| GR-PO-ADM-U-Samsung Agent Settings | |
| Data collected on: 2-9-2025 10:01:24 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\pisogiannakis.5-adm |
| Created | 25-8-2021 10:56:02 |
| Modified | 20-2-2025 12:25:00 |
| User Revisions | 183 (AD), 183 (SYSVOL) |
| Computer Revisions | 0 (AD), 0 (SYSVOL) |
| Unique ID | {21d61722-8879-4f9a-b769-ffddd9081a93} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Agents | Yes | Enabled | emea.tpg.ads/GR/Agents |
| Name |
|---|
| EMEA\GR-L-SEC-User Settings Samsung Agent Settings |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\GR-G-ORG-OU Admins | Edit settings, delete, modify security | No |
| EMEA\GR-L-SEC-User Settings Samsung Agent Settings | Read (from Security Filtering) | No |
| EMEA\pisogiannakis.5-adm | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Name | Parameters |
|---|---|
| \\grkalfs01.emea.tpg.ads\netconfigfiles\GlobalSettings\Setups\TP_StopProcess-v2-CopyOnly\CopyStopProc.vbs |
| Name | Parameters |
|---|---|
| \\grkalfs01\GR\Kalithea\Personal\Profiles\Samsung\Logoff-cleanoutscript.vbs |
| Grant user exclusive rights to Contacts | Disabled |
| Move the contents of Contacts to the new location | Disabled |
| Also apply redirection policy to Windows 2000, Windows 2000 server, Windows XP, and Windows Server 2003 operating systems | Disabled |
| Policy Removal Behavior | Leave contents |
| Configuration Control | Group Policy |
| Primary Computer Evaluation | Not evaluated because primary computer policy is not enabled |
| Grant user exclusive rights to Desktop | Disabled |
| Move the contents of Desktop to the new location | Disabled |
| Also apply redirection policy to Windows 2000, Windows 2000 server, Windows XP, and Windows Server 2003 operating systems | Disabled |
| Policy Removal Behavior | Leave contents |
| Configuration Control | Group Policy |
| Primary Computer Evaluation | Not evaluated because primary computer policy is not enabled |
| Grant user exclusive rights to Documents | Disabled |
| Move the contents of Documents to the new location | Disabled |
| Also apply redirection policy to Windows 2000, Windows 2000 server, Windows XP, and Windows Server 2003 operating systems | Disabled |
| Policy Removal Behavior | Leave contents |
| Configuration Control | Group Policy |
| Primary Computer Evaluation | Not evaluated because primary computer policy is not enabled |
| Grant user exclusive rights to Links | Disabled |
| Move the contents of Links to the new location | Disabled |
| Also apply redirection policy to Windows 2000, Windows 2000 server, Windows XP, and Windows Server 2003 operating systems | Disabled |
| Policy Removal Behavior | Leave contents |
| Configuration Control | Group Policy |
| Primary Computer Evaluation | Not evaluated because primary computer policy is not enabled |
| Grant user exclusive rights to Music | Disabled |
| Move the contents of Music to the new location | Disabled |
| Also apply redirection policy to Windows 2000, Windows 2000 server, Windows XP, and Windows Server 2003 operating systems | Disabled |
| Policy Removal Behavior | Leave contents |
| Configuration Control | Group Policy |
| Primary Computer Evaluation | Not evaluated because primary computer policy is not enabled |
| Grant user exclusive rights to Pictures | Disabled |
| Move the contents of Pictures to the new location | Disabled |
| Also apply redirection policy to Windows 2000, Windows 2000 server, Windows XP, and Windows Server 2003 operating systems | Disabled |
| Policy Removal Behavior | Leave contents |
| Configuration Control | Group Policy |
| Primary Computer Evaluation | Not evaluated because primary computer policy is not enabled |
| Grant user exclusive rights to Saved Games | Disabled |
| Move the contents of Saved Games to the new location | Disabled |
| Also apply redirection policy to Windows 2000, Windows 2000 server, Windows XP, and Windows Server 2003 operating systems | Disabled |
| Policy Removal Behavior | Leave contents |
| Configuration Control | Group Policy |
| Primary Computer Evaluation | Not evaluated because primary computer policy is not enabled |
| Grant user exclusive rights to Searches | Disabled |
| Move the contents of Searches to the new location | Disabled |
| Also apply redirection policy to Windows 2000, Windows 2000 server, Windows XP, and Windows Server 2003 operating systems | Disabled |
| Policy Removal Behavior | Leave contents |
| Configuration Control | Group Policy |
| Primary Computer Evaluation | Not evaluated because primary computer policy is not enabled |
| Grant user exclusive rights to Videos | Disabled |
| Move the contents of Videos to the new location | Disabled |
| Also apply redirection policy to Windows 2000, Windows 2000 server, Windows XP, and Windows Server 2003 operating systems | Disabled |
| Policy Removal Behavior | Leave contents |
| Configuration Control | Group Policy |
| Primary Computer Evaluation | Not evaluated because primary computer policy is not enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Enable Bookmark Bar | Enabled | |||
| Managed Bookmarks | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Set download directory | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Allow insecure content on these sites | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Configure the list of force-installed apps and extensions | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Set download directory | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Allow insecure content on specified sites | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Site to Zone Assignment List | Enabled | |||||||||
| ||||||||||
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 |
| Value name | 1004 |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_CURRENT_USER |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce |
| Value name | KnoxMeetingInstallreg |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | Yes |
| Action | Replace |
| Name | KnoxMeetingInstall | |||
| Author | EMEA\tentolouris.5-adm | |||
| Description | ||||
| Run only when user is logged on | InteractiveToken | |||
| UserId | %LogonDomain%\%LogonUser% | |||
| Run with highest privileges | LeastPrivilege | |||
| Hidden | No | |||
| Configure for | 1.3 | |||
| Enabled | Yes |
| 1. Run at user logon | ||||
| Activate | 2-7-2024 16:48:24 | Synchronize across time zones | No | |
| Enabled | Yes | |||
| 1. Start a program | ||||
| Program/script | \\Grkalfs01\gr\Kalithea\Personal\Profiles\Samsung\KnoxMeeting_Install_net4.exe |
| Stop if the computer ceases to be idle | No | |||
| Restart if the idle state resumes | No | |||
| Start the task only if the computer is on AC power | No | |||
| Stop if the computer switches to battery power | No | |||
| Allow task to be run on demand | No | |||
| Stop task if it runs longer than | Immediately | |||
| If the running task does not end when requested, force it to stop | No | |||
| If the task is already running, then the following rule applies | IgnoreNew |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | Yes |
| Attribute | Value |
|---|---|
| bool | AND |
| not | 1 |
| path | %appdata%\Knox Meeting\Knox Meeting\WyzL.exe |
| type | EXISTS |
| folder | 0 |
| Startup options | Start with tabs from the last session |
| Delete browsing history on exit | No |
| Internet | Custom |
| Local Intranet | Custom |
| Trusted | Custom |
| Restricted | High |
| Loose XAML | Disabled |
| XAML browser applications | Disabled |
| XPS documents | Enabled |
| Permissions for components with manifests | High Safety |
| Run components not signed with Authenticode | Enabled |
| Run components signed with Authenticode | Enabled |
| Allow ActiveX Filtering | Enabled |
| Allow previously unused ActiveX controls to run without prompt | Disabled |
| Allow Scriptlets | Disabled |
| Automatic prompting for ActiveX controls | Disabled |
| Binary and script behaviors | Enabled |
| Display video and animation on a webpage that does not use external media player | Disabled |
| Download signed ActiveX controls | Prompt |
| Download unsigned ActiveX controls | Prompt |
| Initialize and script ActiveX controls not marked as safe for Scripting | Disabled |
| Only allow approved domains to use ActiveX without prompt | Disabled |
| Run ActiveX controls and plug-ins | Enabled |
| Script ActiveX controls marked safe for scripting | Enabled |
| File download | Enabled |
| Font download | Enabled |
| Enable .NET Framework setup | Enabled |
| Access data sources across domains | Disabled |
| Render legacy filters | Disabled |
| Allow dragging of content between domains into separate windows | Disabled |
| Allow dragging of content between domains into the same window | Disabled |
| Allow METAREFRESH | Enabled |
| Allow scripting of Internet Explorer web browser control | Disabled |
| Allow script-initiated windows without size or position constraints | Disabled |
| Allow webpages to use restricted protocols for active content | Prompt |
| Allow websites to open windows without address or status bars | Disabled |
| Display mixed content | Prompt |
| Do not prompt for client certificate selection when no certificates or only one certificate exists. | Disabled |
| Drag and drop or copy and paste files | Enabled |
| Enable MIME Sniffing | Enabled |
| Include local directory path when uploading files to server | Disabled |
| Launching applications and unsafe files | Prompt |
| Launching programs and files in an IFRAME | Prompt |
| Navigate sub-frames across different domains | Disabled |
| Submit nonencrypted form data | Enabled |
| Use Phishing Filter | Enabled |
| Use Pop-up Blocker | Enabled |
| Userdata persistence | Enabled |
| Websites in less privileged web content zone can navigate into this zone | Enabled |
| Active scripting | Enabled |
| Allow Programmatic clipboard access | Prompt |
| Allow Status bar updates via script | Disabled |
| Allow websites to prompt for information using scripted windows | Disabled |
| Enable XSS filter | Enabled |
| Scripting of java applets | Enabled |
| User Authentication | Automatic logon only in Intranet zone |
| Enable Protected Mode | Enabled |
| Loose XAML | Enabled |
| XAML browser applications | Enabled |
| XPS documents | Enabled |
| Permissions for components with manifests | High Safety |
| Run components not signed with Authenticode | Enabled |
| Run components signed with Authenticode | Enabled |
| Allow ActiveX Filtering | Disabled |
| Allow previously unused ActiveX controls to run without prompt | Enabled |
| Allow Scriptlets | Enabled |
| Automatic prompting for ActiveX controls | Enabled |
| Binary and script behaviors | Enabled |
| Display video and animation on a webpage that does not use external media player | Disabled |
| Download signed ActiveX controls | Prompt |
| Download unsigned ActiveX controls | Prompt |
| Initialize and script ActiveX controls not marked as safe for Scripting | Disabled |
| Only allow approved domains to use ActiveX without prompt | Enabled |
| Run ActiveX controls and plug-ins | Enabled |
| Script ActiveX controls marked safe for scripting | Enabled |
| File download | Enabled |
| Font download | Enabled |
| Enable .NET Framework setup | Enabled |
| Access data sources across domains | Prompt |
| Render legacy filters | Enabled |
| Allow dragging of content between domains into separate windows | Disabled |
| Allow dragging of content between domains into the same window | Disabled |
| Allow METAREFRESH | Enabled |
| Allow scripting of Internet Explorer web browser control | Enabled |
| Allow script-initiated windows without size or position constraints | Enabled |
| Allow webpages to use restricted protocols for active content | Prompt |
| Allow websites to open windows without address or status bars | Enabled |
| Display mixed content | Prompt |
| Do not prompt for client certificate selection when no certificates or only one certificate exists. | Enabled |
| Drag and drop or copy and paste files | Enabled |
| Enable MIME Sniffing | Enabled |
| Include local directory path when uploading files to server | Enabled |
| Launching applications and unsafe files | Enabled |
| Launching programs and files in an IFRAME | Prompt |
| Navigate sub-frames across different domains | Enabled |
| Submit nonencrypted form data | Enabled |
| Use Phishing Filter | Disabled |
| Use Pop-up Blocker | Disabled |
| Userdata persistence | Enabled |
| Websites in less privileged web content zone can navigate into this zone | Enabled |
| Active scripting | Enabled |
| Allow Programmatic clipboard access | Enabled |
| Allow Status bar updates via script | Enabled |
| Allow websites to prompt for information using scripted windows | Enabled |
| Enable XSS filter | Disabled |
| Scripting of java applets | Enabled |
| User Authentication | Automatic logon only in Intranet zone |
| Enable Protected Mode | Disabled |
| Loose XAML | Enabled |
| XAML browser applications | Enabled |
| XPS documents | Enabled |
| Permissions for components with manifests | High Safety |
| Run components not signed with Authenticode | Enabled |
| Run components signed with Authenticode | Enabled |
| Allow ActiveX Filtering | Enabled |
| Allow previously unused ActiveX controls to run without prompt | Enabled |
| Allow Scriptlets | Disabled |
| Automatic prompting for ActiveX controls | Disabled |
| Binary and script behaviors | Enabled |
| Display video and animation on a webpage that does not use external media player | Disabled |
| Download signed ActiveX controls | Prompt |
| Download unsigned ActiveX controls | Prompt |
| Initialize and script ActiveX controls not marked as safe for Scripting | Disabled |
| Only allow approved domains to use ActiveX without prompt | Enabled |
| Run ActiveX controls and plug-ins | Enabled |
| Script ActiveX controls marked safe for scripting | Enabled |
| File download | Enabled |
| Font download | Enabled |
| Enable .NET Framework setup | Enabled |
| Access data sources across domains | Disabled |
| Render legacy filters | Enabled |
| Allow dragging of content between domains into separate windows | Disabled |
| Allow dragging of content between domains into the same window | Disabled |
| Allow METAREFRESH | Enabled |
| Allow scripting of Internet Explorer web browser control | Disabled |
| Allow script-initiated windows without size or position constraints | Disabled |
| Allow webpages to use restricted protocols for active content | Prompt |
| Allow websites to open windows without address or status bars | Enabled |
| Display mixed content | Prompt |
| Do not prompt for client certificate selection when no certificates or only one certificate exists. | Disabled |
| Drag and drop or copy and paste files | Enabled |
| Enable MIME Sniffing | Enabled |
| Include local directory path when uploading files to server | Enabled |
| Launching applications and unsafe files | Prompt |
| Launching programs and files in an IFRAME | Prompt |
| Navigate sub-frames across different domains | Disabled |
| Submit nonencrypted form data | Enabled |
| Use Phishing Filter | Enabled |
| Use Pop-up Blocker | Enabled |
| Userdata persistence | Enabled |
| Websites in less privileged web content zone can navigate into this zone | Enabled |
| Active scripting | Enabled |
| Allow Programmatic clipboard access | Prompt |
| Allow Status bar updates via script | Enabled |
| Allow websites to prompt for information using scripted windows | Enabled |
| Enable XSS filter | Enabled |
| Scripting of java applets | Enabled |
| User Authentication | Automatic logon only in Intranet zone |
| Enable Protected Mode | Disabled |
| Enable Protected Mode | Enabled |
| Turn on Pop-up Blocker | Enabled |
| Never allow websites to request your physical location | Disabled |
| Disable toolbars and extensions when InPrivate Browsing starts | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |