Commonly used Windows Group Policy Items


  1. Enable AD User and Computers management MMC in Windows 7
    1. "Control Panel -> Programs and Features -> Turn Windows features on or off -> Remote Server Administration Tools -> AD DS and AD LDS Tools"
      控制台\程式集\開啟或關閉Windows功能 --> 遠端伺服器管理工具\角色管理工具\AD DS與AD LDS工具
    2. (Optional) If you cannot find "Remote Server Administration Tools", you may need to download and install.
  2. Group Policy Management Console 群組原則管理 (gpmc.msc)
    1. You may need to enable first:
      "Control Panel -> Programs and Features -> Turn Windows features on or off -> Remote Server Administration Tools -> Group Policy Management Tools"控制台\程式集\開啟或關閉Windows功能 --> 遠端伺服器管理工具\功能管理工具\群組原則管理工具
  3. Prevent access to command line
    1. User Configuration\Administrative Templates\System\Prevent access to the command prompt
      使用者設定\原則\系統管理範本\系統\防止存取命提示字元
  4. Remove Windows Explorer's default context menu
    1. User Configuration\Administrative Templates\Windows Explorer
      使用者設定\原則\系統管理範本\Windows元件\Windows檔案總管
  5. Stop Control Panel
    1. User Configuration\Administrative Templates\Control Panel\Prohibit access to the Control Panel
      使用者設定\原則\系統管理範本\控制台\禁止存取控制台
  6. Enable specific items inside control panel
    1. Must enable Control Panel first
    2. User Configuration\Administrative Templates\Control Panel\Show only specified Control Panel items
      使用者設定\原則\系統管理範本\控制台\只顯示指定的控制台項目
    3. User Configuration\Administrative Templates\Control Panel\Show only specified Control Panel items
      使用者設定\原則\系統管理範本\控制台\只顯示指定的控制台項目
    4. You need to enter the which item to be allowed to run.  Please refer to here or here (Win7)

Reference: TechNet

Comments