Download and Install Administrative Templates (ADMX) For Windows 11 21H2 & 22H2

Microsoft has released the Administrative Templates, also known as ADMX, for Windows 11 21H2 and Windows 11 22H2 (2022 Update). Although this release is not directed toward version 22H2, it can still be applied.

As with every new version of Windows, Windows 11 comes with its own set of administrative templates. If you have already upgraded to Windows 11, you can download and install these templates on your PC using the guide given below.

Administrative Templates give you more control over your computer, or an entire domain of computers if you are a sysadmin connected to an Active Directory. This allows you to gain more control over each device as you apply more policies.

These templates are compatible with the following operating systems:

  • Windows 11,10, 8, 8.1, and 7.
  • Windows Server 2022, 2019, 2016, 2012, 2012 R2, 2008 R2.

What’s New in Administrative Templates for Windows 11

ADMX Templates are available for download in the following languages:

  • cs-CZ Czech – Czech Republic
  • da-DK Danish – Denmark
  • de-DE German – Germany
  • el-GR Greek – Greece
  • en-US English – United States
  • es-ES Spanish – Spain
  • fi-FL Finnish – Finland
  • fr-FR French – France
  • hu-HU Hungarian – Hungary
  • it-IT Italian – Italy
  • ja-JP Japanese – Japan
  • ko-KR Korean – Korea
  • nb-NO Norwegian (Bokmål) – Norway
  • nl-NL Dutch – The Netherlands
  • pl-PL Polish – Poland
  • pt-BR Portuguese – Brazil
  • pt-PT Portuguese – Portugal
  • ru-RU Russian – Russia
  • sv-SE Swedish – Sweden
  • tr-TR Turkish – Turkey
  • zh-CN Chinese – China
  • zh-TW Chinese – Taiwan

However, the News and Interests template is currently only available in the English language. Microsoft says that they will republish the templates once more languages are supported for the said template.

The following Group Policy settings are added to the OS with these ADMX templates:

LocationPolicy PathPolicy Setting Name
MachineControl Panel\PersonalizationPrevent lock screen background motion
MachineControl Panel\Regional and Language OptionsRestrict Language Pack and Language Feature Installation
MachineMS Security GuideLimits print driver installation to Administrators
MachineNetwork\DNS ClientConfigure DNS over HTTPS (DoH) name resolution
MachinePrintersEnable Device Control Printing Restrictions
MachinePrintersList of Approved USB-connected print devices
MachineStart Menu and TaskbarShow or hide the “Most used” list from the Start menu
MachineStart Menu and Taskbar\NotificationsEnables group policy for the WNS FQDN
MachineSystem\Device Installation\Device Installation RestrictionsApply layered order of evaluation for Allow and Prevent device installation policies across all device match criteria
MachineSystem\Filesystem\NTFSEnable NTFS non-paged pool usage
MachineSystem\Filesystem\NTFSNTFS default tier
MachineSystem\Filesystem\NTFSNTFS parallel flush threshold
MachineSystem\Filesystem\NTFSNTFS parallel flush worker threads
MachineSystem\KerberosAllow retrieving the cloud Kerberos ticket during the logon
MachineSystem\Net Logon\DC Locator DNS RecordsUse lowercase DNS hostnames when registering domain controller SRV records
MachineSystem\Security Account ManagerConfigure validation of ROCA-vulnerable WHfB keys during authentication
MachineWindows Components\App Package DeploymentArchive infrequently used apps
MachineWindows Components\App Package DeploymentNot allow sideloaded apps to auto-update in the background
MachineWindows Components\App Package DeploymentNot allow sideloaded apps to auto-update in the background on a metered network
MachineWindows Components\App PrivacyAllow Windows apps to take screenshots of various windows or displays
MachineWindows Components\App PrivacyAllow Windows apps to turn off the screenshot border
MachineWindows Components\ChatConfigure the Chat icon on the taskbar
MachineWindows Components\Cloud ContentTurn off cloud consumer account state content
MachineWindows Components\Data Collection and Preview BuildsDisable OneSettings Downloads
MachineWindows Components\Data Collection and Preview BuildsEnable OneSettings Audit
MachineWindows Components\Data Collection and Preview BuildsLimit Diagnostic Log Collection
MachineWindows Components\Data Collection and Preview BuildsLimit Dump Collection
MachineWindows Components\Human PresenceForce Instant Lock
MachineWindows Components\Human PresenceForce Instant Wake
MachineWindows Components\Human PresenceLock Timeout
MachineWindows Components\Internet ExplorerReplace JScript by loading JScript9Legacy in place of JScript via MSHTML/WebOC.
MachineWindows Components\Microsoft Defender AntivirusConfigure scheduled task times randomization window
MachineWindows Components\Microsoft Defender AntivirusDefine the directory path to copy support log files
MachineWindows Components\Microsoft Defender Antivirus\Device ControlDefine device control policy groups
MachineWindows Components\Microsoft Defender Antivirus\Device ControlDefine device control policy rules
MachineWindows Components\Microsoft Defender Antivirus\ExclusionsIP Address Exclusions
MachineWindows Components\Microsoft Defender Antivirus\Microsoft Defender Exploit Guard\Network Protection This setting controls whether Network Protection is allowed to be configured into block or audit mode on Windows Server.
MachineWindows Components\Microsoft Defender Antivirus\Network Inspection SystemThis setting controls datagram processing for network protection.
MachineWindows Components\Microsoft Defender Antivirus\Real-time Protection Turn on script scanning
MachineWindows Components\Microsoft Defender Antivirus\Security Intelligence UpdatesAllows Microsoft Defender Antivirus to update and communicate over a metered connection.
MachineWindows Components\Remote Desktop Services\Remote Desktop Session Host\Device and Resource RedirectionAllow UI Automation redirection
MachineWindows Components\Remote Desktop Services\Remote Desktop Session Host\Device and Resource RedirectionDo not allow location redirection
MachineWindows Components\Tenant RestrictionsCloud Policy Details
MachineWindows Components\WidgetsAllow widgets
MachineWindows Components\Windows Hello for BusinessUse cloud trust for on-premises authentication
MachineWindows Components\Windows SandboxAllow audio input in Windows Sandbox
MachineWindows Components\Windows SandboxAllow clipboard sharing with Windows Sandbox
MachineWindows Components\Windows SandboxAllow networking in Windows Sandbox
MachineWindows Components\Windows SandboxAllow printer sharing with Windows Sandbox
MachineWindows Components\Windows SandboxAllow vGPU sharing for Windows Sandbox
MachineWindows Components\Windows SandboxAllow video input in Windows Sandbox
MachineWindows Components\Windows Update\Manage updates offered by Windows Server Update Service.Specify source services for specific classes of Windows Updates
UserAutoSubscriptionEnable auto-subscription
UserControl Panel\PrintersEnable Device Control Printing Restrictions
UserControl Panel\PrintersList of Approved USB-connected print devices
UserControl Panel\Regional and Language OptionsRestrict Language Pack and Language Feature Installation
UserStart Menu and TaskbarShow or hide the “Most used” list from the Start menu
UserWindows Components\Cloud ContentTurn off Spotlight collection on Desktop
UserWindows Components\IMEConfigure Korean IME version
UserWindows Components\Internet ExplorerReplace JScript by loading JScript9Legacy in place of JScript via MSHTML/WebOC.
Policies added after installing Windows 11 ADMX

You can download the complete Group Policy reference from here, or read about the new features here.

Download Administrative Templates for Windows 11 v21H2 & v22H2

There is no need to uninstall any previous version(s) of ADMX files already installed. Simply downloading and installing the new ADMX file will work.

Follow the guide below to download and install Administrative templates for Windows 11:

  1. Download the Administrative Templates for Windows 11 v21H2 [Size: 13.2 MB].

    You may also download Microsoft Security Compliance Toolkit that gives security administrators the ability to apply Group Policy Objects via a Domain Controller throughout an enterprise network.

  2. Run the downloaded .msi package by double-clicking it.

  3. The installation wizard will now open. Click Next.

    next
    Proceed
  4. On the next screen, accept the terms by checking the box and click Next.

    agree next
    Agree to terms
  5. Now select the installation location (which can be left as default) and click Next.

    next again
    Define installation location
  6. On the confirmation screen, click Install.

    install 2
    Begin installation
  7. Windows 11 Administrative Templates will now be installed on your device. Click Finish when done.

    finish 2
    Close wizard

You have now successfully installed the ADMX Templates. Head over to Microsoft’s download center to get more information about the Windows 11 Administrative Templates.

Closing words

This is the first version of the Administrative Templates designed for Windows 11. However, it is backward-compatible with Windows 7 as well. That said, Windows 11 version 22H2 has just been released recently and we anticipate a dedicated ADMX package soon.

If you are a regular Windows consumer, installing these ADMX Templates would do you no harm. Rather, if you know what you are doing, this will only assist you to make your device more secure.

If you liked this post, Share it on:
Subhan Zafar is an established IT professional with interests in Windows and Server infrastructure testing and research, and is currently working with Itechtics as a research consultant. He has studied Electrical Engineering and is also certified by Huawei (HCNA & HCNP Routing and Switching).

Leave the first comment

Get Updates in Your Inbox

Sign up for the regular updates and be the first to know about the latest tech information