| GR-PO-SEC-C-WIN 10 COMPUTER POLICIES | |
| Data collected on: 2-9-2025 08:59:01 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\tentolouris.5 |
| Created | 4-7-2016 11:22:42 |
| Modified | 13-1-2025 10:08:04 |
| User Revisions | 0 (AD), 0 (SYSVOL) |
| Computer Revisions | 232 (AD), 232 (SYSVOL) |
| Unique ID | {d06ec331-9cba-4b1a-ab2b-c984b316b39e} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Clients | No | Enabled | emea.tpg.ads/GR/Systems/Clients |
| Name |
|---|
| NT AUTHORITY\Authenticated Users |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\Domain Computers | Read | No |
| EMEA\GR-G-ORG-OU Admins | Edit settings, delete, modify security | No |
| EMEA\tentolouris.5 | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read (from Security Filtering) | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| S-1-5-21-513466819-3096973226-347852806-203252 | Read | No |
| Name | Parameters |
|---|---|
| \\grkalfs01\netconfigfiles\GlobalSettings\LayoutPowershell\LayoutAdd.ps1 |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read and Execute | This folder, subfolders and files |
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | EMEA\GR-G-ORG-IT | Read and Execute | This folder, subfolders and files |
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Users | Read and Execute | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Policy | Setting |
|---|---|
| Enforce rules of this type | False |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Settings Page Visibility | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Select an active power plan | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Select the lid switch action (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Select the lid switch action (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Select the Power button action (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Select the Power button action (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Select the Sleep button action (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Select the Sleep button action (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Select the Start menu Power button action (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Select the Start menu Power button action (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn Off the hard disk (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn Off the hard disk (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Require a password when a computer wakes (on battery) | Enabled | |||
| Require a password when a computer wakes (plugged in) | Enabled | |||
| Specify the system hibernate timeout (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Specify the system hibernate timeout (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Specify the system sleep timeout (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Specify the system sleep timeout (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Specify the unattended sleep timeout (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Specify the unattended sleep timeout (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn off hybrid sleep (plugged in) | Enabled | |||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn off the display (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn off the display (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Prevent the wizard from running. | Enabled |
| Policy | Setting | Comment | ||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Let Windows apps access account information | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access call history | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access contacts | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access email | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access location | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access messaging | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access motion | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access the calendar | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access the camera | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access trusted devices | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps communicate with unpaired devices | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps control radios | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Block launching desktop apps associated with a URI scheme | Enabled | |
| Block launching Universal Windows apps with Windows Runtime API access from hosted content. | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not show Windows tips | Enabled | |
| Turn off Microsoft consumer experiences | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Restrict unpacking and installation of gadgets that are not digitally signed. | Enabled | |
| Turn off desktop gadgets | Enabled | |
| Turn Off user-installed desktop gadgets | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Disable help tips | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Microsoft Defender Antivirus | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent the usage of OneDrive for file storage | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn on Security Center (Domain PCs only) | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Disable all apps from Microsoft Store | Enabled | |
| Turn off Automatic Download and Install of updates | Enabled | |
| Turn off the offer to update to the latest version of Windows | Enabled | |
| Turn off the Store application | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Do not sync | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not sync app settings | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not sync Apps | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not sync browser settings | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not sync desktop personalization | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not sync on metered connections | Enabled | |||
| Do not sync other Windows settings | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not sync passwords | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not sync personalize | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not sync start settings | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Enables or disables Windows Game Recording and Broadcasting | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Allow Windows Ink Workspace | Enabled | |||
| ||||
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\WindowsStore |
| Value name | DisableStoreApps |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | Software\Microsoft\Windows NT\CurrentVersion\MTCUVC |
| Value name | EnableMtcUvc |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate |
| Value name | SetDisablePauseUXAccess |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Name | OneDriveRemove on Login | |||
| Author | EMEA\tentolouris.5 | |||
| Description | ||||
| Run only when user is logged on | ||||
| GroupId | NT AUTHORITY\SYSTEM | |||
| Run with highest privileges | HighestAvailable | |||
| Hidden | No | |||
| Configure for | 1.3 | |||
| Enabled | Yes |
| 1. Start a program | ||||
| Program/script | \\grkalfs01\netconfigfiles\GlobalSettings\Win81\OneDriveRemove.bat |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |