Endpoint configuration · GraphQL type

ComputerAdministrativeTemplates type

Computer-specific Administrative Templates (ADMX) settings on an Endpoint.

Fields

Field Name Description
noLockScreenCamera - Boolean Whether the camera is disabled on the lock screen.
noLockScreenSlideshow - Boolean Whether the lock screen slideshow is disabled.
allowInputPersonalization - Boolean Whether speech, inking, and typing personalization is allowed.
allowOnlineTips - Boolean Whether online tips and help for the Settings app are allowed.
rpcAuthnLevelPrivacyEnabled - Boolean Whether RPC authentication level privacy is enabled for packet forwarding.
smbV1ClientDriverStart - Boolean Whether the SMBv1 client driver is started.
smbV1Server - Boolean Whether the SMBv1 server protocol is enabled.
disableExceptionChainValidation - Boolean Whether Structured Exception Handling Overwrite Protection (SEHOP) is disabled.
nodeType - NetBTNodeType NetBT node type for NetBIOS over TCP/IP name resolution.
useLogonCredential - Boolean Whether WDigest credentials are stored in memory by the credential manager.
enableCertPaddingCheck - Boolean Whether strict Authenticode signature verification (EnableCertPaddingCheck) is enforced for Portable Executable files, mitigating CVE-2013-3900.
enableCertPaddingCheckWow6432Node - Boolean Whether the Authenticode certificate padding check is also enforced for the 32-bit subsystem on a 64-bit OS (Wow6432Node registry view).
autoAdminLogon - Boolean Whether automatic admin logon is enabled.
disableAutoSourceRouting - SourceRouting IPv6 source routing protection level.
disableIpSourceRouting - SourceRouting IPv4 source routing protection level.
disableSavePassword - Boolean Whether saving passwords in the Remote Desktop connection is disabled.
enableICMPRedirect - Boolean Whether ICMP redirects can override OSPF-generated routes.
keepAliveTime - Duration TCP keep-alive interval duration.
noNameReleaseOnDemand - Boolean Whether the computer releases its NetBIOS name on request.
performRouterDiscovery - Boolean Whether IRDP router discovery is performed.
safeDllSearchMode - Boolean Whether Safe DLL search mode is enabled for the DLL search order.
screenSaverGracePeriod - Duration Grace period before the screen saver password takes effect.
tcpMaxDataRetransmissionsIpv6 - Uint64 Maximum TCP data retransmissions over IPv6.
tcpMaxDataRetransmissionsIpv4 - Uint64 Maximum TCP data retransmissions over IPv4.
eventLogWarningLevel - Uint64 Warning level threshold for the security event log.
enableMulticast - Boolean Whether multicast name resolution (LLMNR) is enabled.
disableIPv6DefaultDnsServers - Boolean Whether the DNS client's built-in default IPv6 DNS server addresses are disabled (DisableIPv6DefaultDnsServers).
enableFrontProviders - Boolean Whether front-end font providers are enabled.
allowInsecureGuestAuth - Boolean Whether insecure guest logons to an SMB server are allowed.
lanmanServerAuditClientDoesNotSupportEncryption - Boolean Whether the SMB server audits clients that do not support encryption.
lanmanServerAuditClientDoesNotSupportSigning - Boolean Whether the SMB server audits clients that do not support signing.
lanmanServerAuditInsecureGuestLogon - Boolean Whether the SMB server audits insecure guest logons.
lanmanServerEnableAuthRateLimiter - Boolean Whether the SMB server authentication rate limiter is enabled.
lanmanServerEnableMailslots - Boolean Whether SMB server mailslots are enabled.
lanmanServerMinSmb2Dialect - SMBVersion Minimum SMB2 dialect version for the SMB server.
lanmanServerInvalidAuthDelayTime - Duration Delay duration for invalid authentication attempts on the SMB server.
lanmanWorkstationAuditInsecureGuestLogon - Boolean Whether the SMB workstation audits insecure guest logons.
lanmanWorkstationAuditServerDoesNotSupportEncrypt - Boolean Whether the SMB workstation audits servers that do not support encryption.
lanmanWorkstationAuditServerDoesNotSupportSigning - Boolean Whether the SMB workstation audits servers that do not support signing.
lanmanWorkstationEnableMailslots - Boolean Whether SMB workstation mailslots are enabled.
lanmanWorkstationMinSmb2Dialect - SMBVersion Minimum SMB2 dialect version for the SMB workstation.
lanmanWorkstationRequireEncryption - Boolean Whether the SMB workstation requires encryption.
allowLLTDIOOnDomain - Boolean Whether LLTDIO responder is allowed on a domain network.
allowLLTDIOOnPublicNet - Boolean Whether LLTDIO responder is allowed on a public network.
enableLLTDIO - Boolean Whether the LLTDIO driver is enabled.
prohibitLLTDIOOnPrivateNet - Boolean Whether LLTDIO responder is prohibited on a private network.
allowRspndrOnDomain - Boolean Whether the Responder (RSPNDR) driver is allowed on a domain network.
allowRspndrOnPublicNet - Boolean Whether the Responder (RSPNDR) driver is allowed on a public network.
enableRspndr - Boolean Whether the Responder (RSPNDR) driver is enabled.
prohibitRspndrOnPrivateNet - Boolean Whether the Responder (RSPNDR) driver is prohibited on a private network.
p2PNetworkServicesDisabled - Boolean Whether peer-to-peer network services are disabled.
ncAllowNetBridgeNla - Boolean Whether Network Bridge can be installed and configured on a domain network.
ncShowSharedAccessUi - Boolean Whether the shared access UI for Internet Connection Sharing is shown.
hardenedPathsNetlogon - String UNC hardened access path configuration for NETLOGON share.
hardenedPathsSysvol - String UNC hardened access path configuration for SYSVOL share.
disabledComponents - Uint64 IPv6 disabled components bitmask.
enableRegistrars - Boolean Whether WCN registrars are enabled for wireless network configuration.
disableFlashConfigRegistrar - Boolean Whether the WCN Flash Config registrar is disabled.
disableInBand802DOT11Registrar - Boolean Whether the WCN In-Band 802.11 registrar is disabled.
disableUPnPRegistrar - Boolean Whether the WCN UPnP registrar is disabled.
disableWPDRegistrar - Boolean Whether the WCN WPD registrar is disabled.
disableWcnUi - Boolean Whether the Windows Connect Now UI is disabled.
fMininimizeConnections - SimultaneousConnectionType Policy for minimizing simultaneous network connections.
autoConnectAllowedOEM - Boolean Whether automatic connection to suggested open Wi-Fi hotspots is allowed.
registerSpoolerRemoteRpcEndPoint - Boolean Whether the Print Spooler accepts remote RPC connections.
redirectionguardPolicy - RedirectionGuardPolicy Printer redirection guard policy.
rpcUseNamedPipeProtocol - RpcUseNamedPipeProtocol RPC protocol used for outgoing printer connections.
rpcAuthentication - RpcAuthentication RPC connection authentication setting for printers.
rpcProtocols - RpcProtocols Allowed RPC protocols for incoming printer connections.
forceKerberosForRpc - ForceKerberosForRpc Whether Kerberos is forced for RPC printer connections.
rpcTcpPort - Uint64 TCP port used for RPC printer connections.
restrictDriverInstallationToAdministrators - Boolean Whether print driver installation is restricted to administrators.
copyFilesPolicy - CopyFilesPolicy Policy for copying files during Point and Print installation.
noWarningNoElevationOnInstall - NoWarningNoElevationOnInstall Warning and elevation behavior for Point and Print driver installation.
updatePromptSettings - UpdatePromptSettings Warning and elevation behavior for Point and Print driver updates.
requireIPPs - Boolean Whether IPP (Internet Printing Protocol) printers must use IPPS (IPP over TLS/SSL).
windowsProtectedPrintGroupPolicyState - Boolean Whether Windows protected print mode (Mopria-certified drivers only) is enabled.
securityFlagsBlockUnknownCA - Boolean Whether the IPP TLS/SSL security policy blocks printers presenting a certificate from an unknown certificate authority.
securityFlagsBlockCertWrongUsage - Boolean Whether the IPP TLS/SSL security policy blocks printers presenting a non-server certificate (wrong certificate usage).
securityFlagsBlockCertCNInvalid - Boolean Whether the IPP TLS/SSL security policy blocks printers presenting a certificate with an invalid common name.
securityFlagsBlockCertDateInvalid - Boolean Whether the IPP TLS/SSL security policy blocks printers presenting a certificate with an invalid (expired or not yet valid) date.
noCloudApplicationNotification - Boolean Whether cloud-based app notifications are disabled.
processCreationIncludeCmdLineEnabled - Boolean Whether command line data is included in process creation audit events.
allowEncryptionOracle - AllowEncryptionOracle CredSSP encryption oracle remediation policy.
allowProtectedCreds - Boolean Whether restricted admin and remote Credential Guard mode connections are allowed.
enableVirtualizationBasedSecurity - Boolean Whether Virtualization Based Security (VBS) is enabled.
requirePlatformSecurityFeatures - RequirePlatformSecurityFeatures Platform security features required for Virtualization Based Security.
hypervisorEnforcedCodeIntegrity - HypervisorEnforcedCodeIntegrity Hypervisor-enforced Code Integrity (HVCI) policy.
hvcimatRequired - Boolean Whether HVCI requires memory attributes table (MAT) support.
lsaCfgFlags - CredentialIsolation Credential Guard (LSA isolation) configuration flags.
configureSystemGuardLaunch - SystemGuardLaunch System Guard Secure Launch configuration.
configureKernelShadowStacksLaunch - KernelShadowStacksLaunch Kernel-mode Hardware-enforced Stack Protection configuration.
denyDeviceIds - Boolean Whether devices matching specific hardware IDs are denied installation.
denyDeviceClasses - Boolean Whether installation of devices using drivers that match the configured device setup classes is prevented (DenyDeviceClasses).
denyDeviceClassesList - [String!] Device setup class GUIDs that Windows is prevented from installing drivers for, e.g. the IEEE 1394 device setup classes.
denyDeviceClassesRetroactive - Boolean Whether the device setup class installation restrictions also apply to devices that were already installed (DenyDeviceClassesRetroactive).
preventDeviceMetadataFromNetwork - Boolean Whether device metadata retrieval from the internet is prevented.
driverLoadPolicy - DriverLoadPolicy Boot-start driver initialization policy for Early Launch Antimalware.
clfsAuthenticationChecking - Boolean Whether Common Log File System (CLFS) logfile authentication is enabled (ClfsAuthenticationChecking).
sudoEnabled - SudoBehavior Behavior of the sudo.exe command line tool. See SudoBehavior.
enableCdp - Boolean Whether Connected Devices Platform (CDP) is enabled.
noUseStoreOpenWith - Boolean Whether the "Look for an app in the Store" option is disabled for unknown file types.
disableWebPnPDownload - Boolean Whether downloading of print drivers over HTTP is disabled.
preventHandwritingDataSharing - Boolean Whether sharing of handwriting recognition personalization data is prevented.
preventHandwritingErrorReports - Boolean Whether handwriting recognition error reports are prevented.
exitOnMSICW - Boolean Whether the Internet Connection Wizard is skipped if the internet connection already exists.
noWebServices - Boolean Whether Windows web services for device operations are disabled.
disableHTTPPrinting - Boolean Whether HTTP printing is disabled.
noRegistration - Boolean Whether Windows registration is disabled.
disableContentFileUpdates - Boolean Whether automatic updates of content files used by Windows are disabled.
noOnlinePrintsWizard - Boolean Whether the Online Prints Wizard is disabled.
noPublishingWizard - Boolean Whether the Web Publishing and Online Ordering Wizards are disabled.
ceip - Boolean Whether the Customer Experience Improvement Program is enabled.
ceipEnable - Boolean Whether the Customer Experience Improvement Program data collection is enabled.
windowsErrorReportingDisabled - Boolean Whether Windows Error Reporting is disabled.
pcHealthErrorReportingDoReport - Boolean Whether PC Health error reporting is enabled.
devicePKInitBehavior - DevicePKInitBehavior Device PKInit authentication behavior for Kerberos.
devicePKInitEnabled - Boolean Whether device PKInit during Kerberos authentication is enabled.
deviceEnumerationPolicy - DeviceEnumerationPolicy DMA Guard device enumeration policy for external DMA-capable devices.
allowCustomSSPsAPs - Boolean Whether custom Security Support Providers and Authentication Packages can be loaded into LSASS.
runAsPPL - RunAsPPL LSA Protection (Protected Process Light) configuration.
blockUserInputMethodsForSignIn - Boolean Whether input methods not specific to the user are blocked at sign-in.
blockUserFromShowingAccountDetailsOnSignin - Boolean Whether the user is blocked from showing account details on the sign-in screen.
dontDisplayNetworkSelectionUI - Boolean Whether the network selection UI is hidden on the logon screen.
disableLockScreenAppNotifications - Boolean Whether app notifications are disabled on the lock screen.
allowDomainPINLogon - Boolean Whether domain PIN logon is allowed.
allowCrossDeviceClipboard - Boolean Whether cross-device clipboard synchronization is allowed.
uploadUserActivities - Boolean Whether user activities are uploaded to the cloud.
allowNetworkConDuringStandbyOnBattery - Boolean Whether network connectivity during connected standby on battery is allowed.
allowNetworkConDuringStandbyPluggedIn - Boolean Whether network connectivity during connected standby when plugged in is allowed.
allowStandbyStatesWhenSleeping - Boolean Whether standby states (S1-S3) are allowed when sleeping on battery.
allowStandbyStatesWhenPluggedIn - Boolean Whether standby states (S1-S3) are allowed when plugged in.
requirePasswordOnWakeOnBattery - Boolean Whether a password is required when waking from sleep on battery.
requirePasswordOnWakeWhenPluggedIn - Boolean Whether a password is required when waking from sleep while plugged in.
fAllowUnsolicited - Boolean Whether unsolicited Remote Assistance offers are allowed.
fAllowToGetHelp - Boolean Whether users can request Remote Assistance.
enableAuthEpResolution - Boolean Whether authenticated RPC endpoint resolution is enabled.
restrictRemoteClients - RestrictRemoteClients RPC remote client restriction policy.
disableQueryRemoteServer - Boolean Whether querying of a remote server for DNS client events is disabled.
scenarioExecutionEnabled - Boolean Whether diagnostic scenario execution is enabled.
disabledByGroupPolicy - Boolean Whether Scheduled Task creation is disabled by Group Policy.
ntpClientEnabled - Boolean Whether the Windows NTP client is enabled.
systemAllowEncryptionOracle - Boolean Whether the system-level CredSSP encryption oracle remediation is enabled.
allowSharedLocalAppData - Boolean Whether apps can share application data between users.
blockNonAdminUserInstall - Boolean Whether non-admin users are blocked from installing packaged apps.
disablePerUserUnsignedPackagesByDefault - Boolean Whether per-user unsigned Windows App packages are prevented from installing by default (DisablePerUserUnsignedPackagesByDefault).
letAppsActivateWithVoiceAboveLock - LetAppsActivateWithVoice Voice activation above lock screen policy for apps.
msaOptional - Boolean Whether a Microsoft account is optional for modern apps.
blockHostedAppAccessWinRT - Boolean Whether hosted apps can access the Windows Runtime.
noAutoplayfornonVolume - Boolean Whether autoplay is disabled for non-volume MTP devices.
noAutorun - NoAutoRun Autorun default behavior.
noDriveTypeAutoRun - NoDriveTypeAutoRun Drive types for which autorun is disabled.
enhancedAntiSpoofing - Boolean Whether enhanced anti-spoofing for Windows Hello face authentication is enabled.
fdvDiscoveryVolumeType - Boolean Whether BitLocker discovery volume type is configured for fixed data drives.
fdvRecovery - Boolean Whether BitLocker recovery options for fixed data drives are configured.
fdvManageDRA - ManageDRA BitLocker Data Recovery Agent policy for fixed data drives.
fdvRecoveryPassword - RecoveryPasswordOption BitLocker recovery password option for fixed data drives.
fdvRecoveryKey - RecoveryPasswordOption BitLocker recovery key option for fixed data drives.
fdvHideRecoveryPage - HideRecoveryPage Whether the BitLocker recovery page is hidden for fixed data drives.
fdvActiveDirectoryBackup - ADBackup Whether BitLocker recovery info is backed up to AD DS for fixed data drives.
fdvActiveDirectoryInfoToStore - ADInfoToStore Type of BitLocker recovery info stored in AD DS for fixed data drives.
fdvRequireActiveDirectoryBackup - RequireADBackup Whether AD DS backup is required before enabling BitLocker on fixed data drives.
fdvHardwareEncryption - Boolean Whether hardware-based encryption is used for fixed data drives.
fdvPassphrase - Boolean Whether passphrase unlock is allowed for fixed data drives.
fdvAllowUserCert - Boolean Whether user certificate unlock is allowed for fixed data drives.
fdvEnforceUserCert - EnforceUserCert Whether a user certificate is enforced for fixed data drive unlock.
useEnhancedPin - Boolean Whether enhanced PIN is allowed for BitLocker startup.
osAllowSecureBootForIntegrity - Boolean Whether Secure Boot is allowed for BitLocker OS drive integrity validation.
osRecovery - Boolean Whether BitLocker recovery options for the OS drive are configured.
osManageDRA - ManageDRA BitLocker Data Recovery Agent policy for the OS drive.
osRecoveryPassword - RecoveryPasswordOption BitLocker recovery password option for the OS drive.
osRecoveryKey - RecoveryPasswordOption BitLocker recovery key option for the OS drive.
osHideRecoveryPage - HideRecoveryPage Whether the BitLocker recovery page is hidden for the OS drive.
osActiveDirectoryBackup - ADBackup Whether BitLocker recovery info is backed up to AD DS for the OS drive.
osActiveDirectoryInfoToStore - ADInfoToStore Type of BitLocker recovery info stored in AD DS for the OS drive.
osRequireActiveDirectoryBackup - RequireADBackup Whether AD DS backup is required before enabling BitLocker on the OS drive.
osHardwareEncryption - Boolean Whether hardware-based encryption is used for the OS drive.
osPassphrase - Boolean Whether passphrase unlock is allowed for the OS drive.
useAdvancedStartup - Boolean Whether additional authentication at startup is required for BitLocker.
enableBDEWithNoTPM - Boolean Whether BitLocker can be enabled without a compatible TPM.
rdvDiscoveryVolumeType - Boolean Whether BitLocker discovery volume type is configured for removable data drives.
rdvRecovery - Boolean Whether BitLocker recovery options for removable data drives are configured.
rdvManageDRA - ManageDRA BitLocker Data Recovery Agent policy for removable data drives.
rdvRecoveryPassword - RecoveryPasswordOption BitLocker recovery password option for removable data drives.
rdvRecoveryKey - RecoveryPasswordOption BitLocker recovery key option for removable data drives.
rdvHideRecoveryPage - HideRecoveryPage Whether the BitLocker recovery page is hidden for removable data drives.
rdvActiveDirectoryBackup - ADBackup Whether BitLocker recovery info is backed up to AD DS for removable data drives.
rdvActiveDirectoryInfoToStore - ADInfoToStore Type of BitLocker recovery info stored in AD DS for removable data drives.
rdvRequireActiveDirectoryBackup - RequireADBackup Whether AD DS backup is required before enabling BitLocker on removable data drives.
rdvHardwareEncryption - Boolean Whether hardware-based encryption is used for removable data drives.
rdvPassphrase - Boolean Whether passphrase unlock is allowed for removable data drives.
rdvAllowUserCert - Boolean Whether user certificate unlock is allowed for removable data drives.
rdvEnforceUserCert - EnforceUserCert Whether a user certificate is enforced for removable data drive unlock.
rdvDenyCrossOrg - Boolean Whether cross-organization BitLocker access for removable data drives is denied.
rdvDenyWriteAccess - Boolean Whether write access to removable data drives not protected by BitLocker is denied.
disableExternalDMAUnderLock - Boolean Whether external DMA is blocked when the device is locked.
allowCamera - Boolean Whether the camera is allowed.
disableConsumerAccountStateContent - Boolean Whether consumer account state content is disabled in cloud settings.
disableCloudOptimizedContent - Boolean Whether cloud-optimized content is disabled.
disableWindowsConsumerFeatures - Boolean Whether Windows consumer features like Start suggestions and notifications are disabled.
requirePinForPairing - RequirePinForPairing PIN requirement for wireless display pairing.
disablePasswordReveal - Boolean Whether the password reveal button is disabled.
enumerateAdministrators - Boolean Whether administrator accounts are enumerated during elevation.
noLocalPasswordResetQuestions - Boolean Whether local password reset security questions are disabled.
allowTelemetry - AllowTelemetry Windows diagnostic and usage data telemetry level.
disableEnterpriseAuthProxy - Boolean Whether the authenticated proxy for Connected User Experience and Telemetry is disabled.
disableOneSettingsDownloads - Boolean Whether OneSettings downloads are disabled.
doNotShowFeedbackNotifications - Boolean Whether feedback notifications are hidden.
enableOneSettingsAuditing - Boolean Whether OneSettings auditing is enabled.
limitDiagnosticLogCollection - Boolean Whether diagnostic log collection is limited.
limitDumpCollection - Boolean Whether dump collection is limited.
allowBuildPreview - Boolean Whether Insider Preview builds are allowed.
doDownloadMode - DODownloadMode Delivery Optimization download mode.
disableAPISamping - Boolean Whether App and Device Inventory API sampling data is prevented from being sent to Microsoft. Note: the backing registry value name DisableAPISamping is Microsoft's typo and is correct.
disableApplicationFootprint - Boolean Whether App and Device Inventory Application Footprint data is prevented from being sent to Microsoft.
disableInstallTracing - Boolean Whether App and Device Inventory Install Tracing data is prevented from being sent to Microsoft.
enableAppInstaller - Boolean Whether the App Installer is enabled.
enableExperimentalFeatures - Boolean Whether experimental App Installer features are enabled.
enableHashOverride - Boolean Whether hash override for App Installer is enabled.
enableMSAppInstallerProtocol - Boolean Whether the ms-appinstaller protocol is enabled.
enableLocalArchiveMalwareScanOverride - Boolean Whether the App Installer local archive malware scan can be overridden.
enableBypassCertificatePinningForMicrosoftStore - Boolean Whether App Installer certificate pinning validation for Microsoft Store sources can be bypassed.
enableWindowsPackageManagerCommandLineInterfaces - Boolean Whether the Windows Package Manager (winget) command line interfaces are enabled.
eventLogApplicationRetention - Boolean Whether event log retention is enabled for the Application log.
eventLogApplicationMaxSize - Uint64 Maximum size in KB of the Application event log.
eventLogSecurityRetention - Boolean Whether event log retention is enabled for the Security log.
eventLogSecurityMaxSize - Uint64 Maximum size in KB of the Security event log.
eventLogSetupRetention - Boolean Whether event log retention is enabled for the Setup log.
eventLogSetupMaxSize - Uint64 Maximum size in KB of the Setup event log.
eventLogSystemRetention - Boolean Whether event log retention is enabled for the System log.
eventLogSystemMaxSize - Uint64 Maximum size in KB of the System event log.
noDataExecutionPreventionForExplorer - Boolean Whether Data Execution Prevention for Windows Explorer is disabled.
disableGraphRecentItems - Boolean Whether Activity History (recent items in Microsoft Graph) is disabled.
noHeapTerminationOnCorruption - Boolean Whether heap termination on corruption for Windows Explorer is disabled.
hideRecommendedPersonalizedSites - Boolean Whether personalized website recommendations are removed from the Recommended section of the Start Menu (HideRecommendedPersonalizedSites).
disableMotWOnInsecurePathCopy - Boolean Whether the Mark of the Web tag is not applied to files copied from insecure sources (DisableMotWOnInsecurePathCopy).
preXPSP2ShellProtocolBehavior - Boolean Whether shell protocol protected mode is turned off (PreXPSP2ShellProtocolBehavior), allowing applications to open any folder rather than a limited set.
disableHomeGroup - Boolean Whether HomeGroup is disabled.
disableLocation - Boolean Whether the Windows location framework is disabled.
allowMessageSync - Boolean Whether text message synchronization is allowed.
disableUserAuth - Boolean Whether user authentication for Defender network inspection is disabled.
localSettingOverrideSpynetReporting - Boolean Whether local setting override for SpyNet (MAPS) reporting is enabled.
spynetReporting - Boolean Whether Microsoft MAPS (SpyNet) cloud-based protection reporting is enabled.
exploitGuardASRRules - Boolean Whether Defender Exploit Guard Attack Surface Reduction rules are enabled.
enableNetworkProtection - EnableNetworkProtection Defender network protection mode.
enableFileHashComputation - Boolean Whether Defender file hash computation for every scanned file is enabled.
disableIOAVProtection - Boolean Whether Defender scanning of downloaded files and attachments is disabled.
disableRealtimeMonitoring - Boolean Whether Defender real-time protection monitoring is disabled.
disableBehaviorMonitoring - Boolean Whether Defender behavior monitoring is disabled.
disableScriptScanning - Boolean Whether Defender script scanning is disabled.
disableGenericRePorts - Boolean Whether Defender generic detection reports are disabled.
disableRemovableDriveScanning - Boolean Whether Defender scanning of removable drives is disabled.
disableEmailScanning - Boolean Whether Defender email scanning is disabled.
puaProtection - PUAProtection Defender potentially unwanted application protection mode.
disableAntiSpyware - Boolean Whether Microsoft Defender Antivirus is disabled.
auditApplicationGuard - Boolean Whether Application Guard auditing is enabled.
allowCameraMicrophoneRedirection - Boolean Whether camera and microphone redirection is allowed in Application Guard.
allowPersistence - Boolean Whether data persistence is allowed in Application Guard.
saveFilesToHost - Boolean Whether files can be saved from Application Guard to the host OS.
appHVSIClipboardSettings - AppHVSIClipboardSettings Application Guard clipboard copy direction.
allowAppHVSIProviderSet - AllowAppHVSIProviderSet Application Guard provider set for isolation.
allowNewsAndInterests - Boolean Whether News and Interests on the taskbar are allowed.
enableFeeds - Boolean Whether the news and interests feed on the taskbar is enabled (EnableFeeds).
disableFileSyncNGSC - Boolean Whether OneDrive file sync is disabled.
disablePushToInstall - Boolean Whether push-to-install service is disabled.
disableCloudClipboardIntegration - Boolean Whether cloud clipboard integration is disabled.
disablePasswordSaving - Boolean Whether saving of Remote Desktop passwords is disabled.
fDenyTSConnections - Boolean Whether Remote Desktop connections to this computer are denied.
enableUiaRedirection - Boolean Whether UI Automation redirection is enabled for Remote Desktop.
fDisableCcm - Boolean Whether clipboard redirection is disabled in Remote Desktop sessions.
fDisableCdm - Boolean Whether drive redirection is disabled in Remote Desktop sessions.
fDisableLocationRedir - Boolean Whether location redirection is disabled in Remote Desktop sessions.
fDisableLPT - Boolean Whether LPT port redirection is disabled in Remote Desktop sessions.
fDisablePNPRedir - Boolean Whether Plug and Play device redirection is disabled in Remote Desktop sessions.
fDisableWebAuthn - Boolean Whether WebAuthn redirection is disabled in Remote Desktop sessions.
fPromptForPassword - Boolean Whether a password is always prompted for upon Remote Desktop connection.
fEncryptRPCTraffic - Boolean Whether RPC traffic for Remote Desktop is encrypted.
securityLayer - SecurityLayer Security layer used for Remote Desktop connections.
userAuthentication - Boolean Whether Network Level Authentication is required for Remote Desktop.
minEncryptionLevel - MinEncryptionLevel Minimum encryption level for Remote Desktop connections.
maxIdleTime - Duration Maximum idle time before a Remote Desktop session is disconnected.
maxDisconnectionTime - Duration Maximum time a disconnected Remote Desktop session remains on the server.
deleteTempDirsOnExit - Boolean Whether temporary folders are deleted when a Remote Desktop session ends.
scClipLevel - ClipboardTransferLevel Restriction on clipboard transfers from a Remote Desktop session server to the client. See ClipboardTransferLevel.
disableEnclosureDownload - Boolean Whether enclosure downloading is disabled in RSS feeds.
allowCloudSearch - AllowCloudSearch Cloud search setting for Windows Search.
allowCortana - Boolean Whether Cortana is allowed.
allowCortanaAboveLock - Boolean Whether Cortana is allowed above the lock screen.
allowIndexingEncryptedStoresOrItems - Boolean Whether indexing of encrypted stores or items is allowed.
allowSearchToUseLocation - Boolean Whether Search is allowed to use location.
enableDynamicContentInWSB - Boolean Whether dynamic content in Windows Security is enabled.
noGenTicket - Boolean Whether Kerberos service ticket generation with a user's S4U2Self ticket is disabled.
disableStoreApps - Boolean Whether store apps are disabled.
requirePrivateStoreOnly - Boolean Whether only the private store is shown in the Microsoft Store.
autoDownload - AutoDownload Auto-download policy for Microsoft Store apps.
disableOSUpgrade - Boolean Whether OS upgrade via the Microsoft Store is disabled.
removeWindowsStore - Boolean Whether access to the Microsoft Store is removed.
allowRecallEnablement - Boolean Whether the Windows AI Recall feature is allowed to be enabled (AllowRecallEnablement).
notifyMalicious - Boolean Whether SmartScreen notifies users about malicious sites.
notifyPasswordReuse - Boolean Whether SmartScreen notifies users about password reuse.
notifyUnsafeApp - Boolean Whether SmartScreen notifies users about unsafe apps.
serviceEnabled - Boolean Whether the SmartScreen service is enabled.
captureThreatWindow - Boolean Whether Enhanced Phishing Protection automatic data collection (CaptureThreatWindow) is enabled, allowing additional content to be collected from suspicious websites or apps for security analysis.
enableSmartScreen - EnableSmartScreen SmartScreen filter setting for Windows Explorer.
shellSmartScreenLevel - ShellSmartScreenLevel SmartScreen blocking level for Windows Explorer.
phishingFilterEnabledV9 - Boolean Whether the SmartScreen phishing filter is enabled in Internet Explorer.
phishingFilterPreventOverride - Boolean Whether users are prevented from overriding SmartScreen phishing warnings.
allowGameDVR - Boolean Whether Game DVR recording is allowed.
enableESSwithSupportedPeripherals - EnableESSwithSupportedPeripherals Enhanced Sign-in Security (ESS) with supported peripherals policy.
allowSuggestedAppsInWindowsInkWorkspace - Boolean Whether suggested apps in Windows Ink Workspace are allowed.
allowWindowsInkWorkspace - AllowWindowsInkWorkspace Windows Ink Workspace access policy.
enableUserControl - Boolean Whether users can control Windows Installer installation options.
alwaysInstallElevated - Boolean Whether Windows Installer always installs with elevated privileges.
safeForScripting - Boolean Whether ActiveX controls marked as safe for scripting can be used.
enableMPRNotifications - Boolean Whether MPR notifications are sent during winlogon.
disableAutomaticRestartSignOn - Boolean Whether automatic restart sign-on after Windows Update is disabled.
enableScriptBlockLogging - Boolean Whether PowerShell script block logging is enabled.
enableTranscripting - Boolean Whether PowerShell transcription is enabled.
winRMClientAllowBasic - Boolean Whether WinRM client allows basic authentication.
winRMClientAllowUnencryptedTraffic - Boolean Whether WinRM client allows unencrypted traffic.
winRMClientAllowDigest - Boolean Whether WinRM client allows digest authentication.
winRMServiceAllowBasic - Boolean Whether WinRM service allows basic authentication.
winRMServiceAllowAutoConfig - Boolean Whether WinRM service auto-configuration for remote management is allowed.
winRMServiceAllowUnencryptedTraffic - Boolean Whether WinRM service allows unencrypted traffic.
winRMServiceDisableRunAs - Boolean Whether WinRM service RunAs is disabled.
allowRemoteShellAccess - Boolean Whether remote shell access is allowed.
allowClipboardRedirection - Boolean Whether clipboard redirection is allowed in Windows Sandbox.
allowNetworking - Boolean Whether networking is allowed in Windows Sandbox.
allowWriteToMappedFolders - Boolean Whether host folders mapped into Windows Sandbox can be written to (AllowWriteToMappedFolders).
disallowExploitProtectionOverride - Boolean Whether users are prevented from overriding Exploit Protection settings.
noAutoRebootWithLoggedOnUsers - Boolean Whether automatic reboot with logged-on users is suppressed for Windows Update.
noAutoUpdate - Boolean Whether Windows automatic updates are disabled.
scheduledInstallDay - ScheduledInstallDay Day of the week for scheduled Windows Update installation.
setDisablePauseUXAccess - Boolean Whether the Pause Updates UI is disabled.
managePreviewBuilds - ManagePreviewBuilds Windows Insider Preview builds management policy.
deferFeatureUpdatesPeriodInDays - Uint64 Number of days to defer feature updates.
deferQualityUpdates - Boolean Whether Quality Update deferral is enabled (DeferQualityUpdates).
deferQualityUpdatesPeriodInDays - Uint64 Number of days Quality Updates are deferred after release.
allowTemporaryEnterpriseFeatureControl - Boolean Whether features introduced via monthly quality updates (servicing) that are off by default may be enabled (AllowTemporaryEnterpriseFeatureControl).
setAllowOptionalContent - Boolean Whether devices can receive optional updates, including Controlled Feature Rollouts (SetAllowOptionalContent).
disableWpad - Boolean Whether Web Proxy Auto-Discovery (WPAD) is disabled for Windows HTTP Services (DisableWpad).
disableProxyAuthenticationSchemes - Uint64 Bitmask of HTTP proxy authentication schemes disabled for Windows HTTP Services (DisableProxyAuthenticationSchemes).

Used by

  • AdministrativeTemplatesWindows type: The Group Policy Administrative Templates (ADMX) settings applied to a Windows Endpoint, read from the policy registry values those templates write.

Example

Example

{
  "noLockScreenCamera": false,
  "noLockScreenSlideshow": true,
  "allowInputPersonalization": false,
  "allowOnlineTips": true,
  "rpcAuthnLevelPrivacyEnabled": true,
  "smbV1ClientDriverStart": true,
  "smbV1Server": true,
  "disableExceptionChainValidation": true,
  "nodeType": "NONE",
  "useLogonCredential": true,
  "enableCertPaddingCheck": false,
  "enableCertPaddingCheckWow6432Node": true,
  "autoAdminLogon": false,
  "disableAutoSourceRouting": "ENABLED_NO_ADDITIONAL_PROTECTION",
  "disableIpSourceRouting": "ENABLED_NO_ADDITIONAL_PROTECTION",
  "disableSavePassword": false,
  "enableICMPRedirect": true,
  "keepAliveTime": "600000000",
  "noNameReleaseOnDemand": false,
  "performRouterDiscovery": true,
  "safeDllSearchMode": false,
  "screenSaverGracePeriod": "600000000",
  "tcpMaxDataRetransmissionsIpv6": "8589934592",
  "tcpMaxDataRetransmissionsIpv4": "8589934592",
  "eventLogWarningLevel": "8589934592",
  "enableMulticast": true,
  "disableIPv6DefaultDnsServers": false,
  "enableFrontProviders": true,
  "allowInsecureGuestAuth": false,
  "lanmanServerAuditClientDoesNotSupportEncryption": true,
  "lanmanServerAuditClientDoesNotSupportSigning": true,
  "lanmanServerAuditInsecureGuestLogon": true,
  "lanmanServerEnableAuthRateLimiter": false,
  "lanmanServerEnableMailslots": false,
  "lanmanServerMinSmb2Dialect": "SMB_2_0_2",
  "lanmanServerInvalidAuthDelayTime": "600000000",
  "lanmanWorkstationAuditInsecureGuestLogon": true,
  "lanmanWorkstationAuditServerDoesNotSupportEncrypt": false,
  "lanmanWorkstationAuditServerDoesNotSupportSigning": true,
  "lanmanWorkstationEnableMailslots": true,
  "lanmanWorkstationMinSmb2Dialect": "SMB_2_0_2",
  "lanmanWorkstationRequireEncryption": true,
  "allowLLTDIOOnDomain": false,
  "allowLLTDIOOnPublicNet": true,
  "enableLLTDIO": true,
  "prohibitLLTDIOOnPrivateNet": false,
  "allowRspndrOnDomain": false,
  "allowRspndrOnPublicNet": true,
  "enableRspndr": false,
  "prohibitRspndrOnPrivateNet": true,
  "p2PNetworkServicesDisabled": true,
  "ncAllowNetBridgeNla": false,
  "ncShowSharedAccessUi": false,
  "hardenedPathsNetlogon": "abc123",
  "hardenedPathsSysvol": "abc123",
  "disabledComponents": "8589934592",
  "enableRegistrars": true,
  "disableFlashConfigRegistrar": true,
  "disableInBand802DOT11Registrar": false,
  "disableUPnPRegistrar": false,
  "disableWPDRegistrar": true,
  "disableWcnUi": true,
  "fMininimizeConnections": "ALLOW_SIMULTANEOUS_CONNECTIONS",
  "autoConnectAllowedOEM": false,
  "registerSpoolerRemoteRpcEndPoint": false,
  "redirectionguardPolicy": "DISABLED",
  "rpcUseNamedPipeProtocol": "RPC_OVER_TCP",
  "rpcAuthentication": "DEFAULT",
  "rpcProtocols": "RPC_OVER_NAMED_PIPES",
  "forceKerberosForRpc": "NEGOTIATE",
  "rpcTcpPort": "8589934592",
  "restrictDriverInstallationToAdministrators": false,
  "copyFilesPolicy": "DISABLED",
  "noWarningNoElevationOnInstall": "WARN_AND_ELEVATE_ON_INSTALL",
  "updatePromptSettings": "WARN_AND_ELEVATE_ON_UPDATE",
  "requireIPPs": false,
  "windowsProtectedPrintGroupPolicyState": false,
  "securityFlagsBlockUnknownCA": true,
  "securityFlagsBlockCertWrongUsage": true,
  "securityFlagsBlockCertCNInvalid": true,
  "securityFlagsBlockCertDateInvalid": false,
  "noCloudApplicationNotification": true,
  "processCreationIncludeCmdLineEnabled": true,
  "allowEncryptionOracle": "FORCE",
  "allowProtectedCreds": true,
  "enableVirtualizationBasedSecurity": true,
  "requirePlatformSecurityFeatures": "SECURE_BOOT",
  "hypervisorEnforcedCodeIntegrity": "DISABLED",
  "hvcimatRequired": false,
  "lsaCfgFlags": "DISABLED",
  "configureSystemGuardLaunch": "NOT_CONFIGURED",
  "configureKernelShadowStacksLaunch": "NOT_CONFIGURED",
  "denyDeviceIds": true,
  "denyDeviceClasses": true,
  "denyDeviceClassesList": ["abc123"],
  "denyDeviceClassesRetroactive": false,
  "preventDeviceMetadataFromNetwork": true,
  "driverLoadPolicy": "GOOD_ONLY",
  "clfsAuthenticationChecking": false,
  "sudoEnabled": "DISABLED",
  "enableCdp": true,
  "noUseStoreOpenWith": false,
  "disableWebPnPDownload": true,
  "preventHandwritingDataSharing": true,
  "preventHandwritingErrorReports": true,
  "exitOnMSICW": false,
  "noWebServices": false,
  "disableHTTPPrinting": false,
  "noRegistration": false,
  "disableContentFileUpdates": true,
  "noOnlinePrintsWizard": true,
  "noPublishingWizard": true,
  "ceip": true,
  "ceipEnable": false,
  "windowsErrorReportingDisabled": false,
  "pcHealthErrorReportingDoReport": false,
  "devicePKInitBehavior": "AUTOMATIC",
  "devicePKInitEnabled": false,
  "deviceEnumerationPolicy": "BLOCK_ALL",
  "allowCustomSSPsAPs": false,
  "runAsPPL": "DISABLED",
  "blockUserInputMethodsForSignIn": false,
  "blockUserFromShowingAccountDetailsOnSignin": true,
  "dontDisplayNetworkSelectionUI": false,
  "disableLockScreenAppNotifications": true,
  "allowDomainPINLogon": true,
  "allowCrossDeviceClipboard": false,
  "uploadUserActivities": true,
  "allowNetworkConDuringStandbyOnBattery": true,
  "allowNetworkConDuringStandbyPluggedIn": false,
  "allowStandbyStatesWhenSleeping": false,
  "allowStandbyStatesWhenPluggedIn": false,
  "requirePasswordOnWakeOnBattery": true,
  "requirePasswordOnWakeWhenPluggedIn": true,
  "fAllowUnsolicited": false,
  "fAllowToGetHelp": true,
  "enableAuthEpResolution": true,
  "restrictRemoteClients": "NONE",
  "disableQueryRemoteServer": true,
  "scenarioExecutionEnabled": true,
  "disabledByGroupPolicy": false,
  "ntpClientEnabled": true,
  "systemAllowEncryptionOracle": true,
  "allowSharedLocalAppData": true,
  "blockNonAdminUserInstall": false,
  "disablePerUserUnsignedPackagesByDefault": true,
  "letAppsActivateWithVoiceAboveLock": "USER_CONTROL",
  "msaOptional": false,
  "blockHostedAppAccessWinRT": true,
  "noAutoplayfornonVolume": false,
  "noAutorun": "DISABLED",
  "noDriveTypeAutoRun": "ALL_DRIVES",
  "enhancedAntiSpoofing": false,
  "fdvDiscoveryVolumeType": true,
  "fdvRecovery": true,
  "fdvManageDRA": "DISALLOW",
  "fdvRecoveryPassword": "DISALLOW",
  "fdvRecoveryKey": "DISALLOW",
  "fdvHideRecoveryPage": "SHOW",
  "fdvActiveDirectoryBackup": "DISABLED",
  "fdvActiveDirectoryInfoToStore": "PASSWORDS_AND_KEY_PACKAGES",
  "fdvRequireActiveDirectoryBackup": "NOT_REQUIRED",
  "fdvHardwareEncryption": false,
  "fdvPassphrase": false,
  "fdvAllowUserCert": false,
  "fdvEnforceUserCert": "NOT_REQUIRED",
  "useEnhancedPin": false,
  "osAllowSecureBootForIntegrity": false,
  "osRecovery": false,
  "osManageDRA": "DISALLOW",
  "osRecoveryPassword": "DISALLOW",
  "osRecoveryKey": "DISALLOW",
  "osHideRecoveryPage": "SHOW",
  "osActiveDirectoryBackup": "DISABLED",
  "osActiveDirectoryInfoToStore": "PASSWORDS_AND_KEY_PACKAGES",
  "osRequireActiveDirectoryBackup": "NOT_REQUIRED",
  "osHardwareEncryption": false,
  "osPassphrase": true,
  "useAdvancedStartup": true,
  "enableBDEWithNoTPM": true,
  "rdvDiscoveryVolumeType": true,
  "rdvRecovery": false,
  "rdvManageDRA": "DISALLOW",
  "rdvRecoveryPassword": "DISALLOW",
  "rdvRecoveryKey": "DISALLOW",
  "rdvHideRecoveryPage": "SHOW",
  "rdvActiveDirectoryBackup": "DISABLED",
  "rdvActiveDirectoryInfoToStore": "PASSWORDS_AND_KEY_PACKAGES",
  "rdvRequireActiveDirectoryBackup": "NOT_REQUIRED",
  "rdvHardwareEncryption": false,
  "rdvPassphrase": false,
  "rdvAllowUserCert": true,
  "rdvEnforceUserCert": "NOT_REQUIRED",
  "rdvDenyCrossOrg": true,
  "rdvDenyWriteAccess": false,
  "disableExternalDMAUnderLock": true,
  "allowCamera": false,
  "disableConsumerAccountStateContent": true,
  "disableCloudOptimizedContent": true,
  "disableWindowsConsumerFeatures": true,
  "requirePinForPairing": "NOT_REQUIRED",
  "disablePasswordReveal": true,
  "enumerateAdministrators": false,
  "noLocalPasswordResetQuestions": true,
  "allowTelemetry": "SECURITY",
  "disableEnterpriseAuthProxy": false,
  "disableOneSettingsDownloads": false,
  "doNotShowFeedbackNotifications": true,
  "enableOneSettingsAuditing": true,
  "limitDiagnosticLogCollection": true,
  "limitDumpCollection": false,
  "allowBuildPreview": false,
  "doDownloadMode": "HTTP_ONLY",
  "disableAPISamping": true,
  "disableApplicationFootprint": true,
  "disableInstallTracing": false,
  "enableAppInstaller": false,
  "enableExperimentalFeatures": false,
  "enableHashOverride": false,
  "enableMSAppInstallerProtocol": true,
  "enableLocalArchiveMalwareScanOverride": false,
  "enableBypassCertificatePinningForMicrosoftStore": false,
  "enableWindowsPackageManagerCommandLineInterfaces": true,
  "eventLogApplicationRetention": true,
  "eventLogApplicationMaxSize": "8589934592",
  "eventLogSecurityRetention": true,
  "eventLogSecurityMaxSize": "8589934592",
  "eventLogSetupRetention": false,
  "eventLogSetupMaxSize": "8589934592",
  "eventLogSystemRetention": true,
  "eventLogSystemMaxSize": "8589934592",
  "noDataExecutionPreventionForExplorer": true,
  "disableGraphRecentItems": false,
  "noHeapTerminationOnCorruption": false,
  "hideRecommendedPersonalizedSites": false,
  "disableMotWOnInsecurePathCopy": false,
  "preXPSP2ShellProtocolBehavior": false,
  "disableHomeGroup": true,
  "disableLocation": true,
  "allowMessageSync": false,
  "disableUserAuth": true,
  "localSettingOverrideSpynetReporting": true,
  "spynetReporting": false,
  "exploitGuardASRRules": false,
  "enableNetworkProtection": "DISABLED",
  "enableFileHashComputation": false,
  "disableIOAVProtection": true,
  "disableRealtimeMonitoring": true,
  "disableBehaviorMonitoring": false,
  "disableScriptScanning": true,
  "disableGenericRePorts": false,
  "disableRemovableDriveScanning": false,
  "disableEmailScanning": true,
  "puaProtection": "DISABLED",
  "disableAntiSpyware": false,
  "auditApplicationGuard": true,
  "allowCameraMicrophoneRedirection": false,
  "allowPersistence": true,
  "saveFilesToHost": true,
  "appHVSIClipboardSettings": "DISABLED",
  "allowAppHVSIProviderSet": "DISABLED",
  "allowNewsAndInterests": false,
  "enableFeeds": true,
  "disableFileSyncNGSC": true,
  "disablePushToInstall": false,
  "disableCloudClipboardIntegration": false,
  "disablePasswordSaving": false,
  "fDenyTSConnections": true,
  "enableUiaRedirection": false,
  "fDisableCcm": true,
  "fDisableCdm": false,
  "fDisableLocationRedir": true,
  "fDisableLPT": true,
  "fDisablePNPRedir": true,
  "fDisableWebAuthn": true,
  "fPromptForPassword": true,
  "fEncryptRPCTraffic": true,
  "securityLayer": "RDP",
  "userAuthentication": true,
  "minEncryptionLevel": "LOW",
  "maxIdleTime": "600000000",
  "maxDisconnectionTime": "600000000",
  "deleteTempDirsOnExit": true,
  "scClipLevel": "DISABLED",
  "disableEnclosureDownload": true,
  "allowCloudSearch": "DISABLED",
  "allowCortana": false,
  "allowCortanaAboveLock": false,
  "allowIndexingEncryptedStoresOrItems": false,
  "allowSearchToUseLocation": true,
  "enableDynamicContentInWSB": true,
  "noGenTicket": false,
  "disableStoreApps": true,
  "requirePrivateStoreOnly": true,
  "autoDownload": "ALWAYS",
  "disableOSUpgrade": true,
  "removeWindowsStore": false,
  "allowRecallEnablement": false,
  "notifyMalicious": true,
  "notifyPasswordReuse": false,
  "notifyUnsafeApp": true,
  "serviceEnabled": false,
  "captureThreatWindow": false,
  "enableSmartScreen": "OFF",
  "shellSmartScreenLevel": "WARN",
  "phishingFilterEnabledV9": false,
  "phishingFilterPreventOverride": false,
  "allowGameDVR": false,
  "enableESSwithSupportedPeripherals": "DISABLED",
  "allowSuggestedAppsInWindowsInkWorkspace": false,
  "allowWindowsInkWorkspace": "DISABLED",
  "enableUserControl": false,
  "alwaysInstallElevated": false,
  "safeForScripting": false,
  "enableMPRNotifications": true,
  "disableAutomaticRestartSignOn": false,
  "enableScriptBlockLogging": true,
  "enableTranscripting": false,
  "winRMClientAllowBasic": true,
  "winRMClientAllowUnencryptedTraffic": true,
  "winRMClientAllowDigest": true,
  "winRMServiceAllowBasic": true,
  "winRMServiceAllowAutoConfig": false,
  "winRMServiceAllowUnencryptedTraffic": false,
  "winRMServiceDisableRunAs": false,
  "allowRemoteShellAccess": true,
  "allowClipboardRedirection": true,
  "allowNetworking": false,
  "allowWriteToMappedFolders": true,
  "disallowExploitProtectionOverride": false,
  "noAutoRebootWithLoggedOnUsers": false,
  "noAutoUpdate": true,
  "scheduledInstallDay": "EVERY_DAY",
  "setDisablePauseUXAccess": false,
  "managePreviewBuilds": "DISABLE",
  "deferFeatureUpdatesPeriodInDays": "8589934592",
  "deferQualityUpdates": true,
  "deferQualityUpdatesPeriodInDays": "8589934592",
  "allowTemporaryEnterpriseFeatureControl": false,
  "setAllowOptionalContent": false,
  "disableWpad": false,
  "disableProxyAuthenticationSchemes": "8589934592"
}