# Screen Lock Group Policy: Lock Windows 11 After Inactivity the Right Way

Source: https://srvscripts.com/guides/screen-lock-group-policy/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

A screen lock Group Policy makes Windows lock a session automatically after a set period without keyboard or mouse input, so an unattended desk never leaves a signed-in session open. Windows 11 and Windows Server 2025 give you several native controls for this: the Interactive logon: Machine inactivity limit security option, the password-protected screen saver policies, the display and wake settings in Power Management, and dynamic lock. This guide shows how each works, the registry values behind them, the Intune equivalents and how to exempt meeting rooms and kiosks.

**Short answer:** In a GPO linked to your computer OU, set `Computer Configuration » Policies » Windows Settings » Security Settings » Local Policies » Security Options » "Interactive logon: Machine inactivity limit"` to `900` seconds and restart the computers. For a per-user timeout on top, enable the screen saver policies under `User Configuration » Policies » Administrative Templates » Control Panel » Personalization` with “Password protect the screen saver” enabled.

In short: In a GPO linked to your computer OU, set Computer Configuration » Policies » Windows Settings » Security Settings » Local Policies » Security Options » “Interactive logon: Machine inactivity limit” to 900 seconds and restart the computers.

## Which method to use

| Method | Scope | Applies | Pros | Cons |
| --- | --- | --- | --- | --- |
| Machine inactivity limit | Computer, every user | After a restart | One value; users cannot change it | Same timeout for everyone on the device |
| Screen saver policies | User | At the next policy refresh or sign-in | Per-group timeouts; users cannot extend them | Four settings must work together |
| Power: display off and wake password | Computer | At refresh | Also saves energy; covers sleep and resume | Display off alone does not lock without the password setting |
| Dynamic lock | Computer, user opt-in | When the paired phone leaves | Locks soon after the user walks away | Needs Bluetooth and a paired phone; supplement only |
| Intune | Device | At sync | Covers Entra-joined devices | Some settings need a restart as well |

Most organisations use the machine inactivity limit as the baseline on every device and add the screen saver policies only for groups that need a shorter timeout.

## Prerequisites

Before you link a screen lock Group Policy, check the following:

- Windows 11 Pro, Enterprise or Education, or Windows Server 2016 to 2025, joined to the domain.

- Rights to create and link GPOs. The machine inactivity limit needs a GPO linked to the computers’ OU; the screen saver settings need a GPO linked to the users’ OU, or loopback processing.

- A decision on the timeout. Microsoft’s security baseline uses 900 seconds (15 minutes) for the machine inactivity limit; public areas often use 300 seconds.

- A list of devices that must not lock: meeting room PCs, digital signage, kiosks, monitoring screens.

## Choose the timeout

Pick one value per type of location rather than per team. Typical starting points:

| Location | Suggested lock after | Notes |
| --- | --- | --- |
| Standard office desks | 900 seconds | Matches the Microsoft security baseline |
| Reception, shop floor, public areas | 300 seconds | Screens visible to visitors |
| Privileged admin workstations | 300–600 seconds | Pair with short RDP idle limits |
| Meeting rooms, signage, monitoring walls | Exception | Separate OU with its own GPO |

Check any compliance framework you follow first; several require a specific maximum. Whatever you choose, use the same number in every screen lock Group Policy object and Intune profile, so users see consistent behaviour on every device.

## Method 1: Machine inactivity limit

This is the core screen lock Group Policy setting and the one we recommend on every device.

- Create a GPO, for example SEC – Screen Lock, and link it to the OU that contains the computers.

- Go to `Computer Configuration » Policies » Windows Settings » Security Settings » Local Policies » Security Options`.

- Open **“Interactive logon: Machine inactivity limit”**, tick **Define this policy setting** and enter the number of seconds, for example `900`.

- Click **OK**, run `gpupdate /force` on a test machine and **restart it**. Microsoft documents that a restart is required before the new value takes effect.

Valid values are `0` to `599940` seconds; `0` disables the lock. The setting writes `InactivityTimeoutSecs` (REG_DWORD) under `HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System`, so `900` appears as `0x384`.

```
reg query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v InactivityTimeoutSecs
```

Windows measures inactivity for the signed-in session and locks it by starting the screen saver. The user cannot shorten or lengthen this timer, and it applies to everyone who signs in, including administrators.

### What users experience

When the timer expires, Windows shows the lock screen. Open applications, file copies and running downloads continue in the background; only the desktop is hidden. Users unlock with their password, PIN, fingerprint or face, whichever Windows Hello method the device supports. Unsaved work is not lost, so tell users that the lock is not a sign-out. Jobs that drive the interactive desktop, such as scripted UI tests, fail or stall while the session is locked, which is a reason to run them under a service account instead.

## Method 2: Password-protected screen saver (per user)

Use the screen saver policies when a group needs a different timeout, or to show a blank screen while locked. Go to `User Configuration » Policies » Administrative Templates » Control Panel » Personalization`:

| Setting | Set to | Registry value (REG_SZ) |
| --- | --- | --- |
| “Enable screen saver” | Enabled | ScreenSaveActive = 1 |
| “Password protect the screen saver” | Enabled | ScreenSaverIsSecure = 1 |
| “Screen saver timeout” | Enabled, seconds (e.g. 600) | ScreenSaveTimeOut = 600 |
| “Force specific screen saver” | Enabled, scrnsave.scr | SCRNSAVE.EXE = scrnsave.scr |

The values are written under `HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop`. All four matter:

- Windows 11 has no screen saver selected by default. Without “Force specific screen saver”, the timeout has nothing to start. `scrnsave.scr` is the built-in blank screen saver and works on every edition.

- Without “Screen saver timeout”, there is no timer: since Windows 7 the default timeout value no longer exists in the user’s registry.

- Without “Password protect the screen saver”, the screen saver starts but does not lock.

When both the machine inactivity limit and a screen saver timeout apply, the shorter timer locks the session first.

## Method 3: Power, display and wake settings

Turning off the display and requiring a password on wake closes the remaining gaps: laptops resuming from sleep and screens that go dark without locking.

- Go to `Computer Configuration » Policies » Administrative Templates » System » Power Management » Sleep Settings` and enable **“Require a password when a computer wakes (plugged in)”** and **“Require a password when a computer wakes (on battery)”**.

- Go to `... » Power Management » Video and Display Settings` and enable **“Turn off the display (plugged in)”** and **“Turn off the display (on battery)”** with a value in seconds, usually the same as or a little longer than the lock timeout.

- Optionally set sleep timeouts in `Sleep Settings` as well.

These write GUID-based values under `HKLM\SOFTWARE\Policies\Microsoft\Power\PowerSettings`, which is why it is easier to check them with `powercfg`:

```
powercfg /query SCHEME_CURRENT SUB_VIDEO VIDEOIDLE
powercfg /query SCHEME_CURRENT SUB_NONE CONSOLELOCK
```

Rely on the machine inactivity limit for the lock itself and use the power settings for energy saving and resume from sleep.

## Method 4: Dynamic lock

Dynamic lock locks the PC when a paired Bluetooth phone moves out of range and the device is idle. Users turn it on under **Settings » Accounts » Sign-in options » Dynamic lock** after pairing their phone.

Administrators can define the signal rules with `Computer Configuration » Policies » Administrative Templates » Windows Components » Windows Hello for Business » "Configure dynamic lock factors"`, which takes an XML rule. Microsoft’s default rule uses `rssiMin="-10"` and `rssiMaxDelta="-10"`, and recommends keeping the defaults:

```

```

Treat dynamic lock as an extra, never as the only screen lock Group Policy control: it depends on Bluetooth being on, the phone being paired and the user enabling it.

## Method 5: Intune equivalents

For Entra-joined devices, create **Devices » Configuration » Create » New policy » Windows 10 and later » Settings catalog** and add:

- **Local Policies Security Options » Interactive Logon Machine Inactivity Limit**: the same value in seconds (`0` to `599940`). The CSP is `./Device/Vendor/MSFT/Policy/Config/LocalPoliciesSecurityOptions/InteractiveLogon_MachineInactivityLimit`. This is the direct equivalent of Method 1.

- **Administrative Templates » Control Panel » Personalization**: the four screen saver settings from Method 2.

- **Power**: the wake password and display timeouts from Method 3.

The **Device Lock » Max Inactivity Time Device Lock** setting (`DeviceLock/MaxInactivityTimeDeviceLock`, in minutes, `0` to `999`) also locks idle devices, but it only takes effect when Device Password Enabled is configured, which brings password requirements with it. For a pure idle lock, the security option above is simpler.

## Servers and Remote Desktop sessions

Servers need the same protection, especially jump hosts and RDS session hosts where many administrators sign in.

- Link the same screen lock Group Policy to server OUs, but test first on hosts that run interactive consoles for monitoring.

- Inside RDP sessions, the user-side screen saver policies lock the session just as on a desktop. The local PC’s own lock protects the RDP client window.

- To end idle sessions rather than lock them, use `Computer Configuration » Policies » Administrative Templates » Windows Components » Remote Desktop Services » Remote Desktop Session Host » Session Time Limits » "Set time limit for active but idle Remote Desktop Services sessions"`. That setting disconnects the session; it is a complement to the lock, not a replacement.

## Exceptions: meeting rooms, kiosks and signage

A screen lock Group Policy has no per-device exception inside the setting, so handle exceptions with scope:

- Put the exempt devices in their own OU, for example Workstations\MeetingRooms, or in a computer group such as SEC-ScreenLock-Exempt.

- For group-based exclusion, open the GPO’s **Delegation » Advanced**, add the computer group and set Apply group policy to **Deny**. See [GPO security filtering](/guides/group-policy-security-filtering/).

- Link a separate GPO to the exempt OU with a longer timeout, or with `0` where the device must never lock. Remember that security options are tattooed (see Roll back below), so an excluded device keeps its old value until another GPO sets a new one.

- For user-side screen saver settings on shared devices, use [loopback processing](/guides/group-policy-loopback-processing/) so the device’s policy wins over each user’s policy.

- Kiosks built with Assigned Access should be configured through their own kiosk profile, not by removing the lock from standard desktops.

Document every exception with an owner and review the list regularly. An exempt OU tends to collect ordinary PCs over time.

## Verify it works

Check the screen lock Group Policy on one device from each OU before you rely on it:

- Run `gpresult /r /scope computer` and `gpresult /r /scope user` and confirm the GPOs are applied.

- Check the machine value: `reg query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v InactivityTimeoutSecs`.

- Check the user values: `reg query "HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop"`.

- Restart, sign in, leave the device untouched for the timeout and confirm the lock screen appears and requires a password or PIN.

- For the wake password, put a laptop to sleep and resume it.

To audit many machines at once, read the value remotely with PowerShell remoting:

```
$pcs = Get-ADComputer -SearchBase "OU=Workstations,DC=contoso,DC=com" -Filter * | Select-Object -ExpandProperty Name
Invoke-Command -ComputerName $pcs -ErrorAction SilentlyContinue -ScriptBlock {
  Get-ItemPropertyValue -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" -Name InactivityTimeoutSecs
} | Group-Object | Select-Object Name, Count
```

Any machine missing from the output is offline, blocks WinRM or has no value set.

## Troubleshooting

| Symptom | Likely cause | Fix |
| --- | --- | --- |
| Machine inactivity limit set but no lock | No restart since the GPO applied | Restart the device |
| Screen saver never starts | No screen saver selected, or no timeout value | Enable “Force specific screen saver” and “Screen saver timeout” |
| Screen saver starts but does not lock | “Password protect the screen saver” not enabled | Enable it |
| Device never goes idle | An app holds a display or system request (video player, browser tab, presentation) | Run powercfg /requests as administrator to find it |
| User settings missing on shared PCs | GPO linked to computer OU without loopback | Enable loopback or link to the user OU |
| Different timeout than expected | Several GPOs set the value; shorter timer wins | Check the winning GPO in gpresult /h |
| Exempt device still locks | Value tattooed from the previous GPO | Apply a GPO that sets the value you want |

`powercfg /requests` lists processes and drivers that keep the display or system awake. Media playback, remote support tools and some browser tabs hold DISPLAY requests that stop the display from turning off and the screen saver from starting. `powercfg /requestsoverride` can tell Windows to ignore requests from a specific process; use it sparingly and document it.

## Roll back or undo

- **Screen saver and power settings** are Administrative Templates: set them to Not Configured or unlink the GPO, and the policy values are removed at the next refresh.

- **Machine inactivity limit** is a security option and is tattooed: removing the GPO leaves `InactivityTimeoutSecs` in place. To undo it, first set the GPO value to `0`, let it apply to all devices, restart them, then remove the setting. On a single machine you can delete the value with `reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v InactivityTimeoutSecs /f` and restart.

- **Intune**: remove the assignment, or better, assign a profile with the value `0` before removing it.

- **Dynamic lock**: set “Configure dynamic lock factors” to Not Configured; users can turn the feature off in Settings.

A screen lock Group Policy is one of the cheapest controls you can deploy. Pilot the timeout with one department, keep a short and documented exception list, and roll it out domain-wide once the service desk is ready for the first week of questions.

## Screen lock Group Policy at a glance

**Official documentation:** [Interactive logon: Machine inactivity limit](https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/security-policy-settings/interactive-logon-machine-inactivity-limit), [Policy CSP – LocalPoliciesSecurityOptions](https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-localpoliciessecurityoptions), [Group Policy screensaver setting not working](https://learn.microsoft.com/en-us/troubleshoot/windows-client/group-policy/group-policy-screensaver-setting-not-work).

**Related guides:** [Group Policy Desktop Wallpaper and Lock Screen: Easy Setup](/guides/group-policy-desktop-wallpaper/) · [GPO security filtering: target or exclude users and computers](/guides/group-policy-security-filtering/) · [Troubleshoot Group Policy not applying: gpresult, RSoP and Events 1058/1030](/guides/group-policy-not-applying/).

## Frequently asked questions

### What timeout should a screen lock Group Policy use?

Microsoft’s security baseline uses 900 seconds (15 minutes) for the machine inactivity limit. Public or shared areas often use 5 minutes, and trusted areas sometimes longer.

### Why does the machine inactivity limit need a restart?

Microsoft documents that a restart is required before a new value for Interactive logon: Machine inactivity limit takes effect, whether it is set locally or through Group Policy.

### Can users change the lock timeout?

No. The machine inactivity limit is a computer security setting that users cannot change. With the screen saver policies enabled, the Screen Saver Settings dialog is also controlled by policy.

### Why does my screen saver policy do nothing on Windows 11?

Windows 11 has no screen saver selected and no default timeout. Enable Force specific screen saver with scrnsave.scr and set Screen saver timeout, as well as Enable screen saver and Password protect the screen saver.

### How do I exclude meeting room PCs?

Put them in a separate OU or computer group, deny Apply group policy for that group on the lock GPO, and link a GPO with the timeout you want for those devices.
