Administrative Templates (Computers)

Permits or prohibits use of this snap-in.

If you enable this setting, the snap-in is permitted. If you disable the setting, the snap-in is prohibited.

If this setting is not configured, the setting of the "Restrict users to the explicitly permitted list of snap-ins" setting determines whether this snap-in is permitted or prohibited.

-- If "Restrict users to the explicitly permitted list of snap-ins" is enabled, users cannot use any snap-in except those explicitly permitted.

To explicitly permit use of this snap-in, enable this setting. If this setting is not configured (or disabled), this snap-in is prohibited.

-- If "Restrict users to the explicitly permitted list of snap-ins" is disabled or not configured, users can use any snap-in except those explicitly prohibited.

To explicitly prohibit use of this snap-in, disable this setting. If this setting is not configured (or enabled), the snap-in is permitted.

When a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.

Supported on: At least Windows 2000

Registry HiveHKEY_CURRENT_USER
Registry PathSoftware\Policies\Microsoft\MMC\{0F6B957D-509E-11D1-A7CC-0000F87571E3}
Value NameRestrict_Run
Value TypeREG_DWORD
Enabled Value0
Disabled Value1
Enable policy:
Registry PathValue NameValue TypeValue
Software\Policies\Microsoft\MMC\{D02B1F72-3407-48ae-BA88-E8213C6761F1}Restrict_RunREG_DWORD0
Software\Policies\Microsoft\MMC\{84DE202D-5D95-4764-9014-A46F994CE856}Restrict_RunREG_DWORD0
Disable Policy:
Registry HiveRegistry PathValue NameValue TypeValue
HKEY_CURRENT_USERSoftware\Policies\Microsoft\MMC\{D02B1F72-3407-48ae-BA88-E8213C6761F1}Restrict_RunREG_DWORD1
HKEY_CURRENT_USERSoftware\Policies\Microsoft\MMC\{84DE202D-5D95-4764-9014-A46F994CE856}Restrict_RunREG_DWORD1

mmcsnapins.admx

Administrative Templates (Computers)

Administrative Templates (Users)