| NLCTX-PO-WIN-Computer Restrictions and Hardening | |
| Data collected on: 2-9-2025 10:15:10 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\cloots.5-adm |
| Created | 8-2-2022 11:31:24 |
| Modified | 6-8-2025 18:04:20 |
| User Revisions | 37 (AD), 37 (SYSVOL) |
| Computer Revisions | 355 (AD), 355 (SYSVOL) |
| Unique ID | {e6e42b51-4084-4f43-9bf5-46749371f44e} |
| GPO Status | User settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| SBC | No | Enabled | emea.tpg.ads/NL/Systems/CitrixBNL/SBC |
| Staging | No | Disabled | emea.tpg.ads/NL/Systems/CitrixBNL/Staging |
| VDI | No | Enabled | emea.tpg.ads/NL/Systems/CitrixBNL/VDI |
| Eneco | Yes | Enabled | emea.tpg.ads/NL/Systems/Test/VDI/Eneco |
| HSD | No | Enabled | emea.tpg.ads/SR/Systems/Citrix/HSD |
| VDI | No | Enabled | emea.tpg.ads/SR/Systems/Citrix/VDI |
| Name |
|---|
| NT AUTHORITY\Authenticated Users |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\cloots.5-adm | Edit settings, delete, modify security | No |
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\NL-L-SEC-Delegation Modify Group Policy Settings Access | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read (from Security Filtering) | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Policy | Setting |
|---|---|
| Audit account logon events | Success, Failure |
| Audit account management | Success, Failure |
| Audit directory service access | Success, Failure |
| Audit logon events | Success, Failure |
| Audit object access | Success, Failure |
| Audit policy change | Success, Failure |
| Audit system events | Success, Failure |
| Policy | Setting |
|---|---|
| Deny log on locally | EMEA\NL-L-SEC-Deny Local Logon ADM accounts, EMEA\NL-L-SEC-Service Accounts Restrictions |
| Deny log on through Terminal Services | EMEA\NL-L-SEC-Deny Local Logon ADM accounts |
| Policy | Setting |
|---|---|
| Accounts: Guest account status | Disabled |
| Accounts: Rename administrator account | "Apollo" |
| Policy | Setting |
|---|---|
| Devices: Prevent users from installing printer drivers | Disabled |
| Policy | Setting |
|---|---|
| Interactive logon: Don't display last signed-in | Enabled |
| Policy | Setting |
|---|---|
| Shutdown: Clear virtual memory pagefile | Enabled |
| Policy | Setting |
|---|---|
| Maximum application log size | 3000000 kilobytes |
| Maximum security log size | 3000000 kilobytes |
| Maximum system log size | 3000000 kilobytes |
| Retain security log | 90 days |
| Retention method for application log | As needed |
| Retention method for security log | By days |
| Retention method for system log | As needed |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read and Execute | This folder, subfolders and files |
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | S-1-5-21-513466819-3096973226-347852806-474671 | Full Control | This folder, subfolders and files |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Users | Read and Execute | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Users | Read and Execute | This folder, subfolders and files |
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read and Execute | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read and Execute | This folder, subfolders and files |
| Allow | CREATOR OWNER | Read and Execute | This folder, subfolders and files |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Users | Read and Execute | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | BUILTIN\Administrators | Full control | This key and subkeys |
| Allow | CREATOR OWNER | Full control | Subkeys only |
| Allow | NT AUTHORITY\SYSTEM | Full control | This key and subkeys |
| Allow | BUILTIN\Users | Read | This key and subkeys |
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read | This key and subkeys |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | BUILTIN\Administrators | Full control | This key and subkeys |
| Allow | CREATOR OWNER | Full control | Subkeys only |
| Allow | NT AUTHORITY\SYSTEM | Full control | This key and subkeys |
| Allow | BUILTIN\Users | Read | This key and subkeys |
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read | This key and subkeys |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | BUILTIN\Administrators | Full control | This key and subkeys |
| Allow | CREATOR OWNER | Full control | Subkeys only |
| Allow | NT AUTHORITY\SYSTEM | Full control | This key and subkeys |
| Allow | BUILTIN\Users | Read | This key and subkeys |
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read | This key and subkeys |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | BUILTIN\Administrators | Full control | This key and subkeys |
| Allow | CREATOR OWNER | Full control | Subkeys only |
| Allow | NT AUTHORITY\SYSTEM | Full control | This key and subkeys |
| Allow | BUILTIN\Users | Read | This key and subkeys |
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read | This key and subkeys |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Policy | Setting |
|---|---|
| Default URL retrieval timeout in seconds | 15 |
| Default path validation cumulative timeout in seconds | 20 |
| Allow issuer certificate retrieval during path validation | Enabled |
| Default cross-certificate download interval in hours | 168 |
| Issued To | Issued By | Expiration Date | Intended Purposes |
|---|---|---|---|
| DigiCert Global Root CA | DigiCert Global Root CA | 10-11-2031 01:00:00 | <All> |
| IISBV Root CA v3 | IISBV Root CA v3 | 9-6-2036 11:13:31 | <All> |
| IKEA Issuing CA V3 | IISBV Root CA v3 | 5-7-2026 15:55:00 | <All> |
| QuoVadis Root CA 2 G3 | QuoVadis Root CA 2 G3 | 12-1-2042 19:59:32 | <All> |
| ssl-proxy-trusted.tpnordic.local | ssl-proxy-trusted.tpnordic.local | 17-9-2024 13:37:31 | <All> |
| USERTrust RSA Certification Authority | AAA Certificate Services | 1-1-2029 00:59:59 | <All> |
| Zscaler Intermediate Root CA (zscloud.net) | Zscaler Root CA | 23-6-2041 07:33:19 | <All> |
| Issued To | Issued By | Expiration Date | Intended Purposes |
|---|---|---|---|
| Sectigo RSA Organization Validation Secure Server CA | USERTrust RSA Certification Authority | 1-1-2031 00:59:59 | Server Authentication, Client Authentication |
| Thawte RSA CA 2018 | DigiCert Global Root CA | 6-11-2027 13:23:52 | Server Authentication, Client Authentication |
| Zscaler Intermediate Root CA (zscloud.net) (t) | Zscaler Intermediate Root CA (zscloud.net) | 11-2-2023 03:01:00 | <All> |
| Policy | Setting |
|---|---|
| Policy version | Not Configured |
| Disable stateful FTP | Not Configured |
| Disable stateful PPTP | Not Configured |
| IPsec exempt | Not Configured |
| IPsec through NAT | Not Configured |
| Preshared key encoding | Not Configured |
| SA idle time | Not Configured |
| Strong CRL check | Not Configured |
| Policy | Setting |
|---|---|
| Firewall state | Off |
| Inbound connections | Not Configured |
| Outbound connections | Not Configured |
| Apply local firewall rules | Not Configured |
| Apply local connection security rules | Not Configured |
| Display notifications | No |
| Allow unicast responses | Not Configured |
| Log dropped packets | Not Configured |
| Log successful connections | Not Configured |
| Log file path | Not Configured |
| Log file maximum size (KB) | Not Configured |
| Policy | Setting |
|---|---|
| Audit Other Account Logon Events | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Application Group Management | Success, Failure |
| Audit Computer Account Management | Success, Failure |
| Audit Security Group Management | Success, Failure |
| Audit User Account Management | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Process Creation | Success, Failure |
| Audit Process Termination | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Account Lockout | Success, Failure |
| Audit Logoff | Success, Failure |
| Audit Logon | Success, Failure |
| Audit Special Logon | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Audit Policy Change | Success, Failure |
| Audit Authentication Policy Change | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Security State Change | Success, Failure |
| Audit System Integrity | Success, Failure |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Agent service port | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Cache synchronization port | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Infrastructure server | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||||
|---|---|---|---|---|---|---|---|---|
| Do not allow password expiration time longer than required by policy | Enabled | |||||||
| Enable local admin password management | Enabled | |||||||
| Password Settings | Enabled | |||||||
| ||||||||
| Policy | Setting | Comment |
|---|---|---|
| Windows Defender Firewall: Prohibit notifications | Enabled | |
| Windows Defender Firewall: Protect all network connections | Disabled |
| Policy | Setting | Comment | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Point and Print Restrictions | Enabled | |||||||||||||||||||
| ||||||||||||||||||||
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Configure folder redirection policy processing | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Continue experiences on this device | Disabled | |||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off Automatic Root Certificates Update | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn Off the hard disk (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn Off the hard disk (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Specify the system hibernate timeout (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Specify the system hibernate timeout (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Specify the system sleep timeout (on battery) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Specify the system sleep timeout (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| Configure Offer Remote Assistance | Enabled | ||||||||||
| |||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Removable Disks: Deny execute access | Enabled | |
| Removable Disks: Deny read access | Enabled | |
| Removable Disks: Deny write access | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Add the Administrators security group to roaming user profiles | Enabled | |||
| Delete cached copies of roaming profiles | Enabled | |||
| Delete user profiles older than a specified number of days on system restart | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn off Autoplay | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Control Event Log behavior when the log file reaches its maximum size | Disabled | |||
| Specify the maximum log file size (KB) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Control Event Log behavior when the log file reaches its maximum size | Disabled | |||
| Specify the maximum log file size (KB) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Set a default associations configuration file | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Enable news and interests on the taskbar | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow users to connect remotely by using Remote Desktop Services | Enabled |
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Require use of specific security layer for remote (RDP) connections | Enabled | PCI Plugin 18405 | ||||
| ||||||
| Policy | Setting | Comment | ||||
| Require user authentication for remote connections by using Network Level Authentication | Enabled | PCI plugin 58453 and 18405 | ||||
| Set client connection encryption level | Enabled | pci plugin 57690 Terminal Service Encryption | ||||
| ||||||
| Policy | Setting | Comment |
|---|---|---|
| Allow Cortana | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Disable all apps from Microsoft Store | Enabled | |
| Turn off the Store application | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do Not Show First Use Dialog Boxes | Enabled | |
| Prevent Automatic Updates | Enabled | |
| Prevent Media Sharing | Enabled |
| Setting | State |
|---|---|
| Software\Policies\Mozilla\lockPref\network.dns.disableIPv6 | 1 |
| Action | Update |
| Context | System |
| Variable | appgateWW |
| Value | --url="appgate://access.wwiops.io/eyJwcm9maWxlTmFtZSI6IldXLVBhcnRuZXJzIiwic3BhIjp7Im1vZGUiOiJUQ1AiLCJuYW1lIjoid3dfY2xpZW50cyIsImtleSI6Ijc0MzlkZWI4MTMxMmE3OWNmYmYwMDdiYTljZDNlMGJlNjQ1Y2VhYTE0ZjYwNGUyMmJhMGZjNGEzOTI2MmEwNWQifSwiY2FGaW5nZXJwcmludCI6IjlkZTE0YmM2ODhmNjhiMWViZTIxMGZmYjY4YjljZmNjYTAyMWU2MjM5M2E5YzVkMThjMWUzYWExMGJmMzA0NGMiLCJpZGVudGl0eVByb3ZpZGVyTmFtZSI6IldXLVBhcnRuZXJzIn0=" |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Source file(s) | \\emea.tpg.ads\NL\Amsterdam\Settings\Pushfiles\Hostfile\hosts |
| Destination file | C:\Windows\System32\drivers\etc\hosts |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Action | Replace |
| Source file(s) | \\emea.tpg.ads\nl\Amsterdam\Settings\Pushfiles\IEX 7.3\Amsterdam\config.ini |
| Destination file | C:\Program Files\NICE\WFM\7.3\TP-DENLPLAC\wfm\configuration\config.ini |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Action | Update |
| Source file(s) | \\emea.tpg.ads\nl\Amsterdam\Settings\Pushfiles\IE11Mode\IE11_Sitelist.xml |
| Destination file | C:\GPO\IE11Mode\IE11_Sitelist.xml |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Source file(s) | \\emea.tpg.ads\NL\Amsterdam\Settings\Pushfiles\Comp_Rest_Hard_Pol\Default.xml |
| Destination file | c:\GPO\DefaultAss\Default.xml |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_USERS |
| Key path | .DEFAULT\Control Panel\Keyboard |
| Value name | InitialKeyboardIndicators |
| Value type | REG_SZ |
| Value data | 2 |
| Stop processing items on this extension if an error occurs on this item | Yes |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Enable num-lock on startup |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\NET Framework Setup\NDP |
| Value name | BlockNetFramework451 |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Edge |
| Value name | UserFeedbackAllowed |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\services\LanmanServer\Parameters |
| Value name | enablesecuritysignature |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| SMB Signing PCI 57608 |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\services\LanmanServer\Parameters |
| Value name | requiresecuresignature |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| SMB Signing PCI 57608 |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\services\LanmanWorkstation\Parameters |
| Value name | RequireSecuritySignature |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| SMB Signing PCI 57608 |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\services\LanmanWorkstation\Parameters |
| Value name | EnableSecuritySignature |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| SMB Siging PCI 57608 |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Windows\Sidebar |
| Value name | TurnOffSidebar |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| PCI Plugin 59915 |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon |
| Value name | CachedLogonsCount |
| Value type | REG_SZ |
| Value data | 0 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Plugin ID 11457 |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Lsa |
| Value name | LmCompatibilityLevel |
| Value type | REG_DWORD |
| Value data | 0x3 (3) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | System\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 3.0\Server |
| Value name | Enabled |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | System\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 3.0\Client |
| Value name | Enabled |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_PRINT_INFO_DISCLOSURE_FIX |
| Value name | iexeplore.exe |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_PRINT_INFO_DISCLOSURE_FIX |
| Value name | iexplore.exe |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ALLOW_USER32_EXCEPTION_HANDLER_HARDENING |
| Value name | iexplore.exe |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ALLOW_USER32_EXCEPTION_HANDLER_HARDENING |
| Value name | iexplore.exe |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Session Manager |
| Value name | CWDIllegalInDllSearch |
| Value type | REG_DWORD |
| Value data | 0x2 (2) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management |
| Value name | FeatureSettingsOverride |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Nessus Plugin 111689 |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management |
| Value name | FeatureSettingsOverrideMask |
| Value type | REG_DWORD |
| Value data | 0x3 (3) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Nessus Plugin 111689 |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint |
| Value name | RestrictDriverInstallationToAdministrators |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon |
| Value name | AllocateCDRoms |
| Value type | REG_SZ |
| Value data | 1 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer |
| Value name | NoDriveTypeAutoRun |
| Value type | REG_DWORD |
| Value data | 0xFF (255) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\FileSystem |
| Value name | NtfsDisable8dot3NameCreation |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems |
| Value name | Optional |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 3.0\Server |
| Value name | Enabled |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 3.0\Client |
| Value name | Enabled |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows\Explorer |
| Value name | NoNewAppAlert |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system |
| Value name | DelayedDesktopSwitchTimeout |
| Value type | REG_DWORD |
| Value data | 0x5 (5) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Active Setup\Installed Components |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Keyboard Layout |
| Value name | Scancode Map |
| Value type | REG_BINARY |
| Value data | 00000000000000000400000000002AE0000037E00000540000000000 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | Software\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.AddNetworkLocation |
| Value name | AttributeMask |
| Value type | REG_DWORD |
| Value data | 0x100000 (1048576) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | Software\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.AddNetworkLocation |
| Value name | AttributeValue |
| Value type | REG_DWORD |
| Value data | 0x100000 (1048576) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | Software\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.AddNetworkLocation |
| Value name | ImpliedSelectionModel |
| Value type | REG_DWORD |
| Value data | 0x100000 (1048576) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | Software\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.AddNetworkLocation |
| Value name | ExplorerCommandHandler |
| Value type | REG_SZ |
| Value data |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.ShowFileExtensions |
| Value name | AttributeMask |
| Value type | REG_DWORD |
| Value data | 0x100000 (1048576) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.ShowFileExtensions |
| Value name | AttributeValue |
| Value type | REG_DWORD |
| Value data | 0x100000 (1048576) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.ShowFileExtensions |
| Value name | ImpliedSelectionModel |
| Value type | REG_DWORD |
| Value data | 0x100000 (1048576) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.ShowFileExtensions |
| Value name | ExplorerCommandHandler |
| Value type | REG_SZ |
| Value data |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.AddMediaServer |
| Value name | AttributeMask |
| Value type | REG_DWORD |
| Value data | 0x100000 (1048576) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.AddMediaServer |
| Value name | AttributeValue |
| Value type | REG_DWORD |
| Value data | 0x100000 (1048576) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.AddMediaServer |
| Value name | ImpliedSelectionModel |
| Value type | REG_DWORD |
| Value data | 0x100000 (1048576) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.AddMediaServer |
| Value name | ExplorerCommandHandler |
| Value type | REG_SZ |
| Value data |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.ShowHiddenFiles |
| Value name | AttributeMask |
| Value type | REG_DWORD |
| Value data | 0x100000 (1048576) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.ShowHiddenFiles |
| Value name | AttributeValue |
| Value type | REG_DWORD |
| Value data | 0x100000 (1048576) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.ShowHiddenFiles |
| Value name | ImpliedSelectionModel |
| Value type | REG_DWORD |
| Value data | 0x100000 (1048576) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell\Windows.ShowHiddenFiles |
| Value name | ExplorerCommandHandler |
| Value type | REG_SZ |
| Value data |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| User name | Administrator (built-in) |
| Rename to | Apollo |
| User cannot change password | False |
| Password never expires | True |
| Account is disabled | False |
| Account expires | Never |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Group name | Remote Desktop Users (built-in) |
| Delete all member users | Disabled |
| Delete all member groups | Disabled |
| EMEA\NL-L-SEC-Remote Desktop Access Users | S-1-5-21-513466819-3096973226-347852806-433231 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Group name | Administrators (built-in) |
| Delete all member users | Disabled |
| Delete all member groups | Disabled |
| EMEA\NL-L-SEC-Delegation Local Administration Rights Client Systems | S-1-5-21-513466819-3096973226-347852806-2181 |
| EMEA\emeanessus.1 | S-1-5-21-513466819-3096973226-347852806-32532 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Service name | wmiApSrv |
| Action | Start service |
| Startup type: | Automatic |
| Wait timeout if service is locked: | 30 seconds |
| Log on service as: | No change |
| First failure: | No change |
| Second failure: | No change |
| Subsequent failures: | No change |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |