Computer-specific Administrative Templates (ADMX) settings on an Endpoint.
Fields
| Field Name | Description |
|---|---|
noLockScreenCamera - Boolean
|
Whether the camera is disabled on the lock screen. |
noLockScreenSlideshow - Boolean
|
Whether the lock screen slideshow is disabled. |
allowInputPersonalization - Boolean
|
Whether speech, inking, and typing personalization is allowed. |
allowOnlineTips - Boolean
|
Whether online tips and help for the Settings app are allowed. |
rpcAuthnLevelPrivacyEnabled - Boolean
|
Whether RPC authentication level privacy is enabled for packet forwarding. |
smbV1ClientDriverStart - Boolean
|
Whether the SMBv1 client driver is started. |
smbV1Server - Boolean
|
Whether the SMBv1 server protocol is enabled. |
disableExceptionChainValidation - Boolean
|
Whether Structured Exception Handling Overwrite Protection (SEHOP) is disabled. |
nodeType - NetBTNodeType
|
NetBT node type for NetBIOS over TCP/IP name resolution. |
useLogonCredential - Boolean
|
Whether WDigest credentials are stored in memory by the credential manager. |
enableCertPaddingCheck - Boolean
|
Whether strict Authenticode signature verification (EnableCertPaddingCheck) is enforced for Portable Executable files, mitigating CVE-2013-3900. |
enableCertPaddingCheckWow6432Node - Boolean
|
Whether the Authenticode certificate padding check is also enforced for the 32-bit subsystem on a 64-bit OS (Wow6432Node registry view). |
autoAdminLogon - Boolean
|
Whether automatic admin logon is enabled. |
disableAutoSourceRouting - SourceRouting
|
IPv6 source routing protection level. |
disableIpSourceRouting - SourceRouting
|
IPv4 source routing protection level. |
disableSavePassword - Boolean
|
Whether saving passwords in the Remote Desktop connection is disabled. |
enableICMPRedirect - Boolean
|
Whether ICMP redirects can override OSPF-generated routes. |
keepAliveTime - Duration
|
TCP keep-alive interval duration. |
noNameReleaseOnDemand - Boolean
|
Whether the computer releases its NetBIOS name on request. |
performRouterDiscovery - Boolean
|
Whether IRDP router discovery is performed. |
safeDllSearchMode - Boolean
|
Whether Safe DLL search mode is enabled for the DLL search order. |
screenSaverGracePeriod - Duration
|
Grace period before the screen saver password takes effect. |
tcpMaxDataRetransmissionsIpv6 - Uint64
|
Maximum TCP data retransmissions over IPv6. |
tcpMaxDataRetransmissionsIpv4 - Uint64
|
Maximum TCP data retransmissions over IPv4. |
eventLogWarningLevel - Uint64
|
Warning level threshold for the security event log. |
enableMulticast - Boolean
|
Whether multicast name resolution (LLMNR) is enabled. |
disableIPv6DefaultDnsServers - Boolean
|
Whether the DNS client's built-in default IPv6 DNS server addresses are disabled (DisableIPv6DefaultDnsServers). |
enableFrontProviders - Boolean
|
Whether front-end font providers are enabled. |
allowInsecureGuestAuth - Boolean
|
Whether insecure guest logons to an SMB server are allowed. |
lanmanServerAuditClientDoesNotSupportEncryption - Boolean
|
Whether the SMB server audits clients that do not support encryption. |
lanmanServerAuditClientDoesNotSupportSigning - Boolean
|
Whether the SMB server audits clients that do not support signing. |
lanmanServerAuditInsecureGuestLogon - Boolean
|
Whether the SMB server audits insecure guest logons. |
lanmanServerEnableAuthRateLimiter - Boolean
|
Whether the SMB server authentication rate limiter is enabled. |
lanmanServerEnableMailslots - Boolean
|
Whether SMB server mailslots are enabled. |
lanmanServerMinSmb2Dialect - SMBVersion
|
Minimum SMB2 dialect version for the SMB server. |
lanmanServerInvalidAuthDelayTime - Duration
|
Delay duration for invalid authentication attempts on the SMB server. |
lanmanWorkstationAuditInsecureGuestLogon - Boolean
|
Whether the SMB workstation audits insecure guest logons. |
lanmanWorkstationAuditServerDoesNotSupportEncrypt - Boolean
|
Whether the SMB workstation audits servers that do not support encryption. |
lanmanWorkstationAuditServerDoesNotSupportSigning - Boolean
|
Whether the SMB workstation audits servers that do not support signing. |
lanmanWorkstationEnableMailslots - Boolean
|
Whether SMB workstation mailslots are enabled. |
lanmanWorkstationMinSmb2Dialect - SMBVersion
|
Minimum SMB2 dialect version for the SMB workstation. |
lanmanWorkstationRequireEncryption - Boolean
|
Whether the SMB workstation requires encryption. |
allowLLTDIOOnDomain - Boolean
|
Whether LLTDIO responder is allowed on a domain network. |
allowLLTDIOOnPublicNet - Boolean
|
Whether LLTDIO responder is allowed on a public network. |
enableLLTDIO - Boolean
|
Whether the LLTDIO driver is enabled. |
prohibitLLTDIOOnPrivateNet - Boolean
|
Whether LLTDIO responder is prohibited on a private network. |
allowRspndrOnDomain - Boolean
|
Whether the Responder (RSPNDR) driver is allowed on a domain network. |
allowRspndrOnPublicNet - Boolean
|
Whether the Responder (RSPNDR) driver is allowed on a public network. |
enableRspndr - Boolean
|
Whether the Responder (RSPNDR) driver is enabled. |
prohibitRspndrOnPrivateNet - Boolean
|
Whether the Responder (RSPNDR) driver is prohibited on a private network. |
p2PNetworkServicesDisabled - Boolean
|
Whether peer-to-peer network services are disabled. |
ncAllowNetBridgeNla - Boolean
|
Whether Network Bridge can be installed and configured on a domain network. |
ncShowSharedAccessUi - Boolean
|
Whether the shared access UI for Internet Connection Sharing is shown. |
hardenedPathsNetlogon - String
|
UNC hardened access path configuration for NETLOGON share. |
hardenedPathsSysvol - String
|
UNC hardened access path configuration for SYSVOL share. |
disabledComponents - Uint64
|
IPv6 disabled components bitmask. |
enableRegistrars - Boolean
|
Whether WCN registrars are enabled for wireless network configuration. |
disableFlashConfigRegistrar - Boolean
|
Whether the WCN Flash Config registrar is disabled. |
disableInBand802DOT11Registrar - Boolean
|
Whether the WCN In-Band 802.11 registrar is disabled. |
disableUPnPRegistrar - Boolean
|
Whether the WCN UPnP registrar is disabled. |
disableWPDRegistrar - Boolean
|
Whether the WCN WPD registrar is disabled. |
disableWcnUi - Boolean
|
Whether the Windows Connect Now UI is disabled. |
fMininimizeConnections - SimultaneousConnectionType
|
Policy for minimizing simultaneous network connections. |
autoConnectAllowedOEM - Boolean
|
Whether automatic connection to suggested open Wi-Fi hotspots is allowed. |
registerSpoolerRemoteRpcEndPoint - Boolean
|
Whether the Print Spooler accepts remote RPC connections. |
redirectionguardPolicy - RedirectionGuardPolicy
|
Printer redirection guard policy. |
rpcUseNamedPipeProtocol - RpcUseNamedPipeProtocol
|
RPC protocol used for outgoing printer connections. |
rpcAuthentication - RpcAuthentication
|
RPC connection authentication setting for printers. |
rpcProtocols - RpcProtocols
|
Allowed RPC protocols for incoming printer connections. |
forceKerberosForRpc - ForceKerberosForRpc
|
Whether Kerberos is forced for RPC printer connections. |
rpcTcpPort - Uint64
|
TCP port used for RPC printer connections. |
restrictDriverInstallationToAdministrators - Boolean
|
Whether print driver installation is restricted to administrators. |
copyFilesPolicy - CopyFilesPolicy
|
Policy for copying files during Point and Print installation. |
noWarningNoElevationOnInstall - NoWarningNoElevationOnInstall
|
Warning and elevation behavior for Point and Print driver installation. |
updatePromptSettings - UpdatePromptSettings
|
Warning and elevation behavior for Point and Print driver updates. |
requireIPPs - Boolean
|
Whether IPP (Internet Printing Protocol) printers must use IPPS (IPP over TLS/SSL). |
windowsProtectedPrintGroupPolicyState - Boolean
|
Whether Windows protected print mode (Mopria-certified drivers only) is enabled. |
securityFlagsBlockUnknownCA - Boolean
|
Whether the IPP TLS/SSL security policy blocks printers presenting a certificate from an unknown certificate authority. |
securityFlagsBlockCertWrongUsage - Boolean
|
Whether the IPP TLS/SSL security policy blocks printers presenting a non-server certificate (wrong certificate usage). |
securityFlagsBlockCertCNInvalid - Boolean
|
Whether the IPP TLS/SSL security policy blocks printers presenting a certificate with an invalid common name. |
securityFlagsBlockCertDateInvalid - Boolean
|
Whether the IPP TLS/SSL security policy blocks printers presenting a certificate with an invalid (expired or not yet valid) date. |
noCloudApplicationNotification - Boolean
|
Whether cloud-based app notifications are disabled. |
processCreationIncludeCmdLineEnabled - Boolean
|
Whether command line data is included in process creation audit events. |
allowEncryptionOracle - AllowEncryptionOracle
|
CredSSP encryption oracle remediation policy. |
allowProtectedCreds - Boolean
|
Whether restricted admin and remote Credential Guard mode connections are allowed. |
enableVirtualizationBasedSecurity - Boolean
|
Whether Virtualization Based Security (VBS) is enabled. |
requirePlatformSecurityFeatures - RequirePlatformSecurityFeatures
|
Platform security features required for Virtualization Based Security. |
hypervisorEnforcedCodeIntegrity - HypervisorEnforcedCodeIntegrity
|
Hypervisor-enforced Code Integrity (HVCI) policy. |
hvcimatRequired - Boolean
|
Whether HVCI requires memory attributes table (MAT) support. |
lsaCfgFlags - CredentialIsolation
|
Credential Guard (LSA isolation) configuration flags. |
configureSystemGuardLaunch - SystemGuardLaunch
|
System Guard Secure Launch configuration. |
configureKernelShadowStacksLaunch - KernelShadowStacksLaunch
|
Kernel-mode Hardware-enforced Stack Protection configuration. |
denyDeviceIds - Boolean
|
Whether devices matching specific hardware IDs are denied installation. |
denyDeviceClasses - Boolean
|
Whether installation of devices using drivers that match the configured device setup classes is prevented (DenyDeviceClasses). |
denyDeviceClassesList - [String!]
|
Device setup class GUIDs that Windows is prevented from installing drivers for, e.g. the IEEE 1394 device setup classes. |
denyDeviceClassesRetroactive - Boolean
|
Whether the device setup class installation restrictions also apply to devices that were already installed (DenyDeviceClassesRetroactive). |
preventDeviceMetadataFromNetwork - Boolean
|
Whether device metadata retrieval from the internet is prevented. |
driverLoadPolicy - DriverLoadPolicy
|
Boot-start driver initialization policy for Early Launch Antimalware. |
clfsAuthenticationChecking - Boolean
|
Whether Common Log File System (CLFS) logfile authentication is enabled (ClfsAuthenticationChecking). |
sudoEnabled - SudoBehavior
|
Behavior of the sudo.exe command line tool. See SudoBehavior. |
enableCdp - Boolean
|
Whether Connected Devices Platform (CDP) is enabled. |
noUseStoreOpenWith - Boolean
|
Whether the "Look for an app in the Store" option is disabled for unknown file types. |
disableWebPnPDownload - Boolean
|
Whether downloading of print drivers over HTTP is disabled. |
preventHandwritingDataSharing - Boolean
|
Whether sharing of handwriting recognition personalization data is prevented. |
preventHandwritingErrorReports - Boolean
|
Whether handwriting recognition error reports are prevented. |
exitOnMSICW - Boolean
|
Whether the Internet Connection Wizard is skipped if the internet connection already exists. |
noWebServices - Boolean
|
Whether Windows web services for device operations are disabled. |
disableHTTPPrinting - Boolean
|
Whether HTTP printing is disabled. |
noRegistration - Boolean
|
Whether Windows registration is disabled. |
disableContentFileUpdates - Boolean
|
Whether automatic updates of content files used by Windows are disabled. |
noOnlinePrintsWizard - Boolean
|
Whether the Online Prints Wizard is disabled. |
noPublishingWizard - Boolean
|
Whether the Web Publishing and Online Ordering Wizards are disabled. |
ceip - Boolean
|
Whether the Customer Experience Improvement Program is enabled. |
ceipEnable - Boolean
|
Whether the Customer Experience Improvement Program data collection is enabled. |
windowsErrorReportingDisabled - Boolean
|
Whether Windows Error Reporting is disabled. |
pcHealthErrorReportingDoReport - Boolean
|
Whether PC Health error reporting is enabled. |
devicePKInitBehavior - DevicePKInitBehavior
|
Device PKInit authentication behavior for Kerberos. |
devicePKInitEnabled - Boolean
|
Whether device PKInit during Kerberos authentication is enabled. |
deviceEnumerationPolicy - DeviceEnumerationPolicy
|
DMA Guard device enumeration policy for external DMA-capable devices. |
allowCustomSSPsAPs - Boolean
|
Whether custom Security Support Providers and Authentication Packages can be loaded into LSASS. |
runAsPPL - RunAsPPL
|
LSA Protection (Protected Process Light) configuration. |
blockUserInputMethodsForSignIn - Boolean
|
Whether input methods not specific to the user are blocked at sign-in. |
blockUserFromShowingAccountDetailsOnSignin - Boolean
|
Whether the user is blocked from showing account details on the sign-in screen. |
dontDisplayNetworkSelectionUI - Boolean
|
Whether the network selection UI is hidden on the logon screen. |
disableLockScreenAppNotifications - Boolean
|
Whether app notifications are disabled on the lock screen. |
allowDomainPINLogon - Boolean
|
Whether domain PIN logon is allowed. |
allowCrossDeviceClipboard - Boolean
|
Whether cross-device clipboard synchronization is allowed. |
uploadUserActivities - Boolean
|
Whether user activities are uploaded to the cloud. |
allowNetworkConDuringStandbyOnBattery - Boolean
|
Whether network connectivity during connected standby on battery is allowed. |
allowNetworkConDuringStandbyPluggedIn - Boolean
|
Whether network connectivity during connected standby when plugged in is allowed. |
allowStandbyStatesWhenSleeping - Boolean
|
Whether standby states (S1-S3) are allowed when sleeping on battery. |
allowStandbyStatesWhenPluggedIn - Boolean
|
Whether standby states (S1-S3) are allowed when plugged in. |
requirePasswordOnWakeOnBattery - Boolean
|
Whether a password is required when waking from sleep on battery. |
requirePasswordOnWakeWhenPluggedIn - Boolean
|
Whether a password is required when waking from sleep while plugged in. |
fAllowUnsolicited - Boolean
|
Whether unsolicited Remote Assistance offers are allowed. |
fAllowToGetHelp - Boolean
|
Whether users can request Remote Assistance. |
enableAuthEpResolution - Boolean
|
Whether authenticated RPC endpoint resolution is enabled. |
restrictRemoteClients - RestrictRemoteClients
|
RPC remote client restriction policy. |
disableQueryRemoteServer - Boolean
|
Whether querying of a remote server for DNS client events is disabled. |
scenarioExecutionEnabled - Boolean
|
Whether diagnostic scenario execution is enabled. |
disabledByGroupPolicy - Boolean
|
Whether Scheduled Task creation is disabled by Group Policy. |
ntpClientEnabled - Boolean
|
Whether the Windows NTP client is enabled. |
systemAllowEncryptionOracle - Boolean
|
Whether the system-level CredSSP encryption oracle remediation is enabled. |
allowSharedLocalAppData - Boolean
|
Whether apps can share application data between users. |
blockNonAdminUserInstall - Boolean
|
Whether non-admin users are blocked from installing packaged apps. |
disablePerUserUnsignedPackagesByDefault - Boolean
|
Whether per-user unsigned Windows App packages are prevented from installing by default (DisablePerUserUnsignedPackagesByDefault). |
letAppsActivateWithVoiceAboveLock - LetAppsActivateWithVoice
|
Voice activation above lock screen policy for apps. |
msaOptional - Boolean
|
Whether a Microsoft account is optional for modern apps. |
blockHostedAppAccessWinRT - Boolean
|
Whether hosted apps can access the Windows Runtime. |
noAutoplayfornonVolume - Boolean
|
Whether autoplay is disabled for non-volume MTP devices. |
noAutorun - NoAutoRun
|
Autorun default behavior. |
noDriveTypeAutoRun - NoDriveTypeAutoRun
|
Drive types for which autorun is disabled. |
enhancedAntiSpoofing - Boolean
|
Whether enhanced anti-spoofing for Windows Hello face authentication is enabled. |
fdvDiscoveryVolumeType - Boolean
|
Whether BitLocker discovery volume type is configured for fixed data drives. |
fdvRecovery - Boolean
|
Whether BitLocker recovery options for fixed data drives are configured. |
fdvManageDRA - ManageDRA
|
BitLocker Data Recovery Agent policy for fixed data drives. |
fdvRecoveryPassword - RecoveryPasswordOption
|
BitLocker recovery password option for fixed data drives. |
fdvRecoveryKey - RecoveryPasswordOption
|
BitLocker recovery key option for fixed data drives. |
fdvHideRecoveryPage - HideRecoveryPage
|
Whether the BitLocker recovery page is hidden for fixed data drives. |
fdvActiveDirectoryBackup - ADBackup
|
Whether BitLocker recovery info is backed up to AD DS for fixed data drives. |
fdvActiveDirectoryInfoToStore - ADInfoToStore
|
Type of BitLocker recovery info stored in AD DS for fixed data drives. |
fdvRequireActiveDirectoryBackup - RequireADBackup
|
Whether AD DS backup is required before enabling BitLocker on fixed data drives. |
fdvHardwareEncryption - Boolean
|
Whether hardware-based encryption is used for fixed data drives. |
fdvPassphrase - Boolean
|
Whether passphrase unlock is allowed for fixed data drives. |
fdvAllowUserCert - Boolean
|
Whether user certificate unlock is allowed for fixed data drives. |
fdvEnforceUserCert - EnforceUserCert
|
Whether a user certificate is enforced for fixed data drive unlock. |
useEnhancedPin - Boolean
|
Whether enhanced PIN is allowed for BitLocker startup. |
osAllowSecureBootForIntegrity - Boolean
|
Whether Secure Boot is allowed for BitLocker OS drive integrity validation. |
osRecovery - Boolean
|
Whether BitLocker recovery options for the OS drive are configured. |
osManageDRA - ManageDRA
|
BitLocker Data Recovery Agent policy for the OS drive. |
osRecoveryPassword - RecoveryPasswordOption
|
BitLocker recovery password option for the OS drive. |
osRecoveryKey - RecoveryPasswordOption
|
BitLocker recovery key option for the OS drive. |
osHideRecoveryPage - HideRecoveryPage
|
Whether the BitLocker recovery page is hidden for the OS drive. |
osActiveDirectoryBackup - ADBackup
|
Whether BitLocker recovery info is backed up to AD DS for the OS drive. |
osActiveDirectoryInfoToStore - ADInfoToStore
|
Type of BitLocker recovery info stored in AD DS for the OS drive. |
osRequireActiveDirectoryBackup - RequireADBackup
|
Whether AD DS backup is required before enabling BitLocker on the OS drive. |
osHardwareEncryption - Boolean
|
Whether hardware-based encryption is used for the OS drive. |
osPassphrase - Boolean
|
Whether passphrase unlock is allowed for the OS drive. |
useAdvancedStartup - Boolean
|
Whether additional authentication at startup is required for BitLocker. |
enableBDEWithNoTPM - Boolean
|
Whether BitLocker can be enabled without a compatible TPM. |
rdvDiscoveryVolumeType - Boolean
|
Whether BitLocker discovery volume type is configured for removable data drives. |
rdvRecovery - Boolean
|
Whether BitLocker recovery options for removable data drives are configured. |
rdvManageDRA - ManageDRA
|
BitLocker Data Recovery Agent policy for removable data drives. |
rdvRecoveryPassword - RecoveryPasswordOption
|
BitLocker recovery password option for removable data drives. |
rdvRecoveryKey - RecoveryPasswordOption
|
BitLocker recovery key option for removable data drives. |
rdvHideRecoveryPage - HideRecoveryPage
|
Whether the BitLocker recovery page is hidden for removable data drives. |
rdvActiveDirectoryBackup - ADBackup
|
Whether BitLocker recovery info is backed up to AD DS for removable data drives. |
rdvActiveDirectoryInfoToStore - ADInfoToStore
|
Type of BitLocker recovery info stored in AD DS for removable data drives. |
rdvRequireActiveDirectoryBackup - RequireADBackup
|
Whether AD DS backup is required before enabling BitLocker on removable data drives. |
rdvHardwareEncryption - Boolean
|
Whether hardware-based encryption is used for removable data drives. |
rdvPassphrase - Boolean
|
Whether passphrase unlock is allowed for removable data drives. |
rdvAllowUserCert - Boolean
|
Whether user certificate unlock is allowed for removable data drives. |
rdvEnforceUserCert - EnforceUserCert
|
Whether a user certificate is enforced for removable data drive unlock. |
rdvDenyCrossOrg - Boolean
|
Whether cross-organization BitLocker access for removable data drives is denied. |
rdvDenyWriteAccess - Boolean
|
Whether write access to removable data drives not protected by BitLocker is denied. |
disableExternalDMAUnderLock - Boolean
|
Whether external DMA is blocked when the device is locked. |
allowCamera - Boolean
|
Whether the camera is allowed. |
disableConsumerAccountStateContent - Boolean
|
Whether consumer account state content is disabled in cloud settings. |
disableCloudOptimizedContent - Boolean
|
Whether cloud-optimized content is disabled. |
disableWindowsConsumerFeatures - Boolean
|
Whether Windows consumer features like Start suggestions and notifications are disabled. |
requirePinForPairing - RequirePinForPairing
|
PIN requirement for wireless display pairing. |
disablePasswordReveal - Boolean
|
Whether the password reveal button is disabled. |
enumerateAdministrators - Boolean
|
Whether administrator accounts are enumerated during elevation. |
noLocalPasswordResetQuestions - Boolean
|
Whether local password reset security questions are disabled. |
allowTelemetry - AllowTelemetry
|
Windows diagnostic and usage data telemetry level. |
disableEnterpriseAuthProxy - Boolean
|
Whether the authenticated proxy for Connected User Experience and Telemetry is disabled. |
disableOneSettingsDownloads - Boolean
|
Whether OneSettings downloads are disabled. |
doNotShowFeedbackNotifications - Boolean
|
Whether feedback notifications are hidden. |
enableOneSettingsAuditing - Boolean
|
Whether OneSettings auditing is enabled. |
limitDiagnosticLogCollection - Boolean
|
Whether diagnostic log collection is limited. |
limitDumpCollection - Boolean
|
Whether dump collection is limited. |
allowBuildPreview - Boolean
|
Whether Insider Preview builds are allowed. |
doDownloadMode - DODownloadMode
|
Delivery Optimization download mode. |
disableAPISamping - Boolean
|
Whether App and Device Inventory API sampling data is prevented from being sent to Microsoft. Note: the backing registry value name DisableAPISamping is Microsoft's typo and is correct. |
disableApplicationFootprint - Boolean
|
Whether App and Device Inventory Application Footprint data is prevented from being sent to Microsoft. |
disableInstallTracing - Boolean
|
Whether App and Device Inventory Install Tracing data is prevented from being sent to Microsoft. |
enableAppInstaller - Boolean
|
Whether the App Installer is enabled. |
enableExperimentalFeatures - Boolean
|
Whether experimental App Installer features are enabled. |
enableHashOverride - Boolean
|
Whether hash override for App Installer is enabled. |
enableMSAppInstallerProtocol - Boolean
|
Whether the ms-appinstaller protocol is enabled. |
enableLocalArchiveMalwareScanOverride - Boolean
|
Whether the App Installer local archive malware scan can be overridden. |
enableBypassCertificatePinningForMicrosoftStore - Boolean
|
Whether App Installer certificate pinning validation for Microsoft Store sources can be bypassed. |
enableWindowsPackageManagerCommandLineInterfaces - Boolean
|
Whether the Windows Package Manager (winget) command line interfaces are enabled. |
eventLogApplicationRetention - Boolean
|
Whether event log retention is enabled for the Application log. |
eventLogApplicationMaxSize - Uint64
|
Maximum size in KB of the Application event log. |
eventLogSecurityRetention - Boolean
|
Whether event log retention is enabled for the Security log. |
eventLogSecurityMaxSize - Uint64
|
Maximum size in KB of the Security event log. |
eventLogSetupRetention - Boolean
|
Whether event log retention is enabled for the Setup log. |
eventLogSetupMaxSize - Uint64
|
Maximum size in KB of the Setup event log. |
eventLogSystemRetention - Boolean
|
Whether event log retention is enabled for the System log. |
eventLogSystemMaxSize - Uint64
|
Maximum size in KB of the System event log. |
noDataExecutionPreventionForExplorer - Boolean
|
Whether Data Execution Prevention for Windows Explorer is disabled. |
disableGraphRecentItems - Boolean
|
Whether Activity History (recent items in Microsoft Graph) is disabled. |
noHeapTerminationOnCorruption - Boolean
|
Whether heap termination on corruption for Windows Explorer is disabled. |
hideRecommendedPersonalizedSites - Boolean
|
Whether personalized website recommendations are removed from the Recommended section of the Start Menu (HideRecommendedPersonalizedSites). |
disableMotWOnInsecurePathCopy - Boolean
|
Whether the Mark of the Web tag is not applied to files copied from insecure sources (DisableMotWOnInsecurePathCopy). |
preXPSP2ShellProtocolBehavior - Boolean
|
Whether shell protocol protected mode is turned off (PreXPSP2ShellProtocolBehavior), allowing applications to open any folder rather than a limited set. |
disableHomeGroup - Boolean
|
Whether HomeGroup is disabled. |
disableLocation - Boolean
|
Whether the Windows location framework is disabled. |
allowMessageSync - Boolean
|
Whether text message synchronization is allowed. |
disableUserAuth - Boolean
|
Whether user authentication for Defender network inspection is disabled. |
localSettingOverrideSpynetReporting - Boolean
|
Whether local setting override for SpyNet (MAPS) reporting is enabled. |
spynetReporting - Boolean
|
Whether Microsoft MAPS (SpyNet) cloud-based protection reporting is enabled. |
exploitGuardASRRules - Boolean
|
Whether Defender Exploit Guard Attack Surface Reduction rules are enabled. |
enableNetworkProtection - EnableNetworkProtection
|
Defender network protection mode. |
enableFileHashComputation - Boolean
|
Whether Defender file hash computation for every scanned file is enabled. |
disableIOAVProtection - Boolean
|
Whether Defender scanning of downloaded files and attachments is disabled. |
disableRealtimeMonitoring - Boolean
|
Whether Defender real-time protection monitoring is disabled. |
disableBehaviorMonitoring - Boolean
|
Whether Defender behavior monitoring is disabled. |
disableScriptScanning - Boolean
|
Whether Defender script scanning is disabled. |
disableGenericRePorts - Boolean
|
Whether Defender generic detection reports are disabled. |
disableRemovableDriveScanning - Boolean
|
Whether Defender scanning of removable drives is disabled. |
disableEmailScanning - Boolean
|
Whether Defender email scanning is disabled. |
puaProtection - PUAProtection
|
Defender potentially unwanted application protection mode. |
disableAntiSpyware - Boolean
|
Whether Microsoft Defender Antivirus is disabled. |
auditApplicationGuard - Boolean
|
Whether Application Guard auditing is enabled. |
allowCameraMicrophoneRedirection - Boolean
|
Whether camera and microphone redirection is allowed in Application Guard. |
allowPersistence - Boolean
|
Whether data persistence is allowed in Application Guard. |
saveFilesToHost - Boolean
|
Whether files can be saved from Application Guard to the host OS. |
appHVSIClipboardSettings - AppHVSIClipboardSettings
|
Application Guard clipboard copy direction. |
allowAppHVSIProviderSet - AllowAppHVSIProviderSet
|
Application Guard provider set for isolation. |
allowNewsAndInterests - Boolean
|
Whether News and Interests on the taskbar are allowed. |
enableFeeds - Boolean
|
Whether the news and interests feed on the taskbar is enabled (EnableFeeds). |
disableFileSyncNGSC - Boolean
|
Whether OneDrive file sync is disabled. |
disablePushToInstall - Boolean
|
Whether push-to-install service is disabled. |
disableCloudClipboardIntegration - Boolean
|
Whether cloud clipboard integration is disabled. |
disablePasswordSaving - Boolean
|
Whether saving of Remote Desktop passwords is disabled. |
fDenyTSConnections - Boolean
|
Whether Remote Desktop connections to this computer are denied. |
enableUiaRedirection - Boolean
|
Whether UI Automation redirection is enabled for Remote Desktop. |
fDisableCcm - Boolean
|
Whether clipboard redirection is disabled in Remote Desktop sessions. |
fDisableCdm - Boolean
|
Whether drive redirection is disabled in Remote Desktop sessions. |
fDisableLocationRedir - Boolean
|
Whether location redirection is disabled in Remote Desktop sessions. |
fDisableLPT - Boolean
|
Whether LPT port redirection is disabled in Remote Desktop sessions. |
fDisablePNPRedir - Boolean
|
Whether Plug and Play device redirection is disabled in Remote Desktop sessions. |
fDisableWebAuthn - Boolean
|
Whether WebAuthn redirection is disabled in Remote Desktop sessions. |
fPromptForPassword - Boolean
|
Whether a password is always prompted for upon Remote Desktop connection. |
fEncryptRPCTraffic - Boolean
|
Whether RPC traffic for Remote Desktop is encrypted. |
securityLayer - SecurityLayer
|
Security layer used for Remote Desktop connections. |
userAuthentication - Boolean
|
Whether Network Level Authentication is required for Remote Desktop. |
minEncryptionLevel - MinEncryptionLevel
|
Minimum encryption level for Remote Desktop connections. |
maxIdleTime - Duration
|
Maximum idle time before a Remote Desktop session is disconnected. |
maxDisconnectionTime - Duration
|
Maximum time a disconnected Remote Desktop session remains on the server. |
deleteTempDirsOnExit - Boolean
|
Whether temporary folders are deleted when a Remote Desktop session ends. |
scClipLevel - ClipboardTransferLevel
|
Restriction on clipboard transfers from a Remote Desktop session server to the client. See ClipboardTransferLevel. |
disableEnclosureDownload - Boolean
|
Whether enclosure downloading is disabled in RSS feeds. |
allowCloudSearch - AllowCloudSearch
|
Cloud search setting for Windows Search. |
allowCortana - Boolean
|
Whether Cortana is allowed. |
allowCortanaAboveLock - Boolean
|
Whether Cortana is allowed above the lock screen. |
allowIndexingEncryptedStoresOrItems - Boolean
|
Whether indexing of encrypted stores or items is allowed. |
allowSearchToUseLocation - Boolean
|
Whether Search is allowed to use location. |
enableDynamicContentInWSB - Boolean
|
Whether dynamic content in Windows Security is enabled. |
noGenTicket - Boolean
|
Whether Kerberos service ticket generation with a user's S4U2Self ticket is disabled. |
disableStoreApps - Boolean
|
Whether store apps are disabled. |
requirePrivateStoreOnly - Boolean
|
Whether only the private store is shown in the Microsoft Store. |
autoDownload - AutoDownload
|
Auto-download policy for Microsoft Store apps. |
disableOSUpgrade - Boolean
|
Whether OS upgrade via the Microsoft Store is disabled. |
removeWindowsStore - Boolean
|
Whether access to the Microsoft Store is removed. |
allowRecallEnablement - Boolean
|
Whether the Windows AI Recall feature is allowed to be enabled (AllowRecallEnablement). |
notifyMalicious - Boolean
|
Whether SmartScreen notifies users about malicious sites. |
notifyPasswordReuse - Boolean
|
Whether SmartScreen notifies users about password reuse. |
notifyUnsafeApp - Boolean
|
Whether SmartScreen notifies users about unsafe apps. |
serviceEnabled - Boolean
|
Whether the SmartScreen service is enabled. |
captureThreatWindow - Boolean
|
Whether Enhanced Phishing Protection automatic data collection (CaptureThreatWindow) is enabled, allowing additional content to be collected from suspicious websites or apps for security analysis. |
enableSmartScreen - EnableSmartScreen
|
SmartScreen filter setting for Windows Explorer. |
shellSmartScreenLevel - ShellSmartScreenLevel
|
SmartScreen blocking level for Windows Explorer. |
phishingFilterEnabledV9 - Boolean
|
Whether the SmartScreen phishing filter is enabled in Internet Explorer. |
phishingFilterPreventOverride - Boolean
|
Whether users are prevented from overriding SmartScreen phishing warnings. |
allowGameDVR - Boolean
|
Whether Game DVR recording is allowed. |
enableESSwithSupportedPeripherals - EnableESSwithSupportedPeripherals
|
Enhanced Sign-in Security (ESS) with supported peripherals policy. |
allowSuggestedAppsInWindowsInkWorkspace - Boolean
|
Whether suggested apps in Windows Ink Workspace are allowed. |
allowWindowsInkWorkspace - AllowWindowsInkWorkspace
|
Windows Ink Workspace access policy. |
enableUserControl - Boolean
|
Whether users can control Windows Installer installation options. |
alwaysInstallElevated - Boolean
|
Whether Windows Installer always installs with elevated privileges. |
safeForScripting - Boolean
|
Whether ActiveX controls marked as safe for scripting can be used. |
enableMPRNotifications - Boolean
|
Whether MPR notifications are sent during winlogon. |
disableAutomaticRestartSignOn - Boolean
|
Whether automatic restart sign-on after Windows Update is disabled. |
enableScriptBlockLogging - Boolean
|
Whether PowerShell script block logging is enabled. |
enableTranscripting - Boolean
|
Whether PowerShell transcription is enabled. |
winRMClientAllowBasic - Boolean
|
Whether WinRM client allows basic authentication. |
winRMClientAllowUnencryptedTraffic - Boolean
|
Whether WinRM client allows unencrypted traffic. |
winRMClientAllowDigest - Boolean
|
Whether WinRM client allows digest authentication. |
winRMServiceAllowBasic - Boolean
|
Whether WinRM service allows basic authentication. |
winRMServiceAllowAutoConfig - Boolean
|
Whether WinRM service auto-configuration for remote management is allowed. |
winRMServiceAllowUnencryptedTraffic - Boolean
|
Whether WinRM service allows unencrypted traffic. |
winRMServiceDisableRunAs - Boolean
|
Whether WinRM service RunAs is disabled. |
allowRemoteShellAccess - Boolean
|
Whether remote shell access is allowed. |
allowClipboardRedirection - Boolean
|
Whether clipboard redirection is allowed in Windows Sandbox. |
allowNetworking - Boolean
|
Whether networking is allowed in Windows Sandbox. |
allowWriteToMappedFolders - Boolean
|
Whether host folders mapped into Windows Sandbox can be written to (AllowWriteToMappedFolders). |
disallowExploitProtectionOverride - Boolean
|
Whether users are prevented from overriding Exploit Protection settings. |
noAutoRebootWithLoggedOnUsers - Boolean
|
Whether automatic reboot with logged-on users is suppressed for Windows Update. |
noAutoUpdate - Boolean
|
Whether Windows automatic updates are disabled. |
scheduledInstallDay - ScheduledInstallDay
|
Day of the week for scheduled Windows Update installation. |
setDisablePauseUXAccess - Boolean
|
Whether the Pause Updates UI is disabled. |
managePreviewBuilds - ManagePreviewBuilds
|
Windows Insider Preview builds management policy. |
deferFeatureUpdatesPeriodInDays - Uint64
|
Number of days to defer feature updates. |
deferQualityUpdates - Boolean
|
Whether Quality Update deferral is enabled (DeferQualityUpdates). |
deferQualityUpdatesPeriodInDays - Uint64
|
Number of days Quality Updates are deferred after release. |
allowTemporaryEnterpriseFeatureControl - Boolean
|
Whether features introduced via monthly quality updates (servicing) that are off by default may be enabled (AllowTemporaryEnterpriseFeatureControl). |
setAllowOptionalContent - Boolean
|
Whether devices can receive optional updates, including Controlled Feature Rollouts (SetAllowOptionalContent). |
disableWpad - Boolean
|
Whether Web Proxy Auto-Discovery (WPAD) is disabled for Windows HTTP Services (DisableWpad). |
disableProxyAuthenticationSchemes - Uint64
|
Bitmask of HTTP proxy authentication schemes disabled for Windows HTTP Services (DisableProxyAuthenticationSchemes). |
Used by
AdministrativeTemplatesWindowstype: The Group Policy Administrative Templates (ADMX) settings applied to a Windows Endpoint, read from the policy registry values those templates write.
Example
Example
{
"noLockScreenCamera": false,
"noLockScreenSlideshow": true,
"allowInputPersonalization": false,
"allowOnlineTips": true,
"rpcAuthnLevelPrivacyEnabled": true,
"smbV1ClientDriverStart": true,
"smbV1Server": true,
"disableExceptionChainValidation": true,
"nodeType": "NONE",
"useLogonCredential": true,
"enableCertPaddingCheck": false,
"enableCertPaddingCheckWow6432Node": true,
"autoAdminLogon": false,
"disableAutoSourceRouting": "ENABLED_NO_ADDITIONAL_PROTECTION",
"disableIpSourceRouting": "ENABLED_NO_ADDITIONAL_PROTECTION",
"disableSavePassword": false,
"enableICMPRedirect": true,
"keepAliveTime": "600000000",
"noNameReleaseOnDemand": false,
"performRouterDiscovery": true,
"safeDllSearchMode": false,
"screenSaverGracePeriod": "600000000",
"tcpMaxDataRetransmissionsIpv6": "8589934592",
"tcpMaxDataRetransmissionsIpv4": "8589934592",
"eventLogWarningLevel": "8589934592",
"enableMulticast": true,
"disableIPv6DefaultDnsServers": false,
"enableFrontProviders": true,
"allowInsecureGuestAuth": false,
"lanmanServerAuditClientDoesNotSupportEncryption": true,
"lanmanServerAuditClientDoesNotSupportSigning": true,
"lanmanServerAuditInsecureGuestLogon": true,
"lanmanServerEnableAuthRateLimiter": false,
"lanmanServerEnableMailslots": false,
"lanmanServerMinSmb2Dialect": "SMB_2_0_2",
"lanmanServerInvalidAuthDelayTime": "600000000",
"lanmanWorkstationAuditInsecureGuestLogon": true,
"lanmanWorkstationAuditServerDoesNotSupportEncrypt": false,
"lanmanWorkstationAuditServerDoesNotSupportSigning": true,
"lanmanWorkstationEnableMailslots": true,
"lanmanWorkstationMinSmb2Dialect": "SMB_2_0_2",
"lanmanWorkstationRequireEncryption": true,
"allowLLTDIOOnDomain": false,
"allowLLTDIOOnPublicNet": true,
"enableLLTDIO": true,
"prohibitLLTDIOOnPrivateNet": false,
"allowRspndrOnDomain": false,
"allowRspndrOnPublicNet": true,
"enableRspndr": false,
"prohibitRspndrOnPrivateNet": true,
"p2PNetworkServicesDisabled": true,
"ncAllowNetBridgeNla": false,
"ncShowSharedAccessUi": false,
"hardenedPathsNetlogon": "abc123",
"hardenedPathsSysvol": "abc123",
"disabledComponents": "8589934592",
"enableRegistrars": true,
"disableFlashConfigRegistrar": true,
"disableInBand802DOT11Registrar": false,
"disableUPnPRegistrar": false,
"disableWPDRegistrar": true,
"disableWcnUi": true,
"fMininimizeConnections": "ALLOW_SIMULTANEOUS_CONNECTIONS",
"autoConnectAllowedOEM": false,
"registerSpoolerRemoteRpcEndPoint": false,
"redirectionguardPolicy": "DISABLED",
"rpcUseNamedPipeProtocol": "RPC_OVER_TCP",
"rpcAuthentication": "DEFAULT",
"rpcProtocols": "RPC_OVER_NAMED_PIPES",
"forceKerberosForRpc": "NEGOTIATE",
"rpcTcpPort": "8589934592",
"restrictDriverInstallationToAdministrators": false,
"copyFilesPolicy": "DISABLED",
"noWarningNoElevationOnInstall": "WARN_AND_ELEVATE_ON_INSTALL",
"updatePromptSettings": "WARN_AND_ELEVATE_ON_UPDATE",
"requireIPPs": false,
"windowsProtectedPrintGroupPolicyState": false,
"securityFlagsBlockUnknownCA": true,
"securityFlagsBlockCertWrongUsage": true,
"securityFlagsBlockCertCNInvalid": true,
"securityFlagsBlockCertDateInvalid": false,
"noCloudApplicationNotification": true,
"processCreationIncludeCmdLineEnabled": true,
"allowEncryptionOracle": "FORCE",
"allowProtectedCreds": true,
"enableVirtualizationBasedSecurity": true,
"requirePlatformSecurityFeatures": "SECURE_BOOT",
"hypervisorEnforcedCodeIntegrity": "DISABLED",
"hvcimatRequired": false,
"lsaCfgFlags": "DISABLED",
"configureSystemGuardLaunch": "NOT_CONFIGURED",
"configureKernelShadowStacksLaunch": "NOT_CONFIGURED",
"denyDeviceIds": true,
"denyDeviceClasses": true,
"denyDeviceClassesList": ["abc123"],
"denyDeviceClassesRetroactive": false,
"preventDeviceMetadataFromNetwork": true,
"driverLoadPolicy": "GOOD_ONLY",
"clfsAuthenticationChecking": false,
"sudoEnabled": "DISABLED",
"enableCdp": true,
"noUseStoreOpenWith": false,
"disableWebPnPDownload": true,
"preventHandwritingDataSharing": true,
"preventHandwritingErrorReports": true,
"exitOnMSICW": false,
"noWebServices": false,
"disableHTTPPrinting": false,
"noRegistration": false,
"disableContentFileUpdates": true,
"noOnlinePrintsWizard": true,
"noPublishingWizard": true,
"ceip": true,
"ceipEnable": false,
"windowsErrorReportingDisabled": false,
"pcHealthErrorReportingDoReport": false,
"devicePKInitBehavior": "AUTOMATIC",
"devicePKInitEnabled": false,
"deviceEnumerationPolicy": "BLOCK_ALL",
"allowCustomSSPsAPs": false,
"runAsPPL": "DISABLED",
"blockUserInputMethodsForSignIn": false,
"blockUserFromShowingAccountDetailsOnSignin": true,
"dontDisplayNetworkSelectionUI": false,
"disableLockScreenAppNotifications": true,
"allowDomainPINLogon": true,
"allowCrossDeviceClipboard": false,
"uploadUserActivities": true,
"allowNetworkConDuringStandbyOnBattery": true,
"allowNetworkConDuringStandbyPluggedIn": false,
"allowStandbyStatesWhenSleeping": false,
"allowStandbyStatesWhenPluggedIn": false,
"requirePasswordOnWakeOnBattery": true,
"requirePasswordOnWakeWhenPluggedIn": true,
"fAllowUnsolicited": false,
"fAllowToGetHelp": true,
"enableAuthEpResolution": true,
"restrictRemoteClients": "NONE",
"disableQueryRemoteServer": true,
"scenarioExecutionEnabled": true,
"disabledByGroupPolicy": false,
"ntpClientEnabled": true,
"systemAllowEncryptionOracle": true,
"allowSharedLocalAppData": true,
"blockNonAdminUserInstall": false,
"disablePerUserUnsignedPackagesByDefault": true,
"letAppsActivateWithVoiceAboveLock": "USER_CONTROL",
"msaOptional": false,
"blockHostedAppAccessWinRT": true,
"noAutoplayfornonVolume": false,
"noAutorun": "DISABLED",
"noDriveTypeAutoRun": "ALL_DRIVES",
"enhancedAntiSpoofing": false,
"fdvDiscoveryVolumeType": true,
"fdvRecovery": true,
"fdvManageDRA": "DISALLOW",
"fdvRecoveryPassword": "DISALLOW",
"fdvRecoveryKey": "DISALLOW",
"fdvHideRecoveryPage": "SHOW",
"fdvActiveDirectoryBackup": "DISABLED",
"fdvActiveDirectoryInfoToStore": "PASSWORDS_AND_KEY_PACKAGES",
"fdvRequireActiveDirectoryBackup": "NOT_REQUIRED",
"fdvHardwareEncryption": false,
"fdvPassphrase": false,
"fdvAllowUserCert": false,
"fdvEnforceUserCert": "NOT_REQUIRED",
"useEnhancedPin": false,
"osAllowSecureBootForIntegrity": false,
"osRecovery": false,
"osManageDRA": "DISALLOW",
"osRecoveryPassword": "DISALLOW",
"osRecoveryKey": "DISALLOW",
"osHideRecoveryPage": "SHOW",
"osActiveDirectoryBackup": "DISABLED",
"osActiveDirectoryInfoToStore": "PASSWORDS_AND_KEY_PACKAGES",
"osRequireActiveDirectoryBackup": "NOT_REQUIRED",
"osHardwareEncryption": false,
"osPassphrase": true,
"useAdvancedStartup": true,
"enableBDEWithNoTPM": true,
"rdvDiscoveryVolumeType": true,
"rdvRecovery": false,
"rdvManageDRA": "DISALLOW",
"rdvRecoveryPassword": "DISALLOW",
"rdvRecoveryKey": "DISALLOW",
"rdvHideRecoveryPage": "SHOW",
"rdvActiveDirectoryBackup": "DISABLED",
"rdvActiveDirectoryInfoToStore": "PASSWORDS_AND_KEY_PACKAGES",
"rdvRequireActiveDirectoryBackup": "NOT_REQUIRED",
"rdvHardwareEncryption": false,
"rdvPassphrase": false,
"rdvAllowUserCert": true,
"rdvEnforceUserCert": "NOT_REQUIRED",
"rdvDenyCrossOrg": true,
"rdvDenyWriteAccess": false,
"disableExternalDMAUnderLock": true,
"allowCamera": false,
"disableConsumerAccountStateContent": true,
"disableCloudOptimizedContent": true,
"disableWindowsConsumerFeatures": true,
"requirePinForPairing": "NOT_REQUIRED",
"disablePasswordReveal": true,
"enumerateAdministrators": false,
"noLocalPasswordResetQuestions": true,
"allowTelemetry": "SECURITY",
"disableEnterpriseAuthProxy": false,
"disableOneSettingsDownloads": false,
"doNotShowFeedbackNotifications": true,
"enableOneSettingsAuditing": true,
"limitDiagnosticLogCollection": true,
"limitDumpCollection": false,
"allowBuildPreview": false,
"doDownloadMode": "HTTP_ONLY",
"disableAPISamping": true,
"disableApplicationFootprint": true,
"disableInstallTracing": false,
"enableAppInstaller": false,
"enableExperimentalFeatures": false,
"enableHashOverride": false,
"enableMSAppInstallerProtocol": true,
"enableLocalArchiveMalwareScanOverride": false,
"enableBypassCertificatePinningForMicrosoftStore": false,
"enableWindowsPackageManagerCommandLineInterfaces": true,
"eventLogApplicationRetention": true,
"eventLogApplicationMaxSize": "8589934592",
"eventLogSecurityRetention": true,
"eventLogSecurityMaxSize": "8589934592",
"eventLogSetupRetention": false,
"eventLogSetupMaxSize": "8589934592",
"eventLogSystemRetention": true,
"eventLogSystemMaxSize": "8589934592",
"noDataExecutionPreventionForExplorer": true,
"disableGraphRecentItems": false,
"noHeapTerminationOnCorruption": false,
"hideRecommendedPersonalizedSites": false,
"disableMotWOnInsecurePathCopy": false,
"preXPSP2ShellProtocolBehavior": false,
"disableHomeGroup": true,
"disableLocation": true,
"allowMessageSync": false,
"disableUserAuth": true,
"localSettingOverrideSpynetReporting": true,
"spynetReporting": false,
"exploitGuardASRRules": false,
"enableNetworkProtection": "DISABLED",
"enableFileHashComputation": false,
"disableIOAVProtection": true,
"disableRealtimeMonitoring": true,
"disableBehaviorMonitoring": false,
"disableScriptScanning": true,
"disableGenericRePorts": false,
"disableRemovableDriveScanning": false,
"disableEmailScanning": true,
"puaProtection": "DISABLED",
"disableAntiSpyware": false,
"auditApplicationGuard": true,
"allowCameraMicrophoneRedirection": false,
"allowPersistence": true,
"saveFilesToHost": true,
"appHVSIClipboardSettings": "DISABLED",
"allowAppHVSIProviderSet": "DISABLED",
"allowNewsAndInterests": false,
"enableFeeds": true,
"disableFileSyncNGSC": true,
"disablePushToInstall": false,
"disableCloudClipboardIntegration": false,
"disablePasswordSaving": false,
"fDenyTSConnections": true,
"enableUiaRedirection": false,
"fDisableCcm": true,
"fDisableCdm": false,
"fDisableLocationRedir": true,
"fDisableLPT": true,
"fDisablePNPRedir": true,
"fDisableWebAuthn": true,
"fPromptForPassword": true,
"fEncryptRPCTraffic": true,
"securityLayer": "RDP",
"userAuthentication": true,
"minEncryptionLevel": "LOW",
"maxIdleTime": "600000000",
"maxDisconnectionTime": "600000000",
"deleteTempDirsOnExit": true,
"scClipLevel": "DISABLED",
"disableEnclosureDownload": true,
"allowCloudSearch": "DISABLED",
"allowCortana": false,
"allowCortanaAboveLock": false,
"allowIndexingEncryptedStoresOrItems": false,
"allowSearchToUseLocation": true,
"enableDynamicContentInWSB": true,
"noGenTicket": false,
"disableStoreApps": true,
"requirePrivateStoreOnly": true,
"autoDownload": "ALWAYS",
"disableOSUpgrade": true,
"removeWindowsStore": false,
"allowRecallEnablement": false,
"notifyMalicious": true,
"notifyPasswordReuse": false,
"notifyUnsafeApp": true,
"serviceEnabled": false,
"captureThreatWindow": false,
"enableSmartScreen": "OFF",
"shellSmartScreenLevel": "WARN",
"phishingFilterEnabledV9": false,
"phishingFilterPreventOverride": false,
"allowGameDVR": false,
"enableESSwithSupportedPeripherals": "DISABLED",
"allowSuggestedAppsInWindowsInkWorkspace": false,
"allowWindowsInkWorkspace": "DISABLED",
"enableUserControl": false,
"alwaysInstallElevated": false,
"safeForScripting": false,
"enableMPRNotifications": true,
"disableAutomaticRestartSignOn": false,
"enableScriptBlockLogging": true,
"enableTranscripting": false,
"winRMClientAllowBasic": true,
"winRMClientAllowUnencryptedTraffic": true,
"winRMClientAllowDigest": true,
"winRMServiceAllowBasic": true,
"winRMServiceAllowAutoConfig": false,
"winRMServiceAllowUnencryptedTraffic": false,
"winRMServiceDisableRunAs": false,
"allowRemoteShellAccess": true,
"allowClipboardRedirection": true,
"allowNetworking": false,
"allowWriteToMappedFolders": true,
"disallowExploitProtectionOverride": false,
"noAutoRebootWithLoggedOnUsers": false,
"noAutoUpdate": true,
"scheduledInstallDay": "EVERY_DAY",
"setDisablePauseUXAccess": false,
"managePreviewBuilds": "DISABLE",
"deferFeatureUpdatesPeriodInDays": "8589934592",
"deferQualityUpdates": true,
"deferQualityUpdatesPeriodInDays": "8589934592",
"allowTemporaryEnterpriseFeatureControl": false,
"setAllowOptionalContent": false,
"disableWpad": false,
"disableProxyAuthenticationSchemes": "8589934592"
}