Group Policy Management
body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } }
Setting Path:
Explanation
No explanation is available for this setting.
Supported On:
Not available
GR-PO-WIN-C-Facebook PC Settings
Data collected on: 2-9-2025 09:15:32
General
Details
Domainemea.tpg.ads
OwnerEMEA\tentolouris.5
Created30-7-2018 10:11:46
Modified23-10-2024 13:51:06
User Revisions4 (AD), 4 (SYSVOL)
Computer Revisions223 (AD), 223 (SYSVOL)
Unique ID{b76f29e9-781f-41ff-a2cb-8996cf318a9f}
GPO StatusEnabled
Links
LocationEnforcedLink StatusPath
ClientsYesEnabledemea.tpg.ads/GR/Systems/Clients

This list only includes links in the domain of the GPO.
Security Filtering
The settings in this GPO can only apply to the following groups, users, and computers:
Name
EMEA\GR-L-SEC-Systems Clients Facebook Computers
Delegation
These groups and users have the specified permission for this GPO
NameAllowed PermissionsInherited
EMEA\Domain AdminsEdit settings, delete, modify securityNo
EMEA\Domain ComputersReadNo
EMEA\GR-G-ORG-OU AdminsEdit settings, delete, modify securityNo
EMEA\GR-L-SEC-Systems Clients Facebook ComputersRead (from Security Filtering)No
EMEA\tentolouris.5Edit settings, delete, modify securityNo
NT AUTHORITY\Authenticated UsersReadNo
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSReadNo
NT AUTHORITY\SYSTEMEdit settings, delete, modify securityNo
ROOT\Enterprise AdminsEdit settings, delete, modify securityNo
Computer Configuration (Enabled)
Policies
Windows Settings
Scripts
Startup
For this GPO, Script order: Not configured
NameParameters
\\grkalfs01.emea.tpg.ads\netconfigfiles\Facebook\Regional\Regional.bat
\\grkalfs01.emea.tpg.ads\netconfigfiles\Facebook\Regional\Regionalreg.vbs
\\grkalfs01.emea.tpg.ads\netconfigfiles\Facebook\NetCacheFormatDatabase.bat
\\grkalfs01\netconfigfiles\Facebook\NetCacheFormatDatabase.bat
Shutdown
For this GPO, Script order: Not configured
NameParameters
\\grkalfs01.emea.tpg.ads\netconfigfiles\Facebook\NetCacheFormatDatabase.bat
\\grkalfs01\netconfigfiles\Facebook\NetCacheFormatDatabase.bat
Security Settings
Account Policies/Password Policy
PolicySetting
Maximum password age60 days
Minimum password age3 days
Minimum password length12 characters
Local Policies/Security Options
Domain Member
PolicySetting
Domain member: Digitally encrypt or sign secure channel data (always)Enabled
Domain member: Digitally encrypt secure channel data (when possible)Enabled
Domain member: Digitally sign secure channel data (when possible)Enabled
Administrative Templates
Policy definitions (ADMX files) retrieved from the central store.
Google/Google Chrome
PolicySettingComment
Use hardware acceleration when availableDisabled
Windows Components/App Privacy
PolicySettingComment
Let Windows apps access the cameraEnabled
Default for all apps:User is in control
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
PolicySettingComment
Let Windows apps access the microphoneEnabled
Default for all apps:User is in control
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
Windows Components/File Explorer
PolicySettingComment
Set a default associations configuration fileEnabled
Default Associations Configuration File\\grkalfs01.emea.tpg.ads\netconfigfiles\Facebook\default_apps.xml
Windows Components/Windows Update/Manage updates offered from Windows Server Update Service
PolicySettingComment
Enable client-side targetingEnabled
Target group name for this computerFacebook
Preferences
Windows Settings
Registry
ms-msdt (Order: 1)
General
ActionDelete
Properties
HiveHKEY_CLASSES_ROOT
Key pathms-msdt
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Apply once and do not reapplyNo
Collection: Registry Wizard Values/HKEY_LOCAL_MACHINE/SOFTWARE/TP
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Apply once and do not reapplyNo
Registry item: TP
General
ActionUpdate
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSOFTWARE\TP
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Collection: Registry Wizard Values/HKEY_LOCAL_MACHINE/SOFTWARE/TP/Hardening
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Apply once and do not reapplyNo
Registry item: Hardening
General
ActionUpdate
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSOFTWARE\TP\Hardening
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Registry item: Version_Q4_2019
General
ActionDelete
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSOFTWARE\TP\Hardening
Value nameVersion_Q4_2019
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Apply once and do not reapplyNo
Registry item: Ticket_285411
General
ActionDelete
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSOFTWARE\TP\Hardening
Value nameTicket_285411
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Apply once and do not reapplyNo
Registry item: Reviewed_by_Stavropoulos Nikos
General
ActionDelete
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSOFTWARE\TP\Hardening
Value nameReviewed_by_Stavropoulos Nikos
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Apply once and do not reapplyNo
Registry item: Performed_by_Pisogiannakis Konstantinos
General
ActionDelete
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSOFTWARE\TP\Hardening
Value namePerformed_by_Pisogiannakis Konstantinos
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Apply once and do not reapplyNo
Registry item: File_name_Facebook_Master_Image_Q4_2019
General
ActionDelete
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSOFTWARE\TP\Hardening
Value nameFile_name_Facebook_Master_Image_Q4_2019
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Apply once and do not reapplyNo
Registry item: Creation_Date_31_10_2019
General
ActionDelete
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSOFTWARE\TP\Hardening
Value nameCreation_Date_31_10_2019
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Apply once and do not reapplyNo
Registry item: Approved_by_Kapodistrias_Thomas
General
ActionDelete
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSOFTWARE\TP\Hardening
Value nameApproved_by_Kapodistrias_Thomas
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Apply once and do not reapplyNo
Control Panel Settings
Local Users and Groups
Group (Name: Users (built-in))
Users (built-in) (Order: 1)
Local Group
ActionUpdate
Properties
Group nameUsers (built-in)
Delete all member usersDisabled
Delete all member groupsEnabled
Add members
EMEA\GR-G-ORG-Remote Admin UsersS-1-5-21-513466819-3096973226-347852806-613115
tpadmin
EMEA\GR-G-ORG-USERS Facebook SLAM AccessS-1-5-21-513466819-3096973226-347852806-1318105
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Group (Name: Administrators (built-in))
Administrators (built-in) (Order: 2)
Local Group
ActionUpdate
Properties
Group nameAdministrators (built-in)
Delete all member usersDisabled
Delete all member groupsEnabled
Add members
EMEA\GR-G-ORG-Remote Admin UsersS-1-5-21-513466819-3096973226-347852806-613115
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Scheduled Tasks
Scheduled Task (At least Windows 7) (Name: Remove all profile)
Remove all profile (Order: 1)
General
ActionUpdate
Task
Name Remove all profile
Author EMEA\lewke.7
Description Remove all profile
Run only when user is logged on InteractiveToken
UserId NT AUTHORITY\System
Run with highest privileges HighestAvailable
Hidden No
Configure for 1.2
Enabled Yes
Triggers
1. Run at user logon
Enabled Yes
Actions
1. Start a program
Program/script Powershell.exe
Arguments -ExecutionPolicy Bypass \\grkalfs01\netconfigfiles\Facebook\RemoveUserAccount.ps1
2. Start a program
Program/script \\grkalfs01.emea.tpg.ads\netconfigfiles\Facebook\NetCacheFormatDatabase.bat
3. Start a program
Program/script \\grkalfs01\netconfigfiles\Facebook\NetCacheFormatDatabase.bat
Settings
Stop if the computer ceases to be idle No
Restart if the idle state resumes No
Start the task only if the computer is on AC power No
Stop if the computer switches to battery power No
Allow task to be run on demand Yes
Run task as soon as possible after a scheduled start is missed Yes
Stop task if it runs longer than Immediately
If the running task does not end when requested, force it to stop No
If the task is already running, then the following rule applies IgnoreNew
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Scheduled Task (At least Windows 7) (Name: CiscoCert)
CiscoCert (Order: 2)
General
ActionDelete
Task
Name CiscoCert
Author EMEA\tentolouris.5
Description
Run only when user is logged on
GroupId NT AUTHORITY\SYSTEM
Run with highest privileges HighestAvailable
Hidden Yes
Configure for 1.3
Enabled Yes
Actions
1. Start a program
Program/script \\grkalfs01\netconfigfiles\GlobalSettings\Setups\Cisco-pbvpn\Cert\proper-import-certificate.bat
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Apply once and do not reapplyNo
Scheduled Task (At least Windows 7) (Name: ReadCache)
ReadCache (Order: 3)
General
ActionDelete
Task
Name ReadCache
Author EMEA\tentolouris.5
Description
Run only when user is logged on
GroupId NT AUTHORITY\SYSTEM
Run with highest privileges HighestAvailable
Hidden Yes
Configure for 1.3
Enabled Yes
Actions
1. Start a program
Program/script \\grkalfs01\netconfigfiles\GlobalSettings\WAHA-NoCachedLogon\ReadCache.vbs
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Apply once and do not reapplyNo
Scheduled Task (At least Windows 7) (Name: Remove_MS3DViewer)
Remove_MS3DViewer (Order: 4)
General
ActionUpdate
Task
Name Remove_MS3DViewer
Author EMEA\tentolouris.5
Description
Run only when user is logged on
GroupId NT AUTHORITY\SYSTEM
Run with highest privileges HighestAvailable
Hidden No
Configure for 1.3
Enabled Yes
Triggers
1. Run at user logon
Delay task for 30 seconds
Repeat task every 5 minutes for a duration of 30 minutes
Stop all running tasks at end of repetition duration No
Activate 26-3-2021 17:00:02Synchronize across time zones No
Enabled Yes
2. At task creation/modification
Enabled Yes
Actions
1. Start a program
Program/script Powershell.exe
Arguments -ExecutionPolicy Bypass \\grkalfs01\netconfigfiles\GlobalSettings\Setups\RemoveMS3DViewerAPPX\Uninstall_MS3DViewerAPPX.ps1
Settings
Stop if the computer ceases to be idle Yes
Restart if the idle state resumes No
Start the task only if the computer is on AC power No
Stop if the computer switches to battery power Yes
Allow task to be run on demand Yes
Run task as soon as possible after a scheduled start is missed Yes
Stop task if it runs longer than 3 days
If the running task does not end when requested, force it to stop Yes
If the task is already running, then the following rule applies IgnoreNew
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Scheduled Task (At least Windows 7) (Name: Remove_Uninstall_Microsoft.MSPaint)
Remove_Uninstall_Microsoft.MSPaint (Order: 5)
General
ActionUpdate
Task
Name Remove_Uninstall_Microsoft.MSPaint
Author EMEA\tentolouris.5
Description
Run only when user is logged on
GroupId NT AUTHORITY\SYSTEM
Run with highest privileges HighestAvailable
Hidden No
Configure for 1.3
Enabled Yes
Triggers
1. Run at user logon
Delay task for 30 seconds
Repeat task every 5 minutes for a duration of 30 minutes
Stop all running tasks at end of repetition duration No
Activate 26-3-2021 17:00:02Synchronize across time zones No
Enabled Yes
2. At task creation/modification
Enabled Yes
Actions
1. Start a program
Program/script Powershell.exe
Arguments -ExecutionPolicy Bypass \\grkalfs01.emea.tpg.ads\netconfigfiles\GlobalSettings\Setups\RemoveAPPX\Uninstall_Microsoft.MSPaint.ps1
Settings
Stop if the computer ceases to be idle Yes
Restart if the idle state resumes No
Start the task only if the computer is on AC power No
Stop if the computer switches to battery power Yes
Allow task to be run on demand Yes
Run task as soon as possible after a scheduled start is missed Yes
Stop task if it runs longer than 3 days
If the running task does not end when requested, force it to stop Yes
If the task is already running, then the following rule applies IgnoreNew
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Scheduled Task (At least Windows 7) (Name: Remove_Uninstall_VP9VideoExtensions)
Remove_Uninstall_VP9VideoExtensions (Order: 6)
General
ActionUpdate
Task
Name Remove_Uninstall_VP9VideoExtensions
Author EMEA\tentolouris.5
Description
Run only when user is logged on
GroupId NT AUTHORITY\SYSTEM
Run with highest privileges HighestAvailable
Hidden No
Configure for 1.3
Enabled Yes
Triggers
1. Run at user logon
Delay task for 30 seconds
Repeat task every 5 minutes for a duration of 30 minutes
Stop all running tasks at end of repetition duration No
Activate 26-3-2021 17:00:02Synchronize across time zones No
Enabled Yes
2. At task creation/modification
Enabled Yes
Actions
1. Start a program
Program/script Powershell.exe
Arguments -ExecutionPolicy Bypass \\grkalfs01.emea.tpg.ads\netconfigfiles\GlobalSettings\Setups\RemoveAPPX\Uninstall_VP9VideoExtensions.ps1
Settings
Stop if the computer ceases to be idle Yes
Restart if the idle state resumes No
Start the task only if the computer is on AC power No
Stop if the computer switches to battery power Yes
Allow task to be run on demand Yes
Run task as soon as possible after a scheduled start is missed Yes
Stop task if it runs longer than 3 days
If the running task does not end when requested, force it to stop Yes
If the task is already running, then the following rule applies IgnoreNew
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Scheduled Task (At least Windows 7) (Name: Remove_Uninstall_WebMediaExtensions)
Remove_Uninstall_WebMediaExtensions (Order: 7)
General
ActionUpdate
Task
Name Remove_Uninstall_WebMediaExtensions
Author EMEA\tentolouris.5
Description
Run only when user is logged on
GroupId NT AUTHORITY\SYSTEM
Run with highest privileges HighestAvailable
Hidden No
Configure for 1.3
Enabled Yes
Triggers
1. Run at user logon
Delay task for 30 seconds
Repeat task every 5 minutes for a duration of 30 minutes
Stop all running tasks at end of repetition duration No
Activate 26-3-2021 17:00:02Synchronize across time zones No
Enabled Yes
2. At task creation/modification
Enabled Yes
Actions
1. Start a program
Program/script Powershell.exe
Arguments -ExecutionPolicy Bypass \\grkalfs01.emea.tpg.ads\netconfigfiles\GlobalSettings\Setups\RemoveAPPX\Uninstall_WebMediaExtensions.ps1
Settings
Stop if the computer ceases to be idle Yes
Restart if the idle state resumes No
Start the task only if the computer is on AC power No
Stop if the computer switches to battery power Yes
Allow task to be run on demand Yes
Run task as soon as possible after a scheduled start is missed Yes
Stop task if it runs longer than 3 days
If the running task does not end when requested, force it to stop Yes
If the task is already running, then the following rule applies IgnoreNew
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Scheduled Task (At least Windows 7) (Name: Remove_Uninstall_WebpImageExtension)
Remove_Uninstall_WebpImageExtension (Order: 8)
General
ActionUpdate
Task
Name Remove_Uninstall_WebpImageExtension
Author EMEA\tentolouris.5
Description
Run only when user is logged on
GroupId NT AUTHORITY\SYSTEM
Run with highest privileges HighestAvailable
Hidden No
Configure for 1.3
Enabled Yes
Triggers
1. Run at user logon
Delay task for 30 seconds
Repeat task every 5 minutes for a duration of 30 minutes
Stop all running tasks at end of repetition duration No
Activate 26-3-2021 17:00:02Synchronize across time zones No
Enabled Yes
2. At task creation/modification
Enabled Yes
Actions
1. Start a program
Program/script Powershell.exe
Arguments -ExecutionPolicy Bypass \\grkalfs01.emea.tpg.ads\netconfigfiles\GlobalSettings\Setups\RemoveAPPX\Uninstall_WebpImageExtension.ps1
Settings
Stop if the computer ceases to be idle Yes
Restart if the idle state resumes No
Start the task only if the computer is on AC power No
Stop if the computer switches to battery power Yes
Allow task to be run on demand Yes
Run task as soon as possible after a scheduled start is missed Yes
Stop task if it runs longer than 3 days
If the running task does not end when requested, force it to stop Yes
If the task is already running, then the following rule applies IgnoreNew
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Scheduled Task (At least Windows 7) (Name: Office StartUP update)
Office StartUP update (Order: 9)
General
ActionUpdate
Task
Name Office StartUP update
Author EMEA\tentolouris.5-adm
Description
Run only when user is logged on
GroupId NT AUTHORITY\SYSTEM
Run with highest privileges HighestAvailable
Hidden No
Configure for 1.2
Enabled Yes
Triggers
1. At startup
Enabled Yes
Actions
1. Start a program
Program/script C:\Windows\System32\cmd.exe
Arguments /c if exist "C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe" ( "C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe" /update user displaylevel=false forceappshutdown=true )
Settings
Stop if the computer ceases to be idle No
Restart if the idle state resumes No
Start the task only if the computer is on AC power No
Stop if the computer switches to battery power No
Allow task to be run on demand No
Stop task if it runs longer than Immediately
If the running task does not end when requested, force it to stop No
If the task is already running, then the following rule applies IgnoreNew
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
User Configuration (Enabled)
No settings defined.