| NLCTX-PO-WIN-C-VDI | |
| Data collected on: 2-9-2025 09:13:21 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\timmermans.5 |
| Created | 15-5-2018 11:57:20 |
| Modified | 13-8-2025 11:20:56 |
| User Revisions | 0 (AD), 0 (SYSVOL) |
| Computer Revisions | 328 (AD), 328 (SYSVOL) |
| Unique ID | {7162ef34-232d-4574-b576-4e79074bdb53} |
| GPO Status | User settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| VDI | No | Enabled | emea.tpg.ads/NL/Systems/CitrixBNL/VDI |
| Belvilla | No | Enabled | emea.tpg.ads/NL/Systems/Test/VDI/Belvilla |
| Beter Bed | No | Enabled | emea.tpg.ads/NL/Systems/Test/VDI/Beter Bed |
| BOL | No | Enabled | emea.tpg.ads/NL/Systems/Test/VDI/BOL |
| Caiway | No | Enabled | emea.tpg.ads/NL/Systems/Test/VDI/Caiway |
| Canada Goose | No | Enabled | emea.tpg.ads/NL/Systems/Test/VDI/Canada Goose |
| Covid Support | No | Enabled | emea.tpg.ads/NL/Systems/Test/VDI/Covid Support |
| Eneco | No | Enabled | emea.tpg.ads/NL/Systems/Test/VDI/Eneco |
| Essent | No | Enabled | emea.tpg.ads/NL/Systems/Test/VDI/Essent |
| Grohe | No | Enabled | emea.tpg.ads/NL/Systems/Test/VDI/Grohe |
| G-star | No | Enabled | emea.tpg.ads/NL/Systems/Test/VDI/G-star |
| Hello Fresh BE | No | Enabled | emea.tpg.ads/NL/Systems/Test/VDI/Hello Fresh BE |
| IKEA | No | Enabled | emea.tpg.ads/NL/Systems/Test/VDI/IKEA |
| Jumbo | No | Enabled | emea.tpg.ads/NL/Systems/Test/VDI/Jumbo |
| Lenovo | No | Enabled | emea.tpg.ads/NL/Systems/Test/VDI/Lenovo |
| MediaMarkt | No | Enabled | emea.tpg.ads/NL/Systems/Test/VDI/MediaMarkt |
| Samsung | No | Enabled | emea.tpg.ads/NL/Systems/Test/VDI/Samsung |
| Telfort | No | Enabled | emea.tpg.ads/NL/Systems/Test/VDI/Telfort |
| Test | No | Enabled | emea.tpg.ads/NL/Systems/Test/VDI/Test |
| Wehkamp | No | Enabled | emea.tpg.ads/NL/Systems/Test/VDI/Wehkamp |
| Zalando | No | Enabled | emea.tpg.ads/NL/Systems/Test/VDI/Zalando |
| Ziggo | No | Enabled | emea.tpg.ads/NL/Systems/Test/VDI/Ziggo |
| Bol | No | Enabled | emea.tpg.ads/TR/Systems/Citrix/VDI/Bol |
| Name |
|---|
| NT AUTHORITY\Authenticated Users |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\NL-L-SEC-Delegation Modify Group Policy Settings Access | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read (from Security Filtering) | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Policy | Setting |
|---|---|
| Audit process tracking | Success |
| Policy | Setting |
|---|---|
| Change the time zone | Everyone |
| Policy | Setting |
|---|---|
| Accounts: Rename administrator account | "Apollo" |
| Policy | Setting |
|---|---|
| Devices: Prevent users from installing printer drivers | Disabled |
| Policy | Setting |
|---|---|
| Interactive logon: Machine inactivity limit | 300 seconds |
| Owner | NT SERVICE\TrustedInstaller |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | BUILTIN\Administrators | Full control | This key and subkeys |
| Allow | CREATOR OWNER | Full control | Subkeys only |
| Allow | NT AUTHORITY\SYSTEM | Full control | This key and subkeys |
| Allow | BUILTIN\Users | Read | This key and subkeys |
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read | This key and subkeys |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Policy | Setting |
|---|---|
| Policy version | 2.22 |
| Disable stateful FTP | Not Configured |
| Disable stateful PPTP | Not Configured |
| IPsec exempt | Not Configured |
| IPsec through NAT | Not Configured |
| Preshared key encoding | Not Configured |
| SA idle time | Not Configured |
| Strong CRL check | Not Configured |
| Policy | Setting |
|---|---|
| Firewall state | Off |
| Inbound connections | Not Configured |
| Outbound connections | Not Configured |
| Apply local firewall rules | Not Configured |
| Apply local connection security rules | Not Configured |
| Display notifications | No |
| Allow unicast responses | Not Configured |
| Log dropped packets | Not Configured |
| Log successful connections | Not Configured |
| Log file path | Not Configured |
| Log file maximum size (KB) | Not Configured |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| High DPI | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Settings Page Visibility | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Prevent changing lock screen and logon image | Enabled | |
| Prevent changing start menu background | Enabled | |
| Prevent enabling lock screen camera | Enabled | |
| Prevent enabling lock screen slide show | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Apply the default account picture to all users | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Update policy override default | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Update policy override default | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Update policy override | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Update policy override | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Enable Automatic Updates | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| IPv6 Configuration Policy | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Windows Defender Firewall: Prohibit notifications | Enabled | |
| Windows Defender Firewall: Protect all network connections | Disabled |
| Policy | Setting | Comment | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Point and Print Restrictions | Enabled | |||||||||||||||||||
| ||||||||||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Remove and prevent access to the Shut Down, Restart, Sleep, and Hibernate commands | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Display highly detailed status messages | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Configure Logon Script Delay | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Always wait for the network at computer startup and logon | Enabled | |||||
| Assign a default domain for logon | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Hide entry points for Fast User Switching | Enabled | |||||
| Show first sign-in animation | Disabled | |||||
| Turn off Windows Startup sound | Enabled | |||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Select an active power plan | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Specify the system sleep timeout (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Specify the unattended sleep timeout (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn off hybrid sleep (plugged in) | Enabled | |||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn off the display (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Run logon scripts synchronously | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off System Restore | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Add the Administrators security group to roaming user profiles | Enabled | |||
| Delete cached copies of roaming profiles | Enabled | |||
| Delete user profiles older than a specified number of days on system restart | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not check for user ownership of Roaming Profile Folders | Enabled | |||
| Set maximum wait time for the network if a user has a roaming user profile or remote home directory | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Allow deployment operations in special profiles | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn off Autoplay | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Do not show Windows tips | Enabled | |
| Turn off Microsoft consumer experiences | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Block all consumer Microsoft account user authentication | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Microsoft Defender Antivirus | Enabled |
| Policy | Setting | Comment | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Path Exclusions | Enabled | |||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||||||||||||||
| Process Exclusions | Enabled | |||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Scan all downloaded files and attachments | Disabled | |
| Turn on process scanning whenever real-time protection is enabled | Disabled |
| Policy | Setting | Comment | ||||||
|---|---|---|---|---|---|---|---|---|
| Configure Sync Method | Enabled | |||||||
| ||||||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Prevent OneDrive files from syncing over metered connections | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Prevent the usage of OneDrive for file storage | Enabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Do not allow client printer redirection | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Set time limit for disconnected sessions | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||||
|---|---|---|---|---|---|---|---|---|
| Allow Cloud Search | Disabled | |||||||
| Allow Cortana | Disabled | |||||||
| Fully disable Search UI | Enabled | |||||||
| Prevent indexing certain paths | Enabled | |||||||
| ||||||||
| Policy | Setting | Comment | ||||||
| Prevent indexing e-mail attachments | Enabled | |||||||
| Prevent indexing Microsoft Office Outlook | Enabled | |||||||
| Policy | Setting | Comment |
|---|---|---|
| Disable all apps from Microsoft Store | Enabled | |
| Turn off Automatic Download and Install of updates | Enabled | |
| Turn off the offer to update to the latest version of Windows | Enabled | |
| Turn off the Store application | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do Not Show First Use Dialog Boxes | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Hide all notifications | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Always automatically restart at the scheduled time | Disabled | |
| Configure Automatic Updates | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not connect to any Windows Update Internet locations | Enabled |
| Action | Update |
| File path | c:\Program Files\Mozilla Firefox\browser\override.ini |
| Section name | XRE |
| Property name | EnableProfileMigrator |
| Property value | false |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows\Explorer |
| Value name | HideRecentlyAddedApps |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\DefaultMediaCost |
| Value name | Ethernet |
| Value type | REG_DWORD |
| Value data | 0x2 (2) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Turn on Metered mode |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | Software\Microsoft\Windows\CurrentVersion\Explorer |
| Value name | SpecialRoamingOverrideAllowed |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Value name | SecurityHealth |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| remove security icon taskbar |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run |
| Value name | ConnectionCenter |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Remove Citrix logon screen on startup |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows\GameDVR |
| Value name | AllowgameDVR |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Wow6432Node\Citrix\Dazzle |
| Value name | AllowAddStore |
| Value type | REG_SZ |
| Value data | A |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\WOW6432Node\Avaya\Avaya one-X Agent\Settings |
| Value name | CentralManagementUri |
| Value type | REG_SZ |
| Value data | https://deffmacm01.emea.tpg.ads/ACCCMONEXCFG/ |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Citrix\GroupPolicy |
| Value name | SaveRsopToFile |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Citrix\GroupPolicy |
| Value name | SaveRsopToRegistry |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Citrix\GroupPolicy |
| Value name | SaveRsopToMemory |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Google\Update |
| Value name | UpdateDefault |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown |
| Value name | bUpdater |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\WOW6432Node\Adobe\Adobe ARM\Legacy\Reader\{AC76BA86-7AD7-1033-7B44-AC0F074E4100} |
| Value name | Mode |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows\Windows Feeds |
| Value name | EnableFeeds |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Services\CtxDNDSvc\ |
| Value name | Enabled |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Citrix\1\User\VCPolicies |
| Value name | DragDrop |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Citrix\2\User\VCPolicies |
| Value name | DragDrop |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Citrix\3\User\VCPolicies |
| Value name | DragDrop |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Edge |
| Value name | UserFeedbackAllowed |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint |
| Value name | RestrictDriverInstallationToAdministrators |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | Software\Microsoft\Windows\CurrentVersion\Explorer |
| Value name | ODriveAllowed |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Teams |
| Value name | disableAutoUpdate |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\WOW6432Node\Citrix\WebSocketService |
| Value name | ProcessWhitelist |
| Value type | REG_MULTI_SZ |
| Line | Value |
|---|---|
| 1 | msedgewebview2.exe |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Citrix\Audio |
| Value name | EdtUnreliableAllowed |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Group name | Administrators (built-in) |
| Delete all member users | Disabled |
| Delete all member groups | Disabled |
| EMEA\NL-L-SEC-Delegation Local Administration Rights Client Systems | S-1-5-21-513466819-3096973226-347852806-2181 |
| Admin |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |