| GR-PO-WIN-Global Servers Settings | |
| Data collected on: 2-9-2025 08:59:46 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\tsitsiklis.5 |
| Created | 5-10-2016 10:52:36 |
| Modified | 24-11-2023 08:33:24 |
| User Revisions | 0 (AD), 0 (SYSVOL) |
| Computer Revisions | 176 (AD), 176 (SYSVOL) |
| Unique ID | {eeab43af-d1fc-4212-b2f2-c6b0c12011d4} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Servers | No | Enabled | emea.tpg.ads/GR/Systems/Servers |
| CHQ | Yes | Enabled | emea.tpg.ads/GR/Systems/Servers/CHQ |
| KAL | Yes | Enabled | emea.tpg.ads/GR/Systems/Servers/KAL |
| MKT | Yes | Enabled | emea.tpg.ads/GR/Systems/Servers/MKT |
| PIR | Yes | Enabled | emea.tpg.ads/GR/Systems/Servers/PIR |
| TAV | Yes | Enabled | emea.tpg.ads/GR/Systems/Servers/TAV |
| Name |
|---|
| NT AUTHORITY\Authenticated Users |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\GR-G-ORG-OU Admins | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read (from Security Filtering) | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Policy | Setting |
|---|---|
| Back up files and directories | BUILTIN\Administrators, BUILTIN\Backup Operators, EMEA\GR-G-ORG-OU Admins, EMEA\GR-L-SEC-Service Accounts as Local Admins |
| Create a token object | EMEA\GR-L-SEC-Service Accounts as Local Admins |
| Debug programs | BUILTIN\Administrators, EMEA\GR-G-ORG-OU Admins |
| Log on as a batch job | BUILTIN\Performance Log Users, Logon As Batch, EMEA\GR-L-SEC-Service Accounts as Local Admins, EMEA\GR-L-SEC-Access to Log on as a batch job, BUILTIN\Backup Operators, BUILTIN\Administrators |
| Log on as a service | EMEA\GR-L-SEC-Service Accounts as Local Admins, Logon as a Service, NT AUTHORITY\NETWORK SERVICE, NT SERVICE\ALL SERVICES |
| Manage auditing and security log | BUILTIN\Administrators, EMEA\GR-G-ORG-OU Admins, EMEA\GR-L-SEC-Service Accounts as Local Admins |
| Perform volume maintenance tasks | EMEA\GR-L-SEC-Service Accounts as Local Admins, BUILTIN\Administrators |
| Restore files and directories | BUILTIN\Administrators, BUILTIN\Backup Operators, EMEA\GR-G-ORG-OU Admins, EMEA\GR-L-SEC-Service Accounts as Local Admins |
| Take ownership of files or other objects | BUILTIN\Administrators, EMEA\GR-L-SEC-Service Accounts as Local Admins |
| Policy | Setting |
|---|---|
| Accounts: Limit local account use of blank passwords to console logon only | Enabled |
| Accounts: Rename administrator account | "yannis" |
| Accounts: Rename guest account | "habos" |
| Policy | Setting |
|---|---|
| Devices: Allowed to format and eject removable media | Administrators |
| Devices: Prevent users from installing printer drivers | Enabled |
| Policy | Setting |
|---|---|
| Domain member: Digitally encrypt secure channel data (when possible) | Enabled |
| Domain member: Disable machine account password changes | Disabled |
| Domain member: Require strong (Windows 2000 or later) session key | Enabled |
| Policy | Setting |
|---|---|
| Interactive logon: Do not require CTRL+ALT+DEL | Disabled |
| Interactive logon: Don't display last signed-in | Enabled |
| Interactive logon: Number of previous logons to cache (in case domain controller is not available) | 0 logons |
| Interactive logon: Require Domain Controller authentication to unlock workstation | Enabled |
| Policy | Setting |
|---|---|
| Network access: Do not allow anonymous enumeration of SAM accounts | Enabled |
| Network access: Do not allow anonymous enumeration of SAM accounts and shares | Enabled |
| Policy | Setting | ||||
|---|---|---|---|---|---|
| Network security: LDAP client signing requirements | Require signing | ||||
| Network security: Minimum session security for NTLM SSP based (including secure RPC) servers | Enabled | ||||
| |||||
| Policy | Setting |
|---|---|
| System cryptography: Force strong key protection for user keys stored on the computer | User is prompted when the key is first used |
| Group | Members | Member of |
|---|---|---|
| EMEA\GR-G-ORG-IT-Systems-ADM | BUILTIN\Administrators | |
| EMEA\GR-L-SEC-Service Accounts as Local Admins | BUILTIN\Administrators |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Set the default behavior for AutoRun | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Download signed ActiveX controls | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Download unsigned ActiveX controls | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Download signed ActiveX controls | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Download unsigned ActiveX controls | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Download signed ActiveX controls | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Download unsigned ActiveX controls | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Download signed ActiveX controls | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Download unsigned ActiveX controls | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Download signed ActiveX controls | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Download unsigned ActiveX controls | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Allow antimalware service to remain running always | Disabled | |
| Turn off Microsoft Defender Antivirus | Enabled | |
| Turn off routine remediation | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Monitor file and program activity on your computer | Disabled | |
| Turn off real-time protection | Enabled | |
| Turn on behavior monitoring | Disabled | |
| Turn on process scanning whenever real-time protection is enabled | Disabled |
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Require secure RPC communication | Enabled | |||||
| Require use of specific security layer for remote (RDP) connections | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Require user authentication for remote connections by using Network Level Authentication | Enabled | |||||
| Server authentication certificate template | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Set client connection encryption level | Enabled | |||||
| ||||||
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System |
| Value name | EnableLUA |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management |
| Value name | FeatureSettingsOverride |
| Value type | REG_DWORD |
| Value data | 0x48 (72) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\VMICTimeProvider |
| Value name | Enabled |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Lsa |
| Value name | restrictanonymous |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management |
| Value name | FeatureSettingsOverrideMask |
| Value type | REG_DWORD |
| Value data | 0x3 (3) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Group name | Administrators (built-in) |
| Delete all member users | Disabled |
| Delete all member groups | Disabled |
| EMEA\emeanessus.1 | S-1-5-21-513466819-3096973226-347852806-32532 |
| EMEA\Domain Admins | S-1-5-21-513466819-3096973226-347852806-512 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Name | SEP Uninstall | |||
| Author | EMEA\tentolouris.5 | |||
| Description | ||||
| Run only when user is logged on | ||||
| GroupId | NT AUTHORITY\SYSTEM | |||
| Run with highest privileges | HighestAvailable | |||
| Hidden | No | |||
| Configure for | 1.3 | |||
| Enabled | Yes |
| 1. Start a program | ||||
| Program/script | Powershell.exe | |||
| Arguments | -ExecutionPolicy Bypass \\kalfs1.tphellas.legacy\netconfigfiles\GlobalSettings\Setups\SEP\UninstallSEP.ps1 |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |