Complete List of Windows 11 Group Policy Settings for Device and User Management

Key Takeaways

  • Complete List of Windows 11 Group Policy Settings for Device and User Management
  • Windows 11 continues to receive new and updated Group Policy settings to support the latest features and security requirements.
  • Administrators can use Group Policy and ADMX templates to manage Windows 11 devices and control user and device settings.
  • Many policies are available for Windows 11 version 21H2 and later, depending on the specific policy and Windows edition.
  • Group Policy settings can help organizations manage areas such as security, system behavior, user experience, and device configuration.
  • IT administrators should keep their Windows ADMX templates updated so they can access the latest policy settings.
  • For organizations using Microsoft Intune, many ADMX-backed policies can also be managed through Intune, providing a modern cloud-based management approach.

Microsoft continues to update Windows 11 Group Policy settings to support new features, security improvements, and device management requirements. With the latest Windows 11 25H2 Administrative Templates (ADMX/ADML), administrators can access updated policy settings for areas such as security, Windows Update, Microsoft Defender, device management, user experience, and system configuration. Microsoft also provides Administrative Templates for Windows 11 24H2 and 23H2, making it easier for IT administrators to manage different Windows 11 environments.

Table of content

Complete List of Windows 11 Group Policy Settings for Device and User Management

How to get Windows 11? Microsoft released different editions of Windows 11 ISOs (Consumer and Business). You can download the Windows 11 ISO directly from the Microsoft Software Download website. You don’t have to log in to download the ISO. To get the details about the latest version of the Windows 11 ISO download (production version), the latest Windows 11 ISO is ready to download the production version.

The devices should meet the Windows 11 minimum requirements for Windows 11 upgrade. Using the PC Health Check app, you can check for compatibility to see if your current PC meets the minimum system requirements to run Windows 11. You have to download the Windows 11 PC Health Check App from the Microsoft site. Here let’s explore the Windows 11 Group Policy; if you are looking to get Group Policy settings added in Windows 10, version 21H1, and earlier.

The best way to find the list of policies from the blog post below – 

Patch My PC
Complete List of Windows 11 Group Policy Settings for Device and User Management - Fig.1
Complete List of Windows 11 Group Policy Settings for Device and User Management – Fig.1

List of Windows 11 Group Policy Settings

The following Windows 11 Group Policy Settings lists for computer and user configurations are included in the Administrative template files (.admx and .adml) delivered with Windows 11. We will try to keep the list up to date with the latest Windows 11 Group Policy.

LocationPolicy Path Policy Setting Name
MachineSystem > Group PolicyTurn off background refresh of Group Policy
MachineSystem > Group PolicyConfigure user Group Policy loopback processing mode
MachineSystem > Group PolicyTurn off automatic update of ADM files
MachineSystem > GroupAlways use local ADM files for Group Policy Object Editor
MachineSystem > Group PolicyEnable Group Policy Caching for Servers
MachineSystem > Mitigation OptionsProcess Mitigation Options
MachineSystem > Group PolicyPhone-PC linking on this device
MachineNetwork > DNS ClientConfigure DNS over HTTPS (DoH) name resolution
MachineSystem > KerberosAllow retrieving the cloud Kerberos ticket during logon
MachineSystem > Device Installation > Device Installation RestrictionsApply layered order of evaluation for Allow and Prevent device installation policies
Machine Windows Components > Windows Hello for BusinessUse cloud trust for on-premises authentication
Machine Windows Components > Human PresenceForce Instant Lock
MachineWindows Components > Human PresenceForce Instant Wake
MachineWindows Components > Human PresenceLock Timeout
MachineWindows Components > Windows SandboxAllow audio input in Windows Sandbox
MachineWindows Components > Windows SandboxAllow clipboard sharing with Windows Sandbox
MachineWindows Components > Windows SandboxAllow networking in Windows Sandbox
MachineWindows Components > Windows SandboxAllow printer sharing with Windows Sandbox
MachineWindows Components > Windows SandboxAllow vGPU sharing for Windows Sandbox
Machine Windows Components > Windows SandboxAllow video input in Windows Sandbox
MachineWindows Components > Remote Desktop Services > Remote Desktop Session Host > Device and Resource RedirectionAllow UI Automation redirection
MachineWindows Components > Remote Desktop Services > Remote Desktop Session Host > Device and ResourceRedirection Do not allow location redirection
MachineWindows Components > WidgetsAllow widgets
MachineWindows Components > Microsoft Defender Antivirus > Real-time ProtectionTurn on script scanning
MachineWindows Components > Microsoft Defender Antivirus > Device ControlDefine device control policy groups
MachineWindows Components > Microsoft Defender Antivirus > Device ControlDefine device control policy rules
MachineWindows Components > Microsoft Defender Antivirus > Security Intelligence UpdatesAllow Microsoft Defender Antivirus to update over a metered connection
MachineWindows Components > Microsoft Defender AntivirusConfigure scheduled task times randomization window
MachineWindows Components > App Package DeploymentArchive infrequently used apps
MachineWindows Components > App Package DeploymentDo not allow sideloaded apps to auto-update in the background
MachineWindows Components > App PrivacyLet Windows apps take screenshots of various windows or displays
MachineWindows Components > Cloud ContentTurn off cloud consumer account state content
MachineWindows Components > Data Collection and Preview BuildsLimit Diagnostic Log Collection
MachineWindows Components > Data Collection and Preview BuildsLimit Dump Collection
MachineWindows Components > Windows Update > Manage updates offered from Windows Server Update ServiceSpecify source service for specific classes of Windows Updates
UserSystem > Group PolicyTurn off automatic update of ADM files
User Start Menu and TaskbarStart Menu and TaskbarShow or hide “Most used” list from Start menu
UserWindows Components > Cloud ContentTurn off Spotlight collection on Desktop
UserWindows Components > IMEConfigure Korean IME version
Machine Control Panel\PersonalizationPrevent lock screen background motion
Machine Control Panel\Regional and Language OptionsRestrict Language Pack and Language Feature Installation
Machine MS Security GuideLimits print driver installation to Administrators.
Machine Network\DNS ClientConfigure DNS over HTTPS (DoH) name resolution
Machine PrintersEnable Device Control Printing Restrictions
Machine PrintersList of Approved USB-connected print devices
Machine Start Menu and TaskbarShow or hide “Most used” list from Start menu
Machine Start Menu and Taskbar\NotificationsEnables group policy for the WNS FQDN
Machine System\Device Installation\Device Installation RestrictionsApply layered order of evaluation for Allow and Prevent device installation policies across all device match criteria
Machine System\Filesystem\NTFSEnable NTFS non-paged pool usage
Machine System\Filesystem\NTFSNTFS default tier
Machine System\Filesystem\NTFSNTFS parallel flush threshold
Machine System\Filesystem\NTFSNTFS parallel flush worker threads
Machine System\KerberosAllow retrieving the cloud kerberos ticket during the logon
Machine System\Net Logon\DC Locator DNS RecordsUse lowercase DNS host names when registering domain controller SRV records
Machine System\Security Account ManagerConfigure validation of ROCA-vulnerable WHfB keys during authentication
MachineWindows Components\App Package DeploymentArchive infrequently used apps
MachineWindows Components\App Package DeploymentNot allow sideloaded apps to auto-update in the background
MachineWindows Components\App Package DeploymentNot allow sideloaded apps to auto-update in the background on a metered network
MachineWindows Components\App PrivacyLet Windows apps take screenshots of various windows or displays
MachineWindows Components\App PrivacyLet Windows apps turn off the screenshot border
MachineWindows Components\ChatConfigures the Chat icon on the taskbar
MachineWindows Components\Cloud ContentTurn off cloud consumer account state content
MachineWindows Components\Data Collection and Preview BuildsDisable OneSettings Downloads
MachineWindows Components\Data Collection and Preview BuildsEnable OneSettings Auditing
MachineWindows Components\Data Collection and Preview BuildsLimit Diagnostic Log Collection
MachineWindows Components\Data Collection and Preview BuildsLimit Dump Collection
MachineWindows Components\Human PresenceForce Instant Lock
MachineWindows Components\Human PresenceForce Instant Wake
MachineWindows Components\Human PresenceLock Timeout
MachineWindows Components\Internet ExplorerReplace JScript by loading JScript9Legacy in place of JScript via MSHTML/WebOC.
MachineWindows Components\Microsoft Defender AntivirusConfigure scheduled task times randomization window
MachineWindows Components\Microsoft Defender AntivirusDefine the directory path to copy support log files
MachineWindows Components\Microsoft Defender Antivirus\Device ControlDefine device control policy groups
MachineWindows Components\Microsoft Defender Antivirus\Device ControlDefine device control policy rules
MachineWindows Components\Microsoft Defender Antivirus\ExclusionsIp Address Exclusions
MachineWindows Components\Microsoft Defender Antivirus\Microsoft Defender Exploit Guard\Network ProtectionThis settings controls whether Network Protection is allowed to be configured into block or audit mode on Windows Server.
MachineWindows Components\Microsoft Defender Antivirus\Network Inspection SystemThis setting controls datagram processing for network protection.
MachineWindows Components\Microsoft Defender Antivirus\Real-time ProtectionTurn on script scanning
MachineWindows Components\Microsoft Defender Antivirus\Security Intelligence UpdatesAllows Microsoft Defender Antivirus to update and communicate over a metered connection.
MachineWindows Components\Remote Desktop Services\Remote Desktop Session Host\Device and Resource RedirectionAllow UI Automation redirection
MachineWindows Components\Remote Desktop Services\Remote Desktop Session Host\Device and Resource RedirectionDo not allow location redirection
MachineWindows Components\Tenant RestrictionsCloud Policy Details
MachineWindows Components\WidgetsAllow widgets
MachineWindows Components\Windows Hello for BusinessUse cloud trust for on-premises authentication
MachineWindows Components\Windows SandboxAllow audio input in Windows Sandbox
MachineWindows Components\Windows SandboxAllow clipboard sharing with Windows Sandbox
MachineWindows Components\Windows SandboxAllow networking in Windows Sandbox
MachineWindows Components\Windows SandboxAllow printer sharing with Windows Sandbox
MachineWindows Components\Windows SandboxAllow vGPU sharing for Windows Sandbox
MachineWindows Components\Windows SandboxAllow video input in Windows Sandbox
MachineWindows Components\Windows Update\Manage updates offered from Windows Server Update ServiceSpecify source service for specific classes of Windows Updates
UserAutoSubscriptionEnable auto-subscription
UserControl Panel\PrintersEnable Device Control Printing Restrictions
UserControl Panel\PrintersList of Approved USB-connected print devices
UserControl Panel\Regional and Language OptionsRestrict Language Pack and Language Feature Installation
UserStart Menu and TaskbarShow or hide “Most used” list from Start menu
UserWindows Components\Cloud ContentTurn off Spotlight collection on Desktop
UserWindows Components\IMEConfigure Korean IME version
UserWindows Components\Internet ExplorerReplace JScript by loading JScript9Legacy in place of JScript via MSHTML/WebOC.
Complete List of Windows 11 Group Policy Settings for Device and User Management – Table 1

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, join the WhatsApp Community  and the Whatsapp channel to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Author 

Jitesh, Microsoft MVP, has over six years of working experience in the IT Industry. He writes and shares his experiences related to Microsoft device management technologies and IT Infrastructure management. His primary focus is Windows 10/11  Deployment solution with Configuration Manager, Microsoft Deployment Toolkit (MDT), and Microsoft Intune.

6 thoughts on “Complete List of Windows 11 Group Policy Settings for Device and User Management”

  1. How do i activate this last setting that is off Windows Defender Application Contol ?!?!?!?!?!

    OS Name Microsoft Windows 11 Pro
    Version 10.0.22581 Build 22581
    Other OS Description Not Available
    OS Manufacturer Microsoft Corporation
    System Name ERIC
    System Manufacturer System manufacturer
    System Model System Product Name
    System Type x64-based PC
    System SKU SKU
    Processor AMD Ryzen 9 5950X 16-Core Processor, 4001 Mhz, 16 Core(s), 32 Logical Processor(s)
    BIOS Version/Date American Megatrends Inc. 4204, 2/24/2022
    SMBIOS Version 3.3
    Embedded Controller Version 255.255
    BIOS Mode UEFI
    BaseBoard Manufacturer ASUSTeK COMPUTER INC.
    BaseBoard Product ROG STRIX X570-E GAMING
    BaseBoard Version Rev X.0x
    Platform Role Desktop
    Secure Boot State On
    PCR7 Configuration Bound
    Windows Directory C:\WINDOWS
    System Directory C:\WINDOWS\system32
    Boot Device \Device\HarddiskVolume1
    Locale United States
    Hardware Abstraction Layer Version = “10.0.22581.1”
    User Name Eric\Administrator
    Time Zone Mountain Daylight Time
    Installed Physical Memory (RAM) 32.0 GB
    Total Physical Memory 31.9 GB
    Available Physical Memory 24.1 GB
    Total Virtual Memory 36.9 GB
    Available Virtual Memory 26.3 GB
    Page File Space 5.00 GB
    Page File C:\pagefile.sys
    Kernel DMA Protection On
    Virtualization-based security Running
    Virtualization-based security Required Security Properties Base Virtualization Support, Secure Boot
    Virtualization-based security Available Security Properties Base Virtualization Support, Secure Boot, DMA Protection, Secure Memory Overwrite, UEFI Code Readonly, Mode Based Execution Control
    Virtualization-based security Services Configured Credential Guard, Hypervisor enforced Code Integrity, Secure Launch
    Virtualization-based security Services Running Credential Guard, Hypervisor enforced Code Integrity, Hardware-enforced Stack Protection (Kernel-mode)
    Windows Defender Application Control policy Enforced
    Windows Defender Application Control user mode policy Off <<——————– This one !!
    Device Encryption Support Reasons for failed automatic device encryption: Un-allowed DMA capable bus/device(s) detected
    A hypervisor has been detected. Features required for Hyper-V will not be displayed.

    Reply

Leave a Comment