Prohibit Browse
Verified with Windows 11 25H2 — updated on July 10, 2026
Supported on: Windows Server 2003, Windows XP, and Windows 2000 only
Path in the GPO console
Computer Configuration\Administrative Templates\Windows Components\Task Scheduler Description
Limits newly scheduled to items on the user's Start menu, and prevents the user from changing the scheduled program for existing tasks. This setting removes the Browse button from the Schedule Task Wizard and from the Task tab of the properties dialog box for a task. Also, users cannot edit the "Run" box or the "Start in" box that determine the program and path for a task. As a result, when users create a task, they must select a program from the list in the Scheduled Task Wizard, which displays only the tasks that appear on the Start menu and its submenus. Once a task is created, users cannot change the program a task runs. Important: This setting does not prevent users from creating a new task by pasting or dragging any program into the Scheduled Tasks folder. To prevent this action, use the "Prohibit Drag-and-Drop" setting. Note: This setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.
Registry
Software\Policies\Microsoft\Windows\Task Scheduler5.0 Value name: Allow Browse
Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Prohibit Browse
; State: Enabled
; Supported on: Windows Server 2003, Windows XP, and Windows 2000 only
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Task Scheduler5.0]
"Allow Browse"=dword:00000001 More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Prohibit Browse
# State: Enabled
# Supported on: Windows Server 2003, Windows XP, and Windows 2000 only
$path = 'HKLM:\Software\Policies\Microsoft\Windows\Task Scheduler5.0'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'Allow Browse' -Value 1 -Type DWord Intune XML
No direct Policy CSP / OMA-URI mapping for this policy. Use the Intune Remediation tab, or ingest the ADMX in Intune. Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Prohibit Browse
# State: Enabled
# Supported on: Windows Server 2003, Windows XP, and Windows 2000 only
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows\Task Scheduler5.0' -Name 'Allow Browse' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Prohibit Browse
# State: Enabled
# Supported on: Windows Server 2003, Windows XP, and Windows 2000 only
$path = 'HKLM:\Software\Policies\Microsoft\Windows\Task Scheduler5.0'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'Allow Browse' -Value 1 -Type DWord SCCM scripts
# Exported from gporais.com
# Policy: Prohibit Browse
# State: Enabled
# Supported on: Windows Server 2003, Windows XP, and Windows 2000 only
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Prohibit Browse
# State: Enabled
# Supported on: Windows Server 2003, Windows XP, and Windows 2000 only
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows\Task Scheduler5.0' -Name 'Allow Browse' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Prohibit Browse
# State: Enabled
# Supported on: Windows Server 2003, Windows XP, and Windows 2000 only
$path = 'HKLM:\Software\Policies\Microsoft\Windows\Task Scheduler5.0'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'Allow Browse' -Value 1 -Type DWord Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.