Turn on Security Center (Domain PCs only)
Verified with Windows 11 25H2 — updated on July 30, 2026
Supported on: At least Windows Server 2003 operating systems or Windows XP Professional
Path in the GPO console
Computer Configuration\Administrative Templates\Windows Components\Security Center Description
This policy setting specifies whether Security Center is turned on or off for computers that are joined to an Active Directory domain. When Security Center is turned on, it monitors essential security settings and notifies the user when the computer might be at risk. The Security Center Control Panel category view also contains a status section, where the user can get recommendations to help increase the computer's security. When Security Center is not enabled on the domain, neither the notifications nor the Security Center status section are displayed. Note that Security Center can only be turned off for computers that are joined to a Windows domain. When a computer is not joined to a Windows domain, the policy setting will have no effect. If you do not congifure this policy setting, the Security Center is turned off for domain members. If you enable this policy setting, Security Center is turned on for all users. If you disable this policy setting, Security Center is turned off for domain members. Windows XP SP2 ---------------------- In Windows XP SP2, the essential security settings that are monitored by Security Center include firewall, antivirus, and Automatic Updates. Note that Security Center might not be available following a change to this policy setting until after the computer is restarted for Windows XP SP2 computers. Windows Vista --------------------- In Windows Vista, this policy setting monitors essential security settings to include firewall, antivirus, antispyware, Internet security settings, User Account Control, and Automatic Updates. Windows Vista computers do not require a reboot for this policy setting to take effect.
Registry
Software\Policies\Microsoft\Windows NT\Security Center Value name: SecurityCenterInDomain
Enabled: SecurityCenterInDomain = 1
Disabled: SecurityCenterInDomain = 0
MDM / Intune (CSP)
./Device/Vendor/MSFT/Policy/Config/ADMX_Securitycenter/SecurityCenter_SecurityCenterInDomain Microsoft Learn documentation Mapping data: Microsoft Learn (CC BY 4.0)
Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Turn on Security Center (Domain PCs only)
; State: Enabled
; Supported on: At least Windows Server 2003 operating systems or Windows XP Professional
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Security Center]
"SecurityCenterInDomain"=dword:00000001 More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Turn on Security Center (Domain PCs only)
# State: Enabled
# Supported on: At least Windows Server 2003 operating systems or Windows XP Professional
$path = 'HKLM:\Software\Policies\Microsoft\Windows NT\Security Center'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'SecurityCenterInDomain' -Value 1 -Type DWord Intune XML
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/ADMX_Securitycenter/SecurityCenter_SecurityCenterInDomain
Data type: String
Value:
<enabled/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Turn on Security Center (Domain PCs only)
# State: Enabled
# Supported on: At least Windows Server 2003 operating systems or Windows XP Professional
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows NT\Security Center' -Name 'SecurityCenterInDomain' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Turn on Security Center (Domain PCs only)
# State: Enabled
# Supported on: At least Windows Server 2003 operating systems or Windows XP Professional
$path = 'HKLM:\Software\Policies\Microsoft\Windows NT\Security Center'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'SecurityCenterInDomain' -Value 1 -Type DWord SCCM scripts
# Exported from gporais.com
# Policy: Turn on Security Center (Domain PCs only)
# State: Enabled
# Supported on: At least Windows Server 2003 operating systems or Windows XP Professional
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Turn on Security Center (Domain PCs only)
# State: Enabled
# Supported on: At least Windows Server 2003 operating systems or Windows XP Professional
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows NT\Security Center' -Name 'SecurityCenterInDomain' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Turn on Security Center (Domain PCs only)
# State: Enabled
# Supported on: At least Windows Server 2003 operating systems or Windows XP Professional
$path = 'HKLM:\Software\Policies\Microsoft\Windows NT\Security Center'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'SecurityCenterInDomain' -Value 1 -Type DWord Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.