Policy
Select Device Control Default Enforcement Policy
Windows 11 25H2
Policy overview
Key metadata and intent for this policy.
Supported OS tags: Windows10, Windows10RT, Windows11, WindowsServer2016
Default Allow: Choosing this default enforcement, will Allow any operations to occur on the attached devices if no policy rules are found to match. Default Deny: Choosing this default enforcement, will Deny any operations to occur on the attached devices if no policy rules are found to match. Default Enforcement will establish what decision should be made during the Device Control access checks when none of the policy rules match.
Registry values
How enabled and disabled states update the registry.
No explicit registry values are set for enabled or disabled states.
Policy elements
Inputs and configuration options exposed by this policy.
| Element | Type | Registry mapping | Constraints & behavior |
|---|---|---|---|
Select Device Control Default Enforcement Policy ID DeviceControlDefaultEnforcementDropDown | enum | HKLM\Software\Policies\Microsoft\Windows Defender\Device Control\DefaultEnforcement Type REG_DWORD | Options: Default Allow (1), Default Deny (2) |
Other policies in this category
Explore related policies at the same level.
- ComputerDefine Device Control evidence data remote locationAt least Windows Server 2016, Windows 10 Version 1607
- ComputerDefine device control policy groupsAt least Windows Server 2016, Windows 10 Version 1607
- ComputerDefine device control policy rulesAt least Windows Server 2016, Windows 10 Version 1607
- ComputerSet the Azure AD refresh rateAt least Windows Server 2016, Windows 10 Version 1607
- ComputerSet the data duplication limit (MB)At least Windows Server 2016, Windows 10 Version 1607
- ComputerSet the policy refresh rateAt least Windows Server 2016, Windows 10 Version 1607
- ComputerSet the retention period for files in the local device control cacheAt least Windows Server 2016, Windows 10 Version 1607
- ComputerSet up a support link for device control notificationsAt least Windows Server 2016, Windows 10 Version 1607
- ComputerTurn on device control for specific device typesAt least Windows Server 2016, Windows 10 Version 1607