# Block Control Panel with Group Policy: 4 Secure Windows 11 Methods

Source: https://srvscripts.com/guides/block-control-panel-with-group-policy/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

To block Control Panel with Group Policy on Windows 11 and Windows Server 2025, you use the Control Panel node of the Administrative Templates: one setting blocks Control Panel and the Settings app completely, two others hide or allow individual applets, and “Settings Page Visibility” hides chosen Settings pages. This guide covers all four, the related lockdowns for Run, the command prompt, Registry Editor and Task Manager, the registry values behind them, Intune, exemptions for IT staff, RDS hosts, verification and rollback.

**Short answer:** Create a GPO linked to the OU that holds the user accounts and enable `User Configuration » Policies » Administrative Templates » Control Panel » "Prohibit access to Control Panel and PC settings"`. After `gpupdate /force` and a new sign-in, `control.exe` and the Settings app no longer start for those users. If users still need some pages, hide only those pages instead.

In short: Create a GPO linked to the OU that holds the user accounts and enable User Configuration » Policies » Administrative Templates » Control Panel » “Prohibit access to Control Panel and PC settings”.

## Which method to use

There are several ways to block Control Panel with Group Policy. The settings overlap, so choose by how much the user still needs.

| Method | Scope | Blocks | Pros | Cons |
| --- | --- | --- | --- | --- |
| “Prohibit access to Control Panel and PC settings” | User | Control Panel and the whole Settings app | One setting, nothing to maintain | Blocks harmless pages such as display scaling, sound output and Wi-Fi |
| “Hide specified Control Panel items” | User | Listed applets only | Precise block-list | No effect on the Settings app |
| “Show only specified Control Panel items” | User | Every applet not on the list | Tight allow-list for kiosks | Ignored if the hide list is also enabled |
| “Settings Page Visibility” | Computer or user | Chosen Settings pages (hide or show only) | Fine-grained control of the modern Settings app | Does not touch classic Control Panel applets |
| Intune (Settings catalog / ADMX) | Device or user | Same as above | Covers Entra-joined devices | Needs an Intune licence |

For most offices, the best balance is “Settings Page Visibility” to hide sensitive pages plus “Hide specified Control Panel items” for the matching classic applets. Keep the full prohibition for kiosks, classrooms and shared RDS hosts.

## Prerequisites

Before you block Control Panel with Group Policy, check the following:

- Windows 11 Pro, Enterprise or Education, or Windows Server 2016 to 2025, joined to the domain.

- Group Policy Management Console and rights to create and link GPOs.

- Current Windows 11 ADMX files in the Central Store (`\\contoso.com\SYSVOL\contoso.com\Policies\PolicyDefinitions`). Settings Page Visibility is in `ControlPanel.admx` and appears under both Computer and User Configuration in current templates.

- A test OU with a test user and a test PC, plus a separate admin account that is not affected.

## Method 1: Prohibit access to Control Panel and Settings

- Open **Group Policy Management** (`gpmc.msc`), right-click the user OU and choose **Create a GPO in this domain, and Link it here**. Name it, for example, USR – Block Control Panel.

- Edit it and go to `User Configuration » Policies » Administrative Templates » Control Panel`.

- Open **“Prohibit access to Control Panel and PC settings”**, choose **Enabled** and click **OK**.

- Sign in as a test user and try Win+I, `control` and an item such as `ncpa.cpl`. Each is blocked with a restriction message.

The setting stops `control.exe` and `SystemSettings.exe` from starting and removes Control Panel from Start and File Explorer. It is a user setting, so it follows the account to any PC where the GPO applies. It writes `NoControlPanel = 1` (REG_DWORD) to `HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer`.

Standalone consoles such as `devmgmt.msc` or `services.msc` are not Control Panel and still open, although standard users cannot change anything that needs administrator rights. When you block Control Panel with Group Policy, test the everyday tasks that open Settings pages, such as adding a printer or connecting to a VPN, and give users another route for them.

## Method 2: Hide or allow specific Control Panel items

If you block Control Panel with Group Policy completely, users also lose harmless applets such as Mouse and Sound. Hiding only the risky applets is often enough.

### Hide specified Control Panel items

- In the same node, open **“Hide specified Control Panel items”** and choose **Enabled**.

- Click **Show** next to List of disallowed Control Panel items.

- Enter one canonical name per row, for example `Microsoft.ProgramsAndFeatures`, `Microsoft.NetworkAndSharingCenter` and `Microsoft.UserAccounts`.

- Click **OK** twice.

The applets disappear from Control Panel and cannot be opened through `control.exe /name` or shortcuts. The setting writes `DisallowCpl = 1` and a subkey `DisallowCpl` with numbered REG_SZ values (`1`, `2` …) holding the names.

### Show only specified Control Panel items

For an allow-list, enable **“Show only specified Control Panel items”** and list the applets users may open, for example `Microsoft.Mouse` and `Microsoft.Sound`. It writes `RestrictCpl = 1` and a `RestrictCpl` subkey. Do not enable it together with the hide list: when both are enabled, the show-only list is ignored.

### Canonical names

| Applet | Canonical name |
| --- | --- |
| Windows Tools (Administrative Tools) | Microsoft.AdministrativeTools |
| Programs and Features | Microsoft.ProgramsAndFeatures |
| Network and Sharing Center | Microsoft.NetworkAndSharingCenter |
| User Accounts | Microsoft.UserAccounts |
| Credential Manager | Microsoft.CredentialManager |
| Device Manager | Microsoft.DeviceManager |
| Devices and Printers | Microsoft.DevicesAndPrinters |
| System | Microsoft.System |
| Windows Defender Firewall | Microsoft.WindowsFirewall |
| Internet Options | Microsoft.InternetOptions |
| Power Options | Microsoft.PowerOptions |
| Date and Time | Microsoft.DateAndTime |
| Region | Microsoft.RegionAndLanguage |
| BitLocker Drive Encryption | Microsoft.BitLockerDriveEncryption |
| Recovery | Microsoft.Recovery |
| Mouse / Sound | Microsoft.Mouse / Microsoft.Sound |

These names only affect classic Control Panel. The matching Settings pages stay reachable until you hide them with Method 3.

## Method 3: Settings Page Visibility

- Go to `Computer Configuration » Policies » Administrative Templates » Control Panel` (or the same path under User Configuration).

- Open **“Settings Page Visibility”** and choose **Enabled**.

- In Settings Page Visibility, enter either a `hide:` list or a `showonly:` list of page identifiers separated by semicolons, for example:

```
hide:windowsupdate;recovery;network-proxy;network-vpn;remotedesktop;developers
```

- Click **OK**. Close and reopen Settings on the client after `gpupdate /force`.

The identifier is the `ms-settings:` URI without the prefix. Hidden pages vanish from Settings, a category disappears when all its pages are hidden, and opening a blocked URI directly lands on the Settings home page. The computer setting writes `SettingsPageVisibility` (REG_SZ) to `HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer`; the user setting writes the same value under HKCU.

| Settings page | Identifier |
| --- | --- |
| Windows Update | windowsupdate |
| Recovery | recovery |
| Installed apps / Apps & features | appsfeatures |
| Optional features | optionalfeatures |
| Default apps | defaultapps |
| Proxy / VPN | network-proxy / network-vpn |
| Network status | network-status |
| Remote Desktop | remotedesktop |
| For developers | developers |
| Sign-in options | signinoptions |
| Date & time | dateandtime |
| Windows Security | windowsdefender |
| Storage | storagesense |
| Power | powersleep |
| Printers & scanners | printers |
| Background / Themes / Lock screen | personalization-background / themes / lockscreen |
| About | about |

For a kiosk, reverse the logic: `showonly:display;sound;bluetooth;printers`. On Windows 11 22H2 and later, hiding a page whose URI contains `quietmoments` also hides the Notifications page. Hiding `windowsupdate` only hides the page; updates keep installing according to your update policies.

## Related lockdowns

Users who cannot open Control Panel often try the command line next. These User Configuration settings complete the lockdown:

| Policy (User Configuration » Policies » Administrative Templates) | Registry value | Notes |
| --- | --- | --- |
| Start Menu and Taskbar » “Remove Run menu from Start Menu” | NoRun = 1 under HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer | Also disables Win+R |
| System » “Prevent access to the command prompt” | DisableCMD under HKCU\Software\Policies\Microsoft\Windows\System | Option to also disable batch script processing; leave that at No if logon scripts use .bat or .cmd files |
| System » “Prevent access to registry editing tools” | DisableRegistryTools under HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System | Option to also block silent regedit /s imports |
| System » Ctrl+Alt+Del Options » “Remove Task Manager” | DisableTaskMgr = 1 under HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System | Also removes Task Manager from the Ctrl+Alt+Del screen |
| System » “Don’t run specified Windows applications” | DisallowRun under the Explorer policies key | Only covers programs started by File Explorer; use AppLocker or App Control for real enforcement |

None of these stop PowerShell. If standard users must not run scripts, use AppLocker or App Control for Business rules rather than more Explorer restrictions.

## Registry values reference

Use this table for scripts, audits and non-domain PCs. Set the values with Group Policy Preferences only if you cannot use the Administrative Templates settings; preference-written values are not removed when the GPO goes out of scope unless you configure removal.

| Setting | Key | Value |
| --- | --- | --- |
| Prohibit Control Panel and Settings | HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer | NoControlPanel REG_DWORD 1 |
| Hide specified items | Same key, plus subkey DisallowCpl | DisallowCpl REG_DWORD 1; subkey values REG_SZ |
| Show only specified items | Same key, plus subkey RestrictCpl | RestrictCpl REG_DWORD 1; subkey values REG_SZ |
| Settings Page Visibility | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer (or HKCU) | SettingsPageVisibility REG_SZ, e.g. hide:recovery |

## Intune

Devices that never contact a domain controller cannot receive the GPO, but Intune delivers the same settings:

- In the Intune admin center go to **Devices » Configuration » Create » New policy**, platform Windows 10 and later, profile type Settings catalog.

- For Settings pages, add **Settings » Page Visibility List** and enter the same `hide:` or `showonly:` string. It maps to the `Settings/PageVisibilityList` policy, which has device and user scope.

- For Control Panel, search the catalog for **“Prohibit access to Control Panel and PC settings”**, **“Hide specified Control Panel items”** or **“Show only specified Control Panel items”**. These are ADMX-backed user settings, so assign the profile to user groups.

- Assign to a pilot group, sync the device and check **Device configuration** status.

Do not target the same device with both a GPO and an Intune profile for these settings. Pick one source per device to keep troubleshooting simple.

## Exempt IT staff with security filtering

Because the Control Panel settings are user settings, the exemption is based on user groups:

- In GPMC select the GPO and open the **Delegation** tab, then click **Advanced**.

- Add the group GRP-IT-Admins, tick **Deny** for **Apply group policy** and leave **Read** allowed.

- Confirm the deny prompt. Keep Authenticated Users (or at least Domain Computers) with **Read**, otherwise the GPO cannot be read after the MS16-072 change.

The alternative is to remove Authenticated Users from **Security Filtering**, add a group of restricted users, and add Domain Computers with Read on the Delegation tab. Allow-listing is clearer when only one department must be locked down. When you block Control Panel with Group Policy for the whole company, the deny entry for IT is quicker.

## RDS session hosts and kiosks: loopback processing

On Remote Desktop Session Hosts, you usually want the restrictions for everyone who signs in to those servers, but not when the same users sign in to their own PCs. Use loopback processing:

- Create a GPO linked to the OU that holds the RDS hosts and configure the user settings above in it.

- In the same GPO enable `Computer Configuration » Policies » Administrative Templates » System » Group Policy » "Configure user Group Policy loopback processing mode"` and choose **Merge** (keep normal user GPOs and add these) or **Replace** (use only GPOs linked to the server’s OU).

- Keep the IT deny entry. With loopback, the security filter is checked against the user, so add the IT group with Deny as above.

Loopback is the standard way to block Control Panel with Group Policy on session hosts and shared kiosks without affecting the same accounts elsewhere.

## Verify it works

After you block Control Panel with Group Policy, check a test session step by step:

- Sign in as a test user and run `gpupdate /force`, then sign out and in again.

- Run `gpresult /r /scope user` and confirm the GPO appears under Applied Group Policy Objects. For the Settings page policy use `gpresult /r /scope computer` as an administrator.

- Query the values:

```
reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowCpl"reg query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v SettingsPageVisibility
```

- Test the entry points users try: `control`, `control /name Microsoft.ProgramsAndFeatures`, `appwiz.cpl`, `start ms-settings:recovery` and right-click » **Display settings** on the desktop.

- For a full report, run `gpresult /h C:\Temp\gp.html` and check the winning GPO for each setting.

## Troubleshooting

Most failures come from scope, filtering or old templates:

| Symptom | Cause | Fix |
| --- | --- | --- |
| Policy has no effect | User settings in a GPO linked to a computer OU | Link to the user OU or enable loopback on the computer OU |
| Admins are blocked too | No exemption; admins are in the linked OU | Add the IT group with Deny “Apply group policy” |
| Settings pages still visible | Typo in identifier, or Settings was already open | Check the URI name and restart the Settings app |
| Show-only list ignored | Hide list also enabled | Use one of the two settings, not both |
| Applet still opens by .cpl name | Wrong canonical name in the list | Use the Microsoft.* name from the table |
| GPO missing from gpresult | Security filtering removed Read for computers | Give Domain Computers or Authenticated Users Read |
| Settings not in the editor | Old ADMX files in the Central Store | Update the Central Store with current Windows 11 templates |

## Roll back

- Set each setting to **Not Configured** (or unlink the GPO). Administrative Templates settings are removed from the registry at the next refresh; users need to sign out and in again.

- To release one user quickly, add them to the exempt group and run `gpupdate /force`.

- If you set the values with preferences or scripts, delete them explicitly, for example `reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoControlPanel /f`.

- In Intune, unassign or delete the profile and sync the device.

Roll out any change that uses these settings to a pilot group first, and document which Settings pages you hide so the service desk knows why a page is missing.

## Block Control Panel with Group Policy at a glance

Covers: Which method to use, Prerequisites, Method 1: Prohibit access to Control Panel and Settings and Method 2: Hide or allow specific Control Panel items.

**Official documentation:** [ADMX_ControlPanel Policy CSP](https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-admx-controlpanel), [Settings Policy CSP (PageVisibilityList)](https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-settings), [Canonical names of Control Panel items](https://learn.microsoft.com/en-us/windows/win32/shell/controlpanel-canonical-names).

**Related guides:** [Group Policy loopback processing: merge vs replace for RDS hosts and kiosks](/guides/group-policy-loopback-processing/) · [GPO security filtering: target or exclude users and computers](/guides/group-policy-security-filtering/) · [AppLocker with Group Policy](/guides/applocker-group-policy/).

## Frequently asked questions

### Does “Prohibit access to Control Panel and PC settings” also block the Settings app?

Yes. It stops both control.exe and SystemSettings.exe from starting, so users cannot open Control Panel, the Settings app or their individual pages.

### How do I hide only some Settings pages on Windows 11?

Enable “Settings Page Visibility” under Administrative Templates » Control Panel and enter a list such as hide:windowsupdate;recovery. Each entry is the ms-settings URI without the ms-settings: prefix.

### Can I block Control Panel for users but not for IT staff?

Yes. On the GPO’s Delegation tab, add the IT group and set Apply group policy to Deny, while keeping Read for Authenticated Users or Domain Computers so the GPO still processes.

### Why does the Control Panel policy not apply to users on an RDS host?

The settings are user settings, so a GPO linked to the server OU is ignored for users unless you enable loopback processing in Merge or Replace mode on that GPO.

### Does hiding the Windows Update page stop updates?

No. It only hides the page in Settings. Updates continue according to your Windows Update, WSUS or Intune update policies.
