during the monthly gradual release cycle. Suggested for pre-production/validation environments.
+ Current Channel (Staged): Devices will be offered updates after the monthly gradual release cycle. Suggested to apply to a small, representative part of your production population (~10%).
+ Current Channel (Broad): Devices will be offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in your production population (~10-100%).
+ Critical - Time delay: Devices will be offered updates with a 48-hour delay. Suggested for critical environments only.
+
+ If you disable or do not configure this policy, the device will stay up to date automatically during the gradual release cycle. Suitable for most devices.
+
+ Select the channel for Microsoft Defender monthly engine updates
+ Enable this policy to specify when devices receive Microsoft Defender engine updates during the monthly gradual rollout.
+
+ Beta Channel: Devices set to this channel will be the first to receive new updates. Select Beta Channel to participate in identifying and reporting issues to Microsoft. Devices in the Windows Insider Program are subscribed to this channel by default. For use in (manual) test environments only and a limited number of devices.
+ Current Channel (Preview): Devices set to this channel will be offered updates earliest during the monthly gradual release cycle. Suggested for pre-production/validation environments.
+ Current Channel (Staged): Devices will be offered updates after the monthly gradual release cycle. Suggested to apply to a small, representative part of your production population (~10%).
+ Current Channel (Broad): Devices will be offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in your production population (~10-100%).
+ Critical - Time delay: Devices will be offered updates with a 48-hour delay. Suggested for critical environments only.
+
+ If you disable or do not configure this policy, the device will stay up to date automatically during the gradual release cycle. Suitable for most devices.
+
+ Select the channel for Microsoft Defender daily security intelligence updates
+ Enable this policy to specify when devices receive Microsoft Defender security intelligence updates during the daily gradual rollout.
+
+ Current Channel (Staged): Devices will be offered updates after the release cycle. Suggested to apply to a small, representative part of production population (~10%).
+ Current Channel (Broad): Devices will be offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in your production population (~10-100%).
+ Critical - Time delay: Devices will be offered updates with a 48-hour delay. Suggested for critical environments only.
+
+ If you disable or do not configure this policy, the device will stay up to date automatically during the daily release cycle. Suitable for most devices.
+
+ Beta Channel
+ Current Channel (Preview)
+ Current Channel (Staged)
+ Current Channel (Broad)
+ Critical - Time delay
+ Disable gradual rollout of Microsoft Defender updates.
+ Enable this policy to disable gradual rollout of Defender updates.
+
+ Current Channel (Broad): Devices set to this channel will be offered updates last during the gradual release cycle. Best for datacenter machines that only receive limited updates.
+
+ Note: This setting applies to both monthly as well as daily Defender updates and will override any previously configured channel selections for platform and engine updates.
+
+ If you disable or do not configure this policy, the device will remain in Current Channel (Default) unless specified otherwise in specific channels for platform and engine updates. Stay up to date automatically during the gradual release cycle. Suitable for most devices.
+ Select Device Control Default Enforcement Policy
+
+ Default Allow: Choosing this default enforcement, will Allow any operations to occur on the attached devices if no policy rules are found to match.
+ Default Deny: Choosing this default enforcement, will Deny any operations to occur on the attached devices if no policy rules are found to match.
+
+ Default Enforcement will establish what decision should be made during the Device Control access checks when none of the policy rules match.
+
+ Default Allow
+ Default Deny
+ Define Device Control evidence data remote location
+
+ Define evidence file remote location, where Device Control service will move evidence data captured.
+
+ When configuring this setting, ensure that Device Control is Enabled and that the provided path is a remote path the user can access.
+
+ Set the retention period for files in the local device control cache
+
+ This policy setting determines how long device control retains files for evidence in its local cache on the device. Device control keeps a file in its local cache only if it is unable to upload the file to a designated network share or Azure storage.
+
+ By default, device control retains files in its local cache for 60 days.
+
+ Turn on device control for specific device types
+
+ This policy setting controls which device types, identified by their PrimaryIds, will have device control protection turned on. If you enable this setting for certain device types, device control will regulate access to those devices based on the corresponding custom policy. Device control will be turned off for all other types of supported devices, even if custom protection policies are configured for those devices.
+
+ This setting currently supports these device types: RemovableMediaDevices, CdRomDevices, WpdDevices, and PrinterDevices.
+
+ If you enable this policy setting but do not specify any PrimaryIds, device control will be turned off across all supported device types.
+
+ If you disable or don’t configure this policy setting, device control will be enforced on all supported devicesbased on their corresponding custom policies.
+
+ Set up a support link for device control notifications
+
+ This setting enables your organization to specify the ‘Get Support’ link in device control notifications.
+
+ When configured, the ‘Get Support” button automatically navigates to the specified link.
+
+ Set the policy refresh rate
+
+ This setting defines the interval, in minutes, at which the device will retry loading the policy configuration in the case that an error has occurred and the policy could not load.
+
+ Set the Azure AD refresh rate
+
+ This setting defines the interval, in minutes, at which the device will query Azure AD to update related settings, configuration, and group memberships.
+
+ Set the data duplication limit (MB)
+
+ This setting defines the maximum amount of data that can be duplicated for device control.
+
+ When the limit is reached, files that are copied to removable storage will not be duplicated on the machine.
+
+ Device Control
+
+ Enable or Disable Defender Device Control on this machine.
+ Note: You must be enrolled as E3 or E5 in order for Device Control to be enabled.
+
+ Intel TDT Integration Level
+ This policy setting configures the Intel TDT integration level for Intel TDT-capable devices.
+
+ If you do not configure this setting, the default value will be applied. The default value is controlled by Microsoft security intelligence updates. Microsoft will enable Intel TDT if there is a known threat.
+ If you configure this setting to enabled, Intel TDT integration will turn on.
+ If you configure this setting to disabled, Intel TDT integration will turn off.
+ Enable EDR in block mode
+ This policy setting enables or disables EDR in block mode (also known as "passive remediation"). EDR in block mode is recommended for devices running Microsoft Defender Antivirus in passive mode. Available with platform release: 4.18.2202.X
+
+ The data type is integer
+
+ Supported values:
+
+ 1: Turn EDR in block mode on
+ 0: Turn EDR in block mode off
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+ Extension Exclusions
+
+
+ Path Exclusions
+
+
+ Process Exclusions
+
+
+ IP Address Exclusions
+
+
+ Specify additional definition sets for network traffic inspection
+
+
+ Configure removal of items from Quarantine folder
+
+
+ Define the maximum size of downloaded files and attachments to be scanned
+
+
+ Configure monitoring for incoming and outgoing file and program activity
+
+
+ Specify the state of Remote Encryption Protection
+
+
+ Specify how long to block detections for, in minutes
+
+
+ Specify how aggressively Remote Encryption Protection blocks threats
+
+
+ Remote Encryption Protection Exclusions
+
+
+ Specify the state of Brute-Force Protection
+
+
+ Specify how long to block detections for, in minutes
+
+
+ Specify how aggressively Brute-Force Protection blocks threats
+
+
+ Brute-Force Protection Exclusions
+
+
+ Specify the day of the week to run a scheduled full scan to complete remediation
+
+
+ Specify the time of day to run a scheduled full scan to complete remediation
+
+
+ Specify how many days without scans should pass before an aggressive quick scan is triggered
+
+
+ Define the number of scheduled scans that can be missed after which a catch-up scan is forced
+
+
+ Configure time out for detections requiring additional action
+
+
+ Configure time out for detections in critically failed state
+
+
+ Configure time out for detections in non-critical failed state
+
+
+ Configure time out for detections in recently remediated state
+
+
+ Configure Windows software trace preprocessor components
+
+
+ Configure WPP tracing level
+
+
+ Configure time interval for service health reports
+
+
+ Specify the maximum depth to scan archive files
+
+
+ Specify the maximum size of archive files to be scanned
+
+
+ Specify the maximum percentage of CPU utilization during a scan
+
+
+ Turn on removal of items from scan history folder
+
+
+ Specify the interval to run quick scans per day
+
+
+ Specify the scan type to use for a scheduled scan
+
+
+ Specify the day of the week to run a scheduled scan
+
+
+ Specify the time for a daily quick scan
+
+
+ Specify the time of day to run a scheduled scan
+
+
+ Define the number of days before spyware security intelligence is considered out of date
+
+
+ Define the number of days before virus security intelligence is considered out of date
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+ Specify the day of the week to check for security intelligence updates
+
+
+ Specify the time to check for security intelligence updates
+
+
+ Define the number of days after which a catch-up security intelligence update is required
+
+
+ Specify the interval to check for security intelligence updates
+
+
+ Join Microsoft MAPS
+
+
+ Send file samples when further analysis is required
+
+
+ Specify threats upon which default action should not be taken when detected
+
+
+ Specify threat alert levels at which default action should not be taken when detected
+
+
+ Specify the interval for expiry notification
+
+
+ Select cloud blocking level
+
+
+ Specify the extended cloud check time in seconds
+
+
+ Configure the guard my folders feature
+
+
+ Exclusions from ASR rules:
+
+
+ Exclusions for each ASR rules:
+
+
+ Set the state for each ASR rule:
+
+
+ Enter the applications that should be trusted:
+
+
+ Enter the folders that should be guarded:
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+ Specify scheduler randomization window in hours.
+
+
+ Select the channel for Microsoft Defender monthly platform updates:
+
+
+ Select the channel for Microsoft Defender monthly engine updates:
+
+
+ Select the channel for Microsoft Defender daily security intelligence updates:
+
+
+ Select Device Control Default Enforcement Policy
+
+
+
+
+
+
+
+ Set the retention period for files in the local device control cache
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
diff --git a/config/admx/kdc.admx b/config/admx/kdc.admx
index 142b0ed..b42a7dc 100644
--- a/config/admx/kdc.admx
+++ b/config/admx/kdc.admx
@@ -1,233 +1,233 @@
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+