Enterprise control for Windows Location Services/Provider/Privacy in Windows 8.1

Hi All,
Is there option (Group Policy/Registry) in Windows 8.1 to disable users to Enable or Disable (one word: control) Windows Location/Privacy global options for Metro/Windows Store/Windows Store LOB Applications?
Is there option (Group Policy/Registry) in Windows 8.1 to disable users to Enable or Disable (one word: control) specific application
in Windows Location/Privacy options for Metro/Windows Store/Windows Store LOB Applications?
Thank you in advance.
Regards,

Hi,
According to your description, I guess APP locker maybe helpful.
By using APP Locker, you can:
1. Define rules based on file attributes that persist across application updates, such as the publisher name (derived from the digital signature), product name, file name, and file version. You can also create rules based on the file path and hash.
2. Assign a rule to a security group or an individual user.
3. Create exceptions to rules. For example, you can create a rule that allows all users to run all Windows binaries except the Registry Editor (Regedit.exe).
4. Use audit-only mode to deploy the policy and understand its impact before enforcing it.
5. Create rules on a staging server, test them, then export them to your production environment and import them into a Group Policy Object.
6. Simplify creating and managing AppLocker rules by using Windows PowerShell cmdlets for AppLocker.
For more details about APP Locker, Please refer to the link below:
http://technet.microsoft.com/en-us/library/hh831440.aspx
Roger Lu
TechNet Community Support

Similar Messages

  • Error encountered while signing. Windows cryptographic service provider reported an error. Object not found. Error code:2148073489. Windows 7, Adobe Reader XI, Symantec PKI, Smart Card and CAC. I have seen other threads for this error but none have a reso

    Error encountered while signing. Windows cryptographic service provider reported an error. Object not found. Error code:2148073489. Windows 7, Adobe Reader XI, Symantec PKI, Smart Card and CAC. I have seen other threads for this error but none have a resolution. Any help would be appreciated.
    Sorry for the long title, first time poster here.

    This thread is pretty old, are you still having this issue?

  • Windows Server Service Provider Registry fails to start - error 1067 The process terminated unexpectedly

    Hello experts,
       I have a SBS 2011 Essentials installation that suddenly has an empty dashboard.
    Event viewer:
    APPLICATION LOG - Event ID: 1000 Source: Application Error
    General Description:
    Faulting application name: ProviderRegistryService.exe, version: 6.1.1840.0, time stamp: 0x4d6dafda
    Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
    Exception code: 0x80131623
    Fault offset: 0x000007fe958b0717
    Faulting process id: 0xff8
    Faulting application start time: 0x01cf340bce30552f
    Faulting application path: C:\Program Files\Windows Server\Bin\ProviderRegistryService.exe
    Faulting module path: unknown
    Report Id: 0befeb0f-9fff-11e3-852b-d4ae52c1faae
    APPLICATION LOG - Event ID: 1025 Source: .Net Runtime
    General Description:
    Application: ProviderRegistryService.exe
    Framework Version: v4.0.30319
    Description: The application requested process termination through System.Environment.FailFast(string message).
    Message: Unhandled exception in OnStart: System.ArgumentOutOfRangeException: Not a valid Win32 FileTime.
    Parameter name: fileTime at System.DateTime.FromFileTimeUtc(Int64 fileTime)
    SYSTEM LOG -Event ID: 7031 Source: Service Control Manager General Description:
    The Windows Server Service Provider Registry service terminated unexpectedly.  It has done this xx0 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
    When I try to start this service I get 'error 1067 - The process terminated unexpectedly'. I have checked all dependencies of this particular service and they are all running properly. I've restarted these dependencies, disabled Kaspersky
    protection, restarted the Server a few times to no avail.
    Any ideas? Thank you!

    I had this exact same problem! Thank you so much Robert for posting a link to that script! That is truly an amazing Powershell script.
    I had all the same errors that AK772 mentioned, but I chose to zoom in on a different issue that the script pointed out. When I ran the "Test CA Infrastructure" step it found several errors. When I looked at what the script was doing there it was
    comparing the server certificate thumbprint in the registry (HKLM:\Software\Microsoft\Windows Server\Identity) with the personal certificates (Personal Certificates in the Certificate snap-in using MMC). When I looked through them individually, sure enough
    the thumbprint in the registry didn't exist in my certificate store. I have NO idea how this could have happened!
    However, from there, I changed my Google search criteria and found the following excellent article:
    http://titlerequired.com/2013/04/29/windows-server-2012-essentials-an-error-prevented-the-dashboard-from-opening/
    This told more about that error and showed how to regenerate the certificate identity in the registry. This totally saved me! Once I ran through the steps that he outlines, even though I got a timeout error towards the end, I could see that the certificate
    thumbprint had changed in the registry and now existed in my personal certificate store.
    Once I saw this, I tried going into services and manually starting the stopped "Windows Server Service Provider Registry" service. Sure enough it started right up, no error this time. Finally, I restarted the server so that all of the other dependent
    services would come back up and re-ran the linked script above and everything was perfect.
    Thanks so much for the breadcrumbs in this post and all of your contributions. I hope that this post will equally be able to help someone else through this very troublesome and evasive error!

  • The windows Cryptographic service provider an error: the keyset is not defined. Error code: 2148073497

    I am using Windows 7, 64 bit,  Adobe 8.1 Professional, ActivClient Agent, with CAC card
    Trying to sign a document digitally however  I keep getting :  The windows Cryptographic service provider an error: the keyset is not defined. Error code: 2148073497
    -I have  tried by deleting my certificates off the computer and reinstalling, this did not help.
    -I have tried rebooting the computer, this did not help.
    -I google the error message and can't locate any step by step instructions to fix this problem.
    Could use some assistance. Please do not assume I'm top of line knowledgeable in Adobe when giving me a fix. That is the reason I am looking for step by step instructions. Thanks.
    Navy Chief

    Hi Chief Mendenhall,
    It's really a Microsoft error, not a Acrobat error, but I know that doesn't make the inability to sign any less frustrating.  This probably has something to do with the communication bridge between Acrobat, Windows, and the CAC software. I know you're not responsible for software upgrades, but is there any chance you can download the free Adobe Reader (Adobe Reader Install for all versions). Even though Reader doesn't have the same editing capability as Acrobat Pro, it will allow you to sign a PDF file, and what I'm looking to see is if this is somehow related to the age of version 8.1, which is well past its end-of life. Even version 9 in longer supported.
    Thanks,
    Steve

  • Error encountered while signing: The Windows Cryptographic Service Provider reported an error: Access was denied because of a security violation. Error Code: 2148532330

    Last night when i tried to sign a document i received the mesage below and after that it says this document can't be signed what can i do to fix this problem.
    Error encountered while signing:
    The Windows Cryptographic Service Provider reported an error:
    Access was denied because of a security violation.
    Error Code: 2148532330

    I assume you are implying "biztax" application here, right?
    I have contacted their program lead, with no result at all.
    Past days I have been searching for a solution - reinstalls / new systems - no solution.
    This issue appeared a week or two ago only.
    I found http://forums.adobe.com/message/5338853 useful - but no positive results either.
    http://test.eid.belgium.be/faq/faq_nl.htm obviously didnt help either.
    If anyone finds a solution to this issue, please do let me know - any help is appreciated.
    Biztax tells to use the "signature", not the "authentication"  - but it is only Auth. that is showing up as option to sign (that works)
    ps, did you fiddle with the Adobe Reader XI security settings and import that PKI etc as well? I hoped that would be the breaktrough. Sadly i'm still crying in my chair.
    Oh, and dont forget: they claim nobody else got this issue. Maybe one or two people. (We got about 8 customers experiencing exactly the same symptoms at the same time )
    >  I noticed that when I try to open the pdf  document that is 'signed' by the government it is not showing the filename in the title bar, but only " - Adobe Reader".    every piece of info helps I guess.
    Obviously last version of Reader   11.0.03

  • "Windows Cryptographic service provider error no. 3221225506" signing in to digital signatures

    Dear Friends,
                       Please help me find solution for this problem which has totally jeopardized my work. I am using Adobe reader X. Everytime I open MCA forms for signing, I have to use some DSC which are stored in my Explorer. But when applying, it shows this error. I am not able to find any solution for this. Pleaaaaase help..

    Hi proindia,
    Please see this point on Acrobatusers.com: http://answers.acrobatusers.com/Why-I-Windows-Cryptographic-Service-Provider-error-Signatu res-sudden-q13152.aspx
    It links to an older Acrobat knowledgebase document, but I think it will fix your error.
    Best,
    Sara

  • Website not asking permission for using location services in Safari iOS 6

    Website is not asking permission for using location services when using Safari mobile  on iOS 6.0 (iPhone 4s)
    Steps to replicate:
    1. Go to http://maps.google.com using Safari
    2. Choose "allow" to use location services
    3. Close Safari and wait 1-2 minutes such that the arrow sign (in the top right) disappears
    4. Go to http://www.nature.com/news/economics-and-genetics-meet-in-uneasy-union-1.11565 using Safari
    5. The arrow sign (in the top right) appears showing that the location services are used when viewing http://www.nature.com/news/economics-and-genetics-meet-in-uneasy-union-1.11565 (even few hours later)
    Why the site http://www.nature.com/news/economics-and-genetics-meet-in-uneasy-union-1.11565 is not asking permission to use location services?
    The Nature journal (site: ww.nature.com) is not affiliated with Google in any way as far as I know!

    I figured out how to stop this from happening. I did 3 things, and I'm not exactly sure which one of them did it because I did them all at the same time.
    1. Turned on Private Browsing
    2. Cleared Cookies and Data
    3. Turned off JavaScript
    This stopped time.com from using my location without permission.
    I then turned off Private Browsing and went back to the same page, and it continued to NOT use my location.
    I'm thinking JavaScript being turned off might be the solution. However, there is a bug that causes JavaScript to turn on again without permission at times:
    http://appleinsider.com/articles/12/12/21/ios-6-bug-reenables-javascript-in-safa ri-without-user-consent
    So just be aware of that. But hopefully doing the above works for you!

  • The Windows Cryptographic Service Provider reported an error Error code 3221225594

    Hi
    When I want to digital sign an inteligent pdf I received this error: The Windows Cryptographic Service Provider reported an error Error code 3221225594 and I couldn't sign. I use adobe 10.1.1 and my operating system is windows server 2008. Please help me to solve the problem...thank you

    Exactly what error do you get?
    Remember this is a CM07 Report and NOT a CM07 query.
    Garth Jones | My blogs: Enhansoft and
    Old Blog site | Twitter:
    @GarthMJ

  • Error: The Windows Cryptographic Service Provider reported an error Error code 3221225594

    Hi
    When I want to digital sign an inteligent pdf I received this error: The Windows Cryptographic Service Provider reported an error Error code 3221225594 and I couldn't sign. I use adobe 10.1.1 and my operating system is windows server 2008. Please help me to solve the problem...thank you

    check the patchdownloader.log file - it can be a permission issue on the folder where you store the updates.
    Kent Agerlund | My blogs: blog.coretech.dk/kea and
    SCUG.dk/ | Twitter:
    @Agerlund | Linkedin: Kent Agerlund |
    Mastering ConfigMgr 2012 The Fundamentals

  • I will be upgrading from Windows XP, service pack 3, to Windows 7 Ultimate. Will I be able to use the same serial number for CS5 I am currently using on Windows XP on Windows 7 Ultimate? THANKS

    I will be upgrading from Windows XP, service pack 3, to Windows 7 Ultimate. Will I be able to use the same serial number for CS5 I am currently using on Windows XP on Windows 7 Ultimate? THANKS

    You should be able to. Just deactivate your copy of CS5 on your old computer. Open one of the applications and choose Help > Deactivate.
    Use your original install discs or a backup of your install file to install on the new computer. Or download here:
    Other downloads

  • Alternative to Find My Friends for Emergency Location Service?

    I'd like to find a way for family members to be able to view my GPS location in case of an emergency. There are two Apple iOS apps that immediately come to mind -- Find My iPhone and Find My Friends -- but they both have limitations.
    Find My iPhone
    This is a great app, and I've used it several times. I love the way that it integrates with icloud.com. However, in order to use this app to share my location with family members, I would have to give them my iCloud username and password. They would not only be able to track my location 24/7, but would also have access to other iCloud assets such as email, calendar, and photos. I'm an adult with nothing to hide, but I still have reservations about giving my parents and siblings full access to my iCloud account.
    Find My Friends
    This app comes very close to what I'm looking for. I could add family members as "friends" in the app and then share my location with them. I like that the app allows you to hide your location. You can choose when you want to make your location available and when you'd rather it remain private.
    So, for example, let's say that I'm going on a long trip by myself. I could unhide my location so that my family would know that I made it to my destination safely. Another example would be if I were going hiking by myself in a remote area. In that case I might want to unhide my location so that family could locate me if I fell and got hurt or became incapacitated.
    The problem with the hide/unhide setting is that it's completely manual. You have to remember to open the app and toggle the setting. This introduces human error into the equation. What if I forget to unhide my location before going on that hiking trip? Or what if I foget to hide my location after the trip is over? I'd rather there be a better, automated approach to location sharing.
    Ideally, I'd like for there to be a way that I could keep my location hidden until requested by family. Family members could use the app to request my location at any time. When a request was made, I would receive a push notification asking me to accept or decline that request. If I didn't respond within a certain amount of time (preferabbly a customizeable amount of time), my location would be automatically unhidden and shared with family.
    Here's an example scenario:
    Let's say I'm by myself and I'm involved in an accident which leaves me unable to call for help or use my phone. My sister wonders why I didn't show up for our scheduled lunch together. She can't reach me by phone or text message, so she sends a request for my location. The app notifies me that she has requested my location and that I have 10 minutes to respond or my location will be made available to her. I'm hurt and can't use the phone, so after 10 minutes, she sees my location and can try to find me or call for help.
    I'd love to see this feature added to Find My Friends. I've looked for other apps that might have this functionality, but can't seem to find any. Most location-sharing apps either make location data available 24/7 or require the user to periodically check in. If anyone has any suggestions for an app that might do what I'm looking for, please let me know. Likewise, if anyone can think of a way that I could use Find My Friends or Find My iPhone to achieve these results, please share that as well.

    I discovered an app a couple days ago that works pretty well. It's called Road ID, and it's made by the company that sells the bracelets by the same name. The app is free and has 2 main features: eCrumb and Stationary Alert.
    Before going on a run, hike, or ride, you specify how long you think the activity will take. You also specify up to 5 contacts to notify. When you begin your activity, the app sends a text message or email to your chosen contacts with a brief message and a URL. By clicking on the URL, friends can track your current and past GPS location on a map. This is the "eCrumb" feature. Your friends don't have to have the app installed, and they don't need anything other than the provided URL to access your location on the map. When your activity is finished (either because the allotted time expires or you manually end the activity), visitors to the URL can still see your past GPS activity (your movements or "bread crumbs" during your activity) but not your current location. They instead receive a message telling them that you have ended your activity (or something similar).
    The "Stationary Alert" feature is pretty neat. Basically it works like this: if you're out for a run, hike, or ride and you remain stationary for longer than 5 minutes, the app's Stationary Alert is triggered. You then have 60 seconds to disable the alert, otherwise the app sends a pre-defined text message or email to your chosen contacts with a link to view your location.
    You can enable eCrumbs or Stationary Alert or both. From my testing, if you only enable Stationary Alert, your chosen contacts are not notified of your activity unless the Stationary Alert is triggered. With eCrumbs enabled, they get an alert as soon as you start the activity. I like that I can choose whether my friends/family get to view my real time GPS data or whether they are just alerted if there's an emergency.
    I think this app will work well for me when I go running. I'm still testing it out, but it looks promising so far.
    Like many third-party app that use location services, this app needs to be running in the background (and most likely needs access to your phone's background app refresh capabilities). That means the app is constantly using your phone's GPS and probably draining your battery more quickly. For that reason, I wouldn't use it for anything other than going out for a run or a hike. I already use GPS apps when I go running, so I'm accustomed to charging my phone before and after a run.
    When it comes to something longer, say a solo road trip, I think I'll stick with Jay-Ray's suggestion and just use Find My Friends. I can always set a reminder to hide my location once I get to my destination, or, as Jay-Ray suggested, just leave it on until I need to be sneaky. Find My Friends only uses location data when one of your friends opens the app to request your location. It's similar to Find My iPhone in that it's not constantly using GPS. This definitely saves on battery life.
    So, for now, I'm using Road ID for short activities and Find My Friends for longer activities. I don't like having to use 2 different apps, but it's a reasonably easy solution at this time.
    P.S. - Don't know if I need one of these, but just in case.......DISCLAIMER: I'm not affiliated with Road ID, Inc., or Apple, Inc., in any way. All app names and feature names are the property of their respective copyright holders/owners and may also be registered trademarks. My recommendations and observations are purely based on my own experiences. Your results may vary. I also don't really go hiking anymore; I'm not a very good runner; and, although I'm often driving by myself, it's certainly not because I'm going on vacation or traveling to fun and exotic locations.

  • Is there a way to change the Windows Update service startup type on Windows Server 2012 R2?

    We have a number of newly built 2012 R2 servers that we have HP Operations Manager agent running on that monitors the status of several services and reports if they are "stopped". One of these services is Windows Update. Every day we
    get at least one alert saying:
    "Service "Windows Update" is not started. Current state is stopped"
    Checking the event logs shows that the Windows Update service stops, then a while later it just starts again. Not an error, just an information event.
    In Windows 2012 R2 the Windows Update service is set to "Automatic (Trigger Start)", where in previous versions we run (2012/2008R2) it would be set to just "Automatic" or "Automatic (Delayed Start)"
    I have come to understand that this behaviour is normal for Windows 2012 R2, and that Trigger Start services by design stop themselves after a period of inactivity. I was unable to find any info on how this works. Our client would like this to
    be changed and the Windows Update service stay running all the time, understanding that this impacts performance.
    Is there a way to change the Windows Update service in Server 2012 R2 to the old Automatic startup behaviour so that it stays running all the time instead of stopping and starting periodicall? There is no option to do this via the services mmc
    gui.
    So far I have tried:
    Removing the Triggers using the command: sc triggerinfo wuauserv delete
    This works temporarily, the service then shows as just Automatic in the services console, however if you restart the server or restart the service it goes right back to being Automatic (Trigger Start).
    Any kind of help would be appreciated.

    This one might help.
    Allow configuration of Automatic Updates in Windows 8 and Windows Server 2012
    Regards, Dave Patrick ....
    Microsoft Certified Professional
    Microsoft MVP [Windows]
    Disclaimer: This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.

  • How to encrpt password for Secure store service while configuring by Windows powershell Script

    To configure Secure store service, we have to mention user name and passowrd for generating key.
    For this is password we are giving in plain text which is readable and also which is security violation as per company rules.
    so i want to encript the password,so that no body can read and it is not against security violation.
    so any body can tell me how to encrpt password while configuring secure store service using powershell command

    Hi,
    For your issue, you can encrypt the files using Encrypting File System. By this method, only the user that stores it can access the encrypted passwords.
    For more information, you can refer to the thread:
    https://social.technet.microsoft.com/Forums/en-US/bae4f78b-e12e-4afe-981f-d93909d33d5a/what-is-the-most-secure-method-to-store-password-in-powershell?forum=winserverpowershell
    Thanks,
    Eric
    Forum Support
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact
    [email protected]
    Eric Tao
    TechNet Community Support

  • Windows Cryptographic Service Provider - error code: 2148532334 (Windows 8.1)

    Dear,
    since my computer was recently updated from Windows 8 to Windows 8.1 I have a problem with placing my signature (via certifcates).
    Before the update I could sign all my pdf-files with my electronic identity card - without issues.
    Now I receive a window: "windows-security" which says: Smartcarderror (some required programmes are not installed on the system).
    When I click "cancel" I get the error code in subject.
    Another card reader is not changing anything, neither another smartcard (id-card).
    Please advise, as signing pdf-files is very important for our company.
    Thanks. Willem Van Lommel
    NB: in my opinion all other updates are done without troubles.
    NB2: please find herewith some prt scns (in Dutch):
    1. before a smartcard was pushed in the cardreader:
    2. after the smartcard was added (same when card was added to other cardreader)
    3. because "ok" didn't result in anything -> you have to click "cancel - annuleren" or on the red X (at the right corner), then the result is:

    If by "Adboe X Pro" you mean Acrobat, you are more likely to get a useful reply if you ask in the Acrobat forum.
    All I can tell you that this error (0x80100068) means "The smart card has been reset, so any shared state information is invalid."

  • How to use amount control for multiple sliders in the basic adjustments window

    In a webinar an instructor (Chris Orwig) demonstrated how to make multiple adjustments in the basic panel in the develop module.  He then showed how to close the basic module by clicking on the small triangle at the top of the module.  When this was done a single control bar and slider appeared in place of the closed basic module. Moving this slider allowed the instructor to adjust all previously set basic module settings at the one time.  I tried to do this.  But when I close the basic module no control bar and slider appear.  Any suggestions why this is the case?
    I use Lightroom 5.4 and OS 10.9.2.

    He evidently wasn't in the Basic panel, but in the Adjustment Brush:
    Clicking on the triangle at the end of the red arrow yields this:
    And there is your Effect slider.
    Hal

Maybe you are looking for