Legacy RADIUS server IPs will be deprecated on Jan 31, 2019. Please see this KB for more info.

Support Center

Policies

NameOSDescription
Disable USB StorageLinuxPrevents USB mass storage devices, such as flash drives and USB hard drives, from being used on the system. This policy works on CentOS 6-7, Debian 8-9, Red Hat Enterprise Linux 6-7, Ubuntu 14.04 and Ubuntu 16.04.
Login Window TextMacThis policy manages the text presented at the login window on selected machines.
Disable Guest AccountMacDisable the local Guest account. This will prevent Guest from appearing as an available login account at the login window.
DictationMacThis policy manages the users ability to leverage Dictation on selected machines. (Only available for macOS 10.13).
Camera ControlMacThis policy manages the ability of an application to access and use the built-in Camera.
Disable External Disk (USB)MacPrevent mounting of external disk volumes. This includes USB and SD flash devices.
Disable CD/DVD ROMMacPrevent mounting of optical media.
Disable SiriMacWhen applied, this policy will disable all access to the Siri assistant. Once applied users will need to logout/login to ensure complete application of the policy. Any attempt to access Siri will result in being prompted to configure Siri. Canceling the prompt will remove Siri from the Menu Bar. If Siri is pinned to the Dock the icon will need to be manually removed. If the policy is removed, the user must logout/login to re-enable Siri.
Login Window ControlsMacThis policy controls the presentation of users at the login window on selected machines.
Lock ScreenMacThe user's screen saver will lock after the amount of seconds specified. A password will be required to unlock the screen saver.
Apple App Store RestrictionsMacThis policy has three controls to restrict a user's ability to install applications from the Apple App Store. 1. Restrict all App Store installs and updates to Admin users 2. Restrict App Store to System and App updates only.
iCloud AccessMacUsers on managed machines will only be able to access the features of iCloud allowed by an administrator. Any feature that is unselected will no longer be available for users on managed machines to modify. (Only available for macOS 10.12, 10.13).
iTunes Music ServiceMacThis policy manages the ability of the system to use the Music feature in iTunes. (Only available for macOS 10.13).
Local Firewall ControlsMacThis policy manages the local host firewall settings. In order to enable Block All Incoming Connections or Enable Stealth Mode, Firewall must be enabled. (Only available for macOS 10.12, 10.13).
Password ModificationMacThis policy manages the ability of the user to change their password through System Preferences on selected machines. (Only available for macOS 10.13).
Wallpaper ModificationMacThis policy manages the ability of the user to change their wallpaper through System Preferences on selected machines. (Only available for macOS 10.13).
Mac AnalyticsMacThis policy controls the ability of the user to manage diagnostic reporting to Apple should an error occur. (Only available for macOS 10.13).
Power ControlsMacControl access to Shutdown, Restart, Sleep, and Power Off options at the login window and under the Apple menu.
Spotlight Internet ResultsMacThis policy manages the ability of the system to include Internet results in a Spotlight search.
Gatekeeper ControlMacThis policy controls the ability of the machine to install and run software by leveraging Gatekeeper in macOS.
System Unlock ControlMacUsers on managed machines will only be able to access the System Unlock features allowed by an administrator. Any feature that is unselected will no longer be available for users on managed machines to modify. (Only available for macOS 10.12, 10.13).
System UpdateMacThis policy contains settings related to system updates. (Only available for macOS 10.13+.)
JumpCloud App ControlsMacThis policy controls the behavior of the JumpCloud Mac App on JumpCloud managed systems.
System Preferences ControlMacThe user will only be able to access the features of System Preferences allowed by the administrator.
Disable Windows Store & Universal Windows Platform ApplicationsWindowsDisables the systems ability to launch Windows Store and all Universal Windows Platform Applications on the system. This policy works on Windows 10 Enterprise and Education only.
Display User Info When The Session Is LockedWindowsThis policy will ensure that the logged in users information will show or not show when the system is locked. It is advised to also enforce 'Do Not Display Last Username On Logon Screen' for this policy to be effective. This Policy works on Windows 7+ systems.
Allow Use Of CameraWindowsThis policy will control the use of camera devices on the system. This policy works on Windows 10+ systems.
Disable USB StorageWindowsPrevents USB mass storage devices, such as flash drives and USB hard drives, from being used on the system. This policy works on Windows 7, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, Windows 10, and Windows Server 2016.
Restrict Control Panel AccessWindowsUsers on managed machines will only be able to access the features of Control Panel allowed by administrators. Any feature that is selected will no longer be available for users on managed machines to modify. This policy works on Windows 7, 8.1, and 10, as well as Server 2008 R2, 2012 R2, and 2016.
Allow The Use Of BiometricsWindowsThis policy will ensure the system is able to use Windows Biometric Service. This policy works on Windows 7,8.1,10,2008r2,2012r2 & 2016 systems.
Turn Off Autoplay.WindowsThis policy will ensure that the system can not launch autoplay features. This policy works on Windows 7,8.1,10,2008r2,2012r2 & 2016 systems.
Block Microsoft AccountsWindowsThis policy will prevent and allow users from adding or logging in with Microsoft Accounts. This policy works on Windows 8+ systems.
Lock ScreenWindowsWhen a managed system is inactive for the length of time specified in the policy's configuration, the screen saver will activate and lock the machine. A password will be required for unlocking the machine. This policy works on Windows 7, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, Windows 10, and Windows Server 2016.
Built-in Guest Account StatusWindowsThis policy will disable and enable the built-in guest account. This policy works on Windows 7+ systems.
Disable CortanaWindowsThis policy prevents the usage of Microsoft's Cortana on systems when applied. Users will still be able to leverage the search functionality on their system with Cortana disabled. This Policy works on Windows 10+ systems only.
Rename Local Administrator AccountWindowsThis policy allows the renaming of the inbuilt Local Administrator Account. This policy works on Windows 7+ systems.
Rename Local Guest AccountWindowsThis policy allows the renaming of the inbuilt Local Guest Account. This policy works on Windows 7+ systems.
Built-in Administrator Account StatusWindowsThis policy will disable and enable the built-in administrator account. It is advised to have an additional local administrator account to manage the system. This policy works on Windows 7+ systems.
Disable Windows Spotlight FeaturesWindowsDisables the systems ability to utilize Windows Spotlight. This policy works on Windows 10 Enterprise and Education only.
Restrict Settings App VisibilityWindowsThis policy will hide the selected pages from view in the UWP Settings Application. If all pages in a category are hidden, the category will also be hidden. Not all options will be present on every system, and labels may vary slightly from system to system. This policy works on Windows 10 Build 1607 and later.
Disable CD & DVD read accessWindowsDisables the system read access to CD & DVD removable storage classes. This policy works on Windows 7, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, Windows 10 and Windows Server 2016.
Message Text For Users Attempting To Log OnWindowsThis policy specifies a text message & title caption that is displayed to users when they log on.
Configure Windows UpdatesWindowsThis policy manages the system update behavior based on the options selected below.
Bitlocker Full Disk EncryptionWindowsThis policy will enable and enforce Bitlocker. This policy works on Windows 8.1 Pro/Ent & 10 Pro/Ent/Edu systems. Target systems must have TPM 2.0. If Bitlocker is already enabled on the target system, it must have a single Bitlocker numerical password set.
Do Not Require CTRL + ALT + DEL on logon screenWindowsThis policy will ensure that CTRL + ALT + DEL is required before logging into a system. This Policy works on Windows 7+ systems.
Do Not Display Last Username on Logon ScreenWindowsThis policy will ensure that entering a username and password is required before logging into a system. This Policy works on Windows 7+ systems.
Allow System To Be Shutdown Without Having To LogonWindowsThis policy will ensure the system is able to be shutdown from the logon screen. This Policy works on Windows 7+ systems.
Disable Windows Store ApplicationWindowsThis policy will ensure that system can not launch the Windows Store application. This policy works on Windows 8 & 10 Enterprise and Education only.
 

Last Updated: Dec 20, 2018 03:32PM MST

Related Articles
31b11a79e2c94470a66430cfe6d3eecd@jumpcloud.desk-mail.com
https://cdn.desk.com/
false
desk
Loading
seconds ago
a minute ago
minutes ago
an hour ago
hours ago
a day ago
days ago
about
false
Invalid characters found
/customer/en/portal/articles/autocomplete