| LT-PO-SEC-C-Workstations common policy | |
| Data collected on: 2-9-2025 09:03:28 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\efimov.6 |
| Created | 17-5-2017 09:34:04 |
| Modified | 27-2-2025 11:30:40 |
| User Revisions | 1 (AD), 1 (SYSVOL) |
| Computer Revisions | 72 (AD), 72 (SYSVOL) |
| Unique ID | {6636b63d-ca63-4f64-a003-265e12086e82} |
| GPO Status | User settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Clients | No | Enabled | emea.tpg.ads/LT/Systems/Clients |
| Name |
|---|
| NT AUTHORITY\Authenticated Users |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\efimov.6 | Edit settings, delete, modify security | No |
| EMEA\LT-L-SEC-Delegation Group Policy Objects Modify Access | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read (from Security Filtering) | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Policy | Setting |
|---|---|
| Accounts: Guest account status | Disabled |
| Accounts: Rename guest account | "xGuest" |
| Policy | Setting |
|---|---|
| Network access: Let Everyone permissions apply to anonymous users | Disabled |
| Policy | Setting |
|---|---|
| Network security: Do not store LAN Manager hash value on next password change | Enabled |
| Network security: LAN Manager authentication level | Send NTLMv2 response only. Refuse LM & NTLM |
| Policy | Setting |
|---|---|
| Shutdown: Clear virtual memory pagefile | Enabled |
| Policy | Setting |
|---|---|
| Maximum security log size | 3145728 kilobytes |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Full control | This key and subkeys |
| Allow | CREATOR OWNER | Full control | Subkeys only |
| Allow | NT AUTHORITY\SYSTEM | Full control | This key and subkeys |
| Allow | BUILTIN\Administrators | Full control | This key and subkeys |
| Allow | BUILTIN\Users | Read | This key and subkeys |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Issued To | Issued By | Expiration Date | Intended Purposes |
|---|---|---|---|
| plwa2fwvip.emea.tpg.ads | plwa2fwvip.emea.tpg.ads | 31-3-2025 11:35:16 | <All> |
| Zscaler Root CA | Zscaler Root CA | 6-5-2042 02:27:55 | <All> |
| Issued To | Issued By | Expiration Date | Intended Purposes |
|---|---|---|---|
| plwa2fwvip.emea.tpg.ads | plwa2fwvip.emea.tpg.ads | 31-3-2025 11:35:16 | <All> |
| Policy | Setting |
|---|---|
| Policy version | 2.22 |
| Disable stateful FTP | Not Configured |
| Disable stateful PPTP | Not Configured |
| IPsec exempt | Not Configured |
| IPsec through NAT | Not Configured |
| Preshared key encoding | Not Configured |
| SA idle time | Not Configured |
| Strong CRL check | Not Configured |
| Policy | Setting |
|---|---|
| Firewall state | Off |
| Inbound connections | Allow |
| Outbound connections | Allow |
| Apply local firewall rules | Not Configured |
| Apply local connection security rules | Not Configured |
| Display notifications | Not Configured |
| Allow unicast responses | Not Configured |
| Log dropped packets | Not Configured |
| Log successful connections | Not Configured |
| Log file path | Not Configured |
| Log file maximum size (KB) | Not Configured |
| Policy | Setting |
|---|---|
| Firewall state | Off |
| Inbound connections | Allow |
| Outbound connections | Allow |
| Apply local firewall rules | Not Configured |
| Apply local connection security rules | Not Configured |
| Display notifications | Not Configured |
| Allow unicast responses | Not Configured |
| Log dropped packets | Not Configured |
| Log successful connections | Not Configured |
| Log file path | Not Configured |
| Log file maximum size (KB) | Not Configured |
| Policy | Setting |
|---|---|
| Firewall state | Off |
| Inbound connections | Allow |
| Outbound connections | Allow |
| Apply local firewall rules | Not Configured |
| Apply local connection security rules | Not Configured |
| Display notifications | Not Configured |
| Allow unicast responses | Not Configured |
| Log dropped packets | Not Configured |
| Log successful connections | Not Configured |
| Log file path | Not Configured |
| Log file maximum size (KB) | Not Configured |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Connection-specific DNS suffix | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Dynamic update | Enabled | |||
| Primary DNS suffix | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Register DNS records with connection-specific DNS suffix | Enabled | |||
| Register PTR records | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| IPv6 Configuration Policy | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Prohibit use of Internet Connection Firewall on your DNS domain network | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Windows Defender Firewall: Protect all network connections | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Windows Defender Firewall: Protect all network connections | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow administrators to override Device Installation Restriction policies | Enabled | |
| Prevent installation of devices not described by other policy settings | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Specify startup policy processing wait time | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Always wait for the network at computer startup and logon | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not log users on with temporary profiles | Enabled | |
| Wait for remote user profile | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow all trusted apps to install | Enabled | |
| Prevent non-admin users from installing packaged Windows apps | Enabled |
| Policy | Setting | Comment | ||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Let Windows apps access the calendar | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn off Autoplay | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Require additional authentication at startup | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Enable App Installer ms-appinstaller protocol | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Disable help tips | Enabled |
| Policy | Setting | Comment | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Intranet Sites: Include all network paths (UNCs) | Enabled | |||||||||||||
| Intranet Sites: Include all sites that bypass the proxy server | Enabled | |||||||||||||
| Intranet Zone Template | Enabled | |||||||||||||
| ||||||||||||||
| Policy | Setting | Comment | ||||||||||||
| Site to Zone Assignment List | Enabled | |||||||||||||
| ||||||||||||||
| Policy | Setting | Comment | ||||||||||||
| Trusted Sites Zone Template | Enabled | |||||||||||||
| ||||||||||||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Access data sources across domains | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow active content over restricted protocols to access my computer | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow active scripting | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow binary and script behaviors | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow cut, copy or paste operations from the clipboard via script | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow drag and drop or copy and paste files | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow file downloads | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow font downloads | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow installation of desktop items | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow loading of XAML Browser Applications | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow loading of XAML files | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow loading of XPS files | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow META REFRESH | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow only approved domains to use ActiveX controls without prompt | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow scripting of Internet Explorer WebBrowser controls | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow script-initiated windows without size or position constraints | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow scriptlets | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow updates to status bar via script | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow video and animation on a webpage that uses an older media player | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow websites to open windows without status bar or Address bar | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow websites to prompt for information by using scripted windows | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Automatic prompting for ActiveX controls | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Automatic prompting for file downloads | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Display mixed content | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not prompt for client certificate selection when no certificates or only one certificate exists. | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Download signed ActiveX controls | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Download unsigned ActiveX controls | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Enable MIME Sniffing | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Include local path when user is uploading files to a server | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Initialize and script ActiveX controls not marked as safe | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Java permissions | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Launching applications and files in an IFRAME | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Logon options | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Navigate windows and frames across different domains | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Run .NET Framework-reliant components not signed with Authenticode | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Run .NET Framework-reliant components signed with Authenticode | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Run ActiveX controls and plugins | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Script ActiveX controls marked safe for scripting | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Scripting of Java applets | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Software channel permissions | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Submit non-encrypted form data | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn off .NET Framework Setup | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn off first-run prompt | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn on Cross-Site Scripting Filter | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn on Protected Mode | Disabled | |||
| Turn on SmartScreen Filter scan | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Use Pop-up Blocker | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Userdata persistence | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Web sites in less privileged Web content zones can navigate into this zone | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Access data sources across domains | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow active content over restricted protocols to access my computer | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow active scripting | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow binary and script behaviors | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow cut, copy or paste operations from the clipboard via script | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow drag and drop or copy and paste files | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow file downloads | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow font downloads | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow installation of desktop items | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow loading of XAML Browser Applications | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow loading of XAML files | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow loading of XPS files | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow META REFRESH | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow only approved domains to use ActiveX controls without prompt | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow scripting of Internet Explorer WebBrowser controls | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow script-initiated windows without size or position constraints | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow scriptlets | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow updates to status bar via script | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow video and animation on a webpage that uses an older media player | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow websites to open windows without status bar or Address bar | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow websites to prompt for information by using scripted windows | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Automatic prompting for ActiveX controls | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Automatic prompting for file downloads | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Display mixed content | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not prompt for client certificate selection when no certificates or only one certificate exists. | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Download signed ActiveX controls | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Download unsigned ActiveX controls | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Enable MIME Sniffing | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Include local path when user is uploading files to a server | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Initialize and script ActiveX controls not marked as safe | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Java permissions | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Launching applications and files in an IFRAME | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Logon options | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Navigate windows and frames across different domains | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Run .NET Framework-reliant components not signed with Authenticode | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Run .NET Framework-reliant components signed with Authenticode | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Run ActiveX controls and plugins | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Script ActiveX controls marked safe for scripting | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Scripting of Java applets | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Software channel permissions | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Submit non-encrypted form data | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn off .NET Framework Setup | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn off first-run prompt | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn on Cross-Site Scripting Filter | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn on Protected Mode | Disabled | |||
| Turn on SmartScreen Filter scan | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Use Pop-up Blocker | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Userdata persistence | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Web sites in less privileged Web content zones can navigate into this zone | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off Microsoft Defender Antivirus | Enabled |
| Action | Replace |
| Source file(s) | \\emea.tpg.ads\SYSVOL\emea.tpg.ads\Policies\{6636B63D-CA63-4F64-A003-265E12086E82}\Machine\files\hosts |
| Destination file | %SystemRoot%\System32\drivers\etc\hosts |
| Suppress errors on individual file actions | Enabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon |
| Value name | Shell |
| Value type | REG_SZ |
| Value data | explorer.exe |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Wow6432Node\Microsoft\Silverlight |
| Value name | AllowElevatedTrustAppsInBrowser |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Wow6432Node\Microsoft\Silverlight |
| Value name | AllowLaunchOfElevatedTrustApps |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Silverlight |
| Value name | AllowElevatedTrustAppsInBrowser |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Silverlight |
| Value name | AllowLaunchOfElevatedTrustApps |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Windows\Sidebar |
| Value name | TurnOffSidebar |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CLASSES_ROOT |
| Key path | CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6} |
| Value name | System.IsPinnedToNameSpaceTree |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CLASSES_ROOT |
| Key path | Wow6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6} |
| Value name | System.IsPinnedToNameSpaceTree |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CLASSES_ROOT |
| Key path | CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder |
| Value name | Attributes |
| Value type | REG_DWORD |
| Value data | 0xB0940064 (2962489444) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Service name | W32Time |
| Action | Start service |
| Startup type: | Automatic |
| Wait timeout if service is locked: | 30 seconds |
| Log on service as: | No change |
| First failure: | No change |
| Second failure: | No change |
| Subsequent failures: | No change |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |