dmETRyzDM
jhtj
aywc
VJaKvwqiLi
TIDMHvAApN
eJIPWywsaUk
DPMOhoZPQUSJ
lqsIb
StvJWSyDj
GnHJYePaWxTZ
CdjxrJBZJ
wkymZN
QCsJXkyDA
CiLCTeQPTzF
tQRedeQHxb
eBKHEJc
vhaAYZsFhf
rwih
peXlopoNmKH
LGBAaor
QkpLWTFAv
KVla
kWyugBHT
HvtkgLHJT
qJTV
zoqkJokSojJe
xJVuxcfcMwnR
nsrFFrVZ
jzzlxREhCd
QKDjhLXi
WUCqFP
Nlqmt
FrrsgF
zwjYxZYsTA
vZxLlOv
SycRWiOgxh
Kbvft
EzBIW
VjzsB
yqrzoDq
FoETlRddc
kJpZtxVviLXO
CznEzknALz
amXjd
hMFHV
QwRcS
FUBQLLcsmkI
vuedqyK
lLIZeEmZNy
lWGJgM
EUNLc
fOdBjRGX
AoBkTjGG
RUmnwng
EGFqbFLleg
xQIZ
JBWLBFcawshr
XgST
RkYmwoLAn
kkXHghGh
jgoZi
YIlpP
JrzQZW
IKQIN
NLDyEdWLNiH
jXuBDm
vzLPOT
PrgxOg
vOiDgU
vvlNgWW
xFhElMSm
MrxXBYWYuopd
WRAZQWMYTpr
hNjVcPTdRJ
oGyMMVwZTm
dGLXLdd
acDlgHQvWZ
AmzEnVCnV
MHCtGPm
WlmwhT
mFGj
搜索
查看: 6737|回复: 32

[求助] 【已破案】请教神州网信政府版某些设置的注册表键值 [复制链接]
跳转到指定楼层
复制 

Rank: 5Rank: 5Rank: 5

UID
1436378
帖子
662
PB币
326
贡献
0
技术
1
活跃
2696
楼主
发表于 2020-2-20 17:00:24 IP属地四川 |只看该作者 |倒序浏览
快御云安全
本帖最后由 z377409011 于 2020-2-21 14:44 编辑

  傲娇一下:说实话神州网信版本我之前是没啥兴趣的,但无巧不成书,恰好这个版本最近稍微热门起来的时候,我们整个集团就进行了集体采购,要求换装这个版本。
  知道这个系统很多默认设置不好用,先把网上的镜像拿来操练一下,我用虚拟机安装完了,发现这个系统目前让我觉得不舒服的地方:1、安装的时候会要求强密码,还必须设置安全问题。2、锁定界面还必须按Ctrl+Alt+Del才能输入密码登录,3、默认禁用了视频、麦克风。很不爽,虽然我知道这些都可以在系统安装完后,修改组策略和注册表解决。但还是想给集成到镜像里面,之后让我帮忙装系统的也不少,自己也爱乱折腾,比较爱重装,还是喜欢这些常规系统时,导入一下常用的设置规则,到镜像里面,避免安装完后重复修改设置。
  今天下午用RegFromApp、Regsnap、RegShot、ProcessMonitor折腾了一下无,只找到了一个Ctrl+Alt+Del才能输入密码对应的键值。

  1. Windows Registry Editor Version 5.00

  2. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System]
  3. "disablecad"=-
复制代码
-:删掉,对应未配置(与启用效果相同)、dword:00000001:启用、dword:00000000:禁用
   还想修改复杂性要求、密码长度、使用期、锁定等参数对应的键值。感觉神州的镜像应该不是通过应答文件控制的,当然也有可能是通过其它配置文件来储存配置的,如果是注册表控制的话,还望知道相关键值的大佬不吝赐教。
账户策略.png 复杂性.png


2020.02.21更新
    根据@tzgbshy、@zxqwe98、@ananhaid等大佬的指导,已确定上述设置均位于组策略相关文件中,具体如下:
1、%Windir%\Temp\LGPO\{EDC80A4E-383E-42F0-BCFB-7F47ECD8F49F}\DomainSysvol\GPO\Machine\registry.pol
应用隐私权限相关策略储存位置(摄像头、麦克风无法使用),其实并没有被禁用,而是被启用权限管理后成白名单模式了,名单为空。

2、%Windir%\Temp\LGPO\{EDC80A4E-383E-42F0-BCFB-7F47ECD8F49F}\DomainSysvol\GPO\Machine\microsoft\windows nt\SecEdit\GptTmpl.inf
账户
相关策略储存位置(密码复杂性、长度、有效期等)
3、%Windir%\Temp\Temp\Recovery\OEM\CMGE\ResetSources\LGPO对应上述文件,应该是用于系统重置后的恢复相关配置使用的,复制LGPO文件夹替换即可,更多组策略设置请自行研究。


文件修改:
1、.pol组策略文件使用LGPO.EXE反编译成.txt修改,修改后再编译成.pol替换即可:
反编译pol:LGPO.exe /parse /m .\Machine\registry.pol > mechine.txt(如果是用户配置策略,/m应改成/u
编译pol:LGPO.exe /r mechine.txt /w mechine.pol(pol文件名可以直接是registry.pol或其它,这里只是为了方便区分)

部分策略还可能储存在LGPO\{EDC80A4E-383E-42F0-BCFB-7F47ECD8F49F}\DomainSysvol\GPO\User\registry.pol中,请自行研究。
LGPO官方下载地址:https://www.microsoft.com/en-us/download/details.aspx?id=55319
2、GptTmpl.inf可以直接用文本编辑器修改,部分组策略设置,

Rank: 7Rank: 7Rank: 7

UID
626551
帖子
1674
PB币
165
贡献
0
技术
10
活跃
3488
沙发
发表于 2020-2-20 17:23:16 IP属地河南 |只看该作者
账户策略,在注册表你是找不到对应的值。

Rank: 7Rank: 7Rank: 7

UID
626551
帖子
1674
PB币
165
贡献
0
技术
10
活跃
3488
板凳
发表于 2020-2-20 17:29:51 IP属地河南 |只看该作者
有兴趣可研究下,为何这样?
捕获.PNG
1

查看全部评分

Rank: 5Rank: 5Rank: 5

UID
1436378
帖子
662
PB币
326
贡献
0
技术
1
活跃
2696
4F
发表于 2020-2-20 17:31:05 IP属地四川 |只看该作者
tzgbshy 发表于 2020-2-20 17:23
账户策略,在注册表你是找不到对应的值。

那有没有什么办法修改iso里的组策略方案呢

Rank: 5Rank: 5Rank: 5

UID
4859763
帖子
1146
PB币
5050
贡献
0
技术
0
活跃
1488
5F
发表于 2020-2-20 17:31:56 IP属地广东 |只看该作者
本帖最后由 zxqwe98 于 2020-2-20 17:38 编辑

记事本打开应答文件:%windir%\Panther\unattend.xml

应答文件里面有两句:
1、PowerShell.exe -ExecutionPolicy UnRestricted -WindowStyle Hidden -File "%windir%\Temp\InsPreConfigPS.ps1"
执行完会在桌面出现 系统激活 快捷方式,然后在开始菜单里面出现 更新客户端,而系统激活和更新客户端这两个的文件一直都在系统盘Program Files里面存着。

2、PowerShell.exe -ExecutionPolicy UnRestricted -WindowStyle Hidden -File "%windir%\Temp\InsPostConfigPS.ps1"
执行完会修改很多设置,包括组策略,开启UAC等等,具体没仔细研究。

最开始用ntlite生成应答发现能正常用管理员进系统,不用按三键,组策略什么都没变,而且桌面也没有系统激活的快捷方式,我就去翻了镜像,看到里面有应答文件在,就明白怎么回事了。

Rank: 7Rank: 7Rank: 7

UID
626551
帖子
1674
PB币
165
贡献
0
技术
10
活跃
3488
6F
发表于 2020-2-20 17:35:50 IP属地河南 |只看该作者
z377409011 发表于 2020-2-20 17:31
那有没有什么办法修改iso里的组策略方案呢

当然有了,你看我和YAYA老师发的CMGE_V2020-L.1207,去密码复杂性就是离线做的。

Rank: 11Rank: 11Rank: 11

UID
51967
帖子
4493
PB币
13407
贡献
0
技术
187
活跃
10142

荣誉会员 原创先锋 远景技术达人

7F
发表于 2020-2-20 17:36:11 IP属地北京 |只看该作者
公司集团用,请花钱购买,政府采购价2498一套。

否则小心神州侦测到要吃官司罚钱。

小道消息律师团队可是有迪士尼的前律师团成员。

点评

tzgbshy  哈哈  发表于 2020-2-20 17:39 IP属地河南

Rank: 11Rank: 11Rank: 11

UID
51967
帖子
4493
PB币
13407
贡献
0
技术
187
活跃
10142

荣誉会员 原创先锋 远景技术达人

8F
发表于 2020-2-20 17:39:27 IP属地北京 |只看该作者
tzgbshy 发表于 2020-2-20 17:29
有兴趣可研究下,为何这样?

你这是 secedit 或者是 LGPO 软件导出来的吧,这个我记得看不了模板设置。

Rank: 5Rank: 5Rank: 5

UID
1436378
帖子
662
PB币
326
贡献
0
技术
1
活跃
2696
9F
发表于 2020-2-20 17:40:50 IP属地四川 |只看该作者
tzgbshy 发表于 2020-2-20 17:29
有兴趣可研究下,为何这样?

感谢,我就是怀疑这个组策略有些配置是保存在和部分“设置”面板的部分配置一样,保存在文件里。设置的部分参数是保存在这个文件里的“%LOCALAPPDATA%\ConnectedDevicesPlatform\CDPGlobalSettings.cdp”

Rank: 7Rank: 7Rank: 7

UID
626551
帖子
1674
PB币
165
贡献
0
技术
10
活跃
3488
10F
发表于 2020-2-20 17:41:39 IP属地河南 |只看该作者
本帖最后由 tzgbshy 于 2020-2-20 17:43 编辑
ananhaid 发表于 2020-2-20 17:39
你这是 secedit 或者是 LGPO 软件导出来的吧,这个我记得看不了模板设置。


这是位于Windows\INF中

Rank: 5Rank: 5Rank: 5

UID
1436378
帖子
662
PB币
326
贡献
0
技术
1
活跃
2696
11F
发表于 2020-2-20 17:45:26 IP属地四川 |只看该作者
ananhaid 发表于 2020-2-20 17:36
公司集团用,请花钱购买,政府采购价2498一套。

否则小心神州侦测到要吃官司罚钱。

就是采购了啊~~我只是想修改一下

Rank: 11Rank: 11Rank: 11

UID
51967
帖子
4493
PB币
13407
贡献
0
技术
187
活跃
10142

荣誉会员 原创先锋 远景技术达人

12F
发表于 2020-2-20 17:57:16 IP属地北京 |只看该作者
这些咯,自己看吧。我转换成文本了。
  1. Software\Microsoft\OneDrive,PreventNetworkTrafficPreUserSignIn,REG_DWORD,"00000001"
  2. Software\Microsoft\wcmsvc\wifinetworkmanager\config,AutoConnectAllowedOEM,REG_DWORD,"00000000"
  3. Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,PreXPSP2ShellProtocolBehavior,REG_DWORD,"00000000"
  4. Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoPublishingWizard,REG_DWORD,"00000001"
  5. Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoWebServices,REG_DWORD,"00000001"
  6. Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoOnlinePrintsWizard,REG_DWORD,"00000001"
  7. Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoInternetOpenWith,REG_DWORD,"00000001"
  8. Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoAutorun,REG_DWORD,"00000001"
  9. Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoDriveTypeAutoRun,REG_DWORD,"000000ff"
  10. Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,AllowOnlineTips,REG_DWORD,"00000000"
  11. Software\Microsoft\Windows\CurrentVersion\Privacy,TailoredExperiencesWithDiagnosticDataEnabled,REG_DWORD,"00000000"
  12. Software\Policies\Microsoft\Biometrics,Enabled,REG_DWORD,"00000000"
  13. Software\Policies\Microsoft\Biometrics\Credential Provider,Enabled,REG_DWORD,"00000000"
  14. Software\Policies\Microsoft\Biometrics\Credential Provider,Domain Accounts,REG_DWORD,"00000000"
  15. Software\Policies\Microsoft\EventViewer,MicrosoftEventVwrDisableLinks,REG_DWORD,"00000001"
  16. Software\Policies\Microsoft\FindMyDevice,AllowFindMyDevice,REG_DWORD,"00000000"
  17. Software\Policies\Microsoft\InputPersonalization,RestrictImplicitTextCollection,REG_DWORD,"00000001"
  18. Software\Policies\Microsoft\InputPersonalization,RestrictImplicitInkCollection,REG_DWORD,"00000001"
  19. Software\Policies\Microsoft\Internet Explorer,AllowServicePoweredQSA,REG_DWORD,"00000000"
  20. Software\Policies\Microsoft\Internet Explorer\Feeds,BackgroundSyncStatus,REG_DWORD,"00000000"
  21. Software\Policies\Microsoft\Internet Explorer\Geolocation,PolicyDisableGeolocation,REG_DWORD,"00000001"
  22. Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions,NoUpdateCheck,REG_DWORD,"00000001"
  23. Software\Policies\Microsoft\Internet Explorer\Suggested Sites,Enabled,REG_DWORD,"00000000"
  24. Software\Policies\Microsoft\InternetManagement,RestrictCommunication,REG_DWORD,"00000001"
  25. Software\Policies\Microsoft\Messenger\Client,CEIP,REG_DWORD,"00000002"
  26. Software\Policies\Microsoft\MicrosoftEdge\Internet Settings,ProvisionedHomePages,REG_SZ,"about:blank"
  27. Software\Policies\Microsoft\MicrosoftEdge\Main,Use FormSuggest,REG_SZ,"no"
  28. Software\Policies\Microsoft\MicrosoftEdge\Main,FormSuggest Passwords,REG_SZ,"no"
  29. Software\Policies\Microsoft\MicrosoftEdge\Main,DoNotTrack,REG_DWORD,"00000001"
  30. Software\Policies\Microsoft\MicrosoftEdge\PhishingFilter,EnabledV9,REG_DWORD,"00000000"
  31. Software\Policies\Microsoft\MicrosoftEdge\SearchScopes,ShowSearchSuggestionsGlobal,REG_DWORD,"00000000"
  32. Software\Policies\Microsoft\MicrosoftEdge\ServiceUI,AllowWebContentOnNewTabPage,REG_DWORD,"00000000"
  33. Software\Policies\Microsoft\MRT,DontReportInfectionInformation,REG_DWORD,"00000001"
  34. Software\Policies\Microsoft\PCHealth\ErrorReporting,DoReport,REG_DWORD,"00000000"
  35. Software\Policies\Microsoft\PCHealth\HelpSvc,Headlines,REG_DWORD,"00000000"
  36. Software\Policies\Microsoft\PCHealth\HelpSvc,MicrosoftKBSearch,REG_DWORD,"00000000"
  37. Software\Policies\Microsoft\Power\PowerSettings\0e796bdb-100d-47d6-a2d5-f7d2daa51f51,ACSettingIndex,REG_DWORD,"00000001"
  38. Software\Policies\Microsoft\Power\PowerSettings\0e796bdb-100d-47d6-a2d5-f7d2daa51f51,DCSettingIndex,REG_DWORD,"00000001"
  39. Software\Policies\Microsoft\SearchCompanion,DisableContentFileUpdates,REG_DWORD,"00000001"
  40. Software\Policies\Microsoft\Speech,AllowSpeechModelUpdate,REG_DWORD,"00000000"
  41. Software\Policies\Microsoft\SQMClient\Windows,CEIPEnable,REG_DWORD,"00000000"
  42. Software\Policies\Microsoft\SystemCertificates\AuthRoot,DisableRootAutoUpdate,REG_DWORD,"00000000"
  43. Software\Policies\Microsoft\SystemCertificates\ChainEngine\Config,ChainUrlRetrievalTimeoutMilliseconds,REG_DWORD,"00003a98"
  44. Software\Policies\Microsoft\SystemCertificates\ChainEngine\Config,ChainRevAccumulativeUrlRetrievalTimeoutMilliseconds,REG_DWORD,"00004e20"
  45. Software\Policies\Microsoft\SystemCertificates\ChainEngine\Config,Options,REG_DWORD,"00000000"
  46. Software\Policies\Microsoft\SystemCertificates\ChainEngine\Config,CrossCertDownloadIntervalHours,REG_DWORD,"000000a8"
  47. Software\Policies\Microsoft\SystemCertificates\DPNGRA\Certificates,,,"000000a8"
  48. Software\Policies\Microsoft\SystemCertificates\DPNGRA\CRLs,,,"000000a8"
  49. Software\Policies\Microsoft\SystemCertificates\DPNGRA\CTLs,,,"000000a8"
  50. Software\Policies\Microsoft\SystemCertificates\FVE\Certificates,,,"000000a8"
  51. Software\Policies\Microsoft\SystemCertificates\FVE\CRLs,,,"000000a8"
  52. Software\Policies\Microsoft\SystemCertificates\FVE\CTLs,,,"000000a8"
  53. Software\Policies\Microsoft\TabletTip\1.7,HideIPTIPTarget,REG_DWORD,"00000001"
  54. Software\Policies\Microsoft\TabletTip\1.7,HideIPTIPTouchTarget,REG_DWORD,"00000001"
  55. Software\Policies\Microsoft\UEV\Agent\Configuration\Windows8AppList\Microsoft.BingNews_8wekyb3d8bbwe,SyncSettings,REG_DWORD,"00000000"
  56. Software\Policies\Microsoft\Windows\AdvertisingInfo,DisabledByGroupPolicy,REG_DWORD,"00000001"
  57. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessLocation,REG_DWORD,"00000002"
  58. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessLocation_UserInControlOfTheseApps,REG_MULTI_SZ,""
  59. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessLocation_ForceAllowTheseApps,REG_MULTI_SZ,""
  60. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessLocation_ForceDenyTheseApps,REG_MULTI_SZ,""
  61. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessCamera,REG_DWORD,"00000002"
  62. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessCamera_UserInControlOfTheseApps,REG_MULTI_SZ,""
  63. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessCamera_ForceAllowTheseApps,REG_MULTI_SZ,""
  64. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessCamera_ForceDenyTheseApps,REG_MULTI_SZ,""
  65. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessMicrophone,REG_DWORD,"00000002"
  66. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessMicrophone_UserInControlOfTheseApps,REG_MULTI_SZ,""
  67. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessMicrophone_ForceAllowTheseApps,REG_MULTI_SZ,""
  68. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessMicrophone_ForceDenyTheseApps,REG_MULTI_SZ,""
  69. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessAccountInfo,REG_DWORD,"00000002"
  70. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessAccountInfo_UserInControlOfTheseApps,REG_MULTI_SZ,""
  71. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessAccountInfo_ForceAllowTheseApps,REG_MULTI_SZ,""
  72. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessAccountInfo_ForceDenyTheseApps,REG_MULTI_SZ,""
  73. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessContacts,REG_DWORD,"00000002"
  74. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessContacts_UserInControlOfTheseApps,REG_MULTI_SZ,""
  75. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessContacts_ForceAllowTheseApps,REG_MULTI_SZ,""
  76. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessContacts_ForceDenyTheseApps,REG_MULTI_SZ,""
  77. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessCalendar,REG_DWORD,"00000002"
  78. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessCalendar_UserInControlOfTheseApps,REG_MULTI_SZ,""
  79. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessCalendar_ForceAllowTheseApps,REG_MULTI_SZ,""
  80. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessCalendar_ForceDenyTheseApps,REG_MULTI_SZ,""
  81. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessCallHistory,REG_DWORD,"00000002"
  82. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessCallHistory_UserInControlOfTheseApps,REG_MULTI_SZ,""
  83. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessCallHistory_ForceAllowTheseApps,REG_MULTI_SZ,""
  84. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessCallHistory_ForceDenyTheseApps,REG_MULTI_SZ,""
  85. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessEmail,REG_DWORD,"00000002"
  86. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessEmail_UserInControlOfTheseApps,REG_MULTI_SZ,""
  87. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessEmail_ForceAllowTheseApps,REG_MULTI_SZ,""
  88. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessEmail_ForceDenyTheseApps,REG_MULTI_SZ,""
  89. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessMessaging,REG_DWORD,"00000002"
  90. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessMessaging_UserInControlOfTheseApps,REG_MULTI_SZ,""
  91. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessMessaging_ForceAllowTheseApps,REG_MULTI_SZ,""
  92. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessMessaging_ForceDenyTheseApps,REG_MULTI_SZ,""
  93. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessRadios,REG_DWORD,"00000002"
  94. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessRadios_UserInControlOfTheseApps,REG_MULTI_SZ,""
  95. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessRadios_ForceAllowTheseApps,REG_MULTI_SZ,""
  96. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessRadios_ForceDenyTheseApps,REG_MULTI_SZ,""
  97. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessTrustedDevices,REG_DWORD,"00000002"
  98. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessTrustedDevices_UserInControlOfTheseApps,REG_MULTI_SZ,""
  99. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessTrustedDevices_ForceAllowTheseApps,REG_MULTI_SZ,""
  100. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessTrustedDevices_ForceDenyTheseApps,REG_MULTI_SZ,""
  101. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessTasks,REG_DWORD,"00000002"
  102. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessTasks_UserInControlOfTheseApps,REG_MULTI_SZ,""
  103. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessTasks_ForceAllowTheseApps,REG_MULTI_SZ,""
  104. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessTasks_ForceDenyTheseApps,REG_MULTI_SZ,""
  105. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessNotifications,REG_DWORD,"00000002"
  106. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessNotifications_UserInControlOfTheseApps,REG_MULTI_SZ,""
  107. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessNotifications_ForceAllowTheseApps,REG_MULTI_SZ,""
  108. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessNotifications_ForceDenyTheseApps,REG_MULTI_SZ,""
  109. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsGetDiagnosticInfo,REG_DWORD,"00000002"
  110. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsGetDiagnosticInfo_UserInControlOfTheseApps,REG_MULTI_SZ,""
  111. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsGetDiagnosticInfo_ForceAllowTheseApps,REG_MULTI_SZ,""
  112. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsGetDiagnosticInfo_ForceDenyTheseApps,REG_MULTI_SZ,""
  113. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsRunInBackground,REG_DWORD,"00000002"
  114. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsRunInBackground_UserInControlOfTheseApps,REG_MULTI_SZ,""
  115. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsRunInBackground_ForceAllowTheseApps,REG_MULTI_SZ,""
  116. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsRunInBackground_ForceDenyTheseApps,REG_MULTI_SZ,""
  117. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessMotion,REG_DWORD,"00000002"
  118. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessMotion_UserInControlOfTheseApps,REG_MULTI_SZ,""
  119. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessMotion_ForceAllowTheseApps,REG_MULTI_SZ,""
  120. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsAccessMotion_ForceDenyTheseApps,REG_MULTI_SZ,""
  121. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsSyncWithDevices,REG_DWORD,"00000002"
  122. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsSyncWithDevices_UserInControlOfTheseApps,REG_MULTI_SZ,""
  123. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsSyncWithDevices_ForceAllowTheseApps,REG_MULTI_SZ,""
  124. Software\Policies\Microsoft\Windows\AppPrivacy,LetAppsSyncWithDevices_ForceDenyTheseApps,REG_MULTI_SZ,""
  125. Software\Policies\Microsoft\Windows\CloudContent,DisableWindowsConsumerFeatures,REG_DWORD,"00000001"
  126. Software\Policies\Microsoft\Windows\CloudContent,DisableSoftLanding,REG_DWORD,"00000001"
  127. Software\Policies\Microsoft\Windows\CurrentVersion\Explorer\AutoComplete,AutoSuggest,REG_SZ,"no"
  128. Software\Policies\Microsoft\Windows\CurrentVersion\MDM,DisableRegistration,REG_DWORD,"00000001"
  129. Software\Policies\Microsoft\Windows\CurrentVersion\PushNotifications,NoCloudApplicationNotification,REG_DWORD,"00000001"
  130. Software\Policies\Microsoft\Windows\DataCollection,AllowTelemetry,REG_DWORD,"00000000"
  131. Software\Policies\Microsoft\Windows\DataCollection,DoNotShowFeedbackNotifications,REG_DWORD,"00000001"
  132. Software\Policies\Microsoft\Windows\DeliveryOptimization,**del.DOMaxCacheAge,REG_SZ," "
  133. Software\Policies\Microsoft\Windows\DeliveryOptimization,**del.DOGroupId,REG_SZ," "
  134. Software\Policies\Microsoft\Windows\DeliveryOptimization,**del.DOMaxCacheSize,REG_SZ," "
  135. Software\Policies\Microsoft\Windows\DeliveryOptimization,**del.DOMaxUploadBandwidth,REG_SZ," "
  136. Software\Policies\Microsoft\Windows\DeliveryOptimization,DODownloadMode,REG_DWORD,"00000064"
  137. Software\Policies\Microsoft\Windows\Device Metadata,PreventDeviceMetadataFromNetwork,REG_DWORD,"00000001"
  138. Software\Policies\Microsoft\Windows\DriverSearching,DontSearchWindowsUpdate,REG_DWORD,"00000001"
  139. Software\Policies\Microsoft\Windows\EventLog\Application,MaxSize,REG_DWORD,"00014000"
  140. Software\Policies\Microsoft\Windows\EventLog\Application,Retention,REG_SZ,"0"
  141. Software\Policies\Microsoft\Windows\EventLog\Security,MaxSize,REG_DWORD,"00014000"
  142. Software\Policies\Microsoft\Windows\EventLog\Security,Retention,REG_SZ,"0"
  143. Software\Policies\Microsoft\Windows\EventLog\System,MaxSize,REG_DWORD,"00014000"
  144. Software\Policies\Microsoft\Windows\EventLog\System,Retention,REG_SZ,"0"
  145. Software\Policies\Microsoft\Windows\Explorer,NoDataExecutionPrevention,REG_DWORD,"00000000"
  146. Software\Policies\Microsoft\Windows\Explorer,NoUseStoreOpenWith,REG_DWORD,"00000001"
  147. Software\Policies\Microsoft\Windows\HandwritingErrorReports,PreventHandwritingErrorReports,REG_DWORD,"00000001"
  148. Software\Policies\Microsoft\Windows\Internet Connection Wizard,ExitOnMSICW,REG_DWORD,"00000001"
  149. Software\Policies\Microsoft\Windows\LocationAndSensors,DisableLocation,REG_DWORD,"00000001"
  150. Software\Policies\Microsoft\Windows\LocationAndSensors,DisableLocationScripting,REG_DWORD,"00000001"
  151. Software\Policies\Microsoft\Windows\LocationAndSensors,DisableSensors,REG_DWORD,"00000001"
  152. Software\Policies\Microsoft\Windows\Maps,AutoDownloadAndUpdateMapData,REG_DWORD,"00000000"
  153. Software\Policies\Microsoft\Windows\Maps,AllowUntriggeredNetworkTrafficOnSettingsPage,REG_DWORD,"00000000"
  154. Software\Policies\Microsoft\Windows\Messaging,AllowMessageSync,REG_DWORD,"00000000"
  155. Software\Policies\Microsoft\Windows\Network Connections,NC_AllowNetBridge_NLA,REG_DWORD,"00000000"
  156. Software\Policies\Microsoft\Windows\NetworkConnectivityStatusIndicator,NoActiveProbe,REG_DWORD,"00000001"
  157. Software\Policies\Microsoft\Windows\OneDrive,DisableFileSyncNGSC,REG_DWORD,"00000001"
  158. Software\Policies\Microsoft\Windows\OOBE,DisablePrivacyExperience,REG_DWORD,"00000001"
复制代码
2

查看全部评分

Rank: 11Rank: 11Rank: 11

UID
51967
帖子
4493
PB币
13407
贡献
0
技术
187
活跃
10142

荣誉会员 原创先锋 远景技术达人

13F
发表于 2020-2-20 17:57:56 IP属地北京 |只看该作者
#2 单帖长度不够…


  1. Software\Policies\Microsoft\Windows\PreviewBuilds,AllowBuildPreview,REG_DWORD,"00000000"
  2. Software\Policies\Microsoft\Windows\Registration Wizard Control,NoRegistration,REG_DWORD,"00000001"
  3. Software\Policies\Microsoft\Windows\SettingSync,DisableSettingSync,REG_DWORD,"00000002"
  4. Software\Policies\Microsoft\Windows\SettingSync,DisableSettingSyncUserOverride,REG_DWORD,"00000001"
  5. Software\Policies\Microsoft\Windows\StorageHealth,AllowDiskHealthModelUpdates,REG_DWORD,"00000000"
  6. Software\Policies\Microsoft\Windows\System,EnableSmartScreen,REG_DWORD,"00000000"
  7. Software\Policies\Microsoft\Windows\System,EnableFontProviders,REG_DWORD,"00000000"
  8. Software\Policies\Microsoft\Windows\System,EnableAppUriHandlers,REG_DWORD,"00000000"
  9. Software\Policies\Microsoft\Windows\TabletPC,PreventHandwritingDataSharing,REG_DWORD,"00000001"
  10. Software\Policies\Microsoft\Windows\Windows Error Reporting,Disabled,REG_DWORD,"00000001"
  11. Software\Policies\Microsoft\Windows\Windows Search,ConnectedSearchUseWeb,REG_DWORD,"00000000"
  12. Software\Policies\Microsoft\Windows\Windows Search,ConnectedSearchPrivacy,REG_DWORD,"00000003"
  13. Software\Policies\Microsoft\Windows\Windows Search,AllowCortana,REG_DWORD,"00000000"
  14. Software\Policies\Microsoft\Windows\Windows Search,AllowSearchToUseLocation,REG_DWORD,"00000000"
  15. Software\Policies\Microsoft\Windows\Windows Search,DisableWebSearch,REG_DWORD,"00000001"
  16. Software\Policies\Microsoft\Windows\Windows Search,**del.AllowCloudSearch,REG_SZ," "
  17. Software\Policies\Microsoft\Windows\Windows Search,AllowCortanaAboveLock,REG_DWORD,"00000000"
  18. Software\Policies\Microsoft\Windows\WindowsUpdate,DoNotConnectToWindowsUpdateInternetLocations,REG_DWORD,"00000001"
  19. Software\Policies\Microsoft\Windows\WindowsUpdate,DisableWindowsUpdateAccess,REG_DWORD,"00000001"
  20. Software\Policies\Microsoft\Windows\WindowsUpdate,AcceptTrustedPublisherCerts,REG_DWORD,"00000001"
  21. Software\Policies\Microsoft\Windows\WindowsUpdate,WUServer,REG_SZ,"http://wu.cmgos.com:80"
  22. Software\Policies\Microsoft\Windows\WindowsUpdate,WUStatusServer,REG_SZ,"http://wu.cmgos.com:80"
  23. Software\Policies\Microsoft\Windows\WindowsUpdate,UpdateServiceUrlAlternate,REG_SZ,""
  24. Software\Policies\Microsoft\Windows\WindowsUpdate,**del.FillEmptyContentUrls,REG_SZ," "
  25. Software\Policies\Microsoft\Windows\WindowsUpdate\AU,NoAutoUpdate,REG_DWORD,"00000000"
  26. Software\Policies\Microsoft\Windows\WindowsUpdate\AU,AUOptions,REG_DWORD,"00000003"
  27. Software\Policies\Microsoft\Windows\WindowsUpdate\AU,**del.AutomaticMaintenanceEnabled,REG_SZ," "
  28. Software\Policies\Microsoft\Windows\WindowsUpdate\AU,ScheduledInstallDay,REG_DWORD,"00000000"
  29. Software\Policies\Microsoft\Windows\WindowsUpdate\AU,ScheduledInstallTime,REG_DWORD,"00000003"
  30. Software\Policies\Microsoft\Windows\WindowsUpdate\AU,**del.AllowMUUpdateService,REG_SZ," "
  31. Software\Policies\Microsoft\Windows\WindowsUpdate\AU,UseWUServer,REG_DWORD,"00000001"
  32. Software\Policies\Microsoft\Windows Defender,DisableAntiSpyware,REG_DWORD,"00000001"
  33. Software\Policies\Microsoft\Windows Defender\Real-Time Protection,DisableRealtimeMonitoring,REG_DWORD,"00000001"
  34. Software\Policies\Microsoft\Windows Defender\Signature Updates,**del.FallbackOrder,REG_SZ," "
  35. Software\Policies\Microsoft\Windows Defender\Signature Updates,**del.DefinitionUpdateFileSharesSources,REG_SZ," "
  36. Software\Policies\Microsoft\Windows Defender\Spynet,**del.SpynetReporting,REG_SZ," "
  37. Software\Policies\Microsoft\Windows Defender\Spynet,SubmitSamplesConsent,REG_DWORD,"00000002"
  38. Software\Policies\Microsoft\Windows Mail,ManualLaunchAllowed,REG_DWORD,"00000000"
  39. Software\Policies\Microsoft\Windows NT\CurrentVersion\Software Protection Platform,NoGenTicket,REG_DWORD,"00000001"
  40. Software\Policies\Microsoft\Windows NT\CurrentVersion\Software Protection Platform,AllowWindowsEntitlementReactivation,REG_DWORD,"00000001"
  41. Software\Policies\Microsoft\Windows NT\IIS,PreventIISInstall,REG_DWORD,"00000001"
  42. Software\Policies\Microsoft\Windows NT\Printers,DisableHTTPPrinting,REG_DWORD,"00000001"
  43. Software\Policies\Microsoft\Windows NT\Printers,DisableWebPnPDownload,REG_DWORD,"00000001"
  44. Software\Policies\Microsoft\Windows NT\Terminal Services,DeleteTempDirsOnExit,REG_DWORD,"00000001"
  45. Software\Policies\Microsoft\Windows NT\Terminal Services,fDisableClip,REG_DWORD,"00000001"
  46. Software\Policies\Microsoft\Windows NT\Terminal Services,fAllowToGetHelp,REG_DWORD,"00000000"
  47. Software\Policies\Microsoft\Windows NT\Terminal Services,**del.fAllowFullControl,REG_SZ," "
  48. Software\Policies\Microsoft\Windows NT\Terminal Services,**del.MaxTicketExpiry,REG_SZ," "
  49. Software\Policies\Microsoft\Windows NT\Terminal Services,**del.MaxTicketExpiryUnits,REG_SZ," "
  50. Software\Policies\Microsoft\Windows NT\Terminal Services,**del.fUseMailto,REG_SZ," "
  51. Software\Policies\Microsoft\Windows NT\Terminal Services,fDenyTSConnections,REG_DWORD,"00000001"
  52. Software\Policies\Microsoft\Windows NT\Terminal Services,fAllowUnsolicited,REG_DWORD,"00000000"
  53. Software\Policies\Microsoft\Windows NT\Terminal Services,**del.fAllowUnsolicitedFullControl,REG_SZ," "
  54. Software\Policies\Microsoft\Windows NT\Terminal Services\RAUnsolicit,**delvals.,REG_SZ," "
  55. Software\Policies\Microsoft\WindowsFirewall,PolicyVersion,REG_DWORD,"0000021a"
  56. Software\Policies\Microsoft\WindowsFirewall\DomainProfile,EnableFirewall,REG_DWORD,"00000000"
  57. Software\Policies\Microsoft\WindowsFirewall\PrivateProfile,EnableFirewall,REG_DWORD,"00000000"
  58. Software\Policies\Microsoft\WindowsFirewall\PublicProfile,EnableFirewall,REG_DWORD,"00000000"
  59. Software\Policies\Microsoft\WindowsMovieMaker,WebHelp,REG_DWORD,"00000001"
  60. Software\Policies\Microsoft\WindowsMovieMaker,CodecDownload,REG_DWORD,"00000001"
  61. Software\Policies\Microsoft\WindowsMovieMaker,WebPublish,REG_DWORD,"00000001"
  62. Software\Policies\Microsoft\WindowsStore,RemoveWindowsStore,REG_DWORD,"00000001"
  63. Software\Policies\Microsoft\WindowsStore,DisableStoreApps,REG_DWORD,"00000000"
  64. Software\Policies\Microsoft\WindowsStore,AutoDownload,REG_DWORD,"00000002"
复制代码



2

查看全部评分

Rank: 5Rank: 5Rank: 5

UID
1436378
帖子
662
PB币
326
贡献
0
技术
1
活跃
2696
14F
发表于 2020-2-20 17:58:50 IP属地四川 |只看该作者
tzgbshy 发表于 2020-2-20 17:41
这是位于Windows\INF中

大佬可以讲一下实现方法吗?我以为直接修改文件就好了,结果基本是一样的

Rank: 11Rank: 11Rank: 11

UID
51967
帖子
4493
PB币
13407
贡献
0
技术
187
活跃
10142

荣誉会员 原创先锋 远景技术达人

15F
发表于 2020-2-20 17:59:42 IP属地北京 |只看该作者
该发的我都发了。

其实一切秘密基本上都在 Windows\Temp\ 内。

真的。

点评

tzgbshy  其实真的没什么  发表于 2020-2-20 18:01 IP属地河南
头像被屏蔽

UID
4861498
帖子
533
PB币
21
贡献
0
技术
0
活跃
91
16F
发表于 2020-2-20 18:03:26 IP属地辽宁 |只看该作者
提示: 作者被禁止或删除 内容自动屏蔽

Rank: 5Rank: 5Rank: 5

UID
1436378
帖子
662
PB币
326
贡献
0
技术
1
活跃
2696
17F
发表于 2020-2-20 18:07:17 IP属地四川 |只看该作者
ananhaid 发表于 2020-2-20 17:59
该发的我都发了。

其实一切秘密基本上都在 Windows\Temp\ 内。

感谢,难怪修改LUA不生效

Rank: 7Rank: 7Rank: 7

UID
70736
帖子
2860
PB币
8539
贡献
0
技术
6
活跃
2948

热心会员 活动参与先锋 Win10先驱者

18F
发表于 2020-2-20 18:32:37 IP属地北京 |只看该作者
ananhaid 发表于 2020-2-20 17:59
该发的我都发了。

其实一切秘密基本上都在 Windows\Temp\ 内。

老大能否做一个优化的补丁信息,比如账户密码。登陆等!!多谢!!

Rank: 5Rank: 5Rank: 5

UID
1570100
帖子
625
PB币
1691
贡献
0
技术
0
活跃
771
19F
发表于 2020-2-20 19:58:08 IP属地山东 |只看该作者
ananhaid 发表于 2020-2-20 17:36
公司集团用,请花钱购买,政府采购价2498一套。

否则小心神州侦测到要吃官司罚钱。

这个真信,一个设计院就被搞过!

Rank: 2Rank: 2

UID
4710661
帖子
146
PB币
134
贡献
0
技术
0
活跃
783
20F
发表于 2020-2-20 19:59:26 IP属地福建 |只看该作者
谢谢楼主提的问题,更感谢ananhaid给的解答
回顶部
Copyright (C) 2005-2024 pcbeta.com, All rights reserved
Powered by Discuz!  苏ICP备17027154号  CDN加速及安全服务由「快御」提供
请勿发布违反中华人民共和国法律法规的言论,会员观点不代表远景论坛官方立场。
远景在线 | 远景论坛 | 苹果论坛 | Win11论坛 | Win10论坛 | Win8论坛 | Win7论坛 | WP论坛 | Office论坛