Creating a GPO for Windows 10 21h2

Alan Raczek 1 Reputation point
2022-09-06T17:16:39.437+00:00

Hi,

Been a while since I worked with GPO's so bear with me. I want to create a Windows 10 GPO essentially to disable services per STIG. I set up a test
environment with Server 2019 on VMware workstation and I used an external Windows 10 machine. I copied the ADMX and lang files from the PolicyDefinitions folder
on Windows 10, created the central store under Windows\sysvol\sysvol\<domain>\PolicyDefinitions on the DC. rebooted everything then attempted to make a
GPO on the Windows DC but I do not see some of the services there that I want to disable like cellulat time, fax, xboxXXXXXX, bluetooth hands free etc.

What am I doing wrong? I know I could set registry entries via preferences but that would be a drawn out process trying to find the keys and values.

Ideas?

...Ar

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
5,099 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. JimmySalian-2011 42,071 Reputation points
    2022-09-06T20:18:32.367+00:00

    Hi,

    As far as I know, there is a package that you need to use to configure for Windows 10 GPOs using STIG baselines - gpo

    This package contains ADMX template files, GPO backup exports, GPO reports, and WMI filter exports and STIG Checklist files. It is to provide enterprise administrators the supporting GPOs and related files to aid them in the deployment of GPOs within their enterprise to meet STIG requirements. See the ReadMe.txt file for additional information.

    ==
    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments