Group Policy Management
body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } }
Setting Path:
Explanation
No explanation is available for this setting.
Supported On:
Not available
NLCTX-PO-WIN-U-VDI Non-Loopback Hardening
Data collected on: 2-9-2025 09:13:56
General
Details
Domainemea.tpg.ads
OwnerEMEA\timmermans.5
Created15-5-2018 11:57:32
Modified13-8-2025 11:20:56
User Revisions317 (AD), 317 (SYSVOL)
Computer Revisions3 (AD), 3 (SYSVOL)
Unique ID{6a5d5bff-3117-45ca-a9aa-4d4378429005}
GPO StatusComputer settings disabled
Links
LocationEnforcedLink StatusPath
VDINoEnabledemea.tpg.ads/NL/Systems/CitrixBNL/VDI
BOLNoEnabledemea.tpg.ads/NL/Systems/Test/SBC/BOL
EnecoNoEnabledemea.tpg.ads/NL/Systems/Test/SBC/Eneco
IKEANoEnabledemea.tpg.ads/NL/Systems/Test/SBC/IKEA
LidlNoEnabledemea.tpg.ads/NL/Systems/Test/SBC/Lidl
OperationsNoEnabledemea.tpg.ads/NL/Systems/Test/SBC/Operations
SamsungNoEnabledemea.tpg.ads/NL/Systems/Test/SBC/Samsung
TestNoEnabledemea.tpg.ads/NL/Systems/Test/SBC/Test
ZalandoNoEnabledemea.tpg.ads/NL/Systems/Test/SBC/Zalando
BelvillaNoEnabledemea.tpg.ads/NL/Systems/Test/VDI/Belvilla
Beter BedNoEnabledemea.tpg.ads/NL/Systems/Test/VDI/Beter Bed
BOLNoEnabledemea.tpg.ads/NL/Systems/Test/VDI/BOL
CaiwayNoEnabledemea.tpg.ads/NL/Systems/Test/VDI/Caiway
Canada GooseNoEnabledemea.tpg.ads/NL/Systems/Test/VDI/Canada Goose
Covid SupportNoEnabledemea.tpg.ads/NL/Systems/Test/VDI/Covid Support
EnecoNoEnabledemea.tpg.ads/NL/Systems/Test/VDI/Eneco
EssentNoEnabledemea.tpg.ads/NL/Systems/Test/VDI/Essent
GroheNoEnabledemea.tpg.ads/NL/Systems/Test/VDI/Grohe
G-starNoEnabledemea.tpg.ads/NL/Systems/Test/VDI/G-star
Hello Fresh BENoEnabledemea.tpg.ads/NL/Systems/Test/VDI/Hello Fresh BE
IKEANoEnabledemea.tpg.ads/NL/Systems/Test/VDI/IKEA
JumboNoEnabledemea.tpg.ads/NL/Systems/Test/VDI/Jumbo
LenovoNoEnabledemea.tpg.ads/NL/Systems/Test/VDI/Lenovo
SamsungNoEnabledemea.tpg.ads/NL/Systems/Test/VDI/Samsung
TelfortNoEnabledemea.tpg.ads/NL/Systems/Test/VDI/Telfort
TestNoEnabledemea.tpg.ads/NL/Systems/Test/VDI/Test
WehkampNoEnabledemea.tpg.ads/NL/Systems/Test/VDI/Wehkamp
ZalandoNoEnabledemea.tpg.ads/NL/Systems/Test/VDI/Zalando
ZiggoNoEnabledemea.tpg.ads/NL/Systems/Test/VDI/Ziggo
BolNoEnabledemea.tpg.ads/TR/Systems/Citrix/VDI/Bol

This list only includes links in the domain of the GPO.
Security Filtering
The settings in this GPO can only apply to the following groups, users, and computers:
Name
EMEA\BE-L-SEC-Users Laptop Restrictions and Harderning Restricted
EMEA\BE-L-SEC-Users Laptop Restrictions and Harderning Unrestricted
EMEA\NLCTX-L-SEC-VDI Default User Settings
EMEA\NL-L-SEC-Users Laptop Restrictions and Harderning Restricted
EMEA\NL-L-SEC-Users Laptop Restrictions and Harderning Unrestricted
EMEA\SR-L-SEC-Users Laptop Restrictions and Harderning Restricted
EMEA\SR-L-SEC-Users Laptop Restrictions and Harderning Unrestricted
Delegation
These groups and users have the specified permission for this GPO
NameAllowed PermissionsInherited
EMEA\BE-L-SEC-Users Laptop Restrictions and Harderning RestrictedRead (from Security Filtering)No
EMEA\BE-L-SEC-Users Laptop Restrictions and Harderning UnrestrictedRead (from Security Filtering)No
EMEA\Domain AdminsEdit settings, delete, modify securityNo
EMEA\Domain ComputersReadNo
EMEA\NLCTX-L-SEC-VDI Default User SettingsRead (from Security Filtering)No
EMEA\NL-L-SEC-Delegation Modify Group Policy Settings AccessEdit settings, delete, modify securityNo
EMEA\NL-L-SEC-Users Laptop Restrictions and Harderning RestrictedRead (from Security Filtering)No
EMEA\NL-L-SEC-Users Laptop Restrictions and Harderning UnrestrictedRead (from Security Filtering)No
EMEA\SR-L-SEC-Users Laptop Restrictions and Harderning RestrictedRead (from Security Filtering)No
EMEA\SR-L-SEC-Users Laptop Restrictions and Harderning UnrestrictedRead (from Security Filtering)No
NT AUTHORITY\Authenticated UsersReadNo
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSReadNo
NT AUTHORITY\SYSTEMEdit settings, delete, modify securityNo
ROOT\Enterprise AdminsEdit settings, delete, modify securityNo
Computer Configuration (Disabled)
No settings defined.
User Configuration (Enabled)
Policies
Windows Settings
Folder Redirection
Desktop
Setting: Advanced (Specify locations for various user groups)
GroupPath
EMEA\NLAMS-L-SEC-Folder Redirection Citrix Laptop Users%DesktopLocation%
Options
Grant user exclusive rights to DesktopDisabled
Move the contents of Desktop to the new locationDisabled
Also apply redirection policy to Windows 2000, Windows 2000 server, Windows XP, and Windows Server 2003 operating systemsEnabled
Policy Removal BehaviorRestore contents
Configuration ControlGroup Policy
Primary Computer EvaluationNot evaluated because primary computer policy is not enabled
Start Menu
Setting: Advanced (Specify locations for various user groups)
GroupPath
EMEA\NLAMS-L-SEC-Folder Redirection Citrix Laptop Users%FRDLocation%
Options
Grant user exclusive rights to Start MenuDisabled
Move the contents of Start Menu to the new locationDisabled
Also apply redirection policy to Windows 2000, Windows 2000 server, Windows XP, and Windows Server 2003 operating systemsEnabled
Policy Removal BehaviorRestore contents
Configuration ControlGroup Policy
Primary Computer EvaluationNot evaluated because primary computer policy is not enabled
Administrative Templates
Policy definitions (ADMX files) retrieved from the central store.
Control Panel
PolicySettingComment
Show only specified Control Panel itemsEnabled
List of allowed Control Panel items
Microsoft.Mouse
Microsoft.RegionAndLanguage
Microsoft.Display
control mouse
Main.cpl
Desktop/Active Directory
PolicySettingComment
Hide Active Directory folderEnabled
Start Menu and Taskbar
PolicySettingComment
Add Search Internet link to Start MenuDisabled
Clear history of recently opened documents on exitEnabled
Clear tile notifications during log onEnabled
Do not allow pinning items in Jump ListsEnabled
Do not allow pinning programs to the TaskbarEnabled
Do not allow pinning Store app to the TaskbarEnabled
Do not search communicationsEnabled
Do not search for filesEnabled
Do not search InternetEnabled
Do not search programs and Control Panel itemsEnabled
Do not use the search-based method when resolving shell shortcutsEnabled
Do not use the tracking-based method when resolving shell shortcutsEnabled
Hide the notification areaEnabled
Pin Apps to Start when installedDisabled
Prevent users from adding or removing toolbarsEnabled
Prevent users from customizing their Start ScreenEnabled
Remove All Programs list from the Start menuEnabled
Choose one of the following actionsNone
PolicySettingComment
Remove common program groups from Start MenuEnabled
Remove Documents icon from Start MenuEnabled
Remove Downloads link from Start MenuEnabled
Remove Favorites menu from Start MenuEnabled
Remove Games link from Start MenuEnabled
Remove Help menu from Start MenuEnabled
Remove Homegroup link from Start MenuEnabled
Remove links and access to Windows UpdateEnabled
Remove Music icon from Start MenuEnabled
Remove Network Connections from Start MenuEnabled
Remove Network icon from Start MenuEnabled
Remove Notifications and Action CenterEnabled
Remove Pictures icon from Start MenuEnabled
Remove pinned programs from the TaskbarEnabled
Remove pinned programs list from the Start MenuEnabled
Remove Recent Items menu from Start MenuEnabled
Remove Recorded TV link from Start MenuEnabled
Remove Run menu from Start MenuEnabled
Remove Search Computer linkEnabled
Remove Search link from Start MenuEnabled
Remove the battery meterDisabled
Remove the Meet Now iconEnabled
Remove the networking iconEnabled
Remove the People Bar from the taskbarEnabled
Remove the Security and Maintenance iconEnabled
Remove the volume control iconDisabled
Remove user folder link from Start MenuEnabled
Remove Videos link from Start MenuEnabled
Show QuickLaunch on TaskbarDisabled
Start LayoutEnabled
Start Layout File\\emea.tpg.ads\NL\Amsterdam\Settings\Pushfiles\User_Rest_Hard_Pol\Startmenu\layout.xml
Reapply layout at every logonEnabled
PolicySettingComment
Turn off feature advertisement balloon notificationsEnabled
Turn off notification area cleanupEnabled
Turn off user trackingEnabled
Start Menu and Taskbar/Notifications
PolicySettingComment
Turn off tile notificationsEnabled
Turn off toast notificationsEnabled
System
PolicySettingComment
Prevent access to registry editing toolsEnabled
Disable regedit from running silently?No
PolicySettingComment
Prevent access to the command promptEnabled
Disable the command prompt script processing also?No
Windows Components/Cloud Content
PolicySettingComment
Turn off the Windows Welcome ExperienceEnabled
Windows Components/File Explorer
PolicySettingComment
Hide these specified drives in My ComputerEnabled
Pick one of the following combinationsRestrict A, B, C and D drives only
Windows Components/Internet Explorer/Internet Control Panel/Security Page
PolicySettingComment
Site to Zone Assignment ListEnabled
Enter the zone assignments here. 
http://klantenservice.wehkampgroep.nl2
wehkampgroep.nl2
https://remote-xa.gslb.office.ziggo.nl2
ziggo.nl2
Windows Components/Remote Desktop Services/Remote Desktop Session Host/Session Time Limits
PolicySettingComment
End session when time limits are reachedEnabled
Set time limit for disconnected sessionsEnabled
End a disconnected session1 hour
Windows Components/Store
PolicySettingComment
Turn off the offer to update to the latest version of WindowsEnabled
Turn off the Store applicationEnabled
Preferences
Windows Settings
Registry
VisualFXSetting (Order: 1)
General
ActionUpdate
Properties
HiveHKEY_CURRENT_USER
Key pathSOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects
Value nameVisualFXSetting
Value typeREG_DWORD
Value data0x2 (2)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
SearchboxTaskbarMode (Order: 2)
General
ActionUpdate
Properties
HiveHKEY_CURRENT_USER
Key pathSoftware\Microsoft\Windows\CurrentVersion\Search
Value nameSearchboxTaskbarMode
Value typeREG_DWORD
Value data0x0 (0)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Description
Remove Search from taskbar
AllUpView (Order: 3)
General
ActionUpdate
Properties
HiveHKEY_CURRENT_USER
Key pathSoftware\Microsoft\Windows\CurrentVersion\Explorer\MultitaskingView\AllUpView
Value nameAllUpView
Value typeREG_DWORD
Value data0x0 (0)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Description
Restrict and Remove Task View Icon from Windows 10 Taskbar
NoTileApplicationNotification (Order: 4)
General
ActionUpdate
Properties
HiveHKEY_CURRENT_USER
Key pathSoftware\Policies\Microsoft\Windows\CurrentVersion\PushNotifications
Value nameNoTileApplicationNotification
Value typeREG_DWORD
Value data0x1 (1)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
Description
Disable Live Tiles in Windows 10 Start Menu
GameDVR_Enabled (Order: 5)
General
ActionUpdate
Properties
HiveHKEY_CURRENT_USER
Key pathSystem\GameConfigStore
Value nameGameDVR_Enabled
Value typeREG_DWORD
Value data0x0 (0)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
EnableFTU (Order: 6)
General
ActionCreate
Properties
HiveHKEY_CURRENT_USER
Key pathSoftware\Citrix\Receiver
Value nameEnableFTU
Value typeREG_DWORD
Value data0x0 (0)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
HideAddAccountOnRestart (Order: 7)
General
ActionCreate
Properties
HiveHKEY_CURRENT_USER
Key pathSoftware\Citrix\Receiver
Value nameHideAddAccountOnRestart
Value typeREG_DWORD
Value data0x1 (1)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
OneDriveSetup (Order: 8)
General
ActionDelete
Properties
HiveHKEY_CURRENT_USER
Key pathSoftware\Microsoft\Windows\CurrentVersion\Run
Value nameOneDriveSetup
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Apply once and do not reapplyNo
StartupDelayInMSec (Order: 9)
General
ActionCreate
Properties
HiveHKEY_CURRENT_USER
Key pathSOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Serialize
Value nameStartupDelayInMSec
Value typeREG_DWORD
Value data0x0 (0)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo
State (Order: 10)
General
ActionUpdate
Properties
HiveHKEY_CURRENT_USER
Key pathSoftware\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\MSTeams_8wekyb3d8bbwe\TeamsTfwStartupTask
Value nameState
Value typeREG_DWORD
Value data0x0 (0)
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Remove this item when it is no longer appliedNo
Apply once and do not reapplyNo