Emergency server help: get in touch

Block Control Panel with Group Policy: 4 Secure Windows 11 Methods

Prohibit Control Panel and Settings, hide individual Control Panel applets and Settings pages, add related lockdowns, exempt IT staff, handle RDS hosts with loopback and replicate it all in Intune.

Published Updated 12 min read

To block Control Panel with Group Policy on Windows 11 and Windows Server 2025, you use the Control Panel node of the Administrative Templates: one setting blocks Control Panel and the Settings app completely, two others hide or allow individual applets, and “Settings Page Visibility” hides chosen Settings pages. This guide covers all four, the related lockdowns for Run, the command prompt, Registry Editor and Task Manager, the registry values behind them, Intune, exemptions for IT staff, RDS hosts, verification and rollback.

Short answer: Create a GPO linked to the OU that holds the user accounts and enable User Configuration » Policies » Administrative Templates » Control Panel » "Prohibit access to Control Panel and PC settings". After gpupdate /force and a new sign-in, control.exe and the Settings app no longer start for those users. If users still need some pages, hide only those pages instead.

Which method to use

There are several ways to block Control Panel with Group Policy. The settings overlap, so choose by how much the user still needs.

MethodScopeBlocksProsCons
“Prohibit access to Control Panel and PC settings”UserControl Panel and the whole Settings appOne setting, nothing to maintainBlocks harmless pages such as display scaling, sound output and Wi-Fi
“Hide specified Control Panel items”UserListed applets onlyPrecise block-listNo effect on the Settings app
“Show only specified Control Panel items”UserEvery applet not on the listTight allow-list for kiosksIgnored if the hide list is also enabled
“Settings Page Visibility”Computer or userChosen Settings pages (hide or show only)Fine-grained control of the modern Settings appDoes not touch classic Control Panel applets
Intune (Settings catalog / ADMX)Device or userSame as aboveCovers Entra-joined devicesNeeds an Intune licence

For most offices, the best balance is “Settings Page Visibility” to hide sensitive pages plus “Hide specified Control Panel items” for the matching classic applets. Keep the full prohibition for kiosks, classrooms and shared RDS hosts.

Prerequisites

Before you block Control Panel with Group Policy, check the following:

  • Windows 11 Pro, Enterprise or Education, or Windows Server 2016 to 2025, joined to the domain.
  • Group Policy Management Console and rights to create and link GPOs.
  • Current Windows 11 ADMX files in the Central Store (\\contoso.com\SYSVOL\contoso.com\Policies\PolicyDefinitions). Settings Page Visibility is in ControlPanel.admx and appears under both Computer and User Configuration in current templates.
  • A test OU with a test user and a test PC, plus a separate admin account that is not affected.

Method 1: Prohibit access to Control Panel and Settings

  1. Open Group Policy Management (gpmc.msc), right-click the user OU and choose Create a GPO in this domain, and Link it here. Name it, for example, USR – Block Control Panel.
  2. Edit it and go to User Configuration » Policies » Administrative Templates » Control Panel.
  3. Open “Prohibit access to Control Panel and PC settings”, choose Enabled and click OK.
  4. Sign in as a test user and try Win+I, control and an item such as ncpa.cpl. Each is blocked with a restriction message.

The setting stops control.exe and SystemSettings.exe from starting and removes Control Panel from Start and File Explorer. It is a user setting, so it follows the account to any PC where the GPO applies. It writes NoControlPanel = 1 (REG_DWORD) to HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer.

Standalone consoles such as devmgmt.msc or services.msc are not Control Panel and still open, although standard users cannot change anything that needs administrator rights. When you block Control Panel with Group Policy, test the everyday tasks that open Settings pages, such as adding a printer or connecting to a VPN, and give users another route for them.

Method 2: Hide or allow specific Control Panel items

If you block Control Panel with Group Policy completely, users also lose harmless applets such as Mouse and Sound. Hiding only the risky applets is often enough.

Hide specified Control Panel items

  1. In the same node, open “Hide specified Control Panel items” and choose Enabled.
  2. Click Show next to List of disallowed Control Panel items.
  3. Enter one canonical name per row, for example Microsoft.ProgramsAndFeatures, Microsoft.NetworkAndSharingCenter and Microsoft.UserAccounts.
  4. Click OK twice.

The applets disappear from Control Panel and cannot be opened through control.exe /name or shortcuts. The setting writes DisallowCpl = 1 and a subkey DisallowCpl with numbered REG_SZ values (1, 2 …) holding the names.

Show only specified Control Panel items

For an allow-list, enable “Show only specified Control Panel items” and list the applets users may open, for example Microsoft.Mouse and Microsoft.Sound. It writes RestrictCpl = 1 and a RestrictCpl subkey. Do not enable it together with the hide list: when both are enabled, the show-only list is ignored.

Canonical names

AppletCanonical name
Windows Tools (Administrative Tools)Microsoft.AdministrativeTools
Programs and FeaturesMicrosoft.ProgramsAndFeatures
Network and Sharing CenterMicrosoft.NetworkAndSharingCenter
User AccountsMicrosoft.UserAccounts
Credential ManagerMicrosoft.CredentialManager
Device ManagerMicrosoft.DeviceManager
Devices and PrintersMicrosoft.DevicesAndPrinters
SystemMicrosoft.System
Windows Defender FirewallMicrosoft.WindowsFirewall
Internet OptionsMicrosoft.InternetOptions
Power OptionsMicrosoft.PowerOptions
Date and TimeMicrosoft.DateAndTime
RegionMicrosoft.RegionAndLanguage
BitLocker Drive EncryptionMicrosoft.BitLockerDriveEncryption
RecoveryMicrosoft.Recovery
Mouse / SoundMicrosoft.Mouse / Microsoft.Sound

These names only affect classic Control Panel. The matching Settings pages stay reachable until you hide them with Method 3.

Method 3: Settings Page Visibility

  1. Go to Computer Configuration » Policies » Administrative Templates » Control Panel (or the same path under User Configuration).
  2. Open “Settings Page Visibility” and choose Enabled.
  3. In Settings Page Visibility, enter either a hide: list or a showonly: list of page identifiers separated by semicolons, for example:
    hide:windowsupdate;recovery;network-proxy;network-vpn;remotedesktop;developers
  4. Click OK. Close and reopen Settings on the client after gpupdate /force.

The identifier is the ms-settings: URI without the prefix. Hidden pages vanish from Settings, a category disappears when all its pages are hidden, and opening a blocked URI directly lands on the Settings home page. The computer setting writes SettingsPageVisibility (REG_SZ) to HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer; the user setting writes the same value under HKCU.

Settings pageIdentifier
Windows Updatewindowsupdate
Recoveryrecovery
Installed apps / Apps & featuresappsfeatures
Optional featuresoptionalfeatures
Default appsdefaultapps
Proxy / VPNnetwork-proxy / network-vpn
Network statusnetwork-status
Remote Desktopremotedesktop
For developersdevelopers
Sign-in optionssigninoptions
Date & timedateandtime
Windows Securitywindowsdefender
Storagestoragesense
Powerpowersleep
Printers & scannersprinters
Background / Themes / Lock screenpersonalization-background / themes / lockscreen
Aboutabout

For a kiosk, reverse the logic: showonly:display;sound;bluetooth;printers. On Windows 11 22H2 and later, hiding a page whose URI contains quietmoments also hides the Notifications page. Hiding windowsupdate only hides the page; updates keep installing according to your update policies.

Users who cannot open Control Panel often try the command line next. These User Configuration settings complete the lockdown:

Policy (User Configuration » Policies » Administrative Templates)Registry valueNotes
Start Menu and Taskbar » “Remove Run menu from Start Menu”NoRun = 1 under HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\ExplorerAlso disables Win+R
System » “Prevent access to the command prompt”DisableCMD under HKCU\Software\Policies\Microsoft\Windows\SystemOption to also disable batch script processing; leave that at No if logon scripts use .bat or .cmd files
System » “Prevent access to registry editing tools”DisableRegistryTools under HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\SystemOption to also block silent regedit /s imports
System » Ctrl+Alt+Del Options » “Remove Task Manager”DisableTaskMgr = 1 under HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\SystemAlso removes Task Manager from the Ctrl+Alt+Del screen
System » “Don’t run specified Windows applications”DisallowRun under the Explorer policies keyOnly covers programs started by File Explorer; use AppLocker or App Control for real enforcement

None of these stop PowerShell. If standard users must not run scripts, use AppLocker or App Control for Business rules rather than more Explorer restrictions.

Registry values reference

Use this table for scripts, audits and non-domain PCs. Set the values with Group Policy Preferences only if you cannot use the Administrative Templates settings; preference-written values are not removed when the GPO goes out of scope unless you configure removal.

SettingKeyValue
Prohibit Control Panel and SettingsHKCU\Software\Microsoft\Windows\CurrentVersion\Policies\ExplorerNoControlPanel REG_DWORD 1
Hide specified itemsSame key, plus subkey DisallowCplDisallowCpl REG_DWORD 1; subkey values REG_SZ
Show only specified itemsSame key, plus subkey RestrictCplRestrictCpl REG_DWORD 1; subkey values REG_SZ
Settings Page VisibilityHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer (or HKCU)SettingsPageVisibility REG_SZ, e.g. hide:recovery

Intune

Devices that never contact a domain controller cannot receive the GPO, but Intune delivers the same settings:

  1. In the Intune admin center go to Devices » Configuration » Create » New policy, platform Windows 10 and later, profile type Settings catalog.
  2. For Settings pages, add Settings » Page Visibility List and enter the same hide: or showonly: string. It maps to the Settings/PageVisibilityList policy, which has device and user scope.
  3. For Control Panel, search the catalog for “Prohibit access to Control Panel and PC settings”, “Hide specified Control Panel items” or “Show only specified Control Panel items”. These are ADMX-backed user settings, so assign the profile to user groups.
  4. Assign to a pilot group, sync the device and check Device configuration status.

Do not target the same device with both a GPO and an Intune profile for these settings. Pick one source per device to keep troubleshooting simple.

Exempt IT staff with security filtering

Because the Control Panel settings are user settings, the exemption is based on user groups:

  1. In GPMC select the GPO and open the Delegation tab, then click Advanced.
  2. Add the group GRP-IT-Admins, tick Deny for Apply group policy and leave Read allowed.
  3. Confirm the deny prompt. Keep Authenticated Users (or at least Domain Computers) with Read, otherwise the GPO cannot be read after the MS16-072 change.

The alternative is to remove Authenticated Users from Security Filtering, add a group of restricted users, and add Domain Computers with Read on the Delegation tab. Allow-listing is clearer when only one department must be locked down. When you block Control Panel with Group Policy for the whole company, the deny entry for IT is quicker.

RDS session hosts and kiosks: loopback processing

On Remote Desktop Session Hosts, you usually want the restrictions for everyone who signs in to those servers, but not when the same users sign in to their own PCs. Use loopback processing:

  1. Create a GPO linked to the OU that holds the RDS hosts and configure the user settings above in it.
  2. In the same GPO enable Computer Configuration » Policies » Administrative Templates » System » Group Policy » "Configure user Group Policy loopback processing mode" and choose Merge (keep normal user GPOs and add these) or Replace (use only GPOs linked to the server’s OU).
  3. Keep the IT deny entry. With loopback, the security filter is checked against the user, so add the IT group with Deny as above.

Loopback is the standard way to block Control Panel with Group Policy on session hosts and shared kiosks without affecting the same accounts elsewhere.

Verify it works

After you block Control Panel with Group Policy, check a test session step by step:

  1. Sign in as a test user and run gpupdate /force, then sign out and in again.
  2. Run gpresult /r /scope user and confirm the GPO appears under Applied Group Policy Objects. For the Settings page policy use gpresult /r /scope computer as an administrator.
  3. Query the values:
    reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"
    reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowCpl"
    reg query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v SettingsPageVisibility
  4. Test the entry points users try: control, control /name Microsoft.ProgramsAndFeatures, appwiz.cpl, start ms-settings:recovery and right-click » Display settings on the desktop.
  5. For a full report, run gpresult /h C:\Temp\gp.html and check the winning GPO for each setting.

Troubleshooting

Most failures come from scope, filtering or old templates:

SymptomCauseFix
Policy has no effectUser settings in a GPO linked to a computer OULink to the user OU or enable loopback on the computer OU
Admins are blocked tooNo exemption; admins are in the linked OUAdd the IT group with Deny “Apply group policy”
Settings pages still visibleTypo in identifier, or Settings was already openCheck the URI name and restart the Settings app
Show-only list ignoredHide list also enabledUse one of the two settings, not both
Applet still opens by .cpl nameWrong canonical name in the listUse the Microsoft.* name from the table
GPO missing from gpresultSecurity filtering removed Read for computersGive Domain Computers or Authenticated Users Read
Settings not in the editorOld ADMX files in the Central StoreUpdate the Central Store with current Windows 11 templates

Roll back

  • Set each setting to Not Configured (or unlink the GPO). Administrative Templates settings are removed from the registry at the next refresh; users need to sign out and in again.
  • To release one user quickly, add them to the exempt group and run gpupdate /force.
  • If you set the values with preferences or scripts, delete them explicitly, for example reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoControlPanel /f.
  • In Intune, unassign or delete the profile and sync the device.

Roll out any change that uses these settings to a pilot group first, and document which Settings pages you hide so the service desk knows why a page is missing.

Block Control Panel with Group Policy at a glance

Block Control Panel with Group Policy summary card: Create a GPO linked to the OU that holds the user accounts and enable User Configuration » Policies » Administrative…
In short: Create a GPO linked to the OU that holds the user accounts and enable User Configuration » Policies » Administrative Templates » Control Panel » “Prohibit access to Control Panel and PC settings”.
Block Control Panel with Group Policy sections: Which method to use, Prerequisites, Method 1: Prohibit access to Control Panel and Settings and Method 2: Hide or allow…
Covers: Which method to use, Prerequisites, Method 1: Prohibit access to Control Panel and Settings and Method 2: Hide or allow specific Control Panel items.

Official documentation: ADMX_ControlPanel Policy CSP, Settings Policy CSP (PageVisibilityList), Canonical names of Control Panel items.

Related guides: Group Policy loopback processing: merge vs replace for RDS hosts and kiosks · GPO security filtering: target or exclude users and computers · AppLocker with Group Policy.

Frequently asked questions

Does “Prohibit access to Control Panel and PC settings” also block the Settings app?

Yes. It stops both control.exe and SystemSettings.exe from starting, so users cannot open Control Panel, the Settings app or their individual pages.

How do I hide only some Settings pages on Windows 11?

Enable “Settings Page Visibility” under Administrative Templates » Control Panel and enter a list such as hide:windowsupdate;recovery. Each entry is the ms-settings URI without the ms-settings: prefix.

Can I block Control Panel for users but not for IT staff?

Yes. On the GPO’s Delegation tab, add the IT group and set Apply group policy to Deny, while keeping Read for Authenticated Users or Domain Computers so the GPO still processes.

Why does the Control Panel policy not apply to users on an RDS host?

The settings are user settings, so a GPO linked to the server OU is ignored for users unless you enable loopback processing in Merge or Replace mode on that GPO.

Does hiding the Windows Update page stop updates?

No. It only hides the page in Settings. Updates continue according to your Windows Update, WSUS or Intune update policies.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.