| BNL-PO-WIN-ADM-U-User Laptop Restrictions and Hardening Restricted | |
| Data collected on: 2-9-2025 10:00:21 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\timmermans.5-adm |
| Created | 9-8-2021 10:16:02 |
| Modified | 1-9-2025 15:36:32 |
| User Revisions | 366 (AD), 366 (SYSVOL) |
| Computer Revisions | 1 (AD), 1 (SYSVOL) |
| Unique ID | {60c02cee-4453-49fd-869f-8ac292872d89} |
| GPO Status | Computer settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| BE | No | Enabled | emea.tpg.ads/BE |
| NL | No | Enabled | emea.tpg.ads/NL |
| SR | No | Enabled | emea.tpg.ads/SR |
| Name |
|---|
| EMEA\BE-L-SEC-Users Laptop Restrictions and Harderning Restricted |
| EMEA\NL-L-SEC-Users Laptop Restrictions and Harderning Restricted |
| EMEA\SR-L-SEC-Users Laptop Restrictions and Harderning Restricted |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\BE-L-SEC-Users Laptop Restrictions and Harderning Restricted | Read (from Security Filtering) | No |
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\NL-L-SEC-Delegation Modify Group Policy Settings Access | Edit settings, delete, modify security | No |
| EMEA\NL-L-SEC-Users Laptop Restrictions and Harderning Restricted | Read (from Security Filtering) | No |
| EMEA\SR-L-SEC-Users Laptop Restrictions and Harderning Restricted | Read (from Security Filtering) | No |
| EMEA\timmermans.5-adm | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Policy | Setting | Comment | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Settings Page Visibility | Enabled | ||||||||||||
| |||||||||||||
| Policy | Setting | Comment | |||||||||||
| Show only specified Control Panel items | Enabled | ||||||||||||
| |||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Force a specific visual style file or force Windows Classic | Enabled | |||||||||||||||||||
| ||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||
| Prevent changing desktop background | Enabled | |||||||||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Point and Print Restrictions | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Hide Regional and Language Options administrative options | Enabled | |
| Restrict Language Pack and Language Feature Installation | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not add shares of recently opened documents to Network Locations | Enabled | |
| Hide and disable all items on the desktop | Enabled | |
| Hide Network Locations icon on desktop | Enabled | |
| Prevent adding, dragging, dropping and closing the Taskbar's toolbars | Enabled | |
| Prohibit User from manually redirecting Profile Folders | Enabled | |
| Remove My Documents icon on the desktop | Enabled | |
| Remove Properties from the Computer icon context menu | Enabled | |
| Remove Properties from the Documents icon context menu | Enabled | |
| Remove Properties from the Recycle Bin context menu | Enabled | |
| Remove the Desktop Cleanup Wizard | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off screen clipping | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Disable Weather Bar | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow shared folders to be published | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Add Logoff to the Start Menu | Enabled | |||
| Do not search communications | Enabled | |||
| Prevent changes to Taskbar and Start Menu Settings | Disabled | |||
| Remove access to the context menus for the taskbar | Enabled | |||
| Remove All Programs list from the Start menu | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Remove Balloon Tips on Start Menu items | Enabled | |||
| Remove common program groups from Start Menu | Disabled | |||
| Remove Default Programs link from the Start menu. | Enabled | |||
| Remove Documents icon from Start Menu | Enabled | |||
| Remove Downloads link from Start Menu | Enabled | |||
| Remove Favorites menu from Start Menu | Enabled | |||
| Remove Games link from Start Menu | Enabled | |||
| Remove Help menu from Start Menu | Enabled | |||
| Remove Homegroup link from Start Menu | Enabled | |||
| Remove links and access to Windows Update | Enabled | |||
| Remove Music icon from Start Menu | Enabled | |||
| Remove Network Connections from Start Menu | Enabled | |||
| Remove Network icon from Start Menu | Enabled | |||
| Remove Pictures icon from Start Menu | Enabled | |||
| Remove pinned programs from the Taskbar | Disabled | |||
| Remove pinned programs list from the Start Menu | Disabled | |||
| Remove Recent Items menu from Start Menu | Enabled | |||
| Remove Recorded TV link from Start Menu | Enabled | |||
| Remove Run menu from Start Menu | Enabled | |||
| Remove Search Computer link | Enabled | |||
| Remove Search link from Start Menu | Enabled | |||
| Remove See More Results / Search Everywhere link | Enabled | |||
| Remove the "Undock PC" button from the Start Menu | Enabled | |||
| Remove the Meet Now icon | Enabled | |||
| Remove the networking icon | Disabled | |||
| Remove the People Bar from the taskbar | Enabled | |||
| Remove the Security and Maintenance icon | Enabled | |||
| Remove user folder link from Start Menu | Enabled | |||
| Remove Videos link from Start Menu | Enabled | |||
| Show "Run as different user" command on Start | Enabled | |||
| Show QuickLaunch on Taskbar | Enabled | |||
| Turn off all balloon notifications | Enabled | |||
| Turn off feature advertisement balloon notifications | Enabled | |||
| Turn off notification area cleanup | Disabled | |||
| Turn off personalized menus | Enabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Turn off toast notifications on the lock screen | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Prevent access to registry editing tools | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Prevent access to the command prompt | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Remove Task Manager | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Windows Update device driver search prompt | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| All Removable Storage classes: Deny all access | Enabled | |
| CD and DVD: Deny read access | Enabled | |
| CD and DVD: Deny write access | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Default risk level for file attachments | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not preserve zone information in file attachments | Enabled | |||
| Inclusion list for low file types | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Do not suggest third-party content in Windows spotlight | Enabled | |
| Do not use diagnostic data for tailored experiences | Enabled | |
| Turn off all Windows spotlight features | Enabled | |
| Turn off the Windows Welcome Experience | Enabled | |
| Turn off Windows Spotlight on Action Center | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Do not allow Folder Options to be opened from the Options button on the View tab of the ribbon | Enabled | |||
| Hide these specified drives in My Computer | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Hides the Manage item on the File Explorer context menu | Enabled | |||
| No Computers Near Me in Network Locations | Enabled | |||
| No Entire Network in Network Locations | Enabled | |||
| Prevent access to drives from My Computer | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Remove "Map Network Drive" and "Disconnect Network Drive" | Enabled | |||
| Remove CD Burning features | Enabled | |||
| Remove DFS tab | Enabled | |||
| Remove Search button from File Explorer | Enabled | |||
| Remove Security tab | Enabled | |||
| Remove Shared Documents from My Computer | Enabled | |||
| Turn off caching of thumbnail pictures | Enabled | |||
| Turn off Windows Key hotkeys | Enabled | |||
| Turn on Classic Shell | Disabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Hide previous versions list for local files | Enabled | |
| Hide previous versions list for remote files | Enabled | |
| Hide previous versions of files on backup location | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Disable changing Automatic Configuration settings | Enabled | |
| Turn off tabbed browsing | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Tools menu: Disable Internet Options... menu option | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Empty Temporary Internet Files folder when browser is closed | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Restrict users to the explicitly permitted list of snap-ins | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Computer Management | Disabled | |
| Local Users and Groups | Disabled | |
| Services | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not allow Windows Messenger to be run | Enabled | |
| Do not automatically start Windows Messenger initially | Enabled |
| Setting | State |
|---|---|
| Software\Policies\Microsoft\WindowsMovieMaker\MovieMaker | 1 |
| Action | Update |
| Path | %userprofile%\AppData\Local\Microsoft\Windows\WinX\Group1 |
| Read-only | Disabled |
| Hidden | Enabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Path | %userprofile%\AppData\Local\Microsoft\Windows\WinX\Group2 |
| Read-only | Disabled |
| Hidden | Enabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Path | %userprofile%\AppData\Local\Microsoft\Windows\WinX\Group3 |
| Read-only | Disabled |
| Hidden | Enabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Path | %userprofile%\AppData\Local\Microsoft\Windows\WinX |
| Read-only | Disabled |
| Hidden | Enabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{031E4825-7B94-4dc3-B131-E946B44C8DD5} |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer |
| Value name | NoRun |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_CURRENT_USER |
| Key path | Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
| Value name | NoRun |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_CURRENT_USER |
| Key path | SOFTWARE\Microsoft\Office\15.0\Outlook\Preferences |
| Value name | DelegateSentItemsStyle |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_CURRENT_USER |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Notifications\Settings |
| Value name | NOC_GLOBAL_SETTING_ALLOW_TOASTS_ABOVE_LOCK |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_CURRENT_USER |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Search |
| Value name | SearchboxTaskbarMode |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced |
| Value name | ShowTaskViewButton |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_CURRENT_USER |
| Key path | Control Panel\Quick Actions\Control Center\Unpinned |
| Value name | Microsoft.QuickAction.ScreenClipping |
| Value type | REG_BINARY |
| Value data |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_CURRENT_USER |
| Key path | Control Panel\Keyboard |
| Value name | PrintScreenKeyForSnippingEnabled |
| Value type | REG_SZ |
| Value data | 0 |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_CURRENT_USER |
| Key path | SOFTWARE\Classes\Extensions\ContractId\Windows.Protocol\PackageId\MicrosoftWindows.Client.CBS_120.2212.4190.0_x64__cw5n1h2txyewy\ActivatableClassId\ScreenClipping.AppX4qm9f5mxaxadptn1dx5ecnnw9b9tddbz.mca |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced |
| Value name | TaskbarDa |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced |
| Value name | TaskbarMn |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Software\Microsoft\Windows\CurrentVersion\Search |
| Value name | SearchboxTaskbarMode |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |