Customize message for Access Denied errors

This policy setting specifies the message that users see when they are denied access to a file or folder. You can customize the Access Denied message to include additional text and links. You can also provide users with the ability to send an email to request access to the file or folder to which they were denied access.

If you enable this policy setting, users receive a customized Access Denied message from the file servers on which this policy setting is applied.

If you disable this policy setting, users see a standard Access Denied message that doesn't provide any of the functionality controlled by this policy setting, regardless of the file server configuration.

If you do not configure this policy setting, users see a standard Access Denied message unless the file server is configured to display the customized Access Denied message. By default, users see the standard Access Denied message.

Supported on: At least Windows Server 2012, Windows 8 or Windows RT

Registry HiveHKEY_LOCAL_MACHINE
Registry PathSOFTWARE\Policies\Microsoft\Windows\ADR\AccessDenied
Value NameEnabled
Value TypeREG_DWORD
Enabled Value1
Disabled Value0

Display the following message to users who are denied access:



Registry HiveHKEY_LOCAL_MACHINE
Registry PathSOFTWARE\Policies\Microsoft\Windows\ADR\AccessDenied
Value NameErrorMessage
Value TypeREG_MULTI_SZ
Default Value
Enable users to request assistance
Registry HiveHKEY_LOCAL_MACHINE
Registry PathSOFTWARE\Policies\Microsoft\Windows\ADR\AccessDenied
Value NameAllowEmailRequests
Value TypeREG_DWORD
Default Value0
True Value1
False Value0

Add the following text to the end of the email:



Registry HiveHKEY_LOCAL_MACHINE
Registry PathSOFTWARE\Policies\Microsoft\Windows\ADR\AccessDenied
Value NameEmailMessage
Value TypeREG_MULTI_SZ
Default Value

Email recipients:

Folder owner
Registry HiveHKEY_LOCAL_MACHINE
Registry PathSOFTWARE\Policies\Microsoft\Windows\ADR\AccessDenied
Value NamePutDataOwnerOnTo
Value TypeREG_DWORD
Default Value1
True Value1
False Value0
File server administrator
Registry HiveHKEY_LOCAL_MACHINE
Registry PathSOFTWARE\Policies\Microsoft\Windows\ADR\AccessDenied
Value NamePutAdminOnTo
Value TypeREG_DWORD
Default Value1
True Value1
False Value0
Additional recipients:

Registry HiveHKEY_LOCAL_MACHINE
Registry PathSOFTWARE\Policies\Microsoft\Windows\ADR\AccessDenied
Value NameAdditonalEmailTo
Value TypeREG_SZ
Default Value

Email settings:

Include device claims
Registry HiveHKEY_LOCAL_MACHINE
Registry PathSOFTWARE\Policies\Microsoft\Windows\ADR\AccessDenied
Value NameIncludeDeviceClaims
Value TypeREG_DWORD
Default Value1
True Value1
False Value0
Include user claims
Registry HiveHKEY_LOCAL_MACHINE
Registry PathSOFTWARE\Policies\Microsoft\Windows\ADR\AccessDenied
Value NameIncludeUserClaims
Value TypeREG_DWORD
Default Value1
True Value1
False Value0
Log emails in Application and Services event log
Registry HiveHKEY_LOCAL_MACHINE
Registry PathSOFTWARE\Policies\Microsoft\Windows\ADR\AccessDenied
Value NameGenerateLog
Value TypeREG_DWORD
Default Value1
True Value1
False Value0

srm-fci.admx

Administrative Templates (Computers)

Administrative Templates (Users)