Group Policy Management
body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } }
Setting Path:
Explanation
No explanation is available for this setting.
Supported On:
Not available
EMEALSILVAGPO_ONTESTING
Data collected on: 2-9-2025 09:22:41
General
Details
Domainemea.tpg.ads
OwnerS-1-5-21-513466819-3096973226-347852806-567654
Created30-1-2019 18:48:24
Modified9-2-2023 14:48:20
User Revisions23 (AD), 23 (SYSVOL)
Computer Revisions44 (AD), 44 (SYSVOL)
Unique ID{380c2f41-7a8d-4a5a-86ea-3534372cbfd8}
GPO StatusEnabled
Links
LocationEnforcedLink StatusPath
None

This list only includes links in the domain of the GPO.
Security Filtering
The settings in this GPO can only apply to the following groups, users, and computers:
Name
S-1-5-21-513466819-3096973226-347852806-542174
Delegation
These groups and users have the specified permission for this GPO
NameAllowed PermissionsInherited
EMEA\Domain AdminsEdit settings, delete, modify securityNo
NT AUTHORITY\Authenticated UsersReadNo
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSReadNo
NT AUTHORITY\SYSTEMEdit settings, delete, modify securityNo
ROOT\Enterprise AdminsEdit settings, delete, modify securityNo
S-1-5-21-513466819-3096973226-347852806-542174Read (from Security Filtering)No
S-1-5-21-513466819-3096973226-347852806-567654Edit settings, delete, modify securityNo
Computer Configuration (Enabled)
Policies
Windows Settings
Security Settings
System Services
Windows Search (Startup Mode: Disabled)
Permissions
No permissions specified
Auditing
No auditing specified
File System
%SystemDrive%\
Do not allow permissions on this file or folder to be replaced
%SystemRoot%\regedit.exe
Do not allow permissions on this file or folder to be replaced
%SystemRoot%\System32\appwiz.cpl
Do not allow permissions on this file or folder to be replaced
%SystemRoot%\System32\compmgmt.msc
Do not allow permissions on this file or folder to be replaced
%SystemRoot%\System32\ipconfig.exe
Do not allow permissions on this file or folder to be replaced
%SystemRoot%\System32\nslookup.exe
Do not allow permissions on this file or folder to be replaced
%SystemRoot%\System32\PING.EXE
Do not allow permissions on this file or folder to be replaced
%SystemRoot%\System32\services.exe
Do not allow permissions on this file or folder to be replaced
%SystemRoot%\System32\services.msc
Do not allow permissions on this file or folder to be replaced
%SystemRoot%\System32\taskkill.exe
Do not allow permissions on this file or folder to be replaced
%SystemRoot%\System32\tasklist.exe
Do not allow permissions on this file or folder to be replaced
%SystemRoot%\System32\WF.msc
Do not allow permissions on this file or folder to be replaced
%SystemRoot%\winhlp32.exe
Do not allow permissions on this file or folder to be replaced
%UserProfile%\Desktop
Do not allow permissions on this file or folder to be replaced
Software Restriction Policies
Enforcement
PolicySetting
Apply Software Restriction Policies to the followingAll software files except libraries (such as DLLs)
Apply Software Restriction Policies to the following usersAll users
When applying Software Restriction PoliciesIgnore certificate rules
Designated File Types
File ExtensionFile Type
ADEADE File
ADPADP File
BASBAS File
BATWindows Batch File
CHMCompiled HTML Help file
CMDWindows Command Script
COMMS-DOS Application
CPLControl panel item
CRTSecurity Certificate
EXEApplication
HLPHelp file
HTAHTML Application
INFSetup Information
INSINS File
ISPISP File
LNKShortcut
MDBMDB File
MDEMDE File
MSCMicrosoft Common Console Document
MSIWindows Installer Package
MSPWindows Installer Patch
MSTMST File
OCXActiveX control
PCDPCD File
PIFShortcut to MS-DOS Program
REGRegistration Entries
SCRScreen saver
SHSSHS File
URLInternet Shortcut
VBVisual Basic Source File
WSCWindows Script Component
Trusted Publishers
Trusted publisher managementAllow all administrators and users to manage user's own Trusted Publishers
Certificate verificationNone
Software Restriction Policies/Security Levels
PolicySetting
Default Security LevelUnrestricted
Software Restriction Policies/Additional Rules
Path Rules
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%
Security LevelUnrestricted
Description
Date last modified31-1-2019 16:46:59
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir%
Security LevelUnrestricted
Description
Date last modified31-1-2019 16:46:59
Administrative Templates
Policy definitions (ADMX files) retrieved from the central store.
Control Panel
PolicySettingComment
Allow Online TipsDisabled
Settings Page VisibilityDisabled
System/Removable Storage Access
PolicySettingComment
All Removable Storage classes: Deny all accessEnabled
Removable Disks: Deny execute accessEnabled
Removable Disks: Deny read accessEnabled
Removable Disks: Deny write accessEnabled
Windows Components/AutoPlay Policies
PolicySettingComment
Disallow Autoplay for non-volume devicesEnabled
Turn off AutoplayEnabled
Turn off Autoplay on:CD-ROM and removable media drives
Windows Components/Internet Explorer
PolicySettingComment
Prevent changing proxy settingsEnabled
Windows Components/Internet Explorer/Internet Control Panel/Security Page/Internet Zone
PolicySettingComment
Allow file downloadsDisabled
Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone
PolicySettingComment
Allow file downloadsDisabled
Windows Components/Internet Explorer/Internet Control Panel/Security Page/Local Machine Zone
PolicySettingComment
Allow file downloadsDisabled
Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Internet Zone
PolicySettingComment
Allow file downloadsDisabled
Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Intranet Zone
PolicySettingComment
Allow file downloadsDisabled
Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Local Machine Zone
PolicySettingComment
Allow file downloadsDisabled
Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone
PolicySettingComment
Allow file downloadsDisabled
Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Trusted Sites Zone
PolicySettingComment
Allow file downloadsDisabled
Windows Components/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone
PolicySettingComment
Allow file downloadsDisabled
Windows Components/Internet Explorer/Internet Control Panel/Security Page/Trusted Sites Zone
PolicySettingComment
Allow file downloadsDisabled
Windows Components/Online Assistance
PolicySettingComment
Turn off Active HelpEnabled
User Configuration (Enabled)
Policies
Administrative Templates
Policy definitions (ADMX files) retrieved from the central store.
Control Panel/Add or Remove Programs
PolicySettingComment
Hide Change or Remove Programs pageEnabled
Control Panel/Programs
PolicySettingComment
Hide the Programs Control PanelEnabled
Start Menu and Taskbar
PolicySettingComment
Add the Run command to the Start MenuDisabled
Do not allow pinning programs to the TaskbarEnabled
Do not search for filesEnabled
Do not search InternetEnabled
Lock all taskbar settingsEnabled
Lock the TaskbarEnabled
Prevent changes to Taskbar and Start Menu SettingsEnabled
Prevent users from uninstalling applications from StartEnabled
Remove access to the context menus for the taskbarEnabled
Remove Games link from Start MenuEnabled
Remove Help menu from Start MenuEnabled
Remove links and access to Windows UpdateEnabled
Remove Run menu from Start MenuEnabled
Remove Search Computer linkEnabled
Remove Search link from Start MenuEnabled
Remove See More Results / Search Everywhere linkEnabled
Show Start on the display the user is using when they press the Windows logo keyDisabled
System/Ctrl+Alt+Del Options
PolicySettingComment
Remove Task ManagerEnabled
Windows Components/File Explorer
PolicySettingComment
Hides the Manage item on the File Explorer context menuEnabled
Windows Components/Internet Explorer/Internet Control Panel/Advanced Page
PolicySettingComment
Do not allow resetting Internet Explorer settingsEnabled
Windows Components/Internet Explorer/Security Features/Restrict File Download
PolicySettingComment
Internet Explorer ProcessesEnabled