| EG-PO-ADM-C-CIS | |
| Data collected on: 2-9-2025 09:21:18 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\ygalal.5 |
| Created | 12-12-2018 10:48:00 |
| Modified | 31-10-2023 14:32:34 |
| User Revisions | 0 (AD), 0 (SYSVOL) |
| Computer Revisions | 112 (AD), 112 (SYSVOL) |
| Unique ID | {2cf9658b-75a0-443c-8e0a-5389675006d5} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Servers | Yes | Enabled | emea.tpg.ads/EG/Systems/Servers |
| Name |
|---|
| EMEA\EG-L-SEC-Servers Computers policies CIS |
| EMEA\EG-L-SEC-Servers Policies |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\Domain Computers | Read | No |
| EMEA\EG-G-ORG-OU Admins | Edit settings, delete, modify security | No |
| EMEA\EG-L-SEC-Servers Computers policies CIS | Read (from Security Filtering) | No |
| EMEA\EG-L-SEC-Servers Policies | Read (from Security Filtering) | No |
| EMEA\ygalal.5 | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Policy | Setting | Comment |
|---|---|---|
| Turn off multicast name resolution | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Enable Font Providers | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| IPv6 Configuration Policy | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Enable insecure guest logons | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn on Mapper I/O (LLTDIO) driver | Disabled | |
| Turn on Responder (RSPNDR) driver | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Microsoft Peer-to-Peer Networking Services | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prohibit use of Internet Connection Sharing on your DNS domain network | Enabled | |
| Require domain users to elevate when setting a network's location | Enabled |
| Policy | Setting | Comment | ||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Hardened UNC Paths | Enabled | |||||||||||||||||||||
| ||||||||||||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Configuration of wireless settings using Windows Connect Now | Disabled | |
| Prohibit access of the Windows Connect Now wizards | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Minimize the number of simultaneous connections to the Internet or a Windows Domain | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Include command line in process creation events | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Remote host allows delegation of non-exportable credentials | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Boot-Start Driver Initialization Policy | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Configure registry policy processing | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Continue experiences on this device | Disabled | |||||
| Turn off background refresh of Group Policy | Disabled | |||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Support device authentication using certificate | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Disallow copying of user input methods to the system account for sign-in | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not enumerate connected users on domain-joined computers | Enabled | |
| Enumerate local users on domain-joined computers | Enabled | |
| Turn off app notifications on the lock screen | Enabled | |
| Turn off picture password sign-in | Enabled | |
| Turn on convenience PIN sign-in | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Untrusted Font Blocking | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Require a password when a computer wakes (on battery) | Enabled | |
| Require a password when a computer wakes (plugged in) | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Configure Offer Remote Assistance | Disabled | |
| Configure Solicited Remote Assistance | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Microsoft Support Diagnostic Tool: Turn on MSDT interactive communication with support provider | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Enable/Disable PerfTrack | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off the advertising ID | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow a Windows app to share application data between users | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow Microsoft accounts to be optional | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Disallow Autoplay for non-volume devices | Enabled | |||
| Set the default behavior for AutoRun | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn off Autoplay | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Configure enhanced anti-spoofing | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow Use of Camera | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Microsoft consumer experiences | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Require pin for pairing | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Do not display the password reveal button | Enabled | |
| Enumerate administrator accounts on elevation | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Allow Diagnostic Data | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Configure Authenticated Proxy usage for the Connected User Experience and Telemetry service | Enabled | |||
| Policy | Setting | Comment | ||
| Do not show feedback notifications | Enabled | |||
| Toggle user control over Insider builds | Disabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Turn off Data Execution Prevention for Explorer | Disabled | |
| Turn off heap termination on corruption | Disabled | |
| Turn off shell protocol protected mode | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off location | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow Message Service Cloud Sync | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Block all consumer Microsoft account user authentication | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Configure local setting override for reporting to Microsoft MAPS | Disabled | |
| Join Microsoft MAPS | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent the usage of OneDrive for file storage | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent downloading of enclosures | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Allow Cloud Search | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow indexing of encrypted files | Disabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Turn off KMS Client Online AVS Validation | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow suggested apps in Windows Ink Workspace | Disabled | |
| Allow Windows Ink Workspace | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow user control over installs | Disabled | |
| Prevent Internet Explorer security prompt for Windows Installer scripts | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn on PowerShell Script Block Logging | Disabled | |
| Turn on PowerShell Transcription | Disabled |
| Setting | State |
|---|---|
| Software\Policies\Microsoft\Windows\PreviewBuilds\EnableConfigFlighting | 0 |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management |
| Value name | FeatureSettingsOverride |
| Value type | REG_DWORD |
| Value data | 0x48 (72) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |