# Restrictions for Windows devices

Configuring restrictions for Windows devices enforce control on how the users access these devices. You may allow or disallow Windows functionalities and features on the devices to ensure security to the organizational data and determine whether the corporate devices are utilized safely. Windows restriction policy can be used to generate restrictions based on device functionality, network connectivity, app configurations, security and privacy settings, and much more.

 Note- The availability of the restrictions listed below depends on your UEM license plan and the Windows version of the end-user. For detailed information, please visit Hexnode [pricing page](https://www.hexnode.com/pricing/uem/).
- The restrictions mentioned below are supported on Pro, Business, Enterprise and Education editions.

 

Basic Restrictions
------------------

To configure basic *Restrictions* for Windows devices,

1. Login to your Hexnode portal.
2. Navigate to **Policies > New Policy** to create a new one or click on any policy name to edit an existing one.
3. Enter the *Policy Name* and *Description* in the provided fields.
4. Navigate to **Windows** > **Restrictions.**
5. Click on **Configure**.

![Basic Restriction policy for Windows devices provided by Hexnode](https:2018/08/Basic-Restrictions-on-Windows.png "Basic Restrictions on Windows")

Note that all the basic Windows restrictions in Hexnode are **Enabled** by default.

### Allow Basic Device Functionality

Device functionality-based restrictions

 RestrictionSupported OS DescriptionCamera✓10 
 ✓11Unchecking this option prevents access to device *camera*.Cortana voice assistant✓10 
 ✓11When this option is unchecked *Cortana voice assistant* is disabled on the device. However, users will still be able to use *search* to find items on the device.Use Cortana if device is locked✓10 (Version 1703+) 
 ✓11Unchecking this option disallows users from interacting with *Cortana* using speech while the system is locked. If you disable this setting, the system will need to be unlocked for the user to interact with Cortana using speech.Use storage card and USB drives✓10 
 ✓11Disabling this option prevents using any external storage cards or USB devices on the devices.  Notes:- On co-managed devices, storage cards will not be restricted.

Telemetry✓10 
 ✓11*Telemetry* collects diagnostic data from a Windows device and sends them to Microsoft. [Learn more](https://www.hexnode.com/mobile-device-management/help/restrictions-for-windows-devices/#telemetry-in-windows)Click the dropdown to select **Disallow/ Limited** for sending diagnostic data to Microsoft.
Disallow – If you choose *Disallow*, diagnostic data will not be sent.
Limited – On choosing *Limited*, device can send only basic data to Microsoft.

 Note: On Windows 11 devices, enabling other basic restrictions may not be effective unless Telemetry is configured to Limited or Disallow.

Location services✓10 
 ✓11This option specifies whether Windows apps can access the device location. There are three sub-options available in the associated drop-down list: 1. **Allow Users to Control** (Default): When this option is selected, users can choose whether Windows apps can access the device’s location. This setting can be configured by navigating to ***Settings > Privacy and security > Location*** on the device.
2. **Force Location Off**: When this option is selected, Windows apps will not be allowed to access the device’s location.
3. **Force Location On**: When this option is selected, Windows apps will be allowed to access the device’s location.

Change language✓10 
 ✓11*Language* settings from the device will be disabled, if this option is unchecked.Voice recording✓10 
 ✓11Unchecking this option prevents users from using *Voice Recorder* app on Windows devices.Users can enable/disable Workplace✓10 
 ✓11Users will not be able to change *Workplace* settings from the device, if this option is unchecked.Users can change AutoPlay settings ✓10 
 ✓11Users will be disallowed from changing Auto Play settings from the device, if this option is unchecked. [Learn more](https://www.hexnode.com/mobile-device-management/help/restrictions-for-windows-devices/#autoplay)

 

 

#### Telemetry in Windows

*Telemetry* is a feature in Windows where the system information will be sent to Microsoft to provide device-specific updates. Microsoft has already revealed that they used *telemetry* to count the number of times Alt+Tab was used on a PC to switch between active Windows. They found that the number of users used Alt+Tab were lesser since most of them were not familiar with that function, which then led to the addition of *Task View* button in Windows 10.

#### AutoPlay

*AutoPlay* lets you choose the program with which you can start different kinds of media, such as DVD, CD, etc. containing music, video, photo, etc. *AutoPlay* begins reading from a drive as soon as you insert media files in the drive. As a result, the setup file of programs and the music on audio media starts immediately.

### Allow Basic App Settings

App based settings

 RestrictionSupported OSDescriptionSync Settings✓10 
 ✓11Unchecking this option disables the Windows *sync settings* on the devices. [Learn more](https://www.hexnode.com/mobile-device-management/help/restrictions-for-windows-devices/#sync-settings)Allow SignIn Options✓10 
 ✓11Unchecking this option prevents users from changing *Sign In* options like password, picture password, PIN, and password policy under device settings.Allow News and Interests ✓10 
 ✓11Unchecking this option will remove the News and Interest feature from the taskbar.  Notes: 
The device needs to be restarted for the restriction to take effect.

Microsoft feedback notifications ✓10 
 ✓11Unchecking this option will restrict notifications from the Feedback Hub app. Game DVR ✓10 Unchecking this option prevents the Windows game recording and broadcasting features in the Game DVR app. 

 

 

#### Sync Settings

On enabling Sync settings, Windows syncs all the settings you choose across all your Windows devices in which you have signed in with your Microsoft account. Sync settings also work if you sign in with a work or school account linked to your Microsoft account.

### Allow Basic Network Settings

Network based restrictions

 RestrictionSupported OSDescriptionWi-Fi✓10 (Version 1703+) 
 ✓11Unchecking this option prevents users from enabling, configuring, and accessing *Wi-Fi* on the device.Bluetooth✓10 
 ✓11If this option is unchecked, users will be disallowed from turning on/off*Bluetooth* on the device.Discover device over Bluetooth✓10 
 ✓11When this option is unchecked, the device is prevented from being discovered by other Bluetooth-enabled devices. Set Bluetooth name ✓10 
 ✓11This option allows admins to set the device’s Bluetooth name as it appears when discovered by other devices. This option supports the use of wildcards. Users can turn VPN on/off✓10 
 ✓11Uncheck this option to disallow users from adding or removing a *VPN* connection.Connect to VPN if on mobile network✓10 
 ✓11Disabling the option prevents the device from accessing *VPN* connection when connected to a mobile network. Connect to VPN if roaming✓10 
 ✓11Disabling the option prevents the device from accessing *VPN* connection when roaming on a mobile network.Cellular data roaming✓10 
 ✓11Unchecking the option prevents data roaming between networks. Using cellular data while roaming might incur additional data charges.

 

 

### Allow Basic Security and Privacy Settings

Security and privacy-based restrictions

 RestrictionSupported OS DescriptionManual MDM administration removal✓10 
 ✓11Unchecking this option prevents users from accessing workplace control panel to delete the workplace account on the device. [Learn More](https://www.hexnode.com/mobile-device-management/help/how-to-make-mdm-profile-non-removable-on-windows-pc/) Note: If your device is Azure AD joined, disabling this option will have no effect.

Show toast notification on lock screen✓10 
 ✓11Disable this option to prevent *toast notification* on the device lock screen.

 

 

### Account Settings

Account based restrictions

 RestrictionSupported OSDescriptionOneDrive file sync✓10 
 ✓11Unchecking this option restricts users from synchronising files to *OneDrive* from their devices.

 

 

Advanced Restrictions
---------------------

To configure Advanced Restrictions for Windows devices,

1. Login to your Hexnode UEM portal.
2. Navigate to **Policies**. You can either create a new policy or click on any policy name to edit an existing one.
3. Enter the *Policy Name* and *Description* in the provided fields.
4. Navigate to **Windows** > **Advanced Restrictions**.
5. Click on **Configure**.

![Hexnode UEM advanced restrictions for Windows mobiles and desktops](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2021/04/advanced-Windows-mobile-and-desktop-restrictions-using-Hexnode-MDM.png)

### Allow Device Functionality

Device functionality-based restrictions

 RestrictionSupported OSDescriptionUsers can reset the device✓10 
 ✓11Users will not be able to perform *factory-reset* or wipe on their devices, if this option is unchecked. Allowed by default.

Users can change date and time✓10 
 ✓11Uncheck this option to prevent users from changing *date and time* settings on the device. Allowed by default.

Users can change power and sleep settings✓10  ✓11Uncheck this option to prevent users from changing *power and sleep* settings on the device. Allowed by default.

Allow Embedded Mode✓10 
 ✓11Enable this option to allow users to activate *Embedded Mode* on their devices. [Learn more](https://www.hexnode.com/mobile-device-management/help/restrictions-for-windows-devices/#embedded-mode)Disabled by default.

Allow Region✓10 
 ✓11Unchecking the option prevents users from changing *Region* under device settings. *Region* option is useful in finding localized content and apps.

Allowed by default.

End task from Task manager✓10 
 ✓11Unchecking this option prevents non-admin users from ending tasks using Task Manager.Projection from device✓10 
 ✓11Unchecking this option prevents the device from discovering or projecting to other devices.Projection to device✓10 
 ✓11Uncheck this option to make the device non-discoverable for projection from other devices.Require PIN for pairing✓11Select how the user wants to enforce PIN for pairing via Bluetooth. The available options are: - Never
- First time
- Always

#### Embedded Mode

[Embedded mode](https://docs.microsoft.com/en-us/windows/iot-core/develop-your-app/embeddedmode) restricts the device to run a single app (often called *kiosk mode*). Embedded mode is allowed by default on devices running Windows 10 IoT Core. On mobile, and desktop devices, it must be enabled manually. Not only does this let you access a single app when using the device, Embedded Mode enables background tasks and other functionalities on the devices in addition to running single app in Kiosk mode.

 

 

### File Explorer Settings

File Explorer-based restrictions

 RestrictionSupported OSDescriptionAllowed folder locations✓11Select the storage locations where users can save and access files. The available options are: - All folder locations
- Documents, Pictures, Downloads
- Desktop, Documents, Pictures, Downloads
- Desktop, Documents, Pictures, Downloads, Network
- This PC, Desktop, Documents, Pictures, Downloads
- This PC, Desktop, Documents, Pictures, Downloads, Network

Allowed storage locations ✓11Select the folders where users an save and access files. The available options are: - All storage locations
- Removable drives
- Sync roots
- Local drives
- Removable drives, sync roots
- Removable drives, local drives
- Sync roots, local drives
- Removable drives, sync roots, local drives

 

 

### Allow App Settings

 App based restrictions 

 RestrictionSupported OSDescriptionUnlock developer options✓10 
 ✓11Configure the *Windows developer settings* here. Click the dropdown to select **Deny/ Allow** for using developer features on the device. Not Configured by default.

Auto update of store apps✓10 
 ✓11Admins can either allow or disallow auto-updating of store apps.Search can use user location✓10 
 ✓11Disabling this option disallows Windows Search from using device location. Allowed by default.

 

 

### Allow Network Settings

All the Windows advanced network settings supported by Hexnode are allowed by default.

 Network based restrictions 

 RestrictionSupported OSDescriptionInternet Sharing✓10 
 ✓11Uncheck this option to prevent users from sharing their Internet connection through Bluetooth or by creating a portable Wi-Fi hotspot.Connect to Wi-Fi Sense automatically✓10 
 ✓11Select the option to allow devices to connect to open Wi-Fi hotspot automatically. Unchecking the option prevents automatic connection to Wi-Fi hotspots. Connect to external Wi-Fi networks manually✓10 
 ✓11Uncheck this option to disallow users from connecting to a Wi-Fi network other than the MDM configured Wi-Fi networks.  Notes:- Enabling this option deletes user-configured Wi-Fi and Wi-Fi sense profiles that have been previously installed on the device.
- Not all non-MDM profiles or non-user configured Wi-Fi profiles may get deleted completely.

Wi-Fi Direct✓10 (Version 1703+) 
 ✓11Disabling the option restricts users from turning on *Wi-Fi Direct* on the device. *Wi-Fi Direct* is a certification from the non-profit Wi-Fi Alliance that allows devices to connect directly to each other without the need for a wireless router.

 

 

### Allow Security and Privacy Settings

 Security and Privacy based restrictions 

 RestrictionSupported OSDescriptionInstall provisioning package✓10 
 ✓11Users can apply configurations to the device directly from the provisioning file or through a removable device. [More info](https://www.hexnode.com/mobile-device-management/help/restrictions-for-windows-devices/#provisioning-package)Disabling this option will prevent installation of provisioning package by run-time configuration agent.

Allowed by default.

Mandate signed certificate for provisioning package✓10 
 ✓11Specifies whether provisioning packages must have a certificate signed by a device trusted authority. A trusted authority signed provisioning package could be easily installed on a device without any user consent. Disabled by default.

Remove provisioning package✓10 
 ✓11Disabling this option prevents the run-time configuration agents that removes the provisioning packages. Allowed by default.

Receive advertisements over Bluetooth✓10 
 ✓11Disabling this option prevents the device from receiving advertisements over Bluetooth. Allowed by default.

Pair with other devices automatically✓10 (Version 1703+) 
 ✓11Unchecking this option disallows devices from pairing with the host devices over Bluetooth automatically. Allowed by default.

Online speech recognition✓10 
 ✓11Disabling this option will prevent online speech recognition on the device.Allow apps to use Advertising ID✓10 
 ✓11When enabled, apps can access the advertising ID to deliver personalized ads based on user activity.Users can download Windows Beta updates✓10 
 ✓11Click the dropdown to specify whether the users can download Windows Beta Updates through Windows Insider Program. Available options are: **Disallow/ Allowed /Not Configured.**Not Configured by default.

 

 

#### Provisioning package

Windows provisioning makes it easy for administrators to configure user devices without imaging. A [provisioning package](https://docs.microsoft.com/en-us/windows/configuration/provisioning-packages/provisioning-create-package) (.ppkg) is a container used for a collection of configuration settings. Provisioning packages can be installed using removable media such as an SD card or USB flash drive, attached to an email, downloaded from a network share, deployed in NFC tags or barcodes.

### Windows AI

AI based restrictions

 RestrictionSupported OS DescriptionAI Data Analysis11 (Version 24H2+)Recall app in Windows captures screen snapshots periodically, enabling users to search and revisit past activities. This option determines whether snapshots can be saved for use with Recall. By default, snapshots for Recall are disabled. IT admins can ***Enable*** or ***Disable*** the option based on organizational requirements.

 

 

### Customize Start Menu

For quick access, you can add different folders to show up on the left side menu, on Windows 10 devices. By default, only File Explorer and Settings folders will be listed there. The following restrictions allow Admin to customize start menu by choosing whether to show or hide shortcuts for some folders.

**Not Enforced** is selected as the default value for all the Start Menu customization options. To add or remove the shortcuts from the Start menu, select the appropriate value from the drop-down. Drop-down values are: **Hide shortcut/ Show shortcut**.

 Restrictions on start menu customization 

 RestrictionSupported OSDescriptionDocuments folder✓10 (Version 1709+) 
 ✓11Specifies whether the *Documents* folder shortcut is to be hidden from the Windows Start menu.Downloads folder✓10 (Version 1709+) 
 ✓11Specifies whether the *Downloads* folder shortcut is to be hidden from the Windows Start menu.File Explorer✓10 (Version 1709+) 
 ✓11Specifies whether the *File Explorer* shortcut is to be hidden from the Windows Start menu. Windows devices use *File Explorer* to organize and manage files and folders.Home group✓10 (Version 1709+) 
 ✓11Specifies whether the *Home group* shortcut is to be hidden from the Windows Start menu. The *Home group* allows Windows devices to share documents, music, videos, pictures, and printers with other devices on the same Home group network.Music folder✓10 (Version 1709+) 
 ✓11Specifies whether the *Music* folder shortcut is to be hidden from the Windows Start menu.Networks✓10 (Version 1709+) 
 ✓11Specifies whether the *Networks* shortcut is to be hidden from the Windows Start menu.Personal folder✓10 (Version 1709+) 
 ✓11Specifies whether the *Personal folder* shortcut is to be hidden from the Windows Start menu. The most frequently used folders will be stored in Personal folder.Pictures folder✓10 (Version 1709+) 
 ✓11Specifies whether the *Pictures* folder shortcut is to be hidden from the Windows Start menu.Settings✓10 (Version 1709+) 
 ✓11Specifies whether the *Settings* shortcut is to be hidden from the Windows Start menu. Settings menu allow users to configure different settings for the Windows operating system.Videos folder✓10 (Version 1709+) 
 ✓11Specifies whether the *Videos* folder shortcut is to be hidden from the Windows Start menu. Note 
To add folders to the Windows 10 Start menu,

- Click on **Start** menu > **Settings**.
- Click on **Personalization** > **Start**.
- Click on **Choose which folders appear on Start**.
- Click on the switch under the folder you want to add.

 

 

 

### Advanced Account Settings

 Account Settings 

 RestrictionSupported OSDescriptionBlock Microsoft accounts ✓10 
 ✓11This option allows administrators to control the usage of Microsoft accounts on the device.  Notes- If this setting is configured, users cannot add a Microsoft account through **Accounts** > **Other users** > **Add account**.
- If the user is logged in as a local account, the “**Sign in with a Microsoft account instead**” option under **Your info** will be disabled.

There are 3 options available:

- **Not configured**: No restrictions are applied.
- **Users cannot add Microsoft accounts**: Prevents users from adding new Microsoft accounts to their devices.  Note 
    When this option is selected, users cannot switch from a local account to a Microsoft account or log out of an existing domain account and add a Microsoft account.
- **Users cannot add or log on with Microsoft accounts**: Blocks users from adding new Microsoft accounts or logging in to existing ones.

Users can change account settings ✓10 
 ✓11If the option is enabled, it allows users to modify their account settings. Enabled by default.  Note 
If this option is disabled,

- **Users can add non-Microsoft accounts** and **Users can connect using Microsoft accounts** options are disabled.
- The **Adjust your photo**, **Account settings**, and **Related settings** options under the **Accounts** > **Your Info** settings of the device are disabled. Additionally, **Add account**, and **Accounts used by other apps** options under **Accounts** > **Email & Accounts** settings are disabled.

Users can add non-Microsoft accounts ✓10 
 ✓11If the option is enabled, it allows users to add accounts from other providers like Office 365, Google, Yahoo, iCloud, etc. but restricts adding Microsoft accounts. Enabled by default.  Note 
Users can add non-Microsoft accounts through **Accounts** > **Email & Accounts** > **Add account**.

Users can connect using Microsoft accounts ✓10 
 ✓11If the option is enabled, it allows users to log in or connect to services using their Microsoft accounts.
Enabled by default.  Note 
If this option is disabled,

- Users cannot use their Microsoft accounts to log in to non-mail-related apps like Microsoft Store, OneDrive, Microsoft Teams, etc. It also prevents setting a PIN for a new local user (even when created with a Microsoft account).
- If logged in as a local account, the users cannot sign in to a Microsoft account through **Accounts** > **Your info** > **Sign in with a Microsoft account instead.**
- Users cannot add a Microsoft account from **Accounts** > **Email & Accounts** > **Add a Microsoft account**.

 

 

How to Apply the Restrictions to Devices/Groups?
------------------------------------------------

There are two ways by which you can associate restrictions to the devices in bulk.

If you haven’t saved the policy yet,

1. Navigate to **Policy Targets**
2. Click on **+ Add Devices**, search and select the required device(s) to which you need to apply the policy > Click **OK**
3. Click on **Save** to apply the policies to the devices.

To associate the policies with a device group, select **Device Groups** from the left pane under Policy Targets, and follow the above instructions. Similarly, you can associate the policy with **Users**, **User Groups**, or **Domains** from the same pane.

If you’ve already saved the policy and you’re taken to the page which displays the policy list,

1. Select the required policy
2. Click on **Manage** > **Associate Targets**
3. Select **Device**/ **User**/ **Device Group**/ **User Group**/ **Domain**
4. Search and select the device(s)/ user(s)/ device group(s)/ user group(s)/ domain(s) to which you need to apply the policy > Click **Associate**.

Frequently Asked Questions (FAQs)
---------------------------------

#### 1. What happens if a device is targeted by two different restriction policies with conflicting settings?

Hexnode UEM follows a “most restrictive” logic for policy arbitration. If one policy allows a feature (e.g., the Camera) and another restricts it, the device will enforce the restriction. This ensures that security is never compromised.

#### 2. If admins disenroll a device or remove the restriction policy, will the restricted features be restored automatically?

Yes. For Windows devices, disassociating a policy or disenrolling the device from Hexnode UEM triggers an immediate lifting of restrictions.

#### 3. Can admins prevent a user from accessing the “Reset this PC” feature if they have local administrator rights?

Yes. By unchecking “**Users can reset the device**” in the Advanced Restrictions section, Hexnode utilizes the Windows Policy CSP to disable the reset option within the Settings app, even for administrative accounts.

Troubleshooting
---------------

#### 1. Restriction settings are not reflecting on the device even though the policy status is “Success.” 

**Probable Cause:**

The endpoint may lack the requisite registry entries used by the local Policy Manager to process management instructions. This condition is often the result of residual configurations from a previous MDM provider or corruption within the registry hives.

**Solution:**

Verify that the necessary registry keys are present on the device. For example, if the “Allow SignIn Options” restriction is non-functional, inspect the path: ***HKEY_LOCAL_MACHINESOFTWAREMicrosoftPolicyManagerdefaultSettings***. If keys are missing, you may need to re-enroll the device or use a Custom Script to manually re-inject the necessary registry values, allowing the UEM to interface effectively with the operating system’s management architecture.

#### 2. Advanced restrictions are failing, but some “Basic Restrictions” still seem to work. 

**Probable Cause:**

The local administrator account used to initially enroll the device has been deleted or renamed, leading to a state of “Partial Enrollment”. When the enrollment account is removed, the MDM profile is lost, which breaks communication for some Advanced Restrictions (like File Explorer settings).

**Solution:**

To resolve this, the user must navigate to **Settings > Accounts > Access work or school** and re-authenticate the management account to reinstate the full MDM profile, or the user can re-enroll the device.

#### 3. Restriction policies fail to take effect on devices migrated from another MDM provider. 

**Probable Cause:**

Persistence of the ‘***ExternallyManaged***‘ registry key from the previous management environment.

**Solution:**

Navigate to the registry path ***HKLMSoftwareMicrosoftEnrollments*** on the device. If the *ExternallyManaged* key is set to **1**, it may block the new MDM from applying restrictions. Set this value to 0 or delete the key, then initiate a **Scan Device** action from the Hexnode portal to re-enforce the policy.