| GR-PO-ADM-C-MerakiMFA | |
| Data collected on: 2-9-2025 09:47:56 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\tentolouris.5-adm |
| Created | 22-7-2020 11:12:52 |
| Modified | 9-2-2023 14:54:04 |
| User Revisions | 0 (AD), 0 (SYSVOL) |
| Computer Revisions | 45 (AD), 45 (SYSVOL) |
| Unique ID | {861a4702-e4fa-4d63-bb4c-156e060fe186} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Clients | No | Enabled | emea.tpg.ads/GR/Systems/Clients |
| Name |
|---|
| EMEA\GR-G-ORG-Computers Meraki MFA |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\Domain Computers | Read | No |
| EMEA\GR-G-ORG-Computers Meraki MFA | Read (from Security Filtering) | No |
| EMEA\GR-G-ORG-OU Admins | Edit settings, delete, modify security | No |
| EMEA\tentolouris.5-adm | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Name | MerakiMFA |
| Description | Sample Description |
| Setting | Value |
|---|---|
| Use Windows wired LAN network services for clients | Enabled |
| Shared user credentials for network authentication | Enabled |
| Enable use of IEEE 802.1X authentication for network access | Enabled |
| Enforce use of IEEE 802.1X authentication for network access | Disabled |
| Computer Authentication | Computer only |
| Maximum Authentication Failures | 1 |
| Maximum EAPOL-Start Messages Sent | |
| Held Period (seconds) | |
| Start Period (seconds) | |
| Authentication Period (seconds) |
| Authentication method | Protected EAP (PEAP) |
| Validate server certificate | Enabled |
| Connect to these servers | |
| Do not prompt user to authorize new servers or trusted certification authorities | Disabled |
| Enable fast reconnect | Enabled |
| Disconnect if server does not present cryptobinding TLV | Disabled |
| Enforce network access protection | Disabled |
| Authentication method | Secured password (EAP-MSCHAP v2) |
| Automatically use my Windows logon name and password(and domain if any) | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Lsa |
| Value name | LsaAllowReturningUnencryptedSecrets |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Name | SetupMerakiMFA | |||
| Author | EMEA\tentolouris.5 | |||
| Description | ||||
| Run only when user is logged on | ||||
| GroupId | NT AUTHORITY\SYSTEM | |||
| Run with highest privileges | HighestAvailable | |||
| Hidden | Yes | |||
| Configure for | 1.3 | |||
| Enabled | Yes |
| 1. Start a program | ||||
| Program/script | \\grkalfs01\netconfigfiles\GlobalSettings\Setups\Cisco-pbvpn\CiscoNamAndCache.vbs |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |