Skip to content
IAM built for the AI-Era

Configure Active Directory-joined Computers

The configuration for Specops Client is stored in the Windows Registry on each computer where it is installed. We recommend deploying the settings described below using Group Policy and the ADMX template included in the Specops Client setup.

After configuring the settings, ensure that the Group Policy Object (GPO) is linked to the domain or organizational unit (OU) containing the intended computers.

Enable or Disable the Start Menu Shortcuts

By default, three Start menu shortcuts are created when a user signs in: Enroll, Password Reset, and Password Change.

To show only a subset of the shortcuts, enable or disable the settings below as needed. For example, you can hide the Password Reset shortcut while keeping the Password Change and Enroll shortcuts.

To enable or disable a shortcut:

  1. In the Group Policy Management Editor, navigate to Computer Configuration > Administrative Templates > Specops Client > General Client settings.
  2. Open the policy for each shortcut you want to configure and set it to Enabled or Disabled:
    • Create start menu shortcut to enroll
    • Create start menu shortcut to password reset
    • Create start menu shortcut to password change
  3. Click OK.

Note

To control shortcuts individually, leave Create all start menu shortcuts to password enroll/change/reset set to Not configured. When configured, this policy overrides the individual shortcut settings.

To restore an individual shortcut, set its policy to Not configured or Enabled.

Also refer to Registry Settings.

When using Specops Client with Specops Password Policy, but without Specops uReset or Specops Password Reset, it is recommended to disable the "Password Reset" link shown on the Windows Sign-in screen.

To hide the Password Reset... link:

  1. In the Group Policy Management Editor, navigate to Computer Configuration > Administrative Templates > Specops Client > Windows logon screen.
  2. Open the Show the Password Reset Link policy and set it to Disabled.
  3. Click OK.

Note

To allow the link to appear again, set the policy to Not configured or Enabled.

Also refer to Registry Settings.

Registry Settings

The Group Policy settings described above use the following registry key. You can also configure these values directly in the Windows Registry.

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Specopssoft\uReset\Client\Settings

Registry Value ADMX Name Description Default
CreateStartMenuShortcutEnroll Create start menu shortcut to enroll Controls the Enroll shortcut in the Start menu. Set to 0 to remove the shortcut at the next sign-in. Enabled
CreateStartMenuShortcutReset Create start menu shortcut to password reset Controls the Password Reset shortcut in the Start menu. Set to 0 to remove the shortcut at the next sign-in. Enabled
CreateStartMenuShortcutChange Create start menu shortcut to password change Controls the Password Change shortcut in the Start menu. Set to 0 to remove the shortcut at the next sign-in. Enabled
EnablePasswordResetLink Show the Password Reset link Controls the password reset link on the Windows sign-in screen. Set to 0 to hide it or 1 to allow it to appear when available. Enabled

Note

The CreateStartMenuShortcuts value in the same registry key overrides the three individual shortcut values when configured. Leave it unconfigured to control shortcuts individually.