| FSM-PO-SEC-C-Zero_Trust_new | |
| Data collected on: 2-9-2025 12:29:23 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\toumi.80-adm |
| Created | 10-1-2025 17:32:38 |
| Modified | 25-2-2025 17:44:36 |
| User Revisions | 0 (AD), 0 (SYSVOL) |
| Computer Revisions | 40 (AD), 40 (SYSVOL) |
| Unique ID | {3c80df6e-5a84-44a1-aa1b-bf1877093b09} |
| GPO Status | User settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Clients | No | Enabled | emea.tpg.ads/FR/Systems/Clients |
| Clients | No | Enabled | emea.tpg.ads/MA/Systems/Clients |
| Clients | No | Enabled | emea.tpg.ads/MG/Systems/Clients |
| Clients | No | Enabled | emea.tpg.ads/TG/Systems/Clients |
| Clients | No | Enabled | emea.tpg.ads/TN/Systems/Clients |
| Name |
|---|
| EMEA\FSM-L-SEC-GPO-Zero_Trust |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\FSM-L-SEC-GPO-Zero_Trust | Read (from Security Filtering) | No |
| EMEA\TN-G-ORG-OU Admins | Edit settings, delete, modify security | No |
| EMEA\TN-L-SEC-Delegation Modify Group Policy Settings Access | Edit settings, delete, modify security | No |
| EMEA\toumi.80-adm | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Policy | Setting | Comment | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Turn On Virtualization Based Security | Enabled | |||||||||||||
| ||||||||||||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Enumeration policy for external devices incompatible with Kernel DMA Protection | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Require additional authentication at startup | Enabled | |||||||||||||||
| ||||||||||||||||
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\DeviceGuard |
| Value name | EnableVirtualizationBasedSecurity |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\DeviceGuard |
| Value name | RequirePlatformSecurityFeatures |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\DeviceGuard |
| Value name | Locked |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\DeviceGuard |
| Value name | Unlocked |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\DeviceGuard |
| Value name | HypervisorEnforcedCodeIntegrity |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity |
| Value name | Enabled |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity |
| Value name | Locked |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | System\CurrentControlSet\Control\LSA |
| Value name | LsaCfgFlags |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |