1. Home
  2. Windows
  3. Restrictions for Windows Devices

Restrictions for Windows Devices

Hexnode MDM enables you to configure restrictions for Windows devices to prevent users from frequently accessing apps and services which are not desirable in a work environment. By setting up these restrictions, you can significantly reduce the risk of data breaches at your company.

Note


The availability of the restrictions listed below depends on your MDM license plan and the Windows version of the end-user. For detailed information, please visit Hexnode pricing page.

Basic Restrictions

To configure basic Restrictions for Windows devices,

  1. Login to your Hexnode MDM portal > Navigate to Policies tab > Click on New Policy to create a new one or click on any policy name to edit an existing one > Enter the Policy Name and Description in the provided fields.
  2. Navigate to Windows > Choose Restrictions > Click on Configure.

Allow Device Functionality

Device functionality-based restrictions

Restriction Supported OS Description
Camera
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to access the camera.

Allowed by default.

Copy and paste between apps
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to copy and paste text and files between apps. Disabling this option won’t restrict the user from copying and pasting between browsers.

Allowed by default.

Cortana voice assistant
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable Cortana voice assistant in the device. However, users will still be able to use search to find items on the device.

Allowed by default.

Use Cortana if device is locked
PCs & tablets:
8.1   10
(Versions above 1607)
Phones:
8.1   10
(Versions above 1607)
Enable/ disable users to interact with Cortana using speech while the system is locked. If you disable this setting, the system will need to be unlocked for the user to interact with Cortana using speech.

Allowed by default.

Use storage card
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable SD card slot.

Allowed by default.

Telemetry
PCs & tablets:
8.1   10
Phones:
8.1   10
Telemetry collects diagnostic data from a Windows device and sends them to Microsoft. Learn more

Click the dropdown to select Disallow/ Limited for sending diagnostic data to Microsoft.
Disallow – If you choose Disallow, off option will be checked in the device.
Limited – On choosing Limited, users can send only basic data to Microsoft.

Allowed by default.

Location services
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable Location services in the device settings.

Allowed by default.

Edit device name
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to edit the device name under device settings.

Allowed by default.

Change language
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to change language settings

Allowed by default.

Voice recording
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable voice recording on Windows devices.

Allowed by default.

Users can enable/disable Workplace
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to add or remove a work place account under device settings.

Allowed by default.

Allow Auto Play
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to change Auto Play settings. Learn more

Allowed by default.

Telemetry in Windows

Telemetry is a feature in Windows where the system information will be sent to Microsoft to provide device-specific updates. Microsoft has already revealed that they used telemetry to count the number of times Alt+Tab was used on a PC to switch between active Windows. They found that the number of users used Alt+Tab were lesser since most of them were not familiar with that function, which then led to the addition of Task View button in Windows 10.

Auto play

Auto play lets you choose the program with which you can start different kinds of media, such as DVD, CD, etc. containing music, video, photo, etc. Auto play begins reading from a drive as soon as you insert media in the drive. As a result, the setup file of programs and the music on audio media starts immediately.

Allow App Settings

App based settings

Restriction Supported OS Description
Sync Settings
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable all Windows sync settings on the devices. Learn more

Allowed by default.

Share Microsoft Office files
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to share the Microsoft office files.

Allowed by default.

Save as Microsoft Office files
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to save files on their devices as Microsoft Office files.

Allowed by default.

Show notifications on Action Center
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable devices to show notifications on Action Center, the notification area of Windows.

Allowed by default.

Access Internet Explorer or Microsoft Edge
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to access the default browser on their devices (Internet Explorer on Windows 8.1 and Microsoft Edge on Windows 10).

Allowed by default.

Allow SignIn Options
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to change SignIn options like password, picture password, PIN, and password policy under device settings.

Allowed by default.

Sync Settings

On enabling Sync settings, Windows syncs all the settings you choose across all your Windows devices in which you have signed in with your Microsoft account. Sync settings also work if you sign in with a work or school account linked to your Microsoft account.

Allow Network Settings

Network based restrictions

Restriction Supported OS Description
Wi-Fi
PCs & tablets:
8.1   10
(Versions above 1609)
Phones:
8.1   10
(Versions above 1609)
Enable/ disable users to use Wi-Fi.

Allowed by default.

Bluetooth
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to use Bluetooth.

Allowed by default.

Discover device over Bluetooth
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable other Bluetooth-enabled devices to discover the device over Bluetooth.

Allowed by default.

Users can turn VPN on/off
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to add or remove a VPN connection.

Allowed by default.

Connect to VPN if on mobile network
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to connect to a VPN while using the mobile network.

Allowed by default.

Connect to VPN if roaming
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to connect to a VPN while roaming.

Allowed by default.

Cellular data roaming
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable Cellular data roaming options. Using cellular data while roaming might incur additional data charges.

Allowed by default.

Allow Security and Privacy Settings

Security and privacy based restrictions

Restriction Supported OS Description
Show toast notification on lock screen
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable toast notification on the device lock screen.

Allowed by default.

Account Settings

Account based restrictions

Restriction Supported OS Description
MMS
PCs & tablets:
8.1   10
Phones:
8.1   10
(Versions above 1703)
Enable/ disable MMS (Multimedia Messaging Service) send/ receive functionality on the device.

Allowed by default.

Sync MMS
PCs & tablets:
8.1   10
Phones:
8.1   10
(Versions above 1703)
Enable/ disable users to sync their MMS inbox with their phone, no matter which device is used to send or receive messages.

Allowed by default.

RCS messaging
PCs & tablets:
8.1   10
Phones:
8.1   10
(Versions above 1703)
Enable/ disable users to send RCS (Rich Communication Services) messages. RCS is a text-message system that is richer and more interactive than SMS.

Allowed by default.

OneDrive file sync
PCs & tablets:
8.1   10
Phones:
8.1   10
(Versions above 1703)
Enable/ disable users to sync files on their device to OneDrive. OneDrive is Microsoft’s cloud storage service that allows you to store files securely in one place and access them from anywhere with any device.

Disabled by default.

Advanced Restrictions

To configure Advanced Restrictions for Windows devices,

  1. Login to your Hexnode MDM portal > Navigate to Policies tab > Click on New Policy to create a new one or click on any policy name to edit an existing one > Enter the Policy Name and Description in the provided fields.
  2. Navigate to Windows > Choose Advanced Restrictions > Click on Configure.

Allow Device Functionality

Device functionality based restrictions

Restriction Supported OS Description
Device Encryption
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable enterprises to turn on device encryption.

Disabled by default.

NFC
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to allow NFC on their devices.

Allowed by default.

USB connection
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable USB connection between the device and a computer.

Allowed by default.

Users can reset the device
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to reset their devices.

Allowed by default.

Screen capture
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to capture the device screen.

Allowed by default.

Users can change date and time
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to change date and time settings.

Allowed by default.

Users can change power and sleep settings
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to change power and sleep settings under device settings.

Allowed by default.

Allow Embedded Mode
PCs & tablets:
8.1   10
Phones:
8.1   10
(Versions above 1607)
Enable/ disable users to activate Embedded Mode on their devices. Learn more

Disabled by default.

Allow Region
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to change Region under device settings.

Region option is useful in finding localized content and apps.

Allowed by default.

Embedded Mode

Embedded mode restricts the device to run a single app (often called kiosk mode). Embedded mode is allowed by default on Windows 10 IoT Core and can also be enabled on mobile or desktop devices. Apart from letting you access a single app when using the device, Embedded Mode enables other functionalities such as background tasks that can run forever.

Allow App Settings

App based restrictions

Restriction Supported OS Description
Windows Store
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable Windows store for the users.

Allowed by default.

Unlock developer options
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to unlock developer options on their devices.

Click the dropdown to select Deny/ Allow for using developer features on the device.

Not Configured by default.

Users can turn Safe Search on/off
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable Safe Search on the devices.

Safe search is where Cortana filters out adult content from the search results.

Allowed by default.

Search can use user location
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable location services to display regional results while searching the internet.

Allowed by default.

Store images captured for Vision search
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable devices to store images captured for Vision search.

Vision search (or Bing Vision) is a feature provided by Bing. Bing allows you to scan an image with your Windows device and display its details.

Allowed by default.

Users can add non-Microsoft accounts
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to add non-Microsoft email accounts on the devices.

Allowed by default.

Allow Network Settings

Network based restrictions

Restriction Supported OS Description
Internet Sharing
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to share their Internet connection through Bluetooth or by creating a portable Wi-Fi hotspot.

Allowed by default.

Connect to Wi-Fi Sense automatically
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable devices to connect to a Wi-Fi hotspot automatically.

Allowed by default.

Connect to external Wi-Fi networks manually
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to connect to a Wi-Fi network other than the MDM configured Wi-Fi networks.

Note

  • Enabling this option deletes user-configured Wi-Fi and Wi-Fi sense profiles that have been previously installed on the device.
  • Not all non-MDM profiles or non-user configured Wi-Fi profiles may get deleted completely.

Allowed by default.

Wi-Fi Direct
PCs & tablets:
8.1   10
(Versions above 1703)
Phones:
8.1   10
(Versions above 1703)
Enable/ disable users to turn on Wi-Fi Direct on the device.

Wi-Fi Direct is a certification from the non-profit Wi-Fi Alliance that allows devices to connect directly to each other without the need for a wireless router.

Allowed by default.

Users can turn Data Sense on/off
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to turn on Data Sense on their devices.

Data Sense helps you to monitor and track the data consumption of users on the devices and block data usage when it crosses the set limit.

Allowed by default.

Allow Security and Privacy Settings

Security and Privacy based restrictions

Restriction Supported OS Description
Manually install root certificate
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to share their Internet connection through Bluetooth or by creating a portable Wi-Fi hotspot.

Allowed by default.

Install provisioning package
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to apply configurations to the device directly from the provisioning file or through a removable device. More info

Disabling this option will hide Add a package option under device settings.

Allowed by default.

Mandate signed certificate for provisioning package
PCs & tablets:
8.1   10
Phones:
8.1   10
Specifies whether provisioning packages must have a certificate signed by a device trusted authority. A provisioning package signed by a trusted provisioner can be installed on a device without a prompt for user consent.

Disabled by default.

Remove provisioning package
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to remove a provisioning package for work or school under device settings.

Allowed by default.

Receive advertisements over Bluetooth
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to receive advertisements over Bluetooth.

Allowed by default.

Pair with other devices automatically
PCs & tablets:
8.1   10
(Versions above 1609)
Phones:
8.1   10
(Versions above 1609)
Enable/ disable devices to pair automatically with other devices over Bluetooth.

Allowed by default.

Users can download Windows Beta updates
PCs & tablets:
8.1   10
Phones:
8.1   10
Enable/ disable users to download Windows Beta Updates through Windows Insider Program.

Click the dropdown to select Disallow/ Allowed for downloading Windows Beta updates.

Not Configured by default.

Provisioning package

Windows provisioning makes it easy for administrators to configure user devices without imaging. A provisioning package (.ppkg) is a container used for a collection of configuration settings. Provisioning packages can be installed using removable media such as an SD card or USB flash drive, attached to an email, downloaded from a network share, deployed in NFC tags or barcodes.

Customize Start Menu

On the left side of the Start Menu, you can add specific Windows 10 folders to show up there, making it quicker to access them. By default, the File Explorer and Settings are the only folders listed there. The following restrictions allow Admin to customize start menu by choosing whether to show or hide shortcuts for some folders.

Restrictions on start menu customization

Restriction Supported OS Description
Documents folder
PCs & tablets:
8.1   10
(Versions above 1709)
Phones:
8.1   10
Controls the visibility of Documents folder shortcut on the Start menu.

Documents folder is the standard location for storing user-created files.

Click the dropdown to select Hide shortcut/ Show shortcut.

Not enforced by default.

Downloads folder
PCs & tablets:
8.1   10
(Versions above 1709)
Phones:
8.1   10
Controls the visibility of the Downloads folder shortcut on the Start menu.

By default, modern web browsers save files to the Downloads folder.

Click the dropdown to select Hide shortcut/ Show shortcut.

Not enforced by default.

File Explorer
PCs & tablets:
8.1   10
(Versions above 1709)
Phones:
8.1   10
Controls the visibility of File Explorer shortcut on the Start menu.

File Explorer is the file management application used by Windows operating systems to browse folders and files.

Click the dropdown to select Hide shortcut/ Show shortcut.

Not enforced by default.

Home group
PCs & tablets:
8.1   10
(Versions above 1709)
Phones:
8.1   10
Controls the visibility of Home group shortcut on the Start menu.

The Home group allows users to share pictures, music, videos, documents, and printers with other people in their Home group network.

Click the dropdown to select Hide shortcut/ Show shortcut.

Not enforced by default.

Music folder
PCs & tablets:
8.1   10
(Versions above 1709)
Phones:
8.1   10
Controls the visibility of the Music folder shortcut on the Start menu.

Click the dropdown to select Hide shortcut/ Show shortcut.

Not enforced by default.

Networks
PCs & tablets:
8.1   10
(Versions above 1709)
Phones:
8.1   10
Controls the visibility of Networks shortcut on the Start menu.

Click the dropdown to select Hide shortcut/ Show shortcut.

Not enforced by default.

Personal folder
PCs & tablets:
8.1   10
(Versions above 1709)
Phones:
8.1   10
Controls the visibility of Personal folder shortcut on the Start menu.

Personal folder stores the most frequently used folders in one location.

Click the dropdown to select Hide shortcut/ Show shortcut.

Not enforced by default.

Pictures folder
PCs & tablets:
8.1   10
(Versions above 1709)
Phones:
8.1   10
Controls the visibility of the Pictures folder shortcut on the Start menu.

Click the dropdown to select Hide shortcut/ Show shortcut.

Not enforced by default.

Settings
PCs & tablets:
8.1   10
(Versions above 1709)
Phones:
8.1   10
Controls the visibility of the Settings shortcut on the Start menu.

Settings allow users to customize and configure the operating system.

Click the dropdown to select Hide shortcut/ Show shortcut.

Not enforced by default.

Videos folder
PCs & tablets:
8.1   10
(Versions above 1709)
Phones:
8.1   10
Controls the visibility of the Videos folder shortcut on the Start menu.

Click the dropdown to select Hide shortcut/ Show shortcut.

Not enforced by default.

Note


To add folders to the Windows 10 Start menu,

  • Click on Start menu > Settings.
  • Click on Personalization > Start.
  • Click on Choose which folders appear on Start.
  • Click on the switch under the folder you want to add.


How to Apply the Restrictions to Devices/Groups?

There are two ways by which you can associate restrictions to the devices in bulk.

If you haven’t saved the policy yet,

  1. Navigate to Policy Targets
  2. Click on + Add Devices, search and select the required device(s) to which you need to apply the policy > Click OK
  3. Click on Save to apply the policies to the devices.

To associate the policies to a device group, select Device Groups from the left pane under Policy Targets, and follow the above instructions. Similarly, you can associate the policy to Users, User Groups, or Domains from the same pane.

If you’ve already saved the policy and you’re taken to the page which displays the policy list,

  1. Select the required policy
  2. Click on Manage > select Associate Targets
  3. Select Device/ User/ Device Group/ User Group/ Domain
  4. Search and select the device(s)/ user(s)/ device group(s)/ user group(s)/ domain(s) to which you need to apply the policy > Click Associate.
  •  
  •  
  •  
  •  
  •  

Was this article helpful?

Related Articles

Leave a Comment