| CZ-PO-SEC-C-Default Systems Policy | |
| Data collected on: 2-9-2025 09:20:55 | |
| Domain | emea.tpg.ads |
| Owner | S-1-5-21-513466819-3096973226-347852806-473619 |
| Created | 3-12-2018 11:18:46 |
| Modified | 20-1-2025 09:52:04 |
| User Revisions | 6 (AD), 6 (SYSVOL) |
| Computer Revisions | 277 (AD), 277 (SYSVOL) |
| Unique ID | {e92e23e2-263a-42e9-b10e-3e5e1fef2b3d} |
| GPO Status | User settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Systems | No | Enabled | emea.tpg.ads/CZ/Systems |
| Name |
|---|
| None |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\CZ-L-SEC-GPO Computer No Logon Message | Custom | No |
| Policy | Setting |
|---|---|
| Audit account logon events | Success, Failure |
| Audit account management | Success, Failure |
| Audit directory service access | Success, Failure |
| Audit logon events | Success, Failure |
| Audit object access | Success, Failure |
| Audit policy change | Success, Failure |
| Audit privilege use | Success, Failure |
| Audit process tracking | Success, Failure |
| Audit system events | Success, Failure |
| Policy | Setting |
|---|---|
| Deny log on locally | EMEA\CZ-L-SEC-GPO Deny interactive logon |
| Deny log on through Terminal Services | EMEA\CZ-L-SEC-GPO Deny interactive logon |
| Log on as a batch job | EMEA\CZ-L-SEC-GPO Deny interactive logon, BUILTIN\Administrators |
| Policy | Setting |
|---|---|
| Accounts: Guest account status | Disabled |
| Policy | Setting |
|---|---|
| Audit: Audit the access of global system objects | Disabled |
| Audit: Audit the use of Backup and Restore privilege | Disabled |
| Audit: Shut down system immediately if unable to log security audits | Disabled |
| Policy | Setting |
|---|---|
| Interactive logon: Do not require CTRL+ALT+DEL | Disabled |
| Interactive logon: Don't display last signed-in | Enabled |
| Interactive logon: Message text for users attempting to log on | Tento počítačový systém (včetně veškerého hardware, software a periferních zařízení) je majetkem Teleperformance. Užívání počítačového systému je omezeno výhradně na oficiální záležitosti Teleperformance. Teleperformance si ponechává právo kdykoliv sledovat užívání počítačového systému. Užíváním tohoto počítače se sledováním souhlasíte. Jakýkoliv neoprávněný přístup, užívání či změny počítačového systému můžou vést k občanskoprávní odpovědnosti a/nebo trestním postihům., This computer system (including all hardware, software, and peripheral, equipment) is the property of Teleperformance. Usage of this computer, system is restricted to official Teleperformance business., Teleperformance reserves the right to monitor usage of this computer, system at any time. Usage of this system constitutes consent to such, monitoring. Any unauthorized access, usage, or modification of this, computer system can result in civil liability and/or criminal penalties. |
| Interactive logon: Message title for users attempting to log on | "Upozornění / Warning" |
| Interactive logon: Number of previous logons to cache (in case domain controller is not available) | 50 logons |
| Interactive logon: Prompt user to change password before expiration | 5 days |
| Policy | Setting |
|---|---|
| Retain application log | 90 days |
| Retain security log | 90 days |
| Retain system log | 90 days |
| Retention method for application log | By days |
| Retention method for security log | By days |
| Retention method for system log | By days |
| Enforcement | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Designated File Types | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Trusted Publishers | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
| Policy | Setting |
|---|---|
| Default Security Level | Unrestricted |
| Policy | Setting |
|---|---|
| Policy version | 2.26 |
| Disable stateful FTP | Not Configured |
| Disable stateful PPTP | Not Configured |
| IPsec exempt | Not Configured |
| IPsec through NAT | Not Configured |
| Preshared key encoding | Not Configured |
| SA idle time | Not Configured |
| Strong CRL check | Not Configured |
| Policy | Setting |
|---|---|
| Firewall state | On |
| Inbound connections | Not Configured |
| Outbound connections | Not Configured |
| Apply local firewall rules | Not Configured |
| Apply local connection security rules | Not Configured |
| Display notifications | Not Configured |
| Allow unicast responses | Not Configured |
| Log dropped packets | Not Configured |
| Log successful connections | Not Configured |
| Log file path | Not Configured |
| Log file maximum size (KB) | Not Configured |
| Policy | Setting |
|---|---|
| Firewall state | On |
| Inbound connections | Not Configured |
| Outbound connections | Not Configured |
| Apply local firewall rules | Not Configured |
| Apply local connection security rules | Not Configured |
| Display notifications | Not Configured |
| Allow unicast responses | Not Configured |
| Log dropped packets | Not Configured |
| Log successful connections | Not Configured |
| Log file path | Not Configured |
| Log file maximum size (KB) | Not Configured |
| Name | Description | ||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Remote Desktop - Shadow (TCP-In) | Inbound rule for the Remote Desktop service to allow shadowing of an existing Remote Desktop session. (TCP-In) | ||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
| Remote Desktop - User Mode (UDP-In) | Inbound rule for the Remote Desktop service to allow RDP traffic. [UDP 3389] | ||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
| Remote Desktop - User Mode (TCP-In) | Inbound rule for the Remote Desktop service to allow RDP traffic. [TCP 3389] | ||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
| Allow ICMPv4 | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
| NAGIOS | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
| CATI | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
| CATI CZ | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
| Name | Description | ||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ICMPv4 | |||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||
| Policy | Setting |
|---|---|
| Audit Credential Validation | Success, Failure |
| Audit Kerberos Authentication Service | No Auditing |
| Audit Kerberos Service Ticket Operations | No Auditing |
| Audit Other Account Logon Events | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Application Group Management | Success, Failure |
| Audit Computer Account Management | Success, Failure |
| Audit Distribution Group Management | Success, Failure |
| Audit Other Account Management Events | Success, Failure |
| Audit Security Group Management | Success, Failure |
| Audit User Account Management | Success, Failure |
| Policy | Setting |
|---|---|
| Audit DPAPI Activity | No Auditing |
| Audit PNP Activity | No Auditing |
| Audit Process Creation | Success, Failure |
| Audit Process Termination | Success, Failure |
| Audit RPC Events | No Auditing |
| Audit Token Right Adjusted | No Auditing |
| Policy | Setting |
|---|---|
| Audit Directory Service Access | Success, Failure |
| Audit Directory Service Changes | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Account Lockout | Success, Failure |
| Audit Logoff | Success, Failure |
| Audit Logon | Success, Failure |
| Audit Network Policy Server | Success, Failure |
| Audit Other Logon/Logoff Events | Success, Failure |
| Audit Special Logon | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Detailed File Share | No Auditing |
| Audit File Share | Failure |
| Audit Filtering Platform Connection | Failure |
| Audit Filtering Platform Packet Drop | Failure |
| Audit Removable Storage | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Audit Policy Change | Success, Failure |
| Audit Authentication Policy Change | Success |
| Audit Authorization Policy Change | Success |
| Policy | Setting |
|---|---|
| Audit Sensitive Privilege Use | Success, Failure |
| Policy | Setting |
|---|---|
| Audit IPsec Driver | Success, Failure |
| Audit Other System Events | Success, Failure |
| Audit Security State Change | Success, Failure |
| Audit Security System Extension | Success, Failure |
| Audit System Integrity | Success, Failure |
| Policy | Setting | Comment |
|---|---|---|
| Clear browsing data when Microsoft Edge closes | Disabled | |
| Clear cached images and files when Microsoft Edge closes | Disabled |
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Configure registry policy processing | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Specify startup policy processing wait time | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Specify workplace connectivity wait time for policy processing | Enabled | |||||
| ||||||
| Policy | Setting | Comment |
|---|---|---|
| Restrict Internet communication | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off handwriting personalization data sharing | Enabled | |
| Turn off handwriting recognition error reporting | Enabled | |
| Turn off Internet Connection Wizard if URL connection is referring to Microsoft.com | Enabled | |
| Turn off Internet File Association service | Enabled | |
| Turn off printing over HTTP | Enabled | |
| Turn off Registration if URL connection is referring to Microsoft.com | Enabled | |
| Turn off Search Companion content file updates | Enabled | |
| Turn off the "Order Prints" picture task | Enabled | |
| Turn off the "Publish to Web" task for files and folders | Enabled | |
| Turn off the Windows Messenger Customer Experience Improvement Program | Enabled | |
| Turn off Windows Customer Experience Improvement Program | Enabled | |
| Turn off Windows Error Reporting | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Always wait for the network at computer startup and logon | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Configure Offer Remote Assistance | Disabled | |
| Configure Solicited Remote Assistance | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Delete cached copies of roaming profiles | Enabled | |
| Do not log users on with temporary profiles | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Enable Windows NTP Client | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Disallow Autoplay for non-volume devices | Enabled | |||
| Set the default behavior for AutoRun | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn off Autoplay | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Do not display the password reveal button | Enabled |
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Use Policy List of Internet Explorer 7 sites | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn off encryption support | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Join Microsoft MAPS | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent the usage of OneDrive for file storage | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Disable Windows Error Reporting | Enabled |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 3.0\Server |
| Value name | Enabled |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 2.0\Server |
| Value name | Enabled |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_USERS |
| Key path | .DEFAULT\Control Panel\Keyboard |
| Value name | InitialKeyboardIndicators |
| Value type | REG_SZ |
| Value data | 2 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\system_a.exe |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\system_a.exe |
| Value name | (Default) |
| Value type | REG_SZ |
| Value data |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\system_a.exe |
| Value name | Debugger |
| Value type | REG_SZ |
| Value data | "c:\windows\system32\systray.exe" /z |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |