GPO policy: "Let Windows apps activate with voice while the system is locked" (LetAppsActivateWithVoice) under Computer Configuration > Administrative Templates > Windows Components > App Privacy. Controls whether apps can be activated by voice commands (e.g. Cortana) from the lock screen. Registry: HKLM\SOFTWARE\Policies\Microsoft\Windows\AppPrivacy:LetAppsActivateWithVoiceAboveLock (REG_DWORD). CIS Benchmark (L1) recommends Force Deny (value 2) to prevent lock-screen voice activation. Reference: Policy CSP - Privacy (LetAppsActivateWithVoiceAboveLock)
Values
| Enum Value | Description |
|---|---|
|
|
User controls this setting per app (registry value 0). Each user decides whether individual apps can activate with voice from the lock screen. |
|
|
Force allow for all apps (registry value 1). All apps are permitted to activate with voice commands from the lock screen, overriding individual user settings. |
|
|
Force deny for all apps (registry value 2). All apps are blocked from activating with voice commands from the lock screen. CIS L1 recommended value. |
Used by
ComputerAdministrativeTemplatestype: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.
Example
Example
"USER_CONTROL"