Jump to content

Recommended Posts

Posted

Is there any way to remove the Settings App from the Start Menu in 10, or at least prevent access to users?

 

I'm not keen on users having access to the proxy settings etc, but I can't find any find to lock it down as yet!

Posted
Tried to block it with software restriction policies but that doesn't work, systemsettings.exe is the one I blocked but all users can still get to it.
Posted
Nothing seems to work - SRP doesn't block it even when specified, there is no way in group policy and removing permissions from SystemSettings.exe breaks it for all users!
Posted

I can't work out how to remove the settings app from the start menu (I've been as far as process monitor attempting to find registry keys that get modified, searching for windows.immersivecontrolpanel_6.2.0.0_neutral_neutral_cw5n1h2txyewy etc. which is what the settings app refers to, but i can't find it)

 

For me though users don't get access to the settings, they click on it, settings appears briefly then instantly disappears (no settings are ever actually shown) so it's possible to lock your policies down so that it won't run, i can't suggest any specifics though as I'm not sure what setting(s) are preventing access for me.

Posted
Looks like you can use local or group policy to control the Start menu. User Configuration->Administrative Templates->Start Menu and Taskbar->Start Layout.
Posted
Looks like you can use local or group policy to control the Start menu. User Configuration->Administrative Templates->Start Menu and Taskbar->Start Layout.

 

This only allows you to layout the tiles, and unfortunately doesn't appear to allow any modification of the items to the left hand side of the tiles section.

Posted

The group policy to control the start tiles doesn't even work properly.

 

I've had some success blocking the settings app by simply creating a loop back policy for the windows 10 machines, with the permissions set so it doesn't apply to admins. Haven't got a way to let the staff access printers or other applets they have on w7 as the start tile group policy doesn't work!

Posted
The group policy to control the start tiles doesn't even work properly.

 

What problems are you getting with it? In terms of deploying a fixed layout to end users i've found it's been ok so long as i point the GP to an xml file on the local machine. It says it's meant to work with UNC paths but i can't seem to get it to work when i direct it to a layout on a server.

Posted
What problems are you getting with it? In terms of deploying a fixed layout to end users i've found it's been ok so long as i point the GP to an xml file on the local machine. It says it's meant to work with UNC paths but i can't seem to get it to work when i direct it to a layout on a server.

 

Well, that's exactly my problem, I want to deploy a centrally managed start menu like I could with previous systems!

 

I tried a local copy and it was the same result though, some tiles appeared, some didn't and the result was consistent. Weirdly Office were the least reliable to appear!

Posted (edited)
or at least prevent access to users?

Block the Settings app through AppLocker. I just tested it in a VM and this was the result...

 

http://vgy.me/Lq71Qc.png

 

http://vgy.me/qRsMqO.png

 

Note. Obviously you wouldn't block it for Everyone like I did above. :)

Edited by Arthur
  • Thanks 2
  • 2 months later...
Posted

Finally managed to get around to trying this, and even with Applock policies set like @Arthur has above - users can still open the Settings control panel.

 

I'm starting to think I'm using a different version of Windows 10 to everyone else, I cannot get even the basic working properly at the moment!

Posted

Talk about timing - I managed to work out why this wasn't working. The Application Identity service wasn't running.

 

I had it set to Automatic in the GPO but it still wasn't starting, hence Applocker failing to work. Manually reset the Service Security settings to Local Service and its now working!

Posted

Actually I haven't cracked it - every time I reboot the Application Identity service is reset to Manual, despite being set to Automatic in the GPO.

 

If I remotely start the service Applocker works, but I'm damned if I can find why its not starting automatically! I'll have to continue using SRP for the foreseeable.

Posted
every time I reboot the Application Identity service is reset to Manual, despite being set to Automatic in the GPO.

I start the service via GPP. Are you using the same method?

 

http://vgy.me/RiJp9A.png

Posted (edited)

I've tried both Machine policy and Preferences but its not working.

 

If I look at the results on the test PC I can see that none of the Services settings are being applied as there is a general error:

 

Group Policy Services failed due to the error listed below.

 

The system cannot find the path specified.

 

This is only happening on the W10 machine - all the W7 machines have their services managed by GPO and its working ok.

 

gpo.png

Edited by Sheridan

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...