Popular Post Arthur Posted April 6, 2017 Popular Post Posted April 6, 2017 Instead of preventing the Settings app from running with AppLocker, it is now possible to control which settings appear. The GPO is located here: Computer Configuration > Administrative Templates > Control Panel > [b]Settings Page Visibility[/b] The ability to control which pages in the Settings app are visible to users using either MDM or Group Policy via the Settings/PageVisibilityList setting. Blocked pages will not be visible in the app and, if all pages in a category are blocked, the category will be hidden as well. Reference: https://docs.microsoft.com/en-us/windows/uwp/launch-resume/launch-settings-app#ms-settings-uri-scheme-reference Before After (if for example you used "showonly:about" in the GPO, Settings would look like this) 8
refusal Posted April 6, 2017 Posted April 6, 2017 I can't find teh 1703 GP Admin Templates - are they generally available yet? If so have you got a link? Thanks so much!
Michael Posted April 6, 2017 Posted April 6, 2017 About time! As above, a link to GPOs would be awesome!
Arthur Posted April 6, 2017 Author Posted April 6, 2017 I can't find the 1703 GP Admin Templates - are they generally available yet? Sadly not. I haven't seen any download links to the new Group Policy templates.
KibosJ Posted April 6, 2017 Posted April 6, 2017 Sadly not. I haven't seen any download links to the new Group Policy templates. They can be extracted from the ISO, I've uploaded them here if you want them PolicyDefinitions.7z
Arthur Posted April 6, 2017 Author Posted April 6, 2017 Thanks @KibosJ. Are the ADM'S and ADMX'S not inside the ISO? There are some in C:\Windows\PolicyDefinitions, although I tend to wait until Microsoft release the downloadable version since there are more settings (for both Windows 10 and Server 2016).
Michael Posted April 6, 2017 Posted April 6, 2017 Be interesting to know whether this is a Redstone 2 or later requirement, or if it'll work on existing/older builds given they do have Settings of course.
KibosJ Posted April 6, 2017 Posted April 6, 2017 Be interesting to know whether this is a Redstone 2 or later requirement, or if it'll work on existing/older builds given they do have Settings of course. Looks like 1703 is a requirement, just tested it on a 1703 machine and a 1607 machine and it works fine on 1703 but nothing changes at all on 1607 2
Arthur Posted April 6, 2017 Author Posted April 6, 2017 (edited) if it'll work on existing/older builds given they do have Settings of course. Nope. See Microsoft's "What's New" blog post... https://blogs.technet.microsoft.com/windowsitpro/2017/04/05/whats-new-for-it-pros-in-the-windows-10-creators-update All of the new features will only apply to 1703 onwards (for obvious reasons). Edited April 6, 2017 by Arthur
3s-gtech Posted April 6, 2017 Posted April 6, 2017 So does this require loopback to be any real use? At least with Applocker you could specify groups. It'd be much easier to enable access to certain applets, but not being able to easily differentiate based on group is a real pain.
Arthur Posted April 6, 2017 Author Posted April 6, 2017 So does this require loopback to be any real use? I was initially thinking about having separate Settings app GPOs for staff and student PCs (since most of our staff wouldn't be logging into student computers), but if loopback works that would probably be a better solution.
ADMaster Posted May 2, 2017 Posted May 2, 2017 (edited) This seams like it should be in user configuration. Has anyone tested this with loopback yet? I've started my 1703 build and testing the new GPOs. Thanks, EDIT: loopback works for user settings against a computer, not the other way around. Edited May 2, 2017 by ADMaster
Michael Posted May 2, 2017 Posted May 2, 2017 Out of curiosity, previously if I installed Java (for example) this would install a Control Panel entry. Will it install a Settings entry?
Arthur Posted May 2, 2017 Author Posted May 2, 2017 Out of curiosity, previously if I installed Java (for example) this would install a Control Panel entry. Will it install a Settings entry? Nope. I don't think third-party developers can even add additional sections to Settings.
3s-gtech Posted May 2, 2017 Posted May 2, 2017 The Control Panel is still there, even if the link from Start is not (and some of the components have gone like Windows Update of course). We've just blocked Settings, but in theory a couple of the handy controls should still be accessible via the Control Panel.
ADMaster Posted May 3, 2017 Posted May 3, 2017 This being a computer setting effects admins too. I could not access add / remove programs, that's one of the things that moved out of the old control panel.
3s-gtech Posted May 3, 2017 Posted May 3, 2017 Programs and Features is still in the Control Panel in 1703. You can use either that or the Settings app.
ADMaster Posted May 3, 2017 Posted May 3, 2017 So it is, I was using the link in This PC titled uninstall or change program. This now goes to the settings app instead of the control panel.
Arthur Posted June 4, 2017 Author Posted June 4, 2017 This seems like it should be in user configuration. So does this require loopback to be any real use? At least with Applocker you could specify groups. It'd be much easier to enable access to certain applets, but not being able to easily differentiate based on group is a real pain. InTune has user-based Settings app restrictions. https://osddeployment.dk/2017/06/04/how-to-configure-windows-settings-app-with-intune Assign the profile to a group of users or devices
win Posted July 18, 2017 Posted July 18, 2017 Looks like 1703 is a requirement, just tested it on a 1703 machine and a 1607 machine and it works fine on 1703 but nothing changes at all on 1607 Is there something similar to remove 'settings' on 1607 via group policy?
Arthur Posted July 19, 2017 Author Posted July 19, 2017 Is there something similar to remove 'settings' on 1607 via group policy? AppLocker.
Chuckster Posted July 19, 2017 Posted July 19, 2017 For a list of all the command Settings: https://docs.microsoft.com/en-us/windows/uwp/launch-resume/launch-settings-app
win Posted July 23, 2017 Posted July 23, 2017 Putting this in a computer policy rather than user policy is a typical windows 10 half baked solution. Is there a workaround to get it to run for restricted users only, rather than all users on the computer?
3s-gtech Posted July 23, 2017 Posted July 23, 2017 Possibly will work by using security filtering in AD - got to be worth a try - but by being a computer policy it may not process this.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now