Category Filter
 
 

Restrictions

You can impose restrictions on the managed Windows devices by creating a profile and associating the profile to the devices or groups. Restrictions profile is applicable for devices running Windows 8.1 or later versions. 

Note:To view a detailed comparison of various policies supported with respect to specific OS version, click here.

Profile Description

Profile SpecificationDescription
Device Functionality
Disable Storage DevicesAllows you to disable the use of external storage devices such as USB drives or SD cards on the device. This helps prevent unauthorized data transfer and enhances security.
CameraControls access to the device's camera. You can either allow or restrict camera usage.
Screen CaptureThis setting governs the ability to take screenshots or screen recordings on the device. Restricting screen capture can prevent sensitive information from being shared.
TelemetryManages the amount of diagnostic data that the device sends to Microsoft. Options include allowing all data, sending only partial data, or disabling telemetry entirely. This helps to control privacy and security compliance.
Microsoft feedback notificationsAllows you to restrict or allow notifications prompting users to provide feedback to Microsoft.
Modify device date & timeControls whether users are allowed to manually change the device’s date and time settings.
Modify device nameDetermines whether users are permitted to change the name of the device.
Network
Internet sharingControls whether users can share the device's internet connection with other devices (e.g., through tethering or hotspot). Disabling this can prevent unauthorized use of network resources.
VPNDetermines whether users are allowed to establish a VPN connection on the device. Restricting VPN usage may be necessary for security and compliance policies.
VPN usage while using cellular dataAllows or restricts VPN usage when the device is connected to a cellular data network. You can also set this to "User Controlled" for flexibility based on user or network preferences.
VPN roaming while using cellular dataControls VPN usage when the device is roaming on cellular networks. Setting this option to "User Controlled" allows the user to decide, while restricting it can help avoid additional data charges.
Cellular NetworkManages the cellular data connection of the device. You can turn the cellular network on or off to control data usage and mobile connectivity.
Wi-FiEnables or restricts the device's ability to connect to Wi-Fi networks. Disabling Wi-Fi may be useful in secure environments where only wired connections are allowed.
Allow Wi-Fi ConfigurationControls whether users are allowed to configure Wi-Fi settings on the device. Restricting this ensures that only authorized Wi-Fi networks can be connected.
Automatically connect to Wi-Fi Sense hotspotsWi-Fi Sense is a feature that allows devices to automatically connect to trusted open Wi-Fi networks. Disabling this can prevent the device from automatically joining unsecured networks.
Security and Privacy
Location servicesControls whether location services are enabled or disabled on the device. Allowing this grants apps and services access to the device's location, while restricting it enhances privacy by preventing location tracking. You can also set this to be User Controlled.
Sync settings across all devicesDetermines whether users can sync settings (such as themes, passwords, and language preferences) across multiple devices using their Microsoft account. Restricting this can help keep settings isolated to specific devices.
Microsoft account connectionManages whether users are allowed to connect their Microsoft account to the device. Restricting this can prevent access to Microsoft services and apps tied to personal accounts, promoting stricter control over data sharing.
Adding non-Microsoft accounts manuallyControls whether users can add accounts from non-Microsoft services (e.g., Google, Yahoo) to the device. Restricting this can help limit external account integration and improve data security.
Developer unlockGoverns whether the device can be unlocked for developer mode, which allows sideloading of apps and advanced settings. Setting this to "User Controlled" can allow flexible usage while maintaining security.
Reset deviceAllows or restricts the option for users to reset the device to factory settings. Restricting this can prevent accidental or unauthorized device resets.
Toast notificationsControls whether users can receive toast notifications on the device (pop-up alerts from apps). Restricting this can reduce distractions or improve focus in a work environment.
FIPS complianceEnsures the device uses FIPS-compliant encryption algorithms. Enabling this enhances security by adhering to government-level encryption standards.
Add provisioning packageManages whether users can add provisioning packages, which are used to configure device settings and policies. Restricting this can prevent unauthorized changes to device configurations.
Remove existing provisioning packageControls whether users can remove provisioning packages that are already applied to the device. Restricting this ensures that applied configurations remain intact.
Applications
Install Non-Store appsControls whether users can install apps from sources other than the Microsoft Store. Allowing this gives flexibility to install third-party apps, while restricting it ensures that only vetted apps from the store can be installed, enhancing security.
Install apps only in device memoryDetermines whether apps can only be installed in the internal storage of the device. Restricting apps to internal memory can ensure better performance and prevent external storage usage, which may be less secure.
Store app data only in device memoryEnsures that app-related data (e.g., settings, cache) is stored only on the device’s internal memory.
Auto-Update Store appsGoverns whether apps downloaded from the Microsoft Store automatically update. Setting this to "User Controlled" allows users to decide, while automatic updates can ensure apps are always up-to-date with security patches and features.
Bluetooth
BluetoothEnables or restricts the device from connecting to other devices via Bluetooth.
Bluetooth discoveryControls whether the device can be discoverable by other Bluetooth-enabled devices. Allowing discovery makes the device visible for pairing, while restricting it prevents unauthorized pairing.
Bluetooth pre-pairingDetermines whether the device can be pre-paired with specific Bluetooth devices before deployment. Allowing this simplifies the setup process for certain peripherals (e.g., keyboards, mice), while restricting it may require users to pair devices manually. For details, refer here.
Bluetooth services advertisingGoverns whether the device can advertise its Bluetooth services to nearby devices. Allowing advertising enables other devices to detect services offered by the device (e.g., file transfer, audio streaming), while restricting it limits Bluetooth functionality and enhances privacy.
Jump To