Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124
Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124

Learn how to remotely restrict or restore access to the Windows Control Panel and Settings app on domain-joined computers using Group Policy Management Console (GPMC) in Windows Server 2025.
Centrally block or allow Control Panel and Windows Settings access for users in an Active Directory domain using the graphical Group Policy Management Console.
In an Active Directory environment, administrators often need centralized control over what users can change on Windows computers. Allowing every standard user unrestricted access to Control Panel and Windows Settings can make it easier for users to change configuration options that are intended to be managed centrally.
Windows Server 2025 provides the Group Policy Management Console (GPMC), which administrators can use to create, configure and link Group Policy Objects (GPOs) across an Active Directory environment.
In this tutorial, we will configure the Prohibit access to Control Panel and PC settings policy through the graphical Group Policy Management tools.
The policy can be used to prevent users from launching Control Panel and the Windows Settings application. Microsoft documents the underlying policy as the NoControlPanel policy.
The Control Panel restriction is located under User Configuration, not Computer Configuration. That means the policy follows the user account that receives the GPO, rather than automatically applying to every person who signs in to a particular computer.
For a normal Active Directory deployment, place the intended user accounts in an OU and link the GPO to that OU.
If your requirement is specifically to apply a User Configuration policy according to the computer on which the user signs in, Group Policy loopback processing may be appropriate. Test that design carefully before deploying it broadly.
The easiest GUI method is to use Group Policy Management Console (GPMC) from Windows Server 2025.
Creating a dedicated GPO makes the configuration easier to identify, test, troubleshoot and roll back than modifying a default domain policy.
Now configure the GPO to prohibit access to Control Panel and the Windows Settings application.
Creating a GPO does not automatically apply it to users. The GPO must be linked to an Active Directory site, domain or OU containing the accounts that should receive the policy.
Group Policy is periodically refreshed by Windows. During testing, you can force an immediate policy refresh on the client computer.
In Group Policy Management Console, right-click the target OU and select:
Confirm the update when Windows displays the remote Group Policy update dialog.
For a test workstation, open Command Prompt and run:
Sign out and sign back in if required, then test the Control Panel and Settings applications.
Sign in to a test client using a user account that is inside the GPO scope.
Press:
Enter:
The user should not be able to launch Control Panel when the policy is successfully applied.
Try launching Windows Settings from the Start menu or by using:
The Settings application should also be restricted for the affected user.
Control.exe and
SystemSettings.exe from starting, thereby
restricting access to Control Panel and PC settings.
If the policy does not appear to work, verify that the expected GPO is actually being applied to the user.
Open Command Prompt on the client and run:
Look under the applied Group Policy Objects and confirm that your Control Panel restriction GPO appears.
Open the generated HTML report in a browser and review the Applied Group Policy Objects and User Details sections.
If you previously blocked Control Panel and now want to restore access, you have several GUI-based options.
Open the policy and select:
Click Apply and OK, then update Group Policy on the affected client.
You can also select Disabled. However, for a dedicated restriction GPO, using Not Configured is often clearer when the GPO should no longer define that setting.
If the entire GPO is no longer required for an OU, remove the GPO link from that OU. The GPO itself can remain available under Group Policy Objects for future use.
You do not always need to block the entire Control Panel. Windows also provides policies that can hide selected Control Panel items.
Microsoft identifies this policy as DisallowCpls. It can be configured with specific Control Panel canonical names.
For example, Microsoft documents canonical names such as:
This approach is useful when users should have access to a limited set of Control Panel items instead of having the entire interface available.
If the objective is not to block the entire Settings application, Windows also supports the Settings Page Visibility policy.
Depending on the required configuration, administrators can use a ShowOnly: or Hide: list of Settings page URIs.
This is a different approach from completely blocking Control Panel and PC settings and can provide more granular control over the Windows Settings interface.
| Requirement | Recommended Policy Area | Result |
|---|---|---|
| Completely block Control Panel and Settings | Prohibit access to Control Panel and PC settings | Blocks both interfaces for affected users. |
| Hide selected Control Panel items | Hide specified Control Panel items | Restricts selected Control Panel items. |
| Allow only selected Control Panel items | Show only specified Control Panel items | Displays only the specified items. |
| Restrict individual Windows Settings pages | Settings Page Visibility | Shows or hides specified Settings pages. |
Open GPMC and verify that the GPO is linked to the correct OU, domain or site.
Because this restriction is a User Configuration policy, verify that the affected user is located in or otherwise included in the GPO’s scope.
In GPMC, inspect the GPO’s Security Filtering and delegation settings. The user must have the appropriate permissions to read and apply the GPO.
Another GPO may configure the same policy differently. Use Group Policy Results or an HTML GPResult report to identify the winning policy.
Confirm that the user account is actually located in the OU where the GPO is linked, or that inheritance and security filtering produce the intended scope.
In Group Policy Management Console, create or edit a GPO and navigate to User Configuration → Administrative Templates → Control Panel. Enable Prohibit access to Control Panel and PC settings, then link the GPO to the appropriate Active Directory OU or domain scope.
Yes. Group Policy allows administrators to configure the restriction centrally through GPMC rather than manually changing every domain-joined Windows computer.
Yes. The documented Prohibit access to Control Panel and PC settings policy blocks both Control Panel and the Windows PC Settings interface for affected users.
The policy is under User Configuration. Therefore, its normal scope follows users rather than automatically applying to every user of a computer.
Edit the GPO and change Prohibit access to Control Panel and PC settings to Not Configured or Disabled, or remove the GPO link from the affected OU. Then refresh Group Policy.
Yes. Windows provides Hide specified Control Panel items and Show only specified Control Panel items policies for more granular Control Panel management.
Run gpresult /r on the client to display applied Group Policy Objects. You can also generate an HTML report with gpresult /h C:\Temp\GPReport.html.
Yes. A common approach is to place the users in an appropriate OU and link the GPO there, or use appropriate security filtering and delegation. Always test the scope before production deployment.
The underlying Control Panel policy is documented for supported Windows client editions. The domain controller or GPMC server can be Windows Server 2025 while the managed client systems use supported Windows client editions.
Group Policy provides a practical way to centrally manage Control Panel and Windows Settings access across an Active Directory environment.
With Windows Server 2025 and Group Policy Management Console, administrators can create a dedicated GPO, configure the Prohibit access to Control Panel and PC settings policy, link it to the required Active Directory scope, refresh Group Policy and verify the result on domain clients.
The same management approach also allows administrators to reverse the restriction when access is required. For more granular administration, Windows provides policies for hiding selected Control Panel items or controlling individual Windows Settings pages.
For production environments, test restrictive GPOs in a dedicated OU first and maintain a separate administrative recovery path before expanding the policy to a larger group of users.
We have detected that you are using extensions to block ads. Please support us by disabling these ads blocker.