| EMEA-PO-CTX-C-ZTA Settings | |
| Data collected on: 2-9-2025 11:12:24 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\cloots.5-adm |
| Created | 6-4-2023 15:31:58 |
| Modified | 14-4-2023 15:49:58 |
| User Revisions | 0 (AD), 0 (SYSVOL) |
| Computer Revisions | 72 (AD), 72 (SYSVOL) |
| Unique ID | {6da594b1-c1c2-4293-b20e-cb51d5a359a7} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Staging | No | Enabled | emea.tpg.ads/NL/Systems/CitrixBNL/Staging |
| Staging | No | Enabled | emea.tpg.ads/TR/Systems/VDI/Staging |
| Name |
|---|
| NT AUTHORITY\Authenticated Users |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\cloots.5-adm | Edit settings, delete, modify security | No |
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\petralia.9-adm | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read (from Security Filtering) | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Policy | Setting | Comment | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Turn On Virtualization Based Security | Enabled | |||||||||||||
| ||||||||||||||
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\SystemGuard |
| Value name | Enabled |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| #Enable SMM protection |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | System\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity |
| Value name | Enabled |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| #Enable Windows Defender Credential Guard |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | System\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity |
| Value name | WasEnabledBy |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| #Enable Windows Defender Credential Guard |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\DeviceGuard |
| Value name | Locked |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| #Enable virtualization-based protection of code integrity + strict |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity |
| Value name | Enabled |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| #Enable virtualization-based protection of code integrity + strict |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity |
| Value name | Locked |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| #Enable virtualization-based protection of code integrity + strict |