Windows updates
New Group Policy settings in Windows 11 updates (KB)
Microsoft publishes one ADMX package per Windows version, but cumulative updates add policies before the next package ships. GPORais harvests them on an up-to-date Windows 11 client, referenced against the Administrative Templates (.admx) for Windows 11 Oct 2025 Update baseline package.
KB5124010 — build 26200.9550
Settings added by this KB.
- Disable changing the taskbar position Both Start Menu and Taskbar
- Disable changing the taskbar size Both Start Menu and Taskbar
- Select the Microsoft Defender safe deployment channel Computer Windows Components > Microsoft Defender Antivirus
KB5124008 — build 26200.9445
First harvest: these settings are absent from the official package and present no later than in this KB.
- Agent Connector Access Policy Computer Windows Components > Windows AI
- Agent Consent Duration Computer Windows Components > Windows AI
- Allow IP address-based SPNs during Kerberos authentication Computer System > Kerberos
- Allow offline scan from trusted Windows Recovery Environment Computer System > Recovery
- Allow user profile registry hives and AppData from non-standard paths Computer System > User Profiles
- Configure Agent Connectors Computer Windows Components > Windows AI
- Configure Camera Options Computer Windows Components > Camera
- Configure the maximum number of days that updates can be paused Computer Windows Components > Windows Update > Manage end user experience
- Configure Windows Ready Print driver ranking Computer Printers
- Disable BitLocker trust of Windows Recovery Environment (WinRE) Computer Windows Components > BitLocker Drive Encryption > Operating System Drives
- Disable Copilot Pin Screen Computer Windows Components > Cloud Content
- Disable File Explorer feature to prelaunch a window in the background Computer Windows Components > File Explorer
- Disable Get Started Computer Windows Components > Cloud Content
- DisableInlineCompose Computer Windows Components > Network Sharing
- Enable Allowed Zones for MSIX Packages Computer Windows Components > App Package Deployment
- Enable Microsoft Entra ID Authentication Enforcement Computer Windows Components > Remote Desktop Services > Remote Desktop Session Host > Security
- Enable Microsoft SmartScreen checks for MSIX Packages Computer Windows Components > App Package Deployment
- Enable Windows Restore Computer Windows Components > Sync your settings
- Let Windows apps access passkeys Computer Windows Components > App Privacy
- Let Windows apps access text content from foreground applications Computer Windows Components > App Privacy
- Let Windows apps autofill passkeys Computer Windows Components > App Privacy
- Limit Secure Boot Required Service Data Computer Windows Components > Secure Boot
- Make Print Screen key yieldable Computer Windows Components > File Explorer
- NTLM Enhanced Blocking Computer System > NTLM
- On-Device Registry Logging Level Computer Windows Components > Windows AI
- Remove Microsoft Copilot App Both Windows Components > Windows AI
- Set CLAT Get Prefix Information from DNS Computer Network > TCPIP Settings > IPv6 Transition Technologies
- Set CLAT Get Prefix Information from RA Computer Network > TCPIP Settings > IPv6 Transition Technologies
- Set CLAT Permit Computer Network > TCPIP Settings > IPv6 Transition Technologies
- Show NFC tap location indicator on logon screen Computer System > Logon
- Turn off API Sampling Computer Windows Components > App and Device Inventory
- Turn off application inbox dependency component Computer Windows Components > App and Device Inventory
Since integrated by Microsoft
These settings now ship in the official ADMX package. They stay here as a record of the update that first delivered them.
- Configure maintenance windows for automatic updates Computer Windows Components > Windows Update > Manage end user experience
- DisableShareAppPromotions Computer Windows Components > Network Sharing
- Set the DLP provider ID for Recall Both Windows Components > Windows AI