| ES-PO-WIN-ADM-U-Restrictions GECSP ACM Allow Notepad | |
| Data collected on: 2-9-2025 12:25:32 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\cespedes.11-adm |
| Created | 8-11-2024 13:55:12 |
| Modified | 20-5-2025 16:37:34 |
| User Revisions | 21 (AD), 21 (SYSVOL) |
| Computer Revisions | 1 (AD), 1 (SYSVOL) |
| Unique ID | {3d192599-1b72-472f-b8ea-5b600b33f42f} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| ES | No | Enabled | emea.tpg.ads/ES |
| Name |
|---|
| EMEA\ES-L-SEC-User Restriction GECSP ACM Allow Notepad |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\ES-L-SEC-Delegation Full Access | Edit settings, delete, modify security | No |
| EMEA\ES-L-SEC-User Restriction GECSP ACM Allow Notepad | Read (from Security Filtering) | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Enforcement | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Designated File Types | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Trusted Publishers | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
| Policy | Setting |
|---|---|
| Default Security Level | Unrestricted |
| APPWIZ.CPL (10.0.17763.2028); APPWIZ; Shell Application Manager; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| bitsadmin.exe (7.8.17763.1); bitsadmin.exe; BITS administration utility; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| CACLS.EXE (10.0.17763.1); cacls; Control ACLs Program; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| Cmd.Exe (10.0.17763.1697); cmd; Windows Command Processor; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| compmgmt.msc; 111 KB; 15/09/2018 8:12:44 | ||||||
| ||||||
| CONTROL.EXE (10.0.17763.2300); Control; Windows Control Panel; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| eventvwr.exe (10.0.17763.1); eventvwr; Event Viewer Snapin Launcher; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| gpedit.msc; 144 KB; 15/09/2018 8:13:19 | ||||||
| ||||||
| Help.Exe (10.0.17763.1); Help; Command Line Help Utility; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| HelpPane.exe (10.0.17763.2989); HelpPane.exe; Microsoft Help and Support; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| mmc.exe (10.0.17763.1697); mmc.exe; Microsoft Management Console; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| PowerShell.EXE (10.0.17763.1); POWERSHELL; Windows PowerShell; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| powershell_ise.EXE (10.0.17763.1); POWERSHELL_ISE; Windows PowerShell ISE; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| REGEDIT.EXE (10.0.17763.1697); REGEDIT; Registry Editor; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| regedt32.exe (10.0.17763.1); regedt32.exe; Registry Editor Utility; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| services.msc; 91 KB; 15/09/2018 8:12:52 | ||||||
|
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% | ||||||
| ||||||
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% | ||||||
|
| Policy | Setting | Comment | |||||
|---|---|---|---|---|---|---|---|
| Prohibit access to Control Panel and PC settings | Enabled | ||||||
| Show only specified Control Panel items | Enabled | ||||||
| |||||||
| Policy | Setting | Comment | ||||||
|---|---|---|---|---|---|---|---|---|
| Enable screen saver | Enabled | |||||||
| Force specific screen saver | Enabled | |||||||
| ||||||||
| Policy | Setting | Comment | ||||||
| Screen saver timeout | Enabled | |||||||
| ||||||||
| Policy | Setting | Comment |
|---|---|---|
| Browse the network to find printers | Disabled | |
| Prevent addition of printers | Enabled |
| Policy | Setting | Comment | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Desktop Wallpaper | Enabled | |||||||||
| ||||||||||
| Policy | Setting | Comment | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Allow Dinosaur Easter Egg Game | Disabled | ||||||||||||||||
| Allow user feedback | Disabled | ||||||||||||||||
| Block access to a list of URLs | Enabled | ||||||||||||||||
| |||||||||||||||||
| Policy | Setting | Comment | |||||||||||||||
| Control where Developer Tools can be used | Enabled | ||||||||||||||||
| |||||||||||||||||
| Policy | Setting | Comment | |||||||||||||||
| Define domains allowed to access Google Workspace | Enabled | ||||||||||||||||
| |||||||||||||||||
| Policy | Setting | Comment | |||||||||||||||
| Proxy settings | Enabled | ||||||||||||||||
| |||||||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Enable reporting of usage and crash-related data | Enabled |
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Allow user feedback | Disabled | |||||
| Block access to a list of URLs | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Control where developer tools can be used | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Define domains allowed to access Google Workspace | Enabled | |||||
| ||||||
| Policy | Setting | Comment |
|---|---|---|
| Enable saving passwords to the password manager | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Proxy settings | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Allow Microsoft content on the new tab page | Disabled | |||
| Configure the home page URL | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Configure the new tab page URL | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Block about:config | Enabled | |||
| Block about:profiles | Enabled | |||
| Block Add-ons Manager | Enabled | |||
| Define domains allowed to access Google Workspace | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Disable Developer Tools | Enabled | |||
| Disable Feedback Commands | Enabled | |||
| Password Manager | Disabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Do not allow proxy settings to be changed | Enabled |
| Policy | Setting | Comment | ||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Don't run specified Windows applications | Enabled | |||||||||||||||||||||
| ||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||||
| Prevent access to registry editing tools | Enabled | |||||||||||||||||||||
| ||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||||
| Prevent access to the command prompt | Enabled | |||||||||||||||||||||
| ||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||||
| Restrict these programs from being launched from Help | Enabled | |||||||||||||||||||||
| ||||||||||||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| All Removable Storage classes: Deny all access | Enabled | |
| CD and DVD: Deny read access | Enabled | |
| CD and DVD: Deny write access | Enabled | |
| Floppy Drives: Deny read access | Enabled | |
| Floppy Drives: Deny write access | Enabled | |
| Removable Disks: Deny read access | Enabled | |
| Removable Disks: Deny write access | Enabled | |
| Tape Drives: Deny read access | Enabled | |
| Tape Drives: Deny write access | Enabled | |
| WPD Devices: Deny read access | Enabled | |
| WPD Devices: Deny write access | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn off Autoplay | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn off encryption support | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Restrict the user from entering author mode | Enabled | |
| Restrict users to the explicitly permitted list of snap-ins | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent access to feed list | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Hide Advanced Properties Checkbox in Add Scheduled Task Wizard | Enabled | |
| Hide Property Pages | Enabled | |
| Prevent Task Run or End | Enabled | |
| Prohibit Browse | Enabled | |
| Prohibit Drag-and-Drop | Enabled | |
| Prohibit New Task Creation | Enabled | |
| Prohibit Task Deletion | Enabled |
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Always install with elevated privileges | Enabled | |||||
| ||||||
| Policy | Setting | Comment |
|---|---|---|
| Do not allow Windows Messenger to be run | Enabled |