| GR-PO-WIN-C-Global Harden Client | |
| Data collected on: 2-9-2025 08:55:31 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\tentolouris.5 |
| Created | 5-10-2015 16:16:42 |
| Modified | 21-5-2025 09:15:46 |
| User Revisions | 8 (AD), 8 (SYSVOL) |
| Computer Revisions | 577 (AD), 577 (SYSVOL) |
| Unique ID | {828e0b5a-4992-48bc-bc04-6131da58220d} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Clients | No | Enabled | emea.tpg.ads/GR/Systems/Clients |
| Name |
|---|
| NT AUTHORITY\Authenticated Users |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\Domain Computers | Read | No |
| EMEA\GR-G-ORG-OU Admins | Edit settings, delete, modify security | No |
| EMEA\tentolouris.5 | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read (from Security Filtering) | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| S-1-5-21-513466819-3096973226-347852806-203252 | Read | No |
| Policy | Setting |
|---|---|
| Accounts: Limit local account use of blank passwords to console logon only | Enabled |
| Accounts: Rename administrator account | "tpadminlc" |
| Accounts: Rename guest account | "habos" |
| Policy | Setting |
|---|---|
| Audit: Audit the access of global system objects | Disabled |
| Audit: Audit the use of Backup and Restore privilege | Disabled |
| Policy | Setting |
|---|---|
| Devices: Allowed to format and eject removable media | Administrators |
| Devices: Prevent users from installing printer drivers | Enabled |
| Devices: Restrict CD-ROM access to locally logged-on user only | Enabled |
| Devices: Restrict floppy access to locally logged-on user only | Enabled |
| Policy | Setting |
|---|---|
| Domain member: Digitally encrypt secure channel data (when possible) | Enabled |
| Policy | Setting |
|---|---|
| Interactive logon: Do not require CTRL+ALT+DEL | Disabled |
| Interactive logon: Don't display last signed-in | Enabled |
| Interactive logon: Prompt user to change password before expiration | 14 days |
| Policy | Setting |
|---|---|
| Network security: Do not store LAN Manager hash value on next password change | Enabled |
| Policy | Setting |
|---|---|
| Recovery console: Allow automatic administrative logon | Disabled |
| Recovery console: Allow floppy copy and access to all drives and all folders | Disabled |
| Policy | Setting |
|---|---|
| Shutdown: Allow system to be shut down without having to log on | Disabled |
| Shutdown: Clear virtual memory pagefile | Enabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Users | Read and Execute | This folder, subfolders and files |
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read and Execute | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read and Execute | This folder, subfolders and files |
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Policy | Setting | Comment | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Force a specific default lock screen and logon image | Enabled | |||||||||||
| ||||||||||||
| Policy | Setting | Comment | ||||||||||
| Prevent changing lock screen and logon image | Enabled | |||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Allow QUIC protocol | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow QUIC protocol | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow or Disallow use of the Offline Files feature | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Always wait for the network at computer startup and logon | Enabled | |
| Do not display the Getting Started welcome screen at logon | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow Clipboard History | Disabled | |
| Allow Clipboard synchronization across devices | Disabled | |
| Allow publishing of User Activities | Disabled | |
| Allow upload of User Activities | Disabled | |
| Enables Activity Feed | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Select the lid switch action (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Select the lid switch action (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Select the Power button action (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Select the Power button action (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Select the Sleep button action (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Select the Sleep button action (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Select the Start menu Power button action (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Select the Start menu Power button action (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn Off the hard disk (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn Off the hard disk (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Allow applications to prevent automatic sleep (on battery) | Enabled | |||
| Allow applications to prevent automatic sleep (plugged in) | Enabled | |||
| Allow automatic sleep with Open Network Files (on battery) | Disabled | |||
| Allow automatic sleep with Open Network Files (plugged in) | Disabled | |||
| Allow network connectivity during connected-standby (on battery) | Enabled | |||
| Allow network connectivity during connected-standby (plugged in) | Enabled | |||
| Allow standby states (S1-S3) when sleeping (on battery) | Disabled | |||
| Allow standby states (S1-S3) when sleeping (plugged in) | Disabled | |||
| Require a password when a computer wakes (on battery) | Enabled | |||
| Require a password when a computer wakes (plugged in) | Enabled | |||
| Specify the system hibernate timeout (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Specify the system hibernate timeout (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Specify the system sleep timeout (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Specify the system sleep timeout (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Specify the unattended sleep timeout (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Specify the unattended sleep timeout (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn off hybrid sleep (on battery) | Enabled | |||
| Turn off hybrid sleep (plugged in) | Enabled | |||
| Turn on the ability for applications to prevent sleep transitions (on battery) | Enabled | |||
| Turn on the ability for applications to prevent sleep transitions (plugged in) | Enabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Configure Offer Remote Assistance | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Configuration | Enabled | |
| Turn off System Restore | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Download Mode | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off desktop gadgets | Enabled | |
| Turn Off user-installed desktop gadgets | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Show hibernate in the power options menu | Disabled | |
| Show sleep in the power options menu | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Prevent "Fix settings" functionality | Enabled | |||
| Prevent access to Internet Explorer Help | Enabled | |||
| Prevent changing proxy settings | Enabled | |||
| Prevent participation in the Customer Experience Improvement Program | Enabled | |||
| Prevent running First Run wizard | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Intranet Sites: Include all local (intranet) sites not listed in other zones | Enabled | |
| Intranet Sites: Include all network paths (UNCs) | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Microsoft Defender Antivirus | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Enable headless UI mode | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent access to the about:flags page in Microsoft Edge | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow users to connect remotely by using Remote Desktop Services | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent access to feed list | Enabled | |
| Prevent automatic discovery of feeds and Web Slices | Enabled | |
| Prevent downloading of enclosures | Enabled | |
| Prevent subscribing to or deleting a feed or a Web Slice | Enabled | |
| Turn off background synchronization for feeds and Web Slices | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not allow web search | Enabled | |
| Don't search the web or display web results in Search | Enabled | |
| Don't search the web or display web results in Search over metered connections | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Windows Mail application | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not allow Windows Media Center to run | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent Windows Media DRM Internet Access | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not allow Windows Messenger to be run | Enabled | |
| Do not automatically start Windows Messenger initially | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Hide the Account protection area | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent users from modifying settings | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Hide the Device performance and health area | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Disable the Clear TPM button | Enabled | |
| Hide the Device security area | Enabled | |
| Hide the Secure boot area | Enabled | |
| Hide the TPM Firmware Update recommendation. | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Hide the Family options area | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Hide the Firewall and network protection area | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Hide the Ransomware data recovery area | Enabled | |
| Hide the Virus and threat protection area | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Windows SideShow | Enabled |
| Setting | State |
|---|---|
| Software\policies\Microsoft\Windows\DeliveryOptimization\DOMaxUploadBandwidth | 1 |
| Software\policies\Microsoft\Windows\Skydrive\DisableFileSync | 1 |
| Software\policies\Microsoft\Windows\Skydrive\DisableLibrariesDefaultSaveToSkyDrive | 1 |
| Action | Create |
| Source file(s) | \\grkalfs01\netconfigfiles\GlobalSettings\fixlogs.bat |
| Destination file | C:\Windows\Temp\fixlogs.bat |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Disabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Source file(s) | \\grkalfs01\netconfigfiles\GlobalSettings\teams\MSteams-detect-createLT.ps1 |
| Destination file | C:\TPSTUFF\MSteams-detect-createLT.ps1 |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Disabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows Defender |
| Value name | DisableAntiSpyware |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Services\SecurityHealthService |
| Value name | LaunchProtected |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Services\SecurityHealthService |
| Value name | Start |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Services\SecurityHealthService |
| Value name | ServiceSidType |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALLOW_USER32_EXCEPTION_HANDLER_HARDENING |
| Value name | iexplore.exe |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ALLOW_USER32_EXCEPTION_HANDLER_HARDENING |
| Value name | iexplore.exe |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ENABLE_PRINT_INFO_DISCLOSURE_FIX |
| Value name | iexplore.exe |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ENABLE_PRINT_INFO_DISCLOSURE_FIX |
| Value name | iexplore.exe |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\.NETFramework\v2.0.50727 |
| Value name | SchUseStrongCrypto |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v2.0.50727 |
| Value name | SchUseStrongCrypto |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System |
| Value name | EnableFirstLogonAnimation |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_CLASSES_ROOT |
| Key path | ms-msdt |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\*.emea.tpg.ads |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\*.emea.tpg.ads |
| Value name | (Default) |
| Value type | REG_SZ |
| Value data |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\*.tpg.zone |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\*.tpg.zone |
| Value name | (Default) |
| Value type | REG_SZ |
| Value data |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\tpg.ads |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\tpg.ads\grkalfs01.emea |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\tpg.ads\grkalfs01.emea |
| Value name | * |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management |
| Value name | FeatureSettingsOverride |
| Value type | REG_DWORD |
| Value data | 0x48 (72) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management |
| Value name | FeatureSettingsOverrideMask |
| Value type | REG_DWORD |
| Value data | 0x3 (3) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grkalfs01 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grkalfs01 |
| Value name | * |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\tpg.ads |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\tpg.ads |
| Value name | * |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\tpg.ads\emea |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\tpg.ads\emea |
| Value name | * |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\tpg.ads\grkalfs01.emea |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\tpg.ads\grkalfs01.emea |
| Value name | * |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Delete |
| User name | sysprep8 |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Group name | Administrators (built-in) |
| Delete all member users | Disabled |
| Delete all member groups | Disabled |
| EMEA\GR-G-ORG-Remote Admin Users | S-1-5-21-513466819-3096973226-347852806-613115 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Group name | Users (built-in) |
| Delete all member users | Disabled |
| Delete all member groups | Disabled |
| EMEA\GR-G-ORG-Remote Admin Users | S-1-5-21-513466819-3096973226-347852806-613115 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Name | Disable Hibernate EMEA | |||
| Author | EMEA\tentolouris.5 | |||
| Description | ||||
| Run only when user is logged on | ||||
| GroupId | NT AUTHORITY\SYSTEM | |||
| Run with highest privileges | HighestAvailable | |||
| Hidden | Yes | |||
| Configure for | 1.3 | |||
| Enabled | Yes |
| 1. At task creation/modification | ||||
| Enabled | Yes | |||
| 1. Start a program | ||||
| Program/script | C:\Windows\System32\powercfg.exe | |||
| Arguments | /hibernate off |
| Stop if the computer ceases to be idle | No | |||
| Restart if the idle state resumes | No | |||
| Start the task only if the computer is on AC power | No | |||
| Stop if the computer switches to battery power | No | |||
| Wake the computer to run this task | Yes | |||
| Allow task to be run on demand | No | |||
| Run task as soon as possible after a scheduled start is missed | Yes | |||
| Stop task if it runs longer than | Immediately | |||
| If the running task does not end when requested, force it to stop | No | |||
| If the task is already running, then the following rule applies | IgnoreNew |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Name | DesktopBackgroundCopy | |||
| Author | EMEA\tentolouris.5 | |||
| Description | ||||
| Run only when user is logged on | InteractiveToken | |||
| UserId | NT AUTHORITY\System | |||
| Run with highest privileges | HighestAvailable | |||
| Hidden | No | |||
| Configure for | 1.3 | |||
| Enabled | Yes |
| 1. On local connection to user session | ||||
| Delay task for | 1 minute | |||
| Enabled | Yes | |||
| 2. Run at user logon | ||||
| Delay task for | 1 minute | |||
| Enabled | Yes | |||
| 3. On remote connection to user session | ||||
| Delay task for | 1 minute | |||
| Enabled | Yes | |||
| 1. Start a program | ||||
| Program/script | \\grkalfs01.emea.tpg.ads\netconfigfiles\GlobalSettings\DesktopBackground\CopyDesktop.bat | |||
| 2. Start a program | ||||
| Program/script | \\grkalfs01\netconfigfiles\GlobalSettings\DesktopBackground\CopyDesktop.bat | |||
| 3. Start a program | ||||
| Program/script | \\kalfs1.tphellas.legacy\netconfigfiles\GlobalSettings\DesktopBackground\CopyDesktop.bat |
| Stop if the computer ceases to be idle | Yes | |||
| Restart if the idle state resumes | No | |||
| Start the task only if the computer is on AC power | No | |||
| Stop if the computer switches to battery power | No | |||
| Start only if the following network connection is available | Any connection | |||
| Allow task to be run on demand | Yes | |||
| Run task as soon as possible after a scheduled start is missed | Yes | |||
| Stop task if it runs longer than | 1 day | |||
| If the running task does not end when requested, force it to stop | Yes | |||
| If the task is already running, then the following rule applies | StopExisting |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Name | NoCacheLogon | |||
| Author | EMEA\tentolouris.5 | |||
| Description | ||||
| Run only when user is logged on | ||||
| GroupId | NT AUTHORITY\SYSTEM | |||
| Run with highest privileges | HighestAvailable | |||
| Hidden | Yes | |||
| Configure for | 1.3 | |||
| Enabled | Yes |
| 1. Start a program | ||||
| Program/script | \\grkalfs01\netconfigfiles\GlobalSettings\WAHA-NoCachedLogon\PassCacheRunandGun.vbs |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Name | ClearTemplogs | |||
| Author | EMEA\tentolouris.5 | |||
| Description | ||||
| Run only when user is logged on | ||||
| GroupId | NT AUTHORITY\SYSTEM | |||
| Run with highest privileges | HighestAvailable | |||
| Hidden | Yes | |||
| Configure for | 1.3 | |||
| Enabled | Yes |
| 1. Daily | ||||
| Delay task for up to (random delay) | 8 hours | |||
| Stop task if it runs longer than | 2 hours | |||
| Activate | 13-4-2020 09:24:03 | Synchronize across time zones | No | |
| Enabled | Yes | |||
| Recur every 1 days |
| 1. Start a program | ||||
| Program/script | C:\Windows\Temp\fixlogs.bat |
| Stop if the computer ceases to be idle | Yes | |||
| Restart if the idle state resumes | No | |||
| Start the task only if the computer is on AC power | No | |||
| Stop if the computer switches to battery power | Yes | |||
| Allow task to be run on demand | Yes | |||
| Run task as soon as possible after a scheduled start is missed | Yes | |||
| Stop task if it runs longer than | 8 hours | |||
| If the running task does not end when requested, force it to stop | Yes | |||
| If the task is already running, then the following rule applies | StopExisting |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Name | CiscoCert | |||
| Author | EMEA\tentolouris.5 | |||
| Description | ||||
| Run only when user is logged on | ||||
| GroupId | NT AUTHORITY\SYSTEM | |||
| Run with highest privileges | HighestAvailable | |||
| Hidden | Yes | |||
| Configure for | 1.3 | |||
| Enabled | Yes |
| 1. Start a program | ||||
| Program/script | \\grkalfs01\netconfigfiles\GlobalSettings\Setups\Cisco-pbvpn\Cert\proper-import-certificate.bat |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Name | Teams-detectand-create | |||
| Author | EMEA\tentolouris.5-adm | |||
| Description | ||||
| Run only when user is logged on | ||||
| GroupId | NT AUTHORITY\SYSTEM | |||
| Run with highest privileges | HighestAvailable | |||
| Hidden | No | |||
| Configure for | 1.2 | |||
| Enabled | Yes |
| 1. At startup | ||||
| Enabled | Yes | |||
| 1. Start a program | ||||
| Program/script | Powershell.exe | |||
| Arguments | -ExecutionPolicy Bypass C:\TPSTUFF\MSteams-detect-createLT.ps1 |
| Stop if the computer ceases to be idle | No | |||
| Restart if the idle state resumes | No | |||
| Start the task only if the computer is on AC power | No | |||
| Stop if the computer switches to battery power | No | |||
| Allow task to be run on demand | Yes | |||
| Stop task if it runs longer than | Immediately | |||
| If the running task does not end when requested, force it to stop | No | |||
| If the task is already running, then the following rule applies | IgnoreNew |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |