Beware: Microsoft is removing Group Policy options from Windows 10 PRO

Discussion in 'Windows 10' started by hb860, Jul 28, 2016.

  1. RobertJ

    RobertJ MDL Senior Member

    Apr 4, 2014
    318
    79
    10
  2. remco8264

    remco8264 MDL Junior Member

    Mar 10, 2013
    91
    46
    0
    Don't really know I'm afraid. But I know that other Microsoft ''business'' subscriptions (Office 365 ProPlus, Intune) can also be directly bought from MS (so not only through partners). Maybe it'll be the same with this.
     
  3. Mr GRiM

    Mr GRiM MDL Junior Member

    Sep 4, 2012
    84
    119
    0
    #143 Mr GRiM, Aug 2, 2016
    Last edited by a moderator: Apr 20, 2017
    Very easy fix for skipping the lock screen just auto login, works with your local or MS account

    Code:
    Windows Registry Editor Version 5.00
    
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "AutoAdminLogon"="1"
    "DefaultUsername"="Your user name"
    "DefaultPassword"="Your Password"
    "ForceAutoLogon"="1"
     
  4. ch4os

    ch4os MDL Junior Member

    Jan 9, 2010
    99
    110
    0
    You don't even have to supply your password in plaintext in registry for this to work.
    Just do these steps:
    - Win+R, "control userpasswords2"
    - click on your username
    - untick checkbox above
    - hit "OK" and supply your password one last time

    ;)
     
  5. 100

    100 MDL Expert

    May 17, 2011
    1,354
    1,590
    60
    The important thing to mention here is that it would be incredibly stupid to put your password in a place like that, where it can be read even by users/processes running without admin privileges.
     
  6. freevista

    freevista MDL Member

    Jan 14, 2009
    102
    45
    10
    I upgraded my test virtual machine (Pro 1511, lock screen and crapware disabled with policy) to 1607. At least the start menu didn't immediately show advertised apps for the preexisting local account. I made a new local account and sure enough, the start menu crapware was there and auto-installing. I tried removing with PowerShell all removable installed and provisioned UWP apps from the machine (also the Store). It doesn't help, at least Twitter still auto-installs. But some crapware icons now tell that "you'll need a new app to open this ms-windows-store" :rolleyes:

    Any way to stop this, as cleanly as possible (without breaking the OS to much..)? Could custom firewall rules work, or does it just bypass them? :p
     
  7. freevista

    freevista MDL Member

    Jan 14, 2009
    102
    45
    10
    #147 freevista, Aug 2, 2016
    Last edited: Aug 2, 2016
    Continuing: I mounted the VHD offline and renamed folder C:\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy. After this I started the machine and created a new user, now the start menu crap didn't appear. ContentDeliveryManager has a subfolder "Experiences" that tipped me off.. There is no exe file for the firewall rule in ContentDeliveryManager, just dlls ContentManagementSDK.dll and ContentDeliveryManager.Background.dll.

    I bet someone with actual knowledge and coding skill would quite easily block the needed "experience" (advertising) functions in W10, without touching the OS itself. This kind of OS butchering is not optimal, and Windows might just auto-repair the system app I renamed away.
     
  8. dmex

    dmex MDL Junior Member

    Apr 20, 2011
    95
    105
    0
  9. freevista

    freevista MDL Member

    Jan 14, 2009
    102
    45
    10
    Thanks for the tip, I continue playing with this tomorrow. That screen has a User column so I guess it affects only a single user. Could the same rule also be applied to all users?
     
  10. dmex

    dmex MDL Junior Member

    Apr 20, 2011
    95
    105
    0
    All firewall rules are system-wide, I made a mistake while creating the rule and that column should not have been visible... I've updated my post with the correct instructions :p
     
  11. Mr GRiM

    Mr GRiM MDL Junior Member

    Sep 4, 2012
    84
    119
    0
    I just gave it a go and I still get the lock screen and also still have to enter a password so looks like your method doesn't work, anyway I don't really give a crap if my password is stored in the registry, been using this method for about 6 years now and never had a problem with it.
     
  12. 100

    100 MDL Expert

    May 17, 2011
    1,354
    1,590
    60
    That's not my point. With this setting any executable you happen to run on your machine will be able to obtain your account name (obviously, but it may be your Live ID) and your password, whether you use disk encryption or not.
    That's the "biggie".
     
  13. T-S

    T-S MDL Guru

    Dec 14, 2012
    3,984
    1,331
    120
    Not sure about the rights needed to read it, but I think you need the admin rights.

    Whatever, nowadays with the people using any crap from MS Google, FB, and so on w/o a blink that seem the lesser problem;)
     
  14. 100

    100 MDL Expert

    May 17, 2011
    1,354
    1,590
    60
    Wrong.

    That doesn't make this way of using autologon any less stupid.
     
  15. T-S

    T-S MDL Guru

    Dec 14, 2012
    3,984
    1,331
    120

    I just think that the users are usually divided in careless and paranoid, personally I try to stay in the middle.

    Better to have some common sense on what I download than being paranoid about a logon password which is useless for a great share of the users.
     
  16. MS_User

    MS_User MDL Guru

    Nov 30, 2014
    4,664
    1,368
    150

    well addiction is a serious disease;)
     
  17. dobbelina

    dobbelina MDL Senior Member

    Apr 2, 2009
    433
    539
    10
    #158 dobbelina, Aug 3, 2016
    Last edited: Aug 3, 2016
    As I wrote in an earlier post, this is exactly what people will do when MS take away the options to control your windows.
    They/Microsoft open security holes.....
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  18. Garbellano

    Garbellano MDL Addicted

    Aug 13, 2012
    947
    248
    30
    "That" or you could create a ps entry ;)
     
  19. freevista

    freevista MDL Member

    Jan 14, 2009
    102
    45
    10
    What is a ps entry?

    Anyway, I created the rule dmex posted and now it still managed to create the icon placeholders but cannot fill them. When the directory C:\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy is renamed, even those placeholders stay away. Edge is of course still there as a system app.

    startmenu_contentdelivery_firewalled.png

    Now to test how the lock screen ads behave, I guess this trick blocks also them.