To block Control Panel with Group Policy on Windows 11 and Windows Server 2025, you use the Control Panel node of the Administrative Templates: one setting blocks Control Panel and the Settings app completely, two others hide or allow individual applets, and “Settings Page Visibility” hides chosen Settings pages. This guide covers all four, the related lockdowns for Run, the command prompt, Registry Editor and Task Manager, the registry values behind them, Intune, exemptions for IT staff, RDS hosts, verification and rollback.
Short answer: Create a GPO linked to the OU that holds the user accounts and enable User Configuration » Policies » Administrative Templates » Control Panel » "Prohibit access to Control Panel and PC settings". After gpupdate /force and a new sign-in, control.exe and the Settings app no longer start for those users. If users still need some pages, hide only those pages instead.
Table of Contents
Which method to use
There are several ways to block Control Panel with Group Policy. The settings overlap, so choose by how much the user still needs.
| Method | Scope | Blocks | Pros | Cons |
|---|---|---|---|---|
| “Prohibit access to Control Panel and PC settings” | User | Control Panel and the whole Settings app | One setting, nothing to maintain | Blocks harmless pages such as display scaling, sound output and Wi-Fi |
| “Hide specified Control Panel items” | User | Listed applets only | Precise block-list | No effect on the Settings app |
| “Show only specified Control Panel items” | User | Every applet not on the list | Tight allow-list for kiosks | Ignored if the hide list is also enabled |
| “Settings Page Visibility” | Computer or user | Chosen Settings pages (hide or show only) | Fine-grained control of the modern Settings app | Does not touch classic Control Panel applets |
| Intune (Settings catalog / ADMX) | Device or user | Same as above | Covers Entra-joined devices | Needs an Intune licence |
For most offices, the best balance is “Settings Page Visibility” to hide sensitive pages plus “Hide specified Control Panel items” for the matching classic applets. Keep the full prohibition for kiosks, classrooms and shared RDS hosts.
Prerequisites
Before you block Control Panel with Group Policy, check the following:
- Windows 11 Pro, Enterprise or Education, or Windows Server 2016 to 2025, joined to the domain.
- Group Policy Management Console and rights to create and link GPOs.
- Current Windows 11 ADMX files in the Central Store (
\\contoso.com\SYSVOL\contoso.com\Policies\PolicyDefinitions). Settings Page Visibility is inControlPanel.admxand appears under both Computer and User Configuration in current templates. - A test OU with a test user and a test PC, plus a separate admin account that is not affected.
Method 1: Prohibit access to Control Panel and Settings
- Open Group Policy Management (
gpmc.msc), right-click the user OU and choose Create a GPO in this domain, and Link it here. Name it, for example, USR – Block Control Panel. - Edit it and go to
User Configuration » Policies » Administrative Templates » Control Panel. - Open “Prohibit access to Control Panel and PC settings”, choose Enabled and click OK.
- Sign in as a test user and try Win+I,
controland an item such asncpa.cpl. Each is blocked with a restriction message.
The setting stops control.exe and SystemSettings.exe from starting and removes Control Panel from Start and File Explorer. It is a user setting, so it follows the account to any PC where the GPO applies. It writes NoControlPanel = 1 (REG_DWORD) to HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer.
Standalone consoles such as devmgmt.msc or services.msc are not Control Panel and still open, although standard users cannot change anything that needs administrator rights. When you block Control Panel with Group Policy, test the everyday tasks that open Settings pages, such as adding a printer or connecting to a VPN, and give users another route for them.
Method 2: Hide or allow specific Control Panel items
If you block Control Panel with Group Policy completely, users also lose harmless applets such as Mouse and Sound. Hiding only the risky applets is often enough.
Hide specified Control Panel items
- In the same node, open “Hide specified Control Panel items” and choose Enabled.
- Click Show next to List of disallowed Control Panel items.
- Enter one canonical name per row, for example
Microsoft.ProgramsAndFeatures,Microsoft.NetworkAndSharingCenterandMicrosoft.UserAccounts. - Click OK twice.
The applets disappear from Control Panel and cannot be opened through control.exe /name or shortcuts. The setting writes DisallowCpl = 1 and a subkey DisallowCpl with numbered REG_SZ values (1, 2 …) holding the names.
Show only specified Control Panel items
For an allow-list, enable “Show only specified Control Panel items” and list the applets users may open, for example Microsoft.Mouse and Microsoft.Sound. It writes RestrictCpl = 1 and a RestrictCpl subkey. Do not enable it together with the hide list: when both are enabled, the show-only list is ignored.
Canonical names
| Applet | Canonical name |
|---|---|
| Windows Tools (Administrative Tools) | Microsoft.AdministrativeTools |
| Programs and Features | Microsoft.ProgramsAndFeatures |
| Network and Sharing Center | Microsoft.NetworkAndSharingCenter |
| User Accounts | Microsoft.UserAccounts |
| Credential Manager | Microsoft.CredentialManager |
| Device Manager | Microsoft.DeviceManager |
| Devices and Printers | Microsoft.DevicesAndPrinters |
| System | Microsoft.System |
| Windows Defender Firewall | Microsoft.WindowsFirewall |
| Internet Options | Microsoft.InternetOptions |
| Power Options | Microsoft.PowerOptions |
| Date and Time | Microsoft.DateAndTime |
| Region | Microsoft.RegionAndLanguage |
| BitLocker Drive Encryption | Microsoft.BitLockerDriveEncryption |
| Recovery | Microsoft.Recovery |
| Mouse / Sound | Microsoft.Mouse / Microsoft.Sound |
These names only affect classic Control Panel. The matching Settings pages stay reachable until you hide them with Method 3.
Method 3: Settings Page Visibility
- Go to
Computer Configuration » Policies » Administrative Templates » Control Panel(or the same path under User Configuration). - Open “Settings Page Visibility” and choose Enabled.
- In Settings Page Visibility, enter either a
hide:list or ashowonly:list of page identifiers separated by semicolons, for example:hide:windowsupdate;recovery;network-proxy;network-vpn;remotedesktop;developers - Click OK. Close and reopen Settings on the client after
gpupdate /force.
The identifier is the ms-settings: URI without the prefix. Hidden pages vanish from Settings, a category disappears when all its pages are hidden, and opening a blocked URI directly lands on the Settings home page. The computer setting writes SettingsPageVisibility (REG_SZ) to HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer; the user setting writes the same value under HKCU.
| Settings page | Identifier |
|---|---|
| Windows Update | windowsupdate |
| Recovery | recovery |
| Installed apps / Apps & features | appsfeatures |
| Optional features | optionalfeatures |
| Default apps | defaultapps |
| Proxy / VPN | network-proxy / network-vpn |
| Network status | network-status |
| Remote Desktop | remotedesktop |
| For developers | developers |
| Sign-in options | signinoptions |
| Date & time | dateandtime |
| Windows Security | windowsdefender |
| Storage | storagesense |
| Power | powersleep |
| Printers & scanners | printers |
| Background / Themes / Lock screen | personalization-background / themes / lockscreen |
| About | about |
For a kiosk, reverse the logic: showonly:display;sound;bluetooth;printers. On Windows 11 22H2 and later, hiding a page whose URI contains quietmoments also hides the Notifications page. Hiding windowsupdate only hides the page; updates keep installing according to your update policies.
Related lockdowns
Users who cannot open Control Panel often try the command line next. These User Configuration settings complete the lockdown:
| Policy (User Configuration » Policies » Administrative Templates) | Registry value | Notes |
|---|---|---|
| Start Menu and Taskbar » “Remove Run menu from Start Menu” | NoRun = 1 under HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer | Also disables Win+R |
| System » “Prevent access to the command prompt” | DisableCMD under HKCU\Software\Policies\Microsoft\Windows\System | Option to also disable batch script processing; leave that at No if logon scripts use .bat or .cmd files |
| System » “Prevent access to registry editing tools” | DisableRegistryTools under HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System | Option to also block silent regedit /s imports |
| System » Ctrl+Alt+Del Options » “Remove Task Manager” | DisableTaskMgr = 1 under HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System | Also removes Task Manager from the Ctrl+Alt+Del screen |
| System » “Don’t run specified Windows applications” | DisallowRun under the Explorer policies key | Only covers programs started by File Explorer; use AppLocker or App Control for real enforcement |
None of these stop PowerShell. If standard users must not run scripts, use AppLocker or App Control for Business rules rather than more Explorer restrictions.
Registry values reference
Use this table for scripts, audits and non-domain PCs. Set the values with Group Policy Preferences only if you cannot use the Administrative Templates settings; preference-written values are not removed when the GPO goes out of scope unless you configure removal.
| Setting | Key | Value |
|---|---|---|
| Prohibit Control Panel and Settings | HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer | NoControlPanel REG_DWORD 1 |
| Hide specified items | Same key, plus subkey DisallowCpl | DisallowCpl REG_DWORD 1; subkey values REG_SZ |
| Show only specified items | Same key, plus subkey RestrictCpl | RestrictCpl REG_DWORD 1; subkey values REG_SZ |
| Settings Page Visibility | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer (or HKCU) | SettingsPageVisibility REG_SZ, e.g. hide:recovery |
Intune
Devices that never contact a domain controller cannot receive the GPO, but Intune delivers the same settings:
- In the Intune admin center go to Devices » Configuration » Create » New policy, platform Windows 10 and later, profile type Settings catalog.
- For Settings pages, add Settings » Page Visibility List and enter the same
hide:orshowonly:string. It maps to theSettings/PageVisibilityListpolicy, which has device and user scope. - For Control Panel, search the catalog for “Prohibit access to Control Panel and PC settings”, “Hide specified Control Panel items” or “Show only specified Control Panel items”. These are ADMX-backed user settings, so assign the profile to user groups.
- Assign to a pilot group, sync the device and check Device configuration status.
Do not target the same device with both a GPO and an Intune profile for these settings. Pick one source per device to keep troubleshooting simple.
Exempt IT staff with security filtering
Because the Control Panel settings are user settings, the exemption is based on user groups:
- In GPMC select the GPO and open the Delegation tab, then click Advanced.
- Add the group GRP-IT-Admins, tick Deny for Apply group policy and leave Read allowed.
- Confirm the deny prompt. Keep Authenticated Users (or at least Domain Computers) with Read, otherwise the GPO cannot be read after the MS16-072 change.
The alternative is to remove Authenticated Users from Security Filtering, add a group of restricted users, and add Domain Computers with Read on the Delegation tab. Allow-listing is clearer when only one department must be locked down. When you block Control Panel with Group Policy for the whole company, the deny entry for IT is quicker.
RDS session hosts and kiosks: loopback processing
On Remote Desktop Session Hosts, you usually want the restrictions for everyone who signs in to those servers, but not when the same users sign in to their own PCs. Use loopback processing:
- Create a GPO linked to the OU that holds the RDS hosts and configure the user settings above in it.
- In the same GPO enable
Computer Configuration » Policies » Administrative Templates » System » Group Policy » "Configure user Group Policy loopback processing mode"and choose Merge (keep normal user GPOs and add these) or Replace (use only GPOs linked to the server’s OU). - Keep the IT deny entry. With loopback, the security filter is checked against the user, so add the IT group with Deny as above.
Loopback is the standard way to block Control Panel with Group Policy on session hosts and shared kiosks without affecting the same accounts elsewhere.
Verify it works
After you block Control Panel with Group Policy, check a test session step by step:
- Sign in as a test user and run
gpupdate /force, then sign out and in again. - Run
gpresult /r /scope userand confirm the GPO appears under Applied Group Policy Objects. For the Settings page policy usegpresult /r /scope computeras an administrator. - Query the values:
reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"
reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowCpl"
reg query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v SettingsPageVisibility - Test the entry points users try:
control,control /name Microsoft.ProgramsAndFeatures,appwiz.cpl,start ms-settings:recoveryand right-click » Display settings on the desktop. - For a full report, run
gpresult /h C:\Temp\gp.htmland check the winning GPO for each setting.
Troubleshooting
Most failures come from scope, filtering or old templates:
| Symptom | Cause | Fix |
|---|---|---|
| Policy has no effect | User settings in a GPO linked to a computer OU | Link to the user OU or enable loopback on the computer OU |
| Admins are blocked too | No exemption; admins are in the linked OU | Add the IT group with Deny “Apply group policy” |
| Settings pages still visible | Typo in identifier, or Settings was already open | Check the URI name and restart the Settings app |
| Show-only list ignored | Hide list also enabled | Use one of the two settings, not both |
| Applet still opens by .cpl name | Wrong canonical name in the list | Use the Microsoft.* name from the table |
| GPO missing from gpresult | Security filtering removed Read for computers | Give Domain Computers or Authenticated Users Read |
| Settings not in the editor | Old ADMX files in the Central Store | Update the Central Store with current Windows 11 templates |
Roll back
- Set each setting to Not Configured (or unlink the GPO). Administrative Templates settings are removed from the registry at the next refresh; users need to sign out and in again.
- To release one user quickly, add them to the exempt group and run
gpupdate /force. - If you set the values with preferences or scripts, delete them explicitly, for example
reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoControlPanel /f. - In Intune, unassign or delete the profile and sync the device.
Roll out any change that uses these settings to a pilot group first, and document which Settings pages you hide so the service desk knows why a page is missing.
Block Control Panel with Group Policy at a glance


Official documentation: ADMX_ControlPanel Policy CSP, Settings Policy CSP (PageVisibilityList), Canonical names of Control Panel items.
Related guides: Group Policy loopback processing: merge vs replace for RDS hosts and kiosks · GPO security filtering: target or exclude users and computers · AppLocker with Group Policy.
Frequently asked questions
Does “Prohibit access to Control Panel and PC settings” also block the Settings app?
Yes. It stops both control.exe and SystemSettings.exe from starting, so users cannot open Control Panel, the Settings app or their individual pages.
How do I hide only some Settings pages on Windows 11?
Enable “Settings Page Visibility” under Administrative Templates » Control Panel and enter a list such as hide:windowsupdate;recovery. Each entry is the ms-settings URI without the ms-settings: prefix.
Can I block Control Panel for users but not for IT staff?
Yes. On the GPO’s Delegation tab, add the IT group and set Apply group policy to Deny, while keeping Read for Authenticated Users or Domain Computers so the GPO still processes.
Why does the Control Panel policy not apply to users on an RDS host?
The settings are user settings, so a GPO linked to the server OU is ignored for users unless you enable loopback processing in Merge or Replace mode on that GPO.
Does hiding the Windows Update page stop updates?
No. It only hides the page in Settings. Updates continue according to your Windows Update, WSUS or Intune update policies.