Group Policy Management
body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } }
Setting Path:
Explanation
No explanation is available for this setting.
Supported On:
Not available
LTVNO-PO-ADM-C-WSUS Client Systems FULLY-PATCHED
Data collected on: 2-9-2025 08:56:23
General
Details
Domainemea.tpg.ads
OwnerEMEA\Domain Admins
Created7-11-2015 13:40:14
Modified9-2-2023 14:45:16
User Revisions0 (AD), 0 (SYSVOL)
Computer Revisions141 (AD), 141 (SYSVOL)
Unique ID{a6bcb274-96cb-4685-959d-5918a500ce6f}
GPO StatusUser settings disabled
Links
LocationEnforcedLink StatusPath
VNONoEnabledemea.tpg.ads/LT/Systems/Clients/VNO

This list only includes links in the domain of the GPO.
Security Filtering
The settings in this GPO can only apply to the following groups, users, and computers:
Name
NT AUTHORITY\Authenticated Users
Delegation
These groups and users have the specified permission for this GPO
NameAllowed PermissionsInherited
EMEA\Domain AdminsEdit settings, delete, modify securityNo
EMEA\LT-L-SEC-Delegation Group Policy Objects Modify AccessEdit settings, delete, modify securityNo
NT AUTHORITY\Authenticated UsersRead (from Security Filtering)No
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSReadNo
NT AUTHORITY\SYSTEMEdit settings, delete, modify securityNo
ROOT\Enterprise AdminsEdit settings, delete, modify securityNo
S-1-5-21-513466819-3096973226-347852806-203252ReadNo
Computer Configuration (Enabled)
Policies
Administrative Templates
Policy definitions (ADMX files) retrieved from the central store.
Windows Components/Delivery Optimization
PolicySettingComment
Download ModeEnabled
Download Mode:HTTP only (0)
Windows Components/Windows Update/Legacy Policies
PolicySettingComment
Allow Automatic Updates immediate installationEnabled
Allow non-administrators to receive update notificationsDisabled
Configure auto-restart reminder notifications for updatesEnabled
Specify the period for auto-restart reminder notifications:
Period (min): 30
PolicySettingComment
Configure auto-restart required notification for updatesEnabled
Specify the method by which the auto-restart required notification is dismissed:
Method: 2 - User Action
PolicySettingComment
Configure auto-restart warning notifications schedule for updatesEnabled
Specify the period for auto-restart warning reminder notifications:
Reminder (hours): 4
Specify the period for auto-restart immiment warning notifications:
Warning (mins): 15
PolicySettingComment
Do not allow update deferral policies to cause scans against Windows UpdateEnabled
Do not display 'Install Updates and Shut Down' option in Shut Down Windows dialog boxEnabled
Enabling Windows Update Power Management to automatically wake up the system to install scheduled updatesEnabled
No auto-restart with logged on users for scheduled automatic updates installationsEnabled
Reschedule Automatic Updates scheduled installationsEnabled
Wait after system
startup (minutes): 15
PolicySettingComment
Turn on recommended updates via Automatic UpdatesEnabled
Turn on Software NotificationsEnabled
Windows Components/Windows Update/Manage end user experience
PolicySettingComment
Always automatically restart at the scheduled timeEnabled
The restart timer will give users this much time to save their
work (minutes): 120
PolicySettingComment
Configure Automatic UpdatesDisabled
Windows Components/Windows Update/Manage updates offered from Windows Server Update Service
PolicySettingComment
Allow signed updates from an intranet Microsoft update service location Enabled
Automatic Updates detection frequencyEnabled
Check for updates at the following
interval (hours): 12
PolicySettingComment
Do not connect to any Windows Update Internet locationsEnabled
Specify intranet Microsoft update service locationEnabled
Set the intranet update service for detecting updates:https://ltvnoms01.emea.tpg.ads:8531
Set the intranet statistics server:https://ltvnoms01.emea.tpg.ads:8531
Set the alternate download server: 
(example: https://IntranetUpd01)
Download files with no Url in the metadata if alternate download server is set. 
Do not enforce TLS certificate pinning for Windows Update client for detecting updates. 
Select the proxy behavior for Windows Update client for detecting updates: 
Extra Registry Settings
Display names for some settings cannot be found. You might be able to resolve this issue by updating the .ADM files used by Group Policy Management.

SettingState
Software\Policies\Microsoft\Windows\WindowsUpdate\AU\AUPowerManagement1
Preferences
Windows Settings
Files
File (Target Path: c:\temp\__restore_pbk.cmd)
__restore_pbk.cmd (Order: 1)
General
ActionUpdate
Properties
Source file(s)\\ltvnoms01.emea.tpg.ads\REMINST\Software\GPOtools\WAHA\__restore_pbk.cmd
Destination filec:\temp\__restore_pbk.cmd
Suppress errors on individual file actionsDisabled
Attributes
Read-onlyDisabled
HiddenDisabled
ArchiveEnabled
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Item-level targeting: Security Group
AttributeValue
boolAND
not0
nameEMEA\LT-L-SEC-GPO Task Scheduler rasphone restore
sidS-1-5-21-513466819-3096973226-347852806-560831
userContext0
primaryGroup0
localGroup0
Registry
Collection: Target Group
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Apply once and do not reapplyNo
Registry item: TargetGroupEnabled
General
ActionReplace
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSOFTWARE\Policies\Microsoft\Windows\WindowsUpdate
Value nameTargetGroupEnabled
Value typeREG_DWORD
Value data0x1 (1)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Registry item: TG: Fully-Patched
General
ActionReplace
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSOFTWARE\Policies\Microsoft\Windows\WindowsUpdate
Value nameTargetGroup
Value typeREG_SZ
Value dataFULLY-PATCHED
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Registry item: TG: TRIAL-STAGE
General
ActionReplace
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSOFTWARE\Policies\Microsoft\Windows\WindowsUpdate
Value nameTargetGroup
Value typeREG_SZ
Value dataTRIAL-STAGE
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Item-level targeting: Security Group
AttributeValue
boolAND
not0
nameEMEA\LT-L-SEC-WSUS Trial Stage
sidS-1-5-21-513466819-3096973226-347852806-434179
userContext0
primaryGroup0
localGroup0
Registry item: TG: WIN10_20H2
General
ActionReplace
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSOFTWARE\Policies\Microsoft\Windows\WindowsUpdate
Value nameTargetGroup
Value typeREG_SZ
Value dataWIN10_20H2
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Item-level targeting: Security Group
AttributeValue
boolAND
not0
nameEMEA\LT-L-SEC-WSUS Win10 20H2
sidS-1-5-21-513466819-3096973226-347852806-751203
userContext0
primaryGroup0
localGroup0
Registry item: TG: WIN10_21H1
General
ActionReplace
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSOFTWARE\Policies\Microsoft\Windows\WindowsUpdate
Value nameTargetGroup
Value typeREG_SZ
Value dataWIN10_21H1
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Item-level targeting: Security Group
AttributeValue
boolAND
not0
nameEMEA\LT-L-SEC-WSUS Win10 21H1
sidS-1-5-21-513466819-3096973226-347852806-875980
userContext0
primaryGroup0
localGroup0
Registry item: TG: WIN10_21H2
General
ActionReplace
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSOFTWARE\Policies\Microsoft\Windows\WindowsUpdate
Value nameTargetGroup
Value typeREG_SZ
Value dataWIN10_21H2
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Item-level targeting: Security Group
AttributeValue
boolAND
not0
nameEMEA\LT-L-SEC-WSUS Win10 21H2
sidS-1-5-21-513466819-3096973226-347852806-1083104
userContext0
primaryGroup0
localGroup0
Control Panel Settings
Scheduled Tasks
Scheduled Task (At least Windows 7) (Name: _Restore PBK)
_Restore PBK (Order: 1)
General
ActionReplace
Task
Name _Restore PBK
Author EMEA\chumakov.5-adm
Description
Run only when user is logged on InteractiveToken
UserId NT AUTHORITY\System
Run with highest privileges HighestAvailable
Hidden No
Configure for 1.2
Enabled Yes
Triggers
1. At startup
Delay task for 1 minute
Stop task if it runs longer than 2 hours
Enabled Yes
Actions
1. Start a program
Program/script C:\Temp\__restore_pbk.cmd
Settings
Stop if the computer ceases to be idle No
Restart if the idle state resumes No
Start the task only if the computer is on AC power No
Stop if the computer switches to battery power No
Allow task to be run on demand No
Stop task if it runs longer than 2 hours
If the running task does not end when requested, force it to stop No
If the task is already running, then the following rule applies IgnoreNew
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Item-level targeting: Security Group
AttributeValue
boolAND
not0
nameEMEA\LT-L-SEC-GPO Task Scheduler rasphone restore
sidS-1-5-21-513466819-3096973226-347852806-560831
userContext0
primaryGroup0
localGroup0
User Configuration (Disabled)
No settings defined.