Restrict system locales
Verified with Windows 11 25H2 — updated on July 30, 2026
Supported on: At least Windows Vista
Path in the GPO console
Computer Configuration\Administrative Templates\System\Locale Services Description
This policy setting restricts the permitted system locales to the specified list. If the list is empty, it locks the system locale to its current value. This policy setting does not change the existing system locale; however, the next time that an administrator attempts to change the computer's system locale, they will be restricted to the specified list. The locale list is specified using language names, separated by a semicolon (;). For example, en-US is English (United States). Specifying "en-US;en-CA" would restrict the system locale to English (United States) and English (Canada). If you enable this policy setting, administrators can select a system locale only from the specified system locale list. If you disable or do not configure this policy setting, administrators can select any system locale shipped with the operating system.
Registry
Software\Policies\Microsoft\Control Panel\International Value name: RestrictSystemLocales
Enabled: RestrictSystemLocales = 1
Disabled: RestrictSystemLocales = 0
MDM / Intune (CSP)
./Device/Vendor/MSFT/Policy/Config/ADMX_Globalization/LocaleSystemRestrict Microsoft Learn documentation Mapping data: Microsoft Learn (CC BY 4.0)
Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Restrict system locales
; State: Enabled
; Supported on: At least Windows Vista
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Control Panel\International]
"RestrictSystemLocales"=dword:00000001
"AllowableSystemLocaleTagList"="" More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Restrict system locales
# State: Enabled
# Supported on: At least Windows Vista
$path = 'HKLM:\Software\Policies\Microsoft\Control Panel\International'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'RestrictSystemLocales' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'AllowableSystemLocaleTagList' -Value '' -Type String Intune XML
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/ADMX_Globalization/LocaleSystemRestrict
Data type: String
Value:
<enabled/>
<data id="AllowableSystemLocaleTagList" value=""/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Restrict system locales
# State: Enabled
# Supported on: At least Windows Vista
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Control Panel\International' -Name 'RestrictSystemLocales' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Control Panel\International' -Name 'AllowableSystemLocaleTagList' -Expected '' -Kind String)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Restrict system locales
# State: Enabled
# Supported on: At least Windows Vista
$path = 'HKLM:\Software\Policies\Microsoft\Control Panel\International'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'RestrictSystemLocales' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'AllowableSystemLocaleTagList' -Value '' -Type String SCCM scripts
# Exported from gporais.com
# Policy: Restrict system locales
# State: Enabled
# Supported on: At least Windows Vista
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Restrict system locales
# State: Enabled
# Supported on: At least Windows Vista
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Control Panel\International' -Name 'RestrictSystemLocales' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Control Panel\International' -Name 'AllowableSystemLocaleTagList' -Expected '' -Kind String)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Restrict system locales
# State: Enabled
# Supported on: At least Windows Vista
$path = 'HKLM:\Software\Policies\Microsoft\Control Panel\International'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'RestrictSystemLocales' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'AllowableSystemLocaleTagList' -Value '' -Type String Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.