{"id":1978,"date":"2026-07-18T06:31:39","date_gmt":"2026-07-18T13:31:39","guid":{"rendered":"http:\/\/macdaddy4sure.ai\/?p=1978"},"modified":"2026-07-18T06:31:39","modified_gmt":"2026-07-18T13:31:39","slug":"augmentedintelligence-enterprise-policy","status":"publish","type":"post","link":"http:\/\/macdaddy4sure.ai\/index.php\/2026\/07\/18\/augmentedintelligence-enterprise-policy\/","title":{"rendered":"AugmentedIntelligence Enterprise Policy"},"content":{"rendered":"\n<p>AugmentedIntelligence reads enterprise policy from:<\/p>\n\n\n\n<p><em>[text]<br><\/em>HKLM\\Software\\Policies\\AugmentedIntelligence<br>HKCU\\Software\\Policies\\AugmentedIntelligence<\/p>\n\n\n\n<p>Computer policy is read first. User policy is read second unless DisableUserOverride=1 is set under HKLM.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Group Policy Template<\/h2>\n\n\n\n<p>Copy these files to a domain Central Store or a local policy definitions folder:<\/p>\n\n\n\n<p><em>[text]<br><\/em>enterprise\\admx\\AugmentedIntelligence.admx<br>enterprise\\admx\\en-US\\AugmentedIntelligence.adml<\/p>\n\n\n\n<p>Typical Central Store target:<\/p>\n\n\n\n<p><em>[text]<br><\/em>\\\\&lt;domain&gt;\\SYSVOL\\&lt;domain&gt;\\Policies\\PolicyDefinitions\\AugmentedIntelligence.admx<br>\\\\&lt;domain&gt;\\SYSVOL\\&lt;domain&gt;\\Policies\\PolicyDefinitions\\en-US\\AugmentedIntelligence.adml<\/p>\n\n\n\n<p>Then open Group Policy Management Editor and configure:<\/p>\n\n\n\n<p><em>[text]<br><\/em>Computer Configuration or User Configuration<br>&nbsp; Administrative Templates<br>&nbsp;&nbsp;&nbsp; AugmentedIntelligence<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Policy Values<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Registry value<\/strong><\/td><td><strong>Type<\/strong><\/td><td><strong>Effect<\/strong><\/td><\/tr><tr><td>EnableAugmentedIntelligence<\/td><td>REG_DWORD<\/td><td>0 disables startup and command execution.<\/td><\/tr><tr><td>RequireDomainJoined<\/td><td>REG_DWORD<\/td><td>1 requires an AD domain user context.<\/td><\/tr><tr><td>DisableUserOverride<\/td><td>REG_DWORD<\/td><td>HKLM only. 1 ignores HKCU policy values.<\/td><\/tr><tr><td>RequiredADGroups<\/td><td>REG_SZ or REG_MULTI_SZ<\/td><td>Semicolon-separated AD security groups. User must be in at least one.<\/td><\/tr><tr><td>AllowedCommandCategories<\/td><td>REG_SZ or REG_MULTI_SZ<\/td><td>If populated, only these categories can run.<\/td><\/tr><tr><td>BlockedCommandCategories<\/td><td>REG_SZ or REG_MULTI_SZ<\/td><td>Always deny these categories.<\/td><\/tr><tr><td>LogAllowedCommands<\/td><td>REG_DWORD<\/td><td>1 logs allowed command decisions.<\/td><\/tr><tr><td>LogDeniedCommands<\/td><td>REG_DWORD<\/td><td>1 logs denied command decisions.<\/td><\/tr><tr><td>CentralLogPath<\/td><td>REG_SZ<\/td><td>Full log file path, or directory ending in \\.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>Feature gate values are REG_DWORD where 0 disables the category and 1 enables it:<\/p>\n\n\n\n<p><em>[text]<br><\/em>EnableLLM<br>EnableCloudLLM<br>EnableWindowsAutomation<br>EnableMinecraft<br>EnableROS<br>EnableIRC<br>EnableWordPress<br>EnableOsTicket<br>EnableNetworking<br>EnableRemoteCommands<br>EnableDeveloperTools<br>EnableSettings<br>EnableAutomation<br>EnableGaming<br>EnableDatabase<br>EnableFileEditor<br>EnableSpeech<br>EnablePerception<br>EnableMemory<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Command Categories<\/h2>\n\n\n\n<p>Use these names in AllowedCommandCategories and BlockedCommandCategories:<\/p>\n\n\n\n<p><em>[text]<br><\/em>llm; windows; minecraft; ros; irc; wordpress; osticket; network; remote;<br>developer; settings; automation; gaming; database; file; speech; perception;<br>memory; enterprise; safety; general<\/p>\n\n\n\n<p>Emergency shutdown and ad\/policy status commands remain reachable.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Runtime Commands<\/h2>\n\n\n\n<p><em>[text]<br><\/em>ad status<br>ad identity<br>ad reload<br>ad check DOMAIN\\Group<br>ad authorize minecraft status<br>ad password status<br>ad password connect<br>ad password apply<br>ad password keys<br>policy status<\/p>\n\n\n\n<p>ad authorize &lt;command&gt; shows the inferred category and whether current policy would allow it.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Program password store (Settings)<\/h2>\n\n\n\n<p>All program passwords (MySQL, FTP, computer, Whisper, LLM, SMTP, WordPress, MyBB, Google Speech key)<\/p>\n\n\n\n<p>can be resolved through Active Directory\u2013backed storage instead of plaintext settings.txt.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Resolution order<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Windows Credential Manager<\/strong> target AugmentedIntelligence\/&lt;key><\/li>\n\n\n\n<li><strong>GPO \/ registry<\/strong> under Software\\Policies\\AugmentedIntelligence\\Secrets\\&lt;key>\u00a0<\/li>\n<\/ol>\n\n\n\n<p>&nbsp;&nbsp; (or Secret.&lt;key&gt; on the policy key)<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Environment<\/strong> AI_SECRET_&lt;KEY_UPPER> (e.g. AI_SECRET_MYSQL_PASSWORD)<\/li>\n\n\n\n<li><strong>Local<\/strong> settings.txt \/ in-memory value (if not the @AD placeholder)<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Settings toggles<\/h3>\n\n\n\n<p><em>[text]<br><\/em>ad_password_store_enabled=true<br>ad_password_require_domain=false<br>ad_password_redact_settings_file=true<\/p>\n\n\n\n<p>When redaction is on, settings.txt writes @AD for secrets so plaintext is not on disk.<\/p>\n\n\n\n<p>Settings menus (MySQL \/ FTP \/ Computer \/ Whisper) call _Settings::SetProgramPassword, which<\/p>\n\n\n\n<p>writes Credential Manager and updates the runtime global.<\/p>\n\n\n\n<p>Computer Settings menu: items <strong>14\u201318<\/strong> manage the AD password store.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Backward Compatibility<\/h2>\n\n\n\n<p>The previous local settings still work:<\/p>\n\n\n\n<p><em>[text]<br><\/em>ad_group_requirement_enabled=true<br>required_ad_domain_group=AugmentedIntelligence_Operators<br>required_ad_domain=<\/p>\n\n\n\n<p>GPO values are applied on top of those settings.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>AugmentedIntelligence reads enterprise policy from: [text]HKLM\\Software\\Policies\\AugmentedIntelligenceHKCU\\Software\\Policies\\AugmentedIntelligence Computer policy is read first. User policy is read second unless DisableUserOverride=1 is set under HKLM. Group Policy Template Copy these files to a domain Central Store or a local policy definitions folder: [text]enterprise\\admx\\AugmentedIntelligence.admxenterprise\\admx\\en-US\\AugmentedIntelligence.adml Typical Central Store target: [text]\\\\&lt;domain&gt;\\SYSVOL\\&lt;domain&gt;\\Policies\\PolicyDefinitions\\AugmentedIntelligence.admx\\\\&lt;domain&gt;\\SYSVOL\\&lt;domain&gt;\\Policies\\PolicyDefinitions\\en-US\\AugmentedIntelligence.adml Then open Group Policy Management Editor and configure: [text]Computer Configuration [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1978","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"http:\/\/macdaddy4sure.ai\/index.php\/wp-json\/wp\/v2\/posts\/1978","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/macdaddy4sure.ai\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/macdaddy4sure.ai\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/macdaddy4sure.ai\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/macdaddy4sure.ai\/index.php\/wp-json\/wp\/v2\/comments?post=1978"}],"version-history":[{"count":1,"href":"http:\/\/macdaddy4sure.ai\/index.php\/wp-json\/wp\/v2\/posts\/1978\/revisions"}],"predecessor-version":[{"id":1979,"href":"http:\/\/macdaddy4sure.ai\/index.php\/wp-json\/wp\/v2\/posts\/1978\/revisions\/1979"}],"wp:attachment":[{"href":"http:\/\/macdaddy4sure.ai\/index.php\/wp-json\/wp\/v2\/media?parent=1978"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/macdaddy4sure.ai\/index.php\/wp-json\/wp\/v2\/categories?post=1978"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/macdaddy4sure.ai\/index.php\/wp-json\/wp\/v2\/tags?post=1978"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}