Group Policy Management
body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } }
Setting Path:
Explanation
No explanation is available for this setting.
Supported On:
Not available
LT-PO-SEC-C-Laptops common policy
Data collected on: 2-9-2025 09:03:47
General
Details
Domainemea.tpg.ads
OwnerEMEA\kornev.5
Created5-6-2017 13:40:18
Modified6-2-2025 14:34:52
User Revisions1 (AD), 1 (SYSVOL)
Computer Revisions1 (AD), 1 (SYSVOL)
Unique ID{3f4b73c5-8200-4b31-b52a-e7a97c79c46c}
GPO StatusEnabled
Links
LocationEnforcedLink StatusPath
Managers LaptopsNoEnabledemea.tpg.ads/LT/Systems/Clients/VNO/Managers Laptops

This list only includes links in the domain of the GPO.
Security Filtering
The settings in this GPO can only apply to the following groups, users, and computers:
Name
NT AUTHORITY\Authenticated Users
Delegation
These groups and users have the specified permission for this GPO
NameAllowed PermissionsInherited
EMEA\Domain AdminsEdit settings, delete, modify securityNo
EMEA\kornev.5Edit settings, delete, modify securityNo
EMEA\LT-L-SEC-Delegation Group Policy Objects Modify AccessEdit settings, delete, modify securityNo
EMEA\RU-L-SEC-Delegation Group Policy Objects Modify AccessEdit settings, delete, modify securityNo
NT AUTHORITY\Authenticated UsersRead (from Security Filtering)No
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSReadNo
NT AUTHORITY\SYSTEMEdit settings, delete, modify securityNo
ROOT\Enterprise AdminsEdit settings, delete, modify securityNo
Computer Configuration (Enabled)
Policies
Windows Settings
Scripts
Startup
For this GPO, Script order: Not configured
NameParameters
__KeePass_install.cmd
Security Settings
System Services
Windows Defender Firewall (Startup Mode: Automatic)
Permissions
No permissions specified
Auditing
No auditing specified
Windows Firewall with Advanced Security
Global Settings
PolicySetting
Policy version2.22
Disable stateful FTPNot Configured
Disable stateful PPTPNot Configured
IPsec exemptNot Configured
IPsec through NATNot Configured
Preshared key encodingNot Configured
SA idle timeNot Configured
Strong CRL checkNot Configured
Domain Profile Settings
PolicySetting
Firewall stateOff
Inbound connectionsNot Configured
Outbound connectionsNot Configured
Apply local firewall rulesNot Configured
Apply local connection security rulesNot Configured
Display notificationsNot Configured
Allow unicast responsesNot Configured
Log dropped packetsNot Configured
Log successful connectionsNot Configured
Log file pathNot Configured
Log file maximum size (KB)Not Configured
Private Profile Settings
PolicySetting
Firewall stateOn
Inbound connectionsNot Configured
Outbound connectionsNot Configured
Apply local firewall rulesNot Configured
Apply local connection security rulesNot Configured
Display notificationsNot Configured
Allow unicast responsesNot Configured
Log dropped packetsNot Configured
Log successful connectionsNot Configured
Log file pathNot Configured
Log file maximum size (KB)Not Configured
Public Profile Settings
PolicySetting
Firewall stateOn
Inbound connectionsNot Configured
Outbound connectionsNot Configured
Apply local firewall rulesNot Configured
Apply local connection security rulesNot Configured
Display notificationsNot Configured
Allow unicast responsesNot Configured
Log dropped packetsNot Configured
Log successful connectionsNot Configured
Log file pathNot Configured
Log file maximum size (KB)Not Configured
Connection Security Settings
Administrative Templates
Policy definitions (ADMX files) retrieved from the central store.
Network/DNS Client
PolicySettingComment
Connection-specific DNS suffixEnabled
DNS suffix:emea.tpg.ads
PolicySettingComment
DNS serversEnabled
IP addresses:10.10.56.240 10.10.150.71 10.10.1.240
PolicySettingComment
DNS suffix search listEnabled
DNS Suffixes:emea.tpg.ads,dstver.ru,ds.ru
PolicySettingComment
Dynamic updateEnabled
Primary DNS suffixEnabled
Enter a primary DNS suffix:emea.tpg.ads
PolicySettingComment
Register DNS records with connection-specific DNS suffixEnabled
Register PTR recordsEnabled
Register PTR records:Register only if A record registration succeeds
Network/Network Connections
PolicySettingComment
Prohibit use of Internet Connection Firewall on your DNS domain networkEnabled
Network/Network Connections/Windows Defender Firewall/Domain Profile
PolicySettingComment
Windows Defender Firewall: Protect all network connectionsDisabled
Network/Network Connections/Windows Defender Firewall/Standard Profile
PolicySettingComment
Windows Defender Firewall: Protect all network connectionsDisabled
System/Group Policy
PolicySettingComment
Configure user Group Policy loopback processing modeEnabled
Mode:Merge
Windows Components/BitLocker Drive Encryption/Operating System Drives
PolicySettingComment
Require additional authentication at startupEnabled
Allow BitLocker without a compatible TPM (requires a password or a startup key on a USB flash drive)Enabled
Settings for computers with a TPM:
Configure TPM startup:Allow TPM
Configure TPM startup PIN:Allow startup PIN with TPM
Configure TPM startup key:Allow startup key with TPM
Configure TPM startup key and PIN:Allow startup key and PIN with TPM
Windows Components/Internet Explorer/Internet Control Panel/Security Page
PolicySettingComment
Site to Zone Assignment ListEnabled
Enter the zone assignments here. 
http://agentservice.xbox.com2
https://agentservice.xbox.com2
http://edccs.partners.extranet.microsoft.com2
https://edccs.partners.extranet.microsoft.com2
https://pssoe.partners.extranet.microsoft.com/OECC/CustomerSearch.aspx2
http://hotfixex.partners.extranet.microsoft.com/2
https://hotfixex.partners.extranet.microsoft.com/2
https://supportdiagnostics.partners.extranet.microsoft.com/ 2
https://vkbexternal.partners.extranet.microsoft.com/2
http://supportdiagnostics.partners.extranet.microsoft.com/ 2
http://*.emea.tpg.ads 2
Preferences
Windows Settings
Files
File (Target Path: %SystemRoot%\System32\drivers\etc\hosts)
hosts file (Order: 1)
General
ActionReplace
Properties
Source file(s)\\rumosfs01.emea.tpg.ads\REMINST\Software\hosts
Destination file%SystemRoot%\System32\drivers\etc\hosts
Suppress errors on individual file actionsEnabled
Attributes
Read-onlyDisabled
HiddenDisabled
ArchiveEnabled
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Registry
Shell (Order: 1)
General
ActionUpdate
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Value nameShell
Value typeREG_SZ
Value dataexplorer.exe
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
AllowElevatedTrustAppsInBrowser (Order: 2)
General
ActionCreate
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSOFTWARE\Wow6432Node\Microsoft\Silverlight
Value nameAllowElevatedTrustAppsInBrowser
Value typeREG_DWORD
Value data0x1 (1)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
AllowLaunchOfElevatedTrustApps (Order: 3)
General
ActionCreate
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSOFTWARE\Wow6432Node\Microsoft\Silverlight
Value nameAllowLaunchOfElevatedTrustApps
Value typeREG_DWORD
Value data0x1 (1)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
AllowElevatedTrustAppsInBrowser (Order: 4)
General
ActionCreate
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSOFTWARE\Microsoft\Silverlight
Value nameAllowElevatedTrustAppsInBrowser
Value typeREG_DWORD
Value data0x1 (1)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
AllowLaunchOfElevatedTrustApps (Order: 5)
General
ActionCreate
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSOFTWARE\Microsoft\Silverlight
Value nameAllowLaunchOfElevatedTrustApps
Value typeREG_DWORD
Value data0x1 (1)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
User Configuration (Enabled)
Preferences
Windows Settings
Registry
ProxyEnable (Order: 1)
General
ActionUpdate
Properties
HiveHKEY_CURRENT_USER
Key pathSoftware\Microsoft\Windows\CurrentVersion\Internet Settings
Value nameProxyEnable
Value typeREG_DWORD
Value data0x0 (0)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Shortcuts
Shortcut (Path: %DesktopDir%\KeePass TP)
KeePass TP (Order: 1)
General
ActionReplace
Attributes
Target typeFile system object
Shortcut path%DesktopDir%\KeePass TP
Target pathC:\PortableApps\KeePassTP\KeePass.exe
Start inC:\PortableApps\KeePassTP
Icon pathC:\PortableApps\KeePassTP\KeePass.exe
Icon index0
Shortcut keyNone
RunNormal window
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)Yes
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Control Panel Settings
Internet Settings
Internet Explorer 10: Internet Explorer 10 MCGW (Order: 1)
General
Startup
Startup optionsStart with home page
Browsing history
Delete browsing history on exitNo
Tabs
Enable Tabbed Browsing (requires restart)Enabled
Warn me when closing multiple tabsEnabled
Always switch to new tabs when they are createdDisabled
Show previews for individual tabs in the taskbarDisabled
Enable Quick Tabs (requires restart)Enabled
Enable Tab GroupsEnabled
Open only the first home page when Internet Explorer startsDisabled
Open new tabs next to the current tabEnabled
When a new tab is opened, open:A blank page
When a pop-up is encounteredLet Internet Explorer decide how pop-ups should open
Open links from other programs inA new tab in the current window
Security
Security levels
InternetMedium-high
Local IntranetCustom
TrustedMedium-low
RestrictedHigh
Internet
Enable Protected ModeDisabled
Local Intranet
Loose XAMLEnabled
XAML browser applicationsEnabled
XPS documentsEnabled
Permissions for components with manifestsHigh Safety
Run components not signed with Authenticode Enabled
Run components signed with Authenticode Enabled
Allow ActiveX FilteringDisabled
Allow previously unused ActiveX controls to run without promptEnabled
Allow ScriptletsEnabled
Automatic prompting for ActiveX controls Enabled
Binary and script behaviorsEnabled
Display video and animation on a webpage that does not use external media playerDisabled
Download signed ActiveX controls Enabled
Download unsigned ActiveX controls Prompt
Initialize and script ActiveX controls not marked as safe for ScriptingPrompt
Only allow approved domains to use ActiveX without promptEnabled
Run ActiveX controls and plug-insEnabled
Script ActiveX controls marked safe for scripting Enabled
File download Enabled
Font download Enabled
Enable .NET Framework setupEnabled
Access data sources across domains Enabled
Render legacy filtersEnabled
Allow dragging of content between domains into separate windowsDisabled
Allow dragging of content between domains into the same windowDisabled
Allow METAREFRESH Enabled
Allow scripting of Internet Explorer web browser controlEnabled
Allow script-initiated windows without size or position constraints Enabled
Allow webpages to use restricted protocols for active content Prompt
Allow websites to open windows without address or status barsEnabled
Display mixed content Enabled
Do not prompt for client certificate selection when no certificates or only one certificate exists. Enabled
Drag and drop or copy and paste files Enabled
Enable MIME SniffingEnabled
Include local directory path when uploading files to serverEnabled
Launching applications and unsafe filesEnabled
Launching programs and files in an IFRAME Enabled
Navigate sub-frames across different domains Enabled
Submit nonencrypted form data Enabled
Use Phishing FilterDisabled
Use Pop-up Blocker Disabled
Userdata persistence Enabled
Websites in less privileged web content zone can navigate into this zonePrompt
Active scripting Enabled
Allow Programmatic clipboard accessEnabled
Allow Status bar updates via scriptEnabled
Allow websites to prompt for information using scripted windowsEnabled
Enable XSS filterEnabled
Scripting of java applets Enabled
User AuthenticationAutomatic logon with current username and password
Enable Protected ModeDisabled
Trusted
Enable Protected ModeDisabled
Restricted
Enable Protected ModeEnabled
Privacy
Turn on Pop-up BlockerEnabled
Pop-up Blocker Settings: Exceptions
Allowed site*.ihelpu.nl
Allowed site*.paymentgate.ru
Allowed site*.zoho.com
Pop-up Blocker Settings: Notifications and filter level
Play a sound when a pop-up is blockedEnabled
Show Information Bar when a pop-up is blockedEnabled
Filter levelMedium: Block most automatic pop-ups
Never allow websites to request your physical locationDisabled
Disable toolbars and extensions when InPrivate Browsing startsEnabled
Connections
Dial-up settings
Connection behaviorNever dial a connection
Local Area Network (LAN) settings
Automatically detect settingsNo
Use automatic configuration scripthttp://rumosfs01.emea.tpg.ads/autoproxy/proxyMCGW.pac
Proxy server
Use a proxy server for your LAN (These settings will not apply to a dial-up or VPN connections)No
Programs
Choose how you open links
Choose how you open linksAlways in Internet Explorer on the desktop
Open Internet Explorer tiles on the desktopEnabled
Advanced
Accelerated graphics
User software rendering instead of GPU renderingDisabled
Accessibility
Always expand ALT text for imagesDisabled
Enable Caret Browser for new windows and tabsDisabled
Move system caret with focus/selection changesDisabled
Play system soundsDisabled
Reset text size to medium for new windows and tabsDisabled
Reset Zoom level for new windows and tabsDisabled
Browsing
Automatically recover from page layout errors with Compatibility ViewEnabled
Close unused folders in History and Favorites (requires restart)Disabled
Disable Script debugging (Internet Explorer)Enabled
Disable Script debugging (Other)Enabled
Display a notification about every script errorDisabled
Display Accelerator button on selectionDisabled
Enable automatic crash recoveryEnabled
Enable flip aheadDisabled
Enable FTP folder view (outside of Internet Explorer)Enabled
Enable Suggested SitesDisabled
Enable third-party browser extensions (requires restart)Disabled
Enable visual styles on buttons and controls in webpagesEnabled
Enable websites to use the search paneDisabled
Go to an intranet site for a single word entry in the Address barDisabled
Notify when downloads completeEnabled
Reuse windows for launching shortcutsEnabled
Show Friendly HTTP Error messagesEnabled
Tell me if Internet Explorer is not the default web browserEnabled
Underline linksAlways
Use inline AutoCompleteEnabled
Use inline Autocomplete in File Explorer and Run DialogDisabled
Use most recent order when switching tabs with Ctrl+TabDisabled
Use Passive FTP (for firewall and DSL model compatibility)Enabled
Use smooth scrollingEnabled
HTTP 1.1 settings
Use HTTP 1.1Enabled
Use HTTP 1.1 through proxy connectionsEnabled
International
Always show encoded addressesDisabled
Send IDN server namesEnabled
Send IDN server names for Intranet addressesDisabled
Send UTF-8 URLsEnabled
Show Information Bar for encoded addressesEnabled
Multimedia
Enable alternative codecs in HTML5 media elementsEnabled
Enable Automatic Image ResizingEnabled
Play animations in webpagesDisabled
Play sounds in webpagesDisabled
Show image download placeholdersDisabled
Show picturesEnabled
Security
Allow active content from CDs to run on My ComputerDisabled
Allow active content to run in files on My ComputerDisabled
Always send Do Not Track headerDisabled
Allow software to run or install even if the signature is invalidDisabled
Block unsecured images with other mixed contentDisabled
Check for publisher's certificate revocationEnabled
Check for server certificate revocation (requires restart)Enabled
Check for signatures on downloaded programsEnabled
Do not save encrypted pages to diskEnabled
Empty Temporary Internet Files folder when browser is closedEnabled
Enable memory protection to help mitigate online attacksDisabled
Enable DOM StorageEnabled
Enable Enhanced Protected ModeDisabled
Enable Integrated Windows Authentication (requires restart)Enabled
Enable native XMLHTTP supportEnabled
Enable SmartScreen FilterDisabled
Use SSL 2.0Disabled
Use SSL 3.0Disabled
Use TLS 1.0Enabled
Use TLS 1.1Enabled
Use TLS 1.2Enabled
Warn about certificate address mismatchEnabled
Warn if changing between secure and not secure modeDisabled
Warn if POST submittal is redirected to a zone that does not permit postsEnabled
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Apply once and do not reapplyNo
Item-level targeting: Security Group
AttributeValue
boolAND
not0
nameEMEA\RU-L-SEC-Internet Settings AutoConfigMCGW
sidS-1-5-21-513466819-3096973226-347852806-204209
userContext1
primaryGroup0
localGroup0