Sheridan Posted September 9, 2015 Posted September 9, 2015 Is there any way to remove the Settings App from the Start Menu in 10, or at least prevent access to users? I'm not keen on users having access to the proxy settings etc, but I can't find any find to lock it down as yet!
Sheridan Posted September 9, 2015 Author Posted September 9, 2015 Tried to block it with software restriction policies but that doesn't work, systemsettings.exe is the one I blocked but all users can still get to it.
Sheridan Posted September 10, 2015 Author Posted September 10, 2015 Nothing seems to work - SRP doesn't block it even when specified, there is no way in group policy and removing permissions from SystemSettings.exe breaks it for all users!
internetuser Posted September 15, 2015 Posted September 15, 2015 Any update on this ? They seem to get full run of the settings, which isnt good.
mrbios Posted September 16, 2015 Posted September 16, 2015 I can't work out how to remove the settings app from the start menu (I've been as far as process monitor attempting to find registry keys that get modified, searching for windows.immersivecontrolpanel_6.2.0.0_neutral_neutral_cw5n1h2txyewy etc. which is what the settings app refers to, but i can't find it) For me though users don't get access to the settings, they click on it, settings appears briefly then instantly disappears (no settings are ever actually shown) so it's possible to lock your policies down so that it won't run, i can't suggest any specifics though as I'm not sure what setting(s) are preventing access for me.
disk Posted September 16, 2015 Posted September 16, 2015 Looks like you can use local or group policy to control the Start menu. User Configuration->Administrative Templates->Start Menu and Taskbar->Start Layout.
mrbios Posted September 16, 2015 Posted September 16, 2015 Looks like you can use local or group policy to control the Start menu. User Configuration->Administrative Templates->Start Menu and Taskbar->Start Layout. This only allows you to layout the tiles, and unfortunately doesn't appear to allow any modification of the items to the left hand side of the tiles section.
Sheridan Posted September 16, 2015 Author Posted September 16, 2015 The group policy to control the start tiles doesn't even work properly. I've had some success blocking the settings app by simply creating a loop back policy for the windows 10 machines, with the permissions set so it doesn't apply to admins. Haven't got a way to let the staff access printers or other applets they have on w7 as the start tile group policy doesn't work!
mrbios Posted September 16, 2015 Posted September 16, 2015 The group policy to control the start tiles doesn't even work properly. What problems are you getting with it? In terms of deploying a fixed layout to end users i've found it's been ok so long as i point the GP to an xml file on the local machine. It says it's meant to work with UNC paths but i can't seem to get it to work when i direct it to a layout on a server.
Sheridan Posted September 16, 2015 Author Posted September 16, 2015 What problems are you getting with it? In terms of deploying a fixed layout to end users i've found it's been ok so long as i point the GP to an xml file on the local machine. It says it's meant to work with UNC paths but i can't seem to get it to work when i direct it to a layout on a server. Well, that's exactly my problem, I want to deploy a centrally managed start menu like I could with previous systems! I tried a local copy and it was the same result though, some tiles appeared, some didn't and the result was consistent. Weirdly Office were the least reliable to appear!
Arthur Posted September 16, 2015 Posted September 16, 2015 some tiles appeared, some didn't and the result was consistent. The current Start menu is a bit buggy... http://www.neowin.net/news/windows-10-start-menu-cant-handle-more-than-512-items
Sheridan Posted September 16, 2015 Author Posted September 16, 2015 No way have I got 512 items! Must be less than 100. The start menu seems to be working,but the tiles layout is junked.
Arthur Posted September 16, 2015 Posted September 16, 2015 (edited) or at least prevent access to users? Block the Settings app through AppLocker. I just tested it in a VM and this was the result... http://vgy.me/Lq71Qc.png http://vgy.me/qRsMqO.png Note. Obviously you wouldn't block it for Everyone like I did above. Edited September 16, 2015 by Arthur 2
Sheridan Posted September 17, 2015 Author Posted September 17, 2015 Good idea, I'm moving to Applocker anyway so the Publisher option isn't one I'd thought of.
Sheridan Posted November 18, 2015 Author Posted November 18, 2015 Finally managed to get around to trying this, and even with Applock policies set like @Arthur has above - users can still open the Settings control panel. I'm starting to think I'm using a different version of Windows 10 to everyone else, I cannot get even the basic working properly at the moment!
Sheridan Posted November 18, 2015 Author Posted November 18, 2015 Talk about timing - I managed to work out why this wasn't working. The Application Identity service wasn't running. I had it set to Automatic in the GPO but it still wasn't starting, hence Applocker failing to work. Manually reset the Service Security settings to Local Service and its now working!
Arthur Posted November 18, 2015 Posted November 18, 2015 The Application Identity service wasn't running. I was just about to suggest checking that.
Sheridan Posted November 18, 2015 Author Posted November 18, 2015 Actually I haven't cracked it - every time I reboot the Application Identity service is reset to Manual, despite being set to Automatic in the GPO. If I remotely start the service Applocker works, but I'm damned if I can find why its not starting automatically! I'll have to continue using SRP for the foreseeable.
Arthur Posted November 18, 2015 Posted November 18, 2015 every time I reboot the Application Identity service is reset to Manual, despite being set to Automatic in the GPO. I start the service via GPP. Are you using the same method? http://vgy.me/RiJp9A.png
Sheridan Posted November 18, 2015 Author Posted November 18, 2015 (edited) I've tried both Machine policy and Preferences but its not working. If I look at the results on the test PC I can see that none of the Services settings are being applied as there is a general error: Group Policy Services failed due to the error listed below. The system cannot find the path specified. This is only happening on the W10 machine - all the W7 machines have their services managed by GPO and its working ok. Edited November 18, 2015 by Sheridan
cybergoldfish Posted November 18, 2015 Posted November 18, 2015 We've just blocked it with the following GPO: User Config -> Admin Templates -> Control Panel -> Prohibit Access to Control Panel and PC Settings
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now