Program Execution
To create a whitelist of allowed programs, use "Run only allowed Windows Applications" in User Configuration, Adminitrative Templates, System.
To create a blacklist of disallowed programs, use "Don't run specified Windows applications" in the same folder.
Computer Configuration >> Administrative Templates
System >> Group Policy
- User Group Policy loopback processing mode: Enabled
Mode: Replace
User Configuration >> Administrative Templates
Control Panel
- Prohibit access to the Control Panel: Enabled
- Show only specified Control Panel Applets: Enabled
List of allowed Control Panel Applets: Printers
Control Panel >> Add or Remove Programs
- Hide Add New Programs page: Enabled
| Policy | Setting |
|---|---|
| Hide Add New Programs page | Enabled |
| Hide Add/Remove Windows Components page | Enabled |
| Hide Change or Remove Programs page | Enabled |
| Hide the "Add a program from CD-ROM or floppy disk" option | Enabled |
| Hide the "Add programs from Microsoft" option | Enabled |
| Hide the "Add programs from your network" option | Enabled |
| Hide the Set Program Access and Defaults page | Enabled |
| Remove Add or Remove Programs | Enabled |
| Remove Support Information | Enabled |
| Policy | Setting |
|---|---|
| Hide Appearance and Themes tab | Enabled |
| Hide Desktop tab | Enabled |
| Hide Screen Saver tab | Enabled |
| Hide Settings tab | Enabled |
| Prevent changing wallpaper | Enabled |
| Remove Display in Control Panel | Enabled |
| Screen Saver | Disabled |
| Policy | Setting |
|---|---|
| Prevent selection of windows and buttons styles | Enabled |
| Prohibit selection of font size | Enabled |
| Prohibit Theme color selection | Enabled |
| Remove Theme option | Enabled |
| Policy | Setting | ||
|---|---|---|---|
| Restrict selection of Windows menus and dialogs language | Enabled | ||
|
|||
| Policy | Setting | ||
|---|---|---|---|
| Disable Active Desktop | Enabled | ||
|
|||
| Policy | Setting | ||
| Enable Active Desktop | Disabled | ||
| Policy | Setting | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Don't display the Getting Started welcome screen at logon | Enabled | ||||||||||||
| Prevent access to registry editing tools | Enabled | ||||||||||||
|
|||||||||||||
| Policy | Setting | ||||||||||||
| Prevent access to the command prompt | Enabled | ||||||||||||
|
|||||||||||||
| Policy | Setting | ||||||||||||
| Run only allowed Windows applications | Enabled | ||||||||||||
|
|||||||||||||
| Policy | Setting | ||||||||||||
| Turn off Autoplay | Enabled | ||||||||||||
|
|||||||||||||


