Group Policy Management
body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } }
Setting Path:
Explanation
No explanation is available for this setting.
Supported On:
Not available
EGCAI-PO-ADM-U-Nahdi Policies
Data collected on: 2-9-2025 09:36:02
General
Details
Domainemea.tpg.ads
OwnerS-1-5-21-513466819-3096973226-347852806-503948
Created1-1-2020 21:39:26
Modified7-6-2023 15:31:50
User Revisions24 (AD), 24 (SYSVOL)
Computer Revisions73 (AD), 73 (SYSVOL)
Unique ID{a3994b67-9cd4-42d3-93f6-73cec3807fd2}
GPO StatusEnabled
Links
LocationEnforcedLink StatusPath
ClientsNoEnabledemea.tpg.ads/EG/Systems/Clients

This list only includes links in the domain of the GPO.
Security Filtering
The settings in this GPO can only apply to the following groups, users, and computers:
Name
EMEA\EGCAI-G-ORG-Client Systems Nahdi
Delegation
These groups and users have the specified permission for this GPO
NameAllowed PermissionsInherited
EMEA\Domain AdminsEdit settings, delete, modify securityNo
EMEA\Domain ComputersReadNo
EMEA\EGCAI-G-ORG-Client Systems NahdiRead (from Security Filtering)No
EMEA\EG-G-ORG-OU AdminsEdit settings, delete, modify securityNo
NT AUTHORITY\Authenticated UsersReadNo
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSReadNo
NT AUTHORITY\SYSTEMEdit settings, delete, modify securityNo
ROOT\Enterprise AdminsEdit settings, delete, modify securityNo
S-1-5-21-513466819-3096973226-347852806-503948Edit settings, delete, modify securityNo
Computer Configuration (Enabled)
Policies
Windows Settings
Security Settings
Registry
MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
Configure this key then: Replace existing permissions on all subkeys with inheritable permissions
Owner
Permissions
TypeNamePermissionApply To
AllowAPPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGESReadThis key and subkeys
AllowCREATOR OWNERFull controlSubkeys only
AllowNT AUTHORITY\SYSTEMFull controlThis key and subkeys
AllowBUILTIN\AdministratorsFull controlThis key and subkeys
AllowBUILTIN\UsersFull controlThis key and subkeys
Allow inheritable permissions from the parent to propagate to this object and all child objectsDisabled
Auditing
No auditing specified
Administrative Templates
Policy definitions (ADMX files) retrieved from the central store.
System/Logon
PolicySettingComment
Run these programs at user logonEnabled
Items to run at logon
\\EGCAIFS01.emea.tpg.ads\EGAGZClients$\Nahdi\Setting\DesktopApps\Al Nahdi Updates Announcer\Al Nahdi Updates Announcer.exe
\\EGCAIFS01.emea.tpg.ads\EGAGZClients$\Nahdi\Setting\DesktopApps\EM-activex\WebLauncher.exe
\\EGCAIFS01\EGAGZClients$\Settings\DesktopApps\SentimentSurvey\SentimentSurvey.exe
Windows Components/Internet Explorer/Internet Control Panel/Security Page
PolicySettingComment
Site to Zone Assignment ListEnabled
Enter the zone assignments here. 
http://prjed-aphist01.nmc.com2
http://prjed-hisbip01.nmc.com2
https://aphis.nahdi.sa2
https://aphist.nahdi.sa2
Preferences
Windows Settings
Files
File (Target Path: %uSERPROFILE%\AppData\LocalLow\Sun\Java\Deployment\security\exception.sites)
exception.sites (Order: 1)
General
ActionCreate
Properties
Source file(s)\\emea.tpg.ads\sysvol\emea.tpg.ads\Policies\{3E37B931-7978-40C4-BCB9-8EA5BE51E9D6}\Machine\Nahdi\exception.sites
Destination file%uSERPROFILE%\AppData\LocalLow\Sun\Java\Deployment\security\exception.sites
Attributes
Read-onlyDisabled
HiddenDisabled
ArchiveEnabled
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Registry
EnableJavaUpdate (Order: 1)
General
ActionUpdate
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSOFTWARE\WOW6432Node\JavaSoft\Java Update\Policy
Value nameEnableJavaUpdate
Value typeREG_DWORD
Value data0x1 (1)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
User Configuration (Enabled)
Preferences
Control Panel Settings
Internet Settings
Internet Explorer 10: Internet Explorer 10 (Order: 1)
General
Startup
Startup optionsStart with tabs from the last session
Browsing history
Delete browsing history on exitNo
Security
Security levels
InternetCustom
Internet
Loose XAMLDisabled
XAML browser applicationsDisabled
XPS documentsEnabled
Permissions for components with manifestsHigh Safety
Run components not signed with Authenticode Enabled
Run components signed with Authenticode Enabled
Allow ActiveX FilteringEnabled
Allow previously unused ActiveX controls to run without promptDisabled
Allow ScriptletsDisabled
Automatic prompting for ActiveX controls Disabled
Binary and script behaviorsEnabled
Display video and animation on a webpage that does not use external media playerDisabled
Download signed ActiveX controls Enabled
Download unsigned ActiveX controls Enabled
Initialize and script ActiveX controls not marked as safe for ScriptingDisabled
Only allow approved domains to use ActiveX without promptDisabled
Run ActiveX controls and plug-insEnabled
Script ActiveX controls marked safe for scripting Enabled
File download Enabled
Font download Enabled
Enable .NET Framework setupEnabled
Access data sources across domains Disabled
Render legacy filtersDisabled
Allow dragging of content between domains into separate windowsDisabled
Allow dragging of content between domains into the same windowDisabled
Allow METAREFRESH Enabled
Allow scripting of Internet Explorer web browser controlDisabled
Allow script-initiated windows without size or position constraints Disabled
Allow webpages to use restricted protocols for active content Prompt
Allow websites to open windows without address or status barsDisabled
Display mixed content Prompt
Do not prompt for client certificate selection when no certificates or only one certificate exists. Disabled
Drag and drop or copy and paste files Enabled
Enable MIME SniffingEnabled
Include local directory path when uploading files to serverDisabled
Launching applications and unsafe filesPrompt
Launching programs and files in an IFRAME Prompt
Navigate sub-frames across different domains Disabled
Submit nonencrypted form data Enabled
Use Phishing FilterEnabled
Use Pop-up Blocker Enabled
Userdata persistence Enabled
Websites in less privileged web content zone can navigate into this zoneEnabled
Active scripting Enabled
Allow Programmatic clipboard accessPrompt
Allow Status bar updates via scriptDisabled
Allow websites to prompt for information using scripted windowsDisabled
Enable XSS filterEnabled
Scripting of java applets Enabled
User AuthenticationAutomatic logon only in Intranet zone
Enable Protected ModeEnabled
Connections
Dial-up settings
Connection behaviorNever dial a connection
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Apply once and do not reapplyNo