We are preparing a refresh of our desktops using Windows 8.1. One of the security requirements is to have Bluetooth disabled by default and only enable on a case by case basis. There are lots of reasons for this which I wont go into here.
I have scoured the interwebs for efficient ways to do this, but have come up short. I could disable at the hardware layer, but would like to have the flexibility to re-enable through Group Policy. I have found a solution, but it is a bit messy;
I am using Group Policy Preferences to disable the Bluetooth related services by default (and will have an override one for those computers that are allowed). This works, except that in Windows 8.1 there is the option under PC Settings/PC and devices/Bluetooth which has the slidy bar to turn on. This is still here, but it just sits there and says it is searching for and can be discovered by Bluetooth devices. Furthermore any devices previously paired (I had paired my mobile phone as a test) is still listed, and I cannot unpair it (I assume because the BT services has been disabled).
I had a scout around to see if there is a registry setting that changes when the slidy bar is changed, but came up short.
Or am I over complicating this? Is there a simpler way to do this?