| GR-PO-WIN-C-Global Systems Settings | |
| Data collected on: 2-9-2025 08:55:23 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\tentolouris.5 |
| Created | 24-9-2015 15:44:04 |
| Modified | 28-8-2025 11:24:26 |
| User Revisions | 0 (AD), 0 (SYSVOL) |
| Computer Revisions | 489 (AD), 489 (SYSVOL) |
| Unique ID | {a5a71a8e-eb9b-41a1-be25-2652e771fa02} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Systems | No | Enabled | emea.tpg.ads/GR/Systems |
| Name |
|---|
| NT AUTHORITY\Authenticated Users |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\Domain Computers | Read | No |
| EMEA\GR-G-ORG-OU Admins | Edit settings, delete, modify security | No |
| EMEA\tentolouris.5 | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read (from Security Filtering) | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| S-1-5-21-513466819-3096973226-347852806-203252 | Read | No |
| Policy | Setting |
|---|---|
| Enforce password history | 24 passwords remembered |
| Maximum password age | 60 days |
| Minimum password age | 1 days |
| Minimum password length | 12 characters |
| Password must meet complexity requirements | Enabled |
| Store passwords using reversible encryption | Disabled |
| Policy | Setting |
|---|---|
| Account lockout duration | 60 minutes |
| Account lockout threshold | 6 invalid logon attempts |
| Reset account lockout counter after | 60 minutes |
| Policy | Setting |
|---|---|
| Enforce user logon restrictions | Enabled |
| Maximum lifetime for service ticket | 600 minutes |
| Maximum lifetime for user ticket | 10 hours |
| Maximum lifetime for user ticket renewal | 7 days |
| Maximum tolerance for computer clock synchronization | 99999 minutes |
| Policy | Setting |
|---|---|
| Audit account logon events | Success, Failure |
| Audit account management | Success, Failure |
| Audit directory service access | Success, Failure |
| Audit logon events | Success, Failure |
| Audit object access | No auditing |
| Audit policy change | Success, Failure |
| Audit privilege use | Success, Failure |
| Audit process tracking | Success, Failure |
| Audit system events | Success, Failure |
| Policy | Setting |
|---|---|
| Back up files and directories | EMEA\GR-G-ORG-OU Admins, BUILTIN\Administrators |
| Debug programs | EMEA\GR-G-ORG-OU Admins, BUILTIN\Administrators |
| Deny log on locally | EMEA\GR-G-ORG-Users NO Login to Windows |
| Deny log on through Terminal Services | EMEA\GR-G-ORG-Users NO Login to Windows |
| Manage auditing and security log | EMEA\GR-G-ORG-OU Admins, BUILTIN\Administrators |
| Policy | Setting |
|---|---|
| Accounts: Guest account status | Disabled |
| Policy | Setting |
|---|---|
| Interactive logon: Message text for users attempting to log on | This computer system (including all hardware, software, and peripheral equipment) is, the property of Teleperformance. Use of this computer system is restricted to official, Teleperformance business. Teleperformance reserves the right to monitor use of the, computer system at any time. Use of this system constitutes consent to such monitoring., Any unauthorized access, use, or modification of the computer system can result in civil, liability and/or criminal penalties. |
| Interactive logon: Message title for users attempting to log on | "---------------Teleperformance Hellas---------------" |
| Policy | Setting |
|---|---|
| Microsoft network client: Digitally sign communications (always) | Enabled |
| Microsoft network client: Digitally sign communications (if server agrees) | Enabled |
| Policy | Setting |
|---|---|
| Microsoft network server: Digitally sign communications (always) | Enabled |
| Microsoft network server: Digitally sign communications (if client agrees) | Enabled |
| Policy | Setting |
|---|---|
| Network access: Let Everyone permissions apply to anonymous users | Disabled |
| Policy | Setting |
|---|---|
| Network security: LAN Manager authentication level | Send NTLMv2 response only. Refuse LM & NTLM |
| Policy | Setting |
|---|---|
| Accounts: Block Microsoft accounts | Users can't add or log on with Microsoft accounts |
| Policy | Setting |
|---|---|
| Prevent local guests group from accessing application log | Enabled |
| Prevent local guests group from accessing security log | Enabled |
| Prevent local guests group from accessing system log | Enabled |
| Retain security log | 90 days |
| Retain system log | 90 days |
| Retention method for application log | As needed |
| Retention method for security log | By days |
| Retention method for system log | By days |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Users | Read and Execute | This folder, subfolders and files |
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read and Execute | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Modify | This folder, subfolders and files |
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Users | Modify | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Modify | This folder, subfolders and files |
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Users | Modify | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Modify | This folder, subfolders and files |
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Users | Modify | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Policy | Setting | ||||||
|---|---|---|---|---|---|---|---|
| Automatic certificate management | Enabled | ||||||
| |||||||
| Issued To | Issued By | Expiration Date | Intended Purposes |
|---|---|---|---|
| grathlnxca01 | grathlnxca01 | 25-2-2043 14:31:45 | <All> |
| s800-TPGRDC03-CA | s800-TPGRDC03-CA | 17-9-2025 09:47:28 | <All> |
| Teleperformance Root CA | Teleperformance Root CA | 25-4-2036 18:58:15 | <All> |
| Issued To | Issued By | Expiration Date | Intended Purposes |
|---|---|---|---|
| TP EMEA Enterprise CA | Teleperformance Root CA | 26-4-2026 17:09:38 | <All> |
| Policy | Setting |
|---|---|
| Policy version | 2.22 |
| Disable stateful FTP | Not Configured |
| Disable stateful PPTP | Not Configured |
| IPsec exempt | Not Configured |
| IPsec through NAT | Not Configured |
| Preshared key encoding | Not Configured |
| SA idle time | Not Configured |
| Strong CRL check | Not Configured |
| Policy | Setting |
|---|---|
| Firewall state | Off |
| Inbound connections | Not Configured |
| Outbound connections | Not Configured |
| Apply local firewall rules | Not Configured |
| Apply local connection security rules | Not Configured |
| Display notifications | Not Configured |
| Allow unicast responses | Not Configured |
| Log dropped packets | Not Configured |
| Log successful connections | Not Configured |
| Log file path | Not Configured |
| Log file maximum size (KB) | Not Configured |
| Policy | Setting |
|---|---|
| Firewall state | Off |
| Inbound connections | Not Configured |
| Outbound connections | Not Configured |
| Apply local firewall rules | Not Configured |
| Apply local connection security rules | Not Configured |
| Display notifications | Not Configured |
| Allow unicast responses | Not Configured |
| Log dropped packets | Not Configured |
| Log successful connections | Not Configured |
| Log file path | Not Configured |
| Log file maximum size (KB) | Not Configured |
| Policy | Setting |
|---|---|
| Firewall state | Off |
| Inbound connections | Not Configured |
| Outbound connections | Not Configured |
| Apply local firewall rules | Not Configured |
| Apply local connection security rules | Not Configured |
| Display notifications | Not Configured |
| Allow unicast responses | Not Configured |
| Log dropped packets | Not Configured |
| Log successful connections | Not Configured |
| Log file path | Not Configured |
| Log file maximum size (KB) | Not Configured |
| Policy | Setting |
|---|---|
| Audit Credential Validation | Success, Failure |
| Audit Kerberos Authentication Service | Success, Failure |
| Audit Kerberos Service Ticket Operations | Success, Failure |
| Audit Other Account Logon Events | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Application Group Management | Success, Failure |
| Audit Computer Account Management | Success, Failure |
| Audit Distribution Group Management | Success, Failure |
| Audit Other Account Management Events | Success, Failure |
| Audit Security Group Management | Success, Failure |
| Audit User Account Management | Success, Failure |
| Policy | Setting |
|---|---|
| Audit DPAPI Activity | Success, Failure |
| Audit Process Creation | Success, Failure |
| Audit Process Termination | Success, Failure |
| Audit RPC Events | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Detailed Directory Service Replication | Success, Failure |
| Audit Directory Service Access | Success, Failure |
| Audit Directory Service Changes | Success, Failure |
| Audit Directory Service Replication | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Account Lockout | Success, Failure |
| Audit User / Device Claims | Success, Failure |
| Audit IPsec Extended Mode | Success, Failure |
| Audit IPsec Main Mode | Success, Failure |
| Audit IPsec Quick Mode | Success, Failure |
| Audit Logoff | Success, Failure |
| Audit Logon | Success, Failure |
| Audit Network Policy Server | Success, Failure |
| Audit Other Logon/Logoff Events | Success, Failure |
| Audit Special Logon | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Audit Policy Change | Success, Failure |
| Audit Authentication Policy Change | Success, Failure |
| Audit Authorization Policy Change | Success, Failure |
| Audit Filtering Platform Policy Change | Success, Failure |
| Audit MPSSVC Rule-Level Policy Change | Success, Failure |
| Audit Other Policy Change Events | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Non Sensitive Privilege Use | Success, Failure |
| Audit Other Privilege Use Events | Success, Failure |
| Audit Sensitive Privilege Use | Success, Failure |
| Policy | Setting |
|---|---|
| Audit IPsec Driver | Success, Failure |
| Audit Other System Events | Success, Failure |
| Audit Security State Change | Success, Failure |
| Audit Security System Extension | Success, Failure |
| Audit System Integrity | Success, Failure |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| DNS suffix search list | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Windows Defender Firewall: Protect all network connections | Disabled |
| Policy | Setting | Comment | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Hardened UNC Paths | Enabled | |||||||||||||
| ||||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Display highly detailed status messages | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Set the default behavior for AutoRun | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn off Autoplay | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn off encryption support | Enabled | |||
| ||||
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows Defender |
| Value name | DisableAntiSpyware |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\QualityCompat |
| Value name | cadca5fe-87d3-4b96-b7fb-a231484277cc |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\system_a.exe |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\system_a.exe |
| Value name | Debugger |
| Value type | REG_SZ |
| Value data | "c:\windows\system32\systray.exe" /z |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Name | Lansweeper Scan on Login | |||
| Author | EMEA\tentolouris.5 | |||
| Description | ||||
| Run only when user is logged on | ||||
| GroupId | NT AUTHORITY\SYSTEM | |||
| Run with highest privileges | HighestAvailable | |||
| Hidden | No | |||
| Configure for | 1.3 | |||
| Enabled | Yes |
| 1. Start a program | ||||
| Program/script | \\grkalfs01\netconfigfiles\GlobalSettings\Lansweeper\LansweeperScan.bat |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Name | KMSSet to Local | |||
| Author | EMEA\tentolouris.5 | |||
| Description | ||||
| Run only when user is logged on | ||||
| GroupId | NT AUTHORITY\SYSTEM | |||
| Run with highest privileges | HighestAvailable | |||
| Hidden | No | |||
| Configure for | 1.3 | |||
| Enabled | Yes |
| 1. Run at user logon | ||||
| Delay task for | 30 minutes | |||
| Enabled | Yes | |||
| 2. On workstation lock | ||||
| Enabled | Yes | |||
| 3. At task creation/modification | ||||
| Enabled | Yes | |||
| 1. Start a program | ||||
| Program/script | \\grkalfs01\netconfigfiles\GlobalSettings\KMStoLocal.bat |
| Stop if the computer ceases to be idle | Yes | |||
| Restart if the idle state resumes | No | |||
| Start the task only if the computer is on AC power | No | |||
| Stop if the computer switches to battery power | Yes | |||
| Allow task to be run on demand | Yes | |||
| Stop task if it runs longer than | 3 days | |||
| If the running task does not end when requested, force it to stop | Yes | |||
| If the task is already running, then the following rule applies | IgnoreNew |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Service name | Island Service Agent |
| Action | Stop service |
| Startup type: | Disabled |
| Wait timeout if service is locked: | 30 seconds |
| Log on service as: | No change |
| First failure: | No change |
| Second failure: | No change |
| Subsequent failures: | No change |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Attribute | Value |
|---|---|
| bool | AND |
| not | 0 |
| name | EMEA\GR-L-SEC-Island Service Disable |
| sid | S-1-5-21-513466819-3096973226-347852806-1927121 |
| userContext | 0 |
| primaryGroup | 0 |
| localGroup | 0 |