Group Policy Management
body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } }
Setting Path:
Explanation
No explanation is available for this setting.
Supported On:
Not available
GR-PO-WIN-C-ZipCar Settings
Data collected on: 2-9-2025 08:59:42
General
Details
Domainemea.tpg.ads
OwnerEMEA\tentolouris.5
Created28-9-2016 11:07:24
Modified25-4-2024 09:46:38
User Revisions0 (AD), 0 (SYSVOL)
Computer Revisions91 (AD), 91 (SYSVOL)
Unique ID{e9ae2c4b-a942-45b3-9655-44e5bfd212b5}
GPO StatusEnabled
Links
LocationEnforcedLink StatusPath
ClientsYesEnabledemea.tpg.ads/GR/Systems/Clients

This list only includes links in the domain of the GPO.
Security Filtering
The settings in this GPO can only apply to the following groups, users, and computers:
Name
EMEA\GR-G-ORG-Computers ZipCar
Delegation
These groups and users have the specified permission for this GPO
NameAllowed PermissionsInherited
EMEA\Domain AdminsEdit settings, delete, modify securityNo
EMEA\Domain ComputersReadNo
EMEA\GR-G-ORG-Computers ZipCarRead (from Security Filtering)No
EMEA\GR-G-ORG-OU AdminsEdit settings, delete, modify securityNo
EMEA\tentolouris.5Edit settings, delete, modify securityNo
NT AUTHORITY\Authenticated UsersReadNo
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSReadNo
NT AUTHORITY\SYSTEMEdit settings, delete, modify securityNo
ROOT\Enterprise AdminsEdit settings, delete, modify securityNo
Computer Configuration (Enabled)
Policies
Windows Settings
Scripts
Startup
For this GPO, Script order: Not configured
NameParameters
\\grkalfs01\netconfigfiles\ZipCar\Hosts_file\CopyHostFile_ZipCar.bat
\\grkalfs01\netconfigfiles\ZipCar\NetCacheFormatDatabase.bat
\\grkalfs01.emea.tpg.ads\netconfigfiles\GlobalSettings\Thunderbird-EMEA-Patch\copy.bat
\\grkalfs01\netconfigfiles\GlobalSettings\Landesk\RepairLandesk.bat
Shutdown
For this GPO, Script order: Not configured
NameParameters
\\grkalfs01\netconfigfiles\ZipCar\NetCacheFormatDatabase.bat
Security Settings
File System
%ProgramFiles% (x86)\Five9
Configure this file or folder then: Propagate inheritable permissions to all subfolders and files
Owner
Permissions
TypeNamePermissionApply To
AllowAPPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGESFull ControlThis folder, subfolders and files
AllowCREATOR OWNERFull ControlThis folder, subfolders and files
AllowNT AUTHORITY\SYSTEMFull ControlThis folder, subfolders and files
AllowBUILTIN\AdministratorsFull ControlThis folder, subfolders and files
AllowBUILTIN\UsersFull ControlThis folder, subfolders and files
Allow inheritable permissions from the parent to propagate to this object and all child objectsDisabled
Auditing
No auditing specified
Administrative Templates
Policy definitions (ADMX files) retrieved from the central store.
Google/Google Update/Applications/Google Chrome
PolicySettingComment
Update policy overrideEnabled
PolicyUpdates disabled
Windows Components/App Privacy
PolicySettingComment
Let Windows apps access the microphoneEnabled
Default for all apps:Force Allow
Put user in control of these specific apps (use Package Family Names):
Force allow these specific apps (use Package Family Names):
Force deny these specific apps (use Package Family Names):
Windows Components/File Explorer
PolicySettingComment
Set a default associations configuration fileEnabled
Default Associations Configuration File\\grkalfs01.emea.tpg.ads\netconfigfiles\ZipCar\chromedefault.xml
Windows Components/Windows Defender SmartScreen/Explorer
PolicySettingComment
Configure App Install ControlEnabled
Pick one of the following settings:Turn off app recommendations
Windows Components/Windows Update/Manage updates offered from Windows Server Update Service
PolicySettingComment
Enable client-side targetingEnabled
Target group name for this computerZipCar
Preferences
Windows Settings
Registry
SchUseStrongCrypto (Order: 1)
General
ActionUpdate
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSOFTWARE\Microsoft\.NETFramework\v2.0.50727
Value nameSchUseStrongCrypto
Value typeREG_DWORD
Value data0x1 (1)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
SchUseStrongCrypto (Order: 2)
General
ActionUpdate
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSOFTWARE\Wow6432Node\Microsoft\.NETFramework\v2.0.50727
Value nameSchUseStrongCrypto
Value typeREG_DWORD
Value data0x1 (1)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Control Panel Settings
Local Users and Groups
Group (Name: Users (built-in))
Users (built-in) (Order: 1)
Local Group
ActionUpdate
Properties
Group nameUsers (built-in)
Delete all member usersDisabled
Delete all member groupsEnabled
Add members
EMEA\GR-G-ORG-Remote Admin UsersS-1-5-21-513466819-3096973226-347852806-613115
tpadmin
EMEA\GR-G-ORG-USERS ZipCar SLAM AccessS-1-5-21-513466819-3096973226-347852806-1300069
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Group (Name: Administrators (built-in))
Administrators (built-in) (Order: 2)
Local Group
ActionUpdate
Properties
Group nameAdministrators (built-in)
Delete all member usersDisabled
Delete all member groupsEnabled
Add members
EMEA\GR-G-ORG-Remote Admin UsersS-1-5-21-513466819-3096973226-347852806-613115
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Scheduled Tasks
Scheduled Task (At least Windows 7) (Name: Remove all profile)
Remove all profile (Order: 1)
General
ActionUpdate
Task
Name Remove all profile
Author EMEA\lewke.7
Description Remove all profile
Run only when user is logged on InteractiveToken
UserId NT AUTHORITY\System
Run with highest privileges HighestAvailable
Hidden No
Configure for 1.2
Enabled Yes
Triggers
1. Run at user logon
Enabled Yes
Actions
1. Start a program
Program/script Powershell.exe
Arguments -ExecutionPolicy Bypass \\grkalfs01\netconfigfiles\ZipCar\RemoveUserAccount.ps1
2. Start a program
Program/script \\grkalfs01.emea.tpg.ads\netconfigfiles\ZipCar\NetCacheFormatDatabase.bat
3. Start a program
Program/script \\grkalfs01\netconfigfiles\ZipCar\NetCacheFormatDatabase.bat
Settings
Stop if the computer ceases to be idle No
Restart if the idle state resumes No
Start the task only if the computer is on AC power No
Stop if the computer switches to battery power No
Allow task to be run on demand Yes
Run task as soon as possible after a scheduled start is missed Yes
Stop task if it runs longer than Immediately
If the running task does not end when requested, force it to stop No
If the task is already running, then the following rule applies IgnoreNew
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
User Configuration (Enabled)
No settings defined.