Policy
Customize message for Access Denied errors
Microsoft Windows
Policy overview
Key metadata and intent for this policy.
Supported OS tags: Windows10, Windows10RT, Windows11, Windows8, Windows81, WindowsRT, WindowsRT81, WindowsServer2012, WindowsServer2012R2, WindowsServer2016
This policy setting specifies the message that users see when they are denied access to a file or folder. You can customize the Access Denied message to include additional text and links. You can also provide users with the ability to send an email to request access to the file or folder to which they were denied access. If you enable this policy setting, users receive a customized Access Denied message from the file servers on which this policy setting is applied. If you disable this policy setting, users see a standard Access Denied message that doesn't provide any of the functionality controlled by this policy setting, regardless of the file server configuration. If you do not configure this policy setting, users see a standard Access Denied message unless the file server is configured to display the customized Access Denied message. By default, users see the standard Access Denied message.
Registry values
How enabled and disabled states update the registry.
| Scope | Registry location | Type | Enabled value | Disabled value | Copy |
|---|---|---|---|---|---|
| Computer | Path SOFTWARE\Policies\Microsoft\Windows\ADR\AccessDenied Value name Enabled | REG_DWORD | HKLM 1 | HKLM 0 |
Policy elements
Inputs and configuration options exposed by this policy.
| Scope | Element | Type | Registry mapping | Constraints & behavior | Copy |
|---|---|---|---|---|---|
| Computer | Additional recipients: ID AdditonalEmailToText | text | Path SOFTWARE\Policies\Microsoft\Windows\ADR\AccessDenied Value name AdditonalEmailTo Type REG_SZ | None | |
| Computer | ErrorMessageText ID ErrorMessageText | list | Path SOFTWARE\Policies\Microsoft\Windows\ADR\AccessDenied Value name ErrorMessage Type REG_MULTI_SZ | None | |
| Computer | EmailMessageText ID EmailMessageText | list | Path SOFTWARE\Policies\Microsoft\Windows\ADR\AccessDenied Value name EmailMessage Type REG_MULTI_SZ | None | |
| Computer | Enable users to request assistance ID AllowEmailRequestsCheck | boolean | Path SOFTWARE\Policies\Microsoft\Windows\ADR\AccessDenied Value name AllowEmailRequests Type REG_DWORD | Options: true (), false () True: None · False: None | |
| Computer | Folder owner ID PutDataOwnerOnToCheck | boolean | Path SOFTWARE\Policies\Microsoft\Windows\ADR\AccessDenied Value name PutDataOwnerOnTo Type REG_DWORD | Options: true (), false () True: None · False: None | |
| Computer | File server administrator ID PutAdminOnToCheck | boolean | Path SOFTWARE\Policies\Microsoft\Windows\ADR\AccessDenied Value name PutAdminOnTo Type REG_DWORD | Options: true (), false () True: None · False: None | |
| Computer | Include device claims ID IncludeDeviceClaimsCheck | boolean | Path SOFTWARE\Policies\Microsoft\Windows\ADR\AccessDenied Value name IncludeDeviceClaims Type REG_DWORD | Options: true (), false () True: None · False: None | |
| Computer | Include user claims ID IncludeUserClaimsCheck | boolean | Path SOFTWARE\Policies\Microsoft\Windows\ADR\AccessDenied Value name IncludeUserClaims Type REG_DWORD | Options: true (), false () True: None · False: None | |
| Computer | Log emails in Application and Services event log ID GenerateLogCheck | boolean | Path SOFTWARE\Policies\Microsoft\Windows\ADR\AccessDenied Value name GenerateLog Type REG_DWORD | Options: true (), false () True: None · False: None |