Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security, Veeam & DevOps

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form

Configure Windows Device Inactivity Limit Locally and Domain Wide

Posted on 26/09/202403/10/2024 Temitope Odemo By Temitope Odemo No Comments on Configure Windows Device Inactivity Limit Locally and Domain Wide
  1. Home
  2. Windows
  3. Configure Windows Device Inactivity Limit Locally and Domain Wide
windows workstations inactivity

In this article i will showing you how to Configure Windows device inactivity limit locally and domain wide. Due to security reasons, it is now important that your computer screen is locked when the system is inactive or idle for some time. Please see How to access shared resources from two different domains, How to demote and remove a Domain Controller on Windows Servers. Read this if you want to Configure Local Administrators Account lockout.

A Windows user can lock a computer screen themselves by using this shortcut key (Win + L). But you can setup your system to auto lock its screen and when your computer is part of a domain system. Please take a look at the YouTube video below for more information.

Play

Then the standard and best approach is to implement a Group Policy that automatically locks the screen of the entire workstations or machines or users on the AD domain.

Configure Windows device inactivity limit locally and domain wide

You can further read about How to add a new Domain Controller to an Existing Domain, and how to Grant Non-Domain Admin Privileges to Manage Workstation,

1. Configure Windows Device Inactivity Limit Locally using Local Security Policy

Run secpol.msc to Open Local Security Policy.

cmd

Expand Local Policies in the left pane and click on Security Options to open the policies on the right pane.

LSP

Scroll down the Policies and click Interactive logon: Machine inactivity limit policy to open its properties.

interactive

Enter a number in the box “Machine will be locked after” for how many seconds of inactivity you can allow before automatically locking your computer. The default is 0 seconds to not automatically lock the computer.

interactive2

Close the Local Security Policy window and restart the computer to apply the configuration.

2. Configure Windows Device Inactivity Limit Locally using Registry Editor

Run regedit.exe to Open Registry Editor and navigate to this registry key location.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
registry

In the right pane double click inactivitytimeoutsecs DWORD to modify it.

inactivity

Inside the Value data box enter the inactivity timeout in seconds and click OK. Close the Registry Editor and restart the computer to apply the configuration.

DWORD

Please see How to configure user resource limits and restrictions in Linux, how to Prevent users from saving RDP Credentials on Windows 11, and “Automatically Log Out After a Period of Inactivity on Mac“.

3. Automatically lock your inactive computers in a domain Using GPO

We shall be using GPO to Configure Windows Device Inactivity Limit Locally and Domain Wide.

Open your Domain Controller and launch the Server Manager. Click on Tools tab and select Group Policy Management. Or you can run gpmc.msc to Open Group Policy Management.

GPM

After opening the Group Policy Management then you can create a new group policy. Right-click Group Policy Objects and click New.

GPO

Enter a name for the new group policy. I will use “TechDirectDeviceInactivity” for our GPO.

new GPO

Right-click on the new Group Policy Object created and select the edit option.

GPM2

On the Group Policy Management Editor screen, expand the Computer Configuration and locate the following.

Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options
securityoption

On the right pane for policy, double-click on Interactive logon: Machine inactivity limit.

GPM Editor

Check the box Define this policy setting and enter the desired amount of inactive time in seconds.

security setting

Click OK and close the Group Policy Management.

Also, see how to Enable Time Limit to Disconnect Remote Desktop After Inactivity, and how to create a Dev Drive on Windows 11.

4. Link an Existing GPO in your domain.

On the Group policy management right-click the domain and select the option to link the newly created Group Policy object.

link GPO

Link the new Group Policy object created to the selected domain and click OK.

select GPO

After configuring and applying the GPO you need to wait some minutes for the GPO to replicate to other domain controllers and workstations.

But if you want the GPO to propagate immediately then you can run “gpupdate /force” on a specific workstation.

I hope you found this blog post on how to Configure Windows Device Inactivity Limit Locally and Domain Wide Interesting and helpful. If you have any questions do not hesitate to ask in the comment section.

5/5 - (1 vote)

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
Windows, Windows Server Tags:GPO, GPOs, group policy, Microsoft Windows, Registry, Windows 10, Windows 11, Windows Server 2016

Post navigation

Previous Post: How to create a Dev Drive on Windows 11
Next Post: How to determine GPO from GUID or Name

Related Posts

  • img 5be0c6cdb96d8
    Is BitLocker Enabled? How to view BitLocker Disk Encryption Status in Windows Windows
  • Featured image widgets
    How to use the Widgets feature on Windows 11 Windows
  • sandbox
    How to Configure Windows Sandbox Virtualization
  • sdfgh 1
    How to fix “Unable to Sign In: Domain Not Available” Windows Server
  • Screenshot 2020 10 31 at 10.35.37
    How to set the PowerShell Execution Policy via Windows Registry Windows Server
  • appp
    How to automatically reopen Windows Apps and Folders upon Startup Windows

More Related Articles

img 5be0c6cdb96d8 Is BitLocker Enabled? How to view BitLocker Disk Encryption Status in Windows Windows
Featured image widgets How to use the Widgets feature on Windows 11 Windows
sandbox How to Configure Windows Sandbox Virtualization
sdfgh 1 How to fix “Unable to Sign In: Domain Not Available” Windows Server
Screenshot 2020 10 31 at 10.35.37 How to set the PowerShell Execution Policy via Windows Registry Windows Server
appp How to automatically reopen Windows Apps and Folders upon Startup Windows

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

Veeam Vanguard

  • Delete Edit or Revert a Snapshot on vSphere
    Manage VMware Snapshots: Delete or Edit or Revert a Snapshot Virtualization
  • loc
    Solve VMware workstation .lck error [Part 1] Virtualization
  • Install Windows Admin Center on Windows Server 2019
    Configure Windows Admin Center on Windows Server 2019 Network | Monitoring
  • Confluence setup
    How to set up Confluence Site and Spaces in Confluence Cloud JIRA|Confluence|Apps
  • defdfd
    The password has expired: Update your password and try again AWS/Azure/OpenShift
  • insufficientaccessright 1
    Azure AD Connect Permission issue: Error 8344 insufficient access rights to perform the operation AWS/Azure/OpenShift
  • wsl5678uh
    Various methods to install Windows Subsystem for Linux Windows
  • How to Upgrade Windows 10 with an Unsupported CPU TPM 1.0 to Windows 11
    Upgrading from Windows 10 with Unsupported CPU and TPM 1.0 Windows

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,796 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

Active Directory Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

Loading Comments...

You must be logged in to post a comment.