| KE-PO-WIN-C-Clients Global Settings New | |
| Data collected on: 2-9-2025 13:10:39 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\Domain Admins |
| Created | 2-7-2025 08:31:40 |
| Modified | 19-8-2025 13:59:14 |
| User Revisions | 1 (AD), 1 (SYSVOL) |
| Computer Revisions | 27 (AD), 27 (SYSVOL) |
| Unique ID | {75142ecd-ed1a-49e2-866f-e46bdf35abff} |
| GPO Status | User settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Clients | No | Enabled | emea.tpg.ads/KE/Systems/Clients |
| Name |
|---|
| EMEA\KE-L-SEC-Clients Global Settings GPO |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\KE-G-ORG-OU Admins | Edit settings, delete, modify security | No |
| EMEA\KE-L-SEC-Clients Global Settings GPO | Read (from Security Filtering) | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Policy | Setting |
|---|---|
| Enforce password history | 24 passwords remembered |
| Maximum password age | 60 days |
| Minimum password age | 1 days |
| Minimum password length | 12 characters |
| Password must meet complexity requirements | Enabled |
| Store passwords using reversible encryption | Disabled |
| Policy | Setting |
|---|---|
| Account lockout duration | 60 minutes |
| Account lockout threshold | 6 invalid logon attempts |
| Reset account lockout counter after | 60 minutes |
| Policy | Setting |
|---|---|
| Enforce user logon restrictions | Enabled |
| Maximum lifetime for service ticket | 600 minutes |
| Maximum lifetime for user ticket | 10 hours |
| Maximum lifetime for user ticket renewal | 7 days |
| Maximum tolerance for computer clock synchronization | 99999 minutes |
| Policy | Setting |
|---|---|
| Audit account logon events | Success, Failure |
| Audit account management | Success, Failure |
| Audit directory service access | Success, Failure |
| Audit logon events | Success, Failure |
| Audit policy change | Success, Failure |
| Audit privilege use | Success, Failure |
| Audit process tracking | Success, Failure |
| Audit system events | Success, Failure |
| Policy | Setting |
|---|---|
| Back up files and directories | BUILTIN\Administrators, EMEA\KE-G-ORG-OU Admins |
| Debug programs | BUILTIN\Administrators, EMEA\KE-G-ORG-OU Admins |
| Deny log on locally | EMEA\KE-G-ORG-Users NO Login to Windows |
| Deny log on through Terminal Services | EMEA\KE-G-ORG-Users NO Login to Windows |
| Manage auditing and security log | BUILTIN\Administrators, EMEA\KE-G-ORG-OU Admins |
| Policy | Setting |
|---|---|
| Accounts: Administrator account status | Disabled |
| Accounts: Guest account status | Disabled |
| Accounts: Limit local account use of blank passwords to console logon only | Enabled |
| Accounts: Rename administrator account | "tpadminlc" |
| Accounts: Rename guest account | "habos" |
| Policy | Setting |
|---|---|
| Audit: Audit the access of global system objects | Disabled |
| Audit: Audit the use of Backup and Restore privilege | Disabled |
| Policy | Setting |
|---|---|
| Devices: Allowed to format and eject removable media | Administrators |
| Devices: Prevent users from installing printer drivers | Enabled |
| Devices: Restrict CD-ROM access to locally logged-on user only | Enabled |
| Devices: Restrict floppy access to locally logged-on user only | Enabled |
| Policy | Setting |
|---|---|
| Interactive logon: Do not require CTRL+ALT+DEL | Disabled |
| Interactive logon: Don't display last signed-in | Enabled |
| Interactive logon: Message text for users attempting to log on | This computer system (including all hardware, software, and peripheral equipment) is, the property of Teleperformance. Use of this computer system is restricted to official, Teleperformance business. Teleperformance reserves the right to monitor use of the, computer system at any time. Use of this system constitutes consent to such monitoring., Any unauthorized access, use, or modification of the computer system can result in civil, liability and/or criminal penalties. |
| Interactive logon: Message title for users attempting to log on | "---------------Teleperformance Kenya---------------" |
| Interactive logon: Prompt user to change password before expiration | 14 days |
| Policy | Setting |
|---|---|
| Microsoft network client: Digitally sign communications (always) | Enabled |
| Microsoft network client: Digitally sign communications (if server agrees) | Enabled |
| Policy | Setting |
|---|---|
| Microsoft network server: Digitally sign communications (always) | Enabled |
| Microsoft network server: Digitally sign communications (if client agrees) | Enabled |
| Policy | Setting |
|---|---|
| Network access: Let Everyone permissions apply to anonymous users | Disabled |
| Policy | Setting |
|---|---|
| Network security: Do not store LAN Manager hash value on next password change | Enabled |
| Network security: LAN Manager authentication level | Send NTLMv2 response only. Refuse LM & NTLM |
| Policy | Setting |
|---|---|
| Recovery console: Allow automatic administrative logon | Disabled |
| Recovery console: Allow floppy copy and access to all drives and all folders | Disabled |
| Policy | Setting |
|---|---|
| Shutdown: Allow system to be shut down without having to log on | Disabled |
| Shutdown: Clear virtual memory pagefile | Enabled |
| Policy | Setting |
|---|---|
| Accounts: Block Microsoft accounts | Users can't add or log on with Microsoft accounts |
| Policy | Setting |
|---|---|
| Prevent local guests group from accessing application log | Enabled |
| Prevent local guests group from accessing security log | Enabled |
| Prevent local guests group from accessing system log | Enabled |
| Retain security log | 90 days |
| Retain system log | 90 days |
| Retention method for application log | As needed |
| Retention method for security log | By days |
| Retention method for system log | By days |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Users | Read and Execute | This folder, subfolders and files |
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read and Execute | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Deny | EMEA\KE-L-SEC-Restricted Windows Apps | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Deny | EMEA\Domain Users | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Deny | EMEA\Domain Users | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Deny | EMEA\KE-L-SEC-Restricted Start menu and Taskbar | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Policy | Setting | ||||||
|---|---|---|---|---|---|---|---|
| Automatic certificate management | Enabled | ||||||
| |||||||
| Issued To | Issued By | Expiration Date | Intended Purposes |
|---|---|---|---|
| grathlnxca01 | grathlnxca01 | 25-2-2043 14:31:45 | <All> |
| s800-TPGRDC03-CA | s800-TPGRDC03-CA | 17-9-2025 09:47:28 | <All> |
| Teleperformance Root CA | Teleperformance Root CA | 25-4-2036 18:58:15 | <All> |
| Issued To | Issued By | Expiration Date | Intended Purposes |
|---|---|---|---|
| TP EMEA Enterprise CA | Teleperformance Root CA | 26-4-2026 17:09:38 | <All> |
| Policy | Setting |
|---|---|
| Policy version | Not Configured |
| Disable stateful FTP | Not Configured |
| Disable stateful PPTP | Not Configured |
| IPsec exempt | Not Configured |
| IPsec through NAT | Not Configured |
| Preshared key encoding | Not Configured |
| SA idle time | Not Configured |
| Strong CRL check | Not Configured |
| Policy | Setting |
|---|---|
| Firewall state | Off |
| Inbound connections | Not Configured |
| Outbound connections | Not Configured |
| Apply local firewall rules | Not Configured |
| Apply local connection security rules | Not Configured |
| Display notifications | Not Configured |
| Allow unicast responses | Not Configured |
| Log dropped packets | Not Configured |
| Log successful connections | Not Configured |
| Log file path | Not Configured |
| Log file maximum size (KB) | Not Configured |
| Policy | Setting |
|---|---|
| Audit Credential Validation | Success, Failure |
| Audit Kerberos Authentication Service | Success, Failure |
| Audit Kerberos Service Ticket Operations | Success, Failure |
| Audit Other Account Logon Events | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Application Group Management | Success, Failure |
| Audit Computer Account Management | Success, Failure |
| Audit Distribution Group Management | Success, Failure |
| Audit Other Account Management Events | Success, Failure |
| Audit Security Group Management | Success, Failure |
| Audit User Account Management | Success, Failure |
| Policy | Setting |
|---|---|
| Audit DPAPI Activity | Success, Failure |
| Audit Process Creation | Success, Failure |
| Audit Process Termination | Success, Failure |
| Audit RPC Events | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Detailed Directory Service Replication | Success, Failure |
| Audit Directory Service Access | Success, Failure |
| Audit Directory Service Changes | Success, Failure |
| Audit Directory Service Replication | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Account Lockout | Success, Failure |
| Audit User / Device Claims | Success, Failure |
| Audit Group Membership | Success, Failure |
| Audit IPsec Extended Mode | Success, Failure |
| Audit IPsec Main Mode | Success, Failure |
| Audit IPsec Quick Mode | Success, Failure |
| Audit Logoff | Success, Failure |
| Audit Logon | Success, Failure |
| Audit Network Policy Server | Success, Failure |
| Audit Other Logon/Logoff Events | Success, Failure |
| Audit Special Logon | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Audit Policy Change | Success, Failure |
| Audit Authentication Policy Change | Success, Failure |
| Audit Authorization Policy Change | Success, Failure |
| Audit Filtering Platform Policy Change | Success, Failure |
| Audit MPSSVC Rule-Level Policy Change | Success, Failure |
| Audit Other Policy Change Events | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Non Sensitive Privilege Use | Success, Failure |
| Audit Other Privilege Use Events | Success, Failure |
| Audit Sensitive Privilege Use | Success, Failure |
| Policy | Setting |
|---|---|
| Audit IPsec Driver | Success, Failure |
| Audit Other System Events | Success, Failure |
| Audit Security State Change | Success, Failure |
| Audit Security System Extension | Success, Failure |
| Audit System Integrity | Success, Failure |
| Policy | Setting |
|---|---|
| Enforce rules of this type | False |
| Policy | Setting |
|---|---|
| Enforce rules of this type | False |
| Policy | Setting |
|---|---|
| Enforce rules of this type | False |
| Policy | Setting |
|---|---|
| Enforce rules of this type | False |
| Policy | Setting | Comment | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Force a specific default lock screen and logon image | Enabled | |||||||||||
| ||||||||||||
| Policy | Setting | Comment | ||||||||||
| Prevent changing lock screen and logon image | Enabled | |||||||||||
| Prevent changing start menu background | Enabled | |||||||||||
| Prevent enabling lock screen camera | Enabled | |||||||||||
| Prevent enabling lock screen slide show | Enabled | |||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Allow QUIC protocol | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow QUIC protocol | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| DNS suffix search list | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| IPv6 Configuration Policy | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Windows Defender Firewall: Protect all network connections | Disabled |
| Policy | Setting | Comment | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Hardened UNC Paths | Enabled | |||||||||||||
| ||||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Allow or Disallow use of the Offline Files feature | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Display highly detailed status messages | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Always wait for the network at computer startup and logon | Enabled | |
| Do not display the Getting Started welcome screen at logon | Enabled | |
| Hide entry points for Fast User Switching | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow Clipboard synchronization across devices | Disabled | |
| Allow publishing of User Activities | Disabled | |
| Allow upload of User Activities | Disabled | |
| Enables Activity Feed | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Select the lid switch action (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Select the lid switch action (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Select the Power button action (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Select the Power button action (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Select the Sleep button action (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Select the Sleep button action (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Select the Start menu Power button action (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Select the Start menu Power button action (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn Off the hard disk (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn Off the hard disk (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Allow applications to prevent automatic sleep (on battery) | Enabled | |||
| Allow applications to prevent automatic sleep (plugged in) | Enabled | |||
| Allow automatic sleep with Open Network Files (on battery) | Disabled | |||
| Allow automatic sleep with Open Network Files (plugged in) | Disabled | |||
| Allow network connectivity during connected-standby (on battery) | Enabled | |||
| Allow network connectivity during connected-standby (plugged in) | Enabled | |||
| Allow standby states (S1-S3) when sleeping (on battery) | Disabled | |||
| Allow standby states (S1-S3) when sleeping (plugged in) | Disabled | |||
| Require a password when a computer wakes (on battery) | Enabled | |||
| Require a password when a computer wakes (plugged in) | Enabled | |||
| Specify the system hibernate timeout (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Specify the system hibernate timeout (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Specify the system sleep timeout (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Specify the system sleep timeout (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Specify the unattended sleep timeout (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Specify the unattended sleep timeout (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn off hybrid sleep (on battery) | Enabled | |||
| Turn off hybrid sleep (plugged in) | Enabled | |||
| Turn on the ability for applications to prevent sleep transitions (on battery) | Enabled | |||
| Turn on the ability for applications to prevent sleep transitions (plugged in) | Enabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Configure Offer Remote Assistance | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| All Removable Storage classes: Deny all access | Enabled | |
| All Removable Storage: Allow direct access in remote sessions | Disabled | |
| Removable Disks: Deny execute access | Enabled | |
| Removable Disks: Deny read access | Enabled | |
| Removable Disks: Deny write access | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Configuration | Enabled | |
| Turn off System Restore | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Connect all USB devices to the desktop or remote application on launch | Enabled | |
| Connect USB devices to the desktop or remote application when they are plugged in | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent the wizard from running. | Enabled |
| Policy | Setting | Comment | ||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Let Windows apps access account information | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access call history | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access contacts | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access diagnostic information about other apps | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access email | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access location | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access messaging | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access motion | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access the calendar | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access trusted devices | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps communicate with unpaired devices | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps control radios | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps take screenshots of various windows or displays | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps turn off the screenshot border | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Block launching desktop apps associated with a URI scheme | Enabled | |
| Block launching Universal Windows apps with Windows Runtime API access from hosted content. | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Set the default behavior for AutoRun | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn off Autoplay | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Do not show Windows tips | Enabled | |
| Turn off cloud consumer account state content | Enabled | |
| Turn off cloud optimized content | Enabled | |
| Turn off Microsoft consumer experiences | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Download Mode | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Restrict unpacking and installation of gadgets that are not digitally signed. | Enabled | |
| Turn off desktop gadgets | Enabled | |
| Turn Off user-installed desktop gadgets | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Disable help tips | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Show hibernate in the power options menu | Disabled | |
| Show sleep in the power options menu | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off downloading of game information | Enabled | |
| Turn off game updates | Enabled | |
| Turn off tracking of last play time of games in the Games folder | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent the computer from joining a homegroup | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Prevent "Fix settings" functionality | Enabled | |||
| Prevent access to Internet Explorer Help | Enabled | |||
| Prevent changing proxy settings | Enabled | |||
| Prevent participation in the Customer Experience Improvement Program | Enabled | |||
| Prevent running First Run wizard | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn off encryption support | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Intranet Sites: Include all local (intranet) sites not listed in other zones | Enabled | |
| Intranet Sites: Include all network paths (UNCs) | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Download signed ActiveX controls | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Download unsigned ActiveX controls | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Download signed ActiveX controls | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Download unsigned ActiveX controls | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Download signed ActiveX controls | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Download unsigned ActiveX controls | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Download signed ActiveX controls | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Download unsigned ActiveX controls | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Download signed ActiveX controls | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Download unsigned ActiveX controls | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off Microsoft Defender Antivirus | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Enable headless UI mode | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent access to the about:flags page in Microsoft Edge | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent the usage of OneDrive for file storage | Enabled | |
| Save documents to OneDrive by default | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Active Help | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow users to connect remotely by using Remote Desktop Services | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent access to feed list | Enabled | |
| Prevent automatic discovery of feeds and Web Slices | Enabled | |
| Prevent downloading of enclosures | Enabled | |
| Prevent subscribing to or deleting a feed or a Web Slice | Enabled | |
| Turn off background synchronization for feeds and Web Slices | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow Cortana | Disabled | |
| Do not allow web search | Enabled | |
| Don't search the web or display web results in Search | Enabled | |
| Don't search the web or display web results in Search over metered connections | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn on Security Center (Domain PCs only) | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Timeout for hung logon sessions during shutdown | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Do not allow Sound Recorder to run | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Disable all apps from Microsoft Store | Enabled | |
| Turn off the Store application | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Do not sync | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not sync app settings | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not sync Apps | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not sync browser settings | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not sync desktop personalization | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not sync on metered connections | Enabled | |||
| Do not sync other Windows settings | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not sync passwords | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not sync personalize | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not sync start settings | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Allow widgets | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Automatically send memory dumps for OS-generated error reports | Disabled | |
| Disable Windows Error Reporting | Enabled | |
| Do not send additional data | Enabled | |
| Do not throttle additional data | Enabled | |
| Prevent display of the user interface for critical errors | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Enables or disables Windows Game Recording and Broadcasting | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Allow Windows Ink Workspace | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off Windows Mail application | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not allow Windows Media Center to run | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent Windows Media DRM Internet Access | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not allow Windows Messenger to be run | Enabled | |
| Do not automatically start Windows Messenger initially | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Hide the Account protection area | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent users from modifying settings | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Hide the Device performance and health area | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Disable the Clear TPM button | Enabled | |
| Hide the Device security area | Enabled | |
| Hide the Secure boot area | Enabled | |
| Hide the TPM Firmware Update recommendation. | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Hide the Family options area | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Hide the Firewall and network protection area | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Hide the Ransomware data recovery area | Enabled | |
| Hide the Virus and threat protection area | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Windows SideShow | Enabled |
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Allow Automatic Updates immediate installation | Enabled | |||||
| No auto-restart with logged on users for scheduled automatic updates installations | Enabled | |||||
| Re-prompt for restart with scheduled installations | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Reschedule Automatic Updates scheduled installations | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Configure Automatic Updates | Enabled | |||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||||||||||
| Specify active hours range for auto-restarts | Enabled | |||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Allow signed updates from an intranet Microsoft update service location | Enabled | |||||||||||||||
| Automatic Updates detection frequency | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Enable client-side targeting | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Specify intranet Microsoft update service location | Enabled | |||||||||||||||
| ||||||||||||||||
| Setting | State |
|---|---|
| Software\policies\Microsoft\Windows\DeliveryOptimization\DOMaxUploadBandwidth | 1 |
| Software\policies\Microsoft\Windows\Skydrive\DisableFileSync | 1 |
| Software\policies\Microsoft\Windows\Skydrive\DisableLibrariesDefaultSaveToSkyDrive | 1 |
| Action | Create |
| Source file(s) | \\grkalfs01\netconfigfiles\GlobalSettings\fixlogs.bat |
| Destination file | C:\Windows\Temp\fixlogs.bat |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Disabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Source file(s) | \\grkalfs01\netconfigfiles\Kenya\Settings\DisableCBSBuiltinApps.ps1 |
| Destination file | C:\TPSTUFF\DisableCBSBuiltinApps.ps1 |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Disabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows Defender |
| Value name | DisableAntiSpyware |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Services\SecurityHealthService |
| Value name | LaunchProtected |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Services\SecurityHealthService |
| Value name | Start |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Services\SecurityHealthService |
| Value name | ServiceSidType |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALLOW_USER32_EXCEPTION_HANDLER_HARDENING |
| Value name | iexplore.exe |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ALLOW_USER32_EXCEPTION_HANDLER_HARDENING |
| Value name | iexplore.exe |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ENABLE_PRINT_INFO_DISCLOSURE_FIX |
| Value name | iexplore.exe |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ENABLE_PRINT_INFO_DISCLOSURE_FIX |
| Value name | iexplore.exe |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\.NETFramework\v2.0.50727 |
| Value name | SchUseStrongCrypto |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v2.0.50727 |
| Value name | SchUseStrongCrypto |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System |
| Value name | EnableFirstLogonAnimation |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_CLASSES_ROOT |
| Key path | ms-msdt |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows Defender |
| Value name | DisableAntiSpyware |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\QualityCompat |
| Value name | cadca5fe-87d3-4b96-b7fb-a231484277cc |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\system_a.exe |
| Value name | Debugger |
| Value type | REG_SZ |
| Value data | "c:\windows\system32\systray.exe" /z |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\system_a.exe |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum |
| Value name | {F02C1A0D-BE21-4350-88B0-7367FC96EF3C} |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Keyboard Layout |
| Value name | Scancode Map |
| Value type | REG_BINARY |
| Value data | 000000000000000003000000000037E00000540000000000 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\services\USBSTOR |
| Value name | Start |
| Value type | REG_DWORD |
| Value data | 0x4 (4) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\WindowsStore |
| Value name | DisableStoreApps |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | Software\Microsoft\Windows NT\CurrentVersion\MTCUVC |
| Value name | EnableMtcUvc |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate |
| Value name | SetDisablePauseUXAccess |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\*.emea.tpg.ads |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\*.emea.tpg.ads |
| Value name | (Default) |
| Value type | REG_SZ |
| Value data |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\*.tpg.zone |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\*.tpg.zone |
| Value name | (Default) |
| Value type | REG_SZ |
| Value data |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\tpg.ads |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\tpg.ads\grkalfs01.emea |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\tpg.ads\grkalfs01.emea |
| Value name | * |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management |
| Value name | FeatureSettingsOverride |
| Value type | REG_DWORD |
| Value data | 0x48 (72) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management |
| Value name | FeatureSettingsOverrideMask |
| Value type | REG_DWORD |
| Value data | 0x3 (3) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grkalfs01 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grkalfs01 |
| Value name | * |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\tpg.ads |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\tpg.ads |
| Value name | * |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\tpg.ads\emea |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\tpg.ads\emea |
| Value name | * |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\tpg.ads\grkalfs01.emea |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\tpg.ads\grkalfs01.emea |
| Value name | * |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Group name | Administrators (built-in) |
| Delete all member users | Disabled |
| Delete all member groups | Disabled |
| EMEA\KE-G-ORG-Remote Admin Users | S-1-5-21-513466819-3096973226-347852806-1260433 |
| EMEA\Domain Admins | S-1-5-21-513466819-3096973226-347852806-512 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Group name | Users (built-in) |
| Delete all member users | Disabled |
| Delete all member groups | Disabled |
| EMEA\KE-G-ORG-Remote Admin Users | S-1-5-21-513466819-3096973226-347852806-1260433 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Name | Disable Hibernate EMEA | |||
| Author | EMEA\tentolouris.5 | |||
| Description | ||||
| Run only when user is logged on | ||||
| GroupId | NT AUTHORITY\SYSTEM | |||
| Run with highest privileges | HighestAvailable | |||
| Hidden | Yes | |||
| Configure for | 1.3 | |||
| Enabled | Yes |
| 1. At task creation/modification | ||||
| Activate | 8-8-2022 15:52:31 | Synchronize across time zones | No | |
| Enabled | Yes | |||
| 1. Start a program | ||||
| Program/script | C:\Windows\System32\powercfg.exe | |||
| Arguments | /hibernate off |
| Stop if the computer ceases to be idle | No | |||
| Restart if the idle state resumes | No | |||
| Start the task only if the computer is on AC power | No | |||
| Stop if the computer switches to battery power | No | |||
| Wake the computer to run this task | Yes | |||
| Allow task to be run on demand | No | |||
| Run task as soon as possible after a scheduled start is missed | Yes | |||
| Stop task if it runs longer than | Immediately | |||
| If the running task does not end when requested, force it to stop | No | |||
| If the task is already running, then the following rule applies | IgnoreNew |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | Yes |
| Action | Update |
| Name | DesktopBackgroundCopy | |||
| Author | EMEA\tentolouris.5 | |||
| Description | ||||
| Run only when user is logged on | ||||
| GroupId | NT AUTHORITY\SYSTEM | |||
| Run with highest privileges | HighestAvailable | |||
| Hidden | No | |||
| Configure for | 1.3 | |||
| Enabled | Yes |
| 1. On local connection to user session | ||||
| Delay task for | 1 minute | |||
| Enabled | Yes | |||
| 2. Run at user logon | ||||
| Delay task for | 1 minute | |||
| Enabled | Yes | |||
| 3. On remote connection to user session | ||||
| Delay task for | 1 minute | |||
| Enabled | Yes | |||
| 1. Start a program | ||||
| Program/script | Powershell.exe | |||
| Arguments | -ExecutionPolicy Bypass -file "\\Kenbofs01\kenboit$\PS\CopyDesktop.ps1" | |||
| Start in | \\Kenbofs01\kenboit$\PS |
| Stop if the computer ceases to be idle | Yes | |||
| Restart if the idle state resumes | No | |||
| Start the task only if the computer is on AC power | No | |||
| Stop if the computer switches to battery power | No | |||
| Start only if the following network connection is available | Any connection | |||
| Allow task to be run on demand | Yes | |||
| Run task as soon as possible after a scheduled start is missed | Yes | |||
| Stop task if it runs longer than | 1 day | |||
| If the running task does not end when requested, force it to stop | Yes | |||
| If the task is already running, then the following rule applies | StopExisting |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Name | ClearTemplogs | |||
| Author | EMEA\tentolouris.5 | |||
| Description | ||||
| Run only when user is logged on | ||||
| GroupId | NT AUTHORITY\SYSTEM | |||
| Run with highest privileges | HighestAvailable | |||
| Hidden | Yes | |||
| Configure for | 1.3 | |||
| Enabled | Yes |
| 1. Daily | ||||
| Delay task for up to (random delay) | 8 hours | |||
| Stop task if it runs longer than | 2 hours | |||
| Activate | 13-4-2020 09:24:03 | Synchronize across time zones | No | |
| Enabled | Yes | |||
| Recur every 1 days |
| 1. Start a program | ||||
| Program/script | C:\Windows\Temp\fixlogs.bat |
| Stop if the computer ceases to be idle | Yes | |||
| Restart if the idle state resumes | No | |||
| Start the task only if the computer is on AC power | No | |||
| Stop if the computer switches to battery power | Yes | |||
| Allow task to be run on demand | Yes | |||
| Run task as soon as possible after a scheduled start is missed | Yes | |||
| Stop task if it runs longer than | 8 hours | |||
| If the running task does not end when requested, force it to stop | Yes | |||
| If the task is already running, then the following rule applies | StopExisting |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Name | KMSSet to Local | |||
| Author | EMEA\tentolouris.5 | |||
| Description | ||||
| Run only when user is logged on | ||||
| GroupId | NT AUTHORITY\SYSTEM | |||
| Run with highest privileges | HighestAvailable | |||
| Hidden | No | |||
| Configure for | 1.3 | |||
| Enabled | Yes |
| 1. At task creation/modification | ||||
| Activate | 8-8-2022 15:48:30 | Synchronize across time zones | No | |
| Enabled | Yes | |||
| 1. Start a program | ||||
| Program/script | \\grkalfs01\netconfigfiles\Kenya\Servers\KMStoLocal.bat |
| Stop if the computer ceases to be idle | Yes | |||
| Restart if the idle state resumes | No | |||
| Start the task only if the computer is on AC power | No | |||
| Stop if the computer switches to battery power | Yes | |||
| Allow task to be run on demand | Yes | |||
| Stop task if it runs longer than | 3 days | |||
| If the running task does not end when requested, force it to stop | Yes | |||
| If the task is already running, then the following rule applies | IgnoreNew |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | Yes |
| Action | Update |
| Name | SeriouSAM HiveNightmare vulnerability | |||
| Author | EMEA\tentolouris.5-adm | |||
| Description | ||||
| Run only when user is logged on | ||||
| GroupId | NT AUTHORITY\SYSTEM | |||
| Run with highest privileges | LeastPrivilege | |||
| Hidden | No | |||
| Configure for | 1.2 | |||
| Enabled | Yes |
| 1. At startup | ||||
| Enabled | Yes | |||
| 1. Start a program | ||||
| Program/script | C:\Windows\System32\cmd.exe | |||
| Arguments | /c IF NOT EXIST C:\TPSTUFF\MARK-SeriousSAMHiveNightmareRemediation.txt icacls %windir%\system32\config\*.* /inheritance:e>>"C:\TPSTUFF\MARK-SeriousSAMHiveNightmareRemediation.txt" |
| Stop if the computer ceases to be idle | No | |||
| Restart if the idle state resumes | No | |||
| Start the task only if the computer is on AC power | No | |||
| Stop if the computer switches to battery power | No | |||
| Allow task to be run on demand | No | |||
| Stop task if it runs longer than | Immediately | |||
| If the running task does not end when requested, force it to stop | No | |||
| If the task is already running, then the following rule applies | IgnoreNew |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Name | Disable_Bluetooth | |||
| Author | EMEA\tentolouris.5 | |||
| Description | ||||
| Run only when user is logged on | ||||
| GroupId | NT AUTHORITY\SYSTEM | |||
| Run with highest privileges | HighestAvailable | |||
| Hidden | No | |||
| Configure for | 1.3 | |||
| Enabled | Yes |
| 1. At task creation/modification | ||||
| Enabled | Yes | |||
| 1. Start a program | ||||
| Program/script | Powershell.exe | |||
| Arguments | -ExecutionPolicy Bypass -file "\\Kenbofs01\kenboit$\PS\DisableBluetooth.ps1" | |||
| Start in | \\Kenbofs01\kenboit$\PS |
| Stop if the computer ceases to be idle | Yes | |||
| Restart if the idle state resumes | No | |||
| Start the task only if the computer is on AC power | No | |||
| Stop if the computer switches to battery power | Yes | |||
| Allow task to be run on demand | Yes | |||
| Run task as soon as possible after a scheduled start is missed | Yes | |||
| Stop task if it runs longer than | 3 days | |||
| If the running task does not end when requested, force it to stop | Yes | |||
| If the task is already running, then the following rule applies | IgnoreNew |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | Yes |
| Action | Create |
| Name | Load STart Layout | |||
| Author | EMEA\tentolouris.5 | |||
| Description | ||||
| Run only when user is logged on | ||||
| GroupId | NT AUTHORITY\SYSTEM | |||
| Run with highest privileges | HighestAvailable | |||
| Hidden | No | |||
| Configure for | 1.3 | |||
| Enabled | Yes |
| 1. At task creation/modification | ||||
| Enabled | Yes | |||
| 1. Start a program | ||||
| Program/script | Powershell.exe | |||
| Arguments | -ExecutionPolicy Bypass \\grkalfs01\netconfigfiles\Kenya\Settings\LayoutPowershell\LayoutAdd.ps1 |
| Stop if the computer ceases to be idle | Yes | |||
| Restart if the idle state resumes | No | |||
| Start the task only if the computer is on AC power | No | |||
| Stop if the computer switches to battery power | Yes | |||
| Allow task to be run on demand | Yes | |||
| Run task as soon as possible after a scheduled start is missed | Yes | |||
| Stop task if it runs longer than | 3 days | |||
| If the running task does not end when requested, force it to stop | Yes | |||
| If the task is already running, then the following rule applies | IgnoreNew |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | Yes |
| Action | Update |
| Name | LockScreenFix | |||
| Author | EMEA\tentolouris.5 | |||
| Description | ||||
| Run only when user is logged on | ||||
| GroupId | NT AUTHORITY\SYSTEM | |||
| Run with highest privileges | HighestAvailable | |||
| Hidden | No | |||
| Configure for | 1.3 | |||
| Enabled | Yes |
| 1. On local connection to user session | ||||
| Delay task for | 30 minutes | |||
| Enabled | Yes | |||
| 2. Run at user logon | ||||
| Delay task for | 30 minutes | |||
| Enabled | Yes | |||
| 3. On workstation unlock | ||||
| Delay task for | 30 minutes | |||
| Enabled | Yes | |||
| 4. On remote connection to user session | ||||
| Delay task for | 1 minute | |||
| Enabled | Yes | |||
| 1. Start a program | ||||
| Program/script | Powershell.exe | |||
| Arguments | -ExecutionPolicy Bypass -file "\\Kenbofs01\kenboit$\PS\LockScreenFix.ps1" | |||
| Start in | \\Kenbofs01\kenboit$\PS |
| Stop if the computer ceases to be idle | Yes | |||
| Restart if the idle state resumes | No | |||
| Start the task only if the computer is on AC power | No | |||
| Stop if the computer switches to battery power | Yes | |||
| Allow task to be run on demand | Yes | |||
| Stop task if it runs longer than | 3 days | |||
| If the running task does not end when requested, force it to stop | Yes | |||
| If the task is already running, then the following rule applies | IgnoreNew |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Name | DisableCBSBuiltinApps | |||
| Author | EMEA\tentolouris.5-adm | |||
| Description | ||||
| Run only when user is logged on | ||||
| GroupId | NT AUTHORITY\SYSTEM | |||
| Run with highest privileges | HighestAvailable | |||
| Hidden | No | |||
| Configure for | 1.2 | |||
| Enabled | Yes |
| 1. At task creation/modification | ||||
| Enabled | Yes | |||
| 2. At startup | ||||
| Enabled | Yes | |||
| 1. Start a program | ||||
| Program/script | Powershell.exe | |||
| Arguments | -ExecutionPolicy Bypass C:\TPSTUFF\DisableCBSBuiltinApps.ps1 |
| Stop if the computer ceases to be idle | Yes | |||
| Restart if the idle state resumes | No | |||
| Start the task only if the computer is on AC power | Yes | |||
| Stop if the computer switches to battery power | Yes | |||
| Allow task to be run on demand | Yes | |||
| Stop task if it runs longer than | 3 days | |||
| If the running task does not end when requested, force it to stop | Yes | |||
| If the task is already running, then the following rule applies | IgnoreNew |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Name | RunUpdates | |||
| Author | EMEA\tentolouris.5 | |||
| Description | ||||
| Run only when user is logged on | ||||
| GroupId | NT AUTHORITY\SYSTEM | |||
| Run with highest privileges | HighestAvailable | |||
| Hidden | Yes | |||
| Configure for | 1.3 | |||
| Enabled | Yes |
| 1. At startup | ||||
| Activate | 13-4-2020 09:24:03 | Synchronize across time zones | No | |
| Enabled | Yes | |||
| 1. Start a program | ||||
| Program/script | C:\Windows\System32\UsoClient.exe | |||
| Arguments | StartInstall |
| Stop if the computer ceases to be idle | Yes | |||
| Restart if the idle state resumes | No | |||
| Start the task only if the computer is on AC power | No | |||
| Stop if the computer switches to battery power | Yes | |||
| Allow task to be run on demand | Yes | |||
| Run task as soon as possible after a scheduled start is missed | Yes | |||
| Stop task if it runs longer than | 8 hours | |||
| If the running task does not end when requested, force it to stop | Yes | |||
| If the task is already running, then the following rule applies | StopExisting |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |