Group Policy Management
body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } }
Setting Path:
Explanation
No explanation is available for this setting.
Supported On:
Not available
GR-PO-WIN-C-Microsoft CPR PC Settings
Data collected on: 2-9-2025 12:18:52
General
Details
Domainemea.tpg.ads
OwnerEMEA\tentolouris.5-adm
Created5-9-2024 10:15:36
Modified15-4-2025 11:48:18
User Revisions1 (AD), 1 (SYSVOL)
Computer Revisions30 (AD), 30 (SYSVOL)
Unique ID{674d0568-9cfc-4082-8d5c-c9a319d35395}
GPO StatusEnabled
Links
LocationEnforcedLink StatusPath
ClientsYesEnabledemea.tpg.ads/GR/Systems/Clients

This list only includes links in the domain of the GPO.
Security Filtering
The settings in this GPO can only apply to the following groups, users, and computers:
Name
EMEA\GR-L-SEC-Systems Clients MICROSOFT CPR Computers
Delegation
These groups and users have the specified permission for this GPO
NameAllowed PermissionsInherited
EMEA\Domain AdminsEdit settings, delete, modify securityNo
EMEA\Domain ComputersReadNo
EMEA\GR-G-ORG-OU AdminsEdit settings, delete, modify securityNo
EMEA\GR-L-SEC-Systems Clients MICROSOFT CPR ComputersRead (from Security Filtering)No
EMEA\tentolouris.5-admEdit settings, delete, modify securityNo
NT AUTHORITY\Authenticated UsersReadNo
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSReadNo
NT AUTHORITY\SYSTEMEdit settings, delete, modify securityNo
ROOT\Enterprise AdminsEdit settings, delete, modify securityNo
Computer Configuration (Enabled)
Policies
Windows Settings
Scripts
Startup
For this GPO, Script order: Not configured
NameParameters
\\grkalfs01\netconfigfiles\Microsoft\Setups\QuickAssist\copyquickassist.bat
\\grkalfs01\netconfigfiles\Microsoft\Setups\DeleteOneDrive.bat
\\grkalfs01\netconfigfiles\Microsoft\Setups\MSWIN101607\OneDriveRemove.bat
\\grkalfs01\netconfigfiles\Microsoft\Setups\spellcheck\Microsoft_spellcheck.bat
\\grkalfs01\netconfigfiles\Microsoft\MSBackground\CopyDesktop.bat
\\grkalfs01\netconfigfiles\Microsoft\Hosts_file\CopyHostFile_MS_ASD.bat
\\grkalfs01\netconfigfiles\Microsoft\Setups\MSWIN101607\UninstallWin10Apps.ps1
Security Settings
Account Policies/Account Lockout Policy
PolicySetting
Account lockout duration0 minutes
Account lockout threshold6 invalid logon attempts
Reset account lockout counter after15 minutes
File System
%ProgramFiles% (x86)\Avaya
Configure this file or folder then: Propagate inheritable permissions to all subfolders and files
Owner
Permissions
TypeNamePermissionApply To
AllowAPPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGESRead and ExecuteThis folder, subfolders and files
AllowCREATOR OWNERFull ControlSubfolders and files only
AllowNT AUTHORITY\SYSTEMFull ControlThis folder, subfolders and files
AllowBUILTIN\AdministratorsFull ControlThis folder, subfolders and files
AllowBUILTIN\UsersModifyThis folder, subfolders and files
Allow inheritable permissions from the parent to propagate to this object and all child objectsDisabled
Auditing
No auditing specified
Public Key Policies/Trusted Root Certification Authorities
Certificates
Issued ToIssued ByExpiration DateIntended Purposes
WebTitan CloudWebTitan Cloud4-6-2028 16:16:43<All>

For additional information about individual settings, launch the Local Group Policy Object Editor.
Application Control Policies
Appx Rules
PolicySetting
Enforce rules of this typeTrue

ActionUserNameRule TypeExceptions
AllowEveryoneMicrosoft.Windows.ShellExperienceHost, from Microsoft CorporationPublisherNo
AllowEveryoneMicrosoftWindows.Client.CBS, from Microsoft WindowsPublisherNo
AllowEveryoneMicrosoft.Windows.ContentDeliveryManager, from Microsoft CorporationPublisherNo
AllowEveryoneMicrosoftWindows.Client.WebExperience, from Microsoft WindowsPublisherNo
AllowEveryoneMicrosoft.TranslatorforMicrosoftEdge, from Microsoft CorporationPublisherNo
AllowEveryoneMicrosoft.Windows.ContentDeliveryManager, from Microsoft CorporationPublisherNo
AllowEveryoneMicrosoft.BioEnrollment, from Microsoft CorporationPublisherNo
AllowEveryoneMicrosoft.Windows.StartMenuExperienceHost, from ms-resource:StartMenuExperienceHost/PublisherDisplayNamePublisherNo
AllowEveryoneMicrosoftWindows.Client.CBS, from Microsoft WindowsPublisherNo
AllowEveryoneMicrosoft.BioEnrollment, from Microsoft CorporationPublisherNo
Dll Rules
No rules of type 'Dll Rules' are defined.
Executable Rules
PolicySetting
Enforce rules of this typeFalse

ActionUserNameRule TypeExceptions
DenyEMEA\GR-G-ORG-USERS Microsoft ALL T1 AgentsMICROSOFT OFFICE 2016, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=USPublisherNo
DenyEMEA\GR-G-ORG-USERS Microsoft ALL T1 Agents%PROGRAMFILES%\Microsoft Office\*PathNo
AllowEveryone(Default Rule) All files located in the Program Files folderPathNo
AllowEveryone(Default Rule) All files located in the Windows folderPathNo
AllowBUILTIN\Administrators(Default Rule) All filesPathNo
Windows Installer Rules
PolicySetting
Enforce rules of this typeFalse

No rules of type 'Windows Installer Rules' are defined.
Script Rules
PolicySetting
Enforce rules of this typeFalse

No rules of type 'Script Rules' are defined.
Administrative Templates
Policy definitions (ADMX files) retrieved from the central store.
Control Panel
PolicySettingComment
Settings Page VisibilityEnabled
Settings Page Visibility:showonly:display;regionlanguage;mousetouchpad;taskbar;colors;defaultapps;dateandtime;easeofaccess-highcontrast;windowsupdate;network-vpn;developers;personalization-colors;sound;easeofaccess-audio;nightlight;devices-touchpad;about;signinoptions
System/User Profiles
PolicySettingComment
Delete cached copies of roaming profilesEnabled
Delete user profiles older than a specified number of days on system restartEnabled
Delete user profiles older than (days)30
PolicySettingComment
Do not log users on with temporary profilesEnabled
Windows Components/App Package Deployment
PolicySettingComment
Allow all trusted apps to installEnabled
Allows development of Windows Store apps and installing them from an integrated development environment (IDE)Enabled
Windows Components/Microsoft Edge
PolicySettingComment
Allow ExtensionsEnabled
Windows Components/Windows Update/Manage updates offered from Windows Server Update Service
PolicySettingComment
Enable client-side targetingEnabled
Target group name for this computerMicrosoft
Preferences
Windows Settings
Files
File (Target Path: C:\ProgramData\TPBackground\MSCopilotProTeamsBackground.jpg)
MSCopilotProTeamsBackground.jpg (Order: 1)
General
ActionUpdate
Properties
Source file(s)\\grkalfs01\netconfigfiles\Microsoft\MSBackground\MSCopilotProTeamsBackground.jpg
Destination fileC:\ProgramData\TPBackground\MSCopilotProTeamsBackground.jpg
Suppress errors on individual file actionsDisabled
Attributes
Read-onlyDisabled
HiddenDisabled
ArchiveEnabled
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Control Panel Settings
Local Users and Groups
Group (Name: Users (built-in))
Users (built-in) (Order: 1)
Local Group
ActionUpdate
Properties
Group nameUsers (built-in)
Delete all member usersDisabled
Delete all member groupsEnabled
Add members
EMEA\GR-G-ORG-Remote Admin UsersS-1-5-21-513466819-3096973226-347852806-613115
EMEA\GR-G-ORG-USERS MICROSOFT CPR AGENTSS-1-5-21-513466819-3096973226-347852806-1687701
EMEA\GR-G-ORG-USERS Microsoft SLAM AccessS-1-5-21-513466819-3096973226-347852806-722924
tpadmin
Remove members
EMEA\uwmtask.2S-1-5-21-513466819-3096973226-347852806-813771
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Group (Name: Administrators (built-in))
Administrators (built-in) (Order: 2)
Local Group
ActionUpdate
Properties
Group nameAdministrators (built-in)
Delete all member usersDisabled
Delete all member groupsEnabled
Add members
EMEA\GR-G-ORG-Remote Admin UsersS-1-5-21-513466819-3096973226-347852806-613115
Remove members
EMEA\uwmtask.2S-1-5-21-513466819-3096973226-347852806-813771
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Scheduled Tasks
Scheduled Task (At least Windows 7) (Name: InstallVisioVWR)
InstallVisioVWR (Order: 1)
General
ActionCreate
Task
Name InstallVisioVWR
Author EMEA\tentolouris.5
Description
Run only when user is logged on
GroupId NT AUTHORITY\SYSTEM
Run with highest privileges HighestAvailable
Hidden Yes
Configure for 1.3
Enabled Yes
Triggers
1. At task creation/modification
Activate 16-6-2020 12:44:32Synchronize across time zones No
Enabled Yes
Actions
1. Start a program
Program/script \\kalfs1.tphellas.legacy\netconfigfiles\Microsoft\Setups\visiovwrinstall.bat
Settings
Stop if the computer ceases to be idle Yes
Restart if the idle state resumes No
Start the task only if the computer is on AC power No
Stop if the computer switches to battery power Yes
Allow task to be run on demand Yes
Stop task if it runs longer than 8 hours
If the running task does not end when requested, force it to stop Yes
If the task is already running, then the following rule applies StopExisting
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyYes
Scheduled Task (At least Windows 7) (Name: Perform Updates)
Perform Updates (Order: 2)
General
ActionCreate
Task
Name Perform Updates
Author EMEA\tentolouris.5
Description
Run only when user is logged on
GroupId NT AUTHORITY\SYSTEM
Run with highest privileges HighestAvailable
Hidden Yes
Configure for 1.3
Enabled Yes
Triggers
1. At startup
Enabled Yes
Actions
1. Start a program
Program/script \\grkalfs01\netconfigfiles\GlobalSettings\WindowsUpdate-Forced\caller.bat
Settings
Stop if the computer ceases to be idle Yes
Restart if the idle state resumes No
Start the task only if the computer is on AC power No
Stop if the computer switches to battery power Yes
Allow task to be run on demand Yes
Stop task if it runs longer than 8 hours
If the running task does not end when requested, force it to stop Yes
If the task is already running, then the following rule applies StopExisting
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Scheduled Task (At least Windows 7) (Name: Uninstall PAPopup)
Uninstall PAPopup (Order: 3)
General
ActionCreate
Task
Name Uninstall PAPopup
Author EMEA\tentolouris.5
Description
Run only when user is logged on
GroupId NT AUTHORITY\SYSTEM
Run with highest privileges HighestAvailable
Hidden Yes
Configure for 1.3
Enabled Yes
Triggers
1. One time
Activate 22-3-2021 12:45:22Synchronize across time zones No
Expire 31-3-2021 10:45:18Synchronize across time zones No
Enabled Yes
Actions
1. Start a program
Program/script MsiExec.exe
Arguments /QN /NORESTART /X{942FF230-40D4-4105-951C-3612BA1DB948}
Settings
Stop if the computer ceases to be idle Yes
Restart if the idle state resumes No
Start the task only if the computer is on AC power No
Stop if the computer switches to battery power Yes
Allow task to be run on demand Yes
Run task as soon as possible after a scheduled start is missed Yes
Stop task if it runs longer than 8 hours
If the running task does not end when requested, force it to stop Yes
If the task is already running, then the following rule applies StopExisting
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Scheduled Task (At least Windows 7) (Name: Host_File_Copyv2)
Host_File_Copyv2 (Order: 4)
General
ActionUpdate
Task
Name Host_File_Copyv2
Author EMEA\tentolouris.5
Description
Run only when user is logged on
GroupId NT AUTHORITY\SYSTEM
Run with highest privileges HighestAvailable
Hidden No
Configure for 1.3
Enabled Yes
Triggers
1. Run at user logon
Delay task for 30 seconds
Repeat task every 5 minutes for a duration of 1 hour
Stop all running tasks at end of repetition duration No
Activate 6-4-2020 14:33:02Synchronize across time zones No
Enabled Yes
Actions
1. Start a program
Program/script \\grkalfs01\netconfigfiles\Microsoft\Hosts_file\CopyHostFile_MS_ASD.bat
Settings
Stop if the computer ceases to be idle Yes
Restart if the idle state resumes No
Start the task only if the computer is on AC power No
Stop if the computer switches to battery power Yes
Allow task to be run on demand Yes
Stop task if it runs longer than 3 days
If the running task does not end when requested, force it to stop Yes
If the task is already running, then the following rule applies IgnoreNew
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Scheduled Task (At least Windows 7) (Name: Uninstall LMI)
Uninstall LMI (Order: 5)
General
ActionUpdate
Task
Name Uninstall LMI
Author EMEA\tentolouris.5-adm
Description
Run only when user is logged on
GroupId NT AUTHORITY\SYSTEM
Run with highest privileges HighestAvailable
Hidden No
Configure for 1.2
Enabled Yes
Triggers
1. One time
Delay task for up to (random delay) 1 day
Activate 17-11-2021 13:35:29Synchronize across time zones No
Expire 2-1-2022 13:38:46Synchronize across time zones No
Enabled Yes
Actions
1. Start a program
Program/script C:\Windows\System32\msiexec.exe
Arguments /QN /NORESTART /X{5BC2AFD7-1C94-4FC6-8B0A-5B9D6C1E983D}
2. Start a program
Program/script C:\Windows\System32\msiexec.exe
Arguments /QN /NORESTART /X{430B9AB3-4071-45B9-9372-57BA3454BC53}
3. Start a program
Program/script C:\Windows\System32\msiexec.exe
Arguments /QN /NORESTART /X{2897AFD7-567D-437A-ACD4-981ED76BC95B}
4. Start a program
Program/script C:\Windows\System32\msiexec.exe
Arguments /QN /NORESTART /X{A2AF44DC-528E-4A70-A3D6-8C4C4AEDDB7C}
Settings
Stop if the computer ceases to be idle No
Restart if the idle state resumes No
Start the task only if the computer is on AC power No
Stop if the computer switches to battery power No
Allow task to be run on demand Yes
Run task as soon as possible after a scheduled start is missed Yes
Stop task if it runs longer than Immediately
If the running task does not end when requested, force it to stop No
If the task is not scheduled to run again, delete it after 30 days
If the task is already running, then the following rule applies IgnoreNew
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Scheduled Task (At least Windows 7) (Name: Office StartUP update)
Office StartUP update (Order: 6)
General
ActionUpdate
Task
Name Office StartUP update
Author EMEA\tentolouris.5-adm
Description
Run only when user is logged on
GroupId NT AUTHORITY\SYSTEM
Run with highest privileges HighestAvailable
Hidden No
Configure for 1.2
Enabled Yes
Triggers
1. At startup
Enabled Yes
Actions
1. Start a program
Program/script C:\Windows\System32\cmd.exe
Arguments /c if exist "C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe" ( "C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe" /update user displaylevel=false forceappshutdown=true )
Settings
Stop if the computer ceases to be idle No
Restart if the idle state resumes No
Start the task only if the computer is on AC power No
Stop if the computer switches to battery power No
Allow task to be run on demand No
Stop task if it runs longer than Immediately
If the running task does not end when requested, force it to stop No
If the task is already running, then the following rule applies IgnoreNew
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
User Configuration (Enabled)
No settings defined.