| ES-PO-WIN-ADM-U-Restrictions GISP Allow Desktop, Drives & StartMenu | |
| Data collected on: 2-9-2025 12:22:53 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\cespedes.11-adm |
| Created | 16-10-2024 09:10:14 |
| Modified | 1-9-2025 13:48:40 |
| User Revisions | 74 (AD), 74 (SYSVOL) |
| Computer Revisions | 1 (AD), 1 (SYSVOL) |
| Unique ID | {5b95063a-2a93-435c-a1bc-01387761428f} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| ES | No | Enabled | emea.tpg.ads/ES |
| Name |
|---|
| EMEA\ES-L-SEC-User Restriction GISP Allow Desktop & StartMenu |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\ES-L-SEC-Delegation Full Access | Edit settings, delete, modify security | No |
| EMEA\ES-L-SEC-User Restriction GISP Allow Desktop & StartMenu | Read (from Security Filtering) | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Enforcement | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Designated File Types | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Trusted Publishers | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
| Policy | Setting |
|---|---|
| Default Security Level | Unrestricted |
| APPWIZ.CPL (10.0.17763.2028); APPWIZ; Shell Application Manager; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| bitsadmin.exe (7.8.17763.1); bitsadmin.exe; BITS administration utility; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| CACLS.EXE (10.0.17763.1); cacls; Control ACLs Program; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| Cmd.Exe (10.0.17763.1697); cmd; Windows Command Processor; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| compmgmt.msc; 111 KB; 15/09/2018 8:12:44 | ||||||
| ||||||
| CONTROL.EXE (10.0.17763.2300); Control; Windows Control Panel; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| eventvwr.exe (10.0.17763.1); eventvwr; Event Viewer Snapin Launcher; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| gpedit.msc; 144 KB; 15/09/2018 8:13:19 | ||||||
| ||||||
| Help.Exe (10.0.17763.1); Help; Command Line Help Utility; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| HelpPane.exe (10.0.17763.2989); HelpPane.exe; Microsoft Help and Support; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| mmc.exe (10.0.17763.1697); mmc.exe; Microsoft Management Console; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| NOTEPAD.EXE (10.0.17763.5328); Notepad; Notepad; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| PowerShell.EXE (10.0.17763.1); POWERSHELL; Windows PowerShell; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| powershell_ise.EXE (10.0.17763.1); POWERSHELL_ISE; Windows PowerShell ISE; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| REGEDIT.EXE (10.0.17763.1697); REGEDIT; Registry Editor; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| regedt32.exe (10.0.17763.1); regedt32.exe; Registry Editor Utility; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| services.msc; 91 KB; 15/09/2018 8:12:52 | ||||||
|
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% | ||||||
| ||||||
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% | ||||||
|
| Policy | Setting | Comment | |||||
|---|---|---|---|---|---|---|---|
| Prohibit access to Control Panel and PC settings | Enabled | ||||||
| Show only specified Control Panel items | Enabled | ||||||
| |||||||
| Policy | Setting | Comment | ||||||
|---|---|---|---|---|---|---|---|---|
| Enable screen saver | Enabled | |||||||
| Force specific screen saver | Enabled | |||||||
| ||||||||
| Policy | Setting | Comment | ||||||
| Password protect the screen saver | Enabled | |||||||
| Screen saver timeout | Enabled | |||||||
| ||||||||
| Policy | Setting | Comment |
|---|---|---|
| Browse the network to find printers | Disabled | |
| Prevent addition of printers | Enabled |
| Policy | Setting | Comment | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Allow Dinosaur Easter Egg Game | Disabled | ||||||||||||||||
| Allow user feedback | Disabled | ||||||||||||||||
| Block access to a list of URLs | Enabled | ||||||||||||||||
| |||||||||||||||||
| Policy | Setting | Comment | |||||||||||||||
| Control where Developer Tools can be used | Enabled | ||||||||||||||||
| |||||||||||||||||
| Policy | Setting | Comment | |||||||||||||||
| Define domains allowed to access Google Workspace | Enabled | ||||||||||||||||
| |||||||||||||||||
| Policy | Setting | Comment | |||||||||||||||
| Proxy settings | Enabled | ||||||||||||||||
| |||||||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Enable reporting of usage and crash-related data | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Enable saving passwords to the password manager | Disabled |
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Allow user feedback | Disabled | |||||
| Block access to a list of URLs | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Control where developer tools can be used | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Define domains allowed to access Google Workspace | Enabled | |||||
| ||||||
| Policy | Setting | Comment |
|---|---|---|
| Enable saving passwords to the password manager | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Proxy settings | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Allow Microsoft content on the new tab page | Disabled | |||
| Configure the home page URL | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Configure the new tab page URL | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Block about:config | Enabled | |||
| Block about:profiles | Enabled | |||
| Block Add-ons Manager | Enabled | |||
| Define domains allowed to access Google Workspace | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Disable Developer Tools | Enabled | |||
| Disable Feedback Commands | Enabled | |||
| Password Manager | Disabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Do not allow proxy settings to be changed | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prohibit access of the Windows Connect Now wizards | Enabled |
| Policy | Setting | Comment | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Do not display the Getting Started welcome screen at logon | Enabled | |||||||||||||||||||||||||
| Don't run specified Windows applications | Enabled | |||||||||||||||||||||||||
| ||||||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||||||||
| Prevent access to registry editing tools | Enabled | |||||||||||||||||||||||||
| ||||||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||||||||
| Prevent access to the command prompt | Enabled | |||||||||||||||||||||||||
| ||||||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||||||||
| Restrict these programs from being launched from Help | Enabled | |||||||||||||||||||||||||
| ||||||||||||||||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| All Removable Storage classes: Deny all access | Enabled | |
| CD and DVD: Deny read access | Enabled | |
| CD and DVD: Deny write access | Enabled | |
| Floppy Drives: Deny read access | Enabled | |
| Floppy Drives: Deny write access | Enabled | |
| Removable Disks: Deny read access | Enabled | |
| Removable Disks: Deny write access | Enabled | |
| Tape Drives: Deny read access | Enabled | |
| Tape Drives: Deny write access | Enabled | |
| WPD Devices: Deny read access | Enabled | |
| WPD Devices: Deny write access | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent the wizard from running. | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn off Autoplay | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off all Windows spotlight features | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow edge swipe | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Hide these specified drives in My Computer | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| No Computers Near Me in Network Locations | Enabled | |||
| Prevent access to drives from My Computer | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Prevent users from adding files to the root of their Users Files folder. | Enabled | |||
| Remove CD Burning features | Enabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Do not allow users to enable or disable add-ons | Enabled | |
| Prevent access to Internet Explorer Help | Enabled | |
| Prevent changing proxy settings | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Disable the Advanced page | Enabled | |
| Disable the Programs page | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn off encryption support | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off Developer Tools | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow Extensions | Disabled | |
| Prevent access to the about:flags page in Microsoft Edge | Enabled | |
| Prevent the First Run webpage from opening on Microsoft Edge | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Restrict the user from entering author mode | Enabled | |
| Restrict users to the explicitly permitted list of snap-ins | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent users from sharing files within their profile. | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Windows presentation settings | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent access to feed list | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Only display the private store within the Microsoft Store | Enabled | |
| Turn off the offer to update to the latest version of Windows | Enabled | |
| Turn off the Store application | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Hide Advanced Properties Checkbox in Add Scheduled Task Wizard | Enabled | |
| Hide Property Pages | Enabled | |
| Prevent Task Run or End | Enabled | |
| Prohibit Browse | Enabled | |
| Prohibit Drag-and-Drop | Enabled | |
| Prohibit New Task Creation | Enabled | |
| Prohibit Task Deletion | Enabled |
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Always install with elevated privileges | Enabled | |||||
| ||||||
| Policy | Setting | Comment |
|---|---|---|
| Do not allow Windows Messenger to be run | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Windows Mobility Center | Enabled |