Policy Group Template Gallery

Created by Karen Pearl Enrique, Modified on Mon, 19 Jun, 2023 at 1:38 PM by Karen Pearl Enrique

Considerations:
There are three options available offering different levels of security in the form of bundled, ready to use policy groups:

Light Security Policy Groups:

The Light Security Policy Group is for Admins looking to provide users with a minimally restrictive experience while enforcing critical security against everyday threats with targeted security policies like firewall controls, sign-on requirements, disk encryption, device storage, and configuring account statuses. 

Standard Security Policy Groups:

The Standard Security Policy Group is for Admins looking to provide users with a moderately restrictive experience while enforcing critical security measures. This group contains everything in the Light security tier plus extra features like file and app-sharing restrictions, secure startup settings, SSH access and security, file ownership, permissions, and storage management.

Enhanced Security Policy Groups:

The Enhanced Security Policy Group is for Admins looking to provide significant device protections with maximum restrictions on the end user. The group contains everything in the Light and Standard tiers, plus features like system hardening, app and app store/software restrictions, remote assistance, blocked profile installation, control panel access, and notification settings.  

Note: To download a Security Policy Group CSV file, click the Files below:

Policy Group Template per Operating System Summary

Apple
No.Policy NameLight
Security
Standard SecurityEnhanced Security
1Activation LockTRUETRUETRUE
2Activation Lock - iOSTRUETRUETRUE
3Allow Standard Users To Approve Screen Sharing & RecordingTRUETRUETRUE
4Application Privacy Preferences - Google Chrome Access to User FilesTRUETRUETRUE
5Disable Guest AccountTRUETRUETRUE
6FileVault 2TRUETRUETRUE
7Local Firewall ControlsTRUETRUETRUE
8Lock ScreenTRUETRUETRUE
9Passcode RestrictionsTRUETRUETRUE
10Require Passcode for User-Enrolled DevicesTRUETRUETRUE
11App Notification Settings - Google Chrome-TRUETRUE
12App Store Restrictions-TRUETRUE
13Block Manual Profile Installation-TRUETRUE
14Disable Analytics-TRUETRUE
15Disable FaceTime-TRUETRUE
16Disable iCloud Private Relay-TRUETRUE
17Gatekeeper Control-TRUETRUE
18Login Window Text-TRUETRUE
19Restrict Erase All Contents and Settings-TRUETRUE
20Restrict Sharing Between Managed and Unmanaged Apps-TRUETRUE
21Supervised iOS Restrictions-TRUETRUE
22System Preferences Control-TRUETRUE
23Block iCloud Access--TRUE
24Disable Content Caching--TRUE
25Disable Siri--TRUE
26Login Window Controls--TRUE


Windows
No.Policy NameLight
Security
Standard SecurityEnhanced Security
1Allow The Use of BiometricsTRUETRUETRUE
2BitLocker Full Disk EncryptionTRUETRUETRUE
3Built-in Administrator Account StatusTRUETRUETRUE
4Built-in Guest Account StatusTRUETRUETRUE
5Display User Info When The Session Is LockedTRUETRUETRUE
6Do Not Display Last Username on Logon ScreenTRUETRUETRUE
7Lock ScreenTRUETRUETRUE
8Restrict Control Panel AccessTRUETRUETRUE
9Windows DefenderTRUETRUETRUE
10Windows FirewallTRUETRUETRUE
11Device Installation-TRUETRUE
12Disable Cortana-TRUETRUE
13Do Not Require CTRL+ALT+DEL on logon screen-TRUETRUE
14FindMyDevice-TRUETRUE
15Message Text For Users Attempting To Log On-TRUETRUE
16Remote Assistance-TRUETRUE
17Removable Storage-TRUETRUE
18Turn Off Autoplay-TRUETRUE
19Control Panel Display--TRUE
20Disable Windows Store Application--TRUE
21Logon Behaviors--TRUE
22Rename Local Administrator Account Policy--TRUE
23Software Restrictions--TRUE


Linux
No.Policy NameLight
Security
Standard SecurityEnhanced Security
1Check Disk EncryptionTRUETRUETRUE
2Lock ScreenTRUETRUETRUE
3Disable USB Storage-TRUETRUE
4File Ownership and Permissions-TRUETRUE
5Network Parameters-TRUETRUE
6Secure Boot Settings-TRUETRUE
7SSH Root Access-TRUETRUE
8SSH Server Security Enforcement-TRUETRUE
9Additional Process Hardening--TRUE
10Disable Forbidden Services--TRUE
11Disable Unused Filesystems--TRUE
12Partition and Mount Options--TRUE
13Services Hardening: Service Clients--TRUE


Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons

Feedback sent

We appreciate your effort and will try to fix the article