win10-组策略-20240518

查看 92|回复 6
作者:心雨飞飞   
[color=]用LTSC2019的组策略导出的设置!
[color=]不要直接运行,自己挑选合适的使用!
[ol]Windows Registry Editor Version 5.00
;QOS吞吐级别3
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\QoS]
"Tcp Autotuning Level"="Normal"
;关闭网络通知
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\PushNotifications]
"NoCloudApplicationNotification"=dword:00000001
;阻止在此计算机上安装 Internet Information Services (IIS)
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\IIS]
"PreventIISInstall"=dword:00000001
;关闭动设备管理(MDM)注册
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\MDM]
"DisableRegistration"=dword:00000001
;禁用 NetMeeting 的远程桌面共享功能。用户将不能设置它或使用它来远程控制其计算机。
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Conferencing]
"NoRDS"=dword:00000001
;关闭流量计费的连接进行的 OneDrive 文件同步行为。
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\OneDrive]
"DisableMeteredNetworkFileSync"=dword:00000000
;启用此策略,隐私体验将不会对新创建的用户帐户或在升级后提示其选择隐私设置的帐户启动。
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\OOBE]
"DisablePrivacyExperience"=dword:00000001
;关闭在后台同步源和网页快讯的功能
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Feeds]
"BackgroundSyncStatus"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Feed Discovery]
"Enabled"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Feeds]
"DisableEnclosureDownload"=dword:00000001
"DisableAddRemove"=dword:00000001
"DisableFeedPane"=dword:00000001
"AllowBasicAuthInClear"=dword:00000001
;关闭 Windows Defender 防病毒程序
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender]
"DisableAntiSpyware"=dword:00000001
;禁用-将不会阻止用户和应用程序连接到危险域(0=关闭,1=阻止,2=审核)
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Windows Defender Exploit Guard\Network Protection]
"EnableNetworkProtection"=dword:00000000
;禁用Windows Defender 防病毒程序增强型通知将显示在客户端上。
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Reporting]
"DisableEnhancedNotifications"=dword:00000001
;反恶意软件服务会被停止
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender]
"ServiceKeepAlive"=dword:00000000
;不会加入 Microsoft MAPS
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet]
"SpynetReporting"=dword:00000000
;Windows Defender 防病毒程序通知将不会显示在客户端上。
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\UX Configuration]
"Notification_Suppress"=dword:00000001
"SuppressRebootNotification"=dword:00000001
;;路径排除项和进程排除项(禁用计划和实时扫描)
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions]
"Exclusions_Paths"=dword:00000001
"Exclusions_Processes"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths]
"d:\"="0"
"e:\"="0"
"f:\"="0"
"g:\"="0"
"z:\"="0"
;;排除进程示例
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Processes]
"c:\\windows\\explorer.exe"="0"
;扫描期间所允许 CPU 使用率的最大百分比。此设置的有效值为整数 5 到 100 表示的百分比。值为零(0)表示应对 CPU 使用率无限制。默认值为 50。
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Scan]
"AvgCPULoadFactor"=dword:00000032
;不会扫描存档文件(1=不,0=允许)
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Scan]
"DisableArchiveScanning"=dword:00000001
;不会扫描压缩的可执行文件
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Scan]
"DisablePackedExeScanning"=dword:00000001
;不会扫描可移动驱动器
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Scan]
"DisableRemovableDriveScanning"=dword:00000001
;不会扫描映射的网络驱动器
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Scan]
"DisableScanningMappedNetworkDrivesForFullScan"=dword:00000001
;不会扫描网络文件
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Scan]
"DisableScanningNetworkFiles"=dword:00000001
;当计算机处于打开但未使用状态运行计划扫描。
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Scan]
"ScanOnlyIfIdle"=dword:00000001
;关闭实时防护
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection]
"DisableRealtimeMonitoring"=dword:00000001
;不会在打开实时保护时启动进程扫描
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection]
"DisableScanOnRealtimeEnable"=dword:00000001
;关闭应用程序防护
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\AppHVSI]
"AllowAppHVSI"=dword:00000000
"AllowAppHVSI_ProviderSet"=dword:00000000
"AllowPersistence"=dword:00000000
"AllowVirtualGPU"=dword:00000000
"AuditApplicationGuard"=dword:00000000
"BlockNonEnterpriseContent"=dword:00000000
; 关闭Windows Ink 工作区
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsInkWorkspace]
"AllowSuggestedAppsInWindowsInkWorkspace"=dword:00000000
"AllowWindowsInkWorkspace"=dword:00000000
;将基线缓存大小设置为 0,则 Windows Installer 会停止为新的更新填充基线缓存。现有缓存的文件将保留在磁盘上,并会在删除产品时被删除。
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Installer]
"MaxPatchCacheSize"=dword:00000000
;阻止 Windows Media DRM 访问 Internet(或 Intranet)以获得授权或进行安全升级
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WMDRM]
"DisableOnline"=dword:00000001
;禁止 Windows Messenger 运行
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Messenger\Client]
"PreventAutoRun"=dword:00000001
"PreventRun"=dword:00000001
;禁用 Windows 错误报告
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Windows Error Reporting]
"Disabled"=dword:00000001
"AutoApproveOSDumps"=dword:00000000
"BypassNetworkCostThrottling"=dword:00000000
"BypassPowerThrottling"=dword:00000000
"LoggingDisabled"=dword:00000001
"DontSendAdditionalData"=dword:00000001
;关闭自动更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate]
"AllowAutoWindowsUpdateDownloadOverMeteredNetwork"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU]
"NoAUShutdownOption"=dword:00000001
"NoAutoUpdate"=dword:00000001
"AutoInstallMinorUpdates"=dword:00000000
;;启用此策略将禁用该功能,并且可能会导致 Windows 应用商店等公共服务连接中断。
;;注意:只有当配置此电脑使用“指定 Intranet Microsoft 更新服务位置”策略连接 Intranet 更新服务时才适用此策略
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate]
"DoNotConnectToWindowsUpdateInternetLocations"=dword:00000001
;暂停更新到2099
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate]
"ManagePreviewBuilds"=dword:00000001
"ManagePreviewBuildsPolicyValue"=dword:00000000
"DeferFeatureUpdates"=dword:00000001
"BranchReadinessLevel"=dword:00000032
"DeferFeatureUpdatesPeriodInDays"=dword:00000000
"PauseFeatureUpdatesStartTime"="2099-01-01"
"DeferQualityUpdates"=dword:00000001
"PauseQualityUpdatesStartTime"="2099-01-01"
;用 Windows 游戏录制和广播功能
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\GameDVR]
"AllowGameDVR"=dword:00000000
;禁止 Windows 向用户显示帮助提示
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\EdgeUI]
"DisableHelpSticker"=dword:00000001
;禁用此策略设置,用户将无法通过从屏幕边缘轻扫来调用系统 UI
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\EdgeUI]
"AllowEdgeSwipe"=dword:00000000
;传递优化,0=仅限 HTTP,无对等互连。
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DeliveryOptimization]
"DODownloadMode"=dword:00000000
;禁用地图数据
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Maps]
"AllowUntriggeredNetworkTrafficOnSettingsPage"=dword:00000000
"AutoDownloadAndUpdateMapData"=dword:00000000
;启用此策略设置,则用户无法将计算机添加到家庭组
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\HomeGroup]
"DisableHomeGroup"=dword:00000001
;使用此策略设置可以禁止投影到某台电脑。
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Connect]
"AllowProjectionToPC"=dword:00000001
;关闭-帮助查看器呈现包含活动元素(如“外壳执行”链接和“引导式帮助”链接)的受信任帮助内容。
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Assistance\Client\1.0]
"NoActiveHelp"=dword:00000001
;启用该策略设置,录音机将不会运行
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SoundRecorder]
"Soundrec"=dword:00000001
;拒绝向 Microsoft 自动发送 KMS 客户端激活数据。启用此设置可防止此计算机将有关其激活状态的数据发送给 Microsoft
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\Software Protection Platform]
"NoGenTicket"=dword:00000001
;诊断数据(遥测相关)
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection]
"LimitEnhancedDiagnosticDataWindowsAnalytics"=dword:00000000
"DisableTelemetryOptInChangeNotification"=dword:00000001
"DisableTelemetryOptInSettingsUx"=dword:00000001
"DisableEnterpriseAuthProxy"=dword:00000001
"AllowDeviceNameInTelemetry"=dword:00000000
"AllowTelemetry"=dword:00000000
;Cortana服务搜索相关设置
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Windows Search]
"DisableWebSearch"=dword:00000001
"PreventIndexingOutlook"=dword:00000001
"PreventIndexingEmailAttachments"=dword:00000001
"PreventIndexingPublicFolders"=dword:00000001
"PreventIndexingOfflineFiles"=dword:00000001
"DisableBackoff"=dword:00000001
"ConnectedSearchUseWebOverMeteredConnections"=dword:00000000
"ConnectedSearchUseWeb"=dword:00000000
"PreventIndexingLowDiskSpaceMB"=dword:00000000
"ConnectedSearchSafeSearch"=dword:00000003
"PreviewPaneLocation"=dword:00000003
"AllowCortana"=dword:00000000
"AllowSearchToUseLocation"=dword:00000000
"AllowCloudSearch"=dword:00000000
"AllowCortanaAboveLock"=dword:00000000
"AllowCortanaInAAD"=dword:00000001
"AllowCortanaInAADPathOOBE"=dword:00000000
"ConnectedSearchPrivacy"=dword:00000003
"HideUNCTab"=dword:00000001
"PreventRemoteQueries"=dword:00000001
"ExcludedExtensionsMultiline0"=".386;.aps;.bin;.bk1;.bk2;.bkf;.blf;.bsc;.btr;.cat;.cfg;.cgm;.chk;.ci;.crwl;.cur;.dat;.dbg;.dct;.dir;.dl_;.el;.evt;.ex_;.exp;.eyb;.fnt;.fon;.ghi;.gthr;.hqx;.icm;.idb;.idx;.ilk;.imc;.in_;.inl;.inv"
"ExcludedExtensionsMultiline1"=".ipp;.jbf;.lib;.local;.log;.log1;.log2;.m14;.mac;.man;.manifest;.map;.MAPIMail;.mmf;.mui;.muimanifest;.mv;.ncb;.obj;.oc_;.ocx;.onecache;.onetoc;.onetoc2;.ost;.pch;.pdb;.pds;.pf;.pic;.pma;.pmc;.pml"
"ExcludedExtensionsMultiline2"=".pmr;.pst;.res;.rmp;.rpc;.rsp;.sbr;.sc2;.sit;.sr_;.sy_;.sym;.TMCONTAINER00000000000000000001;.tlb;.tlh;.tmf;.tmp;.ttc;.ttf;.ttx;.TMCONTAINER00000000000000000002;.ufm;.vbx;.vxd;.wll;.wlt;.xbm;.xix;.z96;.ZFSendToTarget"
"ExcludedExtensionsMultiline3"=""
"PreventUsingAdvancedIndexingOptions"=dword:00000001
"PreventModifyingIndexedLocations"=dword:00000001
"PreventIndexOnBattery"=dword:00000001
"AutoIndexSharedFolders"=dword:00000001
;关闭并禁用电脑设置中的“同步你的设置”页上的“同步你的设置”切换开关。
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\SettingSync]
"DisableSettingSync"=dword:00000002
"DisableSettingSyncUserOverride"=dword:00000001
"DisablePersonalizationSettingSync"=dword:00000002
"DisablePersonalizationSettingSyncUserOverride"=dword:00000001
"DisableStartLayoutSettingSync"=dword:00000002
"DisableStartLayoutSettingSyncUserOverride"=dword:00000001
"DisableWebBrowserSettingSync"=dword:00000002
"DisableWebBrowserSettingSyncUserOverride"=dword:00000001
"DisableCredentialsSettingSync"=dword:00000002
"DisableCredentialsSettingSyncUserOverride"=dword:00000001
"DisableWindowsSettingSync"=dword:00000002
"DisableWindowsSettingSyncUserOverride"=dword:00000001
"DisableAppSyncSettingSync"=dword:00000002
"DisableAppSyncSettingSyncUserOverride"=dword:00000001
"DisableApplicationSettingSync"=dword:00000002
"DisableApplicationSettingSyncUserOverride"=dword:00000001
"DisableDesktopThemeSettingSync"=dword:00000002
"DisableDesktopThemeSettingSyncUserOverride"=dword:00000001
"DisableSyncOnPaidNetwork"=dword:00000001
;启用此设置,则用户将无法从其他设备或 Web 上运行的 Microsoft Store 中将应用推送到此设备。
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PushToInstall]
"DisablePushToInstall"=dword:00000001
;关闭文件历史记录
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\FileHistory]
"Disabled"=dword:00000001
;不会显示使用远程路径的文件快捷方式图标。
;注意: 允许使用文件快捷方式图标中的远程路径会使用户的计算机面临安全风险。
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Explorer]
"EnableShellShortcutIconRemotePath"=dword:00000000
;对于所有用户都将会关闭 SmartScreen
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System]
"EnableSmartScreen"=dword:00000000
;禁用相机设备(0=关闭,1=允许)
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Camera]
"AllowCamera"=dword:00000000
;关闭--将手机网络短信备份和还原到 Microsoft 的云服务
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Messaging]
"AllowMessageSync"=dword:00000000
;禁用步骤记录器
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\AppCompat]
"DisableUAR"=dword:00000001
;禁用应用程序遥测将停止收集使用情况的数据
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\AppCompat]
"AITEnable"=dword:00000000
;禁用清单收集器,并且不会将数据发送给 Microsoft。同时还会禁用通过程序兼容性助手收集安装数据。
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\AppCompat]
"DisableInventory"=dword:00000001
;关闭自动下载和安装应用更新-应用商店
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsStore]
"AutoDownload"=dword:00000002
;关闭--接收对语音识别和语音合成模型的更新
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Speech]
"AllowSpeechModelUpdate"=dword:00000000
;阻止向用户显示 Windows 使用技巧,不会再看到 Microsoft 提供的个性化建议以及有关其 Microsoft 帐户的通知。
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CloudContent]
"DisableSoftLanding"=dword:00000001
"DisableWindowsConsumerFeatures"=dword:00000001
;禁用窗口动画
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DWM]
"DisallowAnimations"=dword:00000001
;可关闭手写识别个性化的自动学习组件。
;自动学习能够收集和存储用户所写的文本和墨迹,以帮助手写识别适合用户的词汇和写作风格。
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\InputPersonalization]
"RestrictImplicitTextCollection"=dword:00000001
"RestrictImplicitInkCollection"=dword:00000001
;此策略设置确定 SMB 客户端是否允许在 SMB 服务器上进行不安全的来宾登录。
;禁用此策略设置,SMB 客户端将拒绝不安全的来宾登录
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\LanmanWorkstation]
"AllowInsecureGuestAuth"=dword:00000000
;QOS相关
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Psched]
"TimerResolution"=dword:0000000a
"MaxOutstandingSends"=dword:0000ffff
"NonBestEffortLimit"=dword:00000000
;禁用此策略设置,则 Windows 不会连接到联机字体提供程序,仅会枚举本地安装的字体。
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System]
"EnableFontProviders"=dword:00000000
;永不激活“系统状态数据”功能,关闭计算机时不显示“关闭事件跟踪程序”。
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Reliability]
"SnapShot"=dword:00000000
"ShutdownReasonOn"=dword:00000000
;限制Internet 通信设置
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\EventViewer]
"MicrosoftEventVwrDisableLinks"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\InternetManagement]
"RestrictCommunication"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Messenger\Client]
"CEIP"=dword:00000002
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting]
"DoReport"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PCHealth\HelpSvc]
"Headlines"=dword:00000000
"MicrosoftKBSearch"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SearchCompanion]
"DisableContentFileUpdates"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SQMClient\Windows]
"CEIPEnable"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\AuthRoot]
"DisableRootAutoUpdate"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DriverSearching]
"DontSearchWindowsUpdate"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\HandwritingErrorReports]
"PreventHandwritingErrorReports"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Internet Connection Wizard]
"ExitOnMSICW"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\NetworkConnectivityStatusIndicator]
"NoActiveProbe"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Registration Wizard Control]
"NoRegistration"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\TabletPC]
"PreventHandwritingDataSharing"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Windows Error Reporting]
"Disabled"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate]
"DisableWindowsUpdateAccess"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\Software Protection Platform]
"NoGenTicket"=dword:00000001
"AllowWindowsEntitlementReactivation"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Printers]
"DisableHTTPPrinting"=dword:00000001
"DisableWebPnPDownload"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsMovieMaker]
"WebHelp"=dword:00000001
"CodecDownload"=dword:00000001
"WebPublish"=dword:00000001
;禁用 Microsoft Application Virtualization (App-V)功能。需要重启才能使禁用生效。
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\AppV\Client]
"Enabled"=dword:00000000
;禁用此策略设置,则无法发布活动,并且 ActivityFeed 应该会禁用云同步。
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System]
"EnableActivityFeed"=dword:00000000
"PublishUserActivities"=dword:00000000
"AllowCrossDeviceClipboard"=dword:00000000
"UploadUserActivities"=dword:00000000
"AllowClipboardHistory"=dword:00000000
;登录到此服务器时不显示“初始配置任务”窗口。不会自动显示服务器管理器。
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Server\InitialConfigurationTasks]
"DoNotOpenAtLogon"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Server\ServerManager]
"DoNotOpenAtLogon"=dword:00000001
"RefreshIntervalEnabled"=dword:00000000
;阻止程序加载不受信任的字体
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\MitigationOptions]
"MitigationOptions_FontBocking"="1000000000000"[/ol]复制代码

策略, 用户, 数据

yousabuk   
谢谢分享
chenxuhua   
谢谢分享,很好
DOLLOR   
谢谢分享
七言V   
谢谢分享
um1ng   
真不错,谢谢楼主。的确是体力活。
七言V   
这个技术含量高,支持了。
您需要登录后才可以回帖 登录 | 立即注册

返回顶部