Configure Get Diagnostics feature's visibility in the Help Ribbon in Office applications and control the feature's mode of operation.
Verified with Microsoft 365/Office 5568.1000 — updated on September 4, 2026
Supported on: At least Windows Server 2016, Windows 10
Path in the GPO console
User Configuration\Administrative Templates\Microsoft Office 2016\Diagnostics Description
This policy setting allows you to enable or disable Get Diagnostics in Office applications and specifies the mode in which the feature operates. If you enable this policy setting, you must choose one of the following options: Disabled Enable upload of diagnostics logs to Microsoft Enable the collection of diagnostic logs in an archive If you select "Disabled", Office applications will not display a visible Get Diagnostics button in the Help Ribbon. If you select "Enable upload of diagnostics logs to Microsoft", Office applications will have a visible Get Diagnostics button in the Help Ribbon. Clicking this button will upload the application’s diagnostic logs to Microsoft for support purposes. If you select "Enable the collection of diagnostic logs in an archive", Office applications will have a visible Get Diagnostics button in the Help Ribbon. Clicking this button will capture the application’s diagnostic logs in a file archive on the device where the application is currently running. These logs will not be uploaded to Microsoft. Please note that the option “Enable the collection of diagnostic logs in an archive” may not be applicable in certain Office applications. When the application does not support local log collection, setting the policy to this option will completely disable the feature, removing the "Get Diagnostics" button. If you don’t set this policy, the feature will operate in the default mode, which is “Enable upload of diagnostics logs to Microsoft.”
Registry
software\policies\microsoft\office\16.0\common\diagnostics Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Configure Get Diagnostics feature's visibility in the Help Ribbon in Office applications and control the feature's mode of operation.
; State: Enabled
; Supported on: At least Windows Server 2016, Windows 10
[HKEY_CURRENT_USER\software\policies\microsoft\office\16.0\common\diagnostics]
"configuregetdiagnostics"=dword:00000001 More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Configure Get Diagnostics feature's visibility in the Help Ribbon in Office applications and control the feature's mode of operation.
# State: Enabled
# Supported on: At least Windows Server 2016, Windows 10
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\software\policies\microsoft\office\16.0\common\diagnostics'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'configuregetdiagnostics' -Value 1 -Type DWord Intune XML
No direct Policy CSP / OMA-URI mapping for this policy. Use the Intune Remediation tab, or ingest the ADMX in Intune. Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Configure Get Diagnostics feature's visibility in the Help Ribbon in Office applications and control the feature's mode of operation.
# State: Enabled
# Supported on: At least Windows Server 2016, Windows 10
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKCU:\software\policies\microsoft\office\16.0\common\diagnostics' -Name 'configuregetdiagnostics' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Configure Get Diagnostics feature's visibility in the Help Ribbon in Office applications and control the feature's mode of operation.
# State: Enabled
# Supported on: At least Windows Server 2016, Windows 10
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\software\policies\microsoft\office\16.0\common\diagnostics'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'configuregetdiagnostics' -Value 1 -Type DWord SCCM scripts
# Exported from gporais.com
# Policy: Configure Get Diagnostics feature's visibility in the Help Ribbon in Office applications and control the feature's mode of operation.
# State: Enabled
# Supported on: At least Windows Server 2016, Windows 10
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Configure Get Diagnostics feature's visibility in the Help Ribbon in Office applications and control the feature's mode of operation.
# State: Enabled
# Supported on: At least Windows Server 2016, Windows 10
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKCU:\software\policies\microsoft\office\16.0\common\diagnostics' -Name 'configuregetdiagnostics' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Configure Get Diagnostics feature's visibility in the Help Ribbon in Office applications and control the feature's mode of operation.
# State: Enabled
# Supported on: At least Windows Server 2016, Windows 10
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\software\policies\microsoft\office\16.0\common\diagnostics'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'configuregetdiagnostics' -Value 1 -Type DWord Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.