ÿþ<html dir="ltr" xmlns:v="urn:schemas-microsoft-com:vml" gpmc_reportInitialized="false"> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-16" /> <title>Pupil Policy</title> <!-- Styles --> <style type="text/css"> body { background-color:#FFFFFF; border:1px solid #666666; color:#000000; font-size:68%; font-family:MS Shell Dlg; margin:0,0,10px,0; word-break:normal; word-wrap:break-word; } table { font-size:100%; table-layout:fixed; width:100%; } td,th { overflow:visible; text-align:left; vertical-align:top; white-space:normal; } .title { background:#FFFFFF; border:none; color:#333333; display:block; height:24px; margin:0px,0px,-1px,0px; padding-top:4px; position:relative; table-layout:fixed; width:100%; z-index:5; } .he0_expanded { background-color:#FEF7D6; border:1px solid #BBBBBB; color:#3333CC; cursor:hand; display:block; font-family:MS Shell Dlg; font-size:100%; font-weight:bold; height:2.25em; margin-bottom:-1px; margin-left:0px; margin-right:0px; padding-left:8px; padding-right:5em; padding-top:4px; position:relative; width:100%; } .he1_expanded { background-color:#A0BACB; border:1px solid #BBBBBB; color:#000000; cursor:hand; display:block; font-family:MS Shell Dlg; font-size:100%; font-weight:bold; height:2.25em; margin-bottom:-1px; margin-left:10px; margin-right:0px; padding-left:8px; padding-right:5em; padding-top:4px; position:relative; width:100%; } .he1 { background-color:#A0BACB; border:1px solid #BBBBBB; color:#000000; cursor:hand; display:block; font-family:MS Shell Dlg; font-size:100%; font-weight:bold; height:2.25em; margin-bottom:-1px; margin-left:10px; margin-right:0px; padding-left:8px; padding-right:5em; padding-top:4px; position:relative; width:100%; } .he2 { background-color:#C0D2DE; border:1px solid #BBBBBB; color:#000000; cursor:hand; display:block; font-family:MS Shell Dlg; font-size:100%; font-weight:bold; height:2.25em; margin-bottom:-1px; margin-left:20px; margin-right:0px; padding-left:8px; padding-right:5em; padding-top:4px; position:relative; width:100%; } .he3 { background-color:#D9E3EA; border:1px solid #BBBBBB; color:#000000; cursor:hand; display:block; font-family:MS Shell Dlg; font-size:100%; font-weight:bold; height:2.25em; margin-bottom:-1px; margin-left:30px; margin-right:0px; padding-left:11px; padding-right:5em; padding-top:4px; position:relative; width:100%; } .he4 { background-color:#E8E8E8; border:1px solid #BBBBBB; color:#000000; cursor:hand; display:block; font-family:MS Shell Dlg; font-size:100%; font-weight:bold; height:2.25em; margin-bottom:-1px; margin-left:40px; margin-right:0px; padding-left:11px; padding-right:5em; padding-top:4px; position:relative; width:100%; } .he4h { background-color:#E8E8E8; border:1px solid #BBBBBB; color:#000000; cursor:hand; display:block; font-family:MS Shell Dlg; font-size:100%; font-weight:bold; height:2.25em; margin-bottom:-1px; margin-left:45px; margin-right:0px; padding-left:11px; padding-right:5em; padding-top:4px; position:relative; width:100%; } .he4i { background-color:#F9F9F9; border:1px solid #BBBBBB; color:#000000; display:block; font-family:MS Shell Dlg; font-size:100%; margin-bottom:-1px; margin-left:45px; margin-right:0px; padding-bottom:5px; padding-left:21px; padding-top:4px; position:relative; width:100%; } .he5 { background-color:#E8E8E8; border:1px solid #BBBBBB; color:#000000; cursor:hand; display:block; font-family:MS Shell Dlg; font-size:100%; font-weight:bold; height:2.25em; margin-bottom:-1px; margin-left:50px; margin-right:0px; padding-left:11px; padding-right:5em; padding-top:4px; position:relative; width:100%; } .he5h { background-color:#E8E8E8; border:1px solid #BBBBBB; color:#000000; cursor:hand; display:block; font-family:MS Shell Dlg; font-size:100%; padding-left:11px; padding-right:5em; padding-top:4px; margin-bottom:-1px; margin-left:55px; margin-right:0px; position:relative; width:100%; } .he5i { background-color:#F9F9F9; border:1px solid #BBBBBB; color:#000000; display:block; font-family:MS Shell Dlg; font-size:100%; margin-bottom:-1px; margin-left:55px; margin-right:0px; padding-left:21px; padding-bottom:5px; padding-top: 4px; position:relative; width:100%; } DIV .expando { color:#000000; text-decoration:none; display:block; font-family:MS Shell Dlg; font-size:100%; font-weight:normal; position:absolute; right:10px; text-decoration:underline; z-index: 0; } .he0 .expando { font-size:100%; } .info, .info3, .info4, .disalign { line-height:1.6em; padding:0px,0px,0px,0px; margin:0px,0px,0px,0px; } .disalign TD { padding-bottom:5px; padding-right:10px; } .info TD { padding-right:10px; width:50%; } .info3 TD { padding-right:10px; width:33%; } .info4 TD, .info4 TH { padding-right:10px; width:25%; } .info TH, .info3 TH, .info4 TH, .disalign TH { border-bottom:1px solid #CCCCCC; padding-right:10px; } .subtable, .subtable3 { border:1px solid #CCCCCC; margin-left:0px; background:#FFFFFF; margin-bottom:10px; } .subtable TD, .subtable3 TD { padding-left:10px; padding-right:5px; padding-top:3px; padding-bottom:3px; line-height:1.1em; width:10%; } .subtable TH, .subtable3 TH { border-bottom:1px solid #CCCCCC; font-weight:normal; padding-left:10px; line-height:1.6em; } .subtable .footnote { border-top:1px solid #CCCCCC; } .subtable3 .footnote, .subtable .footnote { border-top:1px solid #CCCCCC; } .subtable_frame { background:#D9E3EA; border:1px solid #CCCCCC; margin-bottom:10px; margin-left:15px; } .subtable_frame TD { line-height:1.1em; padding-bottom:3px; padding-left:10px; padding-right:15px; padding-top:3px; } .subtable_frame TH { border-bottom:1px solid #CCCCCC; font-weight:normal; padding-left:10px; line-height:1.6em; } .subtableInnerHead { border-bottom:1px solid #CCCCCC; border-top:1px solid #CCCCCC; } .explainlink { color:#000000; text-decoration:none; cursor:hand; } .explainlink:hover { color:#0000FF; text-decoration:underline; } .spacer { background:transparent; border:1px solid #BBBBBB; color:#FFFFFF; display:block; font-family:MS Shell Dlg; font-size:100%; height:10px; margin-bottom:-1px; margin-left:43px; margin-right:0px; padding-top: 4px; position:relative; } .filler { background:transparent; border:none; color:#FFFFFF; display:block; font:100% MS Shell Dlg; line-height:8px; margin-bottom:-1px; margin-left:43px; margin-right:0px; padding-top:4px; position:relative; } .container { display:block; position:relative; } .rsopheader { background-color:#A0BACB; border-bottom:1px solid black; color:#333333; font-family:MS Shell Dlg; font-size:130%; font-weight:bold; padding-bottom:5px; text-align:center; } .rsopname { color:#333333; font-family:MS Shell Dlg; font-size:130%; font-weight:bold; padding-left:11px; } .gponame{ color:#333333; font-family:MS Shell Dlg; font-size:130%; font-weight:bold; padding-left:11px; } .gpotype{ color:#333333; font-family:MS Shell Dlg; font-size:100%; font-weight:bold; padding-left:11px; } #uri { color:#333333; font-family:MS Shell Dlg; font-size:100%; padding-left:11px; } #dtstamp{ color:#333333; font-family:MS Shell Dlg; font-size:100%; padding-left:11px; text-align:left; width:30%; } #objshowhide { color:#000000; cursor:hand; font-family:MS Shell Dlg; font-size:100%; font-weight:bold; margin-right:0px; padding-right:10px; text-align:right; text-decoration:underline; z-index:2; word-wrap:normal; } #gposummary { display:block; } #gpoinformation { display:block; } @media print { #objshowhide{ display:none; } body { color:#000000; border:1px solid #000000; } .title { color:#000000; border:1px solid #000000; } .he0_expanded { color:#000000; border:1px solid #000000; } .he1_expanded { color:#000000; border:1px solid #000000; } .he1 { color:#000000; border:1px solid #000000; } .he2 { color:#000000; background:#EEEEEE; border:1px solid #000000; } .he3 { color:#000000; border:1px solid #000000; } .he4 { color:#000000; border:1px solid #000000; } .he4h { color:#000000; border:1px solid #000000; } .he4i { color:#000000; border:1px solid #000000; } .he5 { color:#000000; border:1px solid #000000; } .he5h { color:#000000; border:1px solid #000000; } .he5i { color:#000000; border:1px solid #000000; } } v\:* {behavior:url(#default#VML);} </style> <!-- Script 1 --> <script language="vbscript"> <!-- '================================================================================ ' String "strShowHide(0/1)" ' 0 = Hide all mode. ' 1 = Show all mode. strShowHide = 1 'Localized strings strShow = "show" strHide = "hide" strShowAll = "show all" strHideAll = "hide all" strShown = "shown" strHidden = "hidden" strExpandoNumPixelsFromEdge = "10px" Function IsSectionHeader(obj) IsSectionHeader = (obj.className = "he0_expanded") Or (obj.className = "he1_expanded") Or (obj.className = "he1") Or (obj.className = "he2") Or (obj.className = "he3") Or (obj.className = "he4") Or (obj.className = "he4h") Or (obj.className = "he5") Or (obj.className = "he5h") End Function Function IsSectionExpandedByDefault(objHeader) IsSectionExpandedByDefault = (Right(objHeader.className, Len("_expanded")) = "_expanded") End Function ' strState must be show | hide | toggle Sub SetSectionState(objHeader, strState) ' Get the container object for the section. It's the first one after the header obj. i = objHeader.sourceIndex Set all = objHeader.parentElement.document.all While (all(i).className <> "container") i = i + 1 Wend Set objContainer = all(i) If strState = "toggle" Then If objContainer.style.display = "none" Then SetSectionState objHeader, "show" Else SetSectionState objHeader, "hide" End If Else Set objExpando = objHeader.children.item(1) If strState = "show" Then objContainer.style.display = "block" objExpando.innerText = strHide ElseIf strState = "hide" Then objContainer.style.display = "none" objExpando.innerText = strShow End If End If End Sub Sub ShowSection(objHeader) SetSectionState objHeader, "show" End Sub Sub HideSection(objHeader) SetSectionState objHeader, "hide" End Sub Sub ToggleSection(objHeader) SetSectionState objHeader, "toggle" End Sub '================================================================================ ' When user clicks anywhere in the document body, determine if user is clicking ' on a header element. '================================================================================ Function document_onclick() Set strsrc = window.event.srcElement While (strsrc.className = "sectionTitle" Or strsrc.className = "expando" Or strsrc.className = "vmlimage") Set strsrc = strsrc.parentElement Wend ' Only handle clicks on headers. If Not IsSectionHeader(strsrc) Then Exit Function ToggleSection strsrc window.event.returnValue = False End Function '================================================================================ ' link at the top of the page to collapse/expand all collapsable elements '================================================================================ Function objshowhide_onClick() Set objBody = document.body.all Select Case strShowHide Case 0 strShowHide = 1 objshowhide.innerText = strShowAll For Each obji In objBody If IsSectionHeader(obji) Then HideSection obji End If Next Case 1 strShowHide = 0 objshowhide.innerText = strHideAll For Each obji In objBody If IsSectionHeader(obji) Then ShowSection obji End If Next End Select End Function '================================================================================ ' onload collapse all except the first two levels of headers (he0, he1) '================================================================================ Function window_onload() ' Only initialize once. The UI may reinsert a report into the webbrowser control, ' firing onLoad multiple times. If UCase(document.documentElement.getAttribute("gpmc_reportInitialized")) <> "TRUE" Then ' Initialize sections to default expanded/collapsed state. Set objBody = document.body.all For Each obji in objBody If IsSectionHeader(obji) Then If IsSectionExpandedByDefault(obji) Then ShowSection obji Else HideSection obji End If End If Next objshowhide.innerText = strShowAll document.documentElement.setAttribute "gpmc_reportInitialized", "true" End If End Function '================================================================================ ' When direction (LTR/RTL) changes, change adjust for readability '================================================================================ Function document_onPropertyChange() If window.event.propertyName = "dir" Then Call fDetDir(UCase(document.dir)) End If End Function Function fDetDir(strDir) strDir = UCase(strDir) Select Case strDir Case "LTR" Set colRules = document.styleSheets(0).rules For i = 0 To colRules.length -1 Set nug = colRules.item(i) strClass = nug.selectorText If nug.style.textAlign = "right" Then nug.style.textAlign = "left" End If Select Case strClass Case "DIV .expando" nug.style.Left = "" nug.style.right = strExpandoNumPixelsFromEdge Case "#objshowhide" nug.style.textAlign = "right" End Select Next Case "RTL" Set colRules = document.styleSheets(0).rules For i = 0 To colRules.length -1 Set nug = colRules.item(i) strClass = nug.selectorText If nug.style.textAlign = "left" Then nug.style.textAlign = "right" End If Select Case strClass Case "DIV .expando" nug.style.Left = strExpandoNumPixelsFromEdge nug.style.right = "" Case "#objshowhide" nug.style.textAlign = "left" End Select Next End Select End Function '================================================================================ 'When printing reports, if a given section is expanded, let's says "shown" (instead of "hide" in the UI). '================================================================================ Function window_onbeforeprint() For Each obji In document.all If obji.className = "expando" Then If obji.innerText = strHide Then obji.innerText = strShown If obji.innerText = strShow Then obji.innerText = strHidden End If Next End Function '================================================================================ 'If a section is collapsed, change to "hidden" in the printout (instead of "show"). '================================================================================ Function window_onafterprint() For Each obji In document.all If obji.className = "expando" Then If obji.innerText = strShown Then obji.innerText = strHide If obji.innerText = strHidden Then obji.innerText = strShow End If Next End Function '================================================================================ ' Adding keypress support for accessibility '================================================================================ Function document_onKeyPress() If window.event.keyCode = "32" Or window.event.keyCode = "13" Or window.event.keyCode = "10" Then 'space bar (32) or carriage return (13) or line feed (10) If window.event.srcElement.className = "expando" Then Call document_onclick() : window.event.returnValue = false If window.event.srcElement.className = "sectionTitle" Then Call document_onclick() : window.event.returnValue = false If window.event.srcElement.id = "objshowhide" Then Call objshowhide_onClick() : window.event.returnValue = false End If End Function --> </script> <!-- Script 2 --> <script language="javascript"> <!-- function getExplainWindowTitle() { return document.getElementById("explainText_windowTitle").innerHTML; } function getExplainWindowStyles() { return document.getElementById("explainText_windowStyles").innerHTML; } function getExplainWindowSettingPathLabel() { return document.getElementById("explainText_settingPathLabel").innerHTML; } function getExplainWindowExplainTextLabel() { return document.getElementById("explainText_explainTextLabel").innerHTML; } function getExplainWindowPrintButton() { return document.getElementById("explainText_printButton").innerHTML; } function getExplainWindowCloseButton() { return document.getElementById("explainText_closeButton").innerHTML; } function getNoExplainTextAvailable() { return document.getElementById("explainText_noExplainTextAvailable").innerHTML; } function getExplainWindowSupportedLabel() { return document.getElementById("explainText_supportedLabel").innerHTML; } function getNoSupportedTextAvailable() { return document.getElementById("explainText_noSupportedTextAvailable").innerHTML; } function showExplainText(srcElement) { var strSettingName = srcElement.getAttribute("gpmc_settingName"); var strSettingPath = srcElement.getAttribute("gpmc_settingPath"); var strSettingDescription = srcElement.getAttribute("gpmc_settingDescription"); if (strSettingDescription == "") { strSettingDescription = getNoExplainTextAvailable(); } var strSupported = srcElement.getAttribute("gpmc_supported"); if (strSupported == "") { strSupported = getNoSupportedTextAvailable(); } var strHtml = "<html>\n"; strHtml += "<head>\n"; strHtml += "<title>" + getExplainWindowTitle() + "</title>\n"; strHtml += "<style type='text/css'>\n" + getExplainWindowStyles() + "</style>\n"; strHtml += "</head>\n"; strHtml += "<body>\n"; strHtml += "<div class='head'>" + strSettingName +"</div>\n"; strHtml += "<div class='path'><b>" + getExplainWindowSettingPathLabel() + "</b><br/>" + strSettingPath +"</div>\n"; strHtml += "<div class='path'><b>" + getExplainWindowSupportedLabel() + "</b><br/>" + strSupported +"</div>\n"; strHtml += "<div class='info'>\n"; strHtml += "<div class='hdr'>" + getExplainWindowExplainTextLabel() + "</div>\n"; strHtml += "<div class='bdy'>" + strSettingDescription + "</div>\n"; strHtml += "<div class='btn'>"; strHtml += getExplainWindowPrintButton(); strHtml += getExplainWindowCloseButton(); strHtml += "</div></body></html>"; var strDiagArgs = "height=360px, width=630px, status=no, toolbar=no, scrollbars=yes, resizable=yes "; var expWin = window.open("", "expWin", strDiagArgs); expWin.document.write(""); expWin.document.close(); expWin.document.write(strHtml); expWin.document.close(); expWin.focus(); //cancels navigation for IE. if(navigator.userAgent.indexOf("MSIE") > 0) { window.event.returnValue = false; } return false; } --> </script> </head> <body> <!-- HTML resources --> <div style="display:none;"> <div id="explainText_windowTitle">Group Policy Management</div> <div id="explainText_windowStyles"> body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } } </div> <div id="explainText_settingPathLabel">Setting Path:</div> <div id="explainText_explainTextLabel">Explanation</div> <div id="explainText_printButton"> <button name="Print" onClick="window.print()" accesskey="P"><u>P</u>rint</button> </div> <div id="explainText_closeButton"> <button name="Close" onClick="window.close()" accesskey="C"><u>C</u>lose</button> </div> <div id="explainText_noExplainTextAvailable">No explanation is available for this setting.</div> <div id="explainText_supportedLabel">Supported On:</div> <div id="explainText_noSupportedTextAvailable">Not available</div> </div><table class="title" cellpadding="0" cellspacing="0"> <tr><td colspan="2" class="gponame">Pupil Policy</td></tr> <tr> <td id="dtstamp">Data collected on: 22/03/2007 10:29:42</td> <td><div id="objshowhide" tabindex="0"></div></td> </tr> </table> <div class="gposummary"> <div class="he0_expanded"><span class="sectionTitle" tabindex="0">General</span><a class="expando" href="#"></a></div> <div class="container"><div class="he1"><span class="sectionTitle" tabindex="0">Details</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><td scope="row">Domain</td><td>mhs.internal</td></tr> <tr><td scope="row">Owner</td><td>PUPILS\Domain Admins</td></tr> <tr><td scope="row">Created</td><td>01/08/2006 13:50:20</td></tr> <tr><td scope="row">Modified</td><td>20/03/2007 12:51:56</td></tr> <tr><td scope="row">User Revisions</td><td>176 (AD), 176 (sysvol)</td></tr> <tr><td scope="row">Computer Revisions</td><td>10 (AD), 10 (sysvol)</td></tr> <tr><td scope="row">Unique ID</td><td>{BA12600A-13B4-4FEF-B597-3EA4DD1DECC2}</td></tr> <tr><td scope="row">GPO Status</td><td>Enabled</td></tr> </table></div></div> <div class="filler"></div> <div class="he1"><span class="sectionTitle" tabindex="0">Links</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info3" cellpadding="0" cellspacing="0"><tr><th scope="col">Location</th><th scope="col">Enforced</th><th scope="col">Link Status</th><th scope="col">Path</th></tr> <tr><td>Pupils</td><td>No</td><td>Enabled</td><td>mhs.internal/Moorside/Users/Pupils</td></tr> </table> <br/>This list only includes links in the domain of the GPO.</div></div> <div class="filler"></div> <div class="he1"><span class="sectionTitle" tabindex="0">Security Filtering</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><b>The settings in this GPO can only apply to the following groups, users, and computers:</b></div> <div class="he4i"> <table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Name</th></tr><tr><td>NT AUTHORITY\Authenticated Users</td></tr></table> </div> </div> <div class="filler"></div> <div class="he1"><span class="sectionTitle" tabindex="0">WMI Filtering</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><td scope="row"><b>WMI Filter Name</b></td><td>None</td></tr> <tr><td scope="row"><b>Description</b></td><td>Not applicable</td></tr> </table></div></div> <div class="filler"></div> <div class="he1"><span class="sectionTitle" tabindex="0">Delegation</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><b>These groups and users have the specified permission for this GPO</b></div> <div class="he4i"> <table class="info3" cellpadding="0" cellspacing="0"> <tr><th scope="col">Name</th><th scope="col">Allowed Permissions</th><th scope="col">Inherited</th></tr> <tr><td>NT AUTHORITY\Authenticated Users</td><td>Read (from Security Filtering)</td><td>No</td></tr> <tr><td>NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS</td><td>Read</td><td>No</td></tr> <tr><td>NT AUTHORITY\SYSTEM</td><td>Edit settings, delete, modify security</td><td>No</td></tr> <tr><td>PUPILS\Domain Admins</td><td>Edit settings, delete, modify security</td><td>No</td></tr> <tr><td>PUPILS\Enterprise Admins</td><td>Edit settings, delete, modify security</td><td>No</td></tr> </table> </div></div></div> <div class="filler"></div> </div> <div class="he0_expanded"><span class="sectionTitle" tabindex="0">Computer Configuration (Enabled)</span><a class="expando" href="#"></a></div> <div class="container"><div class="he1_expanded"><span class="sectionTitle" tabindex="0">Windows Settings</span><a class="expando" href="#"></a></div> <div class="container"><div class="he2"><span class="sectionTitle" tabindex="0">Security Settings</span><a class="expando" href="#"></a></div> <div class="container"><div class="he3"><span class="sectionTitle" tabindex="0">Account Policies/Password Policy</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td>Enforce password history</td><td>6 passwords remembered</td></tr> <tr><td>Maximum password age</td><td>30 days</td></tr> <tr><td>Minimum password age</td><td>1 days</td></tr> <tr><td>Minimum password length</td><td>6 characters</td></tr> <tr><td>Password must meet complexity requirements</td><td>Enabled</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Local Policies/User Rights Assignment</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td>Deny log on locally</td><td>morsguest</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Event Log</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td>Prevent local guests group from accessing application log</td><td>Enabled</td></tr> <tr><td>Prevent local guests group from accessing security log</td><td>Enabled</td></tr> <tr><td>Prevent local guests group from accessing system log</td><td>Enabled</td></tr> <tr><td>Retention method for application log</td><td>As needed</td></tr> <tr><td>Retention method for security log</td><td>As needed</td></tr> <tr><td>Retention method for system log</td><td>As needed</td></tr> </table> </div></div></div></div><div class="filler"></div> <div class="he1_expanded"><span class="sectionTitle" tabindex="0">Administrative Templates</span><a class="expando" href="#"></a></div> <div class="container"><div class="he3"><span class="sectionTitle" tabindex="0">System/Logon</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Always wait for the network at computer startup and logon" gpmc_settingPath="Computer Configuration/Administrative Templates/System/Logon" gpmc_settingDescription="Determines whether Windows XP waits for the network during computer startup and user logon. By default, Windows XP does not wait for the network to be fully initialized at startup and logon. Existing users are logged on using cached credentials, which results in shorter logon times. Group Policy is applied in the background once the network becomes available.&lt;br/&gt;&lt;br/&gt;Note that because this is a background refresh, extensions such as Software Installation and Folder Redirection take two logons to apply changes. To be able to operate safely, these extensions require that no users be logged on. Therefore, they must be processed in the foreground before users are actively using the computer. In addition, changes that are made to the user object, such as adding a roaming profile path, home directory, or user object logon script, may take up to two logons to be detected.&lt;br/&gt;&lt;br/&gt;If a user with a roaming profile, home directory, or user object logon script logs on to a computer, Windows XP always waits for the network to be initialized before logging the user on.&lt;br/&gt;&lt;br/&gt;If a user has never logged on to this computer before, Windows XP always waits for the network to be initialized.&lt;br/&gt;&lt;br/&gt;If you enable this setting, logons are performed in the same way as for Windows 2000 clients, in that Windows XP waits for the network to be fully initialized before users are logged on. Group Policy is applied in the foreground, synchronously.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, Windows does not wait for the network to be fully initialized and users are logged on with cached credentials. Group Policy is applied asynchronously in the background.&lt;br/&gt;&lt;br/&gt;Note: If you want to guarantee the application of Folder Redirection, Software Installation, or roaming user profile settings in just one logon, enable this setting to ensure that Windows waits for the network to be available before applying policy.&lt;br/&gt;&lt;br/&gt;Note: For servers, the startup and logon processing always behaves as if this policy setting is enabled." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Always wait for the network at computer startup and logon</a></td><td>Enabled</td></tr> </table> </div></div></div></div> <div class="filler"></div> <div class="he0_expanded"><span class="sectionTitle" tabindex="0">User Configuration (Enabled)</span><a class="expando" href="#"></a></div> <div class="container"><div class="he1_expanded"><span class="sectionTitle" tabindex="0">Windows Settings</span><a class="expando" href="#"></a></div> <div class="container"><div class="he2"><span class="sectionTitle" tabindex="0">Scripts</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4"><span class="sectionTitle" tabindex="0">Logon</span><a class="expando" href="#"></a></div> <div class="container"> <div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Name</th><th scope="col">Parameters</th></tr> <tr><td>\\gold\netlogon\logon.bat</td><td></td></tr> </table> </div></div><div class="he4"><span class="sectionTitle" tabindex="0">Logoff</span><a class="expando" href="#"></a></div> <div class="container"> <div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Name</th><th scope="col">Parameters</th></tr> <tr><td>\\gold\netlogon\logoff.bat</td><td></td></tr> </table> </div></div></div><div class="he2"><span class="sectionTitle" tabindex="0">Security Settings</span><a class="expando" href="#"></a></div> <div class="container"><div class="he3"><span class="sectionTitle" tabindex="0">Public Key Policies/Autoenrollment Settings</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td>Enroll certificates automatically</td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable3" cellpadding="0" cellspacing="0"> <tr><td scope="row">Renew expired certificates, update pending certificates, and remove revoked certificates</td><td>Disabled</td></tr> <tr><td scope="row">Update certificates that use certificate templates</td><td>Disabled</td></tr> </table></td></tr></table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Software Restriction Policies</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><td><b>Enforcement</b></td></tr> <tr><td colspan="1"> <table class="subtable3" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td>Apply software restriction policies to</td><td>All software files except libraries (such as DLLs)</td></tr> <tr><td>Apply software restriction policies to the following users</td><td>All users except local administrators</td></tr> </table> </td></tr> <tr><td><b>Designated File Types</b></td></tr> <tr><td colspan="1"> <table class="subtable" cellpadding="0" cellspacing="0"><tr><th scope="col">File Extension</th><th scope="col">File Type</th></tr> <tr><td>avi</td><td>Video Clip</td></tr> <tr><td>BAT</td><td>Windows Batch File</td></tr> <tr><td>bgi</td><td>BGInfo Configuration File</td></tr> <tr><td>COM</td><td>Application</td></tr> <tr><td>CPL</td><td>Control Panel extension</td></tr> <tr><td>EXE</td><td>Application</td></tr> <tr><td>INF</td><td>Setup Information</td></tr> <tr><td>mp3</td><td>MP3 Format Sound</td></tr> <tr><td>MSC</td><td>Microsoft Common Console Document</td></tr> <tr><td>vbs</td><td>VBScript Script File</td></tr> </table> </td></tr> <tr><td><b>Trusted Publishers</b></td></tr> <tr><td colspan="1"> <table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Allow the following users to select trusted publishers</td><td>End users</td></tr> <tr><td scope="row">Before trusting a publisher, check the following to determine if the certificate is revoked</td><td>None</td></tr> </table> </td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Software Restriction Policies/Security Levels</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td>Default Security Level</td><td>Disallowed</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Software Restriction Policies/Additional Rules</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4h"><span class="sectionTitle" tabindex="0">Hash Rules</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><td><b>GENLAUN.EXE; 27 KB; 14/12/2006 10:58:48</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">File hash</td><td>84C4757F039F69355FA85E8BAF1EAE48:27395:32771</td></tr> <tr><td scope="row">Security level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>14/12/2006 12:41:14</td></tr> </table></td></tr><tr><td><b>jrew.exe; 15 KB; 14/12/2006 10:59:02</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">File hash</td><td>998DA38CA6DADF3CC20E6DF3A2CA227E:15107:32771</td></tr> <tr><td scope="row">Security level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>14/12/2006 12:41:45</td></tr> </table></td></tr><tr><td><b>launcher.exe; 37 KB; 14/12/2006 10:58:04</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">File hash</td><td>CD7345FE0269845BC5C5A0933A56CCB1:36864:32771</td></tr> <tr><td scope="row">Security level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>14/12/2006 12:41:23</td></tr> </table></td></tr><tr><td><b>Projector.exe (8.5.0.321); Projector; Macromedia Projector; Director 8.5 Shockwave Studio; Macromedia, Inc.</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">File hash</td><td>025118C1FD3FB5C4D0F36670EBBDF1CD:1222834:32771</td></tr> <tr><td scope="row">Security level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>14/12/2006 12:41:33</td></tr> </table></td></tr><tr><td><b>ReportExe.exe (1.0.0.0); ReportExe; ReportExe; CCC</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">File hash</td><td>251BEE81C385F7D1E2A4DB27A175F2C4:32768:32771</td></tr> <tr><td scope="row">Security level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>14/12/2006 12:40:54</td></tr> </table></td></tr></table></div></div><div class="he4h"><span class="sectionTitle" tabindex="0">Path Rules</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><td><b>%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>18/01/2006 12:50:02</td></tr> </table> </td></tr><tr><td><b>%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%\*.exe</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>18/01/2006 12:50:02</td></tr> </table> </td></tr><tr><td><b>%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir%</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>18/01/2006 13:03:28</td></tr> </table> </td></tr><tr><td><b>*.mdb</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>03/01/2007 14:41:33</td></tr> </table> </td></tr><tr><td><b>\\bronze\kudos\</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>11/01/2007 08:16:00</td></tr> </table> </td></tr><tr><td><b>\\Bronze\psa\</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>09/08/2006 11:40:06</td></tr> </table> </td></tr><tr><td><b>\\BRONZE\pupils$\</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>09/08/2006 11:39:34</td></tr> </table> </td></tr><tr><td><b>\\gold\Limitlogon\</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>10/10/2006 08:03:42</td></tr> </table> </td></tr><tr><td><b>\\GOLD\netlogon\*.*</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>02/08/2006 12:40:08</td></tr> </table> </td></tr><tr><td><b>C:\CAI\</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>14/12/2006 12:24:51</td></tr> </table> </td></tr><tr><td><b>C:\Destools\pcbdm</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>02/03/2006 09:40:30</td></tr> </table> </td></tr><tr><td><b>C:\Documents and Settings\All Users\Start Menu\Programs\Startup\*.lnk</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>25/01/2006 11:22:19</td></tr> </table> </td></tr><tr><td><b>C:\History\</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>14/12/2006 12:24:59</td></tr> </table> </td></tr><tr><td><b>C:\localcai\</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>14/12/2006 12:24:44</td></tr> </table> </td></tr><tr><td><b>C:\program files\adobe\acrobat 7.0\reader\*.exe</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>18/01/2006 12:59:03</td></tr> </table> </td></tr><tr><td><b>C:\program files\adobe\photoshop 7.0\*.exe</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>18/01/2006 13:01:18</td></tr> </table> </td></tr><tr><td><b>C:\Program Files\Cascaid\Kudos\</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>03/08/2006 12:00:13</td></tr> </table> </td></tr><tr><td><b>C:\program files\Corel\</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>04/07/2006 11:29:24</td></tr> </table> </td></tr><tr><td><b>C:\Program Files\Corel\Graphics10\Programs\</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>03/04/2006 09:08:19</td></tr> </table> </td></tr><tr><td><b>C:\Program Files\Crocodile Clips\Crocodile Technology 1.6\*.exe</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>24/01/2006 14:59:51</td></tr> </table> </td></tr><tr><td><b>C:\program files\Internet Explorer\iexplore.exe</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>18/01/2006 12:53:02</td></tr> </table> </td></tr><tr><td><b>C:\Program Files\Keep I.T. Easy\Flowol 2\</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>03/05/2006 11:29:04</td></tr> </table> </td></tr><tr><td><b>C:\Program Files\LucidResearch\LASS Secondary Network\*.exe</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>30/01/2006 11:37:16</td></tr> </table> </td></tr><tr><td><b>C:\Program Files\Macromedia\Dreamweaver MX\*.exe</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>18/01/2006 12:59:51</td></tr> </table> </td></tr><tr><td><b>C:\Program Files\Macromedia\Extension Manager\*.exe</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>18/01/2006 13:00:07</td></tr> </table> </td></tr><tr><td><b>C:\Program Files\Macromedia\Firework MX\*.exe</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>18/01/2006 13:00:21</td></tr> </table> </td></tr><tr><td><b>C:\Program Files\Macromedia\Flash MX\*.exe</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>18/01/2006 13:00:32</td></tr> </table> </td></tr><tr><td><b>C:\Program Files\Macromedia\Freehand 10\*.exe</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>18/01/2006 13:00:46</td></tr> </table> </td></tr><tr><td><b>C:\Program Files\Microsoft Office\</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>02/08/2006 11:55:23</td></tr> </table> </td></tr><tr><td><b>C:\program files\network associates\</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>07/02/2006 13:50:45</td></tr> </table> </td></tr><tr><td><b>C:\Program Files\New Wave Concepts\PCB Wizard 3\*.exe</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>24/01/2006 15:03:59</td></tr> </table> </td></tr><tr><td><b>C:\program files\print manager plus - client\*.*</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>26/05/2006 08:16:30</td></tr> </table> </td></tr><tr><td><b>C:\Program Files\QCA Testing\Delivery Point System\TDS\bin\*.*</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>28/04/2006 11:11:10</td></tr> </table> </td></tr><tr><td><b>C:\Program Files\Real\RealPlayer\</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>21/03/2006 14:41:17</td></tr> </table> </td></tr><tr><td><b>C:\Program Files\RealVNC\</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>11/07/2006 13:05:42</td></tr> </table> </td></tr><tr><td><b>C:\program files\windows defender\*.exe</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Disallowed</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>14/06/2006 08:13:04</td></tr> </table> </td></tr><tr><td><b>C:\Program Files\Windows Media Player</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>04/04/2006 08:17:16</td></tr> </table> </td></tr><tr><td><b>C:\ResultsManager\</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>14/12/2006 12:25:09</td></tr> </table> </td></tr><tr><td><b>C:\Student\</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>14/12/2006 12:25:18</td></tr> </table> </td></tr><tr><td><b>C:\teacher\</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>14/12/2006 12:25:25</td></tr> </table> </td></tr><tr><td><b>C:\Virtual PCs\</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>12/03/2007 12:16:06</td></tr> </table> </td></tr><tr><td><b>C:\windows\system32\*.exe</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>20/01/2006 08:34:22</td></tr> </table> </td></tr><tr><td><b>C:\windows\system32\wscript.exe</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>20/01/2006 15:09:29</td></tr> </table> </td></tr><tr><td><b>D:\</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>01/02/2007 14:26:06</td></tr> </table> </td></tr><tr><td><b>M:\</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>14/12/2006 12:24:25</td></tr> </table> </td></tr><tr><td><b>msmsgs.exe</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Disallowed</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>20/01/2006 14:54:44</td></tr> </table> </td></tr><tr><td><b>msnmsgr.exe</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Disallowed</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>30/01/2006 10:55:53</td></tr> </table> </td></tr><tr><td><b>pushprinterconnections.exe</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"> <tr><td scope="row">Security Level</td><td>Unrestricted</td></tr> <tr><td scope="row">Description</td><td></td></tr> <tr><td scope="row">Date last modified</td><td>03/08/2006 10:58:14</td></tr> </table> </td></tr></table></div></div></div></div><div class="he2"><span class="sectionTitle" tabindex="0">Folder Redirection</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4"><span class="sectionTitle" tabindex="0">My Documents</span><a class="expando" href="#"></a></div> <div class="container"> <div class="he4h"><span class="sectionTitle" tabindex="0">Setting: Basic (Redirect everyone's folder to the same location)</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i">Path: \\%HOMESHARE%%HOMEPATH%</div></div><div class="he4h"><span class="sectionTitle" tabindex="0">Options</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><td scope="row">Grant user exclusive rights to My Documents</td><td>Disabled</td></tr> <tr><td scope="row">Move the contents of My Documents to the new location</td><td>Disabled</td></tr> </table> </div> <div class="he4i"> <table class="info" cellpadding="0" cellspacing="0"> <tr><td scope="row">Policy Removal Behavior</td><td>Leave contents</td></tr> </table></div></div></div><div class="he4"><span class="sectionTitle" tabindex="0">Start Menu</span><a class="expando" href="#"></a></div> <div class="container"> <div class="he4h"><span class="sectionTitle" tabindex="0">Setting: Basic (Redirect everyone's folder to the same location)</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i">Path: \\bronze\pupils$</div></div><div class="he4h"><span class="sectionTitle" tabindex="0">Options</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><td scope="row">Grant user exclusive rights to Start Menu</td><td>Disabled</td></tr> <tr><td scope="row">Move the contents of Start Menu to the new location</td><td>Disabled</td></tr> </table> </div> <div class="he4i"> <table class="info" cellpadding="0" cellspacing="0"> <tr><td scope="row">Policy Removal Behavior</td><td>Leave contents</td></tr> </table></div></div></div></div><div class="he2"><span class="sectionTitle" tabindex="0">Internet Explorer Maintenance</span><a class="expando" href="#"></a></div> <div class="container"><div class="he3"><span class="sectionTitle" tabindex="0">Browser User Interface/Customized Title Bar</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Title Bar Text</th></tr> <tr><td>ICT Network Support</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Connection/Proxy Settings</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info3" cellpadding="0" cellspacing="0"> <tr><td colspan="3">Enable proxy settings</td></tr> <tr><td colspan="3"> <table class="subtable3" cellpadding="0" cellspacing="0"> <tr><th scope="col">Protocol</th><th scope="col">Server</th><th scope="col">Port</th></tr> <tr><td>HTTP</td><td>10.4.28.204</td><td>8080</td></tr> <tr><td>Secure</td><td>10.4.28.204</td><td>8080</td></tr> <tr><td>FTP</td><td>10.4.28.204</td><td>8080</td></tr> <tr><td>Gopher</td><td>10.4.28.204</td><td>8080</td></tr> <tr><td>Socks</td><td>10.4.28.204</td><td>8080</td></tr> </table> </td></tr> <tr><td rowspan="2">Exceptions:</td><td>Do not use proxy server for addresses beginning with</td><td></td></tr> <tr><td>Do not use proxy server for local (intranet) addresses</td><td>Enabled</td></tr> </table></div></div><div class="he3"><span class="sectionTitle" tabindex="0">Connection/User Agent String</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Custom string to be appended to user agent string</th></tr> <tr><td>Moorside High School Pupil</td></tr> </table></div></div><div class="he3"><span class="sectionTitle" tabindex="0">URLs/Important URLs</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><td colspan="2"> <table class="subtable" cellpadding="0" cellspacing="0"> <tr><th scope="col">Name</th><th scope="col">URL</th></tr> <tr><td scope="row">Home page URL</td><td>http://lithium/intranet</td></tr> <tr><td scope="row">Search bar URL</td><td>http://www.google.co.uk</td></tr> <tr><td scope="row">Online support page URL</td><td>Not configured</td></tr> </table> </td></tr> </table></div></div><div class="he3"><span class="sectionTitle" tabindex="0">URLs/Favorites and Links</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td>Place favorites and links at the top of the list in the order specified below</td><td>Enabled</td></tr> <tr><td>Delete existing Favorites and Links, if present</td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable" cellpadding="0" cellspacing="0"><tr><td>Only delete the favorites created by the administrator</td><td>Not configured</td></tr> </table></td></tr><tr><td>Delete existing channels, if present</td><td>Enabled</td></tr> </table> <table class="info" cellpadding="0" cellspacing="0"> <tr><td><b>Favorites\BBC Schools</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"><tr><th scope="col">Name</th><th scope="col">URL</th></tr> <tr><td>Bitesize</td><td>http://www.bbc.co.uk/schools/gcsebitesize</td></tr> <tr><td>Revision</td><td>http://www.bbc.co.uk/schools/revision/</td></tr> </table></td></tr><tr><td><b>Favorites\Business Studies</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"><tr><th scope="col">Name</th><th scope="col">URL</th></tr> <tr><td>Richer Sounds</td><td>http://www.richersounds.com</td></tr> </table></td></tr><tr><td><b>Favorites\Geography</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"><tr><th scope="col">Name</th><th scope="col">URL</th></tr> <tr><td>National Geographic</td><td>http://www.nationalgeographic.com</td></tr> <tr><td>NASA</td><td>http://www.nasa.gov</td></tr> </table></td></tr><tr><td><b>Favorites\ICT</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"><tr><th scope="col">Name</th><th scope="col">URL</th></tr> <tr><td>OCR ICT Website</td><td>http://curriculum.ttsonline.net</td></tr> <tr><td>Internal Mail</td><td>http://gold/exchange</td></tr> </table></td></tr><tr><td><b>Favorites\Languages</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"><tr><th scope="col">Name</th><th scope="col">URL</th></tr> <tr><td>Linguascope</td><td>http://www.linguascope.com</td></tr> <tr><td>Languages Online</td><td>http://www.languagesonline.org.uk</td></tr> </table></td></tr><tr><td><b>Favorites\Technology</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"><tr><th scope="col">Name</th><th scope="col">URL</th></tr> <tr><td>Technology Student</td><td>http://www.technologystudent.com</td></tr> <tr><td>Crocodilia</td><td>http://www.crocodilia.co.uk</td></tr> </table></td></tr><tr><td><b>Links</b></td></tr><tr><td><table class="subtable" cellpadding="0" cellspacing="0"><tr><th scope="col">Name</th><th scope="col">URL</th></tr> <tr><td>Google UK</td><td>http://www.google.co.uk</td></tr> <tr><td>Pupil Intranet</td><td>http://lithium/intranet</td></tr> <tr><td>SAM Learning</td><td>http://www.samlearning.com</td></tr> <tr><td>Mirago UK</td><td>http://zone.mirago.co.uk</td></tr> </table></td></tr></table></div></div></div></div><div class="filler"></div> <div class="he1_expanded"><span class="sectionTitle" tabindex="0">Administrative Templates</span><a class="expando" href="#"></a></div> <div class="container"><div class="he3"><span class="sectionTitle" tabindex="0">Control Panel</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Force classic Control Panel Style" gpmc_settingPath="User Configuration/Administrative Templates/Control Panel" gpmc_settingDescription="This setting affects the visual style and presentation of the Control Panel.&lt;br/&gt;&lt;br/&gt;It allows you to disable the new style of Control Panel, which is task-based, and use the Windows 2000 style, referred to as the &amp;quot;classic&amp;quot; Control Panel. The new Control Panel, referred to as the &amp;quot;simple&amp;quot; Control Panel, simplifies how users interact with settings by providing easy-to-understand tasks that help users get their work done quickly. The Control Panel allows the users to configure their computer, add or remove programs, and change settings.&lt;br/&gt;&lt;br/&gt;If you enable this setting, Control Panel sets the classic Control Panel. The user cannot switch to the new simple style.&lt;br/&gt;&lt;br/&gt;If you disable this setting, Control Panel is set to the task-based style. The user cannot switch to the classic Control Panel style.&lt;br/&gt;&lt;br/&gt;If you do not configure it, the default is the task-based style, which the user can change." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Force classic Control Panel Style</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prohibit access to the Control Panel" gpmc_settingPath="User Configuration/Administrative Templates/Control Panel" gpmc_settingDescription="Disables all Control Panel programs.&lt;br/&gt;&lt;br/&gt;This setting prevents Control.exe, the program file for Control Panel, from starting. As a result, users cannot start Control Panel or run any Control Panel items.&lt;br/&gt;&lt;br/&gt;This setting also removes Control Panel from the Start menu. (To open Control Panel, click Start, point to Settings, and then click Control Panel.) This setting also removes the Control Panel folder from Windows Explorer.&lt;br/&gt;&lt;br/&gt;If users try to select a Control Panel item from the Properties item on a context menu, a message appears explaining that a setting prevents the action.&lt;br/&gt;&lt;br/&gt;Also, see the &amp;quot;Remove Display in Control Panel&amp;quot; and &amp;quot;Remove programs on Settings menu&amp;quot; settings." gpmc_supported="At least Microsoft Windows 2000">Prohibit access to the Control Panel</a></td><td>Enabled</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Control Panel/Display</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Hide Appearance and Themes tab" gpmc_settingPath="User Configuration/Administrative Templates/Control Panel/Display" gpmc_settingDescription="Removes the Appearance and Themes tabs from Display in Control Panel.&lt;br/&gt;&lt;br/&gt;When this setting is enabled, it removes the desktop color selection option from the Desktop tab.&lt;br/&gt;&lt;br/&gt;This setting prevents users from using Control Panel to change the colors or color scheme of the desktop and windows.&lt;br/&gt;&lt;br/&gt;If this setting is disabled or not configured, the Appearance and Themes tabs are available in Display in Control Panel." gpmc_supported="At least Microsoft Windows 2000">Hide Appearance and Themes tab</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Hide Desktop tab" gpmc_settingPath="User Configuration/Administrative Templates/Control Panel/Display" gpmc_settingDescription="Removes the Desktop tab from Display in Control Panel.&lt;br/&gt;&lt;br/&gt;This setting prevents users from using Control Panel to change the pattern and wallpaper on the desktop.&lt;br/&gt;&lt;br/&gt;Enabling this setting also prevents the user from customizing the desktop by changing icons or adding new Web content through Control Panel." gpmc_supported="At least Microsoft Windows 2000">Hide Desktop tab</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Hide Screen Saver tab" gpmc_settingPath="User Configuration/Administrative Templates/Control Panel/Display" gpmc_settingDescription="Removes the Screen Saver tab from Display in Control Panel.&lt;br/&gt;&lt;br/&gt;This setting prevents users from using Control Panel to add, configure, or change the screen saver on the computer." gpmc_supported="At least Microsoft Windows 2000">Hide Screen Saver tab</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Hide Settings tab" gpmc_settingPath="User Configuration/Administrative Templates/Control Panel/Display" gpmc_settingDescription="Removes the Settings tab from Display in Control Panel.&lt;br/&gt;&lt;br/&gt;This setting prevents users from using Control Panel to add, configure, or change the display settings on the computer." gpmc_supported="At least Microsoft Windows 2000">Hide Settings tab</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove Display in Control Panel" gpmc_settingPath="User Configuration/Administrative Templates/Control Panel/Display" gpmc_settingDescription="Disables Display in Control Panel.&lt;br/&gt;&lt;br/&gt;If you enable this setting, Display in Control Panel does not run. When users try to start Display, a message appears explaining that a setting prevents the action.&lt;br/&gt;&lt;br/&gt;Also, see the &amp;quot;Prohibit access to the Control Panel&amp;quot; (User Configuration\Administrative Templates\Control Panel) and &amp;quot;Remove programs on Settings menu&amp;quot; (User Configuration\Administrative Templates\Start Menu &amp;amp; Taskbar) settings." gpmc_supported="At least Microsoft Windows 2000">Remove Display in Control Panel</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Screen Saver" gpmc_settingPath="User Configuration/Administrative Templates/Control Panel/Display" gpmc_settingDescription="Enables desktop screen savers.&lt;br/&gt;&lt;br/&gt;If you disable this setting, screen savers do not run. Also, this setting disables the Screen Saver section of the Screen Saver tab in Display in Control Panel. As a result, users cannot change the screen saver options.&lt;br/&gt;&lt;br/&gt;If you do not configure it, this setting has no effect on the system.&lt;br/&gt;&lt;br/&gt;If you enable it, a screen saver runs, provided the following two conditions hold: First, a valid screensaver on the client is specified through the &amp;quot;Screensaver executable name&amp;quot; setting or through Control Panel on the client computer. Second, the screensaver timeout is set to a nonzero value through the setting or Control Panel.&lt;br/&gt;&lt;br/&gt;Also, see the &amp;quot;Hide Screen Saver tab&amp;quot; setting." gpmc_supported="At least Microsoft Windows 2000 Service Pack 1">Screen Saver</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Screen Saver executable name" gpmc_settingPath="User Configuration/Administrative Templates/Control Panel/Display" gpmc_settingDescription="Specifies the screen saver for the user's desktop.&lt;br/&gt;&lt;br/&gt;If you enable this setting, the system displays the specified screen saver on the user's desktop. Also, this setting disables the drop-down list of screen savers on the Screen Saver tab in Display in Control Panel, which prevents users from changing the screen saver.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, users can select any screen saver.&lt;br/&gt;&lt;br/&gt;If you enable this setting, type the name of the file that contains the screen saver, including the .scr file name extension. If the screen saver file is not in the %Systemroot%\System32 directory, type the fully qualified path to the file.&lt;br/&gt;&lt;br/&gt;If the specified screen saver is not installed on a computer to which this setting applies, the setting is ignored.&lt;br/&gt;&lt;br/&gt;Note: This setting can be superseded by the &amp;quot;Screen Saver&amp;quot; setting. If the &amp;quot;Screen Saver&amp;quot; setting is disabled, this setting is ignored, and screen savers do not run." gpmc_supported="At least Microsoft Windows 2000 Service Pack 1">Screen Saver executable name</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Screen Saver executable name</td><td>P:\themes\moorside4.scr</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Screen Saver timeout" gpmc_settingPath="User Configuration/Administrative Templates/Control Panel/Display" gpmc_settingDescription="Specifies how much user idle time must elapse before the screen saver is launched.&lt;br/&gt;&lt;br/&gt;When configured, this idle time can be set from a minimum of 1 second to a maximum of 86,400 seconds, or 24 hours. If set to zero, the screen saver will not be started.&lt;br/&gt;&lt;br/&gt;This setting has no effect under any of the following circumstances:&lt;br/&gt;&lt;br/&gt; - The setting is disabled or not configured.&lt;br/&gt;&lt;br/&gt; - The wait time is set to zero.&lt;br/&gt;&lt;br/&gt; - The &amp;quot;No screen saver&amp;quot; setting is enabled.&lt;br/&gt;&lt;br/&gt; - Neither the &amp;quot;Screen saver executable name&amp;quot; setting nor the Screen Saver tab of the client computer's Display Properties dialog box specifies a valid existing screensaver program on the client.&lt;br/&gt;&lt;br/&gt;When not configured, whatever wait time is set on the client through the Screen Saver tab of the Display Properties dialog box is used. The default is 15 minutes." gpmc_supported="At least Microsoft Windows 2000 Service Pack 1">Screen Saver timeout</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td colspan="2">Number of seconds to wait to enable the Screen Saver</td></tr><tr><td colspan="2"> </td></tr><tr><td>Seconds:</td><td>120</td></tr> </table></td></tr></table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Control Panel/Display/Desktop Themes</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Load a specific visual style file or force Windows Classic" gpmc_settingPath="User Configuration/Administrative Templates/Control Panel/Display/Desktop Themes" gpmc_settingDescription="This setting allows you to load a specific visual style file by entering the path (location) of the visual style file.&lt;br/&gt;&lt;br/&gt;This can be a local computer visual style (Luna.msstyles), or a file located on a remote server using a UNC path (\\Server\Share\luna.msstyles).&lt;br/&gt;&lt;br/&gt;If you enable this setting, the visual style file that you specify will be used. Also, a user may not choose to use a different visual style.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, the users can select the visual style that they want to use for their desktop.&lt;br/&gt;&lt;br/&gt;Note: If this setting is enabled and the file is not available at user logon, the default visual style is loaded.&lt;br/&gt;&lt;br/&gt;Note: When running Windows XP, you can select the Luna visual style by typing %windir%\resources\Themes\Luna\Luna.msstyles&lt;br/&gt;&lt;br/&gt;Note: To select the Windows Classic visual style, leave the box blank beside &amp;quot;Path to Visual Style:&amp;quot; and enable this setting." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Load a specific visual style file or force Windows Classic</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Path to Visual Style:</td><td>\\bronze\psa\themes\Royale\Royale.msstyles</td></tr> <tr><td colspan="2">To select Luna type:</td></tr><tr><td colspan="2">%windir%\resources\Themes\Luna\Luna.msstyles</td></tr><tr><td colspan="2"> </td></tr><tr><td colspan="2">To select a different visual style, type:</td></tr><tr><td colspan="2">ie: \\&lt;server&gt;\share\Corp.msstyles</td></tr><tr><td colspan="2"> </td></tr><tr><td colspan="2">To select Windows Classic, leave the box</td></tr><tr><td colspan="2">above blank and enable this setting</td></tr></table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prevent selection of windows and buttons styles" gpmc_settingPath="User Configuration/Administrative Templates/Control Panel/Display/Desktop Themes" gpmc_settingDescription="Prevents users from changing the visual style of the windows and buttons displayed on their screens. When enabled, this setting disables the &amp;quot;Windows and buttons&amp;quot; drop-down list on the Appearance tab in Display Properties." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Prevent selection of windows and buttons styles</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prohibit selection of font size" gpmc_settingPath="User Configuration/Administrative Templates/Control Panel/Display/Desktop Themes" gpmc_settingDescription="Prevents users from changing the size of the font in the windows and buttons displayed on their screens.&lt;br/&gt;&lt;br/&gt;If this setting is enabled, the &amp;quot;Font size&amp;quot; drop-down list on the Appearance tab in Display Properties is disabled. &lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, a user may change the font size using the &amp;quot;Font size&amp;quot; drop-down list on the Appearance tab." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Prohibit selection of font size</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prohibit Theme color selection" gpmc_settingPath="User Configuration/Administrative Templates/Control Panel/Display/Desktop Themes" gpmc_settingDescription="This setting forces the theme color to be the default color scheme.&lt;br/&gt;&lt;br/&gt;If you enable this setting, a user cannot change the color scheme of the current desktop theme.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, a user may change the color scheme of the current desktop theme." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Prohibit Theme color selection</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove Theme option" gpmc_settingPath="User Configuration/Administrative Templates/Control Panel/Display/Desktop Themes" gpmc_settingDescription="This setting effects the Themes tab that controls the overall appearance of windows.&lt;br/&gt;&lt;br/&gt;It is accessed through the Display icon in Control Panel.&lt;br/&gt;&lt;br/&gt;Using the options under the Themes tab, users can configure the theme for their desktop.&lt;br/&gt;&lt;br/&gt;If you enable this setting, it removes the Themes tab.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, there is no effect.&lt;br/&gt;&lt;br/&gt;Note: If you enable this setting but do not set a theme, the theme defaults to whatever the user previously set." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Remove Theme option</a></td><td>Enabled</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Control Panel/Printers</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Browse a common web site to find printers" gpmc_settingPath="User Configuration/Administrative Templates/Control Panel/Printers" gpmc_settingDescription="Adds a link to an Internet or intranet Web page to the Add Printer Wizard.&lt;br/&gt;&lt;br/&gt;You can use this setting to direct users to a Web page from which they can install printers.&lt;br/&gt;&lt;br/&gt;If you enable this setting and type an Internet or intranet address in the text box, the system adds a Browse button to the &amp;quot;Specify a Printer&amp;quot; page in the Add Printer Wizard. The Browse button appears beside the &amp;quot;Connect to a printer on the Internet or on a home or office network&amp;quot; option. When users click Browse, the system opens an Internet browser and navigates to the specified URL address to display the available printers.&lt;br/&gt;&lt;br/&gt;This setting makes it easy for users to find the printers you want them to add.&lt;br/&gt;&lt;br/&gt;Also, see the &amp;quot;Custom support URL in the Printers folder's left pane&amp;quot; and &amp;quot;Web-based printing&amp;quot; settings in &amp;quot;Computer Configuration\Administrative Templates\Printers.&amp;quot;" gpmc_supported="At least Microsoft Windows 2000">Browse a common web site to find printers</a></td><td>Disabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Browse the network to find printers" gpmc_settingPath="User Configuration/Administrative Templates/Control Panel/Printers" gpmc_settingDescription="Allows users to use the Add Printer Wizard to search the network for shared printers.&lt;br/&gt;&lt;br/&gt;If you enable this setting or do not configure it, when users choose to add a network printer by selecting the &amp;quot;A network printer, or a printer attached to another computer&amp;quot; radio button on Add Printer Wizard's page 2, and also check the &amp;quot;Connect to this printer (or to browse for a printer, select this option and click Next)&amp;quot; radio button on Add Printer Wizard's page 3, and do not specify a printer name in the adjacent &amp;quot;Name&amp;quot; edit box, then Add Printer Wizard displays the list of shared printers on the network and invites to choose a printer from the shown list.&lt;br/&gt;&lt;br/&gt;If you disable this setting, the network printer browse page is removed from within the Add Printer Wizard, and users cannot search the network but must type a printer name.&lt;br/&gt;&lt;br/&gt;Note: This setting affects the Add Printer Wizard only. It does not prevent users from using other programs to search for shared printers or to connect to network printers." gpmc_supported="At least Microsoft Windows 2000">Browse the network to find printers</a></td><td>Disabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prevent deletion of printers" gpmc_settingPath="User Configuration/Administrative Templates/Control Panel/Printers" gpmc_settingDescription="Prevents users from deleting local and network printers.&lt;br/&gt;&lt;br/&gt;If a user tries to delete a printer, such as by using the Delete option in Printers in Control Panel, a message appears explaining that a setting prevents the action.&lt;br/&gt;&lt;br/&gt;This setting does not prevent users from running other programs to delete a printer." gpmc_supported="At least Microsoft Windows 2000">Prevent deletion of printers</a></td><td>Enabled</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Desktop</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Desktop Toolbars Settings" gpmc_settingPath="User Configuration/Administrative Templates/Desktop" gpmc_settingDescription="" gpmc_supported="">Desktop Toolbars Settings</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Disable adding new toolbars</td><td>Enabled</td></tr> <tr><td>Disable resizing ALL toolbars</td><td>Enabled</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Do not add shares of recently opened documents to My Network Places" gpmc_settingPath="User Configuration/Administrative Templates/Desktop" gpmc_settingDescription="Remote shared folders are not added to My Network Places whenever you open a document in the shared folder.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, when you open a document in a remote shared folder, the system adds a connection to the shared folder to My Network Places.&lt;br/&gt;&lt;br/&gt;If you enable this setting, shared folders are not added to My Network Places automatically when you open a document in the shared folder." gpmc_supported="At least Microsoft Windows 2000">Do not add shares of recently opened documents to My Network Places</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Don't save settings at exit" gpmc_settingPath="User Configuration/Administrative Templates/Desktop" gpmc_settingDescription="Prevents users from saving certain changes to the desktop.&lt;br/&gt;&lt;br/&gt;If you enable this setting, users can change the desktop, but some changes, such as the position of open windows or the size and position of the taskbar, are not saved when users log off. However, shortcuts placed on the desktop are always saved." gpmc_supported="At least Microsoft Windows 2000">Don't save settings at exit</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Hide and disable all items on the desktop" gpmc_settingPath="User Configuration/Administrative Templates/Desktop" gpmc_settingDescription="Removes icons, shortcuts, and other default and user-defined items from the desktop, including Briefcase, Recycle Bin, My Computer, and My Network Places.&lt;br/&gt;&lt;br/&gt;Removing icons and shortcuts does not prevent the user from using another method to start the programs or opening the items they represent.&lt;br/&gt;&lt;br/&gt;Also, see &amp;quot;Items displayed in Places Bar&amp;quot; in User Configuration\Administrative Templates\Windows Components\Common Open File Dialog to remove the Desktop icon from the Places Bar. This will help prevent users from saving data to the Desktop." gpmc_supported="At least Microsoft Windows 2000">Hide and disable all items on the desktop</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Hide Internet Explorer icon on desktop" gpmc_settingPath="User Configuration/Administrative Templates/Desktop" gpmc_settingDescription="Removes the Internet Explorer icon from the desktop and from the Quick Launch bar on the taskbar.&lt;br/&gt;&lt;br/&gt;This setting does not prevent the user from starting Internet Explorer by using other methods." gpmc_supported="At least Microsoft Windows 2000">Hide Internet Explorer icon on desktop</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Hide My Network Places icon on desktop" gpmc_settingPath="User Configuration/Administrative Templates/Desktop" gpmc_settingDescription="Removes the My Network Places icon from the desktop.&lt;br/&gt;&lt;br/&gt;This setting only affects the desktop icon. It does not prevent users from connecting to the network or browsing for shared computers on the network." gpmc_supported="At least Microsoft Windows 2000">Hide My Network Places icon on desktop</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prevent adding, dragging, dropping and closing the Taskbar's toolbars" gpmc_settingPath="User Configuration/Administrative Templates/Desktop" gpmc_settingDescription="Prevents users from manipulating desktop toolbars.&lt;br/&gt;&lt;br/&gt;If you enable this setting, users cannot add or remove toolbars from the desktop. Also, users cannot drag toolbars on to or off of docked toolbars.&lt;br/&gt;&lt;br/&gt;Note: If users have added or removed toolbars, this setting prevents them from restoring the default configuration.&lt;br/&gt;&lt;br/&gt;Tip: To view the toolbars that can be added to the desktop, right-click a docked toolbar (such as the taskbar beside the Start button), and point to &amp;quot;Toolbars.&amp;quot;&lt;br/&gt;&lt;br/&gt;Also, see the &amp;quot;Prohibit adjusting desktop toolbars&amp;quot; setting." gpmc_supported="At least Microsoft Windows 2000">Prevent adding, dragging, dropping and closing the Taskbar's toolbars</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prohibit adjusting desktop toolbars" gpmc_settingPath="User Configuration/Administrative Templates/Desktop" gpmc_settingDescription="Prevents users from adjusting the length of desktop toolbars. Also, users cannot reposition items or toolbars on docked toolbars.&lt;br/&gt;&lt;br/&gt;This setting does not prevent users from adding or removing toolbars on the desktop.&lt;br/&gt;&lt;br/&gt;Note: If users have adjusted their toolbars, this setting prevents them from restoring the default configuration.&lt;br/&gt;&lt;br/&gt;Also, see the &amp;quot;Prevent adding, dragging, dropping and closing the Taskbar's toolbars&amp;quot; setting." gpmc_supported="At least Microsoft Windows 2000">Prohibit adjusting desktop toolbars</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prohibit user from changing My Documents path" gpmc_settingPath="User Configuration/Administrative Templates/Desktop" gpmc_settingDescription="Prevents users from changing the path to the My Documents folder.&lt;br/&gt;&lt;br/&gt;By default, a user can change the location of the My Documents folder by typing a new path in the Target box of the My Documents Properties dialog box.&lt;br/&gt;&lt;br/&gt;If you enable this setting, users are unable to type a new location in the Target box." gpmc_supported="At least Microsoft Windows 2000">Prohibit user from changing My Documents path</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove My Documents icon on the desktop" gpmc_settingPath="User Configuration/Administrative Templates/Desktop" gpmc_settingDescription="Removes most occurrences of the My Documents icon.&lt;br/&gt;&lt;br/&gt;This setting removes the My Documents icon from the desktop, from Windows Explorer, from programs that use the Windows Explorer windows, and from the standard Open dialog box.&lt;br/&gt;&lt;br/&gt;This setting does not prevent the user from using other methods to gain access to the contents of the My Documents folder.&lt;br/&gt;&lt;br/&gt;This setting does not remove the My Documents icon from the Start menu. To do so, use the &amp;quot;Remove My Documents icon from Start Menu&amp;quot; setting.&lt;br/&gt;&lt;br/&gt;Note: To make changes to this setting effective, you must log off from and log back on to Windows 2000 Professional." gpmc_supported="At least Microsoft Windows 2000">Remove My Documents icon on the desktop</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove Properties from the My Computer context menu" gpmc_settingPath="User Configuration/Administrative Templates/Desktop" gpmc_settingDescription="This setting hides Properties on the context menu for My Computer.&lt;br/&gt;&lt;br/&gt;If you enable this setting, the Properties option will not be present when the user right-clicks My Computer or clicks My Computer and then goes to the File menu. Likewise, Alt-Enter does nothing when My Computer is selected.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, the Properties option is displayed as usual." gpmc_supported="At least Microsoft Windows 2000 Service Pack 3">Remove Properties from the My Computer context menu</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove Properties from the My Documents context menu" gpmc_settingPath="User Configuration/Administrative Templates/Desktop" gpmc_settingDescription="This setting hides Properties for the context menu on My Documents.&lt;br/&gt;&lt;br/&gt;If you enable this setting, the Properties option will not be present when the user right-clicks My Documents or clicks My Documents and then goes to the File menu. Likewise, Alt-Enter does nothing when My Documents is selected.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, the Properties option is displayed as usual." gpmc_supported="At least Microsoft Windows 2000 Service Pack 3">Remove Properties from the My Documents context menu</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove Properties from the Recycle Bin context menu" gpmc_settingPath="User Configuration/Administrative Templates/Desktop" gpmc_settingDescription="Removes the Properties option from the Recycle Bin context menu.&lt;br/&gt;&lt;br/&gt;If you enable this setting, the Properties option will not be present when the user right-clicks on Recycle Bin or opens Recycle Bin and then clicks File. Likewise, Alt-Enter does nothing when Recycle Bin is selected.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, the Properties option is displayed as usual." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Remove Properties from the Recycle Bin context menu</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove Recycle Bin icon from desktop" gpmc_settingPath="User Configuration/Administrative Templates/Desktop" gpmc_settingDescription="Removes most occurrences of the Recycle Bin icon.&lt;br/&gt;&lt;br/&gt;This setting removes the Recycle Bin icon from the desktop, from Windows Explorer, from programs that use the Windows Explorer windows, and from the standard Open dialog box.&lt;br/&gt;&lt;br/&gt;This setting does not prevent the user from using other methods to gain access to the contents of the Recycle Bin folder.&lt;br/&gt;&lt;br/&gt;Note: To make changes to this setting effective, you must log off and then log back on." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Remove Recycle Bin icon from desktop</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove the Desktop Cleanup Wizard" gpmc_settingPath="User Configuration/Administrative Templates/Desktop" gpmc_settingDescription="Prevents users from using the Desktop Cleanup Wizard.&lt;br/&gt;&lt;br/&gt;If you enable this setting, the Desktop Cleanup wizard does not automatically run on a users workstation every 60 days. The user will also not be able to access the Desktop Cleanup Wizard.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, the default behavior of the Desktop Clean Wizard running every 60 days occurs.&lt;br/&gt;&lt;br/&gt;Note: When this setting is not enabled, users can run the Desktop Cleanup Wizard, or have it run automatically every 60 days from Display, by clicking the Desktop tab and then clicking the Customize Desktop button." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Remove the Desktop Cleanup Wizard</a></td><td>Enabled</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Desktop/Active Desktop</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Allow only bitmapped wallpaper" gpmc_settingPath="User Configuration/Administrative Templates/Desktop/Active Desktop" gpmc_settingDescription="Permits only bitmap images for wallpaper. This setting limits the desktop background (&amp;quot;wallpaper&amp;quot;) to bitmap (.bmp) files. If users select files with other image formats, such as JPEG, GIF, PNG, or HTML, through the Browse button on the Desktop tab, the wallpaper does not load. Files that are autoconverted to a .bmp format, such as JPEG, GIF, and PNG, can be set as Wallpaper by right-clicking the image and selecting &amp;quot;Set as Wallpaper&amp;quot;.&lt;br/&gt;&lt;br/&gt;Also, see the &amp;quot;Active Desktop Wallpaper&amp;quot; and the &amp;quot;Prevent changing wallpaper&amp;quot; (in User Configuration\Administrative Templates\Control Panel\Display) settings." gpmc_supported="At least Microsoft Windows 2000">Allow only bitmapped wallpaper</a></td><td>Disabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable Active Desktop" gpmc_settingPath="User Configuration/Administrative Templates/Desktop/Active Desktop" gpmc_settingDescription="Disables Active Desktop and prevents users from enabling it.&lt;br/&gt;&lt;br/&gt;This setting prevents users from trying to enable or disable Active Desktop while a policy controls it.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, Active Desktop is disabled by default, but users can enable it.&lt;br/&gt;&lt;br/&gt;Note: If both the &amp;quot;Enable Active Desktop&amp;quot; setting and the &amp;quot;Disable Active Desktop&amp;quot; setting are enabled, the &amp;quot;Disable Active Desktop&amp;quot; setting is ignored. If the &amp;quot;Turn on Classic Shell&amp;quot; setting (in User Configuration\Administrative Templates\Windows Components\Windows Explorer) is enabled, Active Desktop is disabled, and both these policies are ignored." gpmc_supported="At least Microsoft Windows 2000">Disable Active Desktop</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td colspan="2">Disallows HTML and Jpg Wallpaper</td></tr></table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable all items" gpmc_settingPath="User Configuration/Administrative Templates/Desktop/Active Desktop" gpmc_settingDescription="Removes Active Desktop content and prevents users from adding Active Desktop content. &lt;br/&gt;&lt;br/&gt;This setting removes all Active Desktop items from the desktop. It also removes the Web tab from Display in Control Panel. As a result, users cannot add Web pages or pictures from the Internet or an intranet to the desktop.&lt;br/&gt;&lt;br/&gt;Note: This setting does not disable Active Desktop. Users can still use image formats, such as JPEG and GIF, for their desktop wallpaper." gpmc_supported="At least Microsoft Windows 2000">Disable all items</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Enable Active Desktop" gpmc_settingPath="User Configuration/Administrative Templates/Desktop/Active Desktop" gpmc_settingDescription="Enables Active Desktop and prevents users from disabling it.&lt;br/&gt;&lt;br/&gt;This setting prevents users from trying to enable or disable Active Desktop while a policy controls it.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, Active Desktop is disabled by default, but users can enable it.&lt;br/&gt;&lt;br/&gt;Note: If both the &amp;quot;Enable Active Desktop&amp;quot; setting and the &amp;quot;Disable Active Desktop&amp;quot; setting are enabled, the &amp;quot;Disable Active Desktop&amp;quot; setting is ignored. If the &amp;quot;Turn on Classic Shell&amp;quot; setting ( in User Configuration\Administrative Templates\Windows Components\Windows Explorer) is enabled, Active Desktop is disabled, and both of these policies are ignored." gpmc_supported="At least Microsoft Windows 2000">Enable Active Desktop</a></td><td>Disabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prohibit changes" gpmc_settingPath="User Configuration/Administrative Templates/Desktop/Active Desktop" gpmc_settingDescription="Prevents the user from enabling or disabling Active Desktop or changing the Active Desktop configuration.&lt;br/&gt;&lt;br/&gt;This is a comprehensive setting that locks down the configuration you establish by using other policies in this folder. This setting removes the Web tab from Display in Control Panel. As a result, users cannot enable or disable Active Desktop. If Active Desktop is already enabled, users cannot add, remove, or edit Web content or disable, lock, or synchronize Active Desktop components." gpmc_supported="At least Microsoft Windows 2000">Prohibit changes</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prohibit editing items" gpmc_settingPath="User Configuration/Administrative Templates/Desktop/Active Desktop" gpmc_settingDescription="Prevents users from changing the properties of Web content items on their Active Desktop.&lt;br/&gt;&lt;br/&gt;This setting disables the Properties button on the Web tab in Display in Control Panel. Also, it removes the Properties item from the menu for each item on the Active Desktop. As a result, users cannot change the properties of an item, such as its synchronization schedule, password, or display characteristics." gpmc_supported="At least Microsoft Windows 2000">Prohibit editing items</a></td><td>Enabled</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Network/Network Connections</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Ability to change properties of an all user remote access connection" gpmc_settingPath="User Configuration/Administrative Templates/Network/Network Connections" gpmc_settingDescription="Determines whether a user can view and change the properties of remote access connections that are available to all users of the computer.&lt;br/&gt;&lt;br/&gt;To create an all-user remote access connection, on the Connection Availability page in the New Connection Wizard, click the &amp;quot;For all users&amp;quot; option.&lt;br/&gt;&lt;br/&gt;This setting determines whether the Properties menu item is enabled, and thus, whether the Remote Access Connection Properties dialog box is available to users.&lt;br/&gt;&lt;br/&gt;If you enable this setting, a Properties menu item appears when any user right-clicks the icon for a remote access connection. Also, when any user selects the connection, Properties appears on the File menu.&lt;br/&gt;&lt;br/&gt;If you disable this setting (and enable the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; setting), the Properties menu items are disabled, and users (including administrators) cannot open the remote access connection properties dialog box.&lt;br/&gt;&lt;br/&gt;Important: If the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; is disabled or not configured, this setting will not apply to administrators on post-Windows 2000 computers.&lt;br/&gt;&lt;br/&gt;If you do not configure this setting, only Administrators and Network Configuration Operators can change properties of all-user remote access connections.&lt;br/&gt;&lt;br/&gt;Note: This setting takes precedence over settings that manipulate the availability of features inside the Remote Access Connection Properties dialog box. If this setting is disabled, nothing within the properties dialog box for a remote access connection will be available to users.&lt;br/&gt;&lt;br/&gt;Note: This setting does not prevent users from using other programs, such as Internet Explorer, to bypass this setting." gpmc_supported="At least Microsoft Windows 2000 Service Pack 1">Ability to change properties of an all user remote access connection</a></td><td>Disabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Ability to delete all user remote access connections" gpmc_settingPath="User Configuration/Administrative Templates/Network/Network Connections" gpmc_settingDescription="Determines whether users can delete all user remote access connections.&lt;br/&gt;&lt;br/&gt;To create an all-user remote access connection, on the Connection Availability page in the New Connection Wizard, click the &amp;quot;For all users&amp;quot; option.&lt;br/&gt;&lt;br/&gt;If you enable this setting, all users can delete shared remote access connections. In addition, if your file system is NTFS, users need to have Write access to Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk to delete a shared remote access connection.&lt;br/&gt;&lt;br/&gt;If you disable this setting (and enable the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; setting), users (including administrators) cannot delete all-user remote access connections. (By default, users can still delete their private connections, but you can change the default by using the &amp;quot;Prohibit deletion of remote access connections&amp;quot; setting.)&lt;br/&gt;&lt;br/&gt;Important: If the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; is disabled or not configured, this setting will not apply to administrators on post-Windows 2000 computers.&lt;br/&gt;&lt;br/&gt;If you do not configure this setting, only Administrators and Network Configuration Operators can delete all user remote access connections.&lt;br/&gt;&lt;br/&gt;Important: When enabled, the &amp;quot;Prohibit deletion of remote access connections&amp;quot; setting takes precedence over this setting. Users (including administrators) cannot delete any remote access connections, and this setting is ignored.&lt;br/&gt;&lt;br/&gt;Note: LAN connections are created and deleted automatically by the system when a LAN adapter is installed or removed. You cannot use the Network Connections folder to create or delete a LAN connection.&lt;br/&gt;&lt;br/&gt;Note: This setting does not prevent users from using other programs, such as Internet Explorer, to bypass this setting." gpmc_supported="At least Microsoft Windows 2000 Service Pack 1">Ability to delete all user remote access connections</a></td><td>Disabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Ability to Enable/Disable a LAN connection" gpmc_settingPath="User Configuration/Administrative Templates/Network/Network Connections" gpmc_settingDescription="Determines whether users can enable/disable LAN connections.&lt;br/&gt;&lt;br/&gt;If you enable this setting, the Enable and Disable options for LAN connections are available to users (including nonadministrators). Users can enable/disable a LAN connection by double-clicking the icon representing the connection, by right-clicking it, or by using the File menu.&lt;br/&gt;&lt;br/&gt;If you disable this setting (and enable the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; setting), double-clicking the icon has no effect, and the Enable and Disable menu items are disabled for all users (including administrators).&lt;br/&gt;&lt;br/&gt;Important: If the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; is disabled or not configured, this setting will not apply to administrators on post-Windows 2000 computers.&lt;br/&gt;&lt;br/&gt;If you do not configure this setting, only Administrators and Network Configuration Operators can enable/disable LAN connections.&lt;br/&gt;&lt;br/&gt;Note: Administrators can still enable/disable LAN connections from Device Manager when this setting is disabled." gpmc_supported="At least Microsoft Windows 2000 Service Pack 1">Ability to Enable/Disable a LAN connection</a></td><td>Disabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Ability to rename all user remote access connections" gpmc_settingPath="User Configuration/Administrative Templates/Network/Network Connections" gpmc_settingDescription="Determines whether nonadministrators can rename all-user remote access connections.&lt;br/&gt;&lt;br/&gt;To create an all-user connection, on the Connection Availability page in the New Connection Wizard, click the &amp;quot;For all users&amp;quot; option.&lt;br/&gt;&lt;br/&gt;If you enable this setting, the Rename option is enabled for all-user remote access connections. Any user can rename all-user connections by clicking an icon representing the connection or by using the File menu.&lt;br/&gt;&lt;br/&gt;If you disable this setting, the Rename option is disabled for nonadministrators only.&lt;br/&gt;&lt;br/&gt;If you do not configure the setting, only Administrators and Network Configuration Operators can rename all-user remote access connections.&lt;br/&gt;&lt;br/&gt;Note: This setting does not apply to Administrators&lt;br/&gt;&lt;br/&gt;Note: When the &amp;quot;Ability to rename LAN connections or remote access connections available to all users&amp;quot; setting is configured (set to either Enabled or Disabled), this setting does not apply.&lt;br/&gt;&lt;br/&gt;Note: This setting does not prevent users from using other programs, such as Internet Explorer, to bypass this setting." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Ability to rename all user remote access connections</a></td><td>Disabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Ability to rename LAN connections" gpmc_settingPath="User Configuration/Administrative Templates/Network/Network Connections" gpmc_settingDescription="Determines whether nonadministrators can rename a LAN connection.&lt;br/&gt;&lt;br/&gt;If you enable this setting, the Rename option is enabled for LAN connections. Nonadministrators can rename LAN connections by clicking an icon representing the connection or by using the File menu.&lt;br/&gt;&lt;br/&gt;If you disable this setting, the Rename option is disabled for nonadministrators only.&lt;br/&gt;&lt;br/&gt;If you do not configure this setting, only Administrators and Network Configuration Operators can rename LAN connections&lt;br/&gt;&lt;br/&gt;Note: This setting does not apply to Administrators.&lt;br/&gt;&lt;br/&gt;Note: When the &amp;quot;Ability to rename LAN connections or remote access connections available to all users&amp;quot; setting is configured (set to either enabled or disabled), this setting does not apply." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Ability to rename LAN connections</a></td><td>Disabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Ability to rename LAN connections or remote access connections available to all users" gpmc_settingPath="User Configuration/Administrative Templates/Network/Network Connections" gpmc_settingDescription="Determines whether users can rename LAN or all user remote access connections.&lt;br/&gt;&lt;br/&gt;If you enable this setting, the Rename option is enabled for all users. Users can rename connections by clicking the icon representing a connection or by using the File menu.&lt;br/&gt;&lt;br/&gt;If you disable this setting (and enable the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; setting), the Rename option for LAN and all user remote access connections is disabled for all users (including Administrators and Network Configuration Operators).&lt;br/&gt;&lt;br/&gt;Important: If the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; is disabled or not configured, this setting will not apply to administrators on post-Windows 2000 computers.&lt;br/&gt;&lt;br/&gt;If this setting is not configured, only Administrators and Network Configuration Operators have the right to rename LAN or all user remote access connections.&lt;br/&gt;&lt;br/&gt;Note: When configured, this setting always takes precedence over the &amp;quot;Ability to rename LAN connections&amp;quot; and &amp;quot;Ability to rename all user remote access connections&amp;quot; settings.&lt;br/&gt;&lt;br/&gt;Note: This setting does not prevent users from using other programs, such as Internet Explorer, to rename remote access connections." gpmc_supported="At least Microsoft Windows 2000 Service Pack 1">Ability to rename LAN connections or remote access connections available to all users</a></td><td>Disabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prohibit access to properties of a LAN connection" gpmc_settingPath="User Configuration/Administrative Templates/Network/Network Connections" gpmc_settingDescription="Determines whether users can change the properties of a LAN connection.&lt;br/&gt;&lt;br/&gt;This setting determines whether the Properties menu item is enabled, and thus, whether the Local Area Connection Properties dialog box is available to users.&lt;br/&gt;&lt;br/&gt;If you enable this setting (and enable the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; setting), the Properties menu items are disabled for all users, and users cannot open the Local Area Connection Properties dialog box.&lt;br/&gt;&lt;br/&gt;Important: If the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; is disabled or not configured, this setting will not apply to administrators on post-Windows 2000 computers.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, a Properties menu item appears when users right-click the icon representing a LAN connection. Also, when users select the connection, Properties is enabled on the File menu.&lt;br/&gt;&lt;br/&gt;Note: This setting takes precedence over settings that manipulate the availability of features inside the Local Area Connection Properties dialog box. If this setting is enabled, nothing within the properties dialog box for a LAN connection is available to users.&lt;br/&gt;&lt;br/&gt;Note: Nonadministrators have the right to view the properties dialog box for a connection but not to make changes, regardless of this setting." gpmc_supported="At least Microsoft Windows 2000 Service Pack 1">Prohibit access to properties of a LAN connection</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prohibit access to properties of components of a LAN connection" gpmc_settingPath="User Configuration/Administrative Templates/Network/Network Connections" gpmc_settingDescription="Determines whether Administrators and Network Configuration Operators can change the properties of components used by a LAN connection.&lt;br/&gt;&lt;br/&gt;This setting determines whether the Properties button for components of a LAN connection is enabled.&lt;br/&gt;&lt;br/&gt;If you enable this setting (and enable the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; setting), the Properties button is disabled for Administrators. Network Configuration Operators are prohibited from accessing connection components, regardless of the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; setting.&lt;br/&gt;&lt;br/&gt;Important: If the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; is disabled or not configured, this setting does not apply to administrators on post-Windows 2000 computers.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, the Properties button is enabled for administrators and Network Configuration Operators.&lt;br/&gt;&lt;br/&gt;The Local Area Connection Properties dialog box includes a list of the network components that the connection uses. To view or change the properties of a component, click the name of the component, and then click the Properties button beneath the component list.&lt;br/&gt;&lt;br/&gt;Note: Not all network components have configurable properties. For components that are not configurable, the Properties button is always disabled.&lt;br/&gt;&lt;br/&gt;Note: When the &amp;quot;Prohibit access to properties of a LAN connection&amp;quot; setting is enabled, users are blocked from accessing the Properties button for LAN connection components.&lt;br/&gt;&lt;br/&gt;Note: Network Configuration Operators only have permission to change TCP/IP properties. Properties for all other components are unavailable to these users.&lt;br/&gt;&lt;br/&gt;Note: Nonadministrators are already prohibited from accessing properties of components for a LAN connection, regardless of this setting." gpmc_supported="At least Microsoft Windows 2000 Service Pack 1">Prohibit access to properties of components of a LAN connection</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prohibit access to properties of components of a remote access connection" gpmc_settingPath="User Configuration/Administrative Templates/Network/Network Connections" gpmc_settingDescription="Determines whether users can view and change the properties of components used by a private or all-user remote access connection.&lt;br/&gt;&lt;br/&gt;This setting determines whether the Properties button for components used by a private or all-user remote access connection is enabled.&lt;br/&gt;&lt;br/&gt;If you enable this setting (and enable the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; setting), the Properties button is disabled for all users (including administrators).&lt;br/&gt;&lt;br/&gt;Important: If the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; is disabled or not configured, this setting does not apply to administrators on post-Windows 2000 computers.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, the Properties button is enabled for all users.&lt;br/&gt;&lt;br/&gt;The Networking tab of the Remote Access Connection Properties dialog box includes a list of the network components that the connection uses. To view or change the properties of a component, click the name of the component, and then click the Properties button beneath the component list.&lt;br/&gt;&lt;br/&gt;Note: Not all network components have configurable properties. For components that are not configurable, the Properties button is always disabled.&lt;br/&gt;&lt;br/&gt;Note: When the &amp;quot;Ability to change properties of an all user remote access connection&amp;quot; or &amp;quot;Prohibit changing properties of a private remote access connection&amp;quot; settings are set to deny access to the Remote Access Connection Properties dialog box, the Properties button for remote access connection components is blocked.&lt;br/&gt;&lt;br/&gt;Note: This setting does not prevent users from using other programs, such as Internet Explorer, to bypass this setting." gpmc_supported="At least Microsoft Windows 2000 Service Pack 1">Prohibit access to properties of components of a remote access connection</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prohibit access to the Advanced Settings item on the Advanced menu" gpmc_settingPath="User Configuration/Administrative Templates/Network/Network Connections" gpmc_settingDescription="Determines whether the Advanced Settings item on the Advanced menu in Network Connections is enabled for administrators.&lt;br/&gt;&lt;br/&gt;The Advanced Settings item lets users view and change bindings and view and change the order in which the computer accesses connections, network providers, and print providers.&lt;br/&gt;&lt;br/&gt;If you enable this setting (and enable the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; setting), the Advanced Settings item is disabled for administrators.&lt;br/&gt;&lt;br/&gt;Important: If the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; is disabled or not configured, this setting will not apply to administrators on post-Windows 2000 computers.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, the Advanced Settings item is enabled for administrators.&lt;br/&gt;&lt;br/&gt;Note: Nonadministrators are already prohibited from accessing the Advanced Settings dialog box, regardless of this setting." gpmc_supported="At least Microsoft Windows 2000 Service Pack 1">Prohibit access to the Advanced Settings item on the Advanced menu</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prohibit access to the New Connection Wizard" gpmc_settingPath="User Configuration/Administrative Templates/Network/Network Connections" gpmc_settingDescription="Determines whether users can use the New Connection Wizard, which creates new network connections.&lt;br/&gt;&lt;br/&gt;If you enable this setting (and enable the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; setting), the Make New Connection icon does not appear in the Start Menu on in the Network Connections folder. As a result, users (including administrators) cannot start the New Connection Wizard.&lt;br/&gt;&lt;br/&gt;Important: If the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; is disabled or not configured, this setting will not apply to administrators on post-Windows 2000 computers.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, the Make New Connection icon appears in the Start menu and in the Network Connections folder for all users. Clicking the Make New Connection icon starts the New Connection Wizard.&lt;br/&gt;&lt;br/&gt;Note: Changing this setting from Enabled to Not Configured does not restore the Make New Connection icon until the user logs off or on. When other changes to this setting are applied, the icon does not appear or disappear in the Network Connections folder until the folder is refreshed.&lt;br/&gt;&lt;br/&gt;Note: This setting does not prevent users from using other programs, such as Internet Explorer, to bypass this setting." gpmc_supported="At least Microsoft Windows 2000 Service Pack 1">Prohibit access to the New Connection Wizard</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prohibit access to the Remote Access Preferences item on the Advanced menu" gpmc_settingPath="User Configuration/Administrative Templates/Network/Network Connections" gpmc_settingDescription="Determines whether the Remote Acccess Preferences item on the Advanced menu in Network Connections folder is enabled.&lt;br/&gt;&lt;br/&gt;The Remote Access Preferences item lets users create and change connections before logon and configure automatic dialing and callback features.&lt;br/&gt;&lt;br/&gt;If you enable this setting (and enable the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; setting), the Remote Access Preferences item is disabled for all users (including administrators).&lt;br/&gt;&lt;br/&gt;Important: If the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; is disabled or not configured, this setting will not apply to administrators on post-Windows 2000 computers.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, the Remote Access Preferences item is enabled for all users." gpmc_supported="At least Microsoft Windows 2000 Service Pack 1">Prohibit access to the Remote Access Preferences item on the Advanced menu</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prohibit adding and removing components for a LAN or remote access connection" gpmc_settingPath="User Configuration/Administrative Templates/Network/Network Connections" gpmc_settingDescription="Determines whether administrators can add and remove network components for a LAN or remote access connection. This setting has no effect on nonadministrators.&lt;br/&gt;&lt;br/&gt;If you enable this setting (and enable the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; setting), the Install and Uninstall buttons for components of connections are disabled, and administrators are not permitted to access network components in the Windows Components Wizard.&lt;br/&gt;&lt;br/&gt;Important: If the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; is disabled or not configured, this setting will not apply to administrators on post-Windows 2000 computers.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, the Install and Uninstall buttons for components of connections in the Network Connections folder are enabled. Also, administrators can gain access to network components in the Windows Components Wizard.&lt;br/&gt;&lt;br/&gt;The Install button opens the dialog boxes used to add network components. Clicking the Uninstall button removes the selected component in the components list (above the button).&lt;br/&gt;&lt;br/&gt;The Install and Uninstall buttons appear in the properties dialog box for connections. These buttons are on the General tab for LAN connections and on the Networking tab for remote access connections.&lt;br/&gt;&lt;br/&gt;Note: When the &amp;quot;Prohibit access to properties of a LAN connection&amp;quot;, &amp;quot;Ability to change properties of an all user remote access connection&amp;quot;, or &amp;quot;Prohibit changing properties of a private remote access connection&amp;quot; settings are set to deny access to the connection properties dialog box, the Install and Uninstall buttons for connections are blocked.&lt;br/&gt;&lt;br/&gt;Note: Nonadministrators are already prohibited from adding and removing connection components, regardless of this setting." gpmc_supported="At least Microsoft Windows 2000 Service Pack 1">Prohibit adding and removing components for a LAN or remote access connection</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prohibit changing properties of a private remote access connection" gpmc_settingPath="User Configuration/Administrative Templates/Network/Network Connections" gpmc_settingDescription="Determines whether users can view and change the properties of their private remote access connections.&lt;br/&gt;&lt;br/&gt;Private connections are those that are available only to one user. To create a private connection, on the Connection Availability page in the New Connection Wizard, click the &amp;quot;Only for myself&amp;quot; option.&lt;br/&gt;&lt;br/&gt;This setting determines whether the Properties menu item is enabled, and thus, whether the Remote Access Connection Properties dialog box for a private connection is available to users.&lt;br/&gt;&lt;br/&gt;If you enable this setting (and enable the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; setting), the Properties menu items are disabled, and no users (including administrators) can open the Remote Access Connection Properties dialog box for a private connection.&lt;br/&gt;&lt;br/&gt;Important: If the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; is disabled or not configured, this setting will not apply to administrators on post-Windows 2000 computers.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, a Properties menu item appears when any user right-clicks the icon representing a private remote access connection. Also, when any user selects the connection, Properties appears on the File menu.&lt;br/&gt;&lt;br/&gt;Note: This setting takes precedence over settings that manipulate the availability of features in the Remote Access Connection Properties dialog box. If this setting is enabled, nothing within the properties dialog box for a remote access connection will be available to users.&lt;br/&gt;&lt;br/&gt;Note: This setting does not prevent users from using other programs, such as Internet Explorer, to bypass this setting." gpmc_supported="At least Microsoft Windows 2000 Service Pack 1">Prohibit changing properties of a private remote access connection</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prohibit connecting and disconnecting a remote access connection" gpmc_settingPath="User Configuration/Administrative Templates/Network/Network Connections" gpmc_settingDescription="Determines whether users can connect and disconnect remote access connections.&lt;br/&gt;&lt;br/&gt;If you enable this setting (and enable the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; setting), double-clicking the icon has no effect, and the Connect and Disconnect menu items are disabled for all users (including administrators).&lt;br/&gt;&lt;br/&gt;Important: If the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; is disabled or not configured, this setting will not apply to administrators on post-Windows 2000 computers.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, the Connect and Disconnect options for remote access connections are available to all users. Users can connect or disconnect a remote access connection by double-clicking the icon representing the connection, by right-clicking it, or by using the File menu." gpmc_supported="At least Microsoft Windows 2000 Service Pack 1">Prohibit connecting and disconnecting a remote access connection</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prohibit deletion of remote access connections" gpmc_settingPath="User Configuration/Administrative Templates/Network/Network Connections" gpmc_settingDescription="Determines whether users can delete remote access connections.&lt;br/&gt;&lt;br/&gt;If you enable this setting (and enable the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; setting), users (including administrators) cannot delete any remote access connections. This setting also disables the Delete option on the context menu for a remote access connection and on the File menu in the Network Connections folder.&lt;br/&gt;&lt;br/&gt;Important: If the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; is disabled or not configured, this setting will not apply to administrators on post-Windows 2000 computers.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, all users can delete their private remote access connections. Private connections are those that are available only to one user. (By default, only Administrators and Network Configuration Operators can delete connections available to all users, but you can change the default by using the &amp;quot;Ability to delete all user remote access connections&amp;quot; setting.)&lt;br/&gt;&lt;br/&gt;Important: When enabled, this setting takes precedence over the &amp;quot;Ability to delete all user remote access connections&amp;quot; setting. Users cannot delete any remote access connections, and the &amp;quot;Ability to delete all user remote access connections&amp;quot; setting is ignored.&lt;br/&gt;&lt;br/&gt;Note: LAN connections are created and deleted automatically when a LAN adapter is installed or removed. You cannot use the Network Connections folder to create or delete a LAN connection.&lt;br/&gt;&lt;br/&gt;Note: This setting does not prevent users from using other programs, such as Internet Explorer, to bypass this setting." gpmc_supported="At least Microsoft Windows 2000 Service Pack 1">Prohibit deletion of remote access connections</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prohibit Enabling/Disabling components of a LAN connection" gpmc_settingPath="User Configuration/Administrative Templates/Network/Network Connections" gpmc_settingDescription="Determines whether administrators can enable and disable the components used by LAN connections.&lt;br/&gt;&lt;br/&gt;If you enable this setting (and enable the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; setting), the check boxes for enabling and disabling components are disabled. As a result, administrators cannot enable or disable the components that a connection uses.&lt;br/&gt;&lt;br/&gt;Important: If the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; is disabled or not configured, this setting will not apply to administrators on post-Windows 2000 computers.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, the Properties dialog box for a connection includes a check box beside the name of each component that the connection uses. Selecting the check box enables the component, and clearing the check box disables the component.&lt;br/&gt;&lt;br/&gt;Note: When the &amp;quot;Prohibit access to properties of a LAN connection&amp;quot; setting is enabled, users are blocked from accessing the check boxes for enabling and disabling the components of a LAN connection.&lt;br/&gt;&lt;br/&gt;Note: Nonadministrators are already prohibited from enabling or disabling components for a LAN connection, regardless of this setting." gpmc_supported="At least Microsoft Windows 2000 Service Pack 1">Prohibit Enabling/Disabling components of a LAN connection</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prohibit renaming private remote access connections" gpmc_settingPath="User Configuration/Administrative Templates/Network/Network Connections" gpmc_settingDescription="Determines whether users can rename their private remote access connections.&lt;br/&gt;&lt;br/&gt;Private connections are those that are available only to one user. To create a private connection, on the Connection Availability page in the New Connection Wizard, click the &amp;quot;Only for myself&amp;quot; option.&lt;br/&gt;&lt;br/&gt;If you enable this setting (and enable the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; setting), the Rename option is disabled for all users (including administrators).&lt;br/&gt;&lt;br/&gt;Important: If the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; is disabled or not configured, this setting will not apply to administrators on post-Windows 2000 computers.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, the Rename option is enabled for all users' private remote access connections. Users can rename their private connection by clicking an icon representing the connection or by using the File menu.&lt;br/&gt;&lt;br/&gt;Note: This setting does not prevent users from using other programs, such as Internet Explorer, to bypass this setting." gpmc_supported="At least Microsoft Windows 2000 Service Pack 1">Prohibit renaming private remote access connections</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prohibit TCP/IP advanced configuration" gpmc_settingPath="User Configuration/Administrative Templates/Network/Network Connections" gpmc_settingDescription="Determines whether users can configure advanced TCP/IP settings.&lt;br/&gt;&lt;br/&gt;If you enable this setting (and enable the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; setting), the Advanced button on the Internet Protocol (TCP/IP) Properties dialog box is disabled for all users (including administrators). As a result, users cannot open the Advanced TCP/IP Settings Properties page and modify IP settings, such as DNS and WINS server information.&lt;br/&gt;&lt;br/&gt;Important: If the &amp;quot;Enable Network Connections settings for Administrators&amp;quot; is disabled or not configured, this setting will not apply to administrators on post-Windows 2000 computers.&lt;br/&gt;&lt;br/&gt;If you disable this setting, the Advanced button is enabled, and all users can open the Advanced TCP/IP Setting dialog box.&lt;br/&gt;&lt;br/&gt;Note: This setting is superseded by settings that prohibit access to properties of connections or connection components. When these policies are set to deny access to the connection properties dialog box or Properties button for connection components, users cannot gain access to the Advanced button for TCP/IP configuration.&lt;br/&gt;&lt;br/&gt;Note: Nonadministrators (excluding Network Configuration Operators) do not have permission to access TCP/IP advanced configuration for a LAN connection, regardless of this setting.&lt;br/&gt;&lt;br/&gt;Tip: To open the Advanced TCP/IP Setting dialog box, in the Network Connections folder, right-click a connection icon, and click Properties. For remote access connections, click the Networking tab. In the &amp;quot;Components checked are used by this connection&amp;quot; box, click Internet Protocol (TCP/IP), click the Properties button, and then click the Advanced button.&lt;br/&gt;&lt;br/&gt;Note: Changing this setting from Enabled to Not Configured does not enable the Advanced button until the user logs off." gpmc_supported="At least Microsoft Windows 2000 Service Pack 1">Prohibit TCP/IP advanced configuration</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Turn off notifications when a connection has only limited or no connectivity" gpmc_settingPath="User Configuration/Administrative Templates/Network/Network Connections" gpmc_settingDescription="This policy setting allows you to manage whether notifications are shown to the user when a DHCP-configured connection is unable to retrieve an IP address from a DHCP server. This is often signified by the assignment of an automatic private IP address (i.e. an IP address in the range 169.254.*.*). This indicates that a DHCP server could not be reached or the DHCP server was reached but unable to respond to the request with a valid IP address. By default, a notification is displayed providing the user with information on how the problem can be resolved.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, this condition will not be reported as an error to the user.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this policy setting, a DHCP-configured connection that has not been assigned an IP address will be reported via a notification, providing the user with information as to how the problem can be resolved." gpmc_supported="At least Microsoft Windows XP Professional with SP2">Turn off notifications when a connection has only limited or no connectivity</a></td><td>Enabled</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Network/Offline Files</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Action on server disconnect" gpmc_settingPath="User Configuration/Administrative Templates/Network/Offline Files" gpmc_settingDescription="Determines whether network files remain available if the computer is suddenly disconnected from the server hosting the files.&lt;br/&gt;&lt;br/&gt;This setting also disables the &amp;quot;When a network connection is lost&amp;quot; option on the Offline Files tab. This prevents users from trying to change the option while a setting controls it.&lt;br/&gt;&lt;br/&gt;If you enable this setting, you can use the &amp;quot;Action&amp;quot; box to specify how computers in the group respond.&lt;br/&gt;&lt;br/&gt;-- &amp;quot;Work offline&amp;quot; indicates that the computer can use local copies of network files while the server is inaccessible.&lt;br/&gt;&lt;br/&gt;-- &amp;quot;Never go offline&amp;quot; indicates that network files are not available while the server is inaccessible.&lt;br/&gt;&lt;br/&gt;If you disable this setting or select the &amp;quot;Work offline&amp;quot; option, users can work offline if disconnected.&lt;br/&gt;&lt;br/&gt;If you do not configure this setting, users can work offline by default, but they can change this option.&lt;br/&gt;&lt;br/&gt;This setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.&lt;br/&gt;&lt;br/&gt;Tip: To configure this setting without establishing a setting, in Windows Explorer, on the Tools menu, click Folder Options, click the Offline Files tab, click Advanced, and then select an option in the &amp;quot;When a network connection is lost&amp;quot; section.&lt;br/&gt;&lt;br/&gt;Also, see the &amp;quot;Non-default server disconnect actions&amp;quot; setting." gpmc_supported="At least Microsoft Windows 2000">Action on server disconnect</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td colspan="2">Specify how the system is to respond when a network server</td></tr><tr><td colspan="2">becomes unavailable.</td></tr><tr><td colspan="2"> </td></tr><tr><td>Action: </td><td>Never go offline</td></tr> <tr><td colspan="2"> </td></tr><tr><td colspan="2">Never go offline = Server's files are unavailable to local computer</td></tr><tr><td colspan="2">Work offline = Server's files are available to local computer</td></tr></table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Do not automatically make redirected folders available offline" gpmc_settingPath="User Configuration/Administrative Templates/Network/Offline Files" gpmc_settingDescription="All redirected shell folders, such as My Documents, Desktop, Start Menu, and Application Data, are available offline by default. This setting allows you to change this behavior so that redirected shell folders are not automatically available for offline use. However, users can still choose to make files and folders available offline themselves.&lt;br/&gt;&lt;br/&gt;If you enable this setting, the users must manually select the files they wish to be made available offline.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, redirected shell folders are automatically made available offline. All subfolders within the redirected folders are also made available offline.&lt;br/&gt;&lt;br/&gt;Note: This setting does not prevent files from being automatically cached if the network share is configured for &amp;quot;Automatic Caching&amp;quot;, nor does it affect the availability of the &amp;quot;Make Available Offline&amp;quot; menu option in the user interface.&lt;br/&gt;&lt;br/&gt;Note: Do not enable this setting unless you are certain that users will not need access to all of their redirected files in the event that the network or server holding the redirected files becomes unavailable." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Do not automatically make redirected folders available offline</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prevent use of Offline Files folder" gpmc_settingPath="User Configuration/Administrative Templates/Network/Offline Files" gpmc_settingDescription="Disables the Offline Files folder.&lt;br/&gt;&lt;br/&gt;This setting disables the &amp;quot;View Files&amp;quot; button on the Offline Files tab. As a result, users cannot use the Offline Files folder to view or open copies of network files stored on their computer. Also, they cannot use the folder to view characteristics of offline files, such as their server status, type, or location.&lt;br/&gt;&lt;br/&gt;This setting does not prevent users from working offline or from saving local copies of files available offline. Also, it does not prevent them from using other programs, such as Windows Explorer, to view their offline files.&lt;br/&gt;&lt;br/&gt;This setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.&lt;br/&gt;&lt;br/&gt;Tip: To view the Offline Files Folder, in Windows Explorer, on the Tools menu, click Folder Options, click the Offline Files tab, and then click &amp;quot;View Files.&amp;quot;" gpmc_supported="At least Microsoft Windows 2000">Prevent use of Offline Files folder</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prohibit user configuration of Offline Files" gpmc_settingPath="User Configuration/Administrative Templates/Network/Offline Files" gpmc_settingDescription="Prevents users from enabling, disabling, or changing the configuration of Offline Files.&lt;br/&gt;&lt;br/&gt;This setting removes the Offline Files tab from the Folder Options dialog box. It also removes the Settings item from the Offline Files context menu and disables the Settings button on the Offline Files Status dialog box. As a result, users cannot view or change the options on the Offline Files tab or Offline Files dialog box.&lt;br/&gt;&lt;br/&gt;This is a comprehensive setting that locks down the configuration you establish by using other settings in this folder.&lt;br/&gt;&lt;br/&gt;This setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.&lt;br/&gt;&lt;br/&gt;Tip: This setting provides a quick method for locking down the default settings for Offline Files. To accept the defaults, just enable this setting. You do not have to disable any other settings in this folder." gpmc_supported="At least Microsoft Windows 2000">Prohibit user configuration of Offline Files</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td colspan="2">Prevents users from changing any cache configuration settings.</td></tr></table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove 'Make Available Offline'" gpmc_settingPath="User Configuration/Administrative Templates/Network/Offline Files" gpmc_settingDescription="Prevents users from making network files and folders available offline.&lt;br/&gt;&lt;br/&gt;This setting removes the &amp;quot;Make Available Offline&amp;quot; option from the File menu and from all context menus in Windows Explorer. As a result, users cannot designate files to be saved on their computer for offline use.&lt;br/&gt;&lt;br/&gt;However, this setting does not prevent the system from saving local copies of files that reside on network shares designated for automatic caching.&lt;br/&gt;&lt;br/&gt;This setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration." gpmc_supported="At least Microsoft Windows 2000">Remove 'Make Available Offline'</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Synchronize all offline files before logging off" gpmc_settingPath="User Configuration/Administrative Templates/Network/Offline Files" gpmc_settingDescription="Determines whether offline files are fully synchronized when users log off.&lt;br/&gt;&lt;br/&gt;This setting also disables the &amp;quot;Synchronize all offline files before logging off&amp;quot; option on the Offline Files tab. This prevents users from trying to change the option while a setting controls it.&lt;br/&gt;&lt;br/&gt;If you enable this setting, offline files are fully synchronized. Full synchronization ensures that offline files are complete and current.&lt;br/&gt;&lt;br/&gt;If you disable this setting, the system only performs a quick synchronization. Quick synchronization ensures that files are complete, but does not ensure that they are current.&lt;br/&gt;&lt;br/&gt;If you do not configure this setting, the system performs a quick synchronization by default, but users can change this option.&lt;br/&gt;&lt;br/&gt;This setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.&lt;br/&gt;&lt;br/&gt;Tip: To change the synchronization method without changing a setting, in Windows Explorer, on the Tools menu, click Folder Options, click the Offline Files tab, and then select the &amp;quot;Synchronize all offline files before logging off&amp;quot; option." gpmc_supported="At least Microsoft Windows 2000">Synchronize all offline files before logging off</a></td><td>Disabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Synchronize all offline files when logging on" gpmc_settingPath="User Configuration/Administrative Templates/Network/Offline Files" gpmc_settingDescription="Determines whether offline files are fully synchronized when users log on.&lt;br/&gt;&lt;br/&gt;This setting also disables the &amp;quot;Synchronize all offline files before logging on&amp;quot; option on the Offline Files tab. This prevents users from trying to change the option while a setting controls it.&lt;br/&gt;&lt;br/&gt;If you enable this setting, offline files are fully synchronized at logon. Full synchronization ensures that offline files are complete and current. Enabling this setting automatically enables logon synchronization in Synchronization Manager.&lt;br/&gt;&lt;br/&gt;If this setting is disabled and Synchronization Manager is configured for logon synchronization, the system performs only a quick synchronization. Quick synchronization ensures that files are complete but does not ensure that they are current.&lt;br/&gt;&lt;br/&gt;If you do not configure this setting and Synchronization Manager is configured for logon synchronization, the system performs a quick synchronization by default, but users can change this option.&lt;br/&gt;&lt;br/&gt;This setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.&lt;br/&gt;&lt;br/&gt;Tip: To change the synchronization method without setting a setting, in Windows Explorer, on the Tools menu, click Folder Options, click the Offline Files tab, and then select the &amp;quot;Synchronize all offline files before logging on&amp;quot; option." gpmc_supported="At least Microsoft Windows 2000">Synchronize all offline files when logging on</a></td><td>Disabled</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Start Menu</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Start Menu" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu" gpmc_settingDescription="" gpmc_supported="">Start Menu</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Remove Favorites menu from Start Menu</td><td>&nbsp;</td></tr> <tr><td>Remove Find menu from Start Menu</td><td>&nbsp;</td></tr> <tr><td>Remove Run menu from Start Menu</td><td>&nbsp;</td></tr> <tr><td>Remove the Active Desktop item from the Settings menu</td><td>Enabled</td></tr> <tr><td>Remove the Windows Update item from the Settings menu</td><td>&nbsp;</td></tr> <tr><td>Disable drag and drop context menus on the Start Menu</td><td>&nbsp;</td></tr> <tr><td>Remove the Folder Options menu item from the Settings menu</td><td>&nbsp;</td></tr> <tr><td>Remove Documents menu from Start Menu</td><td>&nbsp;</td></tr> <tr><td>Do not keep history of recently opened documents</td><td>&nbsp;</td></tr> <tr><td>Clear history of recent opened documents</td><td>&nbsp;</td></tr> <tr><td>Disable Logoff</td><td>&nbsp;</td></tr> <tr><td>Disable Shut Down command from Start Menu</td><td>&nbsp;</td></tr> <tr><td>Disable changes to Printers and Control Panel Settings</td><td>&nbsp;</td></tr> <tr><td>Disable changes to Taskbar and Start Menu Settings</td><td>&nbsp;</td></tr> <tr><td>Disable context menu for Taskbar</td><td>&nbsp;</td></tr> <tr><td>Add Run Dlg checkbox for New Memory Space (Windows NT only)</td><td>Disabled</td></tr> </table></td></tr></table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Start Menu and Taskbar</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Add Logoff to the Start Menu" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="Adds the &amp;quot;Log Off &amp;lt;username&amp;gt;&amp;quot; item to the Start menu and prevents users from removing it.&lt;br/&gt;&lt;br/&gt;If you enable this setting, the Log Off &amp;lt;username&amp;gt; item appears in the Start menu. This setting also removes the Display Logoff item from Start Menu Options. As a result, users cannot remove the Log Off &amp;lt;username&amp;gt; item from the Start Menu.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, users can use the Display Logoff item to add and remove the Log Off item.&lt;br/&gt;&lt;br/&gt;This setting affects the Start menu only. It does not affect the Log Off item on the Windows Security dialog box that appears when you press Ctrl+Alt+Del.&lt;br/&gt;&lt;br/&gt;Note: To add or remove the Log Off item on a computer, click Start, click Settings, click Taskbar and Start Menu, click the Start Menu Options tab, and then, in the Start Menu Settings box, click Display Logoff.&lt;br/&gt;&lt;br/&gt;Also, see &amp;quot;Remove Logoff&amp;quot; in User Configuration\Administrative Templates\System\Logon/Logoff." gpmc_supported="At least Microsoft Windows 2000">Add Logoff to the Start Menu</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Clear history of recently opened documents on exit" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="Clear history of recently opened documents on exit.&lt;br/&gt;&lt;br/&gt;If you enable this setting, the system deletes shortcuts to recently used document files when the user logs off. As a result, the Documents menu on the Start menu is always empty when the user logs on.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, the system retains document shortcuts, and when a user logs on the Documents menu appears just as it did when the user logged off.&lt;br/&gt;&lt;br/&gt;Note: The system saves document shortcuts in the user profile in the System-drive\Documents and Settings\User-name\Recent folder.&lt;br/&gt;&lt;br/&gt;Also, see the &amp;quot;Remove Documents menu from Start Menu&amp;quot; and &amp;quot;Do not keep history of recently opened documents&amp;quot; policies in this folder. The system only uses this setting when neither of these related settings are selected.&lt;br/&gt;&lt;br/&gt;This setting does not clear the list of recent files that Windows programs display at the bottom of the File menu. See the &amp;quot;Do not keep history of recently opened documents&amp;quot; setting.&lt;br/&gt;&lt;br/&gt;This policy setting also does not hide document shortcuts displayed in the Open dialog box. See the &amp;quot;Hide the dropdown list of recent files&amp;quot; setting." gpmc_supported="At least Microsoft Windows 2000">Clear history of recently opened documents on exit</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Do not display any custom toolbars in the taskbar" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="This setting affects the taskbar.&lt;br/&gt;&lt;br/&gt;The taskbar includes the Start button, buttons for currently running tasks, custom toolbars, the notification area, and the system clock. Toolbars include Quick Launch, Address, Links, Desktop, and other custom toolbars created by the user or by an application.&lt;br/&gt;&lt;br/&gt;If this setting is enabled, the taskbar does not display any custom toolbars, and the user cannot add any custom toolbars to the taskbar. Moreover, the &amp;quot;Toolbars&amp;quot; menu command and submenu are removed from the context menu. The taskbar displays only the Start button, taskbar buttons, the notification area, and the system clock.&lt;br/&gt;&lt;br/&gt;If this setting is disabled or is not configured, the taskbar displays all toolbars. Users can add or remove custom toolbars, and the &amp;quot;Toolbars&amp;quot; command appears in the context menu." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Do not display any custom toolbars in the taskbar</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Do not keep history of recently opened documents" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="Prevents the operating system and installed programs from creating and displaying shortcuts to recently opened documents.&lt;br/&gt;&lt;br/&gt;If you enable this setting, the system and Windows programs do not create shortcuts to documents opened while the setting is in effect. Also, they retain but do not display existing document shortcuts. The system empties the Documents menu on the Start menu, and Windows programs do not display shortcuts at the bottom of the File menu.&lt;br/&gt;&lt;br/&gt;If you disable this setting, the system defaults are enforced. Disabling this setting has no effect on the system.&lt;br/&gt;&lt;br/&gt;Note: The system saves document shortcuts in the user profile in the System-drive\Documents and Settings\User-name\Recent folder.&lt;br/&gt;&lt;br/&gt;Also, see the &amp;quot;Remove Documents menu from Start Menu&amp;quot; and &amp;quot;Clear history of recently opened documents on exit&amp;quot; policies in this folder.&lt;br/&gt;&lt;br/&gt;If you enable this setting but do not enable the &amp;quot;Remove Documents menu from Start Menu&amp;quot; setting, the Documents menu appears on the Start menu, but it is empty.&lt;br/&gt;&lt;br/&gt;If you enable this setting, but then later disable it or set it to Not Configured, the document shortcuts saved before the setting was enabled reappear in the Documents menu and program File menus.&lt;br/&gt;&lt;br/&gt;This setting does not hide document shortcuts displayed in the Open dialog box. See the &amp;quot;Hide the dropdown list of recent files&amp;quot; setting.&lt;br/&gt;&lt;br/&gt;Note: It is a requirement for third-party applications with Windows 2000 or later certification to adhere to this setting." gpmc_supported="At least Microsoft Windows 2000">Do not keep history of recently opened documents</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Do not use the search-based method when resolving shell shortcuts" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="Prevents the system from conducting a comprehensive search of the target drive to resolve a shortcut.&lt;br/&gt;&lt;br/&gt;By default, when the system cannot find the target file for a shortcut (.lnk), it searches all paths associated with the shortcut. If the target file is located on an NTFS partition, the system then uses the target's file ID to find a path. If the resulting path is not correct, it conducts a comprehensive search of the target drive in an attempt to find the file.&lt;br/&gt;&lt;br/&gt;If you enable this setting, the system does not conduct the final drive search. It just displays a message explaining that the file is not found.&lt;br/&gt;&lt;br/&gt;Note: This setting only applies to target files on NTFS partitions. FAT partitions do not have this ID tracking and search capability.&lt;br/&gt;&lt;br/&gt;Also, see the &amp;quot;Do not track Shell shortcuts during roaming&amp;quot; and the &amp;quot;Do not use the tracking-based method when resolving shell shortcuts&amp;quot; settings." gpmc_supported="At least Microsoft Windows 2000">Do not use the search-based method when resolving shell shortcuts</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Do not use the tracking-based method when resolving shell shortcuts" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="Prevents the system from using NTFS tracking features to resolve a shortcut.&lt;br/&gt;&lt;br/&gt;By default, when the system cannot find the target file for a shortcut (.lnk), it searches all paths associated with the shortcut. If the target file is located on an NTFS partition, the system then uses the target's file ID to find a path. If the resulting path is not correct, it conducts a comprehensive search of the target drive in an attempt to find the file.&lt;br/&gt;&lt;br/&gt;If you enable this setting, the system does not try to locate the file by using its file ID. It skips this step and begins a comprehensive search of the drive specified in the target path.&lt;br/&gt;&lt;br/&gt;Note: This setting only applies to target files on NTFS partitions. FAT partitions do not have this ID tracking and search capability.&lt;br/&gt;&lt;br/&gt;Also, see the &amp;quot;Do not track Shell shortcuts during roaming&amp;quot; and the &amp;quot;Do not use the search-based method when resolving shell shortcuts&amp;quot; settings." gpmc_supported="At least Microsoft Windows 2000">Do not use the tracking-based method when resolving shell shortcuts</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Gray unavailable Windows Installer programs Start Menu shortcuts" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="Displays Start menu shortcuts to partially installed programs in gray text.&lt;br/&gt;&lt;br/&gt;This setting makes it easier for users to distinguish between programs that are fully installed and those that are only partially installed.&lt;br/&gt;&lt;br/&gt;Partially installed programs include those that a system administrator assigns using Windows Installer and those that users have configured for full installation upon first use.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, all Start menu shortcuts appear as black text.&lt;br/&gt;&lt;br/&gt;Note: Enabling this setting can make the Start menu slow to open." gpmc_supported="At least Microsoft Windows 2000">Gray unavailable Windows Installer programs Start Menu shortcuts</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Lock the Taskbar" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="This setting effects the taskbar, which is used to switch between running applications.&lt;br/&gt;&lt;br/&gt;The taskbar includes the Start button, list of currently running tasks, and the notification area. By default, the taskbar is located at the bottom of the screen, but it can be dragged to any side of the screen. When it is locked, it cannot be moved or resized.&lt;br/&gt;&lt;br/&gt;If you enable this setting, it prevents the user from moving or resizing the taskbar. While the taskbar is locked, auto-hide and other taskbar options are still available in Taskbar properties.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, the user can configure the taskbar position.&lt;br/&gt;&lt;br/&gt;Note: Enabling this setting also locks the quicklaunch bar and any other toolbars that the user has on their taskbar. The toolbar's position is locked, and the user cannot show and hide various toolbars using the taskbar context menu." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Lock the Taskbar</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prevent changes to Taskbar and Start Menu Settings" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="Removes the Taskbar and Start Menu item from Settings on the Start menu. This setting also prevents the user from opening the Taskbar Properties dialog box.&lt;br/&gt;&lt;br/&gt;If the user right-clicks the taskbar and then clicks Properties, a message appears explaining that a setting prevents the action." gpmc_supported="At least Microsoft Windows 2000">Prevent changes to Taskbar and Start Menu Settings</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove access to the context menus for the taskbar" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="Hides the menus that appear when you right-click the taskbar and items on the taskbar, such as the Start button, the clock, and the taskbar buttons.&lt;br/&gt;&lt;br/&gt;This setting does not prevent users from using other methods to issue the commands that appear on these menus." gpmc_supported="At least Microsoft Windows 2000">Remove access to the context menus for the taskbar</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove and prevent access to the Shut Down command" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="Prevents users from shutting down or restarting Windows.&lt;br/&gt;&lt;br/&gt;This setting removes the Shut Down option from the Start menu and disables the Shut Down button on the Windows Security dialog box, which appears when you press CTRL+ALT+DEL.&lt;br/&gt;&lt;br/&gt;This setting prevents users from using the Windows user interface to shut down the system, although it does not prevent them from running programs that shut down Windows. &lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, the Shut Down menu option appears, and the Shut Down button is enabled.&lt;br/&gt;&lt;br/&gt;Note: It is a requirement for third-party applications with Windows 2000 or later certification to adhere to this setting." gpmc_supported="At least Microsoft Windows 2000">Remove and prevent access to the Shut Down command</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove Balloon Tips on Start Menu items" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="Hides pop-up text on the Start menu and in the notification area.&lt;br/&gt;&lt;br/&gt;When you hold the cursor over an item on the Start menu or in the notification area, the system displays pop-up text providing additional information about the object.&lt;br/&gt;&lt;br/&gt;If you enable this setting, some of this pop-up text is not displayed. The pop-up text affected by this setting includes &amp;quot;Click here to begin&amp;quot; on the Start button, &amp;quot;Where have all my programs gone&amp;quot; on the Start menu, and &amp;quot;Where have my icons gone&amp;quot; in the notification area.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, all pop-up text is displayed on the Start menu and in the notification area." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Remove Balloon Tips on Start Menu items</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove common program groups from Start Menu" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="Removes items in the All Users profile from the Programs menu on the Start menu.&lt;br/&gt;&lt;br/&gt;By default, the Programs menu contains items from the All Users profile and items from the user's profile. If you enable this setting, only items in the user's profile appear in the Programs menu.&lt;br/&gt;&lt;br/&gt;Tip: To see the Program menu items in the All Users profile, on the system drive, go to Documents and Settings\All Users\Start Menu\Programs." gpmc_supported="At least Microsoft Windows 2000">Remove common program groups from Start Menu</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove Documents menu from Start Menu" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="Removes the Documents menu from the Start menu.&lt;br/&gt;&lt;br/&gt;The Documents menu contains links to the nonprogram files that users have most recently opened. It appears so that users can easily reopen their documents.&lt;br/&gt;&lt;br/&gt;If you enable this setting, the system saves document shortcuts but does not display them in the Documents menu. If you later disable it or set it to Not Configured, the document shortcuts saved before the setting was enabled and while it was in effect appear in the Documents menu.&lt;br/&gt;&lt;br/&gt;Note: This setting does not prevent Windows programs from displaying shortcuts to recently opened documents. See the &amp;quot;Do not keep history of recently opened documents&amp;quot; setting.&lt;br/&gt;&lt;br/&gt;Also, see the &amp;quot;Do not keep history of recently opened documents&amp;quot; and &amp;quot;Clear history of recenTly opened documents on exit&amp;quot; policies in this folder.&lt;br/&gt;&lt;br/&gt;This setting also does not hide document shortcuts displayed in the Open dialog box. See the &amp;quot;Hide the dropdown list of recent files&amp;quot; setting." gpmc_supported="At least Microsoft Windows 2000">Remove Documents menu from Start Menu</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove Drag-and-drop context menus on the Start Menu" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="Prevents users from using the drag-and-drop method to reorder or remove items on the Start menu. Also, it removes context menus from the Start menu.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, users can remove or reorder Start menu items by dragging and dropping the item. They can display context menus by right-clicking a Start menu item.&lt;br/&gt;&lt;br/&gt;This setting does not prevent users from using other methods of customizing the Start menu or performing the tasks available from the context menus.&lt;br/&gt;&lt;br/&gt;Also, see the &amp;quot;Prevent changes to Taskbar and Start Menu Settings&amp;quot; and the &amp;quot;Remove access to the context menus for taskbar&amp;quot; settings." gpmc_supported="At least Microsoft Windows 2000">Remove Drag-and-drop context menus on the Start Menu</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove frequent programs list from the Start Menu" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="If you enable this setting, the frequently used programs list is removed from the Start menu.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, the frequently used programs list remains on the simple Start menu." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Remove frequent programs list from the Start Menu</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove Help menu from Start Menu" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="Removes the Help command from the Start menu.&lt;br/&gt;&lt;br/&gt;This setting only affects the Start menu. It does not remove the Help menu from Windows Explorer and does not prevent users from running Help." gpmc_supported="At least Microsoft Windows 2000">Remove Help menu from Start Menu</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove links and access to Windows Update" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="Prevents users from connecting to the Windows Update Web site.&lt;br/&gt;&lt;br/&gt;This setting blocks user access to the Windows Update Web site at http://windowsupdate.microsoft.com. Also, the setting removes the Windows Update hyperlink from the Start menu and from the Tools menu in Internet Explorer.&lt;br/&gt;&lt;br/&gt;Windows Update, the online extension of Windows, offers software updates to keep a user s system up-to-date. The Windows Update Product Catalog determines any system files, security fixes, and Microsoft updates that users need and shows the newest versions available for download.&lt;br/&gt;&lt;br/&gt;Also, see the &amp;quot;Hide the &amp;quot;Add programs from Microsoft&amp;quot; option&amp;quot; setting." gpmc_supported="At least Microsoft Windows 2000">Remove links and access to Windows Update</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove My Documents icon from Start Menu" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="Removes the My Documents icon from the Start menu and its submenus.&lt;br/&gt;&lt;br/&gt;This setting only removes the icon. It does not prevent the user from using other methods to gain access to the contents of the My Documents folder.&lt;br/&gt;&lt;br/&gt;Note: To make changes to this setting effective, you must log off and then log on.&lt;br/&gt;&lt;br/&gt;Also, see the &amp;quot;Remove My Documents icon on the desktop&amp;quot; setting." gpmc_supported="At least Microsoft Windows 2000">Remove My Documents icon from Start Menu</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove My Music icon from Start Menu" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="Removes the My Music icon from the Start Menu." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Remove My Music icon from Start Menu</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove My Network Places icon from Start Menu" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="Removes the My Network Places icon from the Start Menu." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Remove My Network Places icon from Start Menu</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove My Pictures icon from Start Menu" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="Removes the My Pictures icon from the Start Menu." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Remove My Pictures icon from Start Menu</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove Network Connections from Start Menu" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="Prevents users from running Network Connections.&lt;br/&gt;&lt;br/&gt;This setting prevents the Network Connections folder from opening. This setting also removes Network Connections from Settings on the Start menu.&lt;br/&gt;&lt;br/&gt;Network Connections still appears in Control Panel and in Windows Explorer, but if users try to start it, a message appears explaining that a setting prevents the action.&lt;br/&gt;&lt;br/&gt;Also, see the &amp;quot;Disable programs on Settings menu&amp;quot; and &amp;quot;Disable Control Panel&amp;quot; settings and the settings in the Network Connections folder (Computer Configuration and User Configuration\Administrative Templates\Network\Network Connections)." gpmc_supported="At least Microsoft Windows 2000">Remove Network Connections from Start Menu</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove pinned programs list from the Start Menu" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="If you enable this setting, the &amp;quot;Pinned Programs&amp;quot; list is removed from the Start menu, and the Internet and Email checkboxes are removed from the simple Start menu customization CPL.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, the &amp;quot;Pinned Programs&amp;quot; list remains on the simple Start menu." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Remove pinned programs list from the Start Menu</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove programs on Settings menu" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="Prevents Control Panel, Printers, and Network Connections from running.&lt;br/&gt;&lt;br/&gt;This setting removes the Control Panel, Printers, and Network and Connection folders from Settings on the Start menu, and from My Computer and Windows Explorer. It also prevents the programs represented by these folders (such as Control.exe) from running.&lt;br/&gt;&lt;br/&gt;However, users can still start Control Panel items by using other methods, such as right-clicking the desktop to start Display or right-clicking My Computer to start System.&lt;br/&gt;&lt;br/&gt;Also, see the &amp;quot;Disable Control Panel,&amp;quot; &amp;quot;Disable Display in Control Panel,&amp;quot; and &amp;quot;Remove Network Connections from Start Menu&amp;quot; settings." gpmc_supported="At least Microsoft Windows 2000">Remove programs on Settings menu</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove Run menu from Start Menu" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="Allows you to remove the Run command from the Start menu, Internet Explorer, and Task Manager.&lt;br/&gt;&lt;br/&gt;If you enable this setting, the following changes occur:&lt;br/&gt;&lt;br/&gt;(1) The Run command is removed from the Start menu.&lt;br/&gt;&lt;br/&gt;(2) The New Task (Run) command is removed from Task Manager.&lt;br/&gt;&lt;br/&gt;(3) The user will be blocked from entering the following into the Internet Explorer Address Bar:&lt;br/&gt;&lt;br/&gt;--- A UNC path: \\&amp;lt;server&amp;gt;\&amp;lt;share&amp;gt; &lt;br/&gt;&lt;br/&gt;---Accessing local drives: e.g., C:&lt;br/&gt;&lt;br/&gt;--- Accessing local folders: e.g., \temp&amp;gt;&lt;br/&gt;&lt;br/&gt;Also, users with extended keyboards will no longer be able to display the Run dialog box by pressing the Application key (the key with the Windows logo) + R.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, users will be able to access the Run command in the Start menu and in Task Manager and use the Internet Explorer Address Bar.&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Note:This setting affects the specified interface only. It does not prevent users from using other methods to run programs.&lt;br/&gt;&lt;br/&gt;Note: It is a requirement for third-party applications with Windows 2000 or later certification to adhere to this setting." gpmc_supported="At least Microsoft Windows 2000">Remove Run menu from Start Menu</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove Search menu from Start Menu" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="Removes the Search item from the Start menu, and disables some Windows Explorer search elements.&lt;br/&gt;&lt;br/&gt;This setting removes the Search item from the Start menu and from the context menu that appears when you right-click the Start menu. Also, the system does not respond when users press the Application key (the key with the Windows logo)+ F.&lt;br/&gt;&lt;br/&gt;In Windows Explorer, the Search item still appears on the Standard buttons toolbar, but the system does not respond when the user presses Ctrl+F. Also, Search does not appear in the context menu when you right-click an icon representing a drive or a folder.&lt;br/&gt;&lt;br/&gt;This setting affects the specified user interface elements only. It does not affect Internet Explorer and does not prevent the user from using other methods to search.&lt;br/&gt;&lt;br/&gt;Also, see the &amp;quot;Remove Search button from Windows Explorer&amp;quot; setting in User Configuration\Administrative Templates\Windows Components\Windows Explorer.&lt;br/&gt;&lt;br/&gt;Note:&lt;br/&gt;&lt;br/&gt;This setting also prevents the user from using the F3 key." gpmc_supported="At least Microsoft Windows 2000">Remove Search menu from Start Menu</a></td><td>Disabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove Set Program Access and Defaults from Start menu" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="Removes the Set Program Access and Defaults icon from the Start menu.&lt;br/&gt;&lt;br/&gt;Clicking the Set Program Access and Defaults icon from the Start menu opens Add or Remove Programs and provides adminstrators the ability to specify default programs for certain activities, such as Web browsing or sending e-mail, as well as which programs are accessible from the Start menu, desktop, and other locations.&lt;br/&gt;&lt;br/&gt;Note: This setting does not prevent the Set Program Access and Defaults button from appearing in Add or Remove Programs. See the &amp;quot;Hide the Set Program Access and Defaults page&amp;quot; setting." gpmc_supported="At least Microsoft Windows 2000 Service Pack 3 or Microsoft Windows XP Professional Service Pack 1">Remove Set Program Access and Defaults from Start menu</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove the &amp;quot;Undock PC&amp;quot; button from the Start Menu" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="If you enable this setting, the &amp;quot;Undock PC&amp;quot; button is removed from the simple Start Menu, and your PC cannot be undocked.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, the &amp;quot;Undock PC&amp;quot; button remains on the simple Start menu, and your PC can be undocked." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Remove the &quot;Undock PC&quot; button from the Start Menu</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Turn off notification area cleanup" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="This setting effects the notification area, also called the &amp;quot;system tray.&amp;quot;&lt;br/&gt;&lt;br/&gt;The notification area is located in the task bar, generally at the bottom of the screen, and itincludes the clock and current notifications. This setting determines whether the items are always expanded or always collapsed. By default, notifications are collapsed. The notification cleanup &amp;lt;&amp;lt; icon can be referred to as the &amp;quot;notification chevron.&amp;quot;&lt;br/&gt;&lt;br/&gt;If you enable this setting, the system notification area expands to show all of the notifications that use this area.&lt;br/&gt;&lt;br/&gt;If you disable this setting, the system notification area will always collapse notifications.&lt;br/&gt;&lt;br/&gt;If you do not configure it, the user can choose if they want notifications collapsed." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Turn off notification area cleanup</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Turn off personalized menus" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="Disables personalized menus.&lt;br/&gt;&lt;br/&gt;Windows personalizes long menus by moving recently used items to the top of the menu and hiding items that have not been used recently. Users can display the hidden items by clicking an arrow to extend the menu.&lt;br/&gt;&lt;br/&gt;If you enable this setting, the system does not personalize menus. All menu items appear and remain in standard order. Also, this setting removes the &amp;quot;Use Personalized Menus&amp;quot; option so users do not try to change the setting while a setting is in effect.&lt;br/&gt;&lt;br/&gt;Note: Personalized menus require user tracking. If you enable the &amp;quot;Turn off user tracking&amp;quot; setting, the system disables user tracking and personalized menus and ignores this setting.&lt;br/&gt;&lt;br/&gt;Tip: To Turn off personalized menus without specifying a setting, click Start, click Settings, click Taskbar and Start Menu, and then, on the General tab, clear the &amp;quot;Use Personalized Menus&amp;quot; option." gpmc_supported="At least Microsoft Windows 2000">Turn off personalized menus</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Turn off user tracking" gpmc_settingPath="User Configuration/Administrative Templates/Start Menu and Taskbar" gpmc_settingDescription="Disables user tracking.&lt;br/&gt;&lt;br/&gt;This setting prevents the system from tracking the programs users run, the paths they navigate, and the documents they open. The system uses this information to customize Windows features, such as personalized menus.&lt;br/&gt;&lt;br/&gt;If you enable this setting, the system does not track these user actions. The system disables customized features that require user tracking information, including personalized menus.&lt;br/&gt;&lt;br/&gt;Also, see the &amp;quot;Turn off personalized menus&amp;quot; setting." gpmc_supported="At least Microsoft Windows 2000">Turn off user tracking</a></td><td>Enabled</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">System</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Code signing for device drivers" gpmc_settingPath="User Configuration/Administrative Templates/System" gpmc_settingDescription="Determines how the system responds when a user tries to install device driver files that are not digitally signed.&lt;br/&gt;&lt;br/&gt;This setting establishes the least secure response permitted on the systems of users in the group. Users can use System in Control Panel to select a more secure setting, but when this setting is enabled, the system does not implement any setting less secure than the one the setting established.&lt;br/&gt;&lt;br/&gt;When you enable this setting, use the drop-down box to specify the desired response.&lt;br/&gt;&lt;br/&gt;-- &amp;quot;Ignore&amp;quot; directs the system to proceed with the installation even if it includes unsigned files.&lt;br/&gt;&lt;br/&gt;-- &amp;quot;Warn&amp;quot; notifies the user that files are not digitally signed and lets the user decide whether to stop or to proceed with the installation and whether to permit unsigned files to be installed. &amp;quot;Warn&amp;quot; is the default.&lt;br/&gt;&lt;br/&gt;-- &amp;quot;Block&amp;quot; directs the system to refuse to install unsigned files. As a result, the installation stops, and none of the files in the driver package are installed.&lt;br/&gt;&lt;br/&gt;To change driver file security without specifying a setting, use System in Control Panel. Right-click My Computer, click Properties, click the Hardware tab, and then click the Driver Signing button." gpmc_supported="At least Microsoft Windows 2000">Code signing for device drivers</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>When Windows detects a driver file without a digital signature:</td><td>Block</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Configure driver search locations" gpmc_settingPath="User Configuration/Administrative Templates/System" gpmc_settingDescription="This setting configures the location that Windows searches for drivers when a new piece of hardware is found.&lt;br/&gt;&lt;br/&gt;By default, Windows searches the following places for drivers: local installation, floppy drives, CD-ROM drives, Windows Update.&lt;br/&gt;&lt;br/&gt;Using this setting, you may remove the floppy and CD-ROM drives from the search algorithm.&lt;br/&gt;&lt;br/&gt;If you enable this setting, you can remove the locations by selecting the associated check box beside the location name.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, Windows searches the installation location, floppy drives, and CD-ROM drives.&lt;br/&gt;&lt;br/&gt;Note: To prevent searching Windows Update for drivers also see &amp;quot;Turn off Windows Update device driver searching&amp;quot; in Administrative Templates/System/Internet Communication Management/Internet Communication settings." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Configure driver search locations</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Don't search floppy disk drives</td><td>Enabled</td></tr> <tr><td>Don't search CD-ROM drives</td><td>Enabled</td></tr> <tr><td>Don't search Windows Update</td><td>Enabled</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Don't display the Getting Started welcome screen at logon" gpmc_settingPath="User Configuration/Administrative Templates/System" gpmc_settingDescription="Supresses the welcome screen.&lt;br/&gt;&lt;br/&gt;This setting hides the welcome screen that is displayed on Windows 2000 Professional and Windows XP Professional each time the user logs on.&lt;br/&gt;&lt;br/&gt;Users can still display the welcome screen by selecting it on the Start menu or by typing &amp;quot;Welcome&amp;quot; in the Run dialog box.&lt;br/&gt;&lt;br/&gt;This setting applies only to Windows 2000 Professional and Windows XP Professional. It does not affect the &amp;quot;Configure Your Server on a Windows 2000 Server&amp;quot; screen on Windows 2000 Server.&lt;br/&gt;&lt;br/&gt;Note: This setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.&lt;br/&gt;&lt;br/&gt;Tip: To display the welcome screen, click Start, point to Programs, point to Accessories, point to System Tools, and then click &amp;quot;Getting Started.&amp;quot; To suppress the welcome screen without specifying a setting, clear the &amp;quot;Show this screen at startup&amp;quot; check box on the welcome screen." gpmc_supported="Only works on Microsoft Windows 2000">Don't display the Getting Started welcome screen at logon</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prevent access to registry editing tools" gpmc_settingPath="User Configuration/Administrative Templates/System" gpmc_settingDescription="Disables the Windows registry editor Regedit.exe.&lt;br/&gt;&lt;br/&gt;If this setting is enabled and the user tries to start a registry editor, a message appears explaining that a setting prevents the action.&lt;br/&gt;&lt;br/&gt;To prevent users from using other administrative tools, use the &amp;quot;Run only allowed Windows applications&amp;quot; setting." gpmc_supported="At least Microsoft Windows 2000">Prevent access to registry editing tools</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Disable regedit from running silently?</td><td>Yes</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prevent access to the command prompt" gpmc_settingPath="User Configuration/Administrative Templates/System" gpmc_settingDescription="Prevents users from running the interactive command prompt, Cmd.exe. This setting also determines whether batch files (.cmd and .bat) can run on the computer.&lt;br/&gt;&lt;br/&gt;If you enable this setting and the user tries to open a command window, the system displays a message explaining that a setting prevents the action.&lt;br/&gt;&lt;br/&gt;Note: Do not prevent the computer from running batch files if the computer uses logon, logoff, startup, or shutdown batch file scripts, or for users that use Terminal Services." gpmc_supported="At least Microsoft Windows 2000">Prevent access to the command prompt</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Disable the command prompt script processing also?</td><td>No</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Restrict these programs from being launched from Help" gpmc_settingPath="User Configuration/Administrative Templates/System" gpmc_settingDescription="Allows you to restrict programs from being run from online Help.&lt;br/&gt;&lt;br/&gt;If you enable this setting, you can prevent programs that you specify from being allowed to be run from Help. When you enable this setting, enter the list of the programs you want to restrict. Enter the file name of the executable for each application, separated by commas.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, users will be able to run applications from online Help.&lt;br/&gt;&lt;br/&gt;Note: You can also restrict users from running applications by using the Software Restriction settings available in Computer Configuration\Security Settings.&lt;br/&gt;&lt;br/&gt;Note: This setting is available under Computer Configuration and User Comfiguration. If both are set, the list of programs specified in each of these will be restricted." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Restrict these programs from being launched from Help</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Enter executables separated by commas:</td><td>iexplore.exe</td></tr> <tr><td colspan="2">Example: calc.exe,paint.exe</td></tr></table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Turn off Autoplay" gpmc_settingPath="User Configuration/Administrative Templates/System" gpmc_settingDescription="Turns off the Autoplay feature.&lt;br/&gt;&lt;br/&gt;Autoplay begins reading from a drive as soon as you insert media in the drive. As a result, the setup file of programs and the music on audio media start immediately.&lt;br/&gt;&lt;br/&gt;By default, Autoplay is disabled on removable drives, such as the floppy disk drive (but not the CD-ROM drive), and on network drives.&lt;br/&gt;&lt;br/&gt;If you enable this setting, you can also disable Autoplay on CD-ROM drives or disable Autoplay on all drives.&lt;br/&gt;&lt;br/&gt;This setting disables Autoplay on additional types of drives. You cannot use this setting to enable Autoplay on drives on which it is disabled by default.&lt;br/&gt;&lt;br/&gt;Note: This setting appears in both the Computer Configuration and User Configuration folders. If the settings conflict, the setting in Computer Configuration takes precedence over the setting in User Configuration.&lt;br/&gt;&lt;br/&gt;Note: This setting does not prevent Autoplay for music CDs." gpmc_supported="At least Microsoft Windows 2000">Turn off Autoplay</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Turn off Autoplay on:</td><td>All drives</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Windows Automatic Updates" gpmc_settingPath="User Configuration/Administrative Templates/System" gpmc_settingDescription="This setting controls automatic updates to a user's computer.&lt;br/&gt;&lt;br/&gt;Whenever a user connects to the Internet, Windows searches for updates available for the software and hardware on their computer and automatically downloads them. This happens in the background, and the user is prompted when downloaded components are ready to be installed, or prior to downloading, depending on their configuration.&lt;br/&gt;&lt;br/&gt;If you enable this setting, it prohibits Windows from searching for updates.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure it, Windows searches for updates and automatically downloads them.&lt;br/&gt;&lt;br/&gt;Note: Windows Update is an online catalog customized for your computer that consists of items such as drivers, critical updates, Help files, and Internet products that you can download to keep your computer up to date.&lt;br/&gt;&lt;br/&gt;Also, see the &amp;quot;Remove links and access to Windows Update&amp;quot; setting. If the &amp;quot;Remove links and access to Windows Update&amp;quot; setting is enabled, the links to Windows Update on the Start menu are also removed.&lt;br/&gt;&lt;br/&gt;Note: If you have installed Windows XP Service Pack 1 or the update to Automatic Updates that was released after Windows XP was originally shipped, then you should use the new Automatic Updates settings located at: 'Computer Configuration / Administrative Templates / Windows Update'" gpmc_supported="Only works on Microsoft Windows XP Professional">Windows Automatic Updates</a></td><td>Disabled</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">System/Ctrl+Alt+Del Options</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove Change Password" gpmc_settingPath="User Configuration/Administrative Templates/System/Ctrl+Alt+Del Options" gpmc_settingDescription="Prevents users from changing their Windows password on demand.&lt;br/&gt;&lt;br/&gt;This setting disables the &amp;quot;Change Password&amp;quot; button on the Windows Security dialog box (which appears when you press Ctrl+Alt+Del).&lt;br/&gt;&lt;br/&gt;However, users are still able to change their password when prompted by the system. The system prompts users for a new password when an administrator requires a new password or their password is expiring." gpmc_supported="At least Microsoft Windows 2000">Remove Change Password</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove Lock Computer" gpmc_settingPath="User Configuration/Administrative Templates/System/Ctrl+Alt+Del Options" gpmc_settingDescription="Prevents users from locking the system.&lt;br/&gt;&lt;br/&gt;While locked, the desktop is hidden and the system cannot be used. Only the user who locked the system or the system administrator can unlock it.&lt;br/&gt;&lt;br/&gt;Tip:To lock a computer without configuring a setting, press Ctrl+Alt+Delete, and then click &amp;quot;Lock Computer.&amp;quot;" gpmc_supported="At least Microsoft Windows 2000">Remove Lock Computer</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove Logoff" gpmc_settingPath="User Configuration/Administrative Templates/System/Ctrl+Alt+Del Options" gpmc_settingDescription="Prevents the user from logging off.&lt;br/&gt;&lt;br/&gt;This setting does not let the user log off the system by using any method, including programs run from the command line, such as scripts. It also disables or removes all menu items and buttons that log the user off the system.&lt;br/&gt;&lt;br/&gt;Also, see the &amp;quot;Remove Logoff on the Start Menu&amp;quot; setting." gpmc_supported="At least Microsoft Windows 2000">Remove Logoff</a></td><td>Disabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove Task Manager" gpmc_settingPath="User Configuration/Administrative Templates/System/Ctrl+Alt+Del Options" gpmc_settingDescription="Prevents users from starting Task Manager (Taskmgr.exe).&lt;br/&gt;&lt;br/&gt;If this setting is enabled and users try to start Task Manager, a message appears explaining that a policy prevents the action.&lt;br/&gt;&lt;br/&gt;Task Manager lets users start and stop programs; monitor the performance of their computers; view and monitor all programs running on their computers, including system services; find the executable names of programs; and change the priority of the process in which programs run." gpmc_supported="At least Microsoft Windows 2000">Remove Task Manager</a></td><td>Enabled</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">System/Group Policy</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Group Policy domain controller selection" gpmc_settingPath="User Configuration/Administrative Templates/System/Group Policy" gpmc_settingDescription="Determines which domain controller the Group Policy Object Editor snap-in uses.&lt;br/&gt;&lt;br/&gt;-- &amp;quot;Use the Primary Domain Controller&amp;quot; indicates that the Group Policy Object Editor snap-in reads and writes changes to the domain controller designated as the PDC Operations Master for the domain.&lt;br/&gt;&lt;br/&gt;-- &amp;quot;Inherit from Active Directory Snap-ins&amp;quot; indicates that the Group Policy Object Editor snap-in reads and writes changes to the domain controller that Active Directory Users and Computers or Active Directory Sites and Services snap-ins use.&lt;br/&gt;&lt;br/&gt;-- &amp;quot;Use any available domain controller&amp;quot; indicates that the Group Policy Object Editor snap-in can read and write changes to any available domain controller.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, the Group Policy Object Editor snap-in uses the domain controller designated as the PDC Operations Master for the domain.&lt;br/&gt;&lt;br/&gt;Note: To change the PDC Operations Master for a domain, in Active Directory Users and Computers, right-click a domain, and then click &amp;quot;Operations Masters.&amp;quot;" gpmc_supported="At least Microsoft Windows 2000">Group Policy domain controller selection</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>When Group Policy Object Editor is selecting a domain controller to use, it should:</td><td>Use the Primary Domain Controller</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Group Policy refresh interval for users" gpmc_settingPath="User Configuration/Administrative Templates/System/Group Policy" gpmc_settingDescription="Specifies how often Group Policy for users is updated while the computer is in use (in the background). This setting specifies a background update rate only for the Group Policies in the User Configuration folder.&lt;br/&gt;&lt;br/&gt;In addition to background updates, Group Policy for users is always updated when users log on.&lt;br/&gt;&lt;br/&gt;By default, user Group Policy is updated in the background every 90 minutes, with a random offset of 0 to 30 minutes.&lt;br/&gt;&lt;br/&gt;You can specify an update rate from 0 to 64,800 minutes (45 days). If you select 0 minutes, the computer tries to update user Group Policy every 7 seconds. However, because updates might interfere with users' work and increase network traffic, very short update intervals are not appropriate for most installations.&lt;br/&gt;&lt;br/&gt;If you disable this setting, user Group Policy is updated every 90 minutes (the default). To specify that Group Policy for users should never be updated while the computer is in use, select the &amp;quot;Turn off background refresh of Group Policy&amp;quot; setting.&lt;br/&gt;&lt;br/&gt;This setting also lets you specify how much the actual update interval varies. To prevent clients with the same update interval from requesting updates simultaneously, the system varies the update interval for each client by a random number of minutes. The number you type in the random time box sets the upper limit for the range of variance. For example, if you type 30 minutes, the system selects a variance of 0 to 30 minutes. Typing a large number establishes a broad range and makes it less likely that client requests overlap. However, updates might be delayed significantly.&lt;br/&gt;&lt;br/&gt;Important: If the &amp;quot;Turn off background refresh of Group Policy&amp;quot; setting is enabled, this setting is ignored.&lt;br/&gt;&lt;br/&gt;Note: This setting establishes the update rate for user Group Policies. To set an update rate for computer Group Policies, use the &amp;quot;Group Policy refresh interval for computers&amp;quot; setting (located in Computer Configuration\Administrative Templates\System\Group Policy).&lt;br/&gt;&lt;br/&gt;Tip: Consider notifying users that their policy is updated periodically so that they recognize the signs of a policy update. When Group Policy is updated, the Windows desktop is refreshed; it flickers briefly and closes open menus. Also, restrictions imposed by Group Policies, such as those that limit the programs a user can run, might interfere with tasks in progress." gpmc_supported="At least Microsoft Windows 2000">Group Policy refresh interval for users</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td colspan="2">This setting allows you to customize how often Group Policy is applied</td></tr><tr><td colspan="2">to users. The range is 0 to 64800 minutes (45 days).</td></tr><tr><td>Minutes:</td><td>5</td></tr> <tr><td colspan="2"> </td></tr><tr><td colspan="2">This is a random time added to the refresh interval to prevent</td></tr><tr><td colspan="2">all clients from requesting Group Policy at the same time.</td></tr><tr><td colspan="2">The range is 0 to 1440 minutes (24 hours)</td></tr><tr><td>Minutes:</td><td>5</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Group Policy slow link detection" gpmc_settingPath="User Configuration/Administrative Templates/System/Group Policy" gpmc_settingDescription="Defines a slow connection for purposes of applying and updating Group Policy.&lt;br/&gt;&lt;br/&gt;If the rate at which data is transferred from the domain controller providing a policy update to the computers in this group is slower than the rate specified by this setting, the system considers the connection to be slow.&lt;br/&gt;&lt;br/&gt;The system's response to a slow policy connection varies among policies. The program implementing the policy can specify the response to a slow link. Also, the policy processing settings in this folder lets you override the programs' specified responses to slow links.&lt;br/&gt;&lt;br/&gt;To use this setting, in the &amp;quot;Connection speed&amp;quot; box, type a decimal number between 0 and 4,294,967,200 (0xFFFFFFA0), indicating a transfer rate in kilobits per second. Any connection slower than this rate is considered to be slow. If you type 0, all connections are considered to be fast.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, the system uses the default value of 500 kilobits per second.&lt;br/&gt;&lt;br/&gt;This setting appears in the Computer Configuration and User Configuration folders. The setting in Computer Configuration defines a slow link for policies in the Computer Configuration folder. The setting in User Configuration defines a slow link for settings in the User Configuration folder.&lt;br/&gt;&lt;br/&gt;Also, see the &amp;quot;Do not detect slow network connections&amp;quot; and related policies in Computer Configuration\Administrative Templates\System\User Profile. Note: If the profile server has IP connectivity, the connection speed setting is used. If the profile server does not have IP connectivity, the SMB timing is used." gpmc_supported="At least Microsoft Windows 2000">Group Policy slow link detection</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Connection speed (Kbps):</td><td>500</td></tr> <tr><td colspan="2"> </td></tr><tr><td colspan="2">Enter 0 to disable slow link detection.</td></tr></table></td></tr></table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">System/Internet Communication Management/Internet Communication settings</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Turn off downloading of print drivers over HTTP" gpmc_settingPath="User Configuration/Administrative Templates/System/Internet Communication Management/Internet Communication settings" gpmc_settingDescription="Specifies whether to allow this client to download print driver packages over HTTP.&lt;br/&gt;&lt;br/&gt;To set up HTTP printing, non-inbox drivers need to be downloaded over HTTP.&lt;br/&gt;&lt;br/&gt;Note: This setting does not prevent the client from printing to printers on the Intranet or the Internet over HTTP. It only prohibits downloading drivers that are not already installed locally.&lt;br/&gt;&lt;br/&gt;If you enable this setting, print drivers will not be downloaded over HTTP.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, users will be able to download print drivers over HTTP." gpmc_supported="At least Microsoft Windows XP Professional with SP2">Turn off downloading of print drivers over HTTP</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Turn off Internet download for Web publishing and online ordering wizards" gpmc_settingPath="User Configuration/Administrative Templates/System/Internet Communication Management/Internet Communication settings" gpmc_settingDescription="Specifies whether Windows should download a list of providers for the Web publishing and online ordering wizards.&lt;br/&gt;&lt;br/&gt;These wizards allow users to select from a list of companies that provide services such as online storage and photographic printing. By default, Windows displays providers downloaded from a Windows Web site in addition to providers specified in the registry.&lt;br/&gt;&lt;br/&gt;If you enable this setting, Windows will not download providers and only the service providers that are cached in the local registry will be displayed.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, a list of providers will be downloaded when the user uses the Web publishing or online ordering wizards.&lt;br/&gt;&lt;br/&gt;See the documentation for the Web publishing and online ordering wizards for more information, including details on specifying service providers in the registry." gpmc_supported="At least Microsoft Windows XP Professional with SP2 or Windows Server 2003 family">Turn off Internet download for Web publishing and online ordering wizards</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Turn off Internet File Association service" gpmc_settingPath="User Configuration/Administrative Templates/System/Internet Communication Management/Internet Communication settings" gpmc_settingDescription="Specifies whether to use the Microsoft Web service for finding an application to open a file with an unhandled file association.&lt;br/&gt;&lt;br/&gt;When a user opens a file that has an extension that is not associated with any applications on the machine, the user is given the choice to choose a local application or use the Web service to find an application.&lt;br/&gt;&lt;br/&gt;If you enable this setting, the link and the dialog for using the Web service to open an unhandled file association are removed.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, the user will be allowed to use the Web service." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Turn off Internet File Association service</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Turn off printing over HTTP" gpmc_settingPath="User Configuration/Administrative Templates/System/Internet Communication Management/Internet Communication settings" gpmc_settingDescription="Specifies whether to allow printing over HTTP from this client.&lt;br/&gt;&lt;br/&gt;Printing over HTTP allows a client to print to printers on the intranet as well as the Internet.&lt;br/&gt;&lt;br/&gt;Note: This setting affects the client side of Internet printing only. It does not prevent this machine from acting as an Internet Printing server and making its shared printers available via HTTP.&lt;br/&gt;&lt;br/&gt;If you enable this setting, it prevents this client from printing to Internet printers over HTTP.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, users will be able to choose to print to Internet printers over HTTP.&lt;br/&gt;&lt;br/&gt;Also see the &amp;quot;Web-based Printing&amp;quot; setting in Computer Configuration/Administrative Templates/Printers." gpmc_supported="At least Microsoft Windows XP Professional with SP2">Turn off printing over HTTP</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Turn off the &amp;quot;Order Prints&amp;quot; picture task" gpmc_settingPath="User Configuration/Administrative Templates/System/Internet Communication Management/Internet Communication settings" gpmc_settingDescription="Specifies whether the &amp;quot;Order Prints Online&amp;quot; task is available from Picture Tasks in Windows folders.&lt;br/&gt;&lt;br/&gt;The &amp;quot;Order Prints Online&amp;quot; Wizard is used to download a list of providers and allow users to order prints online.&lt;br/&gt;&lt;br/&gt;If you enable this setting, the task &amp;quot;Order Prints Online&amp;quot; is removed from Picture Tasks in Windows Explorer folders.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, the task is displayed." gpmc_supported="At least Microsoft Windows XP Professional with SP2 or Windows Server 2003 family">Turn off the &quot;Order Prints&quot; picture task</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Turn off the &amp;quot;Publish to Web&amp;quot; task for files and folders" gpmc_settingPath="User Configuration/Administrative Templates/System/Internet Communication Management/Internet Communication settings" gpmc_settingDescription="Specifies whether the tasks &amp;quot;Publish this file to the Web,&amp;quot; &amp;quot;Publish this folder to the Web,&amp;quot; and &amp;quot;Publish the selected items to the Web,&amp;quot; are available from File and Folder Tasks in Windows folders.&lt;br/&gt;&lt;br/&gt;The Web Publishing Wizard is used to download a list of providers and allow users to publish content to the Web.&lt;br/&gt;&lt;br/&gt;If you enable this setting, these tasks are removed from the File and Folder tasks in Windows folders.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, the tasks will be shown." gpmc_supported="At least Microsoft Windows XP Professional with SP2 or Windows Server 2003 family">Turn off the &quot;Publish to Web&quot; task for files and folders</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Turn off the Windows Messenger Customer Experience Improvement Program" gpmc_settingPath="User Configuration/Administrative Templates/System/Internet Communication Management/Internet Communication settings" gpmc_settingDescription="Specifies whether Windows Messenger collects anonymous information about how Windows Messenger software and service is used.&lt;br/&gt;&lt;br/&gt;With the Customer Experience Improvement program, users can allow Microsoft to collect anonymous information about how the product is used. This information is used to improve the product in future releases.&lt;br/&gt;&lt;br/&gt;If you enable this setting, Windows Messenger will not collect usage information and the user settings to enable the collection of usage information will not be shown.&lt;br/&gt;&lt;br/&gt;If you disable this setting, Windows Messenger will collect anonymous usage information and the setting will not be shown.&lt;br/&gt;&lt;br/&gt;If you do not configure this setting, users will have the choice to opt-in and allow information to be collected." gpmc_supported="At least Microsoft Windows XP Professional with SP2 or Windows Server 2003 family">Turn off the Windows Messenger Customer Experience Improvement Program</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Turn off Windows Movie Maker automatic codec downloads" gpmc_settingPath="User Configuration/Administrative Templates/System/Internet Communication Management/Internet Communication settings" gpmc_settingDescription="Specifies whether Windows Movie Maker automatically downloads codecs.&lt;br/&gt;&lt;br/&gt;Windows Movie Maker can be configured so that codecs are downloaded automatically if the required codecs are not installed on the computer.&lt;br/&gt;&lt;br/&gt;If you enable this setting, Windows Movie Maker will not attempt to download missing codecs for imported audio and video files.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, Windows Movie Maker might attempt to download missing codecs for imported audio and video files." gpmc_supported="At least Microsoft Windows XP Professional with SP2">Turn off Windows Movie Maker automatic codec downloads</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Turn off Windows Movie Maker online Web links" gpmc_settingPath="User Configuration/Administrative Templates/System/Internet Communication Management/Internet Communication settings" gpmc_settingDescription="Specifies whether links to Web sites are available in Windows Movie Maker. These links include the &amp;quot;Windows Movie Maker on the Web&amp;quot; and &amp;quot;Privacy Statement&amp;quot; commands that appear on the Help menu, as well as the &amp;quot;Learn more about video filters&amp;quot; hyperlink in the Options dialog box and the &amp;quot;sign up now&amp;quot; hyperlink in the &amp;quot;The Web&amp;quot; saving option in the Save Movie Wizard.&lt;br/&gt;&lt;br/&gt;The &amp;quot;Windows Movie Maker on the Web&amp;quot; command lets users go directly to the Windows Movie Maker Web site to get more information, and the &amp;quot;Privacy Statement&amp;quot; command lets users view information about privacy issues in respect to Windows Movie Maker. The &amp;quot;Learn more about video filters&amp;quot; hyperlink lets users learn more about video filters and their role in saving movies process in Windows Movie Maker. The &amp;quot;sign up now&amp;quot; hyperlink lets users sign up with a video hosting provider on the Web.&lt;br/&gt;&lt;br/&gt;If you enable this setting, the previously mentioned links to Web sites from Windows Movie Maker are disabled and cannot be selected.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, the previously mentioned links to Web sites from Windows Movie Maker are enabled and can be selected." gpmc_supported="At least Microsoft Windows XP Professional with SP2">Turn off Windows Movie Maker online Web links</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Turn off Windows Movie Maker saving to online video hosting provider" gpmc_settingPath="User Configuration/Administrative Templates/System/Internet Communication Management/Internet Communication settings" gpmc_settingDescription="Specifies whether users can send a final movie to a video hosting provider on the Web by choosing &amp;quot;The Web&amp;quot; saving option in the Save Movie Wizard of Windows Movie Maker.&lt;br/&gt;&lt;br/&gt;When users create a movie in Windows Movie Maker, they can choose to share it in a variety of ways through the Save Movie Wizard. &amp;quot;The Web&amp;quot; saving option lets users send their movies to a video hosting provider.&lt;br/&gt;&lt;br/&gt;If you enable this setting, users cannot choose &amp;quot;The Web&amp;quot; saving option in the Save Movie Wizard of Windows Movie Maker and cannot send a movie to a video hosting provider on the Web.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, users can choose &amp;quot;The Web&amp;quot; saving option in the Save Movie Wizard of Windows Movie Maker and can send a movie to a video hosting provider on the Web." gpmc_supported="At least Microsoft Windows XP Professional with SP2">Turn off Windows Movie Maker saving to online video hosting provider</a></td><td>Enabled</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">System/Scripts</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Run logoff scripts visible" gpmc_settingPath="User Configuration/Administrative Templates/System/Scripts" gpmc_settingDescription="Displays the instructions in logoff scripts as they run.&lt;br/&gt;&lt;br/&gt;Logoff scripts are batch files of instructions that run when the user logs off. By default, the system does not display the instructions in the logoff script.&lt;br/&gt;&lt;br/&gt;If you enable this setting, the system displays each instruction in the logoff script as it runs. The instructions appear in a command window. This setting is designed for advanced users.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, the instructions are suppressed." gpmc_supported="At least Microsoft Windows 2000">Run logoff scripts visible</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Run logon scripts synchronously" gpmc_settingPath="User Configuration/Administrative Templates/System/Scripts" gpmc_settingDescription="Directs the system to wait for the logon scripts to finish running before it starts the Windows Explorer interface program and creates the desktop.&lt;br/&gt;&lt;br/&gt;If you enable this setting, Windows Explorer does not start until the logon scripts have finished running. This setting ensures that logon script processing is complete before the user starts working, but it can delay the appearance of the desktop.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, the logon scripts and Windows Explorer are not synchronized and can run simultaneously.&lt;br/&gt;&lt;br/&gt;This setting appears in the Computer Configuration and User Configuration folders. The setting set in Computer Configuration takes precedence over the setting set in User Configuration." gpmc_supported="At least Microsoft Windows 2000">Run logon scripts synchronously</a></td><td>Enabled</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Windows Components/Internet Explorer</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Configure Outlook Express" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer" gpmc_settingDescription="Allows Administrators to enable and disable the ability for Outlook Express users to save or open attachments that can potentially contain a virus.&lt;br/&gt;&lt;br/&gt;If you check the block attachments setting, users will be unable to open or save attachments that could potentially contain a virus. Users will not be able to disable the blocking of attachments in options.&lt;br/&gt;&lt;br/&gt;If the block attachments setting is not checked, the user can specify to enable or disable the blocking of attachments in options." gpmc_supported="at least Internet Explorer v6.0">Configure Outlook Express</a></td><td>Disabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable AutoComplete for forms" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer" gpmc_settingDescription="Prevents Microsoft Internet Explorer from automatically completing forms, such as filling in a name or a password that the user has entered previously on a Web page.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the Forms check box appears dimmed. To display the Forms check box, users open the Internet Options dialog box, click the Content tab, and then click the AutoComplete button.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can enable the automatic completion of forms.&lt;br/&gt;&lt;br/&gt;The &amp;quot;Disable the Content page&amp;quot; policy (located in \User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel), which removes the Content tab from Internet Explorer in Control Panel, takes precedence over this policy. If it is enabled, this policy is ignored.&lt;br/&gt;&lt;br/&gt;Caution: If you enable this policy after users have used their browser with form automatic completion enabled, it will not clear the automatic completion history for forms that users have already filled out." gpmc_supported="at least Internet Explorer v5.0">Disable AutoComplete for forms</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable changing accessibility settings" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer" gpmc_settingDescription="Prevents users from changing accessibility settings.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the Accessibility button on the General tab in the Internet Options dialog box appears dimmed.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can change accessibility settings, such as overriding fonts and colors on Web pages.&lt;br/&gt;&lt;br/&gt;If you set the &amp;quot;Disable the General page&amp;quot; policy (located in \User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel), you do not need to set this policy, because the &amp;quot;Disable the General page&amp;quot; policy removes the General tab from the interface." gpmc_supported="at least Internet Explorer v5.0">Disable changing accessibility settings</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable changing Advanced page settings" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer" gpmc_settingDescription="Prevents users from changing settings on the Advanced tab in the Internet Options dialog box.&lt;br/&gt;&lt;br/&gt;If you enable this policy, users are prevented from changing advanced Internet settings, such as security, multimedia, and printing. Users cannot select or clear the check boxes on the Advanced tab.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can select or clear settings on the Advanced tab.&lt;br/&gt;&lt;br/&gt;If you set the &amp;quot;Disable the Advanced page&amp;quot; policy (located in \User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel), you do not need to set this policy, because the &amp;quot;Disable the Advanced page&amp;quot; policy removes the Advanced tab from the interface." gpmc_supported="at least Internet Explorer v5.0">Disable changing Advanced page settings</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable changing Automatic Configuration settings" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer" gpmc_settingDescription="Prevents users from changing automatic configuration settings. Automatic configuration is a process that administrators can use to update browser settings periodically.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the automatic configuration settings appear dimmed. The settings are located in the Automatic Configuration area of the Local Area Network (LAN) Settings dialog box. To see the Local Area Network (LAN) Settings dialog box, users open the Internet Options dialog box, click the Connections tab, and then click the LAN Settings button.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, the user can change automatic configuration settings.&lt;br/&gt;&lt;br/&gt;This policy is intended to enable administrators to ensure that users' settings are updated uniformly through automatic configuration.&lt;br/&gt;&lt;br/&gt;The &amp;quot;Disable the Connections page&amp;quot; policy (located in \User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel), which removes the Connections tab from Internet Explorer in Control Panel, takes precedence over this policy. If it is enabled, this policy is ignored." gpmc_supported="at least Internet Explorer v5.0">Disable changing Automatic Configuration settings</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable changing Calendar and Contact settings" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer" gpmc_settingDescription="Prevents users from changing the default programs for managing schedules and contacts.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the Calendar and Contact check boxes appear dimmed in the Internet Programs area. To display these options, users open the Internet Options dialog box, and then click the Programs tab.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can determine which programs to use for managing schedules and contacts, if programs that perform these tasks are installed.&lt;br/&gt;&lt;br/&gt;This &amp;quot;Disable the Programs Page&amp;quot; policy (located in \User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel) takes precedence over this policy. If it is enabled, this policy is ignored." gpmc_supported="at least Internet Explorer v5.0">Disable changing Calendar and Contact settings</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable changing certificate settings" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer" gpmc_settingDescription="Prevents users from changing certificate settings in Internet Explorer. Certificates are used to verify the identity of software publishers.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the settings in the Certificates area on the Content tab in the Internet Options dialog box appear dimmed.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can import new certificates, remove approved publishers, and change settings for certificates that have already been accepted.&lt;br/&gt;&lt;br/&gt;The &amp;quot;Disable the Content page&amp;quot; policy (located in \User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel), which removes the Content tab from Internet Explorer in Control Panel, takes precedence over this policy. If it is enabled, this policy is ignored.&lt;br/&gt;&lt;br/&gt;Caution: If you enable this policy, users can still run the Certificate Manager Import Wizard by double-clicking a software publishing certificate (.spc) file. This wizard enables users to import and configure settings for certificates from software publishers that haven't already been configured for Internet Explorer." gpmc_supported="at least Internet Explorer v5.0">Disable changing certificate settings</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable changing color settings" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer" gpmc_settingDescription="Prevents users from changing the default Web page colors.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the color settings for Web pages appear dimmed. The settings are located in the Colors area in the dialog box that appears when the user clicks the General tab and then clicks the Colors button in the Internet Options dialog box.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can change the default background and text color of Web pages.&lt;br/&gt;&lt;br/&gt;If you set the &amp;quot;Disable the General page&amp;quot; policy (located in \User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel), you do not need to set this policy, because the &amp;quot;Disable the General page&amp;quot; policy removes the General tab from the interface.&lt;br/&gt;&lt;br/&gt;Note: The default Web page colors are ignored on Web pages in which the author has specified the background and text colors." gpmc_supported="at least Internet Explorer v5.0">Disable changing color settings</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable changing connection settings" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer" gpmc_settingDescription="Prevents users from changing dial-up settings.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the Settings button on the Connections tab in the Internet Options dialog box appears dimmed.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can change their settings for dial-up connections.&lt;br/&gt;&lt;br/&gt;If you set the &amp;quot;Disable the Connections page&amp;quot; policy (located in \User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel), you do not need to set this policy, because the &amp;quot;Disable the Connections page&amp;quot; policy removes the Connections tab from the interface." gpmc_supported="at least Internet Explorer v5.0">Disable changing connection settings</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable changing default browser check" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer" gpmc_settingDescription="Prevents Microsoft Internet Explorer from checking to see whether it is the default browser.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the Internet Explorer Should Check to See Whether It Is the Default Browser check box on the Programs tab in the Internet Options dialog box appears dimmed.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can determine whether Internet Explorer will check to see if it is the default browser. When Internet Explorer performs this check, it prompts the user to specify which browser to use as the default.&lt;br/&gt;&lt;br/&gt;This policy is intended for organizations that do not want users to determine which browser should be their default.&lt;br/&gt;&lt;br/&gt;The &amp;quot;Disable the Programs page&amp;quot; policy (located in \User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel), which removes the Programs tab from Internet Explorer in Control Panel, takes precedence over this policy. If it is enabled, this policy is ignored." gpmc_supported="at least Internet Explorer v5.0">Disable changing default browser check</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable changing font settings" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer" gpmc_settingDescription="Prevents users from changing font settings.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the Font button on the General tab in the Internet Options dialog box appears dimmed.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can change the default fonts for viewing Web pages.&lt;br/&gt;&lt;br/&gt;If you set the &amp;quot;Disable the General page&amp;quot; policy (located in \User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel), you do not need to set this policy, because the &amp;quot;Disable the General page&amp;quot; policy removes the General tab from the interface.&lt;br/&gt;&lt;br/&gt;Note: The default font settings colors are ignored in cases in which the Web page author has specified the font attributes." gpmc_supported="at least Internet Explorer v5.0">Disable changing font settings</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable changing home page settings" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer" gpmc_settingDescription="Prevents users from changing the home page of the browser. The home page is the first page that appears when users start the browser.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the settings in the Home Page area on the General tab in the Internet Options dialog box appear dimmed.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can change their home page.&lt;br/&gt;&lt;br/&gt;If you set the &amp;quot;Disable the General page&amp;quot; policy (located in \User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel), you do not need to set this policy, because the &amp;quot;Disable the General page&amp;quot; policy removes the General tab from the interface.&lt;br/&gt;&lt;br/&gt;This policy is intended for administrators who want to maintain a consistent home page across their organization." gpmc_supported="at least Internet Explorer v5.0">Disable changing home page settings</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable changing language settings" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer" gpmc_settingDescription="Prevents users from changing language settings.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the Languages button on the General tab in the Internet Options dialog box appears dimmed.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can change the language settings for viewing Web sites for languages in which the character set has been installed.&lt;br/&gt;&lt;br/&gt;If you set the &amp;quot;Disable the General page&amp;quot; policy (located in \User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel), you do not need to set this policy, because the &amp;quot;Disable the General page&amp;quot; policy removes the General tab from the interface." gpmc_supported="at least Internet Explorer v5.0">Disable changing language settings</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable changing link color settings" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer" gpmc_settingDescription="Prevents users from changing the colors of links on Web pages.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the color settings for links appear dimmed. The settings are located in the Links area of the dialog box that appears when users click the General tab and then click the Colors button in the Internet Options dialog box.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can change the default color of links on Web pages.&lt;br/&gt;&lt;br/&gt;If you set the &amp;quot;Disable the General page&amp;quot; policy (located in \User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel), you do not need to set this policy, because the &amp;quot;Disable the General page&amp;quot; policy removes the General tab from the interface.&lt;br/&gt;&lt;br/&gt;Note: The default link colors are ignored on Web pages on which the author has specified link colors." gpmc_supported="at least Internet Explorer v5.0">Disable changing link color settings</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable changing Messaging settings" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer" gpmc_settingDescription="Prevents users from changing the default programs for messaging tasks.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the E-mail, Newsgroups, and Internet Call options in the Internet Programs area appear dimmed. To display these options, users open the Internet Options dialog box, and then click the Programs tab.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can determine which programs to use for sending mail, viewing newsgroups, and placing Internet calls, if programs that perform these tasks are installed.&lt;br/&gt;&lt;br/&gt;The &amp;quot;Disable the Programs page&amp;quot; policy (located in \User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel), which removes the Programs tab from Internet Explorer in Control Panel, takes precedence over this policy. If it is enabled, this policy is ignored." gpmc_supported="at least Internet Explorer v5.0">Disable changing Messaging settings</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable changing proxy settings" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer" gpmc_settingDescription="Prevents users from changing proxy settings.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the proxy settings appear dimmed. These settings are in the Proxy Server area of the Local Area Network (LAN) Settings dialog box, which appears when the user clicks the Connections tab and then clicks the LAN Settings button in the Internet Options dialog box.&lt;br/&gt;&lt;br/&gt;If you set the &amp;quot;Disable the Connections page&amp;quot; policy (located in \User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel), you do not need to set this policy, because the &amp;quot;Disable the Connections page&amp;quot; policy removes the Connections tab from the interface." gpmc_supported="at least Internet Explorer v5.0">Disable changing proxy settings</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable changing ratings settings" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer" gpmc_settingDescription="Prevents users from changing ratings that help control the type of Internet content that can be viewed.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the settings in the Content Advisor area on the Content tab in the Internet Options dialog box appear dimmed.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can change their ratings settings.&lt;br/&gt;&lt;br/&gt;The &amp;quot;Disable the Ratings page&amp;quot; policy (located in \User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel), which removes the Ratings tab from Internet Explorer in Control Panel, takes precedence over this policy. If it is enabled, this policy is ignored." gpmc_supported="at least Internet Explorer v5.0">Disable changing ratings settings</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable changing Temporary Internet files settings" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer" gpmc_settingDescription="Prevents users from changing the browser cache settings, such as the location and amount of disk space to use for the Temporary Internet Files folder.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the browser cache settings appear dimmed. These settings are found in the dialog box that appears when users click the General tab and then click the Settings button in the Internet Options dialog box.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can change their cache settings.&lt;br/&gt;&lt;br/&gt;If you set the &amp;quot;Disable the General page&amp;quot; policy (located in \User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel), you do not need to set this policy, because the &amp;quot;Disable the General page&amp;quot; policy removes the General tab from the interface." gpmc_supported="at least Internet Explorer v5.0">Disable changing Temporary Internet files settings</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable external branding of Internet Explorer" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer" gpmc_settingDescription="Prevents branding of Internet programs, such as customization of Internet Explorer and Outlook Express logos and title bars, by another party.&lt;br/&gt;&lt;br/&gt;If you enable this policy, it prevents customization of the browser by another party, such as an Internet service provider or Internet content provider.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users could install customizations from another party-for example, when signing up for Internet services.&lt;br/&gt;&lt;br/&gt;This policy is intended for administrators who want to maintain a consistent browser across an organization." gpmc_supported="at least Internet Explorer v5.0">Disable external branding of Internet Explorer</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable Internet Connection wizard" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer" gpmc_settingDescription="Prevents users from running the Internet Connection Wizard.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the Setup button on the Connections tab in the Internet Options dialog box appears dimmed.&lt;br/&gt;&lt;br/&gt;Users will also be prevented from running the wizard by clicking the Connect to the Internet icon on the desktop or by clicking Start, pointing to Programs, pointing to Accessories, pointing to Communications, and then clicking Internet Connection Wizard.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can change their connection settings by running the Internet Connection Wizard.&lt;br/&gt;&lt;br/&gt;Note: This policy overlaps with the &amp;quot;Disable the Connections page&amp;quot; policy (located in \User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel), which removes the Connections tab from the interface. Removing the Connections tab from the interface, however, does not prevent users from running the Internet Connection Wizard from the desktop or the Start menu." gpmc_supported="at least Internet Explorer v5.0">Disable Internet Connection wizard</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable the Reset Web Settings feature" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer" gpmc_settingDescription="Prevents users from restoring default settings for home and search pages.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the Reset Web Settings button on the Programs tab in the Internet Options dialog box appears dimmed.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can restore the default settings for home and search pages.&lt;br/&gt;&lt;br/&gt;The &amp;quot;Disable the Programs page&amp;quot; policy (located in \User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel), which removes the Programs tab from Internet Explorer in Control Panel, takes precedence over this policy. If it is enabled, this policy is ignored." gpmc_supported="at least Internet Explorer v5.0">Disable the Reset Web Settings feature</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Display error message on proxy script download failure" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer" gpmc_settingDescription="Specifies that error messages will be displayed to users if problems occur with proxy scripts.&lt;br/&gt;&lt;br/&gt;If you enable this policy, error messages will be displayed when the browser does not download or run a script to set proxy settings.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, error messages will not be displayed when problems occur with proxy scripts." gpmc_supported="at least Internet Explorer v5.0">Display error message on proxy script download failure</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Do not allow AutoComplete to save passwords" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer" gpmc_settingDescription="Disables automatic completion of user names and passwords in forms on Web pages, and prevents users from being prompted to save passwords.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the User Names and Passwords on Forms and Prompt Me to Save Passwords check boxes appear dimmed. To display these check boxes, users open the Internet Options dialog box, click the Content tab, and then click the AutoComplete button.&lt;br/&gt;&lt;br/&gt;If you disable this policy or don't configure it, users can determine whether Internet Explorer automatically completes user names and passwords on forms and prompts them to save passwords.&lt;br/&gt;&lt;br/&gt;The &amp;quot;Disable the Content page&amp;quot; policy (located in \User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel), which removes the Content tab from Internet Explorer in Control Panel, takes precedence over this policy. If it is enabled, this policy is ignored." gpmc_supported="at least Internet Explorer v5.0">Do not allow AutoComplete to save passwords</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Do not allow users to enable or disable add-ons" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer" gpmc_settingDescription="This policy setting allows you to manage whether users have the ability to allow or deny add-ons through Add-On Manager.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, users cannot enable or disable add-ons through Add-On Manager. The only exception occurs if an add-on has been specifically entered into the 'Add-On List' policy setting in such a way as to allow users to continue to manage the add-on. In this case, the user can still manage the add-on through the Add-On Manager.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this policy setting, the appropriate controls in the Add-On Manager will be available to the user." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Do not allow users to enable or disable add-ons</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Identity Manager: Prevent users from using Identities" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer" gpmc_settingDescription="Prevents users from configuring unique identities by using Identity Manager.&lt;br/&gt;&lt;br/&gt;Identity Manager enables users to create multiple accounts, such as e-mail accounts, on the same computer. Each user has a unique identity, with a different password and different program preferences.&lt;br/&gt;&lt;br/&gt;If you enable this policy, users will not be able to create new identities, manage existing identities, or switch identities. The Switch Identity option will be removed from the File menu in Address Book.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can set up and change identities." gpmc_supported="at least Internet Explorer v5.0">Identity Manager: Prevent users from using Identities</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Search: Disable Search Customization" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer" gpmc_settingDescription="Makes the Customize button in the Search Assistant appear dimmed.&lt;br/&gt;&lt;br/&gt;The Search Assistant is a tool that appears in the Search bar to help users search the Internet.&lt;br/&gt;&lt;br/&gt;If you enable this policy, users cannot change their Search Assistant settings, such as setting default search engines for specific tasks.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can change their settings for the Search Assistant.&lt;br/&gt;&lt;br/&gt;This policy is designed to help administrators maintain consistent settings for searching across an organization." gpmc_supported="at least Internet Explorer v5.0">Search: Disable Search Customization</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Turn off Crash Detection" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer" gpmc_settingDescription="This policy setting allows you to manage the crash detection feature of add-on Management.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, a crash in Internet Explorer will exhibit behavior found in Windows XP Professional Service Pack 1 and earlier, namely to invoke Windows Error Reporting. All policy settings for Windows Error Reporting continue to apply.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this policy setting, the crash detection feature for add-on management will be functional." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Turn off Crash Detection</a></td><td>Enabled</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Windows Components/Internet Explorer/Browser menus</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable Save this program to disk option" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Browser menus" gpmc_settingDescription="Prevents users from saving a program or file that Microsoft Internet Explorer has downloaded to the hard disk.&lt;br/&gt;&lt;br/&gt;If you enable this policy, users cannot save a program to disk by clicking the Save This Program to Disk command while attempting to download a file. The file will not be downloaded and users will be informed that the command is not available.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can download programs from their browsers." gpmc_supported="at least Internet Explorer v5.0">Disable Save this program to disk option</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="File menu: Disable New menu option" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Browser menus" gpmc_settingDescription="Prevents users from opening a new browser window from the File menu.&lt;br/&gt;&lt;br/&gt;If this policy is enabled, users cannot open a new browser window by clicking the File menu, pointing to the New menu, and then clicking Window. The user interface is not changed, but a new window will not be opened, and users will be informed that the command is not available.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can open a new browser window from the File menu.&lt;br/&gt;&lt;br/&gt;Caution: This policy does not prevent users from opening a new browser window by right-clicking, and then clicking the Open in New Window command. To prevent users from using the shortcut menu to open new browser windows, you should also set the &amp;quot;Disable Open in New Window menu option&amp;quot; policy, which disables this command on the shortcut menu, or the &amp;quot;Disable context menu&amp;quot; policy, which disables the entire shortcut menu." gpmc_supported="at least Internet Explorer v5.0">File menu: Disable New menu option</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="File menu: Disable Open menu option" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Browser menus" gpmc_settingDescription="Prevents users from opening a file or Web page from the File menu in Internet Explorer.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the Open dialog box will not appear when users click the Open command on the File menu. If users click the Open command, they will be notified that the command is not available.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can open a Web page from the browser File menu.&lt;br/&gt;&lt;br/&gt;Caution: This policy does not prevent users from right-clicking a link on a Web page, and then clicking the Open or Open in New Window command. To prevent users from opening Web pages by using the shortcut menu, set the &amp;quot;Disable Open in New Window menu option&amp;quot; policy, which disables this command on the shortcut menu, or the &amp;quot;Disable context menu&amp;quot; policy, which disables the entire shortcut menu." gpmc_supported="at least Internet Explorer v5.0">File menu: Disable Open menu option</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="File menu: Disable Save As Web Page Complete" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Browser menus" gpmc_settingDescription="Prevents users from saving the complete contents that are displayed on or run from a Web page, including the graphics, scripts, linked files, and other elements. It does not prevent users from saving the text of a Web page.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the Web Page, Complete file type option will be removed from the Save as Type box in the Save Web Page dialog box. Users can still save Web pages as hypertext markup language (HTML) files or as text files, but graphics, scripts, and other elements are not saved. To display the Save Web Page dialog box, users click the File menu, and then click the Save As command.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can save all elements on a Web page.&lt;br/&gt;&lt;br/&gt;The &amp;quot;File menu: Disable Save As... menu option&amp;quot; policy, which removes the Save As command, takes precedence over this policy. If it is enabled, this policy is ignored." gpmc_supported="at least Internet Explorer v5.0">File menu: Disable Save As Web Page Complete</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="File menu: Disable Save As... menu option" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Browser menus" gpmc_settingDescription="Prevents users from saving Web pages from the browser File menu to their hard disk or to a network share.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the Save As command on the File menu will be removed.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can save Web pages for later viewing.&lt;br/&gt;&lt;br/&gt;This policy takes precedence over the &amp;quot;File Menu: Disable Save As Web Page Complete&amp;quot; policy, which prevents users from saving the entire contents that are displayed or run from a Web Page, such as graphics, scripts, and linked files, but does not prevent users from saving the text of a Web page.&lt;br/&gt;&lt;br/&gt;Caution: If you enable this policy, users are not prevented from saving Web content by pointing to a link on a Web page, clicking the right mouse button, and then clicking Save Target As." gpmc_supported="at least Internet Explorer v5.0">File menu: Disable Save As... menu option</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Help menu: Remove 'For Netscape Users' menu option" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Browser menus" gpmc_settingDescription="Prevents users from displaying tips for users who are switching from Netscape.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the For Netscape Users command is removed from the Help menu.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can display content about switching from Netscape by clicking the For Netscape Users command on the Help menu.&lt;br/&gt;&lt;br/&gt;Caution: Enabling this policy does not remove the tips for Netscape users from the Microsoft Internet Explorer Help file." gpmc_supported="at least Internet Explorer v5.0">Help menu: Remove 'For Netscape Users' menu option</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Help menu: Remove 'Send Feedback' menu option" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Browser menus" gpmc_settingDescription="Prevents users from sending feedback to Microsoft by clicking the Send Feedback command on the Help menu.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the Send Feedback command is removed from the Help menu.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can fill out an Internet form to provide feedback about Microsoft products." gpmc_supported="at least Internet Explorer v5.0">Help menu: Remove 'Send Feedback' menu option</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Help menu: Remove 'Tip of the Day' menu option" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Browser menus" gpmc_settingDescription="Prevents users from viewing or changing the Tip of the Day interface in Microsoft Internet Explorer.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the Tip of the Day command is removed from the Help menu.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can enable or disable the Tip of the Day, which appears at the bottom of the browser." gpmc_supported="at least Internet Explorer v5.0">Help menu: Remove 'Tip of the Day' menu option</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Help menu: Remove 'Tour' menu option" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Browser menus" gpmc_settingDescription="Prevents users from running the Internet Explorer Tour from the Help menu in Internet Explorer.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the Tour command is removed from the Help menu.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can run the tour from the Help menu." gpmc_supported="">Help menu: Remove 'Tour' menu option</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Tools menu: Disable Internet Options... menu option" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Browser menus" gpmc_settingDescription="Prevents users from opening the Internet Options dialog box from the Tools menu in Microsoft Internet Explorer.&lt;br/&gt;&lt;br/&gt;If you enable this policy, users cannot change their Internet options, such as default home page, cache size, and connection and proxy settings, from the browser Tools menu. When users click the Internet Options command on the Tools menu, they are informed that the command is unavailable.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can change their Internet settings from the browser Tools menu.&lt;br/&gt;&lt;br/&gt;Caution: This policy does not prevent users from viewing and changing Internet settings by clicking the Internet Options icon in Windows Control Panel.&lt;br/&gt;&lt;br/&gt;Also, see policies for Internet options in the \Administrative Templates\Windows Components\Internet Explorer and in \Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel folders." gpmc_supported="at least Internet Explorer v5.0">Tools menu: Disable Internet Options... menu option</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="View menu: Disable Full Screen menu option" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Browser menus" gpmc_settingDescription="Prevents users from displaying the browser in full-screen (kiosk) mode, without the standard toolbar.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the Full Screen command on the View menu will appear dimmed, and pressing F11 will not display the browser in a full screen.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can display the browser in a full screen.&lt;br/&gt;&lt;br/&gt;This policy is intended to prevent users from displaying the browser without toolbars, which might be confusing for some beginning users." gpmc_supported="at least Internet Explorer v5.0">View menu: Disable Full Screen menu option</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="View menu: Disable Source menu option" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Browser menus" gpmc_settingDescription="Prevents users from viewing the HTML source of Web pages by clicking the Source command on the View menu.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the Source command on the View menu will appear dimmed.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, then users can view the HTML source of Web pages from the browser View menu.&lt;br/&gt;&lt;br/&gt;Caution: This policy does not prevent users from viewing the HTML source of a Web page by right-clicking a Web page to open the shortcut menu, and then clicking View Source. To prevent users from viewing the HTML source of a Web page from the shortcut menu, set the &amp;quot;Disable context menu&amp;quot; policy, which disables the entire shortcut menu." gpmc_supported="at least Internet Explorer v5.0">View menu: Disable Source menu option</a></td><td>Enabled</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Windows Components/Internet Explorer/Internet Control Panel</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable the Advanced page" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel" gpmc_settingDescription="Removes the Advanced tab from the interface in the Internet Options dialog box.&lt;br/&gt;&lt;br/&gt;If you enable this policy, users are prevented from seeing and changing advanced Internet settings, such as security, multimedia, and printing.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can see and change these settings.&lt;br/&gt;&lt;br/&gt;When you set this policy, you do not need to set the &amp;quot;Disable changing Advanced page settings&amp;quot; policy (located in \User Configuration\Administrative Templates\Windows Components\Internet Explorer\), because this policy removes the Advanced tab from the interface." gpmc_supported="at least Internet Explorer v5.0">Disable the Advanced page</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable the Connections page" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel" gpmc_settingDescription="Removes the Connections tab from the interface in the Internet Options dialog box.&lt;br/&gt;&lt;br/&gt;If you enable this policy, users are prevented from seeing and changing connection and proxy settings.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can see and change these settings.&lt;br/&gt;&lt;br/&gt;When you set this policy, you do not need to set the following policies for the Content tab, because this policy removes the Connections tab from the interface:&lt;br/&gt;&lt;br/&gt;&amp;quot;Disable Internet Connection Wizard&amp;quot;&lt;br/&gt;&lt;br/&gt;&amp;quot;Disable changing connection settings&amp;quot;&lt;br/&gt;&lt;br/&gt;&amp;quot;Disable changing proxy settings&amp;quot;&lt;br/&gt;&lt;br/&gt;&amp;quot;Disable changing Automatic Configuration settings&amp;quot;" gpmc_supported="at least Internet Explorer v5.0">Disable the Connections page</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable the Content page" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel" gpmc_settingDescription="Removes the Content tab from the interface in the Internet Options dialog box.&lt;br/&gt;&lt;br/&gt;If you enable this policy, users are prevented from seeing and changing ratings, certificates, AutoComplete, Wallet, and Profile Assistant settings.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can see and change these settings.&lt;br/&gt;&lt;br/&gt;When you set this policy, you do not need to set the following policies for the Content tab, because this policy removes the Content tab from the interface:&lt;br/&gt;&lt;br/&gt;&amp;quot;Disable changing ratings settings&amp;quot;&lt;br/&gt;&lt;br/&gt;&amp;quot;Disable changing certificate settings&amp;quot;&lt;br/&gt;&lt;br/&gt;&amp;quot;Disable changing Profile Assistant settings&amp;quot;&lt;br/&gt;&lt;br/&gt;&amp;quot;Disable AutoComplete for forms&amp;quot;&lt;br/&gt;&lt;br/&gt;&amp;quot;Do not allow AutoComplete to save passwords&amp;quot;" gpmc_supported="at least Internet Explorer v5.0">Disable the Content page</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable the General page" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel" gpmc_settingDescription="Removes the General tab from the interface in the Internet Options dialog box.&lt;br/&gt;&lt;br/&gt;If you enable this policy, users are unable to see and change settings for the home page, the cache, history, Web page appearance, and accessibility.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can see and change these settings.&lt;br/&gt;&lt;br/&gt;When you set this policy, you do not need to set the following Internet Explorer policies (located in \User Configuration\Administrative Templates\Windows Components\Internet Explorer\), because this policy removes the General tab from the interface:&lt;br/&gt;&lt;br/&gt;&amp;quot;Disable changing home page settings&amp;quot;&lt;br/&gt;&lt;br/&gt;&amp;quot;Disable changing Temporary Internet files settings&amp;quot;&lt;br/&gt;&lt;br/&gt;&amp;quot;Disable changing history settings&amp;quot;&lt;br/&gt;&lt;br/&gt;&amp;quot;Disable changing color settings&amp;quot;&lt;br/&gt;&lt;br/&gt;&amp;quot;Disable changing link color settings&amp;quot;&lt;br/&gt;&lt;br/&gt;&amp;quot;Disable changing font settings&amp;quot;&lt;br/&gt;&lt;br/&gt;&amp;quot;Disable changing language settings&amp;quot;&lt;br/&gt;&lt;br/&gt;&amp;quot;Disable changing accessibility settings&amp;quot;" gpmc_supported="at least Internet Explorer v5.0">Disable the General page</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable the Privacy page" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel" gpmc_settingDescription="Removes the Privacy tab from the interface in the Internet Options dialog box.&lt;br/&gt;&lt;br/&gt;If you enable this policy, users are prevented from seeing and changing default settings for privacy.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can see and change these settings." gpmc_supported="at least Internet Explorer v5.0">Disable the Privacy page</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable the Programs page" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel" gpmc_settingDescription="Removes the Programs tab from the interface in the Internet Options dialog box.&lt;br/&gt;&lt;br/&gt;If you enable this policy, users are prevented from seeing and changing default settings for Internet programs.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can see and change these settings.&lt;br/&gt;&lt;br/&gt;When you set this policy, you do not need to set the following policies for the Programs tab, because this policy removes the Programs tab from the interface:&lt;br/&gt;&lt;br/&gt;&amp;quot;Disable changing Messaging settings&amp;quot;&lt;br/&gt;&lt;br/&gt;&amp;quot;Disable changing Calendar and Contact settings&amp;quot;&lt;br/&gt;&lt;br/&gt;&amp;quot;Disable the Reset Web Settings feature&amp;quot;&lt;br/&gt;&lt;br/&gt;&amp;quot;Disable changing default browser check&amp;quot;" gpmc_supported="at least Internet Explorer v5.0">Disable the Programs page</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable the Security page" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel" gpmc_settingDescription="Removes the Security tab from the interface in the Internet Options dialog box.&lt;br/&gt;&lt;br/&gt;If you enable this policy, it prevents users from seeing and changing settings for security zones, such as scripting, downloads, and user authentication.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can see and change these settings.&lt;br/&gt;&lt;br/&gt;When you set this policy, you do not need to set the following Internet Explorer policies, because this policy removes the Security tab from the interface:&lt;br/&gt;&lt;br/&gt;&amp;quot;Security zones: Do not allow users to change policies&amp;quot;&lt;br/&gt;&lt;br/&gt;&amp;quot;Security zones: Do not allow users to add/delete sites&amp;quot;" gpmc_supported="at least Internet Explorer v5.0">Disable the Security page</a></td><td>Enabled</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Windows Components/Internet Explorer/Internet Control Panel/Advanced Page</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Allow active content from CDs to run on user machines" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Advanced Page" gpmc_settingDescription="This policy setting allows you to manage whether users receive a dialog requesting permission for active content on a CD to run.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, active content on a CD will run without a prompt.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, active content on a CD will always prompt before running.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy, users can choose whether to be prompted before running active content on a CD." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Allow active content from CDs to run on user machines</a></td><td>Disabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Allow Install On Demand (except Internet Explorer)" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Advanced Page" gpmc_settingDescription="This policy setting allows you to manage whether users can download and install self-installing program files (non-Internet Explorer components) that are registered with Internet Explorer (such as Windows Media Player, Macromedia, and Java) that are required in order to view web pages as intended.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, non-Internet Explorer components will be automatically installed as necessary.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, users will be prompted when non-Internet Explorer components would be installed.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, non-Internet Explorer components will be automatically installed as necessary." gpmc_supported="at least Internet Explorer v6.0 in Windows 2003 Service Pack 1">Allow Install On Demand (except Internet Explorer)</a></td><td>Disabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Allow software to run or install even if the signature is invalid" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Advanced Page" gpmc_settingDescription="This policy setting allows you to manage whether software, such as ActiveX controls and file downloads, can be installed or run by the user even though the signature is invalid. An invalid signature might indicate that someone has tampered with the file.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, users will be prompted to install or run files with an invalid signature.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, users cannot run or install files with an invalid signature.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy, users can choose to run or install files with an invalid signature." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Allow software to run or install even if the signature is invalid</a></td><td>Disabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Allow third-party browser extensions" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Advanced Page" gpmc_settingDescription="This policy setting allows you to manage whether Internet Explorer will launch COM add-ons known as browser helper objects, such as toolbars. Browser helper objects may contain flaws such as buffer overruns which impact Internet Explorer s performance or stability.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, Internet Explorer automatically launches any browser helper objects that are installed on the user's computer.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, browser helper objects do not launch.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy, Internet Explorer automatically launches any browser helper objects that are installed on the user's computer." gpmc_supported="at least Internet Explorer v6.0 in Windows 2003 Service Pack 1">Allow third-party browser extensions</a></td><td>Disabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Automatically check for Internet Explorer updates" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Advanced Page" gpmc_settingDescription="This policy setting allows you to manage whether Internet Explorer checks the Internet for newer versions. When Internet Explorer is set to do this, the checks occur approximately every 30 days, and users are prompted to install new versions as they become available.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, Internet Explorer checks the Internet for a new version approximately every 30 days and prompts the user to download new versions when they are available.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, Internet Explorer does not check the Internet for new versions of the browser, so does not prompt users to install them.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, Internet Explorer does not check the Internet for new versions of the browser, so does not prompt users to install them." gpmc_supported="at least Internet Explorer v6.0 in Windows 2003 Service Pack 1">Automatically check for Internet Explorer updates</a></td><td>Disabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Empty Temporary Internet Files folder when browser is closed" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Advanced Page" gpmc_settingDescription="This policy setting allows you to manage whether Internet Explorer deletes the contents of the Temporary Internet Files folder after all browser windows are closed. This protects against storing dangerous files on the computer, or storing sensitive files that other users could see, in addition to managing total disk space usage.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, Internet Explorer will delete the contents of the user's Temporary Internet Files folder when all browser windows are closed.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, Internet Explorer will not delete the contents of the user's Temporary Internet Files folder when browser windows are closed.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy, Internet Explorer will not delete the contents of the Temporary Internet Files folder when browser windows are closed." gpmc_supported="at least Internet Explorer v6.0 in Windows 2003 Service Pack 1">Empty Temporary Internet Files folder when browser is closed</a></td><td>Enabled</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Windows Components/Internet Explorer/Internet Control Panel/Security Page</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Intranet Sites: Include all local (intranet) sites not listed in other zones" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page" gpmc_settingDescription="This policy setting controls whether local sites which are not explicitly mapped into any Security Zone are forced into the local Intranet security zone.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, local sites which are not explicitly mapped into a zone are considered to be in the Intranet Zone.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, local sites which are not explicitly mapped into a zone will not be considered to be in the Intranet Zone (so would typically be in the Internet Zone).&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, users choose whether to force local sites into the Intranet Zone." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Intranet Sites: Include all local (intranet) sites not listed in other zones</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Intranet Sites: Include all sites that bypass the proxy server" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page" gpmc_settingDescription="This policy setting controls whether sites which bypass the proxy server are mapped into the local Intranet security zone.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, sites which bypass the proxy server are mapped into the Intranet Zone.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, sites which bypass the proxy server aren't necessarily mapped into the Intranet Zone (other rules might map one there).&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, users choose whether sites which bypass the proxy server are mapped into the Intranet Zone." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Intranet Sites: Include all sites that bypass the proxy server</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Intranet Zone Template" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page" gpmc_settingDescription="This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.&lt;br/&gt;&lt;br/&gt;If you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults. &lt;br/&gt;&lt;br/&gt;If you disable this template policy setting, no security level is configured.&lt;br/&gt;&lt;br/&gt;If you do not configure this template policy setting, no security level is configured.&lt;br/&gt;&lt;br/&gt;Note. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.&lt;br/&gt;&lt;br/&gt;Note. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Intranet Zone Template</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Intranet</td><td>Medium</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Locked-Down Restricted Sites Zone Template" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page" gpmc_settingDescription="This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.&lt;br/&gt;&lt;br/&gt;If you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults. &lt;br/&gt;&lt;br/&gt;If you disable this template policy setting, no security level is configured.&lt;br/&gt;&lt;br/&gt;If you do not configure this template policy setting, no security level is configured.&lt;br/&gt;&lt;br/&gt;Note. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.&lt;br/&gt;&lt;br/&gt;Note. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Locked-Down Restricted Sites Zone Template</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Locked-Down Restricted Sites</td><td>High</td></tr> </table></td></tr></table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Windows Components/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Logon options" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Internet Zone" gpmc_settingDescription="This policy setting allows you to manage settings for logon options.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, you can choose from the following logon options.&lt;br/&gt;&lt;br/&gt;Anonymous logon to disable HTTP authentication and use the guest account only for the Common Internet File System (CIFS) protocol.&lt;br/&gt;&lt;br/&gt;Prompt for user name and password to query users for user IDs and passwords. After a user is queried, these values can be used silently for the remainder of the session.&lt;br/&gt;&lt;br/&gt;Automatic logon only in Intranet zone to query users for user IDs and passwords in other zones. After a user is queried, these values can be used silently for the remainder of the session.&lt;br/&gt;&lt;br/&gt;Automatic logon with current user name and password to attempt logon using Windows NT Challenge Response (also known as NTLM authentication). If Windows NT Challenge Response is supported by the server, the logon uses the user's network user name and password for logon. If Windows NT Challenge Response is not supported by the server, the user is queried to provide the user name and password.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, logon is set to Automatic logon only in Intranet zone.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, logon is set to Automatic logon only in Intranet zone." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Logon options</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Logon options</td><td>Automatic logon with current username and password</td></tr> </table></td></tr></table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Access data sources across domains" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Access data sources across domains</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Access data sources across domains</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Allow active content over restricted protocols to access my computer" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage whether a resource hosted on an admin-restricted protocol in the Intranet Zone can run active content such as script, ActiveX, Java and Binary Behaviors. The list of restricted protocols may be set in the Intranet Zone Restricted Protocols section under Network Protocol Lockdown policy.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, no Intranet Zone content accessed is affected, even for protocols on the restricted list. If you select Prompt from the drop-down box, the Information Bar will appear to allow control over questionable content accessed over any restricted protocols; content over other protocols is unaffected.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, all attempts to access such content over the restricted protocols is blocked.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, the Information Bar will appear to allow control over questionable content accessed over any restricted protocols when the Network Protocol Lockdown security feature is enabled." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Allow active content over restricted protocols to access my computer</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Allow active content over restricted protocols to access my computer</td><td>Prompt</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Allow active scripting" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage whether script code on pages in the zone is run.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, script code on pages in the zone can run automatically. If you select Prompt in the drop-down box, users are queried to choose whether to allow script code on pages in the zone to run.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, script code on pages in the zone is prevented from running.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, script code on pages in the zone can run automatically." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Allow active scripting</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Allow active scripting</td><td>Enable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Allow binary and script behaviors" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage dynamic binary and script behaviors: components that encapsulate specific functionality for HTML elements to which they were attached.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, binary and script behaviors are available. If you select Administrator approved in the drop-down box, only behaviors listed in the Admin-approved Behaviors under Binary Behaviors Security Restriction policy are available.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, binary and script behaviors are not available unless applications have implemented a custom security manager.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, binary and script behaviors are available." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Allow binary and script behaviors</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Allow Binary and Script Behaviors</td><td>Enable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Allow drag and drop or copy and paste files" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage whether users can drag files or copy and paste files from a source within the zone.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, users can drag files or copy and paste files from this zone automatically. If you select Prompt in the drop-down box, users are queried to choose whether to drag or copy files from this zone.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, users are prevented from dragging files or copying and pasting files from this zone.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, users can drag files or copy and paste files from this zone automatically." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Allow drag and drop or copy and paste files</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Allow drag and drop or copy and paste files</td><td>Enable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Allow file downloads" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage whether file downloads are permitted from the zone. This option is determined by the zone of the page with the link causing the download, not the zone from which the file is delivered.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, files can be downloaded from the zone.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, files are prevented from being downloaded from the zone.&lt;br/&gt;&lt;br/&gt; If you do not configure this policy setting, files can be downloaded from the zone." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Allow file downloads</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Allow file downloads</td><td>Enable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Allow font downloads" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage whether pages of the zone may download HTML fonts.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, HTML fonts are prevented from downloading.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, HTML fonts can be downloaded automatically." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Allow font downloads</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Allow font downloads</td><td>Enable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Allow installation of desktop items" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage whether users can install Active Desktop items from this zone. The settings for this option are: If you enable this policy setting, users can install desktop items from this zone automatically.&lt;br/&gt;&lt;br/&gt;If you select Prompt in the drop-down box, users are queried to choose whether to install desktop items from this zone.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, users are prevented from installing desktop items from this zone. &lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, users are queried to choose whether to install desktop items from this zone." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Allow installation of desktop items</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Allow installation of desktop items</td><td>Prompt</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Allow META REFRESH" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage whether a user's browser can be redirected to another Web page if the author of the Web page uses the Meta Refresh setting (tag) to redirect browsers to another Web page. &lt;br/&gt;&lt;br/&gt;If you enable this policy setting, a user's browser that loads a page containing an active Meta Refresh setting can be redirected to another Web page.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, a user's browser that loads a page containing an active Meta Refresh setting cannot be redirected to another Web page.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, a user's browser that loads a page containing an active Meta Refresh setting can be redirected to another Web page." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Allow META REFRESH</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Allow META REFRESH</td><td>Enable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Allow paste operations via script" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage whether scripts can perform a clipboard operation (for example, cut, copy, and paste) in a specified region.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, a script can perform a clipboard operation.&lt;br/&gt;&lt;br/&gt;If you select Prompt in the drop-down box, users are queried as to whether to perform clipboard operations.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, a script cannot perform a clipboard operation.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, a script can perform a clipboard operation." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Allow paste operations via script</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Allow paste operations via script</td><td>Enable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Allow script-initiated windows without size or position constraints" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage restrictions on script-initiated pop-up windows and windows that include the title and status bars.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, Windows Restrictions security will not apply in this zone. The security zone runs without the added layer of security provided by this feature.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, the possible harmful actions contained in script-initiated pop-up windows and windows that include the title and status bars cannot be run. This Internet Explorer security feature will be on in this zone as dictated by the Scripted Windows Security Restrictions feature control setting for the process.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, Windows Restrictions security will not apply in this zone. The security zone runs without the added layer of security provided by this feature." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Allow script-initiated windows without size or position constraints</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Allow script-initiated windows without size or position constraints</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Automatic prompting for ActiveX controls" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting manages whether users will be automatically prompted for ActiveX control installations.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, ActiveX control installations will be blocked using the Information Bar. Users can click on the Information Bar to allow the ActiveX control prompt.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Automatic prompting for ActiveX controls</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Automatic prompting for ActiveX controls</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Automatic prompting for file downloads" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.&lt;br/&gt;&lt;br/&gt;If you enable this setting, users will receive a file download dialog for automatic download attempts.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, users will receive a file download dialog for automatic download attempts." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Automatic prompting for file downloads</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Automatic prompting for file downloads</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Display mixed content" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage whether users can display nonsecure items and manage whether users receive a security information message to display pages containing both secure and nonsecure items.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, and the drop-down box is set to Enable, the user does not receive a security information message (This page contains both secure and nonsecure items. Do you want to display the nonsecure items?) and nonsecure content can be displayed.&lt;br/&gt;&lt;br/&gt;If the drop-down box is set to Prompt, the user will receive the security information message on the Web pages that contain both secure (https://) and nonsecure (http://) content.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, users cannot receive the security information message and nonsecure content cannot be displayed.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, the user will receive the security information message on the Web pages that contain both secure (https://) and nonsecure (http://) content." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Display mixed content</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Display mixed content</td><td>Prompt</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Do not prompt for client certificate selection when no certificates or only one certificate exists." gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage whether users are prompted to select a certificate when no certificate or only one certificate exists.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, Internet Explorer does not prompt users with a &amp;quot;Client Authentication&amp;quot; message when they connect to a Web site that has no certificate or only one certificate.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, Internet Explorer prompts users with a &amp;quot;Client Authentication&amp;quot; message when they connect to a Web site that has no certificate or only one certificate.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, Internet Explorer does not prompt users with a &amp;quot;Client Authentication&amp;quot; message when they connect to a Web site that has no certificate or only one certificate." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Do not prompt for client certificate selection when no certificates or only one certificate exists.</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Do not prompt for client certificate selection when no certificates or only one certificate exists.</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Download signed ActiveX controls" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage whether users may download signed ActiveX controls from a page in the zone.&lt;br/&gt;&lt;br/&gt;If you enable this policy, users can download signed controls without user intervention. If you select Prompt in the drop-down box, users are queried whether to download controls signed by publishers who aren't trusted. Code signed by trusted publishers is silently downloaded.&lt;br/&gt;&lt;br/&gt;If you disable the policy setting, signed controls cannot be downloaded.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, users are queried whether to download controls signed by publishers who aren't trusted. Code signed by trusted publishers is silently downloaded." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Download signed ActiveX controls</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Download signed ActiveX controls</td><td>Prompt</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Download unsigned ActiveX controls" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage whether users may download unsigned ActiveX controls from the zone. Such code is potentially harmful, especially when coming from an untrusted zone.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, users can run unsigned controls without user intervention. If you select Prompt in the drop-down box, users are queried to choose whether to allow the unsigned control to run.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, users cannot run unsigned controls.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, users cannot run unsigned controls." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Download unsigned ActiveX controls</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Download unsigned ActiveX controls</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Initialize and script ActiveX controls not marked as safe" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage ActiveX controls not marked as safe.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Initialize and script ActiveX controls not marked as safe</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Initialize and script ActiveX controls not marked as safe</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Java permissions" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage permissions for Java applets.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.&lt;br/&gt;&lt;br/&gt;Low Safety enables applets to perform all operations.&lt;br/&gt;&lt;br/&gt;Medium Safety enables applets to run in their sandbox (an area in memory outside of which the program cannot make calls), plus capabilities like scratch space (a safe and secure storage area on the client computer) and user-controlled file I/O.&lt;br/&gt;&lt;br/&gt;High Safety enables applets to run in their sandbox. Disable Java to prevent any applets from running.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, Java applets cannot run.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, the permission is set to Medium Safety." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Java permissions</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Java permissions</td><td>High safety</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Launching applications and files in an IFRAME" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage whether applications may be run and files may be downloaded from an IFRAME reference in the HTML of the pages in this zone. &lt;br/&gt;&lt;br/&gt;If you enable this policy setting, users can run applications and download files from IFRAMEs on the pages in this zone without user intervention. If you select Prompt in the drop-down box, users are queried to choose whether to run applications and download files from IFRAMEs on the pages in this zone.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, users are prevented from running applications and downloading files from IFRAMEs on the pages in this zone.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, users are queried to choose whether to run applications and download files from IFRAMEs on the pages in this zone." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Launching applications and files in an IFRAME</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Launching applications and files in an IFRAME</td><td>Prompt</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Logon options" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage settings for logon options.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, you can choose from the following logon options.&lt;br/&gt;&lt;br/&gt;Anonymous logon to disable HTTP authentication and use the guest account only for the Common Internet File System (CIFS) protocol.&lt;br/&gt;&lt;br/&gt;Prompt for user name and password to query users for user IDs and passwords. After a user is queried, these values can be used silently for the remainder of the session.&lt;br/&gt;&lt;br/&gt;Automatic logon only in Intranet zone to query users for user IDs and passwords in other zones. After a user is queried, these values can be used silently for the remainder of the session.&lt;br/&gt;&lt;br/&gt;Automatic logon with current user name and password to attempt logon using Windows NT Challenge Response (also known as NTLM authentication). If Windows NT Challenge Response is supported by the server, the logon uses the user's network user name and password for logon. If Windows NT Challenge Response is not supported by the server, the user is queried to provide the user name and password.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, logon is set to Automatic logon only in Intranet zone.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, logon is set to Automatic logon only in Intranet zone." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Logon options</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Logon options</td><td>Automatic logon only in Intranet zone</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Navigate sub-frames across different domains" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage the opening of sub-frames and access of applications across different domains.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, users can open sub-frames from other domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow sub-frames or access to applications from other domains.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, users cannot open sub-frames or access applications from different domains.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, users can open sub-frames from other domains and access applications from other domains." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Navigate sub-frames across different domains</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Navigate sub-frames across different domains</td><td>Enable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Open files based on content, not file extension" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage MIME sniffing for file promotion from one type to another based on a MIME sniff. A MIME sniff is the recognition by Internet Explorer of the file type based on a bit signature.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, the MIME Sniffing Safety Feature will not apply in this zone. The security zone will run without the added layer of security provided by this feature.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, the actions that may be harmful cannot run; this Internet Explorer security feature will be turned on in this zone, as dictated by the feature control setting for the process.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, the MIME Sniffing Safety Feature will not apply in this zone." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Open files based on content, not file extension</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Open files based on content, not file extension</td><td>Enable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Run .NET Framework-reliant components not signed with Authenticode" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, Internet Explorer will not execute unsigned managed components.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, Internet Explorer will execute unsigned managed components." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Run .NET Framework-reliant components not signed with Authenticode</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Run .NET Framework-reliant components not signed with Authenticode</td><td>Enable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Run .NET Framework-reliant components signed with Authenticode" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage whether .NET Framework components that are signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, Internet Explorer will execute signed managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute signed managed components.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, Internet Explorer will not execute signed managed components.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, Internet Explorer will execute signed managed components." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Run .NET Framework-reliant components signed with Authenticode</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Run .NET Framework-reliant components signed with Authenticode</td><td>Enable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Run ActiveX controls and plugins" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage whether ActiveX controls and plug-ins can be run on pages from the specified zone.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, controls and plug-ins can run without user intervention.&lt;br/&gt;&lt;br/&gt;If you selected Prompt in the drop-down box, users are asked to choose whether to allow the controls or plug-in to run.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, controls and plug-ins are prevented from running.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, controls and plug-ins can run without user intervention." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Run ActiveX controls and plugins</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Run ActiveX controls and plugins</td><td>Enable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Script ActiveX controls marked safe for scripting" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage whether an ActiveX control marked safe for scripting can interact with a script.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, script interaction can occur automatically without user intervention.&lt;br/&gt;&lt;br/&gt;If you select Prompt in the drop-down box, users are queried to choose whether to allow script interaction.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, script interaction is prevented from occurring.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, script interaction can occur automatically without user intervention." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Script ActiveX controls marked safe for scripting</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Script ActiveX controls marked safe for scripting</td><td>Enable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Scripting of Java applets" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage whether applets are exposed to scripts within the zone.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, scripts can access applets automatically without user intervention.&lt;br/&gt;&lt;br/&gt;If you select Prompt in the drop-down box, users are queried to choose whether to allow scripts to access applets.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, scripts are prevented from accessing applets.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, scripts can access applets automatically without user intervention." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Scripting of Java applets</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Scripting of Java applets</td><td>Enable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Software channel permissions" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage software channel permissions.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, you can choose the following options from the drop-down box.&lt;br/&gt;&lt;br/&gt;Low safety to allow users to be notified of software updates by e-mail, software packages to be automatically downloaded to users' computers, and software packages to be automatically installed on users' computers.&lt;br/&gt;&lt;br/&gt;Medium safety to allow users to be notified of software updates by e-mail and software packages to be automatically downloaded to (but not installed on) users' computers.&lt;br/&gt;&lt;br/&gt;High safety to prevent users from being notified of software updates by e-mail, software packages from being automatically downloaded to users' computers, and software packages from being automatically installed on users' computers.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, permissions are set to high safety.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, permissions are set to Medium safety." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Software channel permissions</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Software channel permissions</td><td>Medium safety</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Submit non-encrypted form data" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage whether data on HTML forms on pages in the zone may be submitted. Forms sent with SSL (Secure Sockets Layer) encryption are always allowed; this setting only affects non-SSL form data submission.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, information using HTML forms on pages in this zone can be submitted automatically. If you select Prompt in the drop-down box, users are queried to choose whether to allow information using HTML forms on pages in this zone to be submitted.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, information using HTML forms on pages in this zone is prevented from being submitted.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, information using HTML forms on pages in this zone can be submitted automatically." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Submit non-encrypted form data</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Submit non-encrypted form data</td><td>Prompt</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Use Pop-up Blocker" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage whether unwanted pop-up windows appear. Pop-up windows that are opened when the end user clicks a link are not blocked.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, most unwanted pop-up windows are prevented from appearing.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, pop-up windows are not prevented from appearing.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, pop-up windows are not prevented from appearing." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Use Pop-up Blocker</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Use Pop-up Blocker</td><td>Enable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Userdata persistence" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Userdata persistence</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Userdata persistence</td><td>Enable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Web sites in less privileged Web content zones can navigate into this zone" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone" gpmc_settingDescription="This policy setting allows you to manage whether Web sites from less privileged zones, such as Restricted Sites, can navigate into this zone.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Web sites in less privileged Web content zones can navigate into this zone</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Web sites in less privileged Web content zones can navigate into this zone</td><td>Enable</td></tr> </table></td></tr></table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Access data sources across domains" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Access data sources across domains</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Access data sources across domains</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Allow active scripting" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage whether script code on pages in the zone is run.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, script code on pages in the zone can run automatically. If you select Prompt in the drop-down box, users are queried to choose whether to allow script code on pages in the zone to run.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, script code on pages in the zone is prevented from running.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, script code on pages in the zone is prevented from running." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Allow active scripting</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Allow active scripting</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Allow binary and script behaviors" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage dynamic binary and script behaviors: components that encapsulate specific functionality for HTML elements to which they were attached.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, binary and script behaviors are available. If you select Administrator approved in the drop-down box, only behaviors listed in the Admin-approved Behaviors under Binary Behaviors Security Restriction policy are available.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, binary and script behaviors are not available unless applications have implemented a custom security manager.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, binary and script behaviors are not available unless applications have implemented a custom security manager." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Allow binary and script behaviors</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Allow Binary and Script Behaviors</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Allow drag and drop or copy and paste files" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage whether users can drag files or copy and paste files from a source within the zone.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, users can drag files or copy and paste files from this zone automatically. If you select Prompt in the drop-down box, users are queried to choose whether to drag or copy files from this zone.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, users are prevented from dragging files or copying and pasting files from this zone.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, users are queried to choose whether to drag or copy files from this zone." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Allow drag and drop or copy and paste files</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Allow drag and drop or copy and paste files</td><td>Prompt</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Allow file downloads" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage whether file downloads are permitted from the zone. This option is determined by the zone of the page with the link causing the download, not the zone from which the file is delivered.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, files can be downloaded from the zone.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, files are prevented from being downloaded from the zone.&lt;br/&gt;&lt;br/&gt; If you do not configure this policy setting, files are prevented from being downloaded from the zone." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Allow file downloads</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Allow file downloads</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Allow font downloads" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage whether pages of the zone may download HTML fonts.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, HTML fonts are prevented from downloading.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, users are queried whether to allow HTML fonts to download." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Allow font downloads</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Allow font downloads</td><td>Prompt</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Allow installation of desktop items" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage whether users can install Active Desktop items from this zone. The settings for this option are: If you enable this policy setting, users can install desktop items from this zone automatically.&lt;br/&gt;&lt;br/&gt;If you select Prompt in the drop-down box, users are queried to choose whether to install desktop items from this zone.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, users are prevented from installing desktop items from this zone. &lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, users are prevented from installing desktop items from this zone." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Allow installation of desktop items</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Allow installation of desktop items</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Allow META REFRESH" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage whether a user's browser can be redirected to another Web page if the author of the Web page uses the Meta Refresh setting (tag) to redirect browsers to another Web page. &lt;br/&gt;&lt;br/&gt;If you enable this policy setting, a user's browser that loads a page containing an active Meta Refresh setting can be redirected to another Web page.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, a user's browser that loads a page containing an active Meta Refresh setting cannot be redirected to another Web page.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, a user's browser that loads a page containing an active Meta Refresh setting cannot be redirected to another Web page." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Allow META REFRESH</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Allow META REFRESH</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Allow paste operations via script" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage whether scripts can perform a clipboard operation (for example, cut, copy, and paste) in a specified region.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, a script can perform a clipboard operation.&lt;br/&gt;&lt;br/&gt;If you select Prompt in the drop-down box, users are queried as to whether to perform clipboard operations.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, a script cannot perform a clipboard operation.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, a script cannot perform a clipboard operation." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Allow paste operations via script</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Allow paste operations via script</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Allow script-initiated windows without size or position constraints" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage restrictions on script-initiated pop-up windows and windows that include the title and status bars.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, Windows Restrictions security will not apply in this zone. The security zone runs without the added layer of security provided by this feature.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, the possible harmful actions contained in script-initiated pop-up windows and windows that include the title and status bars cannot be run. This Internet Explorer security feature will be on in this zone as dictated by the Scripted Windows Security Restrictions feature control setting for the process.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, the possible harmful actions contained in script-initiated pop-up windows and windows that include the title and status bars cannot be run. This Internet Explorer security feature will be on in this zone as dictated by the Scripted Windows Security Restrictions feature control setting for the process." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Allow script-initiated windows without size or position constraints</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Allow script-initiated windows without size or position constraints</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Automatic prompting for ActiveX controls" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting manages whether users will be automatically prompted for ActiveX control installations.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, ActiveX control installations will be blocked using the Information Bar. Users can click on the Information Bar to allow the ActiveX control prompt.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, ActiveX control installations will be blocked using the Information Bar. Users can click on the Information Bar to allow the ActiveX control prompt." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Automatic prompting for ActiveX controls</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Automatic prompting for ActiveX controls</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Automatic prompting for file downloads" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.&lt;br/&gt;&lt;br/&gt;If you enable this setting, users will receive a file download dialog for automatic download attempts.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, file downloads that are not user-initiated will be blocked, and users will see the Information Bar instead of the file download dialog. Users can then click the Information Bar to allow the file download prompt." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Automatic prompting for file downloads</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Automatic prompting for file downloads</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Display mixed content" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage whether users can display nonsecure items and manage whether users receive a security information message to display pages containing both secure and nonsecure items.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, and the drop-down box is set to Enable, the user does not receive a security information message (This page contains both secure and nonsecure items. Do you want to display the nonsecure items?) and nonsecure content can be displayed.&lt;br/&gt;&lt;br/&gt;If the drop-down box is set to Prompt, the user will receive the security information message on the Web pages that contain both secure (https://) and nonsecure (http://) content.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, users cannot receive the security information message and nonsecure content cannot be displayed.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, the user will receive the security information message on the Web pages that contain both secure (https://) and nonsecure (http://) content." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Display mixed content</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Display mixed content</td><td>Prompt</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Do not prompt for client certificate selection when no certificates or only one certificate exists." gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage whether users are prompted to select a certificate when no certificate or only one certificate exists.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, Internet Explorer does not prompt users with a &amp;quot;Client Authentication&amp;quot; message when they connect to a Web site that has no certificate or only one certificate.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, Internet Explorer prompts users with a &amp;quot;Client Authentication&amp;quot; message when they connect to a Web site that has no certificate or only one certificate.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, Internet Explorer prompts users with a Client Authentication message when they connect to a Web site that has no certificate or only one certificate." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Do not prompt for client certificate selection when no certificates or only one certificate exists.</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Do not prompt for client certificate selection when no certificates or only one certificate exists.</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Download signed ActiveX controls" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage whether users may download signed ActiveX controls from a page in the zone.&lt;br/&gt;&lt;br/&gt;If you enable this policy, users can download signed controls without user intervention. If you select Prompt in the drop-down box, users are queried whether to download controls signed by publishers who aren't trusted. Code signed by trusted publishers is silently downloaded.&lt;br/&gt;&lt;br/&gt;If you disable the policy setting, signed controls cannot be downloaded.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, signed controls cannot be downloaded." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Download signed ActiveX controls</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Download signed ActiveX controls</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Download unsigned ActiveX controls" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage whether users may download unsigned ActiveX controls from the zone. Such code is potentially harmful, especially when coming from an untrusted zone.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, users can run unsigned controls without user intervention. If you select Prompt in the drop-down box, users are queried to choose whether to allow the unsigned control to run.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, users cannot run unsigned controls.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, users cannot run unsigned controls." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Download unsigned ActiveX controls</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Download unsigned ActiveX controls</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Initialize and script ActiveX controls not marked as safe" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage ActiveX controls not marked as safe.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Initialize and script ActiveX controls not marked as safe</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Initialize and script ActiveX controls not marked as safe</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Java permissions" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage permissions for Java applets.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.&lt;br/&gt;&lt;br/&gt;Low Safety enables applets to perform all operations.&lt;br/&gt;&lt;br/&gt;Medium Safety enables applets to run in their sandbox (an area in memory outside of which the program cannot make calls), plus capabilities like scratch space (a safe and secure storage area on the client computer) and user-controlled file I/O. &lt;br/&gt;&lt;br/&gt;High Safety enables applets to run in their sandbox. Disable Java to prevent any applets from running.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, Java applets cannot run.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, Java applets are disabled." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Java permissions</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Java permissions</td><td>Disable Java</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Launching applications and files in an IFRAME" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage whether applications may be run and files may be downloaded from an IFRAME reference in the HTML of the pages in this zone. &lt;br/&gt;&lt;br/&gt;If you enable this policy setting, users can run applications and download files from IFRAMEs on the pages in this zone without user intervention. If you select Prompt in the drop-down box, users are queried to choose whether to run applications and download files from IFRAMEs on the pages in this zone.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, users are prevented from running applications and downloading files from IFRAMEs on the pages in this zone.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, users are prevented from running applications and downloading files from IFRAMEs on the pages in this zone." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Launching applications and files in an IFRAME</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Launching applications and files in an IFRAME</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Logon options" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage settings for logon options.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, you can choose from the following logon options.&lt;br/&gt;&lt;br/&gt;Anonymous logon to disable HTTP authentication and use the guest account only for the Common Internet File System (CIFS) protocol.&lt;br/&gt;&lt;br/&gt;Prompt for user name and password to query users for user IDs and passwords. After a user is queried, these values can be used silently for the remainder of the session.&lt;br/&gt;&lt;br/&gt;Automatic logon only in Intranet zone to query users for user IDs and passwords in other zones. After a user is queried, these values can be used silently for the remainder of the session.&lt;br/&gt;&lt;br/&gt;Automatic logon with current user name and password to attempt logon using Windows NT Challenge Response (also known as NTLM authentication). If Windows NT Challenge Response is supported by the server, the logon uses the user's network user name and password for logon. If Windows NT Challenge Response is not supported by the server, the user is queried to provide the user name and password.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, logon is set to Automatic logon only in Intranet zone.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, logon is set to Prompt for username and password." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Logon options</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Logon options</td><td>Prompt for user name and password</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Navigate sub-frames across different domains" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage the opening of sub-frames and access of applications across different domains.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, users can open additional sub-frames from other domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow additional sub-frames or access to applications from other domains.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, users cannot open other sub-frames or access applications from different domains.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, users cannot open other sub-frames or access applications from different domains." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Navigate sub-frames across different domains</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Navigate sub-frames across different domains</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Open files based on content, not file extension" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage MIME sniffing for file promotion from one type to another based on a MIME sniff. A MIME sniff is the recognition by Internet Explorer of the file type based on a bit signature.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, the MIME Sniffing Safety Feature will not apply in this zone. The security zone will run without the added layer of security provided by this feature.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, the actions that may be harmful cannot run; this Internet Explorer security feature will be turned on in this zone, as dictated by the feature control setting for the process.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, the actions that may be harmful cannot run; this Internet Explorer security feature will be turned on in this zone, as dictated by the feature control setting for the process." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Open files based on content, not file extension</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Open files based on content, not file extension</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Run .NET Framework-reliant components not signed with Authenticode" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, Internet Explorer will not execute unsigned managed components.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, Internet Explorer will not execute unsigned managed components." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Run .NET Framework-reliant components not signed with Authenticode</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Run .NET Framework-reliant components not signed with Authenticode</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Run .NET Framework-reliant components signed with Authenticode" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage whether .NET Framework components that are signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, Internet Explorer will execute signed managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute signed managed components.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, Internet Explorer will not execute signed managed components.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, Internet Explorer will not execute signed managed components." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Run .NET Framework-reliant components signed with Authenticode</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Run .NET Framework-reliant components signed with Authenticode</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Run ActiveX controls and plugins" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage whether ActiveX controls and plug-ins can be run on pages from the specified zone.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, controls and plug-ins can run without user intervention.&lt;br/&gt;&lt;br/&gt;If you selected Prompt in the drop-down box, users are asked to choose whether to allow the controls or plug-in to run.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, controls and plug-ins are prevented from running.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, controls and plug-ins are prevented from running." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Run ActiveX controls and plugins</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Run ActiveX controls and plugins</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Script ActiveX controls marked safe for scripting" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage whether an ActiveX control marked safe for scripting can interact with a script.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, script interaction can occur automatically without user intervention.&lt;br/&gt;&lt;br/&gt;If you select Prompt in the drop-down box, users are queried to choose whether to allow script interaction.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, script interaction is prevented from occurring.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, script interaction is prevented from occurring." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Script ActiveX controls marked safe for scripting</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Script ActiveX controls marked safe for scripting</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Scripting of Java applets" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage whether applets are exposed to scripts within the zone.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, scripts can access applets automatically without user intervention.&lt;br/&gt;&lt;br/&gt;If you select Prompt in the drop-down box, users are queried to choose whether to allow scripts to access applets.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, scripts are prevented from accessing applets.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, scripts are prevented from accessing applets." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Scripting of Java applets</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Scripting of Java applets</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Software channel permissions" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage software channel permissions.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, you can choose the following options from the drop-down box.&lt;br/&gt;&lt;br/&gt;Low safety to allow users to be notified of software updates by e-mail, software packages to be automatically downloaded to users' computers, and software packages to be automatically installed on users' computers.&lt;br/&gt;&lt;br/&gt;Medium safety to allow users to be notified of software updates by e-mail and software packages to be automatically downloaded to (but not installed on) users' computers.&lt;br/&gt;&lt;br/&gt;High safety to prevent users from being notified of software updates by e-mail, software packages from being automatically downloaded to users' computers, and software packages from being automatically installed on users' computers.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, permissions are set to high safety.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, permissions are set to Low safety." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Software channel permissions</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Software channel permissions</td><td>High safety</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Submit non-encrypted form data" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage whether data on HTML forms on pages in the zone may be submitted. Forms sent with SSL (Secure Sockets Layer) encryption are always allowed; this setting only affects non-SSL form data submission.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, information using HTML forms on pages in this zone can be submitted automatically. If you select Prompt in the drop-down box, users are queried to choose whether to allow information using HTML forms on pages in this zone to be submitted.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, information using HTML forms on pages in this zone is prevented from being submitted.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, users are queried to choose whether to allow information using HTML forms on pages in this zone to be submitted." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Submit non-encrypted form data</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Submit non-encrypted form data</td><td>Prompt</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Use Pop-up Blocker" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage whether unwanted pop-up windows appear. Pop-up windows that are opened when the end user clicks a link are not blocked.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, most unwanted pop-up windows are prevented from appearing.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, pop-up windows are not prevented from appearing.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, most unwanted pop-up windows are prevented from appearing." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Use Pop-up Blocker</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Use Pop-up Blocker</td><td>Enable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Userdata persistence" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Userdata persistence</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Userdata persistence</td><td>Disable</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Web sites in less privileged Web content zones can navigate into this zone" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone" gpmc_settingDescription="This policy setting allows you to manage whether Web sites from less privileged zones, such as Internet sites, can navigate into this zone.&lt;br/&gt;&lt;br/&gt;If you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.&lt;br/&gt;&lt;br/&gt;If you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.&lt;br/&gt;&lt;br/&gt;If you do not configure this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control." gpmc_supported="at least Internet Explorer v6.0 in Windows XP Service Pack 2 or Windows Server 2003 Service Pack 1">Web sites in less privileged Web content zones can navigate into this zone</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Web sites in less privileged Web content zones can navigate into this zone</td><td>Disable</td></tr> </table></td></tr></table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Windows Components/Internet Explorer/Toolbars</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Configure Toolbar Buttons" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Toolbars" gpmc_settingDescription="Specifies which buttons will be displayed on the standard toolbar in Microsoft Internet Explorer.&lt;br/&gt;&lt;br/&gt;If you enable this policy, you can specify whether or not each button will be displayed by selecting or clearing the check boxes for each button.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, the standard toolbar will be displayed with its default settings, unless users customize it." gpmc_supported="at least Internet Explorer v5.0">Configure Toolbar Buttons</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Show Back button</td><td>Enabled</td></tr> <tr><td>Show Forward button</td><td>Enabled</td></tr> <tr><td>Show Stop button</td><td>Enabled</td></tr> <tr><td>Show Refresh button</td><td>Enabled</td></tr> <tr><td>Show Home button</td><td>Enabled</td></tr> <tr><td>Show Search button</td><td>Disabled</td></tr> <tr><td>Show Favorites button</td><td>Disabled</td></tr> <tr><td>Show History button</td><td>Disabled</td></tr> <tr><td>Show Folders button</td><td>Disabled</td></tr> <tr><td>Show Fullscreen button</td><td>Disabled</td></tr> <tr><td>Show Tools button</td><td>Disabled</td></tr> <tr><td>Show Mail button</td><td>Disabled</td></tr> <tr><td>Show Font size button</td><td>Disabled</td></tr> <tr><td>Show Print button</td><td>Disabled</td></tr> <tr><td>Show Edit button</td><td>Disabled</td></tr> <tr><td>Show Discussions button</td><td>Disabled</td></tr> <tr><td>Show Cut button</td><td>Disabled</td></tr> <tr><td>Show Copy button</td><td>Disabled</td></tr> <tr><td>Show Paste button</td><td>Disabled</td></tr> <tr><td>Show Encoding button</td><td>Disabled</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable customizing browser toolbar buttons" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Toolbars" gpmc_settingDescription="Prevents users from determining which buttons appear on the Microsoft Internet Explorer and Windows Explorer standard toolbars.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the Customize command on the Toolbars submenu of the View menu will be removed.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can customize which buttons appear on the Internet Explorer and Windows Explorer toolbars.&lt;br/&gt;&lt;br/&gt;This policy can be used in coordination with the &amp;quot;Disable customizing browser toolbars&amp;quot; policy, which prevents users from determining which toolbars are displayed in Internet Explorer and Windows Explorer." gpmc_supported="at least Internet Explorer v5.0">Disable customizing browser toolbar buttons</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Disable customizing browser toolbars" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Internet Explorer/Toolbars" gpmc_settingDescription="Prevents users from determining which toolbars are displayed in Microsoft Internet Explorer and Windows Explorer.&lt;br/&gt;&lt;br/&gt;If you enable this policy, the list of toolbars, which users can display by clicking the View menu and then pointing to the Toolbars command, will appear dimmed.&lt;br/&gt;&lt;br/&gt;If you disable this policy or do not configure it, users can determine which toolbars are displayed in Windows Explorer and Internet Explorer.&lt;br/&gt;&lt;br/&gt;This policy can be used in coordination with the &amp;quot;Disable customizing browser toolbar buttons&amp;quot; policy, which prevents users from adding or removing toolbars from Internet Explorer." gpmc_supported="at least Internet Explorer v5.0">Disable customizing browser toolbars</a></td><td>Enabled</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Windows Components/Windows Explorer</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Allow only per user or approved shell extensions" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Explorer" gpmc_settingDescription="This setting is designed to ensure that shell extensions can operate on a per-user basis. If you enable this setting, Windows is directed to only run those shell extensions that have either been approved by an administrator or that will not impact other users of the machine.&lt;br/&gt;&lt;br/&gt;A shell extension only runs if there is an entry in at least one of the following locations in registry.&lt;br/&gt;&lt;br/&gt;For shell extensions that have been approved by the administrator and are available to all users of the computer, there must be an entry at HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved.&lt;br/&gt;&lt;br/&gt;For shell extensions to run on a per-user basis, there must be an entry at HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved." gpmc_supported="At least Microsoft Windows 2000">Allow only per user or approved shell extensions</a></td><td>Disabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Do not track Shell shortcuts during roaming" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Explorer" gpmc_settingDescription="Determines whether Windows traces shortcuts back to their sources when it cannot find the target on the user's system.&lt;br/&gt;&lt;br/&gt;Shortcut files typically include an absolute path to the original target file as well as the relative path to the current target file. When the system cannot find the file in the current target path, then, by default, it searches for the target in the original path. If the shortcut has been copied to a different computer, the original path might lead to a network computer, including external resources, such as an Internet server.&lt;br/&gt;&lt;br/&gt;If you enable this setting, Windows only searches the current target path. It does not search for the original path even when it cannot find the target file in the current target path." gpmc_supported="At least Microsoft Windows 2000">Do not track Shell shortcuts during roaming</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Hide these specified drives in My Computer" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Explorer" gpmc_settingDescription="Removes the icons representing selected hard drives from My Computer and Windows Explorer. Also, the drive letters representing the selected drives do not appear in the standard Open dialog box.&lt;br/&gt;&lt;br/&gt;To use this setting, select a drive or combination of drives in the drop-down list. To display all drives, disable this setting or select the &amp;quot;Do not restrict drives&amp;quot; option in the drop-down list.&lt;br/&gt;&lt;br/&gt;Note: This setting removes the drive icons. Users can still gain access to drive contents by using other methods, such as by typing the path to a directory on the drive in the Map Network Drive dialog box, in the Run dialog box, or in a command window.&lt;br/&gt;&lt;br/&gt;Also, this setting does not prevent users from using programs to access these drives or their contents. And, it does not prevent users from using the Disk Management snap-in to view and change drive characteristics.&lt;br/&gt;&lt;br/&gt;Also, see the &amp;quot;Prevent access to drives from My Computer&amp;quot; setting.&lt;br/&gt;&lt;br/&gt;Note: It is a requirement for third-party applications with Windows 2000 or later certification to adhere to this setting." gpmc_supported="At least Microsoft Windows 2000">Hide these specified drives in My Computer</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Pick one of the following combinations</td><td>Restrict A, B and C drives only</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="No &amp;quot;Entire Network&amp;quot; in My Network Places" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Explorer" gpmc_settingDescription="Removes all computers outside of the user's workgroup or local domain from lists of network resources in Windows Explorer and My Network Places.&lt;br/&gt;&lt;br/&gt;If you enable this setting, the system removes the Entire Network option and the icons representing networked computers from My Network Places and from the browser associated with the Map Network Drive option.&lt;br/&gt;&lt;br/&gt;This setting does not prevent users from viewing or connecting to computers in their workgroup or domain. It also does not prevent users from connecting to remote computers by other commonly used methods, such as by typing the share name in the Run dialog box or the Map Network Drive dialog box.&lt;br/&gt;&lt;br/&gt;To remove computers in the user's workgroup or domain from lists of network resources, use the &amp;quot;No &amp;quot;Computers Near Me&amp;quot; in My Network Places&amp;quot; setting.&lt;br/&gt;&lt;br/&gt;Note: It is a requirement for third-party applications with Windows 2000 or later certification to adhere to this setting." gpmc_supported="At least Microsoft Windows 2000">No &quot;Entire Network&quot; in My Network Places</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prevent access to drives from My Computer" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Explorer" gpmc_settingDescription="Prevents users from using My Computer to gain access to the content of selected drives.&lt;br/&gt;&lt;br/&gt;If you enable this setting, users can browse the directory structure of the selected drives in My Computer or Windows Explorer, but they cannot open folders and access the contents. Also, they cannot use the Run dialog box or the Map Network Drive dialog box to view the directories on these drives.&lt;br/&gt;&lt;br/&gt;To use this setting, select a drive or combination of drives from the drop-down list. To allow access to all drive directories, disable this setting or select the &amp;quot;Do not restrict drives&amp;quot; option from the drop-down list.&lt;br/&gt;&lt;br/&gt;Note: The icons representing the specified drives still appear in My Computer, but if users double-click the icons, a message appears explaining that a setting prevents the action.&lt;br/&gt;&lt;br/&gt; Also, this setting does not prevent users from using programs to access local and network drives. And, it does not prevent them from using the Disk Management snap-in to view and change drive characteristics.&lt;br/&gt;&lt;br/&gt;Also, see the &amp;quot;Hide these specified drives in My Computer&amp;quot; setting." gpmc_supported="At least Microsoft Windows 2000">Prevent access to drives from My Computer</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Pick one of the following combinations</td><td>Restrict A and B drives only</td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove &amp;quot;Map Network Drive&amp;quot; and &amp;quot;Disconnect Network Drive&amp;quot;" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Explorer" gpmc_settingDescription="Prevents users from using Windows Explorer or My Network Places to map or disconnect network drives.&lt;br/&gt;&lt;br/&gt;If you enable this setting, the system removes the Map Network Drive and Disconnect Network Drive commands from the toolbar and Tools menus in Windows Explorer and My Network Places and from menus that appear when you right-click the Windows Explorer or My Network Places icons. It also removes the Add Network Place option from My Network Places.&lt;br/&gt;&lt;br/&gt;This setting does not prevent users from connecting to another computer by typing the name of a shared folder in the Run dialog box.&lt;br/&gt;&lt;br/&gt;Note:&lt;br/&gt;&lt;br/&gt;This setting was documented incorrectly on the Explain tab in Group Policy for Windows 2000. The Explain tab states incorrectly that this setting prevents users from connecting and disconnecting drives.&lt;br/&gt;&lt;br/&gt;Note: It is a requirement for third-party applications with Windows 2000 or later certification to adhere to this setting." gpmc_supported="At least Microsoft Windows 2000">Remove &quot;Map Network Drive&quot; and &quot;Disconnect Network Drive&quot;</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove CD Burning features" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Explorer" gpmc_settingDescription="Windows Explorer allows you to create and modify re-writable CDs if you have a CD writer connected to your PC.&lt;br/&gt;&lt;br/&gt;If you enable this setting, all features in the Windows Explorer that allow you to use your CD writer are removed.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, users are able to use the Windows Explorer CD burning features.&lt;br/&gt;&lt;br/&gt;Note: This setting does not prevent users from using third-party applications to create or modify CDs using a CD writer." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Remove CD Burning features</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove DFS tab" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Explorer" gpmc_settingDescription="Removes the DFS tab from Windows Explorer.&lt;br/&gt;&lt;br/&gt;This setting removes the DFS tab from Windows Explorer and from other programs that use the Windows Explorer browser, such as My Computer. As a result, users cannot use this tab to view or change the properties of the Distributed File System (DFS) shares available from their computer.&lt;br/&gt;&lt;br/&gt;This setting does not prevent users from using other methods to configure DFS." gpmc_supported="At least Microsoft Windows 2000">Remove DFS tab</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove File menu from Windows Explorer" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Explorer" gpmc_settingDescription="Removes the File menu from My Computer and Windows Explorer.&lt;br/&gt;&lt;br/&gt;This setting does not prevent users from using other methods to perform tasks available on the File menu." gpmc_supported="At least Microsoft Windows 2000">Remove File menu from Windows Explorer</a></td><td>Disabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove Hardware tab" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Explorer" gpmc_settingDescription="Removes the Hardware tab.&lt;br/&gt;&lt;br/&gt;This setting removes the Hardware tab from Mouse, Keyboard, and Sounds and Audio Devices in Control Panel. It also removes the Hardware tab from the Properties dialog box for all local drives, including hard drives, floppy disk drives, and CD-ROM drives. As a result, users cannot use the Hardware tab to view or change the device list or device properties, or use the Troubleshoot button to resolve problems with the device." gpmc_supported="At least Microsoft Windows 2000">Remove Hardware tab</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove Search button from Windows Explorer" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Explorer" gpmc_settingDescription="Removes the Search button from the Windows Explorer toolbar.&lt;br/&gt;&lt;br/&gt;This setting removes the Search button from the Standard Buttons toolbar that appears in Windows Explorer and other programs that use the Windows Explorer window, such as My Computer and My Network Places.&lt;br/&gt;&lt;br/&gt;It does not remove the Search button or affect any search features of Internet browser windows, such as the Internet Explorer window.&lt;br/&gt;&lt;br/&gt;This setting does not affect the Search items on the Windows Explorer context menu or on the Start menu. To remove Search from the Start menu, use the &amp;quot;Remove Search menu from Start menu&amp;quot; setting (in User Configuration\Administrative Templates\Start Menu and Taskbar). To hide all context menus, use the &amp;quot;Remove Windows Explorer's default context menu&amp;quot; setting." gpmc_supported="At least Microsoft Windows 2000">Remove Search button from Windows Explorer</a></td><td>Disabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove Security tab" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Explorer" gpmc_settingDescription="Removes the Security tab from Windows Explorer.&lt;br/&gt;&lt;br/&gt;If you enable this setting, users opening the Properties dialog box for all file system objects, including folders, files, shortcuts, and drives, will not be able to access the Security tab. As a result, users will be able to neither change the security settings nor view a list of all users that have access to the resource in question.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, users will be able to access the security tab." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Remove Security tab</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove Shared Documents from My Computer" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Explorer" gpmc_settingDescription="Removes the Shared Documents folder from My Computer.&lt;br/&gt;&lt;br/&gt;When a Windows client in is a workgroup, a Shared Documents icon appears in the Windows Explorer Web view under &amp;quot;Other Places&amp;quot; and also under &amp;quot;Files Stored on This Computer&amp;quot; in My Computer. Using this policy setting, you can choose not to have these items displayed.&lt;br/&gt;&lt;br/&gt;If you enable this setting, the Shared Documents folder is not displayed in the Web view or in My Computer.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, the Shared Documents folder is displayed in Web view and also in My Computer when the client is part of a workgroup.&lt;br/&gt;&lt;br/&gt;Note: The ability to remove the Shared Documents folder via Group Policy is only available on Windows XP Professional." gpmc_supported="Only works on Microsoft Windows XP Professional">Remove Shared Documents from My Computer</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Remove Windows Explorer's default context menu" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Explorer" gpmc_settingDescription="Removes shortcut menus from the desktop and Windows Explorer. Shortcut menus appear when you right-click an item.&lt;br/&gt;&lt;br/&gt;If you enable this setting, menus do not appear when you right-click the desktop or when you right-click the items in Windows Explorer. This setting does not prevent users from using other methods to issue commands available on the shortcut menus." gpmc_supported="At least Microsoft Windows 2000">Remove Windows Explorer's default context menu</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Removes the Folder Options menu item from the Tools menu" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Explorer" gpmc_settingDescription="Removes the Folder Options item from all Windows Explorer menus and removes the Folder Options item from Control Panel. As a result, users cannot use the Folder Options dialog box.&lt;br/&gt;&lt;br/&gt;The Folder Options dialog box lets users set many properties of Windows Explorer, such as Active Desktop, Web view, Offline Files, hidden system files, and file types.&lt;br/&gt;&lt;br/&gt;Also, see the &amp;quot;Enable Active Desktop&amp;quot; setting in User Configuration\AdministrativeTemplates\Desktop\Active Desktop and the &amp;quot;Prohibit user configuration of Offline Files&amp;quot; setting in User Configuration\Administrative Templates\Network\Offline Files." gpmc_supported="At least Microsoft Windows 2000">Removes the Folder Options menu item from the Tools menu</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Request credentials for network installations" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Explorer" gpmc_settingDescription="Prompts users for alternate logon credentials during network-based installations.&lt;br/&gt;&lt;br/&gt;This setting displays the &amp;quot;Install Program As Other User&amp;quot; dialog box even when a program is being installed from files on a network computer across a local area network connection.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, this dialog box appears only when users are installing programs from local media.&lt;br/&gt;&lt;br/&gt;The &amp;quot;Install Program as Other User&amp;quot; dialog box prompts the current user for the user name and password of an administrator. This setting allows administrators who have logged on as regular users to install programs without logging off and logging on again using their administrator credentials.&lt;br/&gt;&lt;br/&gt;If the dialog box does not appear, the installation proceeds with the current user's permissions. If these permissions are not sufficient, the installation might fail, or it might complete but not include all features. Or, it might appear to complete successfully, but the installed program might not operate correctly.&lt;br/&gt;&lt;br/&gt;Note: If it is enabled, the &amp;quot;Do not request alternate credentials&amp;quot; setting takes precedence over this setting. When that setting is enabled, users are not prompted for alternate logon credentials on any installation." gpmc_supported="At least Microsoft Windows 2000">Request credentials for network installations</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Turn off caching of thumbnail pictures" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Explorer" gpmc_settingDescription="This settings controls whether the thumbnail views are cached.&lt;br/&gt;&lt;br/&gt;If you enable this setting, thumbnail views are not cached.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, thumbnail views are cached.&lt;br/&gt;&lt;br/&gt;Note: For shared corporate workstations or computers where security is a top concern, you should enable this setting to turn off the thumbnail view cache, because the thumbnail cache can be read by everyone." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Turn off caching of thumbnail pictures</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Turn off Windows+X hotkeys" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Explorer" gpmc_settingDescription="Turn off Windows+X hotkeys.&lt;br/&gt;&lt;br/&gt;Keyboards with a Windows key provide users with shortcuts to common shell features. For example, pressing the keyboard sequence Windows+R opens the Run dialog box; pressing Windows+E starts Windows Explorer. By using this setting, you can disable these Windows+X shortcut keys.&lt;br/&gt;&lt;br/&gt;If you enable this setting, the Windows+X shortcut keys are unavailable.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, the Windows+X shortcut keys are available." gpmc_supported="At least Microsoft Windows Server 2003">Turn off Windows+X hotkeys</a></td><td>Enabled</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Windows Components/Windows Explorer/Common Open File Dialog</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Hide the common dialog back button" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Explorer/Common Open File Dialog" gpmc_settingDescription="Removes the Back button from the Open dialog box.&lt;br/&gt;&lt;br/&gt;This setting, and others in this folder, lets you remove new features added in Windows 2000 Professional, so that the Open dialog box looks like it did in Windows NT 4.0 and earlier. These policies only affect programs that use the standard Open dialog box provided to developers of Windows programs.&lt;br/&gt;&lt;br/&gt;To see an example of the standard Open dialog box, run Notepad and, on the File menu, click Open.&lt;br/&gt;&lt;br/&gt;Note: It is a requirement for third-party applications with Windows 2000 or later certification to adhere to this setting." gpmc_supported="At least Microsoft Windows 2000">Hide the common dialog back button</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Hide the common dialog places bar" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Explorer/Common Open File Dialog" gpmc_settingDescription="Removes the shortcut bar from the Open dialog box.&lt;br/&gt;&lt;br/&gt;This setting, and others in this folder, lets you remove new features added in Windows 2000 Professional, so that the Open dialog box looks like it did in Windows NT 4.0 and earlier. These policies only affect programs that use the standard Open dialog box provided to developers of Windows programs.&lt;br/&gt;&lt;br/&gt;To see an example of the standard Open dialog box, start Notepad and, on the File menu, click Open.&lt;br/&gt;&lt;br/&gt;Note: It is a requirement for third-party applications with Windows 2000 or later certification to adhere to this setting." gpmc_supported="At least Microsoft Windows 2000">Hide the common dialog places bar</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Hide the dropdown list of recent files" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Explorer/Common Open File Dialog" gpmc_settingDescription="Removes the list of most recently used files from the Open dialog box.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, the &amp;quot;File name&amp;quot; field includes a drop-down list of recently used files. If you enable this setting, the &amp;quot;File name&amp;quot; field is a simple text box. Users must browse directories to find a file or type a file name in the text box.&lt;br/&gt;&lt;br/&gt;This setting, and others in this folder, lets you remove new features added in Windows 2000 Professional, so that the Open dialog box looks like it did in Windows NT 4.0 and earlier. These policies only affect programs that use the standard Open dialog box provided to developers of Windows programs.&lt;br/&gt;&lt;br/&gt;To see an example of the standard Open dialog box, start Notepad and, on the File menu, click Open.&lt;br/&gt;&lt;br/&gt;Note: It is a requirement for third-party applications with Windows 2000 or later certification to adhere to this setting." gpmc_supported="At least Microsoft Windows 2000">Hide the dropdown list of recent files</a></td><td>Enabled</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Windows Components/Windows Installer</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prevent removable media source for any install" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Installer" gpmc_settingDescription="Prevents users from installing programs from removable media.&lt;br/&gt;&lt;br/&gt;If a user tries to install a program from removable media, such as CD-ROMs, floppy disks, and DVDs, a message appears, stating that the feature cannot be found.&lt;br/&gt;&lt;br/&gt;This setting applies even when the installation is running in the user's security context.&lt;br/&gt;&lt;br/&gt;If you disable this setting or do not configure it, users can install from removable media when the installation is running in their own security context, but only system administrators can use removable media when an installation is running with elevated system privileges, such as installations offered on the desktop or in Add or Remove Programs.&lt;br/&gt;&lt;br/&gt;Also, see the &amp;quot;Enable user to use media source while elevated setting&amp;quot; in Computer Configuration\Administrative Templates\Windows Components\Windows Installer.&lt;br/&gt;&lt;br/&gt;Also, see the &amp;quot;Hide the 'Add a program from CD-ROM or floppy disk' option&amp;quot; setting in User Configuration\Administrative Templates\Control Panel\Add or Remove Programs." gpmc_supported="At least Microsoft Windows 2000">Prevent removable media source for any install</a></td><td>Enabled</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Windows Components/Windows Media Player</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prevent CD and DVD Media Information Retrieval" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Media Player" gpmc_settingDescription="Prevents media information for CDs and DVDs from being retrieved from the Internet.&lt;br/&gt;&lt;br/&gt;This policy prevents the Player from automatically obtaining media information from the Internet for CDs and DVDs played by users. In addition, the Retrieve media information for CDs and DVDs from the Internet check box on the Privacy Options tab in the first use dialog box and on the Privacy tab in the Player are not selected and are not available.&lt;br/&gt;&lt;br/&gt;When this policy is not configured or disabled, users can change the setting of the Retrieve media information for CDs and DVDs from the Internet check box." gpmc_supported="Windows Media Player 9 Series and later.">Prevent CD and DVD Media Information Retrieval</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prevent Music File Media Information Retrieval" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Media Player" gpmc_settingDescription="Prevents media information for music files from being retrieved from the Internet.&lt;br/&gt;&lt;br/&gt;This policy prevents the Player from automatically obtaining media information for music files such as Windows Media Audio (WMA) and MP3 files from the Internet. In addition, the Update my music files (WMA and MP3 files) by retrieving missing media information from the Internet check box in the first use dialog box and on the Privacy and Media Library tabs in the Player are not selected and are not available.&lt;br/&gt;&lt;br/&gt;When this policy is not configured or disabled, users can change the setting of the Update my music files (WMA and MP3 files) by retrieving missing media information from the Internet check box." gpmc_supported="Windows Media Player 9 Series and later.">Prevent Music File Media Information Retrieval</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prevent Radio Station Preset Retrieval" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Media Player" gpmc_settingDescription="Prevents radio station presets from being retrieved from the Internet.&lt;br/&gt;&lt;br/&gt;This policy prevents the Player from automatically retrieving radio station presets from the Internet and displaying them in Media Library. In addition, presets that exist before the policy is configured will not be updated, and presets a user adds will not be displayed.&lt;br/&gt;&lt;br/&gt;When this policy is not configured or disabled, the Player automatically retrieves radio station presets from the Internet." gpmc_supported="Windows Media Player 9 Series and later.">Prevent Radio Station Preset Retrieval</a></td><td>Enabled</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Windows Components/Windows Media Player/Networking</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Hide Network Tab" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Media Player/Networking" gpmc_settingDescription="Hides the Network tab.&lt;br/&gt;&lt;br/&gt;This policy hides the Network tab in Windows Media Player. The default network settings are used unless the user has previously defined network settings for the Player.&lt;br/&gt;&lt;br/&gt;When this policy is not configured or disabled, the Network tab appears and users can use it to configure network settings." gpmc_supported="Windows Media Player for Windows XP and later.">Hide Network Tab</a></td><td>Enabled</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Windows Components/Windows Media Player/Playback</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prevent Codec Download" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Media Player/Playback" gpmc_settingDescription="Prevents Windows Media Player from downloading codecs.&lt;br/&gt;&lt;br/&gt;This policy prevents the Player from automatically downloading codecs to your computer. In addition, the Download codecs automatically check box on the Player tab in the Player is not available.&lt;br/&gt;&lt;br/&gt;When this policy is disabled, codecs are automatically downloaded and the Download codecs automatically check box is not available.&lt;br/&gt;&lt;br/&gt;When this policy is not configured, users can change the setting for the Download codecs automatically check box." gpmc_supported="Windows Media Player for Windows XP and later.">Prevent Codec Download</a></td><td>Enabled</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Windows Components/Windows Media Player/User Interface</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Hide Privacy Tab" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Media Player/User Interface" gpmc_settingDescription="Hides the Privacy tab.&lt;br/&gt;&lt;br/&gt;This policy hides the Privacy tab in Windows Media Player. The default privacy settings are used for the options on the Privacy tab unless the user changed the settings previously.&lt;br/&gt;&lt;br/&gt;The Update my music files (WMA and MP3 files) by retrieving missing media information from the Internet check box is on the Privacy and Media Library tabs. When this policy is enabled, the Update my music files (WMA and MP3 files) by retrieving missing media information from the Internet check box on the Media Library tab is available, even though the Privacy tab is hidden, unless the Prevent Music File Media Information Retrieval policy is enabled.&lt;br/&gt;&lt;br/&gt;When this policy is not configured or disabled, the Privacy tab is not hidden, and users can configure any privacy settings not configured by other polices." gpmc_supported="Windows Media Player 9 Series and later.">Hide Privacy Tab</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Hide Security Tab" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Media Player/User Interface" gpmc_settingDescription="Hides the Security tab.&lt;br/&gt;&lt;br/&gt;This policy hides the Security tab in Windows Media Player. The default security settings for the options on the Security tab are used unless the user changed the settings previously.&lt;br/&gt;&lt;br/&gt;Even though this policy is enabled, users can still change security and zone settings by using Internet Explorer unless these settings have been hidden or disabled by Internet Explorer policies.&lt;br/&gt;&lt;br/&gt;When this policy is not configured or disabled, users can configure the security settings on the Security tab." gpmc_supported="Windows Media Player 9 Series and later.">Hide Security Tab</a></td><td>Enabled</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Windows Components/Windows Messenger</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Do not allow Windows Messenger to be run" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Messenger" gpmc_settingDescription="Allows you to disable Windows Messenger.&lt;br/&gt;&lt;br/&gt;If you enable this setting, Windows Messenger will not run.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, Windows Messenger can be used.&lt;br/&gt;&lt;br/&gt;Note: If you enable this setting, Remote Assistance also cannot use Windows Messenger.&lt;br/&gt;&lt;br/&gt;Note: This setting is available under both Computer Configuration and User Configuration. If both are present, the Computer Configuration version of this setting takes precedence." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Do not allow Windows Messenger to be run</a></td><td>Enabled</td></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Do not automatically start Windows Messenger initially" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Messenger" gpmc_settingDescription="Windows Messenger is automatically loaded and running when a user logs on to a Windows XP computer. You can use this setting to stop Windows Messenger from automatically being run at logon.&lt;br/&gt;&lt;br/&gt;If you enable this setting, Windows Messenger will not be loaded automatically when a user logs on.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, the Windows Messenger will be loaded automatically at logon.&lt;br/&gt;&lt;br/&gt;Note: This setting simply prevents Windows Messenger from running intially. If the user invokes and uses Windows Messenger from that point on, Windows Messenger will be loaded.&lt;br/&gt;&lt;br/&gt;The user can also configure this behavior on the Preferences tab on the Tools menu in the Windows Messenger user interface.&lt;br/&gt;&lt;br/&gt;Note: If you do not want users to use Windows Messenger, enable the &amp;quot;Do not allow Windows Messenger to run&amp;quot; setting.&lt;br/&gt;&lt;br/&gt;Note: This setting is available under both Computer Configuration and User Configuration. If both are present, the Computer Configuration version of this setting takes precedence." gpmc_supported="At least Microsoft Windows XP Professional or Windows Server 2003 family">Do not automatically start Windows Messenger initially</a></td><td>Enabled</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Windows Components/Windows Movie Maker</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Do not allow Windows Movie Maker to run" gpmc_settingPath="User Configuration/Administrative Templates/Windows Components/Windows Movie Maker" gpmc_settingDescription="Specifies whether Windows Movie Maker can run.&lt;br/&gt;&lt;br/&gt;Windows Movie Maker is a feature of the Windows XP operating system that can be used to capture, edit, and then save video as a movie to share with others.&lt;br/&gt;&lt;br/&gt;If you enable this setting, Windows Movie Maker will not run.&lt;br/&gt;&lt;br/&gt;If you disable or do not configure this setting, Windows Movie Maker can be run." gpmc_supported="At least Microsoft Windows XP Professional with SP2">Do not allow Windows Movie Maker to run</a></td><td>Enabled</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Windows Media Player customizations</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Customize the Windows Media Player" gpmc_settingPath="User Configuration/Administrative Templates/Windows Media Player customizations" gpmc_settingDescription="" gpmc_supported="">Customize the Windows Media Player</a></td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable_frame" cellpadding="0" cellspacing="0"> <tr><td>Title bar of the Windows Media Player:</td><td>Moorside High School</td></tr> <tr><td>Button name on Windows Media Player navigation bar:</td><td></td></tr> <tr><td>URL for button on Windows Media Player navigation bar:</td><td></td></tr> </table></td></tr><tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td><a class="explainlink" href="javascript:void();" onclick="javascript:showExplainText(this); return false;" gpmc_settingName="Prevent automatic codec download" gpmc_settingPath="User Configuration/Administrative Templates/Windows Media Player customizations" gpmc_settingDescription="" gpmc_supported="">Prevent automatic codec download</a></td><td>Enabled</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Extra Registry Settings</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i">Display names for some settings cannot be found. You might be able to resolve this issue by updating the .ADM files used by Group Policy Management.<br/><br/><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Setting</th><th scope="col">State</th></tr> <tr><td>Software\Microsoft\Internet Explorer\media\Autoplay</td><td>no</td></tr> <tr><td>Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Btn_Media</td><td>2</td></tr> <tr><td>Software\Policies\Microsoft\Internet Explorer\Control Panel\DisableDeleteBrowsingHistory</td><td>1</td></tr> <tr><td>Software\Policies\Microsoft\Internet Explorer\Control Panel\DisableDeleteForms</td><td>1</td></tr> <tr><td>Software\Policies\Microsoft\Internet Explorer\Control Panel\DisableDeletePasswords</td><td>1</td></tr> <tr><td>Software\Policies\Microsoft\Internet Explorer\Control Panel\Settings</td><td>1</td></tr> <tr><td>Software\Policies\Microsoft\Internet Explorer\Main\AllowWindowReuse</td><td>1</td></tr> <tr><td>Software\Policies\Microsoft\Internet Explorer\Main\AlwaysShowMenus</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Internet Explorer\Main\DisableFirstRunCustomize</td><td>1</td></tr> <tr><td>Software\Policies\Microsoft\Internet Explorer\Main\FormSuggest Passwords</td><td>no</td></tr> <tr><td>Software\Policies\Microsoft\Internet Explorer\Main\FormSuggest PW Ask</td><td>no</td></tr> <tr><td>Software\Policies\Microsoft\Internet Explorer\Main\Start Page</td><td>http://lithium/intranet</td></tr> <tr><td>Software\Policies\Microsoft\Internet Explorer\Main\Use FormSuggest</td><td>no</td></tr> <tr><td>Software\Policies\Microsoft\Internet Explorer\PhishingFilter\Enabled</td><td>2</td></tr> <tr><td>Software\Policies\Microsoft\Internet Explorer\Restrictions\DisablePopupFilterLevel</td><td>1</td></tr> <tr><td>Software\Policies\Microsoft\Internet Explorer\Restrictions\RestrictPopupExceptionList</td><td>1</td></tr> <tr><td>Software\Policies\Microsoft\Internet Explorer\Security\P3Global\Enabled</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Internet Explorer\SQM\DisableCustomerImprovementProgram</td><td>1</td></tr> <tr><td>Software\Policies\Microsoft\Internet Explorer\TabbedBrowsing\PopupsUseNewWindow</td><td>2</td></tr> <tr><td>Software\Policies\Microsoft\Windows\CurrentVersion\Explorer\AutoComplete\AutoSuggest</td><td>no</td></tr> </table> </div></div></div></div> </body></html>