Support Center

Policies

Note:

Policies are currently unsupported for Windows Home versions.  Please see the Description for each policy on further specifics with version compatibility.

 
Name OS Description
Disable USB Storage Linux Prevents USB mass storage devices, such as flash drives and USB hard drives, from being used on the system. This policy works on CentOS 6-7, Debian 8-9, Red Hat Enterprise Linux 6-7, Ubuntu 14.04 and Ubuntu 16.04.
Local Firewall Controls Mac This policy manages the local host firewall settings. In order to enable Block All Incoming Connections or Enable Stealth Mode, Firewall must be enabled. (Only available for macOS 10.12+).
Analytics Mac This policy controls the ability of the user to manage diagnostic reporting to Apple should an error occur. (Only available for macOS 10.13+.).
Password Modification Mac This policy manages the ability of the user to change their password through System Preferences on selected machines. (Only available for macOS 10.13).
Power Controls Mac Control access to Shutdown, Restart, Sleep, and Power Off options at the login window and under the Apple menu.
Spotlight Internet Results Mac This policy manages the ability of the system to include Internet results in a Spotlight search.
Wallpaper Modification Mac This policy manages the ability of the user to change their wallpaper through System Preferences on selected machines. (Only available for macOS 10.13).
Login Window Controls Mac This policy controls the presentation of users at the login window on selected machines.
Login Window Text Mac This policy manages the text presented at the login window on selected machines.
Camera Control Mac This policy manages the ability of an application to access and use the built-in Camera.
Dictation Mac This policy manages the users ability to leverage Dictation on selected machines. (Only available for macOS 10.13+.)
Disable CD/DVD ROM Mac Prevent mounting of optical media.
Disable External Disk (USB) Mac Prevent mounting of external disk volumes. This includes USB and SD flash devices.
Disable Guest Account Mac Disable the local Guest account.
Gatekeeper Control Mac This policy controls the ability of the machine to install and run software by leveraging Gatekeeper in macOS.
JumpCloud App Controls Mac This policy controls the behavior of the JumpCloud Mac App on JumpCloud managed systems.
System Preferences Control Mac The user will only be able to access the features of System Preferences allowed by the administrator.
System Unlock Control Mac Users on managed machines will only be able to access the System Unlock features allowed by an administrator. Any feature that is unselected will no longer be available for users on managed machines to modify. (Only available for macOS 10.12+.)
System Update Mac This policy contains settings related to system updates. (Only available for macOS 10.13+.)
App Store Restrictions Mac This policy controls a user's ability to install applications from the Apple App Store.
Disable Siri Mac When applied, this policy will disable all access to the Siri assistant. Once applied users will need to logout/login to ensure complete application of the policy. Any attempt to access Siri will result in being prompted to configure Siri. Canceling the prompt will remove Siri from the Menu Bar. If Siri is pinned to the Dock the icon will need to be manually removed. If the policy is removed, the user must logout/login to re-enable Siri.
FileVault 2 Mac This policy allows you to enable and enforce FileVault. (Only available for macOS 10.13+.)
iCloud Access Mac Users on managed machines will only be able to access the features of iCloud allowed by an administrator. Any feature that is unselected will no longer be available for users on managed machines to modify. (Only available for macOS 10.12+.)
iTunes Music Service Mac This policy manages the ability of the system to use the Music feature in iTunes. (Only available for macOS 10.13+.).
Lock Screen Mac The user's screen saver will lock after the amount of seconds specified. A password will be required to unlock the screen saver.
Restrict Settings App Visibility Windows This policy will hide the selected pages from view in the UWP Settings Application. If all pages in a category are hidden, the category will also be hidden. Not all options will be present on every system, and labels may vary slightly from system to system. This policy works on Windows 10 Build 1607 and later.
Restrict Control Panel Access Windows Users on managed machines will only be able to access the features of Control Panel allowed by administrators. Any feature that is selected will no longer be available for users on managed machines to modify. This policy works on Windows 7, 8.1, and 10, as well as Server 2008 R2, 2012 R2, and 2016.
Disable USB Storage Windows Prevents USB mass storage devices, such as flash drives and USB hard drives, from being used on the system. This policy works on Windows 7, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, Windows 10, and Windows Server 2016.
Lock Screen Windows When a managed system is inactive for the length of time specified in the policy's configuration, the screen saver will activate and lock the machine. A password will be required for unlocking the machine. This policy works on Windows 7, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, Windows 10, and Windows Server 2016.
Built-in Guest Account Status Windows This policy will disable and enable the built-in guest account. This policy works on Windows 7+ systems.
Disable Cortana Windows This policy prevents the usage of Microsoft's Cortana on systems when applied. Users will still be able to leverage the search functionality on their system with Cortana disabled. This Policy works on Windows 10+ systems only.
Disable Windows Spotlight Features Windows Disables the systems ability to utilize Windows Spotlight. This policy works on Windows 10 Enterprise and Education only.
Disable CD & DVD read access Windows Disables the system read access to CD & DVD removable storage classes. This policy works on Windows 7, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, Windows 10 and Windows Server 2016.
Disable Windows Store Application Windows This policy will ensure that system can not launch the Windows Store application. This policy works on Windows 8 & 10 Enterprise and Education only.
Allow Use Of Camera Windows This policy will control the use of camera devices on the system. This policy works on Windows 10+ systems.
Allow The Use Of Biometrics Windows This policy will ensure the system is able to use Windows Biometric Service. This policy works on Windows 7,8.1,10,2008r2,2012r2 & 2016 systems.
Turn Off Autoplay. Windows This policy will ensure that the system can not launch autoplay features. This policy works on Windows 7,8.1,10,2008r2,2012r2 & 2016 systems.
Block Microsoft Accounts Windows This policy will prevent and allow users from adding or logging in with Microsoft Accounts. This policy works on Windows 8+ systems.
Rename Local Administrator Account Windows This policy allows the renaming of the inbuilt Local Administrator Account. This policy works on Windows 7+ systems.
Built-in Administrator Account Status Windows This policy will disable and enable the built-in administrator account. It is advised to have an additional local administrator account to manage the system. This policy works on Windows 7+ systems.
Rename Local Guest Account Windows This policy allows the renaming of the inbuilt Local Guest Account. This policy works on Windows 7+ systems.
Do Not Require CTRL + ALT + DEL on logon screen Windows This policy will ensure that CTRL + ALT + DEL is required before logging into a system. This Policy works on Windows 7+ systems.
Do Not Display Last Username on Logon Screen Windows This policy will ensure that entering a username and password is required before logging into a system. This Policy works on Windows 7+ systems.
Allow System To Be Shutdown Without Having To Logon Windows This policy will ensure the system is able to be shutdown from the logon screen. This Policy works on Windows 7+ systems.
Disable Windows Store & Universal Windows Platform Applications Windows Disables the systems ability to launch Windows Store and all Universal Windows Platform Applications on the system. This policy works on Windows 10 Enterprise and Education only.
Display User Info When The Session Is Locked Windows This policy will ensure that the logged in users information will show or not show when the system is locked. It is advised to also enforce 'Do Not Display Last Username On Logon Screen' for this policy to be effective. This Policy works on Windows 7+ systems.
Message Text For Users Attempting To Log On Windows This policy specifies a text message & title caption that is displayed to users when they log on.
Bitlocker Full Disk Encryption Windows This policy will enable and enforce Bitlocker. This policy works on Windows 8.1 Pro/Ent & 10 Pro/Ent/Edu systems. Target systems must have TPM 2.0. If Bitlocker is already enabled on the target system, it must have a single Bitlocker numerical password set.
Configure Windows Updates Windows This policy manages the system update behavior based on the options selected below.
 

Last Updated: Mar 14, 2019 12:57PM MDT

Related Articles
31b11a79e2c94470a66430cfe6d3eecd@jumpcloud.desk-mail.com
https://cdn.desk.com/
false
desk
Loading
seconds ago
a minute ago
minutes ago
an hour ago
hours ago
a day ago
days ago
about
false
Invalid characters found
/customer/en/portal/articles/autocomplete