| DE-PO-WIN-C-Computer Settings VDI | |
| Data collected on: 2-9-2025 09:10:53 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\Domain Admins |
| Created | 6-2-2018 11:46:36 |
| Modified | 9-2-2023 14:46:54 |
| User Revisions | 1 (AD), 1 (SYSVOL) |
| Computer Revisions | 78 (AD), 78 (SYSVOL) |
| Unique ID | {710c5c94-706f-42a2-ab03-f39eb738fefe} |
| GPO Status | User settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| VDI | No | Enabled | emea.tpg.ads/DE/Systems/Clients/VDI |
| Name |
|---|
| S-1-5-21-513466819-3096973226-347852806-572620 |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\DE-L-SEC-Delegation Modify Group Policy Settings Access | Edit settings, delete, modify security | No |
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\Domain Computers | Read | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| S-1-5-21-513466819-3096973226-347852806-572620 | Read (from Security Filtering) | No |
| Policy | Setting |
|---|---|
| Audit account logon events | Success, Failure |
| Audit account management | Success, Failure |
| Audit directory service access | Success, Failure |
| Audit object access | Success, Failure |
| Audit policy change | Success, Failure |
| Audit system events | Success, Failure |
| Policy | Setting |
|---|---|
| Allow log on through Terminal Services | EMEA\Domain Admins, EMEA\DE-L-SEC-Delegation Remote Desktop Access |
| Deny log on locally | EMEA\DE-L-SEC-Local logon denied on Client Systems |
| Policy | Setting |
|---|---|
| Accounts: Guest account status | Disabled |
| Accounts: Rename administrator account | "adonis" |
| Accounts: Rename guest account | "gaston" |
| Policy | Setting |
|---|---|
| Microsoft network client: Digitally sign communications (always) | Enabled |
| Microsoft network client: Digitally sign communications (if server agrees) | Enabled |
| Policy | Setting |
|---|---|
| Microsoft network server: Digitally sign communications (always) | Enabled |
| Microsoft network server: Digitally sign communications (if client agrees) | Enabled |
| Policy | Setting |
|---|---|
| Network security: Do not store LAN Manager hash value on next password change | Enabled |
| Network security: Force logoff when logon hours expire | Enabled |
| Network security: LAN Manager authentication level | Send NTLMv2 response only. Refuse LM & NTLM |
| Policy | Setting |
|---|---|
| Maximum application log size | 3072000 kilobytes |
| Maximum security log size | 3072000 kilobytes |
| Maximum system log size | 3072000 kilobytes |
| Type | Name | Permission |
|---|---|---|
| Allow | BUILTIN\Administrators | Full Control |
| Allow | NT AUTHORITY\SYSTEM | Full Control |
| Allow | NT AUTHORITY\INTERACTIVE | Read |
| Type | Name | Access |
|---|---|---|
| Failure | Everyone | Full Control |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read and Execute | This folder, subfolders and files |
| Allow | NT AUTHORITY\Authenticated Users | Full Control | This folder, subfolders and files |
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Users | Read and Execute | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read and Execute | This folder, subfolders and files |
| Allow | NT AUTHORITY\Authenticated Users | Full Control | This folder, subfolders and files |
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Users | Read and Execute | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Policy | Setting |
|---|---|
| Trusted Publishers can be managed by: | All administrators and users |
| Verify that certificate is not revoked when adding | Disabled |
| Verify that certificate has a valid time stamp when adding | Disabled |
| Enforcement | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Designated File Types | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Trusted Publishers | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
| Policy | Setting |
|---|---|
| Default Security Level | Unrestricted |
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% | ||||||
| ||||||
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% | ||||||
| ||||||
| C:\Program Files\MSN Gaming Zone\ | ||||||
|
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Allow or Disallow use of the Offline Files feature | Disabled | |||
| Prevent use of Offline Files folder | Enabled | |||
| Prohibit user configuration of Offline Files | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Remove "Make Available Offline" command | Enabled | |||
| Synchronize all offline files before logging off | Disabled | |||
| Synchronize all offline files when logging on | Disabled | |||
| Synchronize offline files before suspend | Disabled | |||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Configure clipboard redirection | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn off Autoplay | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Require use of specific security layer for remote (RDP) connections | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Require user authentication for remote connections by using Network Level Authentication | Enabled | |||||
| Set client connection encryption level | Enabled | |||||
| ||||||
| Policy | Setting | Comment |
|---|---|---|
| Remove access to use all Windows Update features | Enabled |
| Setting | State |
|---|---|
| Software\Policies\Microsoft\Windows\WindowsUpdate\ManagePreviewBuilds | 1 |
| Software\Policies\Microsoft\Windows\WindowsUpdate\ManagePreviewBuildsPolicyValue | 0 |
| Software\Policies\Mozilla\lockPref\security.enable_ssl3 | 0 |
| Software\Policies\Mozilla\lockPref\security.enable_tls | 1 |
| Action | Replace |
| Source file(s) | \\emea.tpg.ads\SYSVOL\emea.tpg.ads\Policies\{710C5C94-706F-42A2-AB03-F39EB738FEFE}\Framework v2\security.config |
| Destination file | C:\windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Source file(s) | \\emea.tpg.ads\SYSVOL\emea.tpg.ads\Policies\{710C5C94-706F-42A2-AB03-F39EB738FEFE}\FrameWork V4\security.config |
| Destination file | C:\windows\Microsoft.NET\Framework\v4.0.30319\Config\security.config |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Source file(s) | \\emea.tpg.ads\SYSVOL\emea.tpg.ads\Policies\{710C5C94-706F-42A2-AB03-F39EB738FEFE}\Framework x64 V2\security.config |
| Destination file | C:\windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\security.config |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Source file(s) | \\emea.tpg.ads\SYSVOL\emea.tpg.ads\Policies\{710C5C94-706F-42A2-AB03-F39EB738FEFE}\Framework x64 V4\security.config |
| Destination file | C:\windows\Microsoft.NET\Framework64\v4.0.30319\Config\security.config |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Source file(s) | \\emea.tpg.ads\SYSVOL\emea.tpg.ads\Policies\{710C5C94-706F-42A2-AB03-F39EB738FEFE}\Framework v2\security.config.cch |
| Destination file | C:\windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Source file(s) | \\emea.tpg.ads\SYSVOL\emea.tpg.ads\Policies\{710C5C94-706F-42A2-AB03-F39EB738FEFE}\FrameWork V4\security.config.cch |
| Destination file | C:\windows\Microsoft.NET\Framework\v4.0.30319\Config\security.config.cch |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Source file(s) | \\emea.tpg.ads\SYSVOL\emea.tpg.ads\Policies\{710C5C94-706F-42A2-AB03-F39EB738FEFE}\Framework x64 V2\security.config.cch |
| Destination file | C:\windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\security.config.cch |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Source file(s) | \\emea.tpg.ads\SYSVOL\emea.tpg.ads\Policies\{710C5C94-706F-42A2-AB03-F39EB738FEFE}\Framework x64 V4\security.config.cch |
| Destination file | C:\windows\Microsoft.NET\Framework64\v4.0.30319\Config\security.config.cch |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.1\Client |
| Value name | DisabledByDefault |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Attribute | Value |
|---|---|
| bool | AND |
| not | 0 |
| class | NT |
| version | WIN7 |
| type | NE |
| edition | NE |
| sp | NE |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client |
| Value name | DisabledByDefault |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Attribute | Value |
|---|---|
| bool | AND |
| not | 0 |
| class | NT |
| version | WIN7 |
| type | NE |
| edition | NE |
| sp | NE |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.1\Server |
| Value name | DisabledByDefault |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Attribute | Value |
|---|---|
| bool | AND |
| not | 0 |
| class | NT |
| version | WIN7 |
| type | NE |
| edition | NE |
| sp | NE |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server |
| Value name | DisabledByDefault |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Attribute | Value |
|---|---|
| bool | AND |
| not | 0 |
| class | NT |
| version | WIN7 |
| type | NE |
| edition | NE |
| sp | NE |
| Action | Replace |
| Hive | HKEY_USERS |
| Key path | .DEFAULT\Control Panel\Keyboard |
| Value name | InitialKeyboardIndicators |
| Value type | REG_SZ |
| Value data | 2 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Action | Replace |
| Hive | HKEY_CURRENT_USER (HKU\.DEFAULT) |
| Key path | Control Panel\Keyboard |
| Value name | InitialKeyboardIndicators |
| Value type | REG_SZ |
| Value data | 2 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\.NETFramework |
| Value name | EnableIEHosting |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Wow6432Node\Microsoft\.NETFramework |
| Value name | EnableIEHosting |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | Software\Policies\Microsoft\Windows\WindowsUpdate\AU |
| Value name | NoAutoUpdate |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |