| FR-PO-WIN-C-Windows 10 Hardening | |
| Data collected on: 2-9-2025 09:25:08 | |
| Domain | emea.tpg.ads |
| Owner | S-1-5-21-513466819-3096973226-347852806-22141 |
| Created | 22-3-2019 14:40:40 |
| Modified | 14-4-2025 13:00:42 |
| User Revisions | 1 (AD), 1 (SYSVOL) |
| Computer Revisions | 68 (AD), 68 (SYSVOL) |
| Unique ID | {48b31ffa-a609-4ec0-b731-0bf90c87cae5} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Clients | No | Enabled | emea.tpg.ads/FR/Systems/Clients |
| Name |
|---|
| EMEA\FR-L-SEC-Hardening_Computers_Windows10 |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\FR-G-ORG-OU Admins | Edit settings, delete, modify security | No |
| EMEA\FR-L-SEC-Delegation Modify Group Policy Settings Access | Edit settings, delete, modify security | No |
| EMEA\FR-L-SEC-Hardening_Computers_Windows10 | Read (from Security Filtering) | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Policy | Setting |
|---|---|
| Deny log on locally | EMEA\FR-L-SEC-GPO-Waha-User-Configuration, EMEA\FR-L-SEC-GPO-Waha-Folder_Redirection_Startmenu |
| Policy | Setting |
|---|---|
| User Account Control: Admin Approval Mode for the Built-in Administrator account | Disabled |
| User Account Control: Behavior of the elevation prompt for standard users | Prompt for credentials |
| User Account Control: Detect application installations and prompt for elevation | Enabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Deny | EMEA\FR-L-SEC Disable Win10 Features | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Deny | EMEA\FR-L-SEC Disable Win10 Features | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Deny | EMEA\FR-L-SEC Disable Win10 Features | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Deny | EMEA\FR-L-SEC Disable Win10 Features | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Deny | EMEA\FR-L-SEC Disable Win10 Features | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Deny | EMEA\FR-L-SEC Disable Win10 Features | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow users to enable online speech recognition services | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off automatic learning | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| IPv6 Configuration Policy | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Prohibit user configuration of Offline Files | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Disable context menus in the Start Menu | Enabled | |||||
| Start Layout | Enabled | |||||
| ||||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off access to the Store | Enabled | |
| Turn off handwriting personalization data sharing | Enabled | |
| Turn off handwriting recognition error reporting | Enabled | |
| Turn off Help and Support Center "Did you know?" content | Enabled | |
| Turn off the Windows Messenger Customer Experience Improvement Program | Enabled | |
| Turn off Windows Error Reporting | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow publishing of User Activities | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn Off the hard disk (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Allow standby states (S1-S3) when sleeping (on battery) | Disabled | |
| Allow standby states (S1-S3) when sleeping (plugged in) | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow restore of system to default state | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Configuration | Enabled | |
| Turn off System Restore | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not log users on with temporary profiles | Enabled | |
| Turn off the advertising ID | Enabled |
| Policy | Setting | Comment | ||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Let Windows apps access account information | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access call history | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access contacts | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access diagnostic information about other apps | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access email | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access location | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access messaging | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access motion | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access notifications | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access Tasks | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access the calendar | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access the camera | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access the microphone | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access trusted devices | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps communicate with unpaired devices | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps control radios | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps make phone calls | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps run in the background | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Remove Program Compatibility Property Page | Enabled | |
| Turn off Application Compatibility Engine | Enabled | |
| Turn off Application Telemetry | Enabled | |
| Turn off Inventory Collector | Enabled | |
| Turn off Program Compatibility Assistant | Enabled | |
| Turn off Steps Recorder | Enabled | |
| Turn off SwitchBack Compatibility Engine | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not show Windows tips | Enabled | |
| Turn off Microsoft consumer experiences | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Allow Diagnostic Data | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Configure the Commercial ID | Disabled | |||
| Do not show feedback notifications | Enabled | |||
| Limit optional diagnostic data for Desktop Analytics | Disabled | |||
| Toggle user control over Insider builds | Disabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Turn off desktop gadgets | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Do not show the 'new application installed' notification | Enabled | |||
| Start File Explorer with ribbon minimized | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off File History | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn On/Off Find My Device | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off downloading of game information | Enabled | |
| Turn off game updates | Enabled | |
| Turn off tracking of last play time of games in the Games folder | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off location | Enabled | |
| Turn off sensors | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Windows Location Provider | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Block all consumer Microsoft account user authentication | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Microsoft Defender Antivirus | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Configure local setting override for reporting to Microsoft MAPS | Disabled | |||
| Join Microsoft MAPS | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Send file samples when further analysis is required | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Monitor file and program activity on your computer | Disabled | |
| Turn off real-time protection | Disabled | |
| Turn on behavior monitoring | Disabled | |
| Turn on process scanning whenever real-time protection is enabled | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Prevent OneDrive files from syncing over metered connections | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Prevent OneDrive from generating network traffic until the user signs in to OneDrive | Enabled | |||
| Prevent the usage of OneDrive for file storage | Enabled | |||
| Prevent the usage of OneDrive for file storage on Windows 8.1 | Enabled | |||
| Save documents to OneDrive by default | Disabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Turn off Active Help | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Push To Install service | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Allow Cloud Search | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow Cortana | Disabled | |||
| Allow Cortana above lock screen | Disabled | |||
| Allow indexing of encrypted files | Disabled | |||
| Allow search and Cortana to use location | Disabled | |||
| Do not allow web search | Enabled | |||
| Don't search the web or display web results in Search | Enabled | |||
| Set what information is shared in Search | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Turn on Security Center (Domain PCs only) | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow Automatic Update of Speech Data | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Disable all apps from Microsoft Store | Enabled | |
| Only display the private store within the Microsoft Store | Enabled | |
| Turn off the Store application | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off automatic learning | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Configure Windows Defender SmartScreen | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Automatically send memory dumps for OS-generated error reports | Disabled | |
| Disable Windows Error Reporting | Enabled | |
| Do not send additional data | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Enables or disables Windows Game Recording and Broadcasting | Disabled |
| Setting | State |
|---|---|
| Software\Policies\Microsoft\Windows\PreviewBuilds\EnableConfigFlighting | 1 |
| Software\Policies\Microsoft\Windows\PreviewBuilds\EnableExperimentation | 1 |
| Action | Update |
| Destination file | C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group1 |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Enabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Destination file | C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2 |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Enabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Destination file | C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3 |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Enabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows Defender |
| Value name | DisableAntiSpyware |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsStore\WindowsUpdate |
| Value name | AutoDownload |
| Value type | REG_DWORD |
| Value data | 0x2 (2) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows\CloudContent |
| Value name | DisableWindowsConsumerFeatures |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Services\SecurityHealthService |
| Value name | Start |
| Value type | REG_DWORD |
| Value data | 0x3 (3) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Config |
| Value name | DownloadMode |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\WindowsStore |
| Value name | AutoDownload |
| Value type | REG_DWORD |
| Value data | 0x2 (2) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System |
| Value name | EnableFirstLogonAnimation |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |