Policy CSP - ADMX_ICM
Tip
This CSP contains ADMX-backed policies which require a special SyncML format to enable or disable. You must specify the data type in the SyncML as <Format>chr</Format>
. For details, see Understanding ADMX-backed policies.
The payload of the SyncML must be XML-encoded; for this XML encoding, there are a variety of online encoders that you can use. To avoid encoding the payload, you can use CDATA if your MDM supports it. For more information, see CDATA Sections.
CEIPEnable
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_ICM/CEIPEnable
This policy setting turns off the Windows Customer Experience Improvement Program. The Windows Customer Experience Improvement Program collects information about your hardware configuration and how you use our software and services to identify trends and usage patterns. Microsoft won't collect your name, address, or any other personally identifiable information. There are no surveys to complete, no salesperson will call, and you can continue working without interruption. It's simple and user-friendly.
If you enable this policy setting, all users are opted out of the Windows Customer Experience Improvement Program.
If you disable this policy setting, all users are opted into the Windows Customer Experience Improvement Program.
If you don't configure this policy setting, the administrator can use the Problem Reports and Solutions component in Control Panel to enable Windows Customer Experience Improvement Program for all users.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | CEIPEnable |
Friendly Name | Turn off Windows Customer Experience Improvement Program |
Location | Computer Configuration |
Path | InternetManagement > Internet Communication settings |
Registry Key Name | Software\Policies\Microsoft\SQMClient\Windows |
Registry Value Name | CEIPEnable |
ADMX File Name | ICM.admx |
CertMgr_DisableAutoRootUpdates
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_ICM/CertMgr_DisableAutoRootUpdates
This policy setting specifies whether to automatically update root certificates using the Windows Update website.
Typically, a certificate is used when you use a secure website or when you send and receive secure email. Anyone can issue certificates, but to have transactions that are as secure as possible, certificates must be issued by a trusted certificate authority (CA). Microsoft has included a list in Windows XP and other products of companies and organizations that it considers trusted authorities.
If you enable this policy setting, when you are presented with a certificate issued by an untrusted root authority, your computer won't contact the Windows Update website to see if Microsoft has added the CA to its list of trusted authorities.
If you disable or don't configure this policy setting, your computer will contact the Windows Update website.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | CertMgr_DisableAutoRootUpdates |
Friendly Name | Turn off Automatic Root Certificates Update |
Location | Computer Configuration |
Path | InternetManagement > Internet Communication settings |
Registry Key Name | Software\Policies\Microsoft\SystemCertificates\AuthRoot |
Registry Value Name | DisableRootAutoUpdate |
ADMX File Name | ICM.admx |
DisableHTTPPrinting_1
Scope | Editions | Applicable OS |
---|---|---|
❌ Device ✅ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./User/Vendor/MSFT/Policy/Config/ADMX_ICM/DisableHTTPPrinting_1
This policy setting specifies whether to allow printing over HTTP from this client.
Printing over HTTP allows a client to print to printers on the intranet as well as the Internet.
Note
This policy setting affects the client side of Internet printing only. It doesn't prevent this computer from acting as an Internet Printing server and making its shared printers available via HTTP.
If you enable this policy setting, it prevents this client from printing to Internet printers over HTTP.
If you disable or don't configure this policy setting, users can choose to print to Internet printers over HTTP.
Also, see the "Web-based printing" policy setting in Computer Configuration/Administrative Templates/Printers.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | DisableHTTPPrinting_1 |
Friendly Name | Turn off printing over HTTP |
Location | User Configuration |
Path | InternetManagement > Internet Communication settings |
Registry Key Name | Software\Policies\Microsoft\Windows NT\Printers |
Registry Value Name | DisableHTTPPrinting |
ADMX File Name | ICM.admx |
DisableWebPnPDownload_1
Scope | Editions | Applicable OS |
---|---|---|
❌ Device ✅ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./User/Vendor/MSFT/Policy/Config/ADMX_ICM/DisableWebPnPDownload_1
This policy setting specifies whether to allow this client to download print driver packages over HTTP.
To set up HTTP printing, non-inbox drivers need to be downloaded over HTTP.
Note
This policy setting doesn't prevent the client from printing to printers on the Intranet or the Internet over HTTP. It only prohibits downloading drivers that aren't already installed locally.
If you enable this policy setting, print drivers can't be downloaded over HTTP.
If you disable or don't configure this policy setting, users can download print drivers over HTTP.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | DisableWebPnPDownload_1 |
Friendly Name | Turn off downloading of print drivers over HTTP |
Location | User Configuration |
Path | InternetManagement > Internet Communication settings |
Registry Key Name | Software\Policies\Microsoft\Windows NT\Printers |
Registry Value Name | DisableWebPnPDownload |
ADMX File Name | ICM.admx |
DriverSearchPlaces_DontSearchWindowsUpdate
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_ICM/DriverSearchPlaces_DontSearchWindowsUpdate
This policy setting specifies whether Windows searches Windows Update for device drivers when no local drivers for a device are present.
If you enable this policy setting, Windows Update isn't searched when a new device is installed.
If you disable this policy setting, Windows Update is always searched for drivers when no local drivers are present.
If you don't configure this policy setting, searching Windows Update is optional when installing a device.
Also see "Turn off Windows Update device driver search prompt" in "Administrative Templates/System," which governs whether an administrator is prompted before searching Windows Update for device drivers if a driver isn't found locally.
Note
This policy setting is replaced by "Specify Driver Source Search Order" in "Administrative Templates/System/Device Installation" on newer versions of Windows.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | DriverSearchPlaces_DontSearchWindowsUpdate |
Friendly Name | Turn off Windows Update device driver searching |
Location | Computer Configuration |
Path | InternetManagement > Internet Communication settings |
Registry Key Name | Software\Policies\Microsoft\Windows\DriverSearching |
Registry Value Name | DontSearchWindowsUpdate |
ADMX File Name | ICM.admx |
EventViewer_DisableLinks
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_ICM/EventViewer_DisableLinks
This policy setting specifies whether "Events.asp" hyperlinks are available for events within the Event Viewer application.
The Event Viewer normally makes all HTTP(S) URLs into hyperlinks that activate the Internet browser when clicked. In addition, "More Information" is placed at the end of the description text if the event is created by a Microsoft component. This text contains a link (URL) that, if clicked, sends information about the event to Microsoft, and allows users to learn more about why that event occurred.
If you enable this policy setting, event description hyperlinks aren't activated and the text "More Information" isn't displayed at the end of the description.
If you disable or don't configure this policy setting, the user can click the hyperlink, which prompts the user and then sends information about the event over the Internet to Microsoft. Also, see "Events.asp URL", "Events.asp program", and "Events.asp Program Command Line Parameters" settings in "Administrative Templates/Windows Components/Event Viewer".
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | EventViewer_DisableLinks |
Friendly Name | Turn off Event Viewer "Events.asp" links |
Location | Computer Configuration |
Path | InternetManagement > Internet Communication settings |
Registry Key Name | Software\Policies\Microsoft\EventViewer |
Registry Value Name | MicrosoftEventVwrDisableLinks |
ADMX File Name | ICM.admx |
HSS_HeadlinesPolicy
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_ICM/HSS_HeadlinesPolicy
This policy setting specifies whether to show the "Did you know?" section of Help and Support Center.
This content is dynamically updated when users who are connected to the Internet open Help and Support Center, and provides up-to-date information about Windows and the computer.
If you enable this policy setting, the Help and Support Center no longer retrieves nor displays "Did you know?" content.
If you disable or don't configure this policy setting, the Help and Support Center retrieves and displays "Did you know?" content.
You might want to enable this policy setting for users who don't have Internet access, because the content in the "Did you know?" section will remain static indefinitely without an Internet connection.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | HSS_HeadlinesPolicy |
Friendly Name | Turn off Help and Support Center "Did you know?" content |
Location | Computer Configuration |
Path | InternetManagement > Internet Communication settings |
Registry Key Name | Software\Policies\Microsoft\PCHealth\HelpSvc |
Registry Value Name | Headlines |
ADMX File Name | ICM.admx |
HSS_KBSearchPolicy
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_ICM/HSS_KBSearchPolicy
This policy setting specifies whether users can perform a Microsoft Knowledge Base search from the Help and Support Center.
The Knowledge Base is an online source of technical support information and self-help tools for Microsoft products, and is searched as part of all Help and Support Center searches with the default search options.
If you enable this policy setting, it removes the Knowledge Base section from the Help and Support Center "Set search options" page, and only Help content on the local computer is searched.
If you disable or don't configure this policy setting, the Knowledge Base is searched if the user has a connection to the Internet and hasn't disabled the Knowledge Base search from the Search Options page.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | HSS_KBSearchPolicy |
Friendly Name | Turn off Help and Support Center Microsoft Knowledge Base search |
Location | Computer Configuration |
Path | InternetManagement > Internet Communication settings |
Registry Key Name | Software\Policies\Microsoft\PCHealth\HelpSvc |
Registry Value Name | MicrosoftKBSearch |
ADMX File Name | ICM.admx |
InternetManagement_RestrictCommunication_1
Scope | Editions | Applicable OS |
---|---|---|
❌ Device ✅ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./User/Vendor/MSFT/Policy/Config/ADMX_ICM/InternetManagement_RestrictCommunication_1
This policy setting specifies whether Windows can access the Internet to accomplish tasks that require Internet resources.
If you enable this setting, all of the policy settings listed in the "Internet Communication settings" section are set such that their respective features can't access the Internet.
If you disable this policy setting, all of the policy settings listed in the "Internet Communication settings" section are set such that their respective features can access the Internet.
If you don't configure this policy setting, all of the policy settings in the "Internet Communication settings" section are set to not configured.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | InternetManagement_RestrictCommunication_1 |
Friendly Name | Restrict Internet communication |
Location | User Configuration |
Path | System > Internet Communication Management |
Registry Key Name | Software\Policies\Microsoft\InternetManagement |
Registry Value Name | RestrictCommunication |
ADMX File Name | ICM.admx |
InternetManagement_RestrictCommunication_2
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_ICM/InternetManagement_RestrictCommunication_2
This policy setting specifies whether Windows can access the Internet to accomplish tasks that require Internet resources.
If you enable this setting, all of the policy settings listed in the "Internet Communication settings" section are set such that their respective features can't access the Internet.
If you disable this policy setting, all of the policy settings listed in the "Internet Communication settings" section are set such that their respective features can access the Internet.
If you don't configure this policy setting, all of the policy settings in the "Internet Communication settings" section are set to not configured.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | InternetManagement_RestrictCommunication_2 |
Friendly Name | Restrict Internet communication |
Location | Computer Configuration |
Path | System > Internet Communication Management |
Registry Key Name | Software\Policies\Microsoft\InternetManagement |
Registry Value Name | RestrictCommunication |
ADMX File Name | ICM.admx |
NC_ExitOnISP
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_ICM/NC_ExitOnISP
This policy setting specifies whether the Internet Connection Wizard can connect to Microsoft to download a list of Internet Service Providers (ISPs).
If you enable this policy setting, the "Choose a list of Internet Service Providers" path in the Internet Connection Wizard causes the wizard to exit. This prevents users from retrieving the list of ISPs, which resides on Microsoft servers.
If you disable or don't configure this policy setting, users can connect to Microsoft to download a list of ISPs for their area.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | NC_ExitOnISP |
Friendly Name | Turn off Internet Connection Wizard if URL connection is referring to Microsoft.com |
Location | Computer Configuration |
Path | InternetManagement > Internet Communication settings |
Registry Key Name | Software\Policies\Microsoft\Windows\Internet Connection Wizard |
Registry Value Name | ExitOnMSICW |
ADMX File Name | ICM.admx |
NC_NoRegistration
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_ICM/NC_NoRegistration
This policy setting specifies whether the Windows Registration Wizard connects to Microsoft.com for online registration.
If you enable this policy setting, it blocks users from connecting to Microsoft.com for online registration and users can't register their copy of Windows online.
If you disable or don't configure this policy setting, users can connect to Microsoft.com to complete the online Windows Registration.
Note that registration is optional and involves submitting some personal information to Microsoft. However, Windows Product Activation is required but doesn't involve submitting any personal information (except the country/region you live in).
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | NC_NoRegistration |
Friendly Name | Turn off Registration if URL connection is referring to Microsoft.com |
Location | Computer Configuration |
Path | InternetManagement > Internet Communication settings |
Registry Key Name | Software\Policies\Microsoft\Windows\Registration Wizard Control |
Registry Value Name | NoRegistration |
ADMX File Name | ICM.admx |
PCH_DoNotReport
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_ICM/PCH_DoNotReport
This policy setting controls whether or not errors are reported to Microsoft.
Error Reporting is used to report information about a system or application that has failed or has stopped responding and is used to improve the quality of the product.
If you enable this policy setting, users aren't given the option to report errors.
If you disable or don't configure this policy setting, the errors may be reported to Microsoft via the Internet or to a corporate file share.
This policy setting overrides any user setting made from the Control Panel for error reporting.
Also see the "Configure Error Reporting", "Display Error Notification" and "Disable Windows Error Reporting" policy settings under Computer Configuration/Administrative Templates/Windows Components/Windows Error Reporting.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | PCH_DoNotReport |
Friendly Name | Turn off Windows Error Reporting |
Location | Computer Configuration |
Path | InternetManagement > Internet Communication settings |
Registry Key Name | Software\Policies\Microsoft\PCHealth\ErrorReporting |
ADMX File Name | ICM.admx |
RemoveWindowsUpdate_ICM
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_ICM/RemoveWindowsUpdate_ICM
This policy setting allows you to remove access to Windows Update.
If you enable this policy setting, all Windows Update features are removed. This includes blocking access to the Windows Update website at
https://windowsupdate.microsoft.com
, from the Windows Update hyperlink on the Start menu, and also on the Tools menu in Internet Explorer. Windows automatic updating is also disabled; you'll neither be notified about nor will you receive critical updates from Windows Update. This policy setting also prevents Device Manager from automatically installing driver updates from the Windows Update website.If you disable or don't configure this policy setting, users can access the Windows Update website and enable automatic updating to receive notifications and critical updates from Windows Update.
Note
This policy applies only when this PC is configured to connect to an intranet update service using the "Specify intranet Microsoft update service location" policy.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | RemoveWindowsUpdate_ICM |
Friendly Name | Turn off access to all Windows Update features |
Location | Computer Configuration |
Path | InternetManagement > Internet Communication settings |
Registry Key Name | Software\Policies\Microsoft\Windows\WindowsUpdate |
Registry Value Name | DisableWindowsUpdateAccess |
ADMX File Name | ICM.admx |
SearchCompanion_DisableFileUpdates
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_ICM/SearchCompanion_DisableFileUpdates
This policy setting specifies whether Search Companion should automatically download content updates during local and Internet searches.
When users search the local computer or the Internet, Search Companion occasionally connects to Microsoft to download an updated privacy policy and additional content files used to format and display results.
If you enable this policy setting, Search Companion doesn't download content updates during searches.
If you disable or don't configure this policy setting, Search Companion downloads content updates unless the user is using Classic Search.
Note
Internet searches still send the search text and information about the search to Microsoft and the chosen search provider. Choosing Classic Search turns off the Search Companion feature completely.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | SearchCompanion_DisableFileUpdates |
Friendly Name | Turn off Search Companion content file updates |
Location | Computer Configuration |
Path | InternetManagement > Internet Communication settings |
Registry Key Name | Software\Policies\Microsoft\SearchCompanion |
Registry Value Name | DisableContentFileUpdates |
ADMX File Name | ICM.admx |
ShellNoUseInternetOpenWith_1
Scope | Editions | Applicable OS |
---|---|---|
❌ Device ✅ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./User/Vendor/MSFT/Policy/Config/ADMX_ICM/ShellNoUseInternetOpenWith_1
This policy setting specifies whether to use the Microsoft Web service for finding an application to open a file with an unhandled file association.
When a user opens a file that has an extension that isn't associated with any applications on the computer, the user is given the choice to select a local application or use the Web service to find an application.
If you enable this policy setting, the link and the dialog for using the Web service to open an unhandled file association are removed.
If you disable or don't configure this policy setting, the user is allowed to use the Web service.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | ShellNoUseInternetOpenWith_1 |
Friendly Name | Turn off Internet File Association service |
Location | User Configuration |
Path | InternetManagement > Internet Communication settings |
Registry Key Name | Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
Registry Value Name | NoInternetOpenWith |
ADMX File Name | ICM.admx |
ShellNoUseInternetOpenWith_2
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_ICM/ShellNoUseInternetOpenWith_2
This policy setting specifies whether to use the Microsoft Web service for finding an application to open a file with an unhandled file association.
When a user opens a file that has an extension that isn't associated with any applications on the computer, the user is given the choice to select a local application or use the Web service to find an application.
If you enable this policy setting, the link and the dialog for using the Web service to open an unhandled file association are removed.
If you disable or don't configure this policy setting, the user is allowed to use the Web service.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | ShellNoUseInternetOpenWith_2 |
Friendly Name | Turn off Internet File Association service |
Location | Computer Configuration |
Path | InternetManagement > Internet Communication settings |
Registry Key Name | Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
Registry Value Name | NoInternetOpenWith |
ADMX File Name | ICM.admx |
ShellNoUseStoreOpenWith_1
Scope | Editions | Applicable OS |
---|---|---|
❌ Device ✅ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./User/Vendor/MSFT/Policy/Config/ADMX_ICM/ShellNoUseStoreOpenWith_1
This policy setting specifies whether to use the Store service for finding an application to open a file with an unhandled file type or protocol association.
When a user opens a file type or protocol that isn't associated with any applications on the computer, the user is given the choice to select a local application or use the Store service to find an application.
If you enable this policy setting, the "Look for an app in the Store" item in the Open With dialog is removed.
If you disable or don't configure this policy setting, the user is allowed to use the Store service and the Store item is available in the Open With dialog.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | ShellNoUseStoreOpenWith_1 |
Friendly Name | Turn off access to the Store |
Location | User Configuration |
Path | InternetManagement > Internet Communication settings |
Registry Key Name | Software\Policies\Microsoft\Windows\Explorer |
Registry Value Name | NoUseStoreOpenWith |
ADMX File Name | ICM.admx |
ShellNoUseStoreOpenWith_2
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_ICM/ShellNoUseStoreOpenWith_2
This policy setting specifies whether to use the Store service for finding an application to open a file with an unhandled file type or protocol association.
When a user opens a file type or protocol that isn't associated with any applications on the computer, the user is given the choice to select a local application or use the Store service to find an application.
If you enable this policy setting, the "Look for an app in the Store" item in the Open With dialog is removed.
If you disable or don't configure this policy setting, the user is allowed to use the Store service and the Store item is available in the Open With dialog.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | ShellNoUseStoreOpenWith_2 |
Friendly Name | Turn off access to the Store |
Location | Computer Configuration |
Path | InternetManagement > Internet Communication settings |
Registry Key Name | Software\Policies\Microsoft\Windows\Explorer |
Registry Value Name | NoUseStoreOpenWith |
ADMX File Name | ICM.admx |
ShellPreventWPWDownload_1
Scope | Editions | Applicable OS |
---|---|---|
❌ Device ✅ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./User/Vendor/MSFT/Policy/Config/ADMX_ICM/ShellPreventWPWDownload_1
This policy setting specifies whether Windows should download a list of providers for the web publishing and online ordering wizards.
These wizards allow users to select from a list of companies that provide services such as online storage and photographic printing. By default, Windows displays providers downloaded from a Windows website in addition to providers specified in the registry.
If you enable this policy setting, Windows doesn't download providers, and only the service providers that are cached in the local registry are displayed.
If you disable or don't configure this policy setting, a list of providers are downloaded when the user uses the web publishing or online ordering wizards.
See the documentation for the web publishing and online ordering wizards for more information, including details on specifying service providers in the registry.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | ShellPreventWPWDownload_1 |
Friendly Name | Turn off Internet download for Web publishing and online ordering wizards |
Location | User Configuration |
Path | InternetManagement > Internet Communication settings |
Registry Key Name | Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
Registry Value Name | NoWebServices |
ADMX File Name | ICM.admx |
ShellRemoveOrderPrints_1
Scope | Editions | Applicable OS |
---|---|---|
❌ Device ✅ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./User/Vendor/MSFT/Policy/Config/ADMX_ICM/ShellRemoveOrderPrints_1
This policy setting specifies whether the "Order Prints Online" task is available from Picture Tasks in Windows folders.
The Order Prints Online Wizard is used to download a list of providers and allow users to order prints online.
If you enable this policy setting, the task "Order Prints Online" is removed from Picture Tasks in File Explorer folders.
If you disable or don't configure this policy setting, the task is displayed.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | ShellRemoveOrderPrints_1 |
Friendly Name | Turn off the "Order Prints" picture task |
Location | User Configuration |
Path | InternetManagement > Internet Communication settings |
Registry Key Name | Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
Registry Value Name | NoOnlinePrintsWizard |
ADMX File Name | ICM.admx |
ShellRemoveOrderPrints_2
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_ICM/ShellRemoveOrderPrints_2
This policy setting specifies whether the "Order Prints Online" task is available from Picture Tasks in Windows folders.
The Order Prints Online Wizard is used to download a list of providers and allow users to order prints online.
If you enable this policy setting, the task "Order Prints Online" is removed from Picture Tasks in File Explorer folders.
If you disable or don't configure this policy setting, the task is displayed.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | ShellRemoveOrderPrints_2 |
Friendly Name | Turn off the "Order Prints" picture task |
Location | Computer Configuration |
Path | InternetManagement > Internet Communication settings |
Registry Key Name | Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
Registry Value Name | NoOnlinePrintsWizard |
ADMX File Name | ICM.admx |
ShellRemovePublishToWeb_1
Scope | Editions | Applicable OS |
---|---|---|
❌ Device ✅ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./User/Vendor/MSFT/Policy/Config/ADMX_ICM/ShellRemovePublishToWeb_1
This policy setting specifies whether the tasks "Publish this file to the Web," "Publish this folder to the Web," and "Publish the selected items to the Web" are available from File and Folder Tasks in Windows folders.
The Web Publishing Wizard is used to download a list of providers and allow users to publish content to the web.
If you enable this policy setting, these tasks are removed from the File and Folder tasks in Windows folders.
If you disable or don't configure this policy setting, the tasks are shown.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | ShellRemovePublishToWeb_1 |
Friendly Name | Turn off the "Publish to Web" task for files and folders |
Location | User Configuration |
Path | InternetManagement > Internet Communication settings |
Registry Key Name | Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
Registry Value Name | NoPublishingWizard |
ADMX File Name | ICM.admx |
ShellRemovePublishToWeb_2
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_ICM/ShellRemovePublishToWeb_2
This policy setting specifies whether the tasks "Publish this file to the Web," "Publish this folder to the Web," and "Publish the selected items to the Web" are available from File and Folder Tasks in Windows folders.
The Web Publishing Wizard is used to download a list of providers and allow users to publish content to the web.
If you enable this policy setting, these tasks are removed from the File and Folder tasks in Windows folders.
If you disable or don't configure this policy setting, the tasks are shown.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | ShellRemovePublishToWeb_2 |
Friendly Name | Turn off the "Publish to Web" task for files and folders |
Location | Computer Configuration |
Path | InternetManagement > Internet Communication settings |
Registry Key Name | Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
Registry Value Name | NoPublishingWizard |
ADMX File Name | ICM.admx |
WinMSG_NoInstrumentation_1
Scope | Editions | Applicable OS |
---|---|---|
❌ Device ✅ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./User/Vendor/MSFT/Policy/Config/ADMX_ICM/WinMSG_NoInstrumentation_1
This policy setting specifies whether Windows Messenger collects anonymous information about how Windows Messenger software and service is used.
With the Customer Experience Improvement program, users can allow Microsoft to collect anonymous information about how the product is used. This information is used to improve the product in future releases.
If you enable this policy setting, Windows Messenger doesn't collect usage information, and the user settings to enable the collection of usage information aren't shown.
If you disable this policy setting, Windows Messenger collects anonymous usage information, and the setting isn't shown.
If you don't configure this policy setting, users have the choice to opt in and allow information to be collected.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | WinMSG_NoInstrumentation_1 |
Friendly Name | Turn off the Windows Messenger Customer Experience Improvement Program |
Location | User Configuration |
Path | InternetManagement > Internet Communication settings |
Registry Key Name | Software\Policies\Microsoft\Messenger\Client |
Registry Value Name | CEIP |
ADMX File Name | ICM.admx |
WinMSG_NoInstrumentation_2
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_ICM/WinMSG_NoInstrumentation_2
This policy setting specifies whether Windows Messenger collects anonymous information about how Windows Messenger software and service is used.
With the Customer Experience Improvement program, users can allow Microsoft to collect anonymous information about how the product is used. This information is used to improve the product in future releases.
If you enable this policy setting, Windows Messenger doesn't collect usage information, and the user settings to enable the collection of usage information aren't shown.
If you disable this policy setting, Windows Messenger collects anonymous usage information, and the setting isn't shown.
If you don't configure this policy setting, users have the choice to opt in and allow information to be collected.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
Tip
This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.
ADMX mapping:
Name | Value |
---|---|
Name | WinMSG_NoInstrumentation_2 |
Friendly Name | Turn off the Windows Messenger Customer Experience Improvement Program |
Location | Computer Configuration |
Path | InternetManagement > Internet Communication settings |
Registry Key Name | Software\Policies\Microsoft\Messenger\Client |
Registry Value Name | CEIP |
ADMX File Name | ICM.admx |