I've covered deploying registry settings via Group Policy Preferences in a previous post, so you may want to have a quick scan if you're not familiar.

After updating to IE 11 this last week, this policy causes a Page Cannot Be Displayed error for most clients. Windows Registry Editor Version 5.00 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains] @="" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\google.com] "*"=dword:00000002 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\microsoft.com] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\microsoft.com\www] "http"=dword:00000002 The dword value in this example is 00000002.

I linked this GPO to my workstation OU as well as the users OU but I still cannot add/remove any trusted sites. Deleting an orphaned NTDS Settings from Active Directory Sites and Services errors with 'DSA object cannot be deleted'? If you want GPO-affected users to be able to add (but not delete) sites to any zone list, use the following GPO setting instead:

JSI Tip 7163. if i save it, can it be attached to the post so you can open it? Reply Peter November 9, 2015 at 1:56 pm Hello, I've created GPO with trusted sities, and of course i can't add it anymore on user machine. Apparently the Flags registry value this is a bitwise value, and thus multiple settings are contained in this one value. Also, be wary that my method also imports the security settings for each zone.

As we discussed in the last couple of posts, Internet Explorer Maintenance (IEM) has been deprecated with Internet Explorer 10. In the right pane of Internet Explorer, double click/tap on Security Zones: Do not allow users to add/delete sites. (see screenshot above)

My machine is one that has this problem on it as well as my data server. Those entries you're posting are strange ones, to say the least.

You cannot restrict domain users who are local administrators from resetting and registering computer accounts?

Now, whenever we need to add more trusted sites, I can just update the reg key in the shared location. This is what I do, I have 5 or 6 trusted sites and 7 URL's in the favs that all users get when they logon to the domain. I tried one more time to add the two sites to the Restricted Zone and for some reason this time it worked.

Have I totally confused you and all else reading this, or have I made some sense? Do step 6 or 7 below for what you would like to do.

First Name Please enter a first name Last Name Please enter a last name Email We will never share this with anyone. So, if I understand you correctly, perhaps if I also add my 2, *.*.bandwidthplace. Reply Matt March 16, 2015 at 2:14 pm We currently deploy intranet zone mappings through Group Policy.

i did some testing and now its working.