Security Policies - Microsoft Management Console

Endpoint Central supports configuring the following security policies in Microsoft Management Console category:

Security PolicyDescription
Restrict user from entering author modeUsers cannot create console files or add or remove snap-ins. Also, because they cannot open author-mode console files, they cannot use the tools that the files contain.
Restrict users to the explicitly permitted list of snap-insAll snap-ins are prohibited, except those that you explicitly permit. Use this setting if you plan to prohibit use of most snap-ins.  To explicitly permit a snap-in, open the Restricted/Permitted snap-ins setting folder and enable the settings representing the snap-in you want to permit.
Restrict/permit Component services snap-inIf the setting is enabled, the snap-in is permitted. If the setting is disabled, the snap-in is prohibited.  If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.
Restrict/permit Computer management snap-inIf the setting is enabled, the snap-in is permitted. If the setting is disabled, the snap-in is prohibited.  If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.
Restrict/permit Device manager snap-inIf the setting is enabled, the snap-in is permitted. If the setting is disabled, the snap-in is prohibited.  If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.
Restrict/permit Disk management snap-inIf the setting is enabled, the snap-in is permitted. If the setting is disabled, the snap-in is prohibited.  If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.
Restrict/permit Disk de-fragmentation snap-inIf the setting is enabled, the snap-in is permitted. If the setting is disabled, the snap-in is prohibited.

If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.
Restrict/permit Event viewer snap-inIf the setting is enabled, the snap-in is permitted. If the setting is disabled, the snap-in is prohibited.  If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.
Restrict/permit Fax services snap-inIf the setting is enabled, the snap-in is permitted. If the setting is disabled, the snap-in is prohibited.

If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.
Restrict/permit Indexing services snap-inIf the setting is enabled, the snap-in is permitted. If the setting is disabled, the snap-in is prohibited.  If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.
Restrict/permit Internet Information Services snap-inIf the setting is enabled, the snap-in is permitted. If the setting is disabled, the snap-in is prohibited.

If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.
Restrict/permit Local users and groups snap-inIf the setting is enabled, the snap-in is permitted. If the setting is disabled, the snap-in is prohibited.  If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.
Restrict/permit Performance logs and alerts snap-inIf the setting is enabled, the snap-in is permitted. If the setting is disabled, the snap-in is prohibited.  If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.
Restrict/permit Services snap-inIf the setting is enabled, the snap-in is permitted. If the setting is disabled, the snap-in is prohibited.  If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.
Restrict/permit Shared folders snap-inIf the setting is enabled, the snap-in is permitted. If the setting is disabled, the snap-in is prohibited.  If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.
Restrict/permit System information snap-inIf the setting is enabled, the snap-in is permitted. If the setting is disabled, the snap-in is prohibited.  If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.
Restrict/permit Telephony snap-inIf the setting is enabled, the snap-in is permitted. If the setting is disabled, the snap-in is prohibited.  If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.
Restrict/permit WMI control snap-inIf the setting is enabled, the snap-in is permitted. If the setting is disabled, the snap-in is prohibited.  If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.
Restrict/permit System properties snap-inIf the setting is enabled, the snap-in is permitted. If the setting is disabled, the snap-in is prohibited.  If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.
Restrict/permit Group policy snap-inIf the setting is enabled, the snap-in is permitted. If the setting is disabled, the snap-in is prohibited.  If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.
Restrict/permit Group policy tab for active directory tool snap-inIf the setting is enabled, the snap-in is permitted. If the setting is disabled, the snap-in is prohibited.  If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.
Restrict/permit Administrative templates (computer) snap-inIf the setting is enabled, the snap-in is permitted. If the setting is disabled, the snap-in is prohibited.  If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.
Restrict/permit Administrative templates (users) snap-inIf the setting is enabled, the snap-in is permitted. If the setting is disabled, the snap-in is prohibited.  If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.
Restrict/permit Folder redirection snap-inIf the setting is enabled, the snap-in is permitted. If the setting is disabled, the snap-in is prohibited.  If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.
Restrict/permit Internet explorer maintenance snap-inIf the setting is enabled, the snap-in is permitted. If the setting is disabled, the snap-in is prohibited.  If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.
Restrict/permit Remote installation services snap-inIf the setting is enabled, the snap-in is permitted. If the setting is disabled, the snap-in is prohibited.  If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.
Restrict/permit Scripts (logon/logoff) snap-inIf the setting is enabled, the snap-in is permitted. If the setting is disabled, the snap-in is prohibited.  If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.
Restrict/permit Scripts(startup/shutdown) snap-inIf the setting is enabled, the snap-in is permitted. If the setting is disabled, the snap-in is prohibited.  If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.
Restrict/permit Security settings snap-inIf the setting is enabled, the snap-in is permitted. If the setting is disabled, the snap-in is prohibited.  If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.
Restrict/permit Software installation (computer) snap-inIf the setting is enabled, the snap-in is permitted. If the setting is disabled, the snap-in is prohibited.  If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.
Restrict/permit Software installation (user) snap-inIf the setting is enabled, the snap-in is permitted. If the setting is disabled, the snap-in is prohibited.  If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.

The policy descriptions are taken from Microsoft Help Documentation

Trusted by