| GC-PO-WIN-C-Server Hardening Policy | |
| Data collected on: 2-9-2025 11:22:55 | |
| Domain | emea.tpg.ads |
| Owner | S-1-5-21-513466819-3096973226-347852806-1233267 |
| Created | 7-7-2023 15:01:26 |
| Modified | 24-7-2023 19:29:08 |
| User Revisions | 17 (AD), 17 (SYSVOL) |
| Computer Revisions | 6 (AD), 6 (SYSVOL) |
| Unique ID | {50907db3-2a66-4599-80a8-1ecec71b388b} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| None | |||
| Name |
|---|
| NT AUTHORITY\Authenticated Users |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\GC-G-ORG-ServerAdmin | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read (from Security Filtering) | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| S-1-5-21-513466819-3096973226-347852806-1233267 | Edit settings, delete, modify security | No |
| Policy | Setting |
|---|---|
| Enforce password history | 10 passwords remembered |
| Maximum password age | 30 days |
| Minimum password age | 1 days |
| Minimum password length | 8 characters |
| Password must meet complexity requirements | Enabled |
| Policy | Setting |
|---|---|
| Account lockout duration | 99999 minutes |
| Account lockout threshold | 3 invalid logon attempts |
| Reset account lockout counter after | 99999 minutes |
| Policy | Setting |
|---|---|
| Audit account logon events | Success, Failure |
| Audit account management | Success, Failure |
| Audit logon events | Success, Failure |
| Audit object access | Success, Failure |
| Audit policy change | Success, Failure |
| Audit privilege use | Success, Failure |
| Audit system events | Success, Failure |
| Policy | Setting |
|---|---|
| Access this computer from the network | BUILTIN\Administrators, NT AUTHORITY\Authenticated Users, BUILTIN\Backup Operators, Everyone |
| Adjust memory quotas for a process | BUILTIN\Administrators, NT AUTHORITY\LOCAL SERVICE, NT AUTHORITY\NETWORK SERVICE |
| Allow log on locally | BUILTIN\Administrators, BUILTIN\Backup Operators |
| Allow log on through Terminal Services | BUILTIN\Administrators, BUILTIN\Backup Operators, BUILTIN\Remote Desktop Users |
| Back up files and directories | BUILTIN\Administrators, BUILTIN\Backup Operators |
| Bypass traverse checking | BUILTIN\Backup Operators, Everyone, BUILTIN\Users |
| Change the system time | BUILTIN\Administrators |
| Create a pagefile | BUILTIN\Administrators |
| Create global objects | BUILTIN\Administrators, NT AUTHORITY\SERVICE |
| Debug programs | BUILTIN\Administrators |
| Deny access to this computer from the network | BUILTIN\Guests |
| Force shutdown from a remote system | BUILTIN\Administrators |
| Generate security audits | NT AUTHORITY\LOCAL SERVICE, NT AUTHORITY\NETWORK SERVICE |
| Impersonate a client after authentication | BUILTIN\Administrators, NT AUTHORITY\SERVICE |
| Increase scheduling priority | BUILTIN\Administrators |
| Load and unload device drivers | BUILTIN\Administrators |
| Log on as a batch job | BUILTIN\Administrators, NT AUTHORITY\LOCAL SERVICE |
| Log on as a service | BUILTIN\Administrators, NT AUTHORITY\NETWORK SERVICE, BUILTIN\Users |
| Manage auditing and security log | BUILTIN\Administrators |
| Modify firmware environment values | BUILTIN\Administrators |
| Perform volume maintenance tasks | BUILTIN\Administrators |
| Profile single process | BUILTIN\Administrators |
| Profile system performance | BUILTIN\Administrators |
| Remove computer from docking station | BUILTIN\Administrators |
| Replace a process level token | NT AUTHORITY\NETWORK SERVICE, NT AUTHORITY\LOCAL SERVICE, BUILTIN\Administrators |
| Restore files and directories | BUILTIN\Administrators, BUILTIN\Backup Operators |
| Shut down the system | BUILTIN\Administrators, BUILTIN\Backup Operators |
| Take ownership of files or other objects | BUILTIN\Administrators |
| Policy | Setting |
|---|---|
| Accounts: Administrator account status | Enabled |
| Accounts: Guest account status | Disabled |
| Accounts: Limit local account use of blank passwords to console logon only | Enabled |
| Accounts: Rename guest account | "!NoUseGuest!" |
| Policy | Setting |
|---|---|
| Audit: Audit the access of global system objects | Disabled |
| Audit: Audit the use of Backup and Restore privilege | Disabled |
| Audit: Shut down system immediately if unable to log security audits | Disabled |
| Policy | Setting |
|---|---|
| Devices: Allow undock without having to log on | Disabled |
| Devices: Allowed to format and eject removable media | Administrators |
| Devices: Prevent users from installing printer drivers | Enabled |
| Devices: Restrict CD-ROM access to locally logged-on user only | Disabled |
| Devices: Restrict floppy access to locally logged-on user only | Enabled |
| Policy | Setting |
|---|---|
| Domain member: Digitally encrypt or sign secure channel data (always) | Enabled |
| Domain member: Digitally encrypt secure channel data (when possible) | Enabled |
| Domain member: Digitally sign secure channel data (when possible) | Enabled |
| Domain member: Disable machine account password changes | Disabled |
| Domain member: Maximum machine account password age | 30 days |
| Domain member: Require strong (Windows 2000 or later) session key | Disabled |
| Policy | Setting |
|---|---|
| Interactive logon: Do not require CTRL+ALT+DEL | Disabled |
| Interactive logon: Don't display last signed-in | Enabled |
| Interactive logon: Message text for users attempting to log on | This system is the property of Teleperformance Global Services, and is to be used in accordance with applicable Teleperformance Policies. Any unauthorized access or activity is a violation of Teleperformance Policies and may be a violation of a law. Use of this system constitutes consent to monitoring for unauthorized use, in accordance with Teleperformance Policies, local laws, and regulations. Unauthorized use may result in penalties including, but not limited to, reprimand, dismissal, financial penalties, and legal actions. |
| Interactive logon: Message title for users attempting to log on | "Teleperformance Security Advisory Warning" |
| Interactive logon: Number of previous logons to cache (in case domain controller is not available) | 10 logons |
| Interactive logon: Prompt user to change password before expiration | 15 days |
| Interactive logon: Require Domain Controller authentication to unlock workstation | Disabled |
| Interactive logon: Require Windows Hello for Business or smart card | Disabled |
| Interactive logon: Smart card removal behavior | Force Logoff |
| Policy | Setting |
|---|---|
| Microsoft network client: Digitally sign communications (always) | Disabled |
| Microsoft network client: Digitally sign communications (if server agrees) | Enabled |
| Microsoft network client: Send unencrypted password to third-party SMB servers | Disabled |
| Policy | Setting |
|---|---|
| Microsoft network server: Amount of idle time required before suspending session | 15 minutes |
| Microsoft network server: Digitally sign communications (always) | Disabled |
| Microsoft network server: Digitally sign communications (if client agrees) | Enabled |
| Microsoft network server: Disconnect clients when logon hours expire | Enabled |
| Policy | Setting |
|---|---|
| Network access: Allow anonymous SID/Name translation | Disabled |
| Network access: Do not allow anonymous enumeration of SAM accounts | Enabled |
| Network access: Do not allow anonymous enumeration of SAM accounts and shares | Enabled |
| Network access: Let Everyone permissions apply to anonymous users | Disabled |
| Policy | Setting |
|---|---|
| Network security: Do not store LAN Manager hash value on next password change | Enabled |
| Network security: Force logoff when logon hours expire | Enabled |
| Network security: LAN Manager authentication level | Send LM & NTLM - use NTLMv2 session security if negotiated |
| Network security: LDAP client signing requirements | Negotiate signing |
| Policy | Setting |
|---|---|
| Recovery console: Allow automatic administrative logon | Disabled |
| Recovery console: Allow floppy copy and access to all drives and all folders | Disabled |
| Policy | Setting |
|---|---|
| Shutdown: Allow system to be shut down without having to log on | Disabled |
| Shutdown: Clear virtual memory pagefile | Disabled |
| Policy | Setting |
|---|---|
| System objects: Require case insensitivity for non-Windows subsystems | Enabled |
| System objects: Strengthen default permissions of internal system objects (e.g. Symbolic Links) | Enabled |
| Policy | Setting |
|---|---|
| MACHINE\Software\Microsoft\Driver Signing\Policy | 1 |
| MACHINE\System\CurrentControlSet\Control\Lsa\FIPSAlgorithmPolicy | 0 |
| MACHINE\System\CurrentControlSet\Control\Lsa\NoDefaultAdminOwner | 0 |
| Policy | Setting |
|---|---|
| Maximum application log size | 153600 kilobytes |
| Maximum security log size | 153600 kilobytes |
| Maximum system log size | 153600 kilobytes |
| Prevent local guests group from accessing application log | Enabled |
| Prevent local guests group from accessing security log | Enabled |
| Prevent local guests group from accessing system log | Enabled |
| Retention method for application log | As needed |
| Retention method for security log | As needed |
| Retention method for system log | As needed |
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Require user authentication for remote connections by using Network Level Authentication | Enabled | |||||
| Set client connection encryption level | Enabled | |||||
| ||||||
| Startup options | Start with tabs from the last session |
| Delete browsing history on exit | No |
| Connection behavior | Dial whenever a network connection is not present |
| User software rendering instead of GPU rendering | Enabled |
| Always expand ALT text for images | Disabled |
| Enable Caret Browser for new windows and tabs | Disabled |
| Move system caret with focus/selection changes | Disabled |
| Play system sounds | Disabled |
| Reset text size to medium for new windows and tabs | Disabled |
| Reset Zoom level for new windows and tabs | Disabled |
| Automatically recover from page layout errors with Compatibility View | Enabled |
| Close unused folders in History and Favorites (requires restart) | Disabled |
| Disable Script debugging (Internet Explorer) | Enabled |
| Disable Script debugging (Other) | Enabled |
| Display a notification about every script error | Disabled |
| Display Accelerator button on selection | Disabled |
| Enable automatic crash recovery | Enabled |
| Enable flip ahead | Disabled |
| Enable FTP folder view (outside of Internet Explorer) | Enabled |
| Enable Suggested Sites | Disabled |
| Enable third-party browser extensions (requires restart) | Disabled |
| Enable visual styles on buttons and controls in webpages | Enabled |
| Enable websites to use the search pane | Disabled |
| Go to an intranet site for a single word entry in the Address bar | Disabled |
| Notify when downloads complete | Enabled |
| Reuse windows for launching shortcuts | Enabled |
| Show Friendly HTTP Error messages | Enabled |
| Tell me if Internet Explorer is not the default web browser | Enabled |
| Underline links | Always |
| Use inline AutoComplete | Enabled |
| Use inline Autocomplete in File Explorer and Run Dialog | Disabled |
| Use most recent order when switching tabs with Ctrl+Tab | Disabled |
| Use Passive FTP (for firewall and DSL model compatibility) | Enabled |
| Use smooth scrolling | Enabled |
| Use HTTP 1.1 | Enabled |
| Use HTTP 1.1 through proxy connections | Enabled |
| Always show encoded addresses | Disabled |
| Send IDN server names | Enabled |
| Send IDN server names for Intranet addresses | Disabled |
| Send UTF-8 URLs | Enabled |
| Show Information Bar for encoded addresses | Enabled |
| Enable alternative codecs in HTML5 media elements | Enabled |
| Enable Automatic Image Resizing | Enabled |
| Play animations in webpages | Disabled |
| Play sounds in webpages | Disabled |
| Show image download placeholders | Disabled |
| Show pictures | Enabled |
| Allow active content from CDs to run on My Computer | Disabled |
| Allow active content to run in files on My Computer | Disabled |
| Always send Do Not Track header | Disabled |
| Allow software to run or install even if the signature is invalid | Disabled |
| Block unsecured images with other mixed content | Disabled |
| Check for publisher's certificate revocation | Enabled |
| Check for server certificate revocation (requires restart) | Enabled |
| Check for signatures on downloaded programs | Enabled |
| Do not save encrypted pages to disk | Enabled |
| Empty Temporary Internet Files folder when browser is closed | Enabled |
| Enable memory protection to help mitigate online attacks | Disabled |
| Enable DOM Storage | Enabled |
| Enable Enhanced Protected Mode | Enabled |
| Enable Integrated Windows Authentication (requires restart) | Enabled |
| Enable native XMLHTTP support | Enabled |
| Enable SmartScreen Filter | Disabled |
| Use SSL 2.0 | Disabled |
| Use SSL 3.0 | Enabled |
| Use TLS 1.0 | Disabled |
| Use TLS 1.1 | Disabled |
| Use TLS 1.2 | Enabled |
| Warn about certificate address mismatch | Enabled |
| Warn if changing between secure and not secure mode | Enabled |
| Warn if POST submittal is redirected to a zone that does not permit posts | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |