| GR-PO-WIN-C-Servers Extra Hardening | |
| Data collected on: 2-9-2025 09:56:02 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\tentolouris.5-adm |
| Created | 13-4-2021 15:31:12 |
| Modified | 9-2-2023 15:01:44 |
| User Revisions | 0 (AD), 0 (SYSVOL) |
| Computer Revisions | 203 (AD), 203 (SYSVOL) |
| Unique ID | {002c444c-6649-494c-8013-e4e65840e0f3} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Servers | Yes | Enabled | emea.tpg.ads/GR/Systems/Servers |
| Name |
|---|
| EMEA\GR-L-SEC-Servers Extra Hardening |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\Domain Computers | Read | No |
| EMEA\GR-G-ORG-OU Admins | Edit settings, delete, modify security | No |
| EMEA\GR-L-SEC-Servers Extra Hardening | Read (from Security Filtering) | No |
| EMEA\tentolouris.5-adm | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Policy | Setting |
|---|---|
| Account lockout duration | 60 minutes |
| Account lockout threshold | 6 invalid logon attempts |
| Reset account lockout counter after | 30 minutes |
| Policy | Setting |
|---|---|
| Audit object access | Success, Failure |
| Policy | Setting |
|---|---|
| Access this computer from the network | NT AUTHORITY\Authenticated Users, BUILTIN\Administrators |
| Allow log on locally | BUILTIN\Administrators |
| Allow log on through Terminal Services | BUILTIN\Administrators, BUILTIN\Remote Desktop Users |
| Change the system time | BUILTIN\Administrators, NT AUTHORITY\LOCAL SERVICE |
| Create a pagefile | BUILTIN\Administrators |
| Deny access to this computer from the network | BUILTIN\Guests, NT AUTHORITY\ANONYMOUS LOGON |
| Force shutdown from a remote system | BUILTIN\Administrators |
| Increase scheduling priority | BUILTIN\Administrators |
| Load and unload device drivers | BUILTIN\Administrators |
| Lock pages in memory | |
| Manage auditing and security log | BUILTIN\Administrators |
| Modify firmware environment values | BUILTIN\Administrators |
| Perform volume maintenance tasks | BUILTIN\Administrators |
| Profile single process | BUILTIN\Administrators |
| Remove computer from docking station | BUILTIN\Administrators |
| Restore files and directories | BUILTIN\Administrators |
| Shut down the system | BUILTIN\Administrators |
| Take ownership of files or other objects | BUILTIN\Administrators |
| Action | Update |
| Group name | Administrators (built-in) |
| Delete all member users | Disabled |
| Delete all member groups | Disabled |
| EMEA\Domain Admins | S-1-5-21-513466819-3096973226-347852806-512 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Group name | Increase Schedulling priority |
| Description | Increase Schedulling priority |
| Delete all member users | Disabled |
| Delete all member groups | Disabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Group name | Logon as a Service |
| Description | Logon as a Service |
| Delete all member users | Disabled |
| Delete all member groups | Disabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Group name | Logon As Batch |
| Description | Logon As Batch |
| Delete all member users | Disabled |
| Delete all member groups | Disabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Group name | Manage Auditing and Security Log |
| Description | Manage Auditing and Security Log |
| Delete all member users | Disabled |
| Delete all member groups | Disabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Group name | Perform Volume Maintenance Tasks |
| Description | Perform Volume Maintenance Tasks |
| Delete all member users | Disabled |
| Delete all member groups | Disabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |