| GC-PO-WIN-C-Service Account Policy | |
| Data collected on: 2-9-2025 11:22:56 | |
| Domain | emea.tpg.ads |
| Owner | S-1-5-21-513466819-3096973226-347852806-1233267 |
| Created | 7-7-2023 15:37:30 |
| Modified | 25-6-2025 19:29:52 |
| User Revisions | 1 (AD), 1 (SYSVOL) |
| Computer Revisions | 45 (AD), 45 (SYSVOL) |
| Unique ID | {952087db-ecfe-4881-941d-2dfaea7d2e25} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Clients | No | Enabled | emea.tpg.ads/Special-Services/GC/Systems/Clients |
| Name |
|---|
| NT AUTHORITY\Authenticated Users |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\GC-G-ORG-ServerAdmin | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read (from Security Filtering) | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| S-1-5-21-513466819-3096973226-347852806-1233267 | Edit settings, delete, modify security | No |
| Policy | Setting |
|---|---|
| Enforce password history | 24 passwords remembered |
| Maximum password age | 60 days |
| Minimum password age | 1 days |
| Minimum password length | 14 characters |
| Password must meet complexity requirements | Enabled |
| Store passwords using reversible encryption | Disabled |
| Policy | Setting |
|---|---|
| Account lockout duration | 30 minutes |
| Account lockout threshold | 6 invalid logon attempts |
| Reset account lockout counter after | 30 minutes |
| Policy | Setting |
|---|---|
| Enforce user logon restrictions | Enabled |
| Maximum lifetime for service ticket | 600 minutes |
| Maximum lifetime for user ticket | 10 hours |
| Maximum lifetime for user ticket renewal | 10 days |
| Maximum tolerance for computer clock synchronization | 5 minutes |
| Policy | Setting |
|---|---|
| Audit account logon events | Failure |
| Audit account management | Failure |
| Audit logon events | Failure |
| Audit object access | Failure |
| Audit policy change | Success, Failure |
| Audit privilege use | Success, Failure |
| Audit system events | Failure |
| Policy | Setting |
|---|---|
| Access this computer from the network | BUILTIN\Administrators |
| Back up files and directories | BUILTIN\Administrators, BUILTIN\Backup Operators, BUILTIN\Users |
| Change the system time | BUILTIN\Administrators |
| Create a pagefile | BUILTIN\Administrators |
| Create a token object | |
| Create global objects | BUILTIN\Administrators |
| Deny access to this computer from the network | BUILTIN\Guests |
| Force shutdown from a remote system | BUILTIN\Administrators |
| Load and unload device drivers | BUILTIN\Administrators |
| Lock pages in memory | |
| Log on as a batch job | BUILTIN\Administrators |
| Manage auditing and security log | BUILTIN\Administrators |
| Modify firmware environment values | BUILTIN\Administrators |
| Perform volume maintenance tasks | BUILTIN\Administrators |
| Profile single process | BUILTIN\Administrators |
| Restore files and directories | BUILTIN\Administrators, BUILTIN\Backup Operators |
| Shut down the system | BUILTIN\Users, BUILTIN\Backup Operators, BUILTIN\Administrators |
| Take ownership of files or other objects | BUILTIN\Administrators |
| Policy | Setting |
|---|---|
| Accounts: Administrator account status | Enabled |
| Accounts: Guest account status | Disabled |
| Accounts: Limit local account use of blank passwords to console logon only | Enabled |
| Accounts: Rename guest account | "!NoUseGuest!" |
| Policy | Setting |
|---|---|
| Audit: Audit the access of global system objects | Disabled |
| Policy | Setting |
|---|---|
| Devices: Allowed to format and eject removable media | Administrators |
| Group | Members | Member of |
|---|---|---|
| S-1-5-21-1834872485-4048471868-719754967-1363 | BUILTIN\Administrators |
| Type | Name | Permission |
|---|---|---|
| Allow | BUILTIN\Administrators | Full Control |
| Allow | NT AUTHORITY\SYSTEM | Full Control |
| Allow | NT AUTHORITY\INTERACTIVE | Read |
| Type | Name | Access |
|---|---|---|
| Failure | Everyone | Full Control |
| Policy | Setting |
|---|---|
| Policy version | Not Configured |
| Disable stateful FTP | Not Configured |
| Disable stateful PPTP | Not Configured |
| IPsec exempt | Not Configured |
| IPsec through NAT | Not Configured |
| Preshared key encoding | Not Configured |
| SA idle time | Not Configured |
| Strong CRL check | Not Configured |
| Policy | Setting |
|---|---|
| Firewall state | On |
| Inbound connections | Not Configured |
| Outbound connections | Not Configured |
| Apply local firewall rules | Not Configured |
| Apply local connection security rules | Not Configured |
| Display notifications | Not Configured |
| Allow unicast responses | Not Configured |
| Log dropped packets | Not Configured |
| Log successful connections | Not Configured |
| Log file path | Not Configured |
| Log file maximum size (KB) | Not Configured |
| Policy | Setting | Comment |
|---|---|---|
| Windows Defender Firewall: Protect all network connections | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Windows Defender Firewall: Protect all network connections | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Hide entry points for Fast User Switching | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not show feedback notifications | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Windows To Go Default Startup Options | Disabled |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System |
| Value name | EnableLUA |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Services\W32Time\Config |
| Value name | MaxAllowedPhaseOffset |
| Value type | REG_DWORD |
| Value data | 0x5 (5) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Services\W32Time\Parameters |
| Value name | Type |
| Value type | REG_SZ |
| Value data | NT5DS |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |