{"id":1343,"date":"2015-01-22T21:37:27","date_gmt":"2015-01-23T02:37:27","guid":{"rendered":"http:\/\/adsecurity.org\/?p=1343"},"modified":"2015-01-29T22:15:23","modified_gmt":"2015-01-30T03:15:23","slug":"group-policy-settings-reference-for-windows-8-1-and-windows-server-2012-r2","status":"publish","type":"post","link":"https:\/\/adsecurity.org\/?p=1343","title":{"rendered":"Group Policy Settings Reference for Windows 8.1 and Windows Server 2012 R2"},"content":{"rendered":"<p>&nbsp;<\/p>\n<blockquote><p>These spreadsheets list the policy settings for computer and user configurations that are included in the Administrative template files delivered with the Windows operating systems specified. You can configure these policy settings when you edit Group Policy Objects.<\/p><\/blockquote>\n<p>The Group Policy Settings reference for Windows &amp; Windows Server can be downloaded <a href=\"http:\/\/www.microsoft.com\/en-us\/download\/confirmation.aspx?id=25250\">here<\/a>.<\/p>\n<p>Here are the key new Windows 8.1 &amp; Windows Server 2012 R2 Group Policy Settings:<br \/>\n<!--more--><\/p>\n<blockquote>\n<table width=\"954\">\n<tbody>\n<tr>\n<td width=\"193\">File Name<\/td>\n<td width=\"602\">Policy Setting Name<\/td>\n<td width=\"159\">Scope<\/td>\n<\/tr>\n<tr>\n<td>AppXRuntime.admx<\/td>\n<td>Allow Microsoft accounts to be optional<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>AppXRuntime.admx<\/td>\n<td>Allow Microsoft accounts to be optional<\/td>\n<td>User<\/td>\n<\/tr>\n<tr>\n<td>FileRevocation.admx<\/td>\n<td>Allow Windows Runtime apps to revoke enterprise data<\/td>\n<td>User<\/td>\n<\/tr>\n<tr>\n<td>kerberos.admx<\/td>\n<td>Always send compound authentication first<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>ErrorReporting.admx<\/td>\n<td>Automatically send memory dumps for OS-generated error reports<\/td>\n<td>User<\/td>\n<\/tr>\n<tr>\n<td>ErrorReporting.admx<\/td>\n<td>Automatically send memory dumps for OS-generated error reports<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>grouppolicy.admx<\/td>\n<td>Configure Group Policy Caching<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>grouppolicy.admx<\/td>\n<td>Configure Logon Script Delay<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>EdgeUI.admx<\/td>\n<td>Disable help tips<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>EdgeUI.admx<\/td>\n<td>Disable help tips<\/td>\n<td>User<\/td>\n<\/tr>\n<tr>\n<td>Taskbar.admx<\/td>\n<td>Do not allow pinning Store app to the Taskbar<\/td>\n<td>User<\/td>\n<\/tr>\n<tr>\n<td>WindowsUpdate.admx<\/td>\n<td>Do not connect to any Windows Update Internet locations<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>EdgeUI.admx<\/td>\n<td>Do not show recent apps when the mouse is pointing to the upper-left corner of the screen<\/td>\n<td>User<\/td>\n<\/tr>\n<tr>\n<td>SettingSync.admx<\/td>\n<td>Do not sync Apps<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>SettingSync.admx<\/td>\n<td>Do not sync start settings<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>grouppolicy.admx<\/td>\n<td>Enable Group Policy Caching for Servers<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>ControlPanelDisplay.admx<\/td>\n<td>Force a specific background and accent color<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>ControlPanelDisplay.admx<\/td>\n<td>Force a specific Start background<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>WorkFolders-Client.admx<\/td>\n<td>Force automatic setup for all users<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>StartMenu.admx<\/td>\n<td>Go to the desktop instead of Start when signing in<\/td>\n<td>User<\/td>\n<\/tr>\n<tr>\n<td>AuditSettings.admx<\/td>\n<td>Include command line in process creation events<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>StartMenu.admx<\/td>\n<td>List desktop apps first in the Apps view<\/td>\n<td>User<\/td>\n<\/tr>\n<tr>\n<td>StartMenu.admx<\/td>\n<td>Pin Apps to Start when installed<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>StartMenu.admx<\/td>\n<td>Pin Apps to Start when installed<\/td>\n<td>User<\/td>\n<\/tr>\n<tr>\n<td>ControlPanelDisplay.admx<\/td>\n<td>Prevent enabling lock screen camera<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>ControlPanelDisplay.admx<\/td>\n<td>Prevent enabling lock screen slide show<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>SkyDrive.admx<\/td>\n<td>Prevent OneDrive files from syncing over metered connections<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>SkyDrive.admx<\/td>\n<td>Prevent the usage of OneDrive for file storage<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>EdgeUI.admx<\/td>\n<td>Prevent users from replacing the Command Prompt with Windows PowerShell in the menu they see when they right-click the lower-left corner or press the Windows logo key+X<\/td>\n<td>User<\/td>\n<\/tr>\n<tr>\n<td>kdc.admx<\/td>\n<td>Request compound authentication<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>CredSsp.admx<\/td>\n<td>Restrict delegation of credentials to remote servers<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>SkyDrive.admx<\/td>\n<td>Save documents and pictures to the local PC by default<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>SkyDrive.admx<\/td>\n<td>Save documents to OneDrive by default<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>StartMenu.admx<\/td>\n<td>Search just apps from the Apps view<\/td>\n<td>User<\/td>\n<\/tr>\n<tr>\n<td>EdgeUI.admx<\/td>\n<td>Search Share Start Devices and Settings don&#8217;t appear when the mouse is pointing to the upper-right corner of the screen<\/td>\n<td>User<\/td>\n<\/tr>\n<tr>\n<td>WPN.admx<\/td>\n<td>Set the time Quiet Hours begins each day<\/td>\n<td>User<\/td>\n<\/tr>\n<tr>\n<td>WPN.admx<\/td>\n<td>Set the time Quiet Hours ends each day<\/td>\n<td>User<\/td>\n<\/tr>\n<tr>\n<td>StartMenu.admx<\/td>\n<td>Show Start on the display the user is using when they press the Windows logo key<\/td>\n<td>User<\/td>\n<\/tr>\n<tr>\n<td>StartMenu.admx<\/td>\n<td>Show the Apps view automatically when the user goes to Start<\/td>\n<td>User<\/td>\n<\/tr>\n<tr>\n<td>Taskbar.admx<\/td>\n<td>Show Windows Store apps on the taskbar<\/td>\n<td>User<\/td>\n<\/tr>\n<tr>\n<td>WinLogon.admx<\/td>\n<td>Sign-in last interactive user automatically after a system-initiated restart<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>WorkFolders-Client.admx<\/td>\n<td>Specify Work Folders settings<\/td>\n<td>User<\/td>\n<\/tr>\n<tr>\n<td>StartMenu.admx<\/td>\n<td>Start Screen Layout<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>StartMenu.admx<\/td>\n<td>Start Screen Layout<\/td>\n<td>User<\/td>\n<\/tr>\n<tr>\n<td>WinStoreUI.admx<\/td>\n<td>Turn off Automatic Download and Install of updates<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>WPN.admx<\/td>\n<td>Turn off calls during Quiet Hours<\/td>\n<td>User<\/td>\n<\/tr>\n<tr>\n<td>WPN.admx<\/td>\n<td>Turn off Quiet Hours<\/td>\n<td>User<\/td>\n<\/tr>\n<tr>\n<td>UserProfiles.admx<\/td>\n<td>Turn off the advertising ID<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>EAIME.admx<\/td>\n<td>Turn on cloud candidate<\/td>\n<td>User<\/td>\n<\/tr>\n<tr>\n<td>AppXRuntime.admx<\/td>\n<td>Turn on dynamic Content URI Rules for Windows store apps<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>TerminalServer.admx<\/td>\n<td>Use advanced RemoteFX graphics for RemoteApp<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>NetLogon.admx<\/td>\n<td>Use DNS name resolution when a single-label domain name is used by appending different registered DNS suffixes if the AllowSingleLabelDnsDomain setting is not enabled.<\/td>\n<td>Machine<\/td>\n<\/tr>\n<tr>\n<td>Terminalserver-Server.admx<\/td>\n<td>Use the hardware default graphics adapter for all Remote Desktop Services sessions<\/td>\n<td>Machine<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/blockquote>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; These spreadsheets list the policy settings for computer and user configurations that are included in the Administrative template files delivered with the Windows operating systems specified. You can configure these policy settings when you edit Group Policy Objects. The Group Policy Settings reference for Windows &amp; Windows Server can be downloaded here. Here are &hellip; <\/p>\n<p><a class=\"more-link btn\" href=\"https:\/\/adsecurity.org\/?p=1343\">Continue reading<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[418,417,307,54],"class_list":["post-1343","post","type-post","status-publish","format-standard","hentry","category-technical-reference","tag-gposettingsreference","tag-grouppolicysettingsreference","tag-windows8-1","tag-windowsserver2012r2","item-wrap"],"_links":{"self":[{"href":"https:\/\/adsecurity.org\/index.php?rest_route=\/wp\/v2\/posts\/1343","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/adsecurity.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/adsecurity.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/adsecurity.org\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/adsecurity.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1343"}],"version-history":[{"count":2,"href":"https:\/\/adsecurity.org\/index.php?rest_route=\/wp\/v2\/posts\/1343\/revisions"}],"predecessor-version":[{"id":1389,"href":"https:\/\/adsecurity.org\/index.php?rest_route=\/wp\/v2\/posts\/1343\/revisions\/1389"}],"wp:attachment":[{"href":"https:\/\/adsecurity.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1343"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/adsecurity.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1343"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/adsecurity.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1343"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}