| AL-PO-SEC-C-Server Hardening | |
| Data collected on: 2-9-2025 09:14:54 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\lala.8 |
| Created | 5-7-2018 12:51:42 |
| Modified | 17-12-2024 15:43:00 |
| User Revisions | 2 (AD), 2 (SYSVOL) |
| Computer Revisions | 170 (AD), 170 (SYSVOL) |
| Unique ID | {c42d5e3b-b508-40c7-ab84-89a4b7365c31} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Servers | Yes | Enabled | emea.tpg.ads/AL/Systems/Servers |
| Name |
|---|
| EMEA\AL-G-ORG-Servers |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\AL-G-ORG-OU Admins | Edit settings, delete, modify security | No |
| EMEA\AL-G-ORG-Servers | Read (from Security Filtering) | No |
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\Domain Computers | Read | No |
| EMEA\lala.8 | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Policy | Setting |
|---|---|
| Audit account logon events | Success, Failure |
| Audit account management | Success, Failure |
| Audit directory service access | Success, Failure |
| Audit logon events | Success, Failure |
| Audit object access | Success, Failure |
| Audit policy change | Success, Failure |
| Audit privilege use | Success, Failure |
| Audit process tracking | Success, Failure |
| Audit system events | Success, Failure |
| Policy | Setting |
|---|---|
| Access this computer from the network | NT AUTHORITY\Authenticated Users, BUILTIN\Administrators |
| Adjust memory quotas for a process | NT AUTHORITY\NETWORK SERVICE, NT AUTHORITY\LOCAL SERVICE, BUILTIN\Administrators |
| Allow log on locally | BUILTIN\Backup Operators, BUILTIN\Administrators |
| Allow log on through Terminal Services | BUILTIN\Administrators |
| Change the system time | NT AUTHORITY\LOCAL SERVICE, BUILTIN\Administrators |
| Create a pagefile | BUILTIN\Administrators |
| Deny access to this computer from the network | BUILTIN\Guests, NT AUTHORITY\ANONYMOUS LOGON |
| Deny log on locally | EMEA\alrobot.8 |
| Deny log on through Terminal Services | EMEA\alrobot.8 |
| Force shutdown from a remote system | BUILTIN\Administrators |
| Generate security audits | NT AUTHORITY\NETWORK SERVICE, NT AUTHORITY\LOCAL SERVICE |
| Increase scheduling priority | BUILTIN\Administrators |
| Load and unload device drivers | BUILTIN\Administrators |
| Lock pages in memory | |
| Manage auditing and security log | BUILTIN\Administrators |
| Modify firmware environment values | BUILTIN\Administrators |
| Perform volume maintenance tasks | BUILTIN\Administrators |
| Profile single process | BUILTIN\Administrators |
| Profile system performance | BUILTIN\Administrators |
| Remove computer from docking station | BUILTIN\Administrators |
| Restore files and directories | BUILTIN\Backup Operators, BUILTIN\Administrators |
| Shut down the system | BUILTIN\Administrators |
| Take ownership of files or other objects | BUILTIN\Administrators |
| Policy | Setting |
|---|---|
| Accounts: Guest account status | Disabled |
| Accounts: Limit local account use of blank passwords to console logon only | Enabled |
| Accounts: Rename administrator account | "tpalbadm" |
| Accounts: Rename guest account | "gaston" |
| Policy | Setting |
|---|---|
| Devices: Allowed to format and eject removable media | Administrators |
| Devices: Prevent users from installing printer drivers | Enabled |
| Policy | Setting |
|---|---|
| Domain controller: LDAP server signing requirements | Require signing |
| Policy | Setting |
|---|---|
| Domain member: Digitally encrypt or sign secure channel data (always) | Enabled |
| Domain member: Digitally encrypt secure channel data (when possible) | Enabled |
| Domain member: Disable machine account password changes | Disabled |
| Domain member: Require strong (Windows 2000 or later) session key | Enabled |
| Policy | Setting |
|---|---|
| Interactive logon: Do not require CTRL+ALT+DEL | Disabled |
| Interactive logon: Don't display last signed-in | Enabled |
| Interactive logon: Message text for users attempting to log on | This computer system is the property of Teleperformance., Use of this computer system is restricted to official Teleperformance business., Teleperformance reserves the right to monitor use of the computer system at any time., Use of this system constitutes consent to such monitoring., Any unauthorized access, use, or modification of the computer system can result in civil, liability and/or criminal penalties. |
| Interactive logon: Message title for users attempting to log on | "WARNING: IF YOU ARE NOT AUTHORIZED TO LOGON TO THIS PC, DON'T TRY TO LOGON!" |
| Interactive logon: Number of previous logons to cache (in case domain controller is not available) | 0 logons |
| Interactive logon: Require Domain Controller authentication to unlock workstation | Enabled |
| Policy | Setting |
|---|---|
| Microsoft network client: Digitally sign communications (always) | Enabled |
| Microsoft network client: Digitally sign communications (if server agrees) | Enabled |
| Policy | Setting |
|---|---|
| Microsoft network server: Digitally sign communications (always) | Enabled |
| Microsoft network server: Digitally sign communications (if client agrees) | Enabled |
| Policy | Setting |
|---|---|
| Network access: Allow anonymous SID/Name translation | Disabled |
| Network access: Do not allow anonymous enumeration of SAM accounts | Enabled |
| Network access: Do not allow anonymous enumeration of SAM accounts and shares | Enabled |
| Network access: Do not allow storage of passwords and credentials for network authentication | Enabled |
| Network access: Let Everyone permissions apply to anonymous users | Disabled |
| Policy | Setting | ||||
|---|---|---|---|---|---|
| Network security: Do not store LAN Manager hash value on next password change | Enabled | ||||
| Network security: LAN Manager authentication level | Send NTLMv2 response only. Refuse LM & NTLM | ||||
| Network security: LDAP client signing requirements | Require signing | ||||
| Network security: Minimum session security for NTLM SSP based (including secure RPC) servers | Enabled | ||||
| |||||
| Policy | Setting |
|---|---|
| System cryptography: Force strong key protection for user keys stored on the computer | User is prompted when the key is first used |
| Policy | Setting |
|---|---|
| Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off multicast name resolution | Enabled |
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Require use of specific security layer for remote (RDP) connections | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Server authentication certificate template | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Set time limit for active but idle Remote Desktop Services sessions | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn on Script Execution | Enabled | |||
| ||||
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\system_a.exe |
| Value name | Debbuger |
| Value type | REG_SZ |
| Value data | "c:\windows\system32\systray.exe" /z |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\system_a.exe |
| Value name | Debbuger |
| Value type | REG_SZ |
| Value data | "c:\windows\system32\systray.exe" /z |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |