| BNL-PO-WIN-ADM-C-Laptop Restrictions and Hardening Unrestricted | |
| Data collected on: 2-9-2025 10:24:33 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\langras.5-adm |
| Created | 3-5-2022 14:30:48 |
| Modified | 28-7-2025 15:32:24 |
| User Revisions | 11 (AD), 11 (SYSVOL) |
| Computer Revisions | 233 (AD), 233 (SYSVOL) |
| Unique ID | {9f56a343-b8be-44ab-8473-e33986aa6df4} |
| GPO Status | User settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| BE | No | Enabled | emea.tpg.ads/BE |
| Laptops | No | Enabled | emea.tpg.ads/BE/Systems/Clients/Laptops |
| NL | No | Enabled | emea.tpg.ads/NL |
| Laptops | No | Enabled | emea.tpg.ads/NL/Systems/Clients/Laptops |
| SR | No | Enabled | emea.tpg.ads/SR |
| Laptops | No | Enabled | emea.tpg.ads/SR/Systems/Clients/Laptops |
| Name |
|---|
| EMEA\BNL-L-SEC-Laptop Restrictions and Hardening Unrestricted |
| EMEA\SR-L-SEC-Laptop Restrictions and Hardening Unrestricted |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\BNL-L-SEC-Laptop Restrictions and Hardening Unrestricted | Read (from Security Filtering) | No |
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\langras.5-adm | Edit settings, delete, modify security | No |
| EMEA\NL-L-SEC-Delegation Modify Group Policy Settings Access | Edit settings, delete, modify security | No |
| EMEA\SR-L-SEC-Laptop Restrictions and Hardening Unrestricted | Read (from Security Filtering) | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Policy | Setting |
|---|---|
| Audit account logon events | Success, Failure |
| Audit account management | Success, Failure |
| Audit directory service access | Success, Failure |
| Audit logon events | Success, Failure |
| Audit object access | Success, Failure |
| Audit policy change | Success, Failure |
| Audit privilege use | Success, Failure |
| Audit process tracking | Success, Failure |
| Audit system events | Success, Failure |
| Policy | Setting |
|---|---|
| Deny log on locally | EMEA\SR-L-SEC-Service Accounts Restrictions, S-1-5-21-513466819-3096973226-347852806-570527, EMEA\NL-L-SEC-Service Accounts Restrictions, EMEA\NL-L-SEC-Deny Local Logon ADM accounts, EMEA\BE-L-SEC-Service Accounts Restrictions, EMEA\BE-L-SEC-Deny local Logon ADM accounts |
| Deny log on through Terminal Services | S-1-5-21-513466819-3096973226-347852806-570527, EMEA\NL-L-SEC-Deny Local Logon ADM accounts, EMEA\BE-L-SEC-Deny local Logon ADM accounts |
| Policy | Setting |
|---|---|
| Accounts: Guest account status | Disabled |
| Accounts: Rename administrator account | "Apollo" |
| Policy | Setting |
|---|---|
| Devices: Prevent users from installing printer drivers | Disabled |
| Policy | Setting |
|---|---|
| Interactive logon: Don't display last signed-in | Enabled |
| Interactive logon: Message text for users attempting to log on | This computer system (including all hardware, software, and peripheral equipment) is the property of Teleperformance unless you have brought your own device (BYOD). In case of BYOD the work-related software and peripheral equipment is the property of Teleperformance. Use of the computer system and in case of BYOD the work-related software and peripheral equipment is restricted to official Teleperformance business. Teleperformance reserves the right to monitor use of the computer system and in case of BYOD the work-related software and peripheral equipment at any time. Use of the equipment/system constitutes consent to such monitoring. Any unauthorized access use, or modification of the computer system and in case of BYOD the work-related software and peripheral equipment can result in civil liability and/or criminal penalties |
| Interactive logon: Message title for users attempting to log on | "Important notice to Users" |
| Policy | Setting |
|---|---|
| Network security: LAN Manager authentication level | Send NTLMv2 response only. Refuse LM & NTLM |
| Policy | Setting |
|---|---|
| Shutdown: Clear virtual memory pagefile | Enabled |
| Policy | Setting |
|---|---|
| User Account Control: Behavior of the elevation prompt for standard users | Prompt for credentials |
| Policy | Setting |
|---|---|
| Maximum application log size | 3000000 kilobytes |
| Maximum security log size | 3000000 kilobytes |
| Maximum system log size | 3000000 kilobytes |
| Retain security log | 90 days |
| Retention method for application log | As needed |
| Retention method for security log | By days |
| Retention method for system log | As needed |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read and Execute | This folder, subfolders and files |
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | S-1-5-21-513466819-3096973226-347852806-474671 | Full Control | This folder, subfolders and files |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Users | Read and Execute | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Users | Read and Execute | This folder, subfolders and files |
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read and Execute | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read | This key and subkeys |
| Allow | CREATOR OWNER | Full control | Subkeys only |
| Allow | NT AUTHORITY\SYSTEM | Full control | This key and subkeys |
| Allow | BUILTIN\Administrators | Full control | This key and subkeys |
| Allow | BUILTIN\Users | Full control | This key and subkeys |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read | This key and subkeys |
| Allow | CREATOR OWNER | Full control | Subkeys only |
| Allow | NT AUTHORITY\SYSTEM | Full control | This key and subkeys |
| Allow | BUILTIN\Administrators | Full control | This key and subkeys |
| Allow | BUILTIN\Users | Full control | This key and subkeys |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read | This key and subkeys |
| Allow | CREATOR OWNER | Full control | Subkeys only |
| Allow | NT AUTHORITY\SYSTEM | Full control | This key and subkeys |
| Allow | BUILTIN\Administrators | Full control | This key and subkeys |
| Allow | BUILTIN\Users | Full control | This key and subkeys |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read | This key and subkeys |
| Allow | CREATOR OWNER | Full control | Subkeys only |
| Allow | NT AUTHORITY\SYSTEM | Full control | This key and subkeys |
| Allow | BUILTIN\Administrators | Full control | This key and subkeys |
| Allow | BUILTIN\Users | Full control | This key and subkeys |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Policy | Setting |
|---|---|
| Default URL retrieval timeout in seconds | 15 |
| Default path validation cumulative timeout in seconds | 20 |
| Allow issuer certificate retrieval during path validation | Enabled |
| Default cross-certificate download interval in hours | 168 |
| Issued To | Issued By | Expiration Date | Intended Purposes |
|---|---|---|---|
| IISBV Root CA v3 | IISBV Root CA v3 | 9-6-2036 11:13:31 | <All> |
| IKEA Issuing CA V3 | IISBV Root CA v3 | 5-7-2026 15:55:00 | <All> |
| Policy | Setting |
|---|---|
| Policy version | Not Configured |
| Disable stateful FTP | Not Configured |
| Disable stateful PPTP | Not Configured |
| IPsec exempt | Not Configured |
| IPsec through NAT | Not Configured |
| Preshared key encoding | Not Configured |
| SA idle time | Not Configured |
| Strong CRL check | Not Configured |
| Policy | Setting |
|---|---|
| Firewall state | Off |
| Inbound connections | Not Configured |
| Outbound connections | Not Configured |
| Apply local firewall rules | Not Configured |
| Apply local connection security rules | Not Configured |
| Display notifications | No |
| Allow unicast responses | Not Configured |
| Log dropped packets | Not Configured |
| Log successful connections | Not Configured |
| Log file path | Not Configured |
| Log file maximum size (KB) | Not Configured |
| Policy | Setting |
|---|---|
| Audit Other Account Logon Events | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Application Group Management | Success, Failure |
| Audit Computer Account Management | Success, Failure |
| Audit Security Group Management | Success, Failure |
| Audit User Account Management | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Process Creation | Success, Failure |
| Audit Process Termination | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Account Lockout | Success, Failure |
| Audit Logoff | Success, Failure |
| Audit Logon | Success, Failure |
| Audit Special Logon | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Audit Policy Change | Success, Failure |
| Audit Authentication Policy Change | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Security State Change | Success, Failure |
| Audit System Integrity | Success, Failure |
| Policy | Setting | Comment | ||||||
|---|---|---|---|---|---|---|---|---|
| Do not allow password expiration time longer than required by policy | Enabled | |||||||
| Enable local admin password management | Enabled | |||||||
| Password Settings | Enabled | |||||||
| ||||||||
| Policy | Setting | Comment |
|---|---|---|
| Windows Defender Firewall: Prohibit notifications | Enabled | |
| Windows Defender Firewall: Protect all network connections | Disabled |
| Policy | Setting | Comment | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Point and Print Restrictions | Enabled | |||||||||||||||||||
| ||||||||||||||||||||
| Policy | Setting | Comment | ||||||
|---|---|---|---|---|---|---|---|---|
| Configure folder redirection policy processing | Enabled | |||||||
| ||||||||
| Policy | Setting | Comment | ||||||
| Configure Internet Explorer Maintenance policy processing | Enabled | |||||||
| ||||||||
| Policy | Setting | Comment | ||||||
| Continue experiences on this device | Disabled | |||||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off Automatic Root Certificates Update | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Select an active power plan | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Select the lid switch action (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn Off the hard disk (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn Off the hard disk (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off Power Throttling | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Allow network connectivity during connected-standby (on battery) | Enabled | |||
| Allow network connectivity during connected-standby (plugged in) | Enabled | |||
| Specify the system hibernate timeout (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Specify the system hibernate timeout (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Specify the system sleep timeout (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Specify the system sleep timeout (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| Configure Offer Remote Assistance | Enabled | ||||||||||
| |||||||||||
| Policy | Setting | Comment | |||||||||
| Configure Solicited Remote Assistance | Disabled | ||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Removable Disks: Deny execute access | Enabled | |
| Removable Disks: Deny read access | Enabled | |
| Removable Disks: Deny write access | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Add the Administrators security group to roaming user profiles | Enabled | |||
| Delete cached copies of roaming profiles | Enabled | |||
| Delete user profiles older than a specified number of days on system restart | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn off Autoplay | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Don't allow this PC to be projected to | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Control Event Log behavior when the log file reaches its maximum size | Disabled | |||
| Specify the maximum log file size (KB) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Control Event Log behavior when the log file reaches its maximum size | Disabled | |||
| Specify the maximum log file size (KB) | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Enable news and interests on the taskbar | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow users to connect remotely by using Remote Desktop Services | Enabled |
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Require use of specific security layer for remote (RDP) connections | Enabled | PCI Plugin 18405 | ||||
| ||||||
| Policy | Setting | Comment | ||||
| Require user authentication for remote connections by using Network Level Authentication | Enabled | PCI plugin 58453 and 18405 | ||||
| Set client connection encryption level | Enabled | pci plugin 57690 Terminal Service Encryption | ||||
| ||||||
| Policy | Setting | Comment |
|---|---|---|
| Allow Cortana | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow widgets | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Do Not Show First Use Dialog Boxes | Enabled | |
| Prevent Automatic Updates | Enabled | |
| Prevent Media Sharing | Enabled |
| Setting | State |
|---|---|
| Software\Policies\Mozilla\lockPref\network.dns.disableIPv6 | 1 |
| Action | Replace |
| Source file(s) | \\emea.tpg.ads\nl\Amsterdam\Settings\Pushfiles\IEX 7.3\Amsterdam\config.ini |
| Destination file | C:\Program Files\NICE\WFM\7.3\TP-DENLPLAC\wfm\configuration\config.ini |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Action | Update |
| Source file(s) | \\emea.tpg.ads\nl\Amsterdam\Settings\Pushfiles\IE11Mode\IE11_Sitelist.xml |
| Destination file | C:\GPO\IE11Mode\IE11_Sitelist.xml |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Attribute | Value |
|---|---|
| bool | AND |
| not | 1 |
| name | SR-PAR |
| Action | Update |
| Source file(s) | \\emea.tpg.ads\SR\Paramaribo\Settings\Pushfiles\Comp_Rest_Hard_Pol\default.xml |
| Destination file | C:\GPO\DefaultAssoc\default.xml |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Attribute | Value |
|---|---|
| bool | AND |
| not | 0 |
| name | SR-PAR |
| Action | Update |
| Source file(s) | \\emea.tpg.ads\NL\Amsterdam\Settings\Pushfiles\Comp_Rest_Hard_Pol\default.xml |
| Destination file | C:\GPO\DefaultAssoc\default.xml |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Attribute | Value |
|---|---|
| bool | AND |
| not | 0 |
| name | NL-AMS |
| Action | Update |
| Hive | HKEY_USERS |
| Key path | .DEFAULT\Control Panel\Keyboard |
| Value name | InitialKeyboardIndicators |
| Value type | REG_SZ |
| Value data | 2 |
| Stop processing items on this extension if an error occurs on this item | Yes |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Enable num-lock on startup |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\NET Framework Setup\NDP |
| Value name | BlockNetFramework451 |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Edge |
| Value name | UserFeedbackAllowed |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\services\LanmanServer\Parameters |
| Value name | enablesecuritysignature |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| SMB Signing PCI 57608 |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\services\LanmanServer\Parameters |
| Value name | RequireSecuritySignature |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| SMB Signing PCI 57608 |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\services\LanmanWorkstation\Parameters |
| Value name | RequireSecuritySignature |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| SMB Signing PCI 57608 |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\services\LanmanWorkstation\Parameters |
| Value name | EnableSecuritySignature |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| SMB Siging PCI 57608 |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Windows\Sidebar |
| Value name | TurnOffSidebar |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| PCI Plugin 59915 |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon |
| Value name | CachedLogonsCount |
| Value type | REG_SZ |
| Value data | 10 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Plugin ID 11457 |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Lsa |
| Value name | LmCompatibilityLevel |
| Value type | REG_DWORD |
| Value data | 0x3 (3) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon |
| Value name | CachedLogonsCount |
| Value type | REG_SZ |
| Value data | 10 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Plugin ID 11457 |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | System\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 3.0\Server |
| Value name | Enabled |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | System\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 3.0\Client |
| Value name | Enabled |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_PRINT_INFO_DISCLOSURE_FIX |
| Value name | iexeplore.exe |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_PRINT_INFO_DISCLOSURE_FIX |
| Value name | iexplore.exe |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ALLOW_USER32_EXCEPTION_HANDLER_HARDENING |
| Value name | iexplore.exe |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ALLOW_USER32_EXCEPTION_HANDLER_HARDENING |
| Value name | iexplore.exe |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Session Manager |
| Value name | CWDIllegalInDllSearch |
| Value type | REG_DWORD |
| Value data | 0x2 (2) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management |
| Value name | FeatureSettingsOverride |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Nessus Plugin 111689 |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management |
| Value name | FeatureSettingsOverrideMask |
| Value type | REG_DWORD |
| Value data | 0x3 (3) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Nessus Plugin 111689 |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Services\NlaSvc\Parameters\Internet |
| Value name | EnableActiveProbing |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint |
| Value name | RestrictDriverInstallationToAdministrators |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon |
| Value name | AllocateCDRoms |
| Value type | REG_SZ |
| Value data | 1 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer |
| Value name | NoDriveTypeAutoRun |
| Value type | REG_DWORD |
| Value data | 0xFF (255) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\FileSystem |
| Value name | NtfsDisable8dot3NameCreation |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems |
| Value name | Optional |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 3.0\Server |
| Value name | Enabled |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 3.0\Client |
| Value name | Enabled |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CLASSES_ROOT |
| Key path | CLSID\{031E4825-7B94-4dc3-B131-E946B44C8DD5}\ShellFolder |
| Value name | Attributes |
| Value type | REG_DWORD |
| Value data | 0xB09001 (11571201) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CLASSES_ROOT |
| Key path | Wow6432Node\CLSID\{031E4825-7B94-4dc3-B131-E946B44C8DD5}\ShellFolder |
| Value name | Attributes |
| Value type | REG_DWORD |
| Value data | 0xB09001 (11571201) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CLASSES_ROOT |
| Key path | CLSID\{323CA680-C24D-4099-B94D-446DD2D7249E}\ShellFolder |
| Value name | Attributes |
| Value type | REG_DWORD |
| Value data | 0xA94001 (11091969) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CLASSES_ROOT |
| Key path | Wow6432Node\CLSID\{323CA680-C24D-4099-B94D-446DD2D7249E}\ShellFolder |
| Value name | Attributes |
| Value type | REG_DWORD |
| Value data | 0xA94001 (11091969) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows\Windows Feeds |
| Value name | EnableFeeds |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | Software\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.AddNetworkLocation |
| Value name | AttributeValue |
| Value type | REG_DWORD |
| Value data | 0x100000 (1048576) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | Software\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.AddNetworkLocation |
| Value name | ImpliedSelectionModel |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | Software\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.connectNetworkDrive |
| Value name | AttributeValue |
| Value type | REG_DWORD |
| Value data | 0x100000 (1048576) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | Software\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.connectNetworkDrive |
| Value name | ImpliedSelectionModel |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | Software\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.MapNetworkDrive |
| Value name | AttributeValue |
| Value type | REG_DWORD |
| Value data | 0x100000 (1048576) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | Software\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.MapNetworkDrive |
| Value name | ImpliedSelectionModel |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Keyboard Layout |
| Value name | Scancode Map |
| Value type | REG_BINARY |
| Value data | 00000000000000000400000000002AE0000037E00000540000000000 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | Software\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.AddNetworkLocation |
| Value name | AttributeMask |
| Value type | REG_DWORD |
| Value data | 0x100000 (1048576) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | Software\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.AddNetworkLocation |
| Value name | AttributeValue |
| Value type | REG_DWORD |
| Value data | 0x100000 (1048576) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | Software\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.AddNetworkLocation |
| Value name | ImpliedSelectionModel |
| Value type | REG_DWORD |
| Value data | 0x100000 (1048576) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Session Manager\Power |
| Value name | HiberbootEnabled |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows\System |
| Value name | AllowDomainPINLogon |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows\Explorer |
| Value name | HideRecommendedSection |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Session Manager\Power |
| Value name | HiberbootEnabled |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Action | Update |
| User name | Administrator (built-in) |
| User cannot change password | True |
| Password never expires | True |
| Account is disabled | False |
| Account expires | Never |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Group name | Remote Desktop Users (built-in) |
| Delete all member users | Disabled |
| Delete all member groups | Disabled |
| EMEA\NL-L-SEC-Remote Desktop Access Users | S-1-5-21-513466819-3096973226-347852806-433231 |
| EMEA\BE-L-SEC-Remote Desktop Access Users | S-1-5-21-513466819-3096973226-347852806-1105742 |
| EMEA\SR-L-SEC-Remote Desktop Access Users | S-1-5-21-513466819-3096973226-347852806-1331907 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Group name | Administrators (built-in) |
| Delete all member users | Disabled |
| Delete all member groups | Disabled |
| EMEA\NL-L-SEC-Delegation Local Administration Rights Client Systems | S-1-5-21-513466819-3096973226-347852806-2181 |
| EMEA\emeanessus.1 | S-1-5-21-513466819-3096973226-347852806-32532 |
| EMEA\BE-L-SEC-Delegation Local Administration Rights Client Systems | S-1-5-21-513466819-3096973226-347852806-2178 |
| EMEA\SR-L-SEC-Delegation Local Administration Rights Client Systems | S-1-5-21-513466819-3096973226-347852806-160787 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Service name | wmiApSrv |
| Action | Start service |
| Startup type: | Automatic |
| Wait timeout if service is locked: | 30 seconds |
| Log on service as: | No change |
| First failure: | No change |
| Second failure: | No change |
| Subsequent failures: | No change |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Service name | WMPNetworkSvc |
| Action | Stop service |
| Startup type: | Disabled |
| Wait timeout if service is locked: | 30 seconds |
| Log on service as: | No change |
| First failure: | No change |
| Second failure: | No change |
| Subsequent failures: | No change |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |