Attempting to disable TLS1.0/1.1 on Windows level via GPO

As per title, am attempting to disable TLS1.0/1.1 and default to TLS 1.2 instead.

However my registry do not have the below paths:

../Protocols/TLS 1.0/servers
../Protocols/TLS 1.0/clients
../Protocols/TLS 1.1/servers
../Protocols/TLS 1.1/clients
../Protocols/TLS 1.2/servers
../Protocols/TLS 1.2/clients

This is causing my gpupdates to fail as those paths cannot be found. Most resources I have checked either added the keys to each individual server which is not viable in my environment(have about 300VMs & 80 HyperV hosts) or they would just add the registries to the GPO however, those are existing keys.

Are there any ways to create the required keys via the registry in GPO?


