How Do IT Admins Control Clipboard History With Group Policy?
IT can allow or deny Windows clipboard history and can block cross-device sync. IT cannot, through a supported policy, raise Microsoft’s 25-item cap, change the 4 MB limit, or add files as a history type. Those are product limits, not knobs.
This page maps the official CSPs and GPOs, shows what a user sees, and lists what still sits outside policy.
Do not invent extra values from forum posts. The two policy titles below are the ones Microsoft documents for clipboard history and clipboard sync. Recall uses a different set under Windows Components > Windows AI. Windows Recall vs the Clipboard.
The two policies that matter
Allow Clipboard History
Microsoft Learn, Experience Policy CSP: Experience/AllowClipboardHistory.
| Item | Official value |
|---|---|
| Scope | Device |
| Editions | Pro, Enterprise, Education, IoT Enterprise |
| OS | Windows 10 1809 and later (includes Windows 11) |
| CSP | ./Device/Vendor/MSFT/Policy/Config/Experience/AllowClipboardHistory |
| Values | 0 not allowed, 1 allowed (default 1) |
| GPO | Computer Configuration > Administrative Templates > System > OS Policies > Allow Clipboard History |
| Registry | Software\Policies\Microsoft\Windows\System value AllowClipboardHistory |
| ADMX | OSPolicy.admx |
Learn’s validate steps: set the policy to 0, copy text, press Win+V, no items including the current copy; Settings > System > Clipboard is grayed out with a policy warning. Change takes effect immediately.
If the policy is enabled (allowed), users may still have history off until they turn it on. “Allowed” is not “forced on” in the CSP description. The CSP states: enable = history of clipboard contents is allowed to be stored; disable = not allowed.
There is no official “force history on” twin in that table. If the org wants history used, that is training and a written standard, not a second DWORD.
Allow Clipboard synchronization across devices
Microsoft Learn, Privacy Policy CSP: Privacy/AllowCrossDeviceClipboard.
| Item | Official value |
|---|---|
| Scope | Device |
| OS | Windows 10 1809 and later |
| CSP | ./Device/Vendor/MSFT/Policy/Config/Privacy/AllowCrossDeviceClipboard |
| Values | 0 not allowed, 1 allowed (default 1) |
| Most restrictive | 0 |
| GPO | Computer Configuration > Administrative Templates > System > OS Policies > Allow Clipboard synchronization across devices |
| Registry | Software\Policies\Microsoft\Windows\System value AllowCrossDeviceClipboard |
| ADMX | OSPolicy.admx |
Learn: if enabled, clipboard contents may sync across devices signed in with the same Microsoft account or Microsoft Entra account. If disabled, contents cannot be shared to other devices. Takes effect immediately.
This is the enterprise name for the consumer toggle Clipboard history across your devices.
Default 1 (allowed) surprises teams that assumed Entra join would turn sync off. Set 0 explicitly on regulated fleets.
Intune / Settings Catalog
Both settings appear in Intune Settings Catalog (search Allow Clipboard History and Allow Clipboard synchronization). Assign at the device scope. There is no user-scoped twin in the CSP tables above.
A typical hardened baseline:
| Policy | Value | Intent |
|---|---|---|
| AllowClipboardHistory | Allowed (1) or Not allowed (0) | Product decision: session reuse vs no log |
| AllowCrossDeviceClipboard | Not allowed (0) | Default for regulated fleets |
Many organizations allow local history and deny sync. That matches the consumer recommendation on this site.
Pilot in a ring. Sync-off is low drama. History-off generates same-day help-desk volume from people who used Win+V as a scratch pad.
Confirm on a test device: Settings gray state, gpresult /h for domain GPO, or Intune device status for the Settings Catalog items.
What users see
| Policy state | Settings | Win+V |
|---|---|---|
| History allowed, user Off | Toggle available, Off | Prompt to turn on |
| History allowed, user On | Toggle On | 25-item list |
| History not allowed | Gray, policy warning | No stored items (per Learn validate) |
| Sync not allowed | Devices toggle gray | Local history can still work |
| Sync allowed, user Off | Toggle available, Off | Local only |
School and Work PCs: When Win+V Is Disabled.
Copy and paste still work when history is denied. Only the list goes away. Communicate that, or users will install a Store manager.
What these policies do not do
- They do not encrypt Win+V.
- They do not add an auto-delete timer other than restart wipe of unpinned items.
- They do not stop other processes from reading the live clipboard.
- They do not uninstall Ditto, CopyQ, or Phone Link.
- They do not configure Windows Recall. Use Recall’s own admin controls (Allow Recall to be enabled, Turn off saving snapshots for Recall, and the other Windows AI policies).
- They do not change Snipping Tool capture. A separate Experience policy exists for Snipping Tool screen recorder (
AllowScreenRecorder), which is not clipboard history. - They do not raise 25 items or 4 MB.
- They do not disable Suggested actions by themselves.
Software restriction / WDAC / AppLocker still needed if the goal is “no third-party clipboard monitors.”
Can Other Apps Read Everything You Copy?.
Suggested baselines
Knowledge-worker laptop
- Allow history.
- Deny cross-device clipboard.
- Communicate: no pinning of customer data; clear at end of day.
- Block unmanaged clip apps if the data classification requires it.
Privileged-access workstation
- Deny history.
- Deny sync.
- Password manager autofill only.
- Should You Disable Clipboard History on a Work Laptop?
Shared lab / kiosk
- Deny history.
- Deny sync.
- Fast user switching is not a cleanup strategy; use assigned access or reboot.
Contractor BYOD (when enrolled)
- Deny sync at minimum.
- History: deny if the tenant data is regulated; allow if the alternative is an unmanaged personal manager.
- State the rule in the contractor handbook.
Consumer note
Home PCs do not need gpedit for a safe setup. Settings > System > Clipboard, history as desired, devices Off. Windows 10 Home leftover devices still have the Settings toggles. Support ended October 14, 2025.
Do not paste random registry exports from forums. The official value names are above; inventing extra DWORDs is not a supported way to get 250 items.
Rollout notes
- Pilot AllowCrossDeviceClipboard = 0 first. It is the lower-regret change.
- Communicate before AllowClipboardHistory = 0. Help desk will notice the missing Win+V list the same day.
- Pair history-off with a written alternative: “put scratch text in the ticket, not in a personal manager.”
- Hunt existing Ditto/CopyQ installs. Policy does not remove them.
- Document that Snipping Tool still copies to the live clipboard when history is denied.
- If Copilot+ hardware is in the fleet, review Recall policies in the same change window so the two logs are not left inconsistent.
Intune report: Settings Catalog shows the two Experience/Privacy items. Confirm on a test device with gpresult or by inspecting the Settings gray state.
Inventory query ideas (names only, not a detection-evasion guide): look for Ditto.exe, copyq.exe, ClipboardFusion.exe in installed programs and Run keys. Offer an approved config or a removal package.
Help-desk script
“Open Settings, type Clipboard. If the switches are gray, that is company policy. Copy and paste still work. Win+V will not keep a list. Do not download a clipboard app from the Store to replace it.”
That script prevents the unmanaged-DB problem.
If the user needs reusable text, point them at the approved expander or the ticket template — not at a portable .exe in Downloads.
Adjacent Microsoft features to schedule separately
| Feature | Official control family | Not solved by clipboard CSPs |
|---|---|---|
| Windows Recall | Windows AI policies on Learn’s Manage Recall page | Snapshots of uncopied screen content |
| Phone Link clipboard | App permissions / MDM app control | Phone as a second clipboard |
| Suggested actions | Separate Settings toggle | Reacts to copies |
| RDP clipboard redirection | Remote Desktop host/client settings | Jump-host paste |
| Third-party managers | WDAC / AppLocker / catalog | Longer local logs |
leave Microsoft clipboard sync off is the consumer twin of AllowCrossDeviceClipboard = 0.
Related reading
- Can Other Apps Read Everything You Copy?
- How to Audit Whether a Clipboard App Talks to the Network
- Does Windows Clipboard Sync Upload What You Copy?
- Why You Cannot Drag Old Clipboard Files Into Explorer
Sources
- Experience Policy CSP — AllowClipboardHistory (Microsoft Learn) — CSP, GPO mapping, validate steps.
- Privacy Policy CSP — AllowCrossDeviceClipboard (Microsoft Learn) — sync allow/deny, Entra/Microsoft account wording.
- Using the clipboard (Microsoft Support) — 25 / 4 MB / formats the policies cannot change.
- How to use clipboard history in Windows 11 — consumer labels that map to these policies.
- Manage Recall for Windows clients (Microsoft Learn) — separate Windows AI policy titles; do not reuse clipboard GPO names.
Mohit Sehrawat is a B.Tech Computer Science Engineering student with a focus on software testing, bug detection, and product quality. He is interested in exploring applications, identifying issues, and improving the overall user experience through thorough testing.
GitHub · LinkedInCopy. Stack. Drop.
Transform your clipboard into an interactive edge shelf. Stack, pin, and drag assets into any app with zero friction.
Download for Windows Get from Microsoft Store
How to Install Guide · First 10 Minutes Guide · Drag & Drop Guide · Edge-Drop vs Win+V · Support
Free · Lightweight · Privacy First