| NLCTX-PO-WIN-C-SBC | |
| Data collected on: 2-9-2025 09:13:19 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\timmermans.5 |
| Created | 15-5-2018 11:56:38 |
| Modified | 28-6-2024 12:56:54 |
| User Revisions | 0 (AD), 0 (SYSVOL) |
| Computer Revisions | 151 (AD), 151 (SYSVOL) |
| Unique ID | {9aa6f0da-3fdf-4765-bb36-7996dcd0241e} |
| GPO Status | User settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| SBC | No | Enabled | emea.tpg.ads/NL/Systems/CitrixBNL/SBC |
| BOL | No | Enabled | emea.tpg.ads/NL/Systems/Test/SBC/BOL |
| Canada Goose | No | Enabled | emea.tpg.ads/NL/Systems/Test/SBC/Canada Goose |
| Covid Support | No | Enabled | emea.tpg.ads/NL/Systems/Test/SBC/Covid Support |
| Eneco | No | Enabled | emea.tpg.ads/NL/Systems/Test/SBC/Eneco |
| IKEA | No | Enabled | emea.tpg.ads/NL/Systems/Test/SBC/IKEA |
| Lidl | No | Enabled | emea.tpg.ads/NL/Systems/Test/SBC/Lidl |
| Operations | No | Enabled | emea.tpg.ads/NL/Systems/Test/SBC/Operations |
| Samsung | No | Enabled | emea.tpg.ads/NL/Systems/Test/SBC/Samsung |
| Telfort | No | Disabled | emea.tpg.ads/NL/Systems/Test/SBC/Telfort |
| Test | No | Enabled | emea.tpg.ads/NL/Systems/Test/SBC/Test |
| Wehkamp | No | Enabled | emea.tpg.ads/NL/Systems/Test/SBC/Wehkamp |
| Zalando | No | Enabled | emea.tpg.ads/NL/Systems/Test/SBC/Zalando |
| HSD | No | Enabled | emea.tpg.ads/SR/Systems/Citrix/HSD |
| Name |
|---|
| NT AUTHORITY\Authenticated Users |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\NL-L-SEC-Delegation Modify Group Policy Settings Access | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read (from Security Filtering) | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Policy | Setting |
|---|---|
| Audit process tracking | Success |
| Policy | Setting |
|---|---|
| Change the time zone | Everyone |
| Policy | Setting |
|---|---|
| Policy version | Not Configured |
| Disable stateful FTP | Not Configured |
| Disable stateful PPTP | Not Configured |
| IPsec exempt | Not Configured |
| IPsec through NAT | Not Configured |
| Preshared key encoding | Not Configured |
| SA idle time | Not Configured |
| Strong CRL check | Not Configured |
| Policy | Setting |
|---|---|
| Firewall state | Off |
| Inbound connections | Not Configured |
| Outbound connections | Not Configured |
| Apply local firewall rules | Not Configured |
| Apply local connection security rules | Not Configured |
| Display notifications | No |
| Allow unicast responses | Not Configured |
| Log dropped packets | Not Configured |
| Log successful connections | Not Configured |
| Log file path | Not Configured |
| Log file maximum size (KB) | Not Configured |
| Policy | Setting | Comment |
|---|---|---|
| EnableFTU | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent changing lock screen and logon image | Enabled | |
| Prevent changing start menu background | Enabled | |
| Prevent enabling lock screen camera | Enabled | |
| Prevent enabling lock screen slide show | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Apply the default account picture to all users | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Import bookmarks from default browser on first run | Enabled | |
| Use hardware acceleration when available | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Update policy override default | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Update policy override default | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Enable Automatic Updates | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Disable Profile Import | Enabled | |||
| Disable Update | Enabled | |||
| Don't Check Default Browser | Enabled | |||
| Override the first run page | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Windows Defender Firewall: Prohibit notifications | Enabled | |
| Windows Defender Firewall: Protect all network connections | Disabled |
| Policy | Setting | Comment | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Point and Print Restrictions | Enabled | |||||||||||||||||||
| ||||||||||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Display highly detailed status messages | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Configure Logon Script Delay | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Configure user Group Policy loopback processing mode | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Always wait for the network at computer startup and logon | Enabled | |||||
| Assign a default domain for logon | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Hide entry points for Fast User Switching | Enabled | |||||
| Show first sign-in animation | Disabled | |||||
| Turn off Windows Startup sound | Enabled | |||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Select an active power plan | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Specify the system sleep timeout (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Specify the unattended sleep timeout (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn off hybrid sleep (plugged in) | Enabled | |||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn off the display (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Run logon scripts synchronously | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off System Restore | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Add the Administrators security group to roaming user profiles | Enabled | |||
| Delete cached copies of roaming profiles | Enabled | |||
| Delete user profiles older than a specified number of days on system restart | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Allow deployment operations in special profiles | Disabled |
| Policy | Setting | Comment | ||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Let Windows apps access the microphone | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn off Autoplay | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Do not show Windows tips | Enabled | |
| Turn off Microsoft consumer experiences | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent the usage of OneDrive for file storage | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow audio and video playback redirection | Enabled | |
| Allow audio recording redirection | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not allow client printer redirection | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Remove "Disconnect" option from Shut Down dialog | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Set time limit for active but idle Remote Desktop Services sessions | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Set time limit for disconnected sessions | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||||
|---|---|---|---|---|---|---|---|---|
| Allow Cortana | Disabled | |||||||
| Prevent indexing certain paths | Enabled | |||||||
| ||||||||
| Policy | Setting | Comment | ||||||
| Prevent indexing e-mail attachments | Enabled | |||||||
| Prevent indexing Microsoft Office Outlook | Enabled | |||||||
| Policy | Setting | Comment |
|---|---|---|
| Disable all apps from Microsoft Store | Enabled | |
| Turn off Automatic Download and Install of updates | Enabled | |
| Turn off the offer to update to the latest version of Windows | Enabled | |
| Turn off the Store application | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do Not Show First Use Dialog Boxes | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow Automatic Updates immediate installation | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Configure Automatic Updates | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not connect to any Windows Update Internet locations | Enabled |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\WOW6432Node\Avaya\Avaya one-X Agent\Settings |
| Value name | CentralManagementUri |
| Value type | REG_SZ |
| Value data | https://deffmacm01.emea.tpg.ads/ACCCMONEXCFG/ |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Citrix\wfshell\TWI |
| Value name | ApplicationLaunchWaitTimeoutMS |
| Value type | REG_DWORD |
| Value data | 0x57E40 (360000) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Google\Update |
| Value name | UpdateDefault |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint |
| Value name | RestrictDriverInstallationToAdministrators |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\EXPLORER.EXE |
| Value name | DontUseDesktopChangeRouter |
| Value type | REG_SZ |
| Value data | 1 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Citrix\wfshell\TWI |
| Value name | SeamlessFlags |
| Value type | REG_DWORD |
| Value data | 0x2000 (8192) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Office\16.0\Common\Licensing |
| Value name | SharedComputerLicensing |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Teams |
| Value name | disableAutoUpdate |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\WOW6432Node\Citrix\WebSocketService |
| Value name | ProcessWhitelist |
| Value type | REG_MULTI_SZ |
| Line | Value |
|---|---|
| 1 | msedgewebview2.exe |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Group name | Administrators (built-in) |
| Delete all member users | Disabled |
| Delete all member groups | Disabled |
| EMEA\NL-L-SEC-Delegation Local Administration Rights Client HSD | S-1-5-21-513466819-3096973226-347852806-1487080 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |