1. Home
  2. Windows
  3. Restrictions for Windows Devices

Restrictions for Windows Devices

Hexnode MDM allows you to configure restrictions for Windows devices to prevent employees from frequently accessing apps and services which aren’t required in a work environment. With restrictions being setup, protect the corporate data on the device from getting leaked by any means, even through a third-party app installed on the device.

Note:

The restrictions provided here are available for you to configure based on the MDM plan you’ve subscribed and the Windows version the end-user is on. For detailed information, please visit our pricing page.

To configure restrictions for Windows devices

  1. From your Hexnode MDM portal, head on to Policies tab.
  2. Create a new policy by clicking on New Policy button or continue with an existing one.
  3. From Windows Settings, choose Restrictions > Configure.

Allow Device Functionality

Device functionality based restrictions
Restriction Supported OS Description
Camera PCs & tablets:
8.1   10

Phones:
8.1   10

When checked users are allowed to access the camera. However, camera icon is not hidden even if this option is unchecked. Camera is allowed by default.
Copy and paste between apps PCs & tablets:
8.1   10

Phones:
8.1   10

When checked users can copy and paste text and files between apps. Disabling this option won’t restrict the user from copying and pasting between browsers. Allowed by default.
Device Encryption PCs & tablets:
8.1   10

Phones:
8.1   10

Allow enterprise to turn on device encryption. Disabled by default.
NFC PCs & tablets:
8.1   10

Phones:
8.1   10

Allow users to enable or disable NFC on their device. Enabled by default.
Cortana voice assistant PCs & tablets:
8.1   10

Phones:
8.1   10

If disabled Cortana voice assistant will be hidden. Users will still be able to use search to find items on the device. Allowed by default.
Use Cortana if device is locked PCs & tablets:
8.1   10

Phones:
8.1   10(Versions above 1607)

If checked the user can interact with Cortana using speech while the system is locked. If you disable this setting, the system will need to be unlocked for the user to interact with Cortana using speech. Allowed by default.
USB connection PCs & tablets:
8.1   10

Phones:
8.1   10

Enables USB connection between the device and a computer. Allowed by default.
Use storage card PCs & tablets:
8.1   10

Phones:
8.1   10

If unchecked SD card slot will be disabled. Allowed by default.
Users can reset the device PCs & tablets:
8.1   10

Phones:
8.1   10

If unchecked ‘Reset your phone’ option in Device settings will be hidden. Allowed by default.
Screen capture PCs & tablets:
8.1   10

Phones:
8.1   10

When checked users can capture the device screen. Allowed by default.
Telemetry PCs & tablets:
8.1   10

Phones:
8.1   10

Telemetry collects diagnostic data from a Windows device and sends them to Microsoft(more info). This is a drop-down box with three options, disallow, limited and allow. When limited is selected users can send only basic data to Microsoft. When disallow is selected off option will be checked in the device. Allowed by default.
Location services PCs & tablets:
8.1   10

Phones:
8.1   10

This is a drop-down box with two options disallow and allow with ‘allow’ option selected by default. When disallowed ‘location services’ under device settings will be off.
Edit device name PCs & tablets:
8.1   10

Phones:
8.1   10

When checked users are allowed to edit the ‘device name’ under device settings. Allowed by default.
Change language PCs & tablets:
8.1   10

Phones:
8.1   10

When checked users are allowed to change language settings. Allowed by default.
Users can change date and time PCs & tablets:
8.1   10

Phones:
8.1   10

When checked users are allowed to change date and time settings. Allowed by default.
Voice Recording PCs & tablets:
8.1   10

Phones:
8.1   10

Allow voice recording in Windows devices. Allowed by default.
Users can change power and sleep settings PCs & tablets:
8.1   10

Phones:
8.1   10

Allow users to change power and sleep settings under device settings. Allowed by default.
Users can enable/disable Workplace PCs & tablets:
8.1   10

Phones:
8.1   10

When checked users can add or remove a work place account under device settings. Allowed by default.
Allow Embedded Mode PCs & tablets:
8.1   10

Phones:
8.1   10(Versions above 1607)

Allow users to enable Embedded mode(more info) on the device. Disabled by default.
Allow Auto Play PCs & tablets:
8.1   10

Phones:
8.1   10

Allow users to change Auto play(more info). settings. Allowed by default.
Allow Region PCs & tablets:
8.1   10

Phones:
8.1   10

Allow users to change Region under device settings. Region option is useful in finding localised contents and apps. Allowed by default.

Telemetry in Windows

Telemetry is a feature in Windows where the system information will be sent to Microsoft to provide device-specific updates. This feature is not only used for providing updates, but also to improve their services as well. Microsoft already revealed that they used telemetry to count the number of times Alt+Tab was used on a PC to switch between active Windows and found that lesser number of users used Alt+Tab since most of them weren’t familiar with that function, which then led to the addition of Task View button in Windows 10.

Embedded Mode

Embedded mode restricts the device to run a single app (often called ‘kiosk mode’). Embedded mode is allowed by default on Windows 10 IoT Core and can be enabled on mobile or desktop devices too. Not only does this let you only access a single app when using the device but also enables other functionality such as background tasks that can run forever.

Auto play

Auto play lets you choose which program to use to start different kinds of media, such as DVD, CD, etc., containing music, video, photo, etc. We can choose and set Auto play defaults for removable drives and memory cards. Auto play begins reading from a drive as soon as you insert media in the drive. As a result, the setup file of programs and the music on audio media start immediately.

Allow App Settings

App based restrictions
Restriction Supported OS Description
Windows Store PCs & tablets:
8.1   10

Phones:
8.1   10

If this option is disabled, Windows store become unavailable for the users. By default, store can be accessed by the user.
Sync Settings PCs & tablets:
8.1   10

Phones:
8.1   10

Allows or disallows all Windows sync settings(more info) on the device. Allowed by default.
Unlock developer options PCs & tablets:
8.1   10

Phones:
8.1   10

Can Allow, Disallow or leave it Not configured. When Allow option is selected, Developer mode under ‘Use developer features’ in Device settings will be on.
Users can turn Safe Search on/off PCs & tablets:
8.1   10

Phones:
8.1   10

Allow users to switch safe search settings between strict, moderate and off options. Safe search is where Cortana filters out adult content from the search results. Allowed by default.
Share Microsoft Office files PCs & tablets:
8.1   10

Phones:
8.1   10

Allow users to share the Microsoft office files. Allowed by default.
Search can use user location PCs & tablets:
8.1   10

Phones:
8.1   10

Use location services to display regional results while searching the internet. Allowed by default.
Store images captured for Vision search PCs & tablets:
8.1   10

Phones:
8.1   10

Allow the device to store images captured for Vision search. Vision search (or Bing Vision) is a feature provided by Bing which allows you to scan an image (be it an object or a bar code) with your Windows device and Bing will display its details. Allowed by default.
Users can add non-Microsoft accounts PCs & tablets:
8.1   10

Phones:
8.1   10

If unchecked, users are not allowed to add non-Microsoft email accounts on the device. Allowed by default.
Save as Microsoft Office files PCs & tablets:
8.1   10

Phones:
8.1   10

Allow users to save files on their device as a Microsoft Office file. You can specify the location to which the file is to be stored. Allowed by default.
Show notifications on Action Center PCs & tablets:
8.1   10

Phones:
8.1   10

Allow the device to show notification on Action Center, the notification area of Windows. Allowed by default.
Access Internet Explorer or Microsoft Edge PCs & tablets:
8.1   10

Phones:
8.1   10

If unchecked, users are not allowed to access the default browser on their device (Internet Explorer on Windows 8.1 and Microsoft Edge on Windows 10). Allowed by default.
Allow Sign in Options PCs & tablets:
8.1   10

Phones:
8.1   10

Allow users to change sign in options like password, picture password, PIN and password policy under device settings. Allowed by default.

Sync Settings

Auto play lets you choose which program to use to start different kinds of media, such as DVD, CD, etc., containing music, video, photo, etc. We can choose and set Auto play defaults for removable drives and memory cards. Auto play begins reading from a drive as soon as you insert media in the drive. As a result, the setup file of programs and the music on audio media start immediately.

Allow Network Settings

Network based restrictions
Restriction Supported OS Description
Internet Sharing PCs & tablets:
8.1   10

Phones:
8.1   10

Allow users to share their Internet connection through Bluetooth or by creating a portable Wi-Fi hotspot. Allowed by default.
Wi-Fi PCs & tablets:
8.1   10

Phones:
8.1   10(Versions above 1607)

Allow users to enable/disable Wi-Fi. Allowed by default.
Connect to Wi-Fi sense automatically PCs & tablets:
8.1   10

Phones:
8.1   10

Allow the device to connect to a Wi-Fi hotspot automatically. If unchecked, Wi-Fi sense option will be hidden.
Connect to external Wi-Fi networks manually PCs & tablets:
8.1   10

Phones:
8.1   10

Allow or disallow connecting to Wi-Fi outside of MDM configured Wi-Fi networks. Enabling this will delete user configured Wi-Fi, Wi-Fi sense profiles that have been previously installed on the device. Not all non-MDM profiles or non-user configured Wi-Fi profiles may get deleted completely. By default, users are allowed to do so.
Wi-Fi direct PCs & tablets:
8.1   10

Phones:
8.1   10(Versions above 1703)

Allow users to enable Wi-Fi direct on the device. Wi-Fi Direct is a certification from the non-profit Wi-Fi Alliance that allows devices to connect directly to each other without the need for a wireless router. Allowed by default.
Bluetooth PCs & tablets:
8.1   10

Phones:
8.1   10

Allow users to turn Bluetooth on or off. This is a drop-down box with two options disallow and allow, with ‘allow’ selected by default.
Discover device over Bluetooth PCs & tablets:
8.1   10

Phones:
8.1   10

Specifies whether other Bluetooth-enabled devices can discover the device over Bluetooth. Allowed by default.
Users can turn VPN on/off PCs & tablets:
8.1   10

Phones:
8.1   10

Allow users to add or remove a VPN connection. Allowed by default.
Connect to VPN if on mobile network PCs & tablets:
8.1   10

Phones:
8.1   10

Allow users to connect to VPN when on mobile network. Allowed by default.
Connect to VPN if roaming PCs & tablets:
8.1   10

Phones:
8.1   10

When checked VPN while roaming option will be on. Allowed by default.
Cellular data roaming PCs & tablets:
8.1   10

Phones:
8.1   10

If unchecked, data roaming options will be hidden. Using cellular data while roaming might incur additional data charges. Allowed by default.
Users can turn Data Sense on/off PCs & tablets:
8.1   10

Phones:
8.1   10

Allows users to turn Data Sense on/off. Data sense monitors the amount of data you use and try to compress it, so you use less. Allowed by default.

Allow Security and Privacy Settings

Security and privacy based restrictions
Restriction Supported OS Description
Manually install root certificate PCs & tablets:
8.1   10

Phones:
8.1   10

Allow users to manually install root certificate on their Windows device. Allowed by default.
Install provisioning package PCs & tablets:
8.1   10

Phones:
8.1   10

Adds ability to apply configurations to the device directly from the provisioning file or through a removable device (more info) . When unchecked ‘add a package’ option will be hidden under device settings. Allowed by default.
Mandate signed certificate for provisioning package PCs & tablets:
8.1   10

Phones:
8.1   10

Specifies whether provisioning packages must have a certificate signed by a device trusted authority. If a provisioning package is signed by a trusted provisioner, it can be installed on a device without a prompt for user consent. Disabled by default.
Remove provisioning package PCs & tablets:
8.1   10

Phones:
8.1   10

Allow users to remove a provisioning package for work or school under device settings. Allowed by default.
Show toast notification on lock screen PCs & tablets:
8.1   10

Phones:
8.1   10

Allow toast notification above the device lock screen. When unchecked, show notification on the lock screen option under device settings will be hidden. Allowed by default.
Receive advertisements over Bluetooth PCs & tablets:
8.1   10

Phones:
8.1   10

When checked users can receive advertisements over Bluetooth. Allowed by default.
Pair with other devices automatically PCs & tablets:
8.1   10

Phones:
8.1   10(Versions above 1609)

Allow the device to pair automatically with other devices over Bluetooth. Allowed by default.
Users can download Windows Beta updates PCs & tablets:
8.1   10

Phones:
8.1   10

Allow users to download Windows Beta Updates through Windows Insider Program. This is a drop-down box with three options, allow, disallow and not configured. Not configured by default.

Provisioning package

Windows provisioning makes it easy for Admins to configure end user’s devices without imaging. A provisioning package (.ppkg) is a container for a collection of configuration settings. Provisioning packages can be installed using removable media such as an SD card or USB flash drive, attached to an email, downloaded from a network share, deployed in NFC tags or barcodes.

Account Settings

Account based restrictions
Restriction Supported OS Description
MMS PCs & tablets:
8.1   10

Phones:
8.1   10(Versions above 1703)

Enables or disables MMS (Multimedia Messaging Service) send/receive functionality on the device. Allowed by default.
Sync MMS PCs & tablets:
8.1   10

Phones:
8.1   10(Versions above 1607)

Allow users to sync their MMS inbox with their phone, no matter which device is used to send or receive messages. Allowed by default.
RCS messaging PCs & tablets:
8.1   10

Phones:
8.1   10(Versions above 1703)

Allow users to send RCS (Rich Communication Services) messages. RCS is a text-message system that is richer and more interactive than SMS. Allowed by default.
OneDrive file sync PCs & tablets:
8.1   10

Phones:
8.1   10(Versions above 1703)

Allow users to sync files on their device to OneDrive, Microsoft’s cloud storage service so that they can be accessed from other devices. Disabled by default.

Customize Start Menu

On the left side of the Start Menu you can add certain Windows 10 folders to show up there, making it quicker to access them. By default, the File Explorer and Settings are the only folders listed there. The following restrictions allows Admin to customize start menu by choosing whether to show or hide shortcuts for some folders.

Restrictions on start menu customization
Restriction Supported OS Description
Documents folder PCs & tablets:
8.1   10(Versions above 1709)

Phones:
8.1   10

Controls the visibility of Documents shortcut on the Start menu. Documents folder is the standard location for storing user-created files. There is a drop-down box with three options, hide shortcut, show shortcut and not enforced. Not enforced by default.
Downloads folder PCs & tablets:
8.1   10(Versions above 1709)

Phones:
8.1   10

Controls the visibility of Downloads shortcut on the Start menu. By default, modern web browsers save files to the Downloads folder. There is a drop-down box with three options, hide shortcut, show shortcut and not enforced. Not enforced by default.
File Explorer PCs & tablets:
8.1   10(Versions above 1709)

Phones:
8.1   10

Controls the visibility of File Explorer shortcut on the Start menu. File Explorer is the file management application used by Windows operating systems to browse folders and files. There is a drop-down box with three options, hide shortcut, show shortcut and not enforced. Not enforced by default.
Home group PCs & tablets:
8.1   10(Versions above 1709)

Phones:
8.1   10

Controls the visibility of Home group shortcut on the Start menu. Home group allow users to share pictures, music, videos, documents, and printers with other people in their Home group network. There is a drop-down box with three options, hide shortcut, show shortcut and not enforced. Not enforced by default.
Music folder PCs & tablets:
8.1   10(Versions above 1709)

Phones:
8.1   10

Controls the visibility of Music folder shortcut on the Start menu.This is a drop-down box with three options, hide shortcut, show shortcut and not enforced. Not enforced by default.
Networks PCs & tablets:
8.1   10(Versions above 1709)

Phones:
8.1   10

Controls the visibility of Networks shortcut on the Start menu. This is a drop-down box with three options, hide shortcut, show shortcut and not enforced. Not enforced by default.
Personal folder PCs & tablets:
8.1   10(Versions above 1709)

Phones:
8.1   10

Controls the visibility of Personal folder shortcut on the Start menu. Personal folder stores the most frequently used folders in one location. There is a drop-down box with three options, hide shortcut, show shortcut and not enforced. Not enforced by default.
Pictures folder PCs & tablets:
8.1   10(Versions above 1709)

Phones:
8.1   10

Controls the visibility of Pictures folder shortcut on the Start menu. This is a drop-down box with three options, hide shortcut, show shortcut and not enforced. Not enforced by default.
Settings PCs & tablets:
8.1   10(Versions above 1709)

Phones:
8.1   10

Controls the visibility of Settings shortcut on the Start menu. Settings allows the user to customize and configure the operating system. There is a drop-down box with three options, hide shortcut, show shortcut and not enforced. Not enforced by default.
Videos folder PCs & tablets:
8.1   10(Versions above 1709)

Phones:
8.1   10

Controls the visibility of Videos folder shortcut on the Start menu. This is a drop-down box with three options, hide shortcut, show shortcut and not enforced. Not enforced by default.
Notes:

To add folders to start menu in Windows 10

  • Click on Start menu > Settings.
  • Click on Personalization > Start.
  • Click on Choose which folders appear on start.
  • Click on the switch under the folder you want to add.

  •  
  •  
  •  
  •  
  •  

Was this article helpful?

Related Articles

Leave a Comment