How to Remotely Block and Allow Control Panel on Domain Computers via GUI Tool

How to remotely Block and Allow Control Panel on Doman Computer

⌂ Home › Windows Server › Active Directory › Block and Allow Control Panel
🖥️ Windows Server 2025 Tutorial

How to Remotely Block and Allow Control Panel on Domain Computers via GUI Tool

Learn how to remotely restrict or restore access to the Windows Control Panel and Settings app on domain-joined computers using Group Policy Management Console (GPMC) in Windows Server 2025.

By Khurram Shahzad Published: October 1, 2026 Updated: October 1, 2026 Category: Windows Server / Active Directory Reading Time: 10–12 minutes
⚙️

Control Panel Access Management with Group Policy

Centrally block or allow Control Panel and Windows Settings access for users in an Active Directory domain using the graphical Group Policy Management Console.

🖥️
Windows Server 2025 Configure the policy from a Windows Server 2025 Active Directory environment.
⚙️
GUI-Based Administration Use Group Policy Management Console instead of editing the registry on every client.
🔒
Block Control Panel Prevent users from opening Control Panel and Windows Settings.
↩️
Allow Access Again Disable or remove the policy to restore normal access.

📑 In This Tutorial

▤ Introduction

In an Active Directory environment, administrators often need centralized control over what users can change on Windows computers. Allowing every standard user unrestricted access to Control Panel and Windows Settings can make it easier for users to change configuration options that are intended to be managed centrally.

Windows Server 2025 provides the Group Policy Management Console (GPMC), which administrators can use to create, configure and link Group Policy Objects (GPOs) across an Active Directory environment.

In this tutorial, we will configure the Prohibit access to Control Panel and PC settings policy through the graphical Group Policy Management tools.

The policy can be used to prevent users from launching Control Panel and the Windows Settings application. Microsoft documents the underlying policy as the NoControlPanel policy.

What you will learn: By the end of this guide, you will know how to create a domain GPO, configure the Control Panel restriction, link the GPO to an appropriate Active Directory container, refresh Group Policy remotely, verify the result, and restore access when required.

⚠ Important: This is a User-Based Policy

The Control Panel restriction is located under User Configuration, not Computer Configuration. That means the policy follows the user account that receives the GPO, rather than automatically applying to every person who signs in to a particular computer.

For a normal Active Directory deployment, place the intended user accounts in an OU and link the GPO to that OU.

If your requirement is specifically to apply a User Configuration policy according to the computer on which the user signs in, Group Policy loopback processing may be appropriate. Test that design carefully before deploying it broadly.

Recommended practice: Do not immediately link a restrictive GPO at the entire domain root in a production environment. Create a dedicated test OU, place one or two test users in it, validate the behavior, and then expand the deployment scope.

✓ Requirements

  • Windows Server 2025 domain environment
  • Active Directory Domain Services configured
  • Domain-joined Windows client computers
  • Group Policy Management Console installed
  • Appropriate permissions to create and modify GPOs
  • A test user and test computer for validation
  • Network connectivity between clients and domain controllers
Administrative permissions: Creating or modifying GPOs requires the appropriate permissions on the GPO. Linking a GPO also requires appropriate permissions on the target site, domain or OU.

⚙ Step 1: Open Group Policy Management Console

The easiest GUI method is to use Group Policy Management Console (GPMC) from Windows Server 2025.

1
Sign in to Windows Server 2025 Sign in using an account with sufficient permissions to manage Group Policy.
2
Open Server Manager Launch Server Manager from the Windows Server desktop.
3
Open Tools Select Tools from the Server Manager menu.
4
Select Group Policy Management This opens the Group Policy Management Console.
Server Manager → Tools → Group Policy Management

+ Step 2: Create a Dedicated GPO

Creating a dedicated GPO makes the configuration easier to identify, test, troubleshoot and roll back than modifying a default domain policy.

1
Expand your Active Directory domain In GPMC, expand Forest and then Domains.
2
Locate Group Policy Objects Expand the Group Policy Objects container.
3
Create a new GPO Right-click Group Policy Objects and select New.
4
Name the GPO Use a descriptive name such as Block Control Panel – Domain Users.
Example GPO name:
Block Control Panel – Standard Users

🔒 Step 3: Configure the Control Panel Restriction

Now configure the GPO to prohibit access to Control Panel and the Windows Settings application.

User Configuration → Policies → Administrative Templates → Control Panel
1
Right-click the new GPO In Group Policy Management, right-click your new GPO and select Edit.
2
Navigate to Control Panel policies Expand User Configuration, Policies, Administrative Templates and Control Panel.
3
Open the policy Double-click Prohibit access to Control Panel and PC settings.
4
Select Enabled Select Enabled, click Apply and then click OK.
Group Policy Management Editor
User Configuration
Policies
Administrative Templates
Control Panel

Prohibit access to Control Panel and PC settings

Policy Setting
◯ Not Configured
◯ Disabled
◉ Enabled

↻ Step 5: Apply the Group Policy

Group Policy is periodically refreshed by Windows. During testing, you can force an immediate policy refresh on the client computer.

Method 1: GUI-Based Group Policy Update

In Group Policy Management Console, right-click the target OU and select:

Group Policy Update

Confirm the update when Windows displays the remote Group Policy update dialog.

Method 2: Run GPUpdate on the Client

For a test workstation, open Command Prompt and run:

gpupdate /force

Sign out and sign back in if required, then test the Control Panel and Settings applications.

✓ Step 6: Verify That Control Panel Is Blocked

Sign in to a test client using a user account that is inside the GPO scope.

Test Control Panel

Press:

Windows + R

Enter:

control

The user should not be able to launch Control Panel when the policy is successfully applied.

Test Windows Settings

Try launching Windows Settings from the Start menu or by using:

Windows + I

The Settings application should also be restricted for the affected user.

What is actually being blocked? Microsoft documents that the policy prevents Control.exe and SystemSettings.exe from starting, thereby restricting access to Control Panel and PC settings.

▣ Step 7: Verify the Applied GPO

If the policy does not appear to work, verify that the expected GPO is actually being applied to the user.

Use GPResult

Open Command Prompt on the client and run:

gpresult /r

Look under the applied Group Policy Objects and confirm that your Control Panel restriction GPO appears.

Generate an HTML Group Policy Report

gpresult /h C:\Temp\GPReport.html

Open the generated HTML report in a browser and review the Applied Group Policy Objects and User Details sections.

🔓 How to Allow Control Panel Access Again

If you previously blocked Control Panel and now want to restore access, you have several GUI-based options.

Option 1: Set the Policy to Not Configured

User Configuration → Policies → Administrative Templates → Control Panel → Prohibit access to Control Panel and PC settings

Open the policy and select:

Not Configured

Click Apply and OK, then update Group Policy on the affected client.

Option 2: Disable the Policy

You can also select Disabled. However, for a dedicated restriction GPO, using Not Configured is often clearer when the GPO should no longer define that setting.

Option 3: Remove the GPO Link

If the entire GPO is no longer required for an OU, remove the GPO link from that OU. The GPO itself can remain available under Group Policy Objects for future use.

⚙ Alternative: Block Only Specific Control Panel Items

You do not always need to block the entire Control Panel. Windows also provides policies that can hide selected Control Panel items.

Hide Specific Control Panel Items

User Configuration → Administrative Templates → Control Panel → Hide specified Control Panel items

Microsoft identifies this policy as DisallowCpls. It can be configured with specific Control Panel canonical names.

For example, Microsoft documents canonical names such as:

Microsoft.Mouse Microsoft.System Microsoft.Personalization

Show Only Specific Control Panel Items

User Configuration → Administrative Templates → Control Panel → Show only specified Control Panel items

This approach is useful when users should have access to a limited set of Control Panel items instead of having the entire interface available.

▦ Control Specific Windows Settings Pages

If the objective is not to block the entire Settings application, Windows also supports the Settings Page Visibility policy.

Computer Configuration → Administrative Templates → Control Panel → Settings Page Visibility

Depending on the required configuration, administrators can use a ShowOnly: or Hide: list of Settings page URIs.

Hide:network-proxy;network-ethernet

This is a different approach from completely blocking Control Panel and PC settings and can provide more granular control over the Windows Settings interface.

▦ Which Group Policy Approach Should You Use?

Requirement Recommended Policy Area Result
Completely block Control Panel and Settings Prohibit access to Control Panel and PC settings Blocks both interfaces for affected users.
Hide selected Control Panel items Hide specified Control Panel items Restricts selected Control Panel items.
Allow only selected Control Panel items Show only specified Control Panel items Displays only the specified items.
Restrict individual Windows Settings pages Settings Page Visibility Shows or hides specified Settings pages.

🔧 Troubleshooting: Control Panel Policy Not Working

1. Confirm the GPO Is Linked

Open GPMC and verify that the GPO is linked to the correct OU, domain or site.

2. Confirm the User Is in Scope

Because this restriction is a User Configuration policy, verify that the affected user is located in or otherwise included in the GPO’s scope.

3. Run GPUpdate

gpupdate /force

4. Check GPResult

gpresult /r

5. Check Security Filtering

In GPMC, inspect the GPO’s Security Filtering and delegation settings. The user must have the appropriate permissions to read and apply the GPO.

6. Check for GPO Conflicts

Another GPO may configure the same policy differently. Use Group Policy Results or an HTML GPResult report to identify the winning policy.

7. Check OU Placement

Confirm that the user account is actually located in the OU where the GPO is linked, or that inheritance and security filtering produce the intended scope.

Do not test this policy with your only administrator account. Maintain a separate administrative path that is not subject to the restriction so you can recover or modify the GPO if the deployment does not behave as expected.

✓ Group Policy Best Practices

  • Create dedicated GPOs for specific administrative purposes.
  • Avoid modifying the Default Domain Policy for unrelated workstation restrictions.
  • Test restrictive policies in a dedicated OU first.
  • Use descriptive GPO names.
  • Document the purpose and scope of every restrictive GPO.
  • Keep at least one tested administrative recovery path.
  • Use Group Policy Results and GPResult when troubleshooting.
  • Consider selective policies when a full Control Panel restriction is unnecessarily broad.
  • Review GPO links and security filtering before expanding the deployment.

? Frequently Asked Questions

How do I block Control Panel on domain computers?

In Group Policy Management Console, create or edit a GPO and navigate to User Configuration → Administrative Templates → Control Panel. Enable Prohibit access to Control Panel and PC settings, then link the GPO to the appropriate Active Directory OU or domain scope.

Can I block Control Panel remotely from Windows Server 2025?

Yes. Group Policy allows administrators to configure the restriction centrally through GPMC rather than manually changing every domain-joined Windows computer.

Does the policy block Windows Settings too?

Yes. The documented Prohibit access to Control Panel and PC settings policy blocks both Control Panel and the Windows PC Settings interface for affected users.

Is the Control Panel restriction a computer policy or user policy?

The policy is under User Configuration. Therefore, its normal scope follows users rather than automatically applying to every user of a computer.

How can I allow Control Panel again?

Edit the GPO and change Prohibit access to Control Panel and PC settings to Not Configured or Disabled, or remove the GPO link from the affected OU. Then refresh Group Policy.

Can I block only specific Control Panel settings?

Yes. Windows provides Hide specified Control Panel items and Show only specified Control Panel items policies for more granular Control Panel management.

How can I check whether the GPO is applied?

Run gpresult /r on the client to display applied Group Policy Objects. You can also generate an HTML report with gpresult /h C:\Temp\GPReport.html.

Can I apply this policy to only selected users?

Yes. A common approach is to place the users in an appropriate OU and link the GPO there, or use appropriate security filtering and delegation. Always test the scope before production deployment.

Can this policy be used with Windows 11 domain computers?

The underlying Control Panel policy is documented for supported Windows client editions. The domain controller or GPMC server can be Windows Server 2025 while the managed client systems use supported Windows client editions.

✓ Conclusion

Group Policy provides a practical way to centrally manage Control Panel and Windows Settings access across an Active Directory environment.

With Windows Server 2025 and Group Policy Management Console, administrators can create a dedicated GPO, configure the Prohibit access to Control Panel and PC settings policy, link it to the required Active Directory scope, refresh Group Policy and verify the result on domain clients.

The same management approach also allows administrators to reverse the restriction when access is required. For more granular administration, Windows provides policies for hiding selected Control Panel items or controlling individual Windows Settings pages.

For production environments, test restrictive GPOs in a dedicated OU first and maintain a separate administrative recovery path before expanding the policy to a larger group of users.

▤ References & Microsoft Documentation

Microsoft Learn — Group Policy Management Console GPMC documentation for Windows Server 2025, including creating, editing and linking GPOs. View Microsoft Learn →
Microsoft Learn — Control Panel Policy CSP Documentation for NoControlPanel, DisallowCpls and RestrictCpls policies. View Control Panel Policies →
Microsoft Learn — Settings Page Visibility Documentation for controlling Windows Settings pages through Group Policy. View Settings Policy Guide →

Khurram Shahzad — Hybrid Cloud & Virtualization Engineer

Hybrid Cloud & Virtualization Engineer specializing in VMware, Azure, AWS, Windows Server, Microsoft 365, Linux, networking, backup & disaster recovery.

I share practical guides, technical projects and insights into modern IT infrastructure through VMoreCloud.

Important: Group Policy behavior depends on the Windows client edition, Active Directory structure, GPO inheritance, security filtering, loopback configuration and other policies in the environment. Always test configuration changes in a controlled OU before deploying them broadly.
© 2026 VMoreCloud. All rights reserved.
Windows and Windows Server are trademarks of Microsoft Corporation. VMoreCloud is an independent technical information website.
Ads Blocker Image Powered by Code Help Pro

Ads Blocker Detected!!!

We have detected that you are using extensions to block ads. Please support us by disabling these ads blocker.

Powered By
100% Free SEO Tools - Tool Kits PRO