Group Policy Management
body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } }
Setting Path:
Explanation
No explanation is available for this setting.
Supported On:
Not available
ND-PO-ADM-C-Additional Computer Restrictions
Data collected on: 2-9-2025 09:08:02
General
Details
Domainemea.tpg.ads
OwnerS-1-5-21-513466819-3096973226-347852806-367141
Created14-11-2017 10:12:22
Modified30-7-2025 08:17:34
User Revisions2 (AD), 2 (SYSVOL)
Computer Revisions78 (AD), 78 (SYSVOL)
Unique ID{881bdc93-9db7-46f7-9286-72251489b67b}
GPO StatusEnabled
Links
LocationEnforcedLink StatusPath
ClientsNoEnabledemea.tpg.ads/DK/Systems/Clients
ClientsNoEnabledemea.tpg.ads/FI/Systems/Clients
ClientsNoEnabledemea.tpg.ads/NO/Systems/Clients
ClientsNoEnabledemea.tpg.ads/SE/Systems/Clients

This list only includes links in the domain of the GPO.
Security Filtering
The settings in this GPO can only apply to the following groups, users, and computers:
Name
EMEA\ND-L-SEC-Additional Computer Restrictions
Delegation
These groups and users have the specified permission for this GPO
NameAllowed PermissionsInherited
EMEA\Domain AdminsEdit settings, delete, modify securityNo
EMEA\Domain ComputersReadNo
EMEA\ND-L-SEC-Additional Computer RestrictionsRead (from Security Filtering)No
EMEA\ND-L-SEC-Delegation Modify Group Policy SettingsEdit settings, delete, modify securityNo
NT AUTHORITY\Authenticated UsersReadNo
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSReadNo
NT AUTHORITY\SYSTEMEdit settings, delete, modify securityNo
ROOT\Enterprise AdminsEdit settings, delete, modify securityNo
S-1-5-21-513466819-3096973226-347852806-367141Edit settings, delete, modify securityNo
Computer Configuration (Enabled)
Policies
Windows Settings
Security Settings
Software Restriction Policies
Enforcement
PolicySetting
Apply Software Restriction Policies to the followingAll software files except libraries (such as DLLs)
Apply Software Restriction Policies to the following usersAll users
When applying Software Restriction PoliciesIgnore certificate rules
Designated File Types
File ExtensionFile Type
ADEADE File
ADPADP File
BASBAS File
BATWindows Batch File
CHMCompiled HTML Help file
CMDWindows Command Script
COMMS-DOS Application
CPLControl panel item
CRTSecurity Certificate
EXEApplication
HLPHelp file
HTAHTML Application
INFSetup Information
INSINS File
ISPISP File
LNKShortcut
MDBMDB File
MDEMDE File
MSCMicrosoft Common Console Document
MSIWindows Installer Package
MSPWindows Installer Patch
MSTMST File
OCXActiveX control
PCDPCD File
PIFShortcut to MS-DOS Program
REGRegistration Entries
SCRScreen saver
SHSSHS File
URLInternet Shortcut
VBVisual Basic Source File
WSCWindows Script Component
Trusted Publishers
Trusted publisher managementAllow all administrators and users to manage user's own Trusted Publishers
Certificate verificationNone
Software Restriction Policies/Security Levels
PolicySetting
Default Security LevelUnrestricted
Software Restriction Policies/Additional Rules
Path Rules
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%
Security LevelUnrestricted
Description
Date last modified30-10-2024 07:41:39
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir%
Security LevelUnrestricted
Description
Date last modified30-10-2024 07:41:39
%programfiles%\WindowsApps\Microsoft.WindowsStore*
Security LevelDisallowed
DescriptionDisable Microsoft Windows Store Application
Date last modified30-10-2024 07:42:33
Administrative Templates
Policy definitions (ADMX files) retrieved from the central store.
Control Panel
PolicySettingComment
Allow Online TipsDisabled
Settings Page VisibilityEnabled
Settings Page Visibility:showonly:defaultapps;display;network-ethernet;network-status;dateandtime;regionlanguage;about;display;windowsupdate
Control Panel/Personalization
PolicySettingComment
Prevent changing lock screen and logon imageEnabled
Control Panel/Regional and Language Options
PolicySettingComment
Restricts the UI language Windows uses for all logged usersEnabled
Restrict users to the following language:English
Google/Google Chrome
PolicySettingComment
Allow user feedbackDisabled
Browser sign in settingsEnabled
Browser sign in settingsDisable browser sign-in
Google/Google Chrome/Deprecated policies
PolicySettingComment
Allow sign in to Google ChromeDisabled
Disable Developer ToolsDisabled
Google/Google Chrome/Extensions
PolicySettingComment
Configure extension installation blocklistEnabled
Extension IDs the user should be prevented from installing (or * for all)
*
Google/Google Update/Applications/Google Chrome
PolicySettingComment
Update policy overrideEnabled
PolicyUpdates disabled
Microsoft Edge/Extensions
PolicySettingComment
Control which extensions cannot be installedEnabled
Extension IDs the user should be prevented from installing (or * for all)
*
System/User Profiles
PolicySettingComment
Delete user profiles older than a specified number of days on system restartEnabled
Delete user profiles older than (days)90
Windows Components/Cloud Content
PolicySettingComment
Do not show Windows tipsEnabled
Turn off Microsoft consumer experiencesEnabled
Windows Components/Find My Device
PolicySettingComment
Turn On/Off Find My DeviceDisabled
Windows Components/Maps
PolicySettingComment
Turn off Automatic Download and Update of Map DataEnabled
Turn off unsolicited network traffic on the Offline Maps settings pageEnabled
Windows Components/Messaging
PolicySettingComment
Allow Message Service Cloud SyncDisabled
Windows Components/Microsoft Defender Antivirus
PolicySettingComment
Turn off Microsoft Defender AntivirusEnabled
Windows Components/Microsoft Defender Antivirus/Real-time Protection
PolicySettingComment
Monitor file and program activity on your computerDisabled
Scan all downloaded files and attachmentsDisabled
Turn off real-time protectionEnabled
Turn on behavior monitoringDisabled
Turn on process scanning whenever real-time protection is enabledDisabled
Windows Components/OneDrive
PolicySettingComment
Prevent OneDrive files from syncing over metered connectionsEnabled
Metered Network SettingBlock syncing on all metered connections
PolicySettingComment
Prevent OneDrive from generating network traffic until the user signs in to OneDriveEnabled
Prevent the usage of OneDrive for file storageEnabled
Prevent the usage of OneDrive for file storage on Windows 8.1Enabled
Save documents to OneDrive by defaultDisabled
Windows Components/Push To Install
PolicySettingComment
Turn off Push To Install serviceEnabled
Windows Components/Search
PolicySettingComment
Allow Cloud SearchDisabled
Allow CortanaDisabled
Allow Cortana above lock screenDisabled
Allow search and Cortana to use locationDisabled
Do not allow web searchEnabled
Don't search the web or display web results in SearchEnabled
Don't search the web or display web results in Search over metered connectionsEnabled
Fully disable Search UIEnabled
Windows Components/Store
PolicySettingComment
Disable all apps from Microsoft Store Enabled
Turn off the Store applicationEnabled
Windows Components/Widgets
PolicySettingComment
Allow widgetsDisabled
Windows Components/Windows Game Recording and Broadcasting
PolicySettingComment
Enables or disables Windows Game Recording and BroadcastingDisabled
Windows Components/Windows Security/App and browser protection
PolicySettingComment
Hide the App and browser protection areaEnabled
Prevent users from modifying settingsEnabled
Windows Components/Windows Update/Manage end user experience
PolicySettingComment
Remove access to use all Windows Update featuresDisabled
Preferences
Windows Settings
Registry
Start (Order: 1)
General
ActionUpdate
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSYSTEM\CurrentControlSet\Services\SecurityHealthService
Value nameStart
Value typeREG_DWORD
Value data0x4 (4)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
User Configuration (Enabled)
No settings defined.