Group Policy Management
body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } }
Setting Path:
Explanation
No explanation is available for this setting.
Supported On:
Not available
SMS Windows 10 Policy
Data collected on: 26/02/2016 11:13:53
General
Details
DomainAPGNTNET.local
OwnerAPGNTNET\Domain Admins
Created25/11/2015 11:32:30
Modified26/02/2016 10:33:42
User Revisions6 (AD), 6 (sysvol)
Computer Revisions366 (AD), 366 (sysvol)
Unique ID{63A18AB0-FCA0-4110-BE51-79DEAA4DE2B1}
GPO StatusUser settings disabled
Links
LocationEnforcedLink StatusPath
Windows 10NoDisabledAPGNTNET.local/Curriculum Workstations/Windows 10

This list only includes links in the domain of the GPO.
Security Filtering
The settings in this GPO can only apply to the following groups, users, and computers:
Name
NT AUTHORITY\Authenticated Users
Delegation
These groups and users have the specified permission for this GPO
NameAllowed PermissionsInherited
APGNTNET\Domain AdminsEdit settings, delete, modify securityNo
APGNTNET\Enterprise AdminsEdit settings, delete, modify securityNo
NT AUTHORITY\Authenticated UsersRead (from Security Filtering)No
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSReadNo
NT AUTHORITY\SYSTEMEdit settings, delete, modify securityNo
Computer Configuration (Enabled)
Policies
Windows Settings
Security Settings
Local Policies/User Rights Assignment
PolicySetting
Allow log on through Terminal ServicesDomain Users
Local Policies/Security Options
Accounts
PolicySetting
Accounts: Administrator account statusEnabled
Accounts: Guest account statusDisabled
Interactive Logon
PolicySetting
Interactive logon: Do not display last user nameEnabled
Interactive logon: Do not require CTRL+ALT+DELEnabled
Interactive logon: Message text for users attempting to log on*** By Logging in you are accepting this policy! ***, The School computer system is owned by the School and is made available to students to further their education and to staff to enhance their professional activities including teaching, research, administration and management. The School’s Internet Access Policy has been drawn up to protect all parties – the students, the staff and the School., • School email addresses should be used ONLY for school correspondence and should never be your personal email address., • The School reserves the right to examine or delete any files that may be held on its computer systems or to monitor any Internet sites visited. Staff and students requesting Internet access should sign a copy of the Acceptable Use Statement., • All Internet activity should be appropriate to your education., • Access should only be made through your authorised account and password, which should not be made available to any other person., • Activity that threatens the integrity of the School ICT systems or attacks or corrupts other systems is forbidden., • Users are responsible for all e-mail sent and for contacts made that may result in e-mail being received. Inappropriate e-mails and attachments received should be trashed immediately on sight., • Copyright of materials must be respected., • As e-mail can be forwarded or inadvertently be sent to the wrong person, the same levels of language and content should be applied as for letters or other media., • Use of the network to access inappropriate materials is forbidden., • Large scale copying of material from Internet sites should be avoided., • All users should ensure that they are correctly trained in the deleting and trashing of e-mail and attachments. Trash should be emptied daily., • Students should follow clearly, rules about access to unauthorised sites such as chat rooms/games/non-educational sites. These will only be accessible during specific times during after-school hours by agreement with a member of staff. No access is available during the school day., Sanctions, Use of the Internet and the School computer network may be withdrawn from any student found to be in breach of the School Policy working outside of the Internet guidelines.
Interactive logon: Message title for users attempting to log on"Computer Usage Policy"
Shutdown
PolicySetting
Shutdown: Allow system to be shut down without having to log onEnabled
Restricted Groups
GroupMembersMember of
BUILTIN\Remote Desktop UsersDomain Users
System Services
Application Identity (Startup Mode: Automatic)
Permissions
TypeNamePermission
AllowEveryoneFull Control
Auditing
No auditing specified
Computer Browser (Startup Mode: Automatic)
Permissions
No permissions specified
Auditing
No auditing specified
Remote Registry (Startup Mode: Automatic)
Permissions
No permissions specified
Auditing
No auditing specified
Remote Procedure Call (RPC) (Startup Mode: Automatic)
Permissions
No permissions specified
Auditing
No auditing specified
Task Scheduler (Startup Mode: Automatic)
Permissions
No permissions specified
Auditing
No auditing specified
File System
%ProgramFiles% (x86)\4Matrix
Configure this file or folder then: Replace existing permissions on all subfolders and files with inheritable permissions
Owner
Permissions
TypeNamePermissionApply To
AllowCREATOR OWNERFull ControlSubfolders and files only
AllowNT AUTHORITY\SYSTEMFull ControlThis folder, subfolders and files
AllowBUILTIN\AdministratorsFull ControlThis folder, subfolders and files
AllowAPGNTNET\Domain UsersFull ControlThis folder, subfolders and files
AllowBUILTIN\UsersRead and ExecuteThis folder, subfolders and files
Allow inheritable permissions from the parent to propagate to this object and all child objectsDisabled
Auditing
No auditing specified
%ProgramFiles% (x86)\SIMS
Configure this file or folder then: Replace existing permissions on all subfolders and files with inheritable permissions
Owner
Permissions
TypeNamePermissionApply To
AllowCREATOR OWNERFull ControlSubfolders and files only
AllowNT AUTHORITY\SYSTEMFull ControlThis folder, subfolders and files
AllowBUILTIN\AdministratorsFull ControlThis folder, subfolders and files
AllowAPGNTNET\Domain UsersFull ControlThis folder, subfolders and files
AllowBUILTIN\UsersRead and ExecuteThis folder, subfolders and files
Allow inheritable permissions from the parent to propagate to this object and all child objectsDisabled
Auditing
No auditing specified
%SystemRoot%\System32\osk.exe
Configure this file or folder then: Replace existing permissions on all subfolders and files with inheritable permissions
Owner
Permissions
TypeNamePermissionApply To
DenyCREATOR OWNERFull ControlThis folder, subfolders and files
DenyNT AUTHORITY\SYSTEMFull ControlThis folder, subfolders and files
DenyBUILTIN\AdministratorsFull ControlThis folder, subfolders and files
DenyAPGNTNET\Domain UsersFull ControlThis folder, subfolders and files
DenyBUILTIN\UsersFull ControlThis folder, subfolders and files
AllowCREATOR OWNERFull ControlSubfolders and files only
Allow inheritable permissions from the parent to propagate to this object and all child objectsDisabled
Auditing
No auditing specified
%SystemRoot%\System32\sethc.exe
Configure this file or folder then: Replace existing permissions on all subfolders and files with inheritable permissions
Owner
Permissions
TypeNamePermissionApply To
DenyEveryoneFull ControlThis folder, subfolders and files
Allow inheritable permissions from the parent to propagate to this object and all child objectsDisabled
Auditing
No auditing specified
%SystemRoot%\System32\Utilman.exe
Configure this file or folder then: Replace existing permissions on all subfolders and files with inheritable permissions
Owner
Permissions
TypeNamePermissionApply To
DenyEveryoneFull ControlThis folder, subfolders and files
Allow inheritable permissions from the parent to propagate to this object and all child objectsDisabled
Auditing
No auditing specified
%SystemRoot%\Web
Configure this file or folder then: Replace existing permissions on all subfolders and files with inheritable permissions
OwnerAPGNTNET\Administrator
Permissions
TypeNamePermissionApply To
AllowCREATOR OWNERFull ControlSubfolders and files only
AllowNT AUTHORITY\SYSTEMFull ControlThis folder, subfolders and files
AllowAPGNTNET\Domain AdminsFull ControlThis folder, subfolders and files
Allow inheritable permissions from the parent to propagate to this object and all child objectsDisabled
Auditing
No auditing specified
Registry
MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AccountPicture\Users
Configure this key then: Replace existing permissions on all subkeys with inheritable permissions
Owner
Permissions
TypeNamePermissionApply To
AllowCREATOR OWNERFull controlSubkeys only
AllowNT AUTHORITY\SYSTEMFull controlThis key and subkeys
AllowBUILTIN\AdministratorsFull controlThis key and subkeys
AllowAPGNTNET\Domain UsersFull controlThis key and subkeys
AllowBUILTIN\UsersReadThis key and subkeys
Allow inheritable permissions from the parent to propagate to this object and all child objectsDisabled
Auditing
No auditing specified
Application Control Policies
Appx Rules
PolicySetting
Enforce rules of this typeTrue

ActionUserNameRule TypeExceptions
AllowEveryoneMicrosoft.MicrosoftEdge, version 20.10240.0.0 and above, from CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=USPublisherNo
AllowEveryoneMicrosoft.WindowsSoundRecorder, version 10.1506.0.0 and above, from CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=USPublisherNo
DenyEveryoneMicrosoft.People, version 1.10159.0.0 and above, from CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=USPublisherNo
DenyEveryoneMicrosoft.WindowsFeedback, version 10.0.0.0 and above, from CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=USPublisherNo
DenyEveryoneMicrosoft.WindowsPhone, version 10.1506.0.0 and above, from CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=USPublisherNo
DenyEveryoneMicrosoft.Windows.Photos, version 15.618.0.0 and above, from CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=USPublisherNo
DenyEveryoneWindows.PurchaseDialog, version 6.2.0.0 and above, from CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=USPublisherNo
DenyEveryoneMicrosoft.BingSports, version 4.3.0.0 and above, from CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=USPublisherNo
DenyEveryoneMicrosoft.XboxGameCallableUI, version 1000.10240.0.0 and above, from CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=USPublisherNo
DenyAPGNTNET\All StudentsMicrosoft.SkypeApp, version 3.2.0.0 and above, from CN=Skype Software Sarl, O=Microsoft Corporation, L=Luxembourg, S=Luxembourg, C=LUPublisherNo
DenyEveryoneMicrosoft.Getstarted, version 2.1.0.0 and above, from CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=USPublisherNo
DenyEveryoneMicrosoft.XboxApp, version 5.6.0.0 and above, from CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=USPublisherNo
DenyEveryoneMicrosoft.XboxIdentityProvider, version 1000.10240.0.0 and above, from CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=USPublisherNo
AllowEveryoneMicrosoft.WindowsMaps, version 4.1505.0.0 and above, from CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=USPublisherNo
DenyEveryoneMicrosoft.BingFinance, version 4.3.0.0 and above, from CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=USPublisherNo
DenyEveryoneWindows.MiracastView, version 6.3.0.0 and above, from Microsoft CorporationPublisherNo
DenyEveryoneMicrosoft.MicrosoftSolitaireCollection, version 3.1.0.0 and above, from CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=USPublisherNo
AllowEveryoneWindows.PrintDialog, version 6.2.0.0 and above, from Microsoft CorporationPublisherNo
AllowEveryoneMicrosoft.WindowsCalculator, version 10.1506.0.0 and above, from CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=USPublisherNo
DenyEveryoneWindows.ContactSupport, version 10.0.0.0 and above, from CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=USPublisherNo
DenyEveryoneMicrosoft.ZuneMusic, version 3.6.0.0 and above, from CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=USPublisherNo
DenyEveryoneMicrosoft.Appconnector, version 1.3.0.0 and above, from CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=USPublisherNo
DenyEveryoneMicrosoft.ZuneVideo, version 3.6.0.0 and above, from CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=USPublisherNo
DenyEveryoneMicrosoft.WindowsCamera, version 5.38.0.0 and above, from CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=USPublisherNo
DenyEveryonemicrosoft.windowscommunicationsapps, version 17.6002.0.0 and above, from CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=USPublisherNo
AllowAPGNTNET\STAFFMicrosoft.SkypeApp, version 3.2.0.0 and above, from CN=Skype Software Sarl, O=Microsoft Corporation, L=Luxembourg, S=Luxembourg, C=LUPublisherNo
DenyEveryoneMicrosoft.BingWeather, version 4.3.0.0 and above, from CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=USPublisherNo
DenyEveryoneMicrosoft.3DBuilder, version 10.0.0.0 and above, from CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=USPublisherNo
DenyEveryoneMicrosoft.BingNews, version 4.3.0.0 and above, from CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=USPublisherNo
DenyEveryoneMicrosoft.WindowsStore, version 2015.7.0.0 and above, from CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=USPublisherNo
DenyEveryoneAll signed packaged appsPublisherNo
DenyEveryonewindows.immersivecontrolpanel, version 6.2.0.0 and above, from Microsoft CorporationPublisherNo
DenyEveryoneMicrosoft.BingWeather, version 4.3.0.0 and above, from CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=USPublisherNo
DenyEveryoneMicrosoft.WindowsAlarms, version 10.1506.0.0 and above, from CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=USPublisherNo
DenyEveryoneMicrosoft.Windows.ParentalControls, version 1000.10240.0.0 and above, from CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=USPublisherNo
Dll Rules
No rules of type 'Dll Rules' are defined.
Executable Rules
PolicySetting
Enforce rules of this typeTrue

No rules of type 'Executable Rules' are defined.
Windows Installer Rules
PolicySetting
Enforce rules of this typeTrue

No rules of type 'Windows Installer Rules' are defined.
Script Rules
PolicySetting
Enforce rules of this typeTrue

No rules of type 'Script Rules' are defined.
Administrative Templates
Policy definitions (ADMX files) retrieved from the central store.
Control Panel/Personalization
PolicySettingComment
Force a specific default lock screen imageEnabled
Path to lock screen image:\\Apgntnet.local\netlogon\CLS_WIN10\backgroundDefault.jpg
Example: Using a local path: C:\windows\web\screen\lockscreen.jpg
Example: Using a UNC path: \\Server\Share\Corp.jpg
Turn off fun facts, tips, tricks, and more on lock screenEnabled
PolicySettingComment
Prevent changing lock screen imageEnabled
Prevent enabling lock screen cameraEnabled
Network/Network Connections/Windows Firewall/Domain Profile
PolicySettingComment
Windows Firewall: Allow inbound Remote Desktop exceptionsEnabled
Allow unsolicited incoming messages from these IP addresses:*
Syntax:
Type "*" to allow messages from any network, or
else type a comma-separated list that contains
any number or combination of these:
IP addresses, such as 10.0.0.1
Subnet descriptions, such as 10.2.3.0/24
The string "localsubnet"
Example: to allow messages from 10.0.0.1,
10.0.0.2, and from any system on the
local subnet or on the 10.3.4.x subnet,
type the following in the "Allow unsolicited"
incoming messages from these IP addresses":
10.0.0.1,10.0.0.2,localsubnet,10.3.4.0/24
Network/Network Provider
PolicySettingComment
Hardened UNC PathsEnabled
Specify hardened network paths. In the name field, type a fully-qualified UNC path for each network resource. To secure all access to a share with a particular name, regardless of the server name, specify a server name of '*' (asterisk). For example, "\\*\NETLOGON". To secure all access to all shares hosted on a server, the share name portion of the UNC path may be omitted. For example, "\\SERVER". In the value field, specify one or more of the following options, separated by commas: 'RequireMutualAuthentication=1': Mutual authentication between the client and server is required to ensure the client connects to the correct server. 'RequireIntegrity=1': Communication between the client and server must employ an integrity mechanism to prevent data tampering. 'RequirePrivacy=1': Communication between the client and the server must be encrypted to prevent third parties from observing sensitive data.
Hardened UNC Paths: 
\\*\NETLOGONRequireMutualAuthentication=0
\\*\SYSVOLRequireMutualAuthentication=0
You should require both Integrity and Mutual Authentication for any UNC paths that host executable programs, script files, or files that control security policies. Consider hosting files that do not require Integrity or Privacy on separate shares from those that absolutely need such security for optimal performance. For additional details on configuring Windows computers to require additional security when accessing specific UNC paths, visit http://support.microsoft.com/kb/3000483.
Network/Offline Files
PolicySettingComment
Action on server disconnectEnabled
Specify how the system is to respond when a network server
becomes unavailable.
Action: Never go offline
Never go offline = Server's files are unavailable to local computer
Work offline = Server's files are available to local computer
PolicySettingComment
Allow or Disallow use of the Offline Files featureDisabled
At logoff, delete local copy of user’s offline filesEnabled
Causes the local copy of any offline file accessed by the user
to be deleted when the user logs off of the computer.
Delete only the temporary offline files.Disabled
PolicySettingComment
Configure Background SyncDisabled
Enable Transparent CachingDisabled
Prevent use of Offline Files folderEnabled
Prohibit user configuration of Offline FilesEnabled
Prevents users from changing any cache configuration settings.
PolicySettingComment
Remove "Make Available Offline" commandEnabled
Synchronize all offline files before logging offDisabled
Synchronize all offline files when logging onDisabled
Synchronize offline files before suspendDisabled
Turn off reminder balloonsEnabled
Printers
PolicySettingComment
Point and Print RestrictionsEnabled
Users can only point and print to these servers:Disabled
Enter fully qualified server names separated by semicolons
Users can only point and print to machines in their forestEnabled
Security Prompts:
When installing drivers for a new connection:Do not show warning or elevation prompt
When updating drivers for an existing connection:Do not show warning or elevation prompt
This setting only applies to:
Windows Vista and later
System
System/Group Policy
PolicySettingComment
Configure folder redirection policy processingEnabled
Allow processing across a slow network connectionEnabled
Process even if the Group Policy objects have not changedEnabled
PolicySettingComment
Configure Internet Explorer Maintenance policy processingEnabled
Allow processing across a slow network connectionEnabled
Do not apply during periodic background processingDisabled
Process even if the Group Policy objects have not changedEnabled
PolicySettingComment
Configure registry policy processingEnabled
Do not apply during periodic background processingDisabled
Process even if the Group Policy objects have not changedEnabled
System/Logon
System/Power Management
PolicySettingComment
Select an active power planEnabled
Active Power Plan:High Performance
System/Power Management/Button Settings
PolicySettingComment
Select the lid switch action (on battery)Enabled
Lid Switch ActionShut down
PolicySettingComment
Select the lid switch action (plugged in)Enabled
Lid Switch ActionShut down
PolicySettingComment
Select the Power button action (on battery)Enabled
Power Button ActionShut down
PolicySettingComment
Select the Power button action (plugged in)Enabled
Power Button ActionShut down
PolicySettingComment
Select the Sleep button action (on battery)Enabled
Sleep Button ActionShut down
PolicySettingComment
Select the Sleep button action (plugged in)Enabled
Sleep Button ActionShut down
PolicySettingComment
Select the Start menu Power button action (on battery)Enabled
User Interface Sleep Button ActionShut down
PolicySettingComment
Select the Start menu Power button action (plugged in)Enabled
User Interface Sleep Button ActionShut down
System/Power Management/Hard Disk Settings
System/Power Management/Notification Settings
PolicySettingComment
Turn off low battery user notificationDisabled
System/Remote Assistance
System/Scripts
System/System Restore
PolicySettingComment
Turn off ConfigurationEnabled
Turn off System RestoreEnabled
System/User Profiles
Windows Components/Application Compatibility
PolicySettingComment
Turn off Program Compatibility AssistantEnabled
Windows Components/AutoPlay Policies
PolicySettingComment
Turn off AutoplayEnabled
Turn off Autoplay on:All drives
Windows Components/Internet Explorer
PolicySettingComment
Prevent running First Run wizardEnabled
Select your choiceGo directly to home page
Windows Components/Internet Explorer/Internet Control Panel/Advanced Page
PolicySettingComment
Allow third-party browser extensionsDisabled
Windows Components/Internet Explorer/Internet Control Panel/Security Page
PolicySettingComment
Intranet Sites: Include all local (intranet) sites not listed in other zonesEnabled
Intranet Sites: Include all network paths (UNCs)Enabled
Site to Zone Assignment ListEnabled
Enter the zone assignments here. 
*.microlibrarian.net2
www.sunburymanor.surrey.sch.uk2
remote.sunburymanor.surrey.sch.uk2
adfs.sunburymanor.surrey.sch.uk 1
parsconnect.sunburymanor.surrey.sch.uk2
insight.sunburymanor.surrey.sch.uk2
PolicySettingComment
Turn on automatic detection of intranetDisabled
Windows Components/Internet Explorer/Internet Control Panel/Security Page/Internet Zone
PolicySettingComment
Access data sources across domainsEnabled
Access data sources across domainsEnable
PolicySettingComment
Display mixed contentEnabled
Display mixed contentEnable
Windows Components/NetMeeting
PolicySettingComment
Disable remote Desktop SharingEnabled
Windows Components/Remote Desktop Services/Remote Desktop Session Host/Connections
Windows Components/Remote Desktop Services/Remote Desktop Session Host/Security
Windows Components/Windows Defender
PolicySettingComment
Turn off routine remediationEnabled
Turn off Windows DefenderEnabled
Windows Components/Windows Defender/MAPS
PolicySettingComment
Join Microsoft MAPSEnabled
Join Microsoft MAPSDisabled
Windows Components/Windows Defender/Real-time Protection
PolicySettingComment
Turn off real-time protectionEnabled
Windows Components/Windows Media Player
Windows Components/Windows Mobility Center
PolicySettingComment
Turn off Windows Mobility CenterEnabled
Windows Components/Windows Remote Shell
PolicySettingComment
Allow Remote Shell AccessEnabled
Windows Components/Windows Update
PolicySettingComment
Allow Automatic Updates immediate installationEnabled
Allow signed updates from an intranet Microsoft update service location Enabled
Configure Automatic UpdatesEnabled
Configure automatic updating:4 - Auto download and schedule the install
The following settings are only required and applicable if 4 is selected.
Install during automatic maintenanceDisabled
Scheduled install day: 0 - Every day
Scheduled install time:03:00
PolicySettingComment
Do not adjust default option to 'Install Updates and Shut Down' in Shut Down Windows dialog boxDisabled
Do not display 'Install Updates and Shut Down' option in Shut Down Windows dialog boxDisabled
Enable client-side targetingEnabled
Target group name for this computerComputers
PolicySettingComment
No auto-restart with logged on users for scheduled automatic updates installationsEnabled
Reschedule Automatic Updates scheduled installationsEnabled
Wait after system
startup (minutes): 5
PolicySettingComment
Specify intranet Microsoft update service locationEnabled
Set the intranet update service for detecting updates:http://sms-updates:8530
Set the intranet statistics server:http://sms-updates:8530
(example: http://IntranetUpd01)
Extra Registry Settings
Display names for some settings cannot be found. You might be able to resolve this issue by updating the .ADM files used by Group Policy Management.

SettingState
Software\Policies\Google\Chrome\RestoreOnStartup4
Software\Policies\Google\Chrome\RestoreOnStartupURLs\1http://www.sunburymanor.surrey.sch.uk/index.phtml?d=1978931
Preferences
Windows Settings
Files
File (Target Path: C:\ProgramData\Microsoft\User Account Pictures\guest.bmp)
guest.bmp (Order: 1)
General
ActionReplace
Properties
Source file(s)\\Apgntnet.local\netlogon\CLS_WIN10\User Account Pictures\guest.bmp
Destination fileC:\ProgramData\Microsoft\User Account Pictures\guest.bmp
Suppress errors on individual file actionsDisabled
Attributes
Read-onlyDisabled
HiddenDisabled
ArchiveDisabled
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyYes
File (Target Path: C:\ProgramData\Microsoft\User Account Pictures\guest.png)
guest.png (Order: 2)
General
ActionReplace
Properties
Source file(s)\\Apgntnet.local\netlogon\CLS_WIN10\User Account Pictures\guest.png
Destination fileC:\ProgramData\Microsoft\User Account Pictures\guest.png
Suppress errors on individual file actionsDisabled
Attributes
Read-onlyDisabled
HiddenDisabled
ArchiveDisabled
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyYes
File (Target Path: C:\ProgramData\Microsoft\User Account Pictures\user.bmp)
user.bmp (Order: 3)
General
ActionReplace
Properties
Source file(s)\\Apgntnet.local\netlogon\CLS_WIN10\User Account Pictures\user.bmp
Destination fileC:\ProgramData\Microsoft\User Account Pictures\user.bmp
Suppress errors on individual file actionsDisabled
Attributes
Read-onlyDisabled
HiddenDisabled
ArchiveEnabled
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyYes
File (Target Path: C:\ProgramData\Microsoft\User Account Pictures\user-32.png)
user-32.png (Order: 4)
General
ActionReplace
Properties
Source file(s)\\Apgntnet.local\netlogon\CLS_WIN10\User Account Pictures\user-32.png
Destination fileC:\ProgramData\Microsoft\User Account Pictures\user-32.png
Suppress errors on individual file actionsDisabled
Attributes
Read-onlyDisabled
HiddenDisabled
ArchiveDisabled
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyYes
File (Target Path: C:\ProgramData\Microsoft\User Account Pictures\user-40.png)
user-40.png (Order: 5)
General
ActionReplace
Properties
Source file(s)\\Apgntnet.local\netlogon\CLS_WIN10\User Account Pictures\user-40.png
Destination fileC:\ProgramData\Microsoft\User Account Pictures\user-40.png
Suppress errors on individual file actionsDisabled
Attributes
Read-onlyDisabled
HiddenDisabled
ArchiveDisabled
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyYes
File (Target Path: C:\ProgramData\Microsoft\User Account Pictures\user-48.png)
user-48.png (Order: 6)
General
ActionReplace
Properties
Source file(s)\\Apgntnet.local\netlogon\CLS_WIN10\User Account Pictures\user-48.png
Destination fileC:\ProgramData\Microsoft\User Account Pictures\user-48.png
Suppress errors on individual file actionsDisabled
Attributes
Read-onlyDisabled
HiddenDisabled
ArchiveDisabled
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyYes
File (Target Path: C:\ProgramData\Microsoft\User Account Pictures\user-192.png)
user-192.png (Order: 7)
General
ActionReplace
Properties
Source file(s)\\Apgntnet.local\netlogon\CLS_WIN10\User Account Pictures\user-192.png
Destination fileC:\ProgramData\Microsoft\User Account Pictures\user-192.png
Suppress errors on individual file actionsDisabled
Attributes
Read-onlyDisabled
HiddenDisabled
ArchiveDisabled
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyYes
File (Target Path: C:\Windows\system32\oobe\info\backgrounds\backgroundDefault.jpg)
backgroundDefault.jpg (Order: 8)
General
ActionReplace
Properties
Source file(s)\\Apgntnet.local\netlogon\CLS_WIN10\backgroundDefault.jpg
Destination fileC:\Windows\system32\oobe\info\backgrounds\backgroundDefault.jpg
Suppress errors on individual file actionsDisabled
Attributes
Read-onlyDisabled
HiddenDisabled
ArchiveDisabled
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
File (Target Path: C:\Program Files (x86)\Sunbury Manor School\Roaming Icons\PARS .connect.exe)
PARS .connect.exe (Order: 9)
General
ActionUpdate
Properties
Source file(s)\\Apgntnet.local\netlogon\CLS_WIN10\Roaming Icons\PARS .connect.exe
Destination fileC:\Program Files (x86)\Sunbury Manor School\Roaming Icons\PARS .connect.exe
Suppress errors on individual file actionsDisabled
Attributes
Read-onlyDisabled
HiddenDisabled
ArchiveDisabled
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
File (Target Path: C:\Windows\Fonts\OpenDyslexic-Bold.otf)
OpenDyslexic-Bold.otf (Order: 10)
General
ActionCreate
Properties
Source file(s)\\Apgntnet.local\netlogon\CLS_WIN10\OpenDyslexic\OpenDyslexic-Bold.otf
Destination fileC:\Windows\Fonts\OpenDyslexic-Bold.otf
Attributes
Read-onlyDisabled
HiddenDisabled
ArchiveEnabled
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
File (Target Path: C:\Windows\Fonts\OpenDyslexic-BoldItalic.otf)
OpenDyslexic-BoldItalic.otf (Order: 11)
General
ActionCreate
Properties
Source file(s)\\Apgntnet.local\netlogon\CLS_WIN10\OpenDyslexic\OpenDyslexic-BoldItalic.otf
Destination fileC:\Windows\Fonts\OpenDyslexic-BoldItalic.otf
Attributes
Read-onlyDisabled
HiddenDisabled
ArchiveEnabled
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
File (Target Path: C:\Windows\Fonts\OpenDyslexic-Italic.otf)
OpenDyslexic-Italic.otf (Order: 12)
General
ActionCreate
Properties
Source file(s)\\Apgntnet.local\netlogon\CLS_WIN10\OpenDyslexic\OpenDyslexic-Italic.otf
Destination fileC:\Windows\Fonts\OpenDyslexic-Italic.otf
Attributes
Read-onlyDisabled
HiddenDisabled
ArchiveEnabled
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
File (Target Path: C:\Windows\Fonts\OpenDyslexic-Regular.otf)
OpenDyslexic-Regular.otf (Order: 13)
General
ActionCreate
Properties
Source file(s)\\Apgntnet.local\netlogon\CLS_WIN10\OpenDyslexic\OpenDyslexic-Regular.otf
Destination fileC:\Windows\Fonts\OpenDyslexic-Regular.otf
Attributes
Read-onlyDisabled
HiddenDisabled
ArchiveEnabled
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
File (Target Path: C:\Program Files (x86)\NetSupport\NetSupport School\nss_lock_image.jpg)
nss_lock_image.jpg (Order: 14)
General
ActionReplace
Properties
Source file(s)\\Apgntnet.local\netlogon\CLS_WIN10\nss_lock_image.jpg
Destination fileC:\Program Files (x86)\NetSupport\NetSupport School\nss_lock_image.jpg
Suppress errors on individual file actionsDisabled
Attributes
Read-onlyDisabled
HiddenDisabled
ArchiveEnabled
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
File (Target Path: C:\Program Files (x86)\NetSupport\NetSupport School\nss_lock_image_ws.jpg)
nss_lock_image_ws.jpg (Order: 15)
General
ActionReplace
Properties
Source file(s)\\Apgntnet.local\netlogon\CLS_WIN10\nss_lock_image_ws.jpg
Destination fileC:\Program Files (x86)\NetSupport\NetSupport School\nss_lock_image_ws.jpg
Suppress errors on individual file actionsDisabled
Attributes
Read-onlyDisabled
HiddenDisabled
ArchiveEnabled
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Registry
Wallpaper (Order: 1)
General
ActionUpdate
Properties
HiveHKEY_CURRENT_USER (HKU\.DEFAULT)
Key pathControl Panel\Desktop
Value nameWallpaper
Value typeREG_SZ
Value data\\Apgntnet.local\netlogon\CLS_WIN10\AllUsersDesktop.jpg
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
OpenDyslexic-Bold (Order: 2)
General
ActionCreate
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts
Value nameOpenDyslexic-Bold
Value typeREG_SZ
Value dataOpenDyslexic-Bold.otf
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
OpenDyslexic-BoldItalic (Order: 3)
General
ActionCreate
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts
Value nameOpenDyslexic-BoldItalic
Value typeREG_SZ
Value dataOpenDyslexic-BoldItalic.otf
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
OpenDyslexic-Italic (Order: 4)
General
ActionCreate
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts
Value nameOpenDyslexic-Italic
Value typeREG_SZ
Value dataOpenDyslexic-Italic.otf
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
OpenDyslexic-Regular (Order: 5)
General
ActionCreate
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts
Value nameOpenDyslexic-Regular
Value typeREG_SZ
Value dataOpenDyslexic-Regular.otf
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
SMARTInk64 (Order: 6)
General
ActionCreate
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value nameSMARTInk64
Value typeREG_SZ
Value data"C:\Program Files (x86)\SMART Technologies\SMART Product Drivers\SMARTink.exe"
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Control Panel Settings
Printers
Local Printer (Name: Fax)
Fax (Order: 1)
General
ActionDelete
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Apply once and do not reapplyNo
Local Printer (Name: Microsoft XPS Document Writer)
Microsoft XPS Document Writer (Order: 2)
General
ActionDelete
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Apply once and do not reapplyNo
Local Printer (Name: Send to OneNote 2013)
Send to OneNote 2013 (Order: 3)
General
ActionDelete
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Apply once and do not reapplyNo
Local Printer (Name: SMART Notebook Document Writer)
SMART Notebook Document Writer (Order: 4)
General
ActionDelete
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Apply once and do not reapplyNo
User Configuration (Disabled)
No settings defined.