| AL-SEC-WIN-C-Security Settings PCI | |
| Data collected on: 2-9-2025 09:16:34 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\likaj.7 |
| Created | 22-8-2018 12:18:30 |
| Modified | 3-10-2024 16:22:24 |
| User Revisions | 14 (AD), 14 (SYSVOL) |
| Computer Revisions | 461 (AD), 461 (SYSVOL) |
| Unique ID | {1ab2d516-df09-48d5-a395-b3edfad96b41} |
| GPO Status | User settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Clients | No | Enabled | emea.tpg.ads/AL/Systems/Clients |
| Name |
|---|
| EMEA\AL-L-SEC-Security PCI Settings |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\AL-G-ORG-OU Admins | Edit settings, delete, modify security | No |
| EMEA\AL-L-SEC-Security PCI Settings | Read (from Security Filtering) | No |
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\Domain Computers | Read | No |
| EMEA\likaj.7 | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Policy | Setting |
|---|---|
| Audit account logon events | Success, Failure |
| Audit account management | Success, Failure |
| Audit directory service access | Success, Failure |
| Audit logon events | Success, Failure |
| Audit object access | Success, Failure |
| Audit policy change | Success, Failure |
| Audit privilege use | Success, Failure |
| Audit process tracking | Success, Failure |
| Audit system events | Success, Failure |
| Policy | Setting |
|---|---|
| Deny log on locally | EMEA\AL-L-SEC-Delegation Local Administration Rights Tier1, EMEA\AL-G-ORG-Service Accounts, AL-L-SEC-Delegation Local Administration Rights PAA |
| Policy | Setting |
|---|---|
| Accounts: Administrator account status | Enabled |
| Accounts: Guest account status | Disabled |
| Accounts: Rename administrator account | "tpalbadm" |
| Accounts: Rename guest account | "Gaston" |
| Policy | Setting |
|---|---|
| Domain member: Maximum machine account password age | 60 days |
| Policy | Setting |
|---|---|
| Interactive logon: Don't display last signed-in | Enabled |
| Interactive logon: Message text for users attempting to log on | This computer system is the property of Teleperformance., Use of this computer system is restricted to official Teleperformance business., Teleperformance reserves the right to monitor use of the computer system at any time., Use of this system constitutes consent to such monitoring., Any unauthorized access, use, or modification of the computer system can result in civil, liability and/or criminal penalties. |
| Interactive logon: Prompt user to change password before expiration | 14 days |
| Policy | Setting |
|---|---|
| Microsoft network client: Digitally sign communications (if server agrees) | Enabled |
| Microsoft network client: Send unencrypted password to third-party SMB servers | Disabled |
| Policy | Setting |
|---|---|
| Microsoft network server: Digitally sign communications (always) | Enabled |
| Microsoft network server: Digitally sign communications (if client agrees) | Enabled |
| Policy | Setting |
|---|---|
| Network access: Do not allow anonymous enumeration of SAM accounts and shares | Enabled |
| Policy | Setting |
|---|---|
| Network security: Do not store LAN Manager hash value on next password change | Enabled |
| Network security: LAN Manager authentication level | Send NTLMv2 response only. Refuse LM & NTLM |
| Policy | Setting |
|---|---|
| Shutdown: Clear virtual memory pagefile | Enabled |
| Policy | Setting |
|---|---|
| Interactive logon: Machine account lockout threshold | 5 invalid logon attempts |
| Interactive logon: Machine inactivity limit | 300 seconds |
| Policy | Setting |
|---|---|
| Maximum application log size | 3072000 kilobytes |
| Maximum security log size | 4096000 kilobytes |
| Maximum system log size | 3072000 kilobytes |
| Retain application log | 90 days |
| Retain security log | 90 days |
| Retain system log | 90 days |
| Retention method for application log | By days |
| Retention method for security log | By days |
| Retention method for system log | By days |
| Policy Name | New Wireless Network Policy |
| Policy Description | Sample Description |
| Policy Type | Windows Vista and Later Releases |
| Use Windows wireless LAN network services for clients | Enabled |
| Shared user credentials for network authentication | Enabled |
| Hosted networks | Enabled |
| Allow user to view denied networks | Enabled |
| Allow everyone to create all user profiles | Enabled |
| Only use Group Policy profiles for allowed networks | Disabled |
| Prevent connection to infrastructure networks | Disabled |
| Prevent connection to adhoc networks | Disabled |
| Policy | Setting |
|---|---|
| Trusted Publishers can be managed by: | All administrators and users |
| Verify that certificate is not revoked when adding | Disabled |
| Verify that certificate has a valid time stamp when adding | Disabled |
| Enforcement | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Designated File Types | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Trusted Publishers | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
| Policy | Setting |
|---|---|
| Default Security Level | Unrestricted |
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% | ||||||
| ||||||
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% | ||||||
|
| Policy | Setting |
|---|---|
| Policy version | 2.28 |
| Disable stateful FTP | Not Configured |
| Disable stateful PPTP | Not Configured |
| IPsec exempt | Not Configured |
| IPsec through NAT | Not Configured |
| Preshared key encoding | Not Configured |
| SA idle time | Not Configured |
| Strong CRL check | Not Configured |
| Policy | Setting |
|---|---|
| Firewall state | On |
| Inbound connections | Allow |
| Outbound connections | Allow |
| Apply local firewall rules | Not Configured |
| Apply local connection security rules | Not Configured |
| Display notifications | No |
| Allow unicast responses | Yes |
| Log dropped packets | Not Configured |
| Log successful connections | Not Configured |
| Log file path | Not Configured |
| Log file maximum size (KB) | Not Configured |
| Policy | Setting |
|---|---|
| Firewall state | On |
| Inbound connections | Not Configured |
| Outbound connections | Not Configured |
| Apply local firewall rules | Not Configured |
| Apply local connection security rules | Not Configured |
| Display notifications | Not Configured |
| Allow unicast responses | Not Configured |
| Log dropped packets | Not Configured |
| Log successful connections | Not Configured |
| Log file path | Not Configured |
| Log file maximum size (KB) | Not Configured |
| Policy | Setting |
|---|---|
| Firewall state | On |
| Inbound connections | Not Configured |
| Outbound connections | Not Configured |
| Apply local firewall rules | Not Configured |
| Apply local connection security rules | Not Configured |
| Display notifications | Not Configured |
| Allow unicast responses | Not Configured |
| Log dropped packets | Not Configured |
| Log successful connections | Not Configured |
| Log file path | Not Configured |
| Log file maximum size (KB) | Not Configured |
| Name | Description | ||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| IN Domain ANY ANY | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
| IN Domain ANY ANY | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
| Name | Description | ||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| OUT Domain ANY ANY | |||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||
| Policy | Setting |
|---|---|
| Audit Credential Validation | Success, Failure |
| Audit Kerberos Authentication Service | Success, Failure |
| Audit Kerberos Service Ticket Operations | Success, Failure |
| Audit Other Account Logon Events | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Computer Account Management | Success, Failure |
| Audit Security Group Management | Success, Failure |
| Audit User Account Management | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Process Creation | Success, Failure |
| Audit Process Termination | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Directory Service Access | Success, Failure |
| Audit Directory Service Changes | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Account Lockout | Success |
| Audit Logoff | Success |
| Audit Logon | Success, Failure |
| Audit Special Logon | Success, Failure |
| Policy | Setting |
|---|---|
| Audit File Share | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Audit Policy Change | Success, Failure |
| Audit Authentication Policy Change | Success, Failure |
| Policy | Setting |
|---|---|
| Audit IPsec Driver | Success, Failure |
| Audit Security State Change | Success, Failure |
| Audit System Integrity | Success, Failure |
| Policy | Setting | Comment |
|---|---|---|
| Apply the default account picture to all users | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| DNS suffix search list | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| IPv6 Configuration Policy | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Windows Defender Firewall: Allow ICMP exceptions | Enabled | |||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||||||||||||
| Windows Defender Firewall: Allow inbound file and printer sharing exception | Enabled | |||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||||||||||||
| Windows Defender Firewall: Allow inbound remote administration exception | Enabled | |||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||||||||||||
| Windows Defender Firewall: Allow inbound Remote Desktop exceptions | Enabled | |||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||||||||||||
| Windows Defender Firewall: Allow local program exceptions | Enabled | |||||||||||||||||||||||||||||
| Windows Defender Firewall: Prohibit notifications | Enabled | |||||||||||||||||||||||||||||
| Windows Defender Firewall: Prohibit unicast response to multicast or broadcast requests | Disabled | |||||||||||||||||||||||||||||
| Windows Defender Firewall: Protect all network connections | Enabled | |||||||||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Windows Defender Firewall: Allow ICMP exceptions | Enabled | |||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||||||||||||
| Windows Defender Firewall: Allow inbound file and printer sharing exception | Enabled | |||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||||||||||||
| Windows Defender Firewall: Allow inbound remote administration exception | Enabled | |||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||||||||||||
| Windows Defender Firewall: Allow inbound Remote Desktop exceptions | Enabled | |||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||||||||||||
| Windows Defender Firewall: Allow local program exceptions | Enabled | |||||||||||||||||||||||||||||
| Windows Defender Firewall: Prohibit notifications | Enabled | |||||||||||||||||||||||||||||
| Windows Defender Firewall: Prohibit unicast response to multicast or broadcast requests | Disabled | |||||||||||||||||||||||||||||
| Windows Defender Firewall: Protect all network connections | Enabled | |||||||||||||||||||||||||||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Allow or Disallow use of the Offline Files feature | Disabled | |||
| Prevent use of Offline Files folder | Enabled | |||
| Prohibit user configuration of Offline Files | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Remove "Make Available Offline" command | Enabled | |||
| Synchronize all offline files before logging off | Disabled | |||
| Synchronize all offline files when logging on | Disabled | |||
| Synchronize offline files before suspend | Disabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Remove Recommended section from Start Menu | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Configure user Group Policy loopback processing mode | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Always wait for the network at computer startup and logon | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow Clipboard synchronization across devices | Disabled | |
| Allow publishing of User Activities | Disabled | |
| Allow upload of User Activities | Disabled | |
| Enables Activity Feed | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not log users on with temporary profiles | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn off Autoplay | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Do not show feedback notifications | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Restrict unpacking and installation of gadgets that are not digitally signed. | Enabled | |
| Turn off desktop gadgets | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Control Event Log behavior when the log file reaches its maximum size | Disabled |
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Require use of specific security layer for remote (RDP) connections | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Require user authentication for remote connections by using Network Level Authentication | Enabled | |||||
| Set client connection encryption level | Enabled | |||||
| ||||||
| Policy | Setting | Comment |
|---|---|---|
| Do not allow Windows Messenger to be run | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Configure Automatic Updates | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not connect to any Windows Update Internet locations | Enabled |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Session Manager |
| Value name | CWDIllegalInDllSearch |
| Value type | REG_DWORD |
| Value data | 0x2 (2) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters |
| Value name | DisabledComponents |
| Value type | REG_DWORD |
| Value data | 0xFF (255) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Edge |
| Value name | UserFeedbackAllowed |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\.NETFramework\v2.0.50727 |
| Value name | SchUseStrongCrypto |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v2.0.50727 |
| Value name | SchUseStrongCrypto |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| User name | Administrator (built-in) |
| User must change password at next logon | False |
| User cannot change password | False |
| Password never expires | False |
| Account is disabled | False |
| Account expires | 5/18/2019 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | Yes |