Showing posts with label Microsoft. Show all posts
Showing posts with label Microsoft. Show all posts

588-Certificate Templates


Group Policy : Certificate Templates

 
Group Policy Supported on :
Group Policy Explain :
   Permits or prohibits use of this snap-in. If you enable this setting, the snap-in is permitted. If you disable the setting, the snap-in is prohibited. If this setting is not configured, the setting of the Restrict users to the explicitly permitted list of snap-ins setting determines whether this snap-in is permitted or prohibited. -- If Restrict users to the explicitly permitted list of snap-ins is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this setting. If this setting is not configured (or disabled), this snap-in is prohibited. -- If Restrict users to the explicitly permitted list of snap-ins is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this setting. If this setting is not configured (or enabled), the snap-in is permitted. When a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.
Group Policy Computer/User Node :
   USER
Group Policy Path :
   Administrative Templates\Windows Components\Microsoft Management Console\Restricted/Permitted snap-ins
  hkcu\software\policies\microsoft\mmc\{a994e107-6854-4f3d-917c-e6f01670f6d3}!restrict_run


Enhanced by Zemanta

Posted By Ahmed Gamal12:30 AM

553-Allow only per user or approved shell extensions

Group Policy : Allow only per user or approved shell extensions

 
Group Policy Supported on :
   At least Microsoft Windows 2000
Group Policy Explain :
   This setting is designed to ensure that shell extensions can operate on a per-user basis. If you enable this setting, Windows is directed to only run those shell extensions that have either been approved by an administrator or that will not impact other users of the machine. A shell extension only runs if there is an entry in at least one of the following locations in registry. For shell extensions that have been approved by the administrator and are available to all users of the computer, there must be an entry at HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved. For shell extensions to run on a per-user basis, there must be an entry at HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved.
Group Policy Computer/User Node :
   USER
   Administrative Templates\Windows Components\Windows Explorer
  hkcu\software\microsoft\windows\currentversion\policies\explorer!enforceshellextensionsecurity


Enhanced by Zemanta

Posted By Ahmed Gamal7:30 AM

535-Turn off Windows Movie Maker saving to online video hosting provider


Group Policy : Turn off Windows Movie Maker saving to online video hosting provider

 
Group Policy Supported on :
   At least Microsoft Windows XP Professional with SP2
Group Policy Explain :
   Specifies whether users can send a final movie to a video hosting provider on the Web by choosing The Web saving option in the Save Movie Wizard of Windows Movie Maker. When users create a movie in Windows Movie Maker, they can choose to share it in a variety of ways through the Save Movie Wizard. The Web saving option lets users send their movies to a video hosting provider. If you enable this setting, users cannot choose The Web saving option in the Save Movie Wizard of Windows Movie Maker and cannot send a movie to a video hosting provider on the Web. If you disable or do not configure this setting, users can choose The Web saving option in the Save Movie Wizard of Windows Movie Maker and can send a movie to a video hosting provider on the Web.
Group Policy Computer/User Node :
   USER
Group Policy Path :
   Administrative Templates\System\Internet Communication Management\Internet Communication settings
  hkcu\software\policies\microsoft\windowsmoviemaker!webpublish


Enhanced by Zemanta

Posted By Ahmed Gamal10:30 PM

534-Turn off Windows Movie Maker online Web links


Group Policy : Turn off Windows Movie Maker online Web links

 
Group Policy Supported on :
   At least Microsoft Windows XP Professional with SP2
Group Policy Explain :
   Specifies whether links to Web sites are available in Windows Movie Maker. These links include the Windows Movie Maker on the Web and Privacy Statement commands that appear on the Help menu, as well as the Learn more about video filters hyperlink in the Options dialog box and the sign up now hyperlink in the The Web saving option in the Save Movie Wizard. The Windows Movie Maker on the Web command lets users go directly to the Windows Movie Maker Web site to get more information, and the Privacy Statement command lets users view information about privacy issues in respect to Windows Movie Maker. The Learn more about video filters hyperlink lets users learn more about video filters and their role in saving movies process in Windows Movie Maker. The sign up now hyperlink lets users sign up with a video hosting provider on the Web. If you enable this setting, the previously mentioned links to Web sites from Windows Movie Maker are disabled and cannot be selected. If you disable or do not configure this setting, the previously mentioned links to Web sites from Windows Movie Maker are enabled and can be selected.
Group Policy Computer/User Node :
   USER
Group Policy Path :
   Administrative Templates\System\Internet Communication Management\Internet Communication settings
Group Policy Registry Settings :
  hkcu\software\policies\microsoft\windowsmoviemaker!webhelp


Enhanced by Zemanta

Posted By Ahmed Gamal10:00 PM

533-Turn off Windows Movie Maker automatic codec downloads


Group Policy : Turn off Windows Movie Maker automatic codec downloads

 
Group Policy Supported on :
   At least Microsoft Windows XP Professional with SP2
Group Policy Explain :
   Specifies whether Windows Movie Maker automatically downloads codecs. Windows Movie Maker can be configured so that codecs are downloaded automatically if the required codecs are not installed on the computer. If you enable this setting, Windows Movie Maker will not attempt to download missing codecs for imported audio and video files. If you disable or do not configure this setting, Windows Movie Maker might attempt to download missing codecs for imported audio and video files.
Group Policy Computer/User Node :
   USER
Group Policy Path :
   Administrative Templates\System\Internet Communication Management\Internet Communication settings
  hkcu\software\policies\microsoft\windowsmoviemaker!codecdownload


Enhanced by Zemanta

Posted By Ahmed Gamal9:30 PM

530-Turn off Internet File Association service


Group Policy : Turn off Internet File Association service

 
Group Policy Supported on :
   At least Microsoft Windows XP Professional or Windows Server 2003 family
Group Policy Explain :
   Specifies whether to use the Microsoft Web service for finding an application to open a file with an unhandled file association. When a user opens a file that has an extension that is not associated with any applications on the machine, the user is given the choice to choose a local application or use the Web service to find an application. If you enable this setting, the link and the dialog for using the Web service to open an unhandled file association are removed. If you disable or do not configure this setting, the user will be allowed to use the Web service.
Group Policy Computer/User Node :
   USER
Group Policy Path :
   Administrative Templates\System\Internet Communication Management\Internet Communication settings
  hkcu\software\microsoft\windows\currentversion\policies\explorer!nointernetopenwith



Enhanced by Zemanta

Posted By Ahmed Gamal8:00 PM

529-Turn off the Windows Messenger Customer Experience Improvement Program


Group Policy : Turn off the Windows Messenger Customer Experience Improvement Program

 
Group Policy Supported on :
   At least Microsoft Windows XP Professional with SP2 or Windows Server 2003 family
Group Policy Explain :
   Specifies whether Windows Messenger collects anonymous information about how Windows Messenger software and service is used. With the Customer Experience Improvement program, users can allow Microsoft to collect anonymous information about how the product is used. This information is used to improve the product in future releases. If you enable this setting, Windows Messenger will not collect usage information and the user settings to enable the collection of usage information will not be shown. If you disable this setting, Windows Messenger will collect anonymous usage information and the setting will not be shown. If you do not configure this setting, users will have the choice to opt-in and allow information to be collected.
Group Policy Computer/User Node :
   USER
Group Policy Path :
   Administrative Templates\System\Internet Communication Management\Internet Communication settings
  hkcu\software\policies\microsoft\messenger\client!ceip


Enhanced by Zemanta

Posted By Ahmed Gamal7:30 PM

525-Restrict Internet communication


Group Policy : Restrict Internet communication

 
Group Policy Supported on :
   At least Microsoft Windows XP Professional with SP2
Group Policy Explain :
   Specifies whether Windows can access the Internet to accomplish tasks that require Internet resources. If this setting is enabled, all of the the policy settings listed in the Internet Communication settings section will be set to enabled. If this setting is disabled, all of the the policy settings listed in the 'Internet Communication settings' section will be set to disabled. If this setting is not configured, all of the the policy settings in the 'Internet Communication settings' section will be set to not configured.
Group Policy Computer/User Node :
   USER
Group Policy Path :
Group Policy Registry Settings :
  HKCU\Software\Policies\Microsoft\InternetManagement!RestrictCommunication, HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer!NoPublishingWizard, HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer!NoWebServices, HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer!NoOnlinePrintsWizard, HKCU\Software\Policies\Microsoft\Messenger\Client!CEIP, HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer!NoInternetOpenWith, HKCU\Software\Policies\Microsoft\Windows NT\Printers!DisableHTTPPrinting, HKCU\Software\Policies\Microsoft\Windows NT\Printers!DisableWebPnPDownload, HKCU\Software\Policies\Microsoft\WindowsMovieMaker!CodecDownload, HKCU\Software\Policies\Microsoft\WindowsMovieMaker!WebHelp, HKCU\Software\Policies\Microsoft\WindowsMovieMaker!WebPublish, HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer!NoPublishingWizard, HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer!NoWebServices, HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer!NoOnlinePrintsWizard, HKCU\Software\Policies\Microsoft\Messenger\Client!CEIP, HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer!NoInternetOpenWith, HKCU\Software\Policies\Microsoft\Windows NT\Printers!DisableHTTPPrinting, HKCU\Software\Policies\Microsoft\Windows NT\Printers!DisableWebPnPDownload, HKCU\Software\Policies\Microsoft\WindowsMovieMaker!CodecDownload, HKCU\Software\Policies\Microsoft\WindowsMovieMaker!WebHelp, HKCU\Software\Policies\Microsoft\WindowsMovieMaker!WebPublish

Enhanced by Zemanta

Posted By Ahmed Gamal5:30 PM

521-Enforce Show Policies Only


Group Policy : Enforce Show Policies Only

 
Group Policy Supported on :
   At least Microsoft Windows 2000
Group Policy Explain :
   Prevents administrators from viewing or using Group Policy preferences. A Group Policy administration (.adm) file can contain both true settings and preferences. True settings, which are fully supported by Group Policy, must use registry entries in the Software\Policies or Software\Microsoft\Windows\CurrentVersion\Policies registry subkeys. Preferences, which are not fully supported, use registry entries in other subkeys. If you enable this setting, the Show Policies Only command is turned on, and administrators cannot turn it off. As a result, Group Policy Object Editor displays only true settings; preferences do not appear. If you disable this setting or do not configure it, the Show Policies Only command is turned on by default, but administrators can view preferences by turning off the Show Policies Only command. Note: To find the Show Policies Only command, in Group Policy Object Editor, click the Administrative Templates folder (either one), right-click the same folder, and then point to View. In Group Policy Object Editor, preferences have a red icon to distinguish them from true settings, which have a blue icon.
Group Policy Computer/User Node :
   USER
Group Policy Path :
   Administrative Templates\System\Group Policy
  hkcu\software\policies\microsoft\windows\group policy editor!showpoliciesonly


Enhanced by Zemanta

Posted By Ahmed Gamal3:30 PM

515-Do not process the legacy run list


Group Policy : Do not process the legacy run list

 
Group Policy Supported on :
   At least Microsoft Windows 2000
Group Policy Explain :
   Ignores the customized run list. You can create a customized list of additional programs and documents that the system starts automatically when it runs on Windows XP Professional, Windows 2000 Professional, Windows NT Workstation 4.0 and earlier. These programs are added to the standard run list of programs and services that the system starts. If you enable this setting, the system ignores the run list for Windows NT Workstation 4.0, Windows 2000 Professional, and Windows XP Professional. If you disable or do not configure this setting, Windows 2000 adds any customized run list configured for Windows NT 4.0 and earlier to its run list. Deze instelling verschijnt in de Computerconfiguratie en Gebruikersconfiguratie mappen. If both policies are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration. Note: To create a customized run list by using a policy, use the Run these applications at startup setting. The customized run lists for Windows NT 4.0 and earlier are stored in the registry in HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\Run. They can be configured by using the Run setting in System Policy Editor for Windows NT 4.0 and earlier. Also, see the Do not process the run once list setting.
Group Policy Computer/User Node :
   USER
Group Policy Path :
   Administrative Templates\System\Logon
Group Policy Registry Settings :
  hkcu\software\microsoft\windows\currentversion\policies\explorer!disablecurrentuserrun


Enhanced by Zemanta

Posted By Ahmed Gamal12:30 PM

501-Windows Automatic Updates


Group Policy : Windows Automatic Updates

 
Group Policy Supported on :
   Only works on Microsoft Windows XP Professional
Group Policy Explain :
   This setting controls automatic updates to a user's computer. Whenever a user connects to the Internet, Windows searches for updates available for the software and hardware on their computer and automatically downloads them. This happens in the background, and the user is prompted when downloaded components are ready to be installed, or prior to downloading, depending on their configuration. If you enable this setting, it prohibits Windows from searching for updates. If you disable or do not configure it, Windows searches for updates and automatically downloads them. Note: Windows Update is an online catalog customized for your computer that consists of items such as drivers, critical updates, Help files, and Internet products that you can download to keep your computer up to date. Also, see the Remove links and access to Windows Update setting. If the Remove links and access to Windows Update setting is enabled, the links to Windows Update on the Start menu are also removed. Note: If you have installed Windows XP Service Pack 1 or the update to Automatic Updates that was released after Windows XP was originally shipped, then you should use the new Automatic Updates settings located at: 'Computer Configuration / Administrative Templates / Windows Update'
Group Policy Computer/User Node :
   USER
Group Policy Path :
   Administrative Templates\System
  hkcu\software\microsoft\windows\currentversion\policies\explorer!noautoupdate


Enhanced by Zemanta

Posted By Ahmed Gamal5:30 AM

478-Ability to delete all user remote access connections


Group Policy : Ability to delete all user remote access connections



Group Policy Supported on :
   At least Microsoft Windows 2000 Service Pack 1
Group Policy Explain :
   Determines whether users can delete all user remote access connections. To create an all-user remote access connection, on the Connection Availability page in the New Connection Wizard, click the For all users option. If you enable this setting, all users can delete shared remote access connections. In addition, if your file system is NTFS, users need to have Write access to Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk to delete a shared remote access connection. If you disable this setting (and enable the Enable Network Connections settings for Administrators setting), users (including administrators) cannot delete all-user remote access connections. (By default, users can still delete their private connections, but you can change the default by using the Prohibit deletion of remote access connections setting.) Important: If the Enable Network Connections settings for Administrators is disabled or not configured, this setting will not apply to administrators on post-Windows 2000 computers. If you do not configure this setting, only Administrators and Network Configuration Operators can delete all user remote access connections. Important: When enabled, the Prohibit deletion of remote access connections setting takes precedence over this setting. Users (including administrators) cannot delete any remote access connections, and this setting is ignored. Note: LAN connections are created and deleted automatically by the system when a LAN adapter is installed or removed. You cannot use the Network Connections folder to create or delete a LAN connection. Note: This setting does not prevent users from using other programs, such as Internet Explorer, to bypass this setting.
Group Policy Computer/User Node :
   USER
Group Policy Path :
   Administrative Templates\Network\Network Connections
Group Policy Registry Settings :
  hkcu\software\policies\microsoft\windows\network connections!nc_deletealluserconnection


Enhanced by Zemanta

Posted By Ahmed Gamal6:00 PM