| CZ-PO-WIN-C-Operators Workstations Restriction | |
| Data collected on: 2-9-2025 09:20:58 | |
| Domain | emea.tpg.ads |
| Owner | S-1-5-21-513466819-3096973226-347852806-473619 |
| Created | 3-12-2018 15:06:40 |
| Modified | 13-2-2025 15:43:24 |
| User Revisions | 19 (AD), 19 (SYSVOL) |
| Computer Revisions | 113 (AD), 113 (SYSVOL) |
| Unique ID | {05ee252c-9bb1-4ee5-9257-f37e3b1c2a48} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Production | No | Enabled | emea.tpg.ads/CZ/Systems/Clients/BRQ/Production |
| Production | No | Enabled | emea.tpg.ads/CZ/Systems/Clients/HKR/Production |
| Production | No | Enabled | emea.tpg.ads/CZ/Systems/Clients/HOD/Production |
| Production | Yes | Enabled | emea.tpg.ads/CZ/Systems/Clients/PRB/Production |
| Production | No | Enabled | emea.tpg.ads/CZ/Systems/Clients/PRG/Production |
| Name |
|---|
| NT AUTHORITY\Authenticated Users |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\CZ-G-ORG-OU Admins | Edit settings, delete, modify security | No |
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read (from Security Filtering) | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| S-1-5-21-513466819-3096973226-347852806-473619 | Edit settings, delete, modify security | No |
| Policy | Setting |
|---|---|
| Deny log on locally | EMEA\CZ-G-ORG-ServiceAccounts |
| Deny log on through Terminal Services | EMEA\CZ-G-ORG-ServiceAccounts |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read and Execute | This folder, subfolders and files |
| Allow | NT AUTHORITY\Authenticated Users | Full Control | This folder, subfolders and files |
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Users | Read and Execute | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Enforcement | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Designated File Types | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Trusted Publishers | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
| Policy | Setting |
|---|---|
| Default Security Level | Unrestricted |
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% | ||||||
| ||||||
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% | ||||||
| ||||||
| %programfiles%\WindowsApps\Microsoft.WindowsStore* | ||||||
|
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Settings Page Visibility | Enabled | https://www.windowscentral.com/how-hide-settings-pages-windows-10-creators-update | ||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Allow installation | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Update policy override | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Application Autoupdate | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| All Removable Storage classes: Deny all access | Enabled | |
| Floppy Drives: Deny execute access | Enabled | |
| Floppy Drives: Deny read access | Enabled | |
| Floppy Drives: Deny write access | Enabled | |
| Removable Disks: Deny execute access | Enabled | |
| Removable Disks: Deny read access | Enabled | |
| Removable Disks: Deny write access | Enabled | |
| WPD Devices: Deny read access | Enabled | |
| WPD Devices: Deny write access | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Delete cached copies of roaming profiles | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Set a default associations configuration file | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off downloading of game information | Enabled | |
| Turn off game updates | Enabled |
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Use Policy List of Internet Explorer 7 sites | Enabled | |||||
| ||||||
| Policy | Setting | Comment |
|---|---|---|
| Prevent the usage of OneDrive for file storage | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off background synchronization for feeds and Web Slices | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not allow web search | Enabled | |
| Don't search the web or display web results in Search | Enabled | |
| Don't search the web or display web results in Search over metered connections | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Disable all apps from Microsoft Store | Enabled | |
| Turn off Automatic Download and Install of updates | Enabled | |
| Turn off the Store application | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Disable Windows Error Reporting | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off the communities features | Enabled | |
| Turn off Windows Mail application | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not allow Windows Messenger to be run | Enabled | |
| Do not automatically start Windows Messenger initially | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Windows SideShow | Enabled |
| Action | Update |
| Source file(s) | \\emea.tpg.ads\SysVol\emea.tpg.ads\Policies\{05EE252C-9BB1-4EE5-9257-F37E3B1C2A48}\Machine\Mapa znaku.lnk |
| Destination file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mapa znaku.lnk |
| Suppress errors on individual file actions | Enabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Path | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools |
| Delete this folder (if emptied) | Enabled |
| Recursively delete all subfolders (if emptied) | Disabled |
| Delete all files in the folder(s) | Enabled |
| Allow deletion of read-only files/folders | Disabled |
| Ignore errors for files/folders that cannot be deleted | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Path | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories |
| Delete this folder (if emptied) | Enabled |
| Recursively delete all subfolders (if emptied) | Enabled |
| Delete all files in the folder(s) | Enabled |
| Allow deletion of read-only files/folders | Enabled |
| Ignore errors for files/folders that cannot be deleted | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\OneDrive |
| Value name | DisableFileSyncNGSC |
| Value type | REG_SZ |
| Value data | 1 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Service name | wlansrv |
| Action | Stop service |
| Startup type: | Automatic |
| Wait timeout if service is locked: | 30 seconds |
| Log on service as: | No change |
| First failure: | No change |
| Second failure: | No change |
| Subsequent failures: | No change |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Path | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows PowerShell |
| Delete this folder (if emptied) | Enabled |
| Recursively delete all subfolders (if emptied) | Enabled |
| Delete all files in the folder(s) | Enabled |
| Allow deletion of read-only files/folders | Enabled |
| Ignore errors for files/folders that cannot be deleted | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |