| AE-PO-WIN-C-WinWorkstations | |
| Data collected on: 2-9-2025 09:02:16 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\ygalal.5 |
| Created | 9-3-2017 12:16:36 |
| Modified | 5-2-2025 14:59:06 |
| User Revisions | 1 (AD), 1 (SYSVOL) |
| Computer Revisions | 231 (AD), 231 (SYSVOL) |
| Unique ID | {1431936f-eb06-4928-9808-92e1820396df} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| DXB | Yes | Enabled | emea.tpg.ads/AE/Systems/Clients/DXB |
| Name |
|---|
| None |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\AEDXB-G-ORG-AdminComputers | Custom | No |
| Policy | Setting |
|---|---|
| Enforce password history | 24 passwords remembered |
| Maximum password age | 60 days |
| Minimum password age | 1 days |
| Minimum password length | 12 characters |
| Password must meet complexity requirements | Enabled |
| Store passwords using reversible encryption | Disabled |
| Policy | Setting |
|---|---|
| Account lockout duration | 30 minutes |
| Account lockout threshold | 6 invalid logon attempts |
| Reset account lockout counter after | 30 minutes |
| Policy | Setting |
|---|---|
| Enforce user logon restrictions | Enabled |
| Maximum lifetime for service ticket | 600 minutes |
| Maximum lifetime for user ticket | 10 hours |
| Maximum lifetime for user ticket renewal | 7 days |
| Maximum tolerance for computer clock synchronization | 5 minutes |
| Policy | Setting |
|---|---|
| Audit account logon events | Success, Failure |
| Audit account management | Success, Failure |
| Audit directory service access | Success, Failure |
| Audit logon events | Success, Failure |
| Audit object access | Success, Failure |
| Audit policy change | Success, Failure |
| Audit privilege use | Success, Failure |
| Audit process tracking | Success, Failure |
| Audit system events | Success, Failure |
| Policy | Setting |
|---|---|
| Deny log on locally | EMEA\AE-G-ORG-ServiceAccounts |
| Deny log on through Terminal Services | EMEA\AE-G-ORG-ServiceAccounts |
| Policy | Setting |
|---|---|
| Accounts: Administrator account status | Enabled |
| Accounts: Guest account status | Disabled |
| Accounts: Rename guest account | "TP User" |
| Policy | Setting |
|---|---|
| Audit: Shut down system immediately if unable to log security audits | Disabled |
| Policy | Setting |
|---|---|
| Devices: Allow undock without having to log on | Enabled |
| Devices: Prevent users from installing printer drivers | Enabled |
| Policy | Setting |
|---|---|
| Domain member: Digitally encrypt or sign secure channel data (always) | Disabled |
| Domain member: Digitally encrypt secure channel data (when possible) | Enabled |
| Domain member: Digitally sign secure channel data (when possible) | Enabled |
| Domain member: Maximum machine account password age | 30 days |
| Policy | Setting |
|---|---|
| Interactive logon: Do not require CTRL+ALT+DEL | Enabled |
| Interactive logon: Message text for users attempting to log on | This computer system (including all hardware, software, and peripheral equipment) is the property of Teleperformance. Use of this computer system is restricted to official Teleperformance business. Teleperformance reserves the right to monitor use of the computer system at any time. Use of this system constitutes consent to such monitoring. Any unauthorized access, use, or modification of the computer system can result in civil liability and/or criminal penalties |
| Interactive logon: Message title for users attempting to log on | "Warning Banner" |
| Policy | Setting |
|---|---|
| Microsoft network client: Digitally sign communications (always) | Enabled |
| Microsoft network client: Digitally sign communications (if server agrees) | Enabled |
| Microsoft network client: Send unencrypted password to third-party SMB servers | Disabled |
| Policy | Setting |
|---|---|
| Microsoft network server: Amount of idle time required before suspending session | 15 minutes |
| Microsoft network server: Digitally sign communications (always) | Enabled |
| Microsoft network server: Digitally sign communications (if client agrees) | Enabled |
| Policy | Setting | ||||
|---|---|---|---|---|---|
| Network security: Do not store LAN Manager hash value on next password change | Enabled | ||||
| Network security: Force logoff when logon hours expire | Disabled | ||||
| Network security: LAN Manager authentication level | Send NTLMv2 response only. Refuse LM & NTLM | ||||
| Network security: Minimum session security for NTLM SSP based (including secure RPC) clients | Enabled | ||||
| |||||
| Network security: Minimum session security for NTLM SSP based (including secure RPC) servers | Enabled | ||||
| |||||
| Policy | Setting |
|---|---|
| Shutdown: Clear virtual memory pagefile | Enabled |
| Policy | Setting | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Accounts: Block Microsoft accounts | Users can't add or log on with Microsoft accounts | ||||||||||||
| Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings | Disabled | ||||||||||||
| Network security: Allow Local System to use computer identity for NTLM | Enabled | ||||||||||||
| Network security: Allow LocalSystem NULL session fallback | Disabled | ||||||||||||
| Network security: Allow PKU2U authentication requests to this computer to use online identities. | Disabled | ||||||||||||
| Network security: Configure encryption types allowed for Kerberos | Enabled | ||||||||||||
| |||||||||||||
| Policy | Setting |
|---|---|
| Prevent local guests group from accessing application log | Enabled |
| Prevent local guests group from accessing security log | Enabled |
| Prevent local guests group from accessing system log | Enabled |
| Retain application log | 90 days |
| Retain security log | 90 days |
| Retain system log | 90 days |
| Retention method for application log | By days |
| Retention method for security log | By days |
| Retention method for system log | By days |
| Issued To | Issued By | Expiration Date | Intended Purposes |
|---|---|---|---|
| TPDXBVPN.teleperformance.com.eg | TPDXBVPN.teleperformance.com.eg | 30-12-2025 12:25:21 | <All> |
| Issued To | Issued By | Expiration Date | Intended Purposes |
|---|---|---|---|
| TPDXBVPN.teleperformance.com.eg | TPDXBVPN.teleperformance.com.eg | 30-12-2025 12:25:21 | <All> |
| Policy | Setting |
|---|---|
| Audit Security Group Management | Success, Failure |
| Audit User Account Management | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Process Creation | Success, Failure |
| Audit Process Termination | Success |
| Policy | Setting |
|---|---|
| Audit Account Lockout | Success |
| Audit Logoff | Success |
| Audit Logon | Success, Failure |
| Audit Special Logon | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Audit Policy Change | Success, Failure |
| Audit Authentication Policy Change | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Security State Change | Success, Failure |
| Audit System Integrity | Success, Failure |
| Policy | Setting | Comment |
|---|---|---|
| Enable the Collections feature | Disabled |
| Policy | Setting | Comment | ||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Windows Defender Firewall: Define inbound program exceptions | Enabled | |||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Windows Defender Firewall: Define inbound program exceptions | Enabled | |||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| All Removable Storage classes: Deny all access | Enabled | |
| CD and DVD: Deny execute access | Enabled | |
| CD and DVD: Deny read access | Enabled | |
| CD and DVD: Deny write access | Enabled | |
| Removable Disks: Deny execute access | Enabled | |
| Removable Disks: Deny read access | Enabled | |
| Removable Disks: Deny write access | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not show feedback notifications | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Set a default associations configuration file | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Start File Explorer with ribbon minimized | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Allow users to connect remotely by using Remote Desktop Services | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow Cortana | Disabled |
| Action | Delete |
| Destination file | C:\Program Files\WindowsApps\Microsoft.WindowsStore_22406.1401.6.0_x64__8wekyb3d8bbwe\WinStore.App.exe |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Path | C:\Windows\Help |
| Delete this folder (if emptied) | Enabled |
| Recursively delete all subfolders (if emptied) | Disabled |
| Delete all files in the folder(s) | Enabled |
| Allow deletion of read-only files/folders | Disabled |
| Ignore errors for files/folders that cannot be deleted | Disabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Terminal Server |
| Value name | fDenyTSConnections |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Skype\Phone |
| Value name | DisableFileTransfer |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Skype\Phone |
| Value name | DisableFileTransfer |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Edge |
| Value name | HubsSidebarEnabled |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Group name | Administrators (built-in) |
| Delete all member users | Enabled |
| Delete all member groups | Enabled |
| tpladmin | |
| EMEA\EMEA-G-ORG-Local Workstation and Server Admins | S-1-5-21-513466819-3096973226-347852806-321520 |
| EMEA\AE-G-ORG-Help Desk Admins | S-1-5-21-513466819-3096973226-347852806-258365 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |