| MKSKP-PO-WIN-U-PCI_GECSP_Restrictions | |
| Data collected on: 2-9-2025 09:55:18 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\bahtiri.5-adm |
| Created | 26-3-2021 12:26:26 |
| Modified | 9-2-2023 15:01:00 |
| User Revisions | 1 (AD), 1 (SYSVOL) |
| Computer Revisions | 1 (AD), 1 (SYSVOL) |
| Unique ID | {d3e819e5-1b60-4568-9dbd-e2b26f5b23fe} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| MK | No | Enabled | emea.tpg.ads/MK |
| Name |
|---|
| EMEA\MK-L-SEC-User Restrictions PCI_GESCP |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\bahtiri.5-adm | Edit settings, delete, modify security | No |
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\Domain Computers | Read | No |
| EMEA\MK-L-SEC-Delegation Full Access | Edit settings, delete, modify security | No |
| EMEA\MK-L-SEC-Delegation Read Group Policy results Data Access | Read | No |
| EMEA\MK-L-SEC-User Restrictions PCI_GESCP | Read (from Security Filtering) | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Enforcement | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Designated File Types | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Trusted Publishers | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
| Policy | Setting |
|---|---|
| Default Security Level | Unrestricted |
| Help.Exe (6.3.9600.17415); Help; Command Line Help Utility; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
| ||||||
| MSPAINT.EXE (6.3.9600.17415); MSPAINT; Paint; Microsoft® Windows® Operating System; Microsoft Corporation | ||||||
|
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% | ||||||
| ||||||
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% | ||||||
| ||||||
| C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy | ||||||
|
| Policy | Setting | Comment | |||||||
|---|---|---|---|---|---|---|---|---|---|
| Always open All Control Panel Items when opening Control Panel | Enabled | ||||||||
| Prohibit access to Control Panel and PC settings | Enabled | ||||||||
| Show only specified Control Panel items | Enabled | ||||||||
| |||||||||
| Policy | Setting | Comment |
|---|---|---|
| Hide Add/Remove Windows Components page | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Disable the Display Control Panel | Enabled | |
| Hide Settings tab | Enabled |
| Policy | Setting | Comment | ||||||
|---|---|---|---|---|---|---|---|---|
| Enable screen saver | Enabled | |||||||
| Password protect the screen saver | Enabled | |||||||
| Prevent changing color and appearance | Enabled | |||||||
| Prevent changing color scheme | Enabled | |||||||
| Prevent changing desktop background | Enabled | |||||||
| Prevent changing desktop icons | Enabled | |||||||
| Prevent changing mouse pointers | Enabled | |||||||
| Prevent changing screen saver | Enabled | |||||||
| Prevent changing theme | Enabled | |||||||
| Prevent changing visual style for windows and buttons | Enabled | |||||||
| Prohibit selection of visual style font size | Enabled | |||||||
| Screen saver timeout | Enabled | |||||||
| ||||||||
| Policy | Setting | Comment |
|---|---|---|
| Browse a common web site to find printers | Disabled | |
| Browse the network to find printers | Disabled | |
| Default Active Directory path when searching for printers | Disabled | |
| Package Point and print - Approved servers | Disabled | |
| Point and Print Restrictions | Disabled | |
| Prevent addition of printers | Enabled | |
| Prevent deletion of printers | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not add shares of recently opened documents to Network Locations | Enabled | |
| Don't save settings at exit | Enabled | |
| Hide and disable all items on the desktop | Disabled | |
| Hide Network Locations icon on desktop | Enabled | |
| Prevent adding, dragging, dropping and closing the Taskbar's toolbars | Enabled | |
| Prohibit adjusting desktop toolbars | Enabled | |
| Prohibit User from manually redirecting Profile Folders | Enabled | |
| Remove Computer icon on the desktop | Enabled | |
| Remove My Documents icon on the desktop | Enabled | |
| Remove Properties from the Computer icon context menu | Enabled | |
| Remove Properties from the Documents icon context menu | Enabled | |
| Remove Properties from the Recycle Bin context menu | Enabled | |
| Remove Recycle Bin icon from desktop | Enabled | |
| Remove the Desktop Cleanup Wizard | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Hide Active Directory folder | Enabled | |||
| Maximum size of Active Directory searches | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Disable all items | Enabled | |
| Prohibit adding items | Enabled | |
| Prohibit changes | Enabled | |
| Prohibit deleting items | Enabled | |
| Prohibit editing items | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Choose how to specify proxy server settings | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| URL to a proxy .pac file | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||||
|---|---|---|---|---|---|---|---|---|
| Blocked websites | Enabled | |||||||
| ||||||||
| Policy | Setting | Comment | ||||||
| Disable Firefox Accounts | Enabled | |||||||
| Disable Private Browsing | Enabled | |||||||
| Display Menu Bar (Deprecated) | Disabled | |||||||
| Policy | Setting | Comment | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Automatic proxy configuration URL | Enabled | |||||||||
| ||||||||||
| Policy | Setting | Comment | ||||||||
| Connection Type | Enabled | |||||||||
| ||||||||||
| Policy | Setting | Comment | ||||||||
| Do not allow proxy settings to be changed | Enabled | |||||||||
| Do not prompt for authentication if password is saved | Disabled | |||||||||
| HTTP Proxy | Enabled | |||||||||
| ||||||||||
| Policy | Setting | Comment | ||||||||
| HTTPS Proxy | Enabled | |||||||||
| ||||||||||
| Policy | Setting | Comment | ||||||||
| Proxy DNS when using SOCKS v5 | Disabled | |||||||||
| Proxy Passthrough | Enabled | |||||||||
| ||||||||||
| Policy | Setting | Comment | ||||||||
| SOCKS Host | Enabled | |||||||||
| ||||||||||
| Policy | Setting | Comment | ||||||||
| Use HTTP proxy for HTTPS | Enabled | |||||||||
| Policy | Setting | Comment |
|---|---|---|
| Ability to change properties of an all user remote access connection | Disabled | |
| Ability to Enable/Disable a LAN connection | Disabled | |
| Ability to rename all user remote access connections | Disabled | |
| Ability to rename LAN connections | Disabled | |
| Ability to rename LAN connections or remote access connections available to all users | Disabled | |
| Prohibit access to properties of a LAN connection | Enabled | |
| Prohibit access to properties of components of a LAN connection | Enabled | |
| Prohibit access to properties of components of a remote access connection | Enabled | |
| Prohibit access to the Advanced Settings item on the Advanced menu | Enabled | |
| Prohibit access to the New Connection Wizard | Enabled | |
| Prohibit access to the Remote Access Preferences item on the Advanced menu | Enabled | |
| Prohibit adding and removing components for a LAN or remote access connection | Enabled | |
| Prohibit connecting and disconnecting a remote access connection | Enabled | |
| Prohibit Enabling/Disabling components of a LAN connection | Enabled | |
| Prohibit TCP/IP advanced configuration | Enabled |
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Add "Run in Separate Memory Space" check box to Run dialog box | Disabled | |||||
| Add Logoff to the Start Menu | Enabled | |||||
| Add Search Internet link to Start Menu | Disabled | |||||
| Add the Run command to the Start Menu | Disabled | |||||
| Change Start Menu power button | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Clear history of recently opened documents on exit | Enabled | |||||
| Clear the recent programs list for new users | Enabled | |||||
| Clear tile notifications during log on | Enabled | |||||
| Disable showing balloon notifications as toasts. | Enabled | |||||
| Do not allow pinning programs to the Taskbar | Enabled | |||||
| Do not allow pinning Store app to the Taskbar | Enabled | |||||
| Do not display any custom toolbars in the taskbar | Enabled | |||||
| Do not keep history of recently opened documents | Enabled | |||||
| Do not search communications | Enabled | |||||
| Do not search for files | Enabled | |||||
| Do not search Internet | Enabled | |||||
| Do not search programs and Control Panel items | Enabled | |||||
| Force classic Start Menu | Disabled | |||||
| Force Start to be either full screen size or menu size | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Gray unavailable Windows Installer programs Start Menu shortcuts | Enabled | |||||
| Prevent changes to Taskbar and Start Menu Settings | Enabled | |||||
| Prevent grouping of taskbar items | Enabled | |||||
| Prevent users from adding or removing toolbars | Enabled | |||||
| Prevent users from customizing their Start Screen | Enabled | |||||
| Prevent users from moving taskbar to another screen dock location | Enabled | |||||
| Prevent users from rearranging toolbars | Enabled | |||||
| Prevent users from uninstalling applications from Start | Enabled | |||||
| Remove access to the context menus for the taskbar | Enabled | |||||
| Remove All Programs list from the Start menu | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Remove Balloon Tips on Start Menu items | Enabled | |||||
| Remove common program groups from Start Menu | Enabled | |||||
| Remove Default Programs link from the Start menu. | Enabled | |||||
| Remove Documents icon from Start Menu | Enabled | |||||
| Remove Downloads link from Start Menu | Enabled | |||||
| Remove Favorites menu from Start Menu | Enabled | |||||
| Remove Games link from Start Menu | Enabled | |||||
| Remove Help menu from Start Menu | Enabled | |||||
| Remove Homegroup link from Start Menu | Enabled | |||||
| Remove links and access to Windows Update | Enabled | |||||
| Remove Music icon from Start Menu | Enabled | |||||
| Remove Network Connections from Start Menu | Enabled | |||||
| Remove Network icon from Start Menu | Enabled | |||||
| Remove Notifications and Action Center | Enabled | |||||
| Remove Pictures icon from Start Menu | Enabled | |||||
| Remove pinned programs from the Taskbar | Enabled | |||||
| Remove programs on Settings menu | Enabled | |||||
| Remove Recorded TV link from Start Menu | Enabled | |||||
| Remove Run menu from Start Menu | Enabled | |||||
| Remove Search Computer link | Enabled | |||||
| Remove Search link from Start Menu | Enabled | |||||
| Remove See More Results / Search Everywhere link | Enabled | |||||
| Remove the People Bar from the taskbar | Enabled | |||||
| Remove the Security and Maintenance icon | Enabled | |||||
| Remove user folder link from Start Menu | Enabled | |||||
| Remove user's folders from the Start Menu | Enabled | |||||
| Remove Videos link from Start Menu | Enabled | |||||
| Search just apps from the Apps view | Disabled | |||||
| Show "Run as different user" command on Start | Disabled | |||||
| Show QuickLaunch on Taskbar | Enabled | |||||
| Show the Apps view automatically when the user goes to Start | Disabled | |||||
| Show Windows Store apps on the taskbar | Disabled | |||||
| Start Layout | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Turn off all balloon notifications | Enabled | |||||
| Turn off automatic promotion of notification icons to the taskbar | Enabled | |||||
| Turn off feature advertisement balloon notifications | Enabled | |||||
| Turn off notification area cleanup | Enabled | |||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off tile notifications | Enabled | |
| Turn off toast notifications | Enabled |
| Policy | Setting | Comment | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Do not display the Getting Started welcome screen at logon | Enabled | ||||||||||||||||||
| Don't run specified Windows applications | Enabled | ||||||||||||||||||
| |||||||||||||||||||
| Policy | Setting | Comment | |||||||||||||||||
| Prevent access to registry editing tools | Enabled | ||||||||||||||||||
| |||||||||||||||||||
| Policy | Setting | Comment | |||||||||||||||||
| Prevent access to the command prompt | Enabled | ||||||||||||||||||
| |||||||||||||||||||
| Policy | Setting | Comment | |||||||||||||||||
| Restrict these programs from being launched from Help | Enabled | ||||||||||||||||||
| |||||||||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Remove Task Manager | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Restrict Internet communication | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off downloading of print drivers over HTTP | Enabled | |
| Turn off handwriting personalization data sharing | Enabled | |
| Turn off handwriting recognition error reporting | Enabled | |
| Turn off Help Experience Improvement Program | Enabled | |
| Turn off Help Ratings | Enabled | |
| Turn off Internet download for Web publishing and online ordering wizards | Enabled | |
| Turn off Internet File Association service | Enabled | |
| Turn off printing over HTTP | Enabled | |
| Turn off the "Order Prints" picture task | Enabled | |
| Turn off the "Publish to Web" task for files and folders | Enabled | |
| Turn off the Windows Messenger Customer Experience Improvement Program | Enabled | |
| Turn off Windows Online | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| All Removable Storage classes: Deny all access | Enabled | |
| CD and DVD: Deny read access | Enabled | |
| CD and DVD: Deny write access | Enabled | |
| Floppy Drives: Deny read access | Enabled | |
| Floppy Drives: Deny write access | Enabled | |
| Removable Disks: Deny read access | Enabled | |
| Removable Disks: Deny write access | Enabled | |
| Tape Drives: Deny read access | Enabled | |
| Tape Drives: Deny write access | Enabled | |
| WPD Devices: Deny read access | Enabled | |
| WPD Devices: Deny write access | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Windows HotStart | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent the wizard from running. | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Set the default behavior for AutoRun | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn off Autoplay | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Restrict unpacking and installation of gadgets that are not digitally signed. | Enabled | |
| Turn off desktop gadgets | Enabled | |
| Turn Off user-installed desktop gadgets | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not allow color changes | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow edge swipe | Disabled | |
| Disable help tips | Enabled | |
| Do not show recent apps when the mouse is pointing to the upper-left corner of the screen | Enabled | |
| Prevent users from replacing the Command Prompt with Windows PowerShell in the menu they see when they right-click the lower-left corner or press the Windows logo key+X | Enabled | |
| Search, Share, Start, Devices, and Settings don't appear when the mouse is pointing to the upper-right corner of the screen | Enabled | |
| Turn off switching between recent apps | Enabled | |
| Turn off tracking of app usage | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Display the menu bar in File Explorer | Disabled | |||
| Do not move deleted files to the Recycle Bin | Enabled | |||
| Hide these specified drives in My Computer | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Hides the Manage item on the File Explorer context menu | Enabled | |||
| No Computers Near Me in Network Locations | Enabled | |||
| No Entire Network in Network Locations | Enabled | |||
| Prevent access to drives from My Computer | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Prevent users from adding files to the root of their Users Files folder. | Enabled | |||
| Remove "Map Network Drive" and "Disconnect Network Drive" | Enabled | |||
| Remove CD Burning features | Enabled | |||
| Remove File Explorer's default context menu | Enabled | |||
| Remove File menu from File Explorer | Enabled | |||
| Remove Hardware tab | Enabled | |||
| Remove Search button from File Explorer | Enabled | |||
| Remove Security tab | Enabled | |||
| Remove Shared Documents from My Computer | Enabled | |||
| Remove the Search the Internet "Search again" link | Enabled | |||
| Remove UI to change keyboard navigation indicator setting | Enabled | |||
| Remove UI to change menu animation setting | Enabled | |||
| Turn off the caching of thumbnails in hidden thumbs.db files | Enabled | |||
| Turn off Windows Key hotkeys | Enabled | |||
| Policy | Setting | Comment | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Hide the dropdown list of recent files | Enabled | |||||||||||||
| Items displayed in Places Bar | Enabled | |||||||||||||
| ||||||||||||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn off Preview Pane | Enabled | |||
| Turn on or off details pane | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Hide previous versions list for local files | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Search: Disable Search Customization | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| File menu: Disable Save As Web Page Complete | Enabled | |
| File menu: Disable Save As... menu option | Enabled | |
| Help menu: Remove 'For Netscape Users' menu option | Enabled | |
| Help menu: Remove 'Send Feedback' menu option | Enabled | |
| Help menu: Remove 'Tip of the Day' menu option | Enabled | |
| Help menu: Remove 'Tour' menu option | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Allow deleting browsing history on exit | Enabled | |||
| Disable "Configuring History" | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Disable the Advanced page | Enabled | |
| Disable the Connections page | Enabled | |
| Disable the Content page | Enabled | |
| Disable the General page | Enabled | |
| Disable the Privacy page | Enabled | |
| Disable the Programs page | Enabled | |
| Disable the Security page | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Allow websites to store application caches on client computers | Enabled | |||
| Set application caches expiration time limit for individual domains | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Configure Toolbar Buttons | Enabled | |||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||||||||||||||||||||||||
| Disable customizing browser toolbar buttons | Enabled | |||||||||||||||||||||||||||||||||||||||||
| Disable customizing browser toolbars | Enabled | |||||||||||||||||||||||||||||||||||||||||
| Display tabs on a separate row | Enabled | |||||||||||||||||||||||||||||||||||||||||
| Lock all toolbars | Enabled | |||||||||||||||||||||||||||||||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Prevent Microsoft Edge from gathering Live Tile information when pinning a site to Start | Enabled | |
| Prevent the First Run webpage from opening on Microsoft Edge | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off the Store application | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prohibit New Task Creation | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Configure Windows Defender SmartScreen | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not send additional data | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent removable media source for any installation | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Report when logon server was not available during user logon | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Windows Mail application | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not allow Windows Media Center to run | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent CD and DVD Media Information Retrieval | Enabled | |
| Prevent Music File Media Information Retrieval | Enabled | |
| Prevent Radio Station Preset Retrieval | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do Not Show Anchor | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not allow Windows Messenger to be run | Enabled | |
| Do not automatically start Windows Messenger initially | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Windows Mobility Center | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn on Script Execution | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Windows SideShow | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Remove access to use all Windows Update features | Enabled | |||
| ||||
| Setting | State |
|---|---|
| Software\Policies\Mozilla\Firefox\Proxy\FTPProxy |