JoeCav Posted December 14, 2016 Posted December 14, 2016 Hi I've attached images of how the policy is set here. [ATTACH=CONFIG]40296[/ATTACH][ATTACH=CONFIG]40297[/ATTACH][ATTACH=CONFIG]40298[/ATTACH] My policy is the same but it's not restricting it, just to confirm this policy blocks you from being able to type command lines into search (in the start menu)? like for example I can open the start menu on a student device and login type in cmd, powershell, gpupdate, etc.. and I get the option to run the command directly from there even though it's blocked elsewhere. Thanks so much for your help.
KibosJ Posted December 14, 2016 Posted December 14, 2016 My policy is the same but it's not restricting it, just to confirm this policy blocks you from being able to type command lines into search (in the start menu)? like for example I can open the start menu on a student device and login type in cmd, powershell, gpupdate, etc.. and I get the option to run the command directly from there even though it's blocked elsewhere. Thanks so much for your help. That's strange. With this set, when I log in and type anything into the start menu nothing happens at all. Unless Microsoft have changed something, this is still on 1511, are you on 1607 yet?
JoeCav Posted December 14, 2016 Posted December 14, 2016 That's strange. With this set, when I log in and type anything into the start menu nothing happens at all. Unless Microsoft have changed something, this is still on 1511, are you on 1607 yet? Oh that might be it, we're using 1607 Enterprise over here. I've got 1511 somewhere, I'll try image a computer with this version to confirm if this is the problem.
atechguy Posted December 14, 2016 Author Posted December 14, 2016 you can set a policy just to disable CMD from running commands, The CMD windows still open but just has a message saying you need to be an admin. as for powershell ive not looked if running .ps scripts can be disabled by group policy.
KibosJ Posted December 15, 2016 Posted December 15, 2016 I've just imaged a machine with our new 1607 image and search is blocked there too. I've been looking through my GPOs and found this one, not sure if it makes any difference though. Computer Configuration>Policies>Administrative Templates>Windows Components>Search>Allow Cortana. I also have a GPO that turns off the Windows Search service for students These settings below are also set:
alex17pat Posted August 1, 2017 Posted August 1, 2017 I prefer run commands over other ways as it seems faster to me. Hereare some run commands which I use daily for opening various windowsapplications . On screen Keyboard – osk Calculator – calc WordPad – write Windows Media Player – wmplayer Windows Fax and Scan – wfs Snipping Tools – snippingtool Paint – mspaint Notepad – notepad Task manager – taskmgrt/ Sticky Notes – stikyno source: -http://merabheja.com/101-windows-10-run-commands-shortcuts-to-find-hidden-features/
sonofsanta Posted July 9, 2018 Posted July 9, 2018 Bit of a necro, as Google has just dug this thread up for me... but it seems that even though the Group Policy is deprecated (WHYYYYY, MICROSOFT, WHY SO MANY STUPID ENTERPRISE DECISIONS IN WIN10, WHY DO YOU HATE SYSADMINS SO MUCH), the underlying reg key still works. I've added this registry key as a GPP item in my user policy: The full path is HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer That blocks Win+R and takes it off the Start Menu, as it should, as it used to. Of course, this just makes it all the more mystifying--if the underlying mechanism is still present and working, why deprecate the GPO? It's because you hate sysadmins, isn't it. Argh. (This is on 1803, btw.)
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now