Group Policy Management
body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } }
Setting Path:
Explanation
No explanation is available for this setting.
Supported On:
Not available
GR-PO-WIN-C-Yubikey Block
Data collected on: 2-9-2025 09:58:29
General
Details
Domainemea.tpg.ads
OwnerEMEA\tentolouris.5-adm
Created11-6-2021 10:32:50
Modified9-2-2023 15:03:58
User Revisions0 (AD), 0 (SYSVOL)
Computer Revisions17 (AD), 17 (SYSVOL)
Unique ID{2432a674-efb3-4da5-b627-365d16b1f0bd}
GPO StatusEnabled
Links
LocationEnforcedLink StatusPath
ClientsYesEnabledemea.tpg.ads/GR/Systems/Clients

This list only includes links in the domain of the GPO.
Security Filtering
The settings in this GPO can only apply to the following groups, users, and computers:
Name
EMEA\GR-L-SEC-Yubikey Block
Delegation
These groups and users have the specified permission for this GPO
NameAllowed PermissionsInherited
EMEA\Domain AdminsEdit settings, delete, modify securityNo
EMEA\Domain ComputersReadNo
EMEA\GR-G-ORG-OU AdminsEdit settings, delete, modify securityNo
EMEA\GR-L-SEC-Yubikey BlockRead (from Security Filtering)No
EMEA\tentolouris.5-admEdit settings, delete, modify securityNo
NT AUTHORITY\Authenticated UsersReadNo
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSReadNo
NT AUTHORITY\SYSTEMEdit settings, delete, modify securityNo
ROOT\Enterprise AdminsEdit settings, delete, modify securityNo
Computer Configuration (Enabled)
Policies
Administrative Templates
Policy definitions (ADMX files) retrieved from the central store.
System/Device Installation/Device Installation Restrictions
PolicySettingComment
Prevent installation of devices that match any of these device IDsEnabled
Prevent installation of devices that match any of these Device IDs:
USB\VID_1050&PID_0407&MI_02
USB\VID_0A5C&PID_5843&MI_01
USB\VID_1050&PID_0407&MI_01
USB\VID_1050&PID_0407&MI_00
HID\VID_1050&PID_0407&MI_01
HID\VID_1050&UP:F1D0_U:0001
USB\VID_1050
HID\VID_1050
SCFILTER\CID_597562696b657934
SCFILTER\CID_8073c021c057597562694b6579
To create a list of devices, click Show. In the Show Contents dialog box, in the Value column,
type a Plug and Play hardware ID or compatible ID
(for example, gendisk, USB\COMPOSITE, USB\Class_ff).
Also apply to matching devices that are already installed.Enabled
PolicySettingComment
Prevent installation of devices using drivers that match these device setup classesEnabled
Prevent installation of devices using drivers for these device setup classes:
{990a2bd7-e738-46c7-b26f-1cf8fb9f1391}
To create a list of device classes, click Show. In the Show Contents dialog box, in the Value column,
type a GUID that represents a device setup class
(for example, {25DBCE51-6C8F-4A72-8A6D-B54C2B4FC835}).
Also apply to matching devices that are already installed.Enabled
System/Removable Storage Access
PolicySettingComment
Custom Classes: Deny read accessEnabled
Enter GUID in format {xxxxxxxx-xxxx-xxxx-xxxxxxxxxxxx},
include brackets. Each custom GUID must be a separate entry
GUID for custom removable storage class:
{50dd5230-ba8a-11d1-bf5d-0000f805f530}
{62f9c741-b25a-46ce-b54c-9bccce08b6f2}
{990a2bd7-e738-46c7-b26f-1cf8fb9f1391}
PolicySettingComment
Custom Classes: Deny write accessEnabled
Enter GUID in format {xxxxxxxx-xxxx-xxxx-xxxxxxxxxxxx},
include brackets. Each custom GUID must be a separate entry
GUID for custom removable storage class:
{50dd5230-ba8a-11d1-bf5d-0000f805f530}
{62f9c741-b25a-46ce-b54c-9bccce08b6f2}
{990a2bd7-e738-46c7-b26f-1cf8fb9f1391}
User Configuration (Enabled)
No settings defined.