| EG-PO-WIN-ADM-C-Workstation Policies | |
| Data collected on: 2-9-2025 09:05:08 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\ygalal.5 |
| Created | 21-8-2017 12:23:42 |
| Modified | 31-8-2025 09:57:46 |
| User Revisions | 22 (AD), 22 (SYSVOL) |
| Computer Revisions | 1208 (AD), 1208 (SYSVOL) |
| Unique ID | {1658a1d1-e776-44e6-82d4-c0bd3ca45601} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Clients | No | Enabled | emea.tpg.ads/EG/Systems/Clients |
| Name |
|---|
| None |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\EGCAIDGM0SPRG4$ | Custom | No |
| Name | Parameters |
|---|---|
| \\EGCAIFS01\EGCAIDepartments$\IT\Policies\Patches\Bios Boot and PW.bat |
| Policy | Setting |
|---|---|
| Enforce password history | 24 passwords remembered |
| Maximum password age | 60 days |
| Minimum password age | 1 days |
| Minimum password length | 12 characters |
| Password must meet complexity requirements | Enabled |
| Store passwords using reversible encryption | Disabled |
| Policy | Setting |
|---|---|
| Account lockout duration | 30 minutes |
| Account lockout threshold | 6 invalid logon attempts |
| Reset account lockout counter after | 30 minutes |
| Policy | Setting |
|---|---|
| Enforce user logon restrictions | Enabled |
| Maximum lifetime for service ticket | 600 minutes |
| Maximum lifetime for user ticket | 10 hours |
| Maximum lifetime for user ticket renewal | 7 days |
| Maximum tolerance for computer clock synchronization | 5 minutes |
| Policy | Setting |
|---|---|
| Audit account logon events | Success, Failure |
| Audit account management | Success, Failure |
| Audit directory service access | Success, Failure |
| Audit logon events | Success, Failure |
| Audit object access | Success, Failure |
| Audit policy change | Success, Failure |
| Audit privilege use | Success, Failure |
| Audit process tracking | Success, Failure |
| Audit system events | Success, Failure |
| Policy | Setting |
|---|---|
| Access this computer from the network | BUILTIN\Administrators, EMEA\EG-G-ORG-Helpdesk Admins, EMEA\EG-G-ORG-OU Admins |
| Allow log on locally | BUILTIN\Administrators, EMEA\Domain Users, BUILTIN\Users |
| Back up files and directories | BUILTIN\Administrators, EMEA\EG-G-ORG-Helpdesk Admins, EMEA\EG-G-ORG-OU Admins |
| Change the system time | EMEA\EG-G-ORG-OU Admins, EMEA\EG-G-ORG-Helpdesk Admins, BUILTIN\Administrators |
| Change the time zone | EMEA\EG-G-ORG-OU Admins, EMEA\EG-G-ORG-Helpdesk Admins, BUILTIN\Administrators |
| Create global objects | BUILTIN\Administrators, NT AUTHORITY\LOCAL SERVICE, NT AUTHORITY\NETWORK SERVICE, NT AUTHORITY\SERVICE |
| Create permanent shared objects | |
| Debug programs | BUILTIN\Administrators, EMEA\EG-G-ORG-Helpdesk Admins, EMEA\EG-G-ORG-OU Admins |
| Deny access to this computer from the network | TPladmin, TPUser |
| Deny log on as a batch job | TPUser |
| Deny log on as a service | TPUser |
| Deny log on locally | TPUser, EMEA\EG-G-ORG-ServiceAccounts, EMEA\EG-G-ORG-OU Admins |
| Deny log on through Terminal Services | TPUser, TPLadmin, EMEA\EG-G-ORG-ServiceAccounts, EMEA\EG-G-ORG-OU Admins |
| Enable computer and user accounts to be trusted for delegation | |
| Force shutdown from a remote system | BUILTIN\Administrators, EMEA\EG-G-ORG-Helpdesk Admins, EMEA\EG-G-ORG-OU Admins |
| Generate security audits | NT AUTHORITY\LOCAL SERVICE, NT AUTHORITY\NETWORK SERVICE |
| Impersonate a client after authentication | BUILTIN\Administrators, NT AUTHORITY\LOCAL SERVICE, NT AUTHORITY\NETWORK SERVICE, NT AUTHORITY\SERVICE |
| Increase scheduling priority | BUILTIN\Administrators, EMEA\EG-G-ORG-Helpdesk Admins, EMEA\EG-G-ORG-OU Admins |
| Load and unload device drivers | BUILTIN\Administrators, EMEA\EG-G-ORG-Helpdesk Admins, EMEA\EG-G-ORG-OU Admins |
| Lock pages in memory | |
| Log on as a batch job | BUILTIN\Administrators, EMEA\EG-G-ORG-Helpdesk Admins, EMEA\EG-G-ORG-OU Admins |
| Manage auditing and security log | BUILTIN\Administrators, EMEA\EG-G-ORG-Helpdesk Admins, EMEA\EG-G-ORG-OU Admins |
| Modify an object label | |
| Modify firmware environment values | BUILTIN\Administrators, EMEA\EG-G-ORG-Helpdesk Admins, EMEA\EG-G-ORG-OU Admins |
| Perform volume maintenance tasks | BUILTIN\Administrators, EMEA\EG-G-ORG-Helpdesk Admins, EMEA\EG-G-ORG-OU Admins |
| Profile single process | BUILTIN\Administrators, EMEA\EG-G-ORG-Helpdesk Admins, EMEA\EG-G-ORG-OU Admins |
| Profile system performance | BUILTIN\Administrators, EMEA\EG-G-ORG-Helpdesk Admins, EMEA\EG-G-ORG-OU Admins, NT SERVICE\WdiServiceHost |
| Replace a process level token | NT AUTHORITY\LOCAL SERVICE, NT AUTHORITY\NETWORK SERVICE |
| Restore files and directories | BUILTIN\Administrators, EMEA\EG-G-ORG-Helpdesk Admins, EMEA\EG-G-ORG-OU Admins |
| Shut down the system | BUILTIN\Administrators, EMEA\Domain Users, EMEA\EG-G-ORG-Helpdesk Admins, EMEA\EG-G-ORG-OU Admins, BUILTIN\Users |
| Take ownership of files or other objects | BUILTIN\Administrators, EMEA\EG-G-ORG-Helpdesk Admins, EMEA\EG-G-ORG-OU Admins |
| Policy | Setting |
|---|---|
| Accounts: Administrator account status | Enabled |
| Accounts: Guest account status | Disabled |
| Accounts: Limit local account use of blank passwords to console logon only | Enabled |
| Accounts: Rename administrator account | "TPLAdmin" |
| Accounts: Rename guest account | "TPUser" |
| Policy | Setting |
|---|---|
| Audit: Shut down system immediately if unable to log security audits | Disabled |
| Policy | Setting |
|---|---|
| Devices: Allow undock without having to log on | Enabled |
| Devices: Prevent users from installing printer drivers | Enabled |
| Policy | Setting |
|---|---|
| Domain member: Digitally encrypt or sign secure channel data (always) | Disabled |
| Domain member: Digitally encrypt secure channel data (when possible) | Enabled |
| Domain member: Digitally sign secure channel data (when possible) | Enabled |
| Domain member: Disable machine account password changes | Disabled |
| Domain member: Maximum machine account password age | 30 days |
| Domain member: Require strong (Windows 2000 or later) session key | Enabled |
| Policy | Setting |
|---|---|
| Interactive logon: Do not require CTRL+ALT+DEL | Disabled |
| Interactive logon: Don't display last signed-in | Enabled |
| Interactive logon: Message text for users attempting to log on | This computer system (including all hardware, software, and peripheral equipment) is the property of Teleperformance. Use of this computer system is restricted to official Teleperformance business. Teleperformance reserves the right to monitor use of the computer system at any time. Use of this system constitutes consent to such monitoring. Any unauthorized access, use, or modification of the computer system can result in civil liability and/or criminal penalties |
| Interactive logon: Message title for users attempting to log on | "Warning Banner" |
| Interactive logon: Number of previous logons to cache (in case domain controller is not available) | 4 logons |
| Interactive logon: Prompt user to change password before expiration | 5 days |
| Interactive logon: Require Domain Controller authentication to unlock workstation | Enabled |
| Policy | Setting |
|---|---|
| Microsoft network client: Digitally sign communications (always) | Enabled |
| Microsoft network client: Digitally sign communications (if server agrees) | Enabled |
| Microsoft network client: Send unencrypted password to third-party SMB servers | Disabled |
| Policy | Setting |
|---|---|
| Microsoft network server: Amount of idle time required before suspending session | 15 minutes |
| Microsoft network server: Digitally sign communications (always) | Enabled |
| Microsoft network server: Digitally sign communications (if client agrees) | Enabled |
| Policy | Setting |
|---|---|
| Network access: Allow anonymous SID/Name translation | Disabled |
| Network access: Do not allow anonymous enumeration of SAM accounts | Enabled |
| Network access: Do not allow anonymous enumeration of SAM accounts and shares | Disabled |
| Network access: Do not allow storage of passwords and credentials for network authentication | Enabled |
| Network access: Let Everyone permissions apply to anonymous users | Disabled |
| Network access: Named Pipes that can be accessed anonymously | |
| Network access: Restrict anonymous access to Named Pipes and Shares | Enabled |
| Network access: Shares that can be accessed anonymously | |
| Network access: Sharing and security model for local accounts | Classic - local users authenticate as themselves |
| Policy | Setting | ||||
|---|---|---|---|---|---|
| Network security: Do not store LAN Manager hash value on next password change | Enabled | ||||
| Network security: LAN Manager authentication level | Send NTLMv2 response only. Refuse LM & NTLM | ||||
| Network security: LDAP client signing requirements | Require signing | ||||
| Network security: Minimum session security for NTLM SSP based (including secure RPC) clients | Enabled | ||||
| |||||
| Network security: Minimum session security for NTLM SSP based (including secure RPC) servers | Enabled | ||||
| |||||
| Policy | Setting |
|---|---|
| Shutdown: Clear virtual memory pagefile | Enabled |
| Policy | Setting |
|---|---|
| System cryptography: Force strong key protection for user keys stored on the computer | User is prompted when the key is first used |
| Policy | Setting |
|---|---|
| System objects: Require case insensitivity for non-Windows subsystems | Enabled |
| System objects: Strengthen default permissions of internal system objects (e.g. Symbolic Links) | Enabled |
| Policy | Setting |
|---|---|
| User Account Control: Allow UIAccess applications to prompt for elevation without using the secure desktop | Disabled |
| User Account Control: Detect application installations and prompt for elevation | Enabled |
| User Account Control: Only elevate UIAccess applications that are installed in secure locations | Enabled |
| User Account Control: Run all administrators in Admin Approval Mode | Enabled |
| User Account Control: Switch to the secure desktop when prompting for elevation | Enabled |
| User Account Control: Virtualize file and registry write failures to per-user locations | Enabled |
| Policy | Setting | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Accounts: Block Microsoft accounts | Users can't add or log on with Microsoft accounts | ||||||||||||
| Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings | Enabled | ||||||||||||
| Interactive logon: Machine inactivity limit | 300 seconds | ||||||||||||
| Network security: Allow Local System to use computer identity for NTLM | Enabled | ||||||||||||
| Network security: Allow LocalSystem NULL session fallback | Disabled | ||||||||||||
| Network security: Allow PKU2U authentication requests to this computer to use online identities. | Disabled | ||||||||||||
| Network security: Configure encryption types allowed for Kerberos | Enabled | ||||||||||||
| |||||||||||||
| Policy | Setting |
|---|---|
| Prevent local guests group from accessing application log | Enabled |
| Prevent local guests group from accessing security log | Enabled |
| Prevent local guests group from accessing system log | Enabled |
| Retention method for application log | As needed |
| Retention method for security log | As needed |
| Retention method for system log | As needed |
| Type | Name | Access |
|---|---|---|
| Failure | Everyone | Full Control |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Deny | EMEA\EGCAI-G-ORG-Etihad Agent | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | EMEA\Domain Users | Modify | This folder, subfolders and files |
| Allow | BUILTIN\Users | Read and Execute | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Deny | BUILTIN\Users | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Users | Read and Execute | This folder, subfolders and files |
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read and Execute | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | EMEA\EG-L-SEC-Allow StickyNotes | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | EMEA\EG-L-SEC-Allow StickyNotes | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | EMEA\Domain Users | Read and Execute | This folder, subfolders and files |
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Users | Read and Execute | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read and Execute | This folder, subfolders and files |
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | Everyone | Full Control | This folder, subfolders and files |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Users | Read and Execute | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Deny | EMEA\EGCAI-G-ORG-Etihad Supervisor | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Deny | EMEA\Domain Users | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read | This key and subkeys |
| Allow | CREATOR OWNER | Full control | Subkeys only |
| Allow | EMEA\Domain Users | Full control | This key and subkeys |
| Allow | NT AUTHORITY\SYSTEM | Full control | This key and subkeys |
| Allow | BUILTIN\Administrators | Full control | This key and subkeys |
| Allow | BUILTIN\Users | Read | This key and subkeys |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Issued To | Issued By | Expiration Date | Intended Purposes |
|---|---|---|---|
| AAA Certificate Services | AAA Certificate Services | 1-1-2029 00:59:59 | <All> |
| ISRG Root X1 | ISRG Root X1 | 4-6-2035 13:04:38 | <All> |
| Sectigo RSA Domain Validation Secure Server CA | USERTrust RSA Certification Authority | 1-1-2031 00:59:59 | Server Authentication, Client Authentication |
| USERTrust RSA Certification Authority | USERTrust RSA Certification Authority | 19-1-2038 00:59:59 | <All> |
| Policy | Setting |
|---|---|
| Audit Credential Validation | Success, Failure |
| Audit Kerberos Authentication Service | Success, Failure |
| Audit Kerberos Service Ticket Operations | Success, Failure |
| Audit Other Account Logon Events | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Application Group Management | Success, Failure |
| Audit Computer Account Management | Success, Failure |
| Audit Other Account Management Events | Success, Failure |
| Audit Security Group Management | Success, Failure |
| Audit User Account Management | Success, Failure |
| Policy | Setting |
|---|---|
| Audit DPAPI Activity | Success, Failure |
| Audit PNP Activity | Success, Failure |
| Audit Process Creation | Success, Failure |
| Audit Process Termination | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Account Lockout | Success, Failure |
| Audit Logoff | Success |
| Audit Logon | Success, Failure |
| Audit Other Logon/Logoff Events | Success, Failure |
| Audit Special Logon | Success, Failure |
| Policy | Setting |
|---|---|
| Audit File Share | Success, Failure |
| Audit Other Object Access Events | Success, Failure |
| Audit Removable Storage | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Audit Policy Change | Success, Failure |
| Audit Authentication Policy Change | Success, Failure |
| Audit Authorization Policy Change | Success |
| Audit MPSSVC Rule-Level Policy Change | Success |
| Policy | Setting |
|---|---|
| Audit Sensitive Privilege Use | Success, Failure |
| Policy | Setting |
|---|---|
| Audit IPsec Driver | Success, Failure |
| Audit Other System Events | Success, Failure |
| Audit Security State Change | Success, Failure |
| Audit Security System Extension | Success, Failure |
| Audit System Integrity | Success, Failure |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Settings Page Visibility | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Allow user feedback | Disabled | |||||
| Clear Browsing Data on Exit | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Disable synchronization of data with Google | Enabled | |||||
| Enable ending processes in Task Manager | Disabled | |||||
| Enable guest mode in browser | Disabled | |||||
| Enable High Efficiency Mode | Disabled | |||||
| Import bookmarks from default browser on first run | Disabled | |||||
| Restrict which Google accounts are allowed to be set as browser primary accounts in Google Chrome | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Configure extension installation blocklist | Enabled | |||||
| ||||||
| Policy | Setting | Comment |
|---|---|---|
| Enable Google Cast | Disabled | |
| Show the Google Cast toolbar icon | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Enable saving passwords to the password manager | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Control how Chrome Cleanup reports data to Google | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Allow importing of autofill form data | Disabled | |||
| Allow importing of favorites | Disabled | |||
| Allow importing of payment info | Disabled | |||
| Allow importing of saved passwords | Disabled | |||
| Browser sign-in settings | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Clear browsing data when Microsoft Edge closes | Enabled | |||
| Clear cached images and files when Microsoft Edge closes | Enabled | |||
| Configure the Enterprise Mode Site List | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Control where developer tools can be used | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Enable AutoFill for addresses | Disabled | |||
| Enable AutoFill for payment instruments | Disabled | |||
| Enable ending processes in the Browser task manager | Disabled | |||
| Enable guest mode | Disabled | |||
| Enable the Collections feature | Disabled | |||
| Save and fill memberships | Disabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Enable Google Cast | Disabled | |
| Show the cast icon in the toolbar | Disabled |
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Configure allowed extension types | Disabled | |||||
| Control which extensions cannot be installed | Enabled | |||||
| ||||||
| Policy | Setting | Comment |
|---|---|---|
| Enable saving passwords to the password manager | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Prohibit use of Internet Connection Sharing on your DNS domain network | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Prevent use of Offline Files folder | Enabled | |||
| Prohibit user configuration of Offline Files | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Remove "Make Available Offline" command | Enabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Continue experiences on this device | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Always wait for the network at computer startup and logon | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| All Removable Storage classes: Deny all access | Enabled | |
| All Removable Storage: Allow direct access in remote sessions | Disabled | |
| CD and DVD: Deny execute access | Enabled | |
| CD and DVD: Deny read access | Enabled | |
| CD and DVD: Deny write access | Enabled | |
| Floppy Drives: Deny execute access | Enabled | |
| Floppy Drives: Deny read access | Enabled | |
| Floppy Drives: Deny write access | Enabled | |
| Removable Disks: Deny execute access | Enabled | |
| Removable Disks: Deny read access | Enabled | |
| Removable Disks: Deny write access | Enabled | |
| Tape Drives: Deny execute access | Enabled | |
| Tape Drives: Deny read access | Enabled | |
| Tape Drives: Deny write access | Enabled | |
| WPD Devices: Deny read access | Enabled | |
| WPD Devices: Deny write access | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn off Autoplay | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||||
|---|---|---|---|---|---|---|---|---|
| Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later) | Enabled | |||||||
| ||||||||
| Policy | Setting | Comment | ||||||
| Choose drive encryption method and cipher strength (Windows 8, Windows Server 2012, Windows 8.1, Windows Server 2012 R2, Windows 10 [Version 1507]) | Enabled | |||||||
| ||||||||
| Policy | Setting | Comment | ||||||
| Choose drive encryption method and cipher strength (Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2) | Enabled | |||||||
| ||||||||
| Policy | Setting | Comment |
|---|---|---|
| Do not show feedback notifications | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Back up log automatically when full | Enabled | |||
| Control Event Log behavior when the log file reaches its maximum size | Enabled | |||
| Specify the maximum log file size (KB) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Back up log automatically when full | Enabled | |||
| Control Event Log behavior when the log file reaches its maximum size | Enabled | |||
| Specify the maximum log file size (KB) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Back up log automatically when full | Enabled | |||
| Control Event Log behavior when the log file reaches its maximum size | Enabled | |||
| Specify the maximum log file size (KB) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Back up log automatically when full | Enabled | |||
| Control Event Log behavior when the log file reaches its maximum size | Enabled | |||
| Specify the maximum log file size (KB) | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Allow Developer Tools | Disabled | |
| Allow Extensions | Disabled | |
| Allow InPrivate browsing | Disabled | |
| Allow Saving History | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent the usage of OneDrive for file storage | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow users to connect remotely by using Remote Desktop Services | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Remove Windows Security item from Start menu | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Do not sync | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not sync app settings | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not sync Apps | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not sync browser settings | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not sync desktop personalization | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not sync on metered connections | Enabled | |||
| Do not sync other Windows settings | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not sync passwords | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not sync personalize | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not sync start settings | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Allow Windows Ink Workspace | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn on Script Execution | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Hide the Family options area | Enabled |
| Action | Create |
| Source file(s) | \\10.124.101.60\mcafee\Mail\eg.teleperformance.com.xml |
| Destination file | %programfiles%\Mozilla Thunderbird\isp\eg.teleperformance.com.xml |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Source file(s) | \\10.124.101.60\mcafee\Mail\eg.teleperformance.com.xml |
| Destination file | %programfiles(x86)%\Mozilla Thunderbird\isp\eg.teleperformance.com.xml |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Destination file | %USERPROFILE%\appdata\local\Mozilla firefox\firefox.exe |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Destination file | %USERPROFILE%\APPDATA\Local\BraveSoftware\Brave-Browser\Application\brave.exe |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Destination file | C:\Program Files\PowerToys\WinUI3Apps\Microsoft.Xaml.Interactions.dll |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Destination file | C:\Program Files\WindowsApps\Microsoft.WindowsStore_22406.1401.6.0_x64__8wekyb3d8bbwe\WinStore.App.exe |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Destination file | C:\Program Files\WindowsApps\Microsoft.WindowsStore_22406.1401.6.0_x64__8wekyb3d8bbwe\WinStore.App.exe |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Destination file | C:\Program Files\WindowsApps\Microsoft.WindowsStore_11910.1002.5.0_x64__8wekyb3d8bbwe\WinStore.App.exe |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Destination file | C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11029.20108.0_x64__8wekyb3d8bbwe\HxCalendarAppImm.exe |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Destination file | C:\Program Files\WindowsApps\Microsoft.WindowsStore_22407.1401.5.0_x64__8wekyb3d8bbwe |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Destination file | C:\Program Files\WindowsApps\Microsoft.WindowsStore_22408.1401.8.0_x64__8wekyb3d8bbwe \WinStore.App.exe |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Destination file | C:\Program Files\WindowsApps\Microsoft.WindowsStore_22408.1401.9.0_x64__8wekyb3d8bbwe \WinStore.App.exe |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Destination file | C:\Program Files\WindowsApps\Microsoft.WindowsStore_22409.1401.5.0_x64__8wekyb3d8bbwe \WinStore.App.exe |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Destination file | C:\Program Files\WindowsApps\Microsoft.WindowsStore_22410.1401.2.0_x64__8wekyb3d8bbwe \WinStore.App.exe |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Destination file | C:\Program Files\WindowsApps\Microsoft.WindowsStore_22410.1401.4.0_x64__8wekyb3d8bbwe\WinStore.App.exe |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Create |
| Source file(s) | \\emea.tpg.ads\SysVol\emea.tpg.ads\Policies\{6FC12019-14D1-4DB0-B563-D76ECF4DDE1B}\User\Scripts\Logon\tick.ps1 |
| Destination file | C:\tick.ps1 |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Path | C:\Windows\Help |
| Delete this folder (if emptied) | Enabled |
| Recursively delete all subfolders (if emptied) | Disabled |
| Delete all files in the folder(s) | Enabled |
| Allow deletion of read-only files/folders | Disabled |
| Ignore errors for files/folders that cannot be deleted | Disabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Path | C:\Program Files\WindowsApps\Microsoft.ScreenSketch* |
| Delete this folder (if emptied) | Enabled |
| Recursively delete all subfolders (if emptied) | Disabled |
| Delete all files in the folder(s) | Enabled |
| Allow deletion of read-only files/folders | Disabled |
| Ignore errors for files/folders that cannot be deleted | Disabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Path | %USERPROFILE%\Appdata\Loacl\BraveSoftware |
| Delete this folder (if emptied) | Enabled |
| Recursively delete all subfolders (if emptied) | Enabled |
| Delete all files in the folder(s) | Enabled |
| Allow deletion of read-only files/folders | Disabled |
| Ignore errors for files/folders that cannot be deleted | Disabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Path | "C:\Program Files\WindowsApps\Stollenwerk.FastInternetBrowser_2.0.6.0_x64__0p6hs1rbf3jn6 |
| Delete this folder (if emptied) | Enabled |
| Recursively delete all subfolders (if emptied) | Enabled |
| Delete all files in the folder(s) | Enabled |
| Allow deletion of read-only files/folders | Disabled |
| Ignore errors for files/folders that cannot be deleted | Disabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Skype\Phone |
| Value name | DisableFileTransfer |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Skype\Phone |
| Value name | DisableFileTransfer |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum |
| Value name | {F02C1A0D-BE21-4350-88B0-7367FC96EF3C} |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\system_a.exe |
| Value name | Debugger |
| Value type | REG_SZ |
| Value data | "c:\windows\system32\systray.exe" /z |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters |
| Value name | DisableFsquirt |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters |
| Value name | DisableFsquirt |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Keyboard Layout |
| Value name | Scancode Map |
| Value type | REG_BINARY |
| Value data | 00000000000000000400000000002AE0000037E00000540000000000 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | Software\Policies\Microsoft\Edge |
| Value name | EdgeCollectionsEnabled |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Edge\URLBlocklist |
| Value name | 1 |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Edge\URLBlocklist |
| Value name | 2 |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Edge\URLBlocklist |
| Value name | 3 |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Edge\URLBlocklist |
| Value name | 4 |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Edge\URLBlocklist |
| Value name | 5 |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Edge |
| Value name | BrowserSignin |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Edge |
| Value name | WebCaptureEnabled |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Edge |
| Value name | WebCaptureEnabled |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Services\DoSvc |
| Value name | Start |
| Value type | REG_DWORD |
| Value data | 0x4 (4) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Services\DoSvc |
| Value name | Start |
| Value type | REG_DWORD |
| Value data | 0x4 (4) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Edge |
| Value name | HubsSidebarEnabled |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Edge |
| Value name | HubsSidebarEnabled |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer |
| Value name | HubMode |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer |
| Value name | HubMode |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Office\16.0\Lync |
| Value name | EnableSkypeForBusiness |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Office\16.0\Lync |
| Value name | EnableSkypeForBusiness |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.3\Client |
| Value name | Enabled |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.3\Client |
| Value name | Enabled |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Explorer |
| Value name | TaskbarNoPinndList |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Keyboard Layout |
| Value name | Scancode Map |
| Value type | REG_BINARY |
| Value data | 00000000000000000400000000002AE0000037E00000540000000000 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Enforcement | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Designated File Types | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Trusted Publishers | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
| Policy | Setting |
|---|---|
| Default Security Level | Unrestricted |
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% | ||||||
| ||||||
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% | ||||||
|
| Policy | Setting | Comment | ||||||
|---|---|---|---|---|---|---|---|---|
| Allow access to a list of URLs | Enabled | |||||||
| ||||||||
| Policy | Setting | Comment | ||||||
| Block access to a list of URLs | Enabled | |||||||
| ||||||||
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Office\16.0\Lync |
| Value name | EnableSkypeForBusiness |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |