Security Settings

User Configuration\Administrative Templates\Windows Components\Microsoft Management Console\Restricted/Permitted snap-ins\Group Policy

Description

Permits or prohibits use of the Security Settings folders in the Group Policy snap-in.

  • If you enable this policy, these snap-in folders are permitted.
  • If you disable the policy, these snap-in folders are prohibited.
  • If this policy is not configured, the setting of the Restrict users to the explicitly permitted list of snap-ins policy determines whether this snap-in folder permitted or prohibited.

If Restrict users to the explicitly permitted list of snap-ins is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in folder, enable this policy. If this policy is not configured (or disabled), these snap-in folders are prohibited.

If Restrict users to the explicitly permitted list of snap-ins is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in folder, disable this policy. If this policy is not configured (or enabled), these snap-in folders are permitted.

When a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.