| AL-PO-WIN-U-CTX LOOPBACK User Restrictions and Hardening | |
| Data collected on: 2-9-2025 10:42:35 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\Laboti.6-adm |
| Created | 1-9-2022 09:54:34 |
| Modified | 9-2-2023 15:51:18 |
| User Revisions | 63 (AD), 63 (SYSVOL) |
| Computer Revisions | 2 (AD), 2 (SYSVOL) |
| Unique ID | {9636ba9d-63e1-4b73-9f79-c901649454eb} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Citrix | No | Enabled | emea.tpg.ads/AL/Systems/Citrix |
| Name |
|---|
| NT AUTHORITY\Authenticated Users |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\AL-G-ORG-OU Admins | Edit settings, delete, modify security | No |
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\EMEA-G-ORG-CEMEA VEUC infra Team | Edit settings | No |
| EMEA\Laboti.6-adm | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read (from Security Filtering) | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Enforcement | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Designated File Types | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Trusted Publishers | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
| Policy | Setting |
|---|---|
| Default Security Level | Unrestricted |
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% | ||||||
| ||||||
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% | ||||||
| ||||||
| C:\Windows\System32\schtasks.exe | ||||||
| ||||||
| C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | ||||||
| ||||||
| C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy | ||||||
|
| Group | Path |
|---|---|
| EMEA\NLAMS-L-SEC-Folder Redirection Start Menu ALL | \\emea.tpg.ads\NL\Amsterdam\Settings\FRD |
| Grant user exclusive rights to Start Menu | Disabled |
| Move the contents of Start Menu to the new location | Disabled |
| Also apply redirection policy to Windows 2000, Windows 2000 server, Windows XP, and Windows Server 2003 operating systems | Enabled |
| Policy Removal Behavior | Leave contents |
| Configuration Control | Group Policy |
| Primary Computer Evaluation | Not evaluated because primary computer policy is not enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Settings Page Visibility | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Allow user feedback | Disabled | |||||||||
| Block access to a list of URLs | Enabled | |||||||||
| ||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Disable Developer Tools | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Disable context menus in the Start Menu | Enabled | |
| Do not search programs and Control Panel items | Enabled | |
| Remove Search link from Start Menu | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Prevent access to drives from My Computer | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Computer Management | Disabled | |
| Disk Management | Disabled | |
| Event Viewer | Disabled | |
| Event Viewer (Windows Vista) | Disabled | |
| Services | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Hide Property Pages | Enabled | |
| Prevent Task Run or End | Enabled | |
| Prohibit Browse | Enabled | |
| Prohibit New Task Creation | Enabled | |
| Prohibit Task Deletion | Enabled |
| Action | Delete |
| Hive | HKEY_CURRENT_USER |
| Key path | \Software\Microsoft\Windows\CurrentVersion\Run |
| Value name | com.squirrel.Teams.Teams |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Target type | File system object |
| Shortcut path | %NetPlacesDir%\Amsterdam - Zalando AL Staging |
| Target path | \\emea.tpg.ads\NL\Amsterdam\CEMEA CTX\AL\Zalando\Staging |
| Shortcut key | None |
| Run | Normal window |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | Yes |
| Remove this item when it is no longer applied | Yes |
| Attribute | Value |
|---|---|
| bool | AND |
| not | 0 |
| name | EMEA\NLAMS-L-SEC-Filesystem CemeaCTX AL Zalando Staging RW |
| sid | S-1-5-21-513466819-3096973226-347852806-1103834 |
| userContext | 1 |
| primaryGroup | 0 |
| localGroup | 0 |