Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security, Veeam & DevOps

  • Home
  • About
  • Advertise With US
  • Reviews
  • Tech News
  • Contact
  • Toggle search form

Configure Windows Device Inactivity Limit Locally and Domain Wide

Posted on 26/09/202430/06/2026 Temitope Odemo By Temitope Odemo No Comments on Configure Windows Device Inactivity Limit Locally and Domain Wide
  1. Home
  2. Windows
  3. Configure Windows Device Inactivity Limit Locally and Domain Wide
windows workstations inactivity

In this article i will showing you how to Configure Windows device inactivity limit locally and domain wide. Due to security reasons, it is now important that your computer screen is locked when the system is inactive or idle for some time. Please see How to access shared resources from two different domains, How to demote and remove a Domain Controller on Windows Servers. Read this if you want to Configure Local Administrators Account lockout.

A Windows user can lock a computer screen themselves by using this shortcut key (Win + L). But you can setup your system to auto lock its screen and when your computer is part of a domain system. Please take a look at the YouTube video below for more information.

Play

Then the standard and best approach is to implement a Group Policy that automatically locks the screen of the entire workstations or machines or users on the AD domain.

Configure Windows device inactivity limit locally and domain wide

You can further read about How to add a new Domain Controller to an Existing Domain, and how to Grant Non-Domain Admin Privileges to Manage Workstation,

1. Configure Windows Device Inactivity Limit Locally using Local Security Policy

Run secpol.msc to Open Local Security Policy.

cmd

Expand Local Policies in the left pane and click on Security Options to open the policies on the right pane.

LSP

Scroll down the Policies and click Interactive logon: Machine inactivity limit policy to open its properties.

interactive

Enter a number in the box “Machine will be locked after” for how many seconds of inactivity you can allow before automatically locking your computer. The default is 0 seconds to not automatically lock the computer.

interactive2

Close the Local Security Policy window and restart the computer to apply the configuration.

Please, see How to uninstall and upgrade ADK, WinPE, and MDT, and Various Msiexec.exe Command Line Switches.

2. Configure Windows Device Inactivity Limit Locally using Registry Editor

Run regedit.exe to Open Registry Editor and navigate to this registry key location.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
registry

In the right pane double click inactivitytimeoutsecs DWORD to modify it.

inactivity

Inside the Value data box enter the inactivity timeout in seconds and click OK. Close the Registry Editor and restart the computer to apply the configuration.

DWORD

Please see How to configure user resource limits and restrictions in Linux, how to Prevent users from saving RDP Credentials on Windows 11, and “Automatically Log Out After a Period of Inactivity on Mac“.

3. Automatically lock your inactive computers in a domain Using GPO

We shall be using GPO to Configure Windows Device Inactivity Limit Locally and Domain Wide.

Open your Domain Controller and launch the Server Manager. Click on Tools tab and select Group Policy Management. Or you can run gpmc.msc to Open Group Policy Management.

GPM

After opening the Group Policy Management then you can create a new group policy. Right-click Group Policy Objects and click New.

GPO

Enter a name for the new group policy. I will use “TechDirectDeviceInactivity” for our GPO.

new GPO

Right-click on the new Group Policy Object created and select the edit option.

GPM2

On the Group Policy Management Editor screen, expand the Computer Configuration and locate the following.

Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options
securityoption

On the right pane for policy, double-click on Interactive logon: Machine inactivity limit.

GPM Editor

Check the box Define this policy setting and enter the desired amount of inactive time in seconds.

security setting

Click OK and close the Group Policy Management.

Also, see how to Enable Time Limit to Disconnect Remote Desktop After Inactivity, and how to create a Dev Drive on Windows 11.

4. Link an Existing GPO in your domain.

On the Group policy management right-click the domain and select the option to link the newly created Group Policy object.

link GPO

Link the new Group Policy object created to the selected domain and click OK.

select GPO

After configuring and applying the GPO you need to wait some minutes for the GPO to replicate to other domain controllers and workstations.

But if you want the GPO to propagate immediately then you can run “gpupdate /force” on a specific workstation.

I hope you found this blog post on how to Configure Windows Device Inactivity Limit Locally and Domain Wide Interesting and helpful. If you have any questions do not hesitate to ask in the comment section.

5/5 - (1 vote)

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
Windows, Windows Server Tags:computer idle timeout Active Directory policy, configure screen lock after inactivity Windows, configure user inactivity logoff Windows domain, domain wide idle session timeout Group Policy, enforce workstation lock idle time Windows, GPO, GPOs, group policy, Microsoft Windows, Registry, security inactivity lock Windows Server GPO, set inactivity timeout Windows local policy, Windows 10, Windows 11, Windows device inactivity limit configure, Windows lock screen inactivity policy GPO, Windows power and sleep inactivity settings GPO, Windows Server 2016, Windows session timeout domain policy

Post navigation

Previous Post: How to create a Dev Drive on Windows 11
Next Post: How to determine GPO from GUID or Name

Related Posts

  • FixThunderboltissue
    Fix the Thunderbolt application is not in use and can be safely uninstalled Windows
  • why use bitlocker drive encryption.width 800
    This device cannot use a Trusted Platform Module, allow BitLocker without a compatible TPM when turning on Bitlocker Windows
  • fhgjk
    Replicating MDT Deployment Share: How to Create a Selection Profile and Link MDT Deployment Shares Windows Server
  • fddd
    How to check the version of Windows ADK Windows
  • How to Install Winget on Windows Server
    How to Install Winget on Windows Server Windows Server
  • How to Disable Automatic Opening of Previous files in Notepad on Windows 11
    How to Disable Automatic Opening of Previous Files in Notepad on Windows 11 Windows

More Related Articles

FixThunderboltissue Fix the Thunderbolt application is not in use and can be safely uninstalled Windows
why use bitlocker drive encryption.width 800 This device cannot use a Trusted Platform Module, allow BitLocker without a compatible TPM when turning on Bitlocker Windows
fhgjk Replicating MDT Deployment Share: How to Create a Selection Profile and Link MDT Deployment Shares Windows Server
fddd How to check the version of Windows ADK Windows
How to Install Winget on Windows Server How to Install Winget on Windows Server Windows Server
How to Disable Automatic Opening of Previous files in Notepad on Windows 11 How to Disable Automatic Opening of Previous Files in Notepad on Windows 11 Windows

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

Veeam Vanguard

  • article 1280x720.78eff5c4
    How to reset your built-in Local Administrator password in Windows 10 Windows Server
  • add or remove features on the specified server failed
    Error 0x80073701: The request to add or remove features on the specified server failed Windows Server
  • gfhj
    Debugging: How to debug a PowerShell script Windows
  • ClearTPM
    Clear TPM via Management Console or Windows Defender Center App Windows
  • enable or disable WinRM
    How to enable or disable WinRM via the command-line Windows
  • dotnet6783
    Various methods to Install .NET Framework in Windows Windows
  • image 117
    Deploy MVC Application to AWS EC2 Using RDP and Web Deploy Configuration Management Tool
  • FEATURE IMAGE
    SSH into a VM created using Azure CLI or GUI Linux

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,779 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

Active Directory Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2026 TechDirectArchive

Loading Comments...

You must be logged in to post a comment.