<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Harsh Shah's eBlog</title><link>http://blogs.msdn.com/harshs/default.aspx</link><description>Sharing views on Windows Embedded Technologies and Devices</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Removing Windows Firewall from SP2 Configuration to reduce footprint</title><link>http://blogs.msdn.com/harshs/archive/2004/10/12/241426.aspx</link><pubDate>Tue, 12 Oct 2004 23:32:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:241426</guid><dc:creator>harshs</dc:creator><slash:comments>7</slash:comments><comments>http://blogs.msdn.com/harshs/comments/241426.aspx</comments><wfw:commentRss>http://blogs.msdn.com/harshs/commentrss.aspx?PostID=241426</wfw:commentRss><description>&lt;p&gt;Hello All,&lt;/p&gt; &lt;p&gt;Are you looking for low footprint SP2 Image?&amp;nbsp;Here is one way to reduce the footprint, if you don't need&amp;nbsp;"Windows Firewall"&amp;nbsp;in your configuration&amp;nbsp;(Note: In general keeping windows firewall in runtime is recommended):&lt;/p&gt; &lt;p&gt;1. Create a new SP2 configuration and import PMQ for your system.&lt;br /&gt;2. Add any other components that you want in your configuration with the following exceptions:&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;A) If you add "Retail Point of Sale Terminal" macro, go to settings of this component and uncheck "Windows Firewall/Internet Connection Sharing (ICS)".&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;B) If you add "Home Gateway" macro, go to settings of this component and uncheck "Windows Firewall/Internet Connection Sharing (ICS)".&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;C) If you add "Networking Application Compatibility" macro, go to settings of this component and uncheck following:&lt;br /&gt;&amp;nbsp;"Windows Firewall/Internet Connection Sharing (ICS)"&lt;br /&gt;&amp;nbsp;"Windows Firewall Control Panel"&lt;br /&gt;&amp;nbsp;"Core Networking"&lt;br /&gt;&amp;nbsp;"Connection Manager Runtime"&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;D) If you add any of the following components manually in your runtime, Windows Firewall will be brought in your runtime:&lt;br /&gt;&amp;nbsp;Connection Manager Runtime &lt;br /&gt;&amp;nbsp;Security Center&lt;br /&gt;&amp;nbsp;Windows Firewall Control Panel&lt;br /&gt;&amp;nbsp;Windows .Net Messenger&lt;br /&gt;3. Manually add "Core Networking" component in your configuration. Go to settings of this component and uncheck "Windows Firewall/Internet Connection Sharing (ICS)".&lt;br /&gt;4. Run dependency check and build image.&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=241426" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/harshs/archive/tags/XP+Embedded/default.aspx">XP Embedded</category></item><item><title>Retail-optimized XP Embedded Operating System</title><link>http://blogs.msdn.com/harshs/archive/2004/10/05/238191.aspx</link><pubDate>Tue, 05 Oct 2004 21:56:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:238191</guid><dc:creator>harshs</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/harshs/comments/238191.aspx</comments><wfw:commentRss>http://blogs.msdn.com/harshs/commentrss.aspx?PostID=238191</wfw:commentRss><description>&lt;p&gt;Microsoft just announced the development of customized windows embedded OS targeted towards retail POS systems. Check it out at:&lt;/p&gt; &lt;p&gt;&lt;a href="http://msdn.microsoft.com/embedded/getstart/devplat/pos/default.aspx"&gt;http://msdn.microsoft.com/embedded/getstart/devplat/pos/default.aspx&lt;/a&gt;&lt;/p&gt; &lt;p&gt;This is a part of Smarter Retailing Initiative from Microsoft. For information on this initiative, visit following site:&lt;/p&gt; &lt;p&gt;&lt;a href="http://www.microsoft.com/resources/retail/"&gt;http://www.microsoft.com/resources/retail/&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=238191" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/harshs/archive/tags/XP+Embedded/default.aspx">XP Embedded</category></item><item><title>Windows XP Embedded with eTRUST Antivirus Software!</title><link>http://blogs.msdn.com/harshs/archive/2004/10/05/238186.aspx</link><pubDate>Tue, 05 Oct 2004 21:48:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:238186</guid><dc:creator>harshs</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.msdn.com/harshs/comments/238186.aspx</comments><wfw:commentRss>http://blogs.msdn.com/harshs/commentrss.aspx?PostID=238186</wfw:commentRss><description>&lt;p&gt;Computer Associates released eTrust Antivirus software for XP Embedded yesterday. It promises minimal&amp;nbsp;footprint starting at under 6MB and compatability with XP Embedded SP2.&amp;nbsp; It&amp;nbsp;provides protection against viruses and a variety of other network-based threats and essential updates of virus signatures for ongoing security. Check it out at:&lt;/p&gt; &lt;p&gt;&lt;a href="http://ca.com/channel/oem/eav.htm"&gt;http://ca.com/channel/oem/eav.htm&lt;/a&gt;&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=238186" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/harshs/archive/tags/XP+Embedded/default.aspx">XP Embedded</category></item><item><title>Free XP Embedded SP2 Tech Preview is Available </title><link>http://blogs.msdn.com/harshs/archive/2004/10/05/238182.aspx</link><pubDate>Tue, 05 Oct 2004 21:40:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:238182</guid><dc:creator>harshs</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/harshs/comments/238182.aspx</comments><wfw:commentRss>http://blogs.msdn.com/harshs/commentrss.aspx?PostID=238182</wfw:commentRss><description>&lt;p&gt;XP Embedded SP2 Tech preview is available for download from the following site:&lt;/p&gt; &lt;p&gt;&lt;a href="http://download.microsoft.com/download/D/5/5/D55A381F-F2B7-4787-8A43-0D79CF8B8C35/XPEFFI.exe"&gt;http://download.microsoft.com/download/D/5/5/D55A381F-F2B7-4787-8A43-0D79CF8B8C35/XPEFFI.exe&lt;/a&gt;&lt;/p&gt; &lt;p&gt;For more information on what is new in XP Embedded SP2, check out the following article:&lt;/p&gt; &lt;p&gt;&lt;a href="http://www.windowsfordevices.com/news/NS9761865541.html"&gt;http://www.windowsfordevices.com/news/NS9761865541.html&lt;/a&gt;&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=238182" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/harshs/archive/tags/XP+Embedded/default.aspx">XP Embedded</category></item><item><title>How to configure Firewall in XPE SP2?</title><link>http://blogs.msdn.com/harshs/archive/2004/10/01/236768.aspx</link><pubDate>Fri, 01 Oct 2004 23:12:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:236768</guid><dc:creator>harshs</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/harshs/comments/236768.aspx</comments><wfw:commentRss>http://blogs.msdn.com/harshs/commentrss.aspx?PostID=236768</wfw:commentRss><description>&lt;p&gt;Hi All:&lt;/p&gt; &lt;p&gt;Windows XP Embedded SP2 is coming and one of the major feature that has changed is windows firewall. Firewall is enabled by default in SP2 and you will need to open ports used by your applications.&amp;nbsp;Here is how you can configure Windows Firewall in XPE SP2:&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;u&gt;To Configure Firewall Pre-FBA (offline) you can do one of the following:&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;1. In TD configuration, go to "Windows Firewall/Internet Connection Sharing (ICS)" component and modify settings.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;2. If you have already built image and want to change firewall options without rebuilding image, you can do one of the following:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;&lt;span style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;A) You can use firewall configuration information file (netfw.inf). This file is located in your image folder under "windows\inf" directory. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;This file has two sections:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;[ICF.AddReg.DomainProfile] - change settings under this section to change firewall settings for all domain accounts (domain firewall policy)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;[ICF.AddReg.StandardProfile] - change settings under this section to only affect local system account(s). &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;Following settings are available under each of the above sections (The value shown for each setting s the default value):&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;HKLM,"System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile","&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="COLOR: maroon"&gt;EnableFirewall&lt;/span&gt;&lt;/b&gt;",0x00010001,&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="COLOR: maroon"&gt;1&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: maroon"&gt;- EnableFirewall = Enable Firewall? &lt;span style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Values: 0 = Firewall Off,&lt;span style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/span&gt;1= Firewall On (default)&lt;/span&gt;&lt;/b&gt;&lt;span style="FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;HKLM,"System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile","&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="COLOR: maroon"&gt;DoNotAllowExceptions&lt;/span&gt;&lt;/b&gt;",0x00010001,&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="COLOR: maroon"&gt;0&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: maroon"&gt;-DoNotAllowExceptions = Don’t allow any exceptions?&lt;span style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Values: 0 = Allow Exceptions (default),&lt;span style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/span&gt;1 = No Exceptions&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: maroon"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: navy"&gt;NOTE: &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: navy"&gt;- If you want to turn on the firewall w/o any exceptions, set EnableFirewall = 1 and DoNotAllowExceptions = 1&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: navy"&gt;- If you want to turn on the firewall with exceptions, set EnableFirewall = 1 and DoNotAllowExceptions = 0&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: navy"&gt;- If you want to turn off the firewall, set EnableFirewall = 0. (The value that you set for DoNotAllowExceptions does not matter until you turn on the firewall in runtime. At this point the default starting value for exceptions will be the one that you set using DoNotAllowExceptions)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: maroon"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;HKLM,"System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile","&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="COLOR: maroon"&gt;DisableNotifications&lt;/span&gt;&lt;/b&gt;",0x00010001,&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="COLOR: maroon"&gt;0&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: maroon"&gt;- DisableNotifications = Disable Firewall Notifications when a program is blocked?&lt;span style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Values: 0 = Notify when a program is blocked (default),&lt;span style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/span&gt;1=DON’T notify when a program is blocked.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;All ICMP settings can be found here under IcmpSettings subkey (default setting is to NOT allow any ICMP requests).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;For e.g.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;HKLM,"System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="COLOR: maroon"&gt;IcmpSettings&lt;/span&gt;&lt;/b&gt;","&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="COLOR: maroon"&gt;AllowInboundTimeStampRequest&lt;/span&gt;&lt;/b&gt;",0x00010001,&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="COLOR: maroon"&gt;0&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: maroon"&gt;- AllowInboundTimeStampRequst = Allow incoming timestamp request? &lt;span style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Values: 0 = No (default), 1= Yes&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: maroon"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;List of Authorized Applications:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;HKLM,"System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List","%windir%\system32\sessmgr.exe",0x00000000,&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="COLOR: maroon"&gt;"%windir%\system32\sessmgr.exe:*:Enabled:Remote Assistance"&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;The last part of the entry is formatted as:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: maroon"&gt;"%windir%\system32\sessmgr.exe:*:Enabled:Remote Assistance"&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: maroon"&gt;(Path to program executable): (Scope – LocalSubnet or * (for any source) ): (Enabled/Disabled): (Program Name)&lt;span style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;There is only one application that is authorized by default – remote assistance. You can, however, add more entries here. Here is an example of how you will add your application – myapp.exe in authorized application list and enable it for local subnet.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;HKLM,"System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List",&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="COLOR: maroon"&gt;"C:\Program Files\Applications\myapp.exe",&lt;/span&gt;&lt;/b&gt;0x00000000,&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="COLOR: maroon"&gt;"C:\Program Files\Applications\myapp.exe: LocalSubnet: Enabled: My Application"&lt;/span&gt;&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;List of Port Openings:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;HKLM,"System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List",&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="COLOR: maroon"&gt;"137:UDP"&lt;/span&gt;&lt;/b&gt;,0x00000000,&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="COLOR: maroon"&gt;"137:UDP:LocalSubnet:Disabled:NetBIOS Name Service"&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;The last part of this entry is formatted as:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: maroon"&gt;"137:UDP:LocalSubnet:Disabled:NetBIOS Name Service"&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: maroon"&gt;(Port Number(1-65535) : Protocol(UDP/TCP) : Scope(LocalSubnet/*) : Enabled/Disabled : Port Name&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: maroon"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;Port openings can be added either as enabled or disabled. If port opening entry is disabled, that port is effectively blocked by firewall, until it is enabled in the runtime. There are 7 entries for port opening by default and all of them are disabled. You can edit those entries to enable some port opening(s) or you can add new entries. For example, you can edit the above port to enable it for any source.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;HKLM,"System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List",&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="COLOR: maroon"&gt;"137:UDP"&lt;/span&gt;&lt;/b&gt;,0x00000000,&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="COLOR: maroon"&gt;"137:UDP:*:Enabled:NetBIOS Name Service"&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: maroon"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: maroon"&gt;&lt;span style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="FONT-SIZE: 10pt"&gt;B) Alternatively you can open regedit and load system hive from image folder located at windows\system32\config\system.sav. Go to the following sub tree under this hive:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: maroon"&gt;CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: maroon"&gt;Or&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: maroon"&gt;CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\GlobalProfile&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: maroon"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: black"&gt;Add/Edit/Delete the registry keys according to the settings explained above in (A). All ICMP related settings will be under “ICMPSettings” subkey.&lt;span style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/span&gt;All authorized application settings will be under “Authorized Applications\List” subkey. All port opening settings will be under “GloballyOpenPorts\List” subkey.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: maroon"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: maroon"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;u&gt;&lt;span style="COLOR: black"&gt;To configure Firewall Post-FBA you can do one of the following:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="COLOR: black"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;ol style="MARGIN-TOP: 0in" type="1"&gt; &lt;li class="MsoNormal" style="MARGIN: 0in 0in 0pt; COLOR: black; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;If you added “Windows Firewall Control Panel” component in the configuration, you can run firewall.cpl to change all firewall related settings.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt; &lt;li class="MsoNormal" style="MARGIN: 0in 0in 0pt; COLOR: black; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;If you don’t have control panel access, but if your runtime has access to netsh shell you can use it to change firewall settings.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: black"&gt;Using netsh:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt 0.25in"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: black"&gt;&lt;span style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: maroon"&gt;netsh&amp;gt;Firewall&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt 0.25in"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: maroon"&gt;&lt;span style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;netsh firewall&amp;gt; show state (to check the current status of firewall)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 0.5in"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: maroon"&gt;netsh firewall&amp;gt;set opmode [enable/disable] [enable/disable] &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt 0.25in"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: black"&gt;Where first parameter is state of the firewall (enable=on, disable=off) and second parameter is whether you want to allow exceptions (enable=allow exceptions, disable=don’t allow exceptions). You can also specify interface and/or profile. Please use netsh shell help for details.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt 0.25in; TEXT-INDENT: 0.25in"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: maroon"&gt;netsh firewall&amp;gt;set notifications [enable/disable]&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt 0.25in"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: black"&gt;enable = notify when program is blocked, disable = do not notify when program is blocked&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt 0.25in"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: black"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt 0.25in"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: black"&gt;You can also change ICMP settings, create port openings and authorized application/service using the following netsh commands.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt 0.25in"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: maroon"&gt;&lt;span style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;netsh firewall&amp;gt;set icmpsetting &lt;span style="mso-tab-count: 2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;span style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/span&gt;(to change ICMP Settings)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt 0.25in"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: maroon"&gt;&lt;span style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;netsh firewall&amp;gt;set service&lt;span style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/span&gt;&lt;span style="mso-tab-count: 2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;(to create authorized applications)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt 0.25in"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: maroon"&gt;&lt;span style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;netsh firewall&amp;gt;set portopening &lt;span style="mso-tab-count: 2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;(to create port openings)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="MARGIN: 0in 0in 0pt 0.25in"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: black"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;ol style="MARGIN-TOP: 0in" type="1" start="3"&gt; &lt;li class="MsoNormal" style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: black"&gt;If you have access to regedit in runtime, edit the related registry keys directly as explained above.&lt;/span&gt;&lt;span style="FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=236768" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/harshs/archive/tags/XP+Embedded/default.aspx">XP Embedded</category></item><item><title>Configuring common user settings and Policies in runtime</title><link>http://blogs.msdn.com/harshs/archive/2004/09/15/229795.aspx</link><pubDate>Wed, 15 Sep 2004 09:19:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:229795</guid><dc:creator>harshs</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/harshs/comments/229795.aspx</comments><wfw:commentRss>http://blogs.msdn.com/harshs/commentrss.aspx?PostID=229795</wfw:commentRss><description>&lt;p&gt;&lt;font face="Arial" color="#000080" size="2"&gt;Severeal common user settings and policies can be set using gpedit.msc (Group Policy Snap-in). This includes desktop, start menu, taskbar, contorl panel, logon, network and power management related settings etc. Have you ever wondered how to remove logoff or shutdown button from start menu?&amp;nbsp; Or how to set wallpaper or screensaver in runtime? Or how to hide notification area or tooltip? There are so many such settings that can be done through gpedit.msc. &lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font face="Arial" color="#000080" size="2"&gt;If your runtime configuration includes "Group Policy Core Administration MMC Snap-In" Component and some support components, you can use gpedit.msc in runtime to change above settings. Alternatively, you can use regmon (&lt;/font&gt;&lt;a href="http://www.sysinternals.com"&gt;&lt;font face="Arial" color="#000080" size="2"&gt;www.sysinternals.com&lt;/font&gt;&lt;/a&gt;&lt;font face="Arial" color="#000080" size="2"&gt;) to identify the registry key corresponding to particular setting and use regedit to change the setting in runtime. The registry key related to most of the above settings are under the following registry branch:&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font face="Arial" color="#000080" size="2"&gt;HKCU\Software\Microsoft\Windows\CurrentVersion\Policies (and sub branches - Explorer, Network, System etc.)&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font face="Arial" color="#000080" size="2"&gt;Once you identify the key corresponding to the setting, you can create that registry key under this branch and set the value to 0 (for disable) or 1(for enable). For example, if you want to remove logoff button from your start menu, you need to create the following registry key in runtime and set the value to 1(to enable):&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font face="Arial" color="#000080" size="2"&gt;HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\StartMenuLogoff&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font face="Arial" color="#000080" size="2"&gt;This is same as enabling the following policy in gpedit.msc:&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font face="Arial" color="#000080" size="2"&gt;User configuration-&amp;gt;Administrative Templates-&amp;gt;Start menu and taskbar-&amp;gt;"Remove Logoff on the start menu" (change to 'enabled' from 'not configured')&lt;/font&gt;&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=229795" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/harshs/archive/tags/XP+Embedded/default.aspx">XP Embedded</category></item><item><title>Improved Security Agent for XP Embedded from Sygate Technologies</title><link>http://blogs.msdn.com/harshs/archive/2004/09/14/229231.aspx</link><pubDate>Tue, 14 Sep 2004 10:12:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:229231</guid><dc:creator>harshs</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.msdn.com/harshs/comments/229231.aspx</comments><wfw:commentRss>http://blogs.msdn.com/harshs/commentrss.aspx?PostID=229231</wfw:commentRss><description>&lt;p&gt;&lt;font face="Arial" color="#000080" size="2"&gt;Sygate Technologies announced that their improved&amp;nbsp;security agent 4.0 for XP Embedded devices will be available by end of this month. It promises advanced protection against worm, viruses and application hijacking. Check out the following article:&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;a href="http://biz.yahoo.com/prnews/040913/nym073_1.html"&gt;&lt;font face="Arial" color="#000080" size="2"&gt;http://biz.yahoo.com/prnews/040913/nym073_1.html&lt;/font&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;/font&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=229231" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/harshs/archive/tags/XP+Embedded/default.aspx">XP Embedded</category></item><item><title>EOL (End of Life) Components and Branching </title><link>http://blogs.msdn.com/harshs/archive/2004/09/08/227153.aspx</link><pubDate>Thu, 09 Sep 2004 04:56:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:227153</guid><dc:creator>harshs</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.msdn.com/harshs/comments/227153.aspx</comments><wfw:commentRss>http://blogs.msdn.com/harshs/commentrss.aspx?PostID=227153</wfw:commentRss><description>&lt;p class="MsoNormal"&gt;&lt;font color="navy" size="2"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: Arial"&gt;Have you ever wondered what are those "End of Life (EOL)" components in XPE database and how they work? &lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt;&lt;font color="navy" size="2"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: Arial"&gt;When a new version of some application or component is available (e.g. Windows Media Player 9.0 or DirectX 9.0), old version of that component (e.g. WMP 8.0 or DirectX 8.0) is retired. To replace the old version of component, an EOL object for that component is added to XPE database which indicates that the component is no longer valid. EOL components are created by removing all resources (file, registry and any other resources) from the original component - they are essentially empty objects with special revision and visibility values. EOL objects have revision value of 100,000 or greater and they typically have a visibility of 0 (so you wouldn't see them under components list in TD). If your existing configuration already contains the component(s) that has been EOLed, Target designer can detect it and handle it correctly. Target Designer will show "(EOL)" at the end of component displayname - so that you can recognize that the component has been EOLed in the new version of the database. &lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt;&lt;font color="navy" size="2"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: Arial"&gt;&lt;/span&gt;&lt;/font&gt;&lt;font color="navy" size="2"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: Arial"&gt;To replace the EOLed component in the configuration with the new version of component, "Branching" is used. Components support a special branch resource that is added in EOL component (NOTE: Branch resource is only valid in an EOL object). The Branch resource contains a property, TargetVIGUID, which contains the VIGUID of a replacement component. Due to this branch resource, when you upgrade your existing configuration and go through dependency check, the new component replaces the EOL component in the configuration. The Branch resource also contains an optional MinRevision property that indicates the minimum revision level of the target component that may be used as a replacement for the current component. Following are special scenarios:&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt; &lt;div class="MsoNormal"&gt;&lt;font color="navy" size="2"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: Arial"&gt;If MinRevision&amp;nbsp;not specified or 0, any revision level may be used. &lt;/span&gt;&lt;/font&gt;&lt;/div&gt; &lt;li&gt; &lt;div class="MsoNormal"&gt;&lt;font color="navy" size="2"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: Arial"&gt;If the EOL component does not specify a Branch resource, then the component is dead, and has no replacement component. &lt;/span&gt;&lt;/font&gt;&lt;/div&gt; &lt;li&gt; &lt;div class="MsoNormal"&gt;&lt;font color="navy" size="2"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: Arial"&gt;If the EOL component specifies multiple Branch resources, then the component is replaced by all the components specified. &lt;/span&gt;&lt;/font&gt;&lt;/div&gt; &lt;li&gt; &lt;div class="MsoNormal"&gt;&lt;font color="navy" size="2"&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: Arial"&gt;If several different EOL components specify Branch resources that all reference the same target component, these components are replaced by single new component.&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=227153" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/harshs/archive/tags/XP+Embedded/default.aspx">XP Embedded</category></item><item><title>Another XPE Blog</title><link>http://blogs.msdn.com/harshs/archive/2004/09/07/226265.aspx</link><pubDate>Tue, 07 Sep 2004 11:32:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:226265</guid><dc:creator>harshs</dc:creator><slash:comments>6</slash:comments><comments>http://blogs.msdn.com/harshs/comments/226265.aspx</comments><wfw:commentRss>http://blogs.msdn.com/harshs/commentrss.aspx?PostID=226265</wfw:commentRss><description>&lt;p&gt;&lt;font color="#000080"&gt;First, a little bit about myself: I joined Microsoft and XP Embedded team about 8 months back. Before coming to Microsoft, I did my Masters in Computer Engineering at University of Southern California and I also worked there as a Systems Analyst for about a year and a half. Even though, I have been in XP Embedded team for a short time, I have worked on several bits and pieces of XPE SP2 and I wanted to share some useful information that I have learned. So, here I am, blogging for the first time, in the hope that someone out there will find this useful.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font color="#000080"&gt;I will&amp;nbsp;use this&amp;nbsp;blog primarily to talk about common XP Embedded issues raised in newsgroups and also to share news&amp;nbsp;on embedded features and cool devices.&amp;nbsp; I am planning to post articles on how to configure some features offline (Windows Firewall, Dr. Watson, Pop-UP blocking etc.) and tweaking registry settings. Also, whenever possible, I am planning to post some scripts and tools that I am working on. I have&amp;nbsp;written scripts to backup, restore and remove XPE database which can be useful as a starting point for anyone who wants to write his/her own custom database scripts. I have also written tools to diff SLDs and SLXs.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font color="#000080"&gt;Stay Tuned......&lt;/font&gt;&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=226265" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/harshs/archive/tags/XP+Embedded/default.aspx">XP Embedded</category></item></channel></rss>