Skip to content
IAM built for the AI-Era

Configure Entra ID-joined Computers

The configuration for Specops Client is stored in the Windows Registry on each computer where it is installed. We recommend deploying the settings described below using Microsoft Intune and the ADMX template included in the Specops Client setup.

To create a configuration profile using the imported ADMX template, follow Create a profile using your imported files. The navigation paths below apply within the profile's configuration settings.

Show the Start Menu Shortcuts

By default, Specops Client expects computers to be joined to an on-premises Active Directory domain. On Entra ID-joined computers, you must enable the following setting to allow Specops Client to create shortcuts in the Windows Start menu.

  1. Open the Microsoft Intune admin center and open the configuration profile that uses the imported Specops Client Administrative Templates.
  2. In the profile's configuration settings, navigate to Specops Client (Microsoft Entra ID Computers) > General settings for Specops Client.
  3. Set Enable shortcuts for cloud joined computer to Enabled.

Also refer to Registry Settings.

Enable or Disable the Start Menu Shortcuts

Once shortcuts have been enabled as described above, three shortcuts are created in the Start menu when a user signs in (Enroll, Password Reset and Password Change).

To show only a subset of the shortcuts, enable or disable the settings below as needed. For example, you can hide the Password Reset shortcut while keeping the Password Change and Enroll shortcuts.

To enable or disable a shortcut:

  1. Open the Microsoft Intune admin center and open the configuration profile that uses the imported Specops Client Administrative Templates.
  2. In the profile's configuration settings, navigate to Administrative Templates > Specops Client (Microsoft Entra ID Computers) > General settings for Specops Client.
  3. Open the policy for each shortcut you want to configure and set it to Enabled or Disabled:
    • Create start menu shortcut to enroll
    • Create start menu shortcut to password reset
    • Create start menu shortcut to password change

Note

To control shortcuts individually, leave Create all start menu shortcuts to password enroll/change/reset set to Not configured. When configured, this policy overrides the individual shortcut settings.

To restore an individual shortcut, set its policy to Not configured or Enabled.

Also refer to Registry Settings.

Configure the uReset Start Menu Shortcut URLs

Each Start menu shortcut (Enroll, Password Reset and Password Change) needs a URL that directs users to the corresponding uReset web page.

To configure the shortcut URLs:

  1. Open the Specops Gatekeeper Admin Tool and copy the URLs for enrollment, password reset and password change.
  2. Open the Microsoft Intune admin center and open the configuration profile that uses the imported Specops Client Administrative Templates.
  3. In the profile's configuration settings, navigate to Administrative Templates > Specops Client (Microsoft Entra ID Computers) > URLs to Specops Authentication.
  4. Enable each of the following policies and enter the corresponding URL copied from the Specops Gatekeeper Admin Tool:
    • URL to web page for user enrollment
    • URL to web page for resetting password
    • URL to web page for changing password

Also refer to Registry Settings.

Disable the Windows Change Password Option

To provide dynamic feedback on password policy requirements as users type a new password, it is recommended to hide Windows' built-in Change password option (Ctrl+Alt+Del) and advise users to use Specops uReset instead.

Note

This is a per-user setting.

To hide the Change password option after pressing Ctrl+Alt+Del on Entra ID-joined computers:

  1. Open the Microsoft Intune admin center and open the configuration profile that uses the imported Specops Client Administrative Templates.
  2. In the profile's configuration settings, navigate to Administrative Templates > System > Ctrl+Alt+Del Options.
  3. Set Remove 'Change Password' in Windows to Enabled.

Also refer to Registry Settings.

Registry Settings

The settings described above use the following registry keys and values. You can also configure these values directly in the Windows Registry.

Start Menu Shortcuts

The following values use this registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Specopssoft\uReset\Client\Settings

All values in this table are of type REG_DWORD. The Default column describes the behavior when the setting is not configured.

Registry Value ADMX Name Description Default
AllowShortcutsWithoutOnpremDomain Enable shortcuts for Entra ID-joined computers Set to 1 to allow Start menu shortcuts on computers that are not joined to an on-premises Active Directory domain. Set to 0 to disable this functionality. Not specified in the template. Set to 1 for this configuration.
CreateStartMenuShortcutEnroll Create start menu shortcut to enroll Set to 0 to hide the Enroll shortcut or 1 to show it. Enabled
CreateStartMenuShortcutReset Create start menu shortcut to password reset Set to 0 to hide the Password Reset shortcut or 1 to show it. Enabled
CreateStartMenuShortcutChange Create start menu shortcut to password change Set to 0 to hide the Password Change shortcut or 1 to show it. Enabled

Existing shortcuts are removed at the next sign-in when disabled.

Note

The individual shortcut settings are enabled by default, but you must also set AllowShortcutsWithoutOnpremDomain to 1 to allow shortcuts on Entra ID-joined computers.

The CreateStartMenuShortcuts value in the same registry key overrides the three individual shortcut values when configured. Leave it unconfigured to control shortcuts individually.

uReset Start Menu Shortcut URLs

The following values use this registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Specopssoft\uReset\Client\Urls

All values in this table are of type REG_SZ.

Registry Value ADMX Name Description Template Example
Enroll URL to web page for user enrollment The enrollment URL copied from the Specops Gatekeeper Admin Tool. Example URL
Reset URL to web page for resetting password The password reset URL copied from the Specops Gatekeeper Admin Tool. Example URL
Change URL to web page for changing password The password change URL copied from the Specops Gatekeeper Admin Tool. Example URL

Note

The ADMX template provides example URLs containing ACME.ORG, which represents an example domain. Replace each example URL with the corresponding URL copied from the Specops Gatekeeper Admin Tool.

Windows Change Password Option

The following value uses this registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System

The value is of type REG_DWORD.

Registry Value ADMX Name Description Default
DisableChangePassword Remove Change Password Set to 1 to hide the Change password option shown after pressing Ctrl+Alt+Del. Set to 0 to allow it. Not configured (Change password option available)

Note

This setting applies to the current user. It hides the Change password option but does not prevent users from changing their password when prompted by Windows.