| PLKAT-PO-WIN-ADM-U-Restrictions Backoffice (Lenovo QA&SV) | |
| Data collected on: 2-9-2025 09:55:44 | |
| Domain | emea.tpg.ads |
| Owner | S-1-5-21-513466819-3096973226-347852806-383093 |
| Created | 6-4-2021 18:02:06 |
| Modified | 10-1-2025 12:33:38 |
| User Revisions | 60 (AD), 60 (SYSVOL) |
| Computer Revisions | 1 (AD), 1 (SYSVOL) |
| Unique ID | {246f61ec-b956-41f1-b05a-196ee5e9dfbb} |
| GPO Status | Computer settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| PL | No | Enabled | emea.tpg.ads/PL |
| Name |
|---|
| EMEA\PLKAT-L-SEC-Restrictions Backoffice Lenovo QA&SV |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\Domain Computers | Read | No |
| EMEA\PLKAT-L-SEC-Restrictions Backoffice Lenovo QA&SV | Read (from Security Filtering) | No |
| EMEA\PL-L-SEC-Delegation Modify Group Policy Settings Access | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Enforcement | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Designated File Types | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Trusted Publishers | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
| Policy | Setting |
|---|---|
| Default Security Level | Unrestricted |
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% | ||||||
| ||||||
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% | ||||||
| ||||||
| C:\WINDOWS\system32\rsop.msc | ||||||
| ||||||
| C:\WINDOWS\system32\secpol.msc | ||||||
| ||||||
| C:\WINDOWS\system32\services.msc | ||||||
|
| Policy | Setting | Comment | ||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Always open All Control Panel Items when opening Control Panel | Enabled | |||||||||||||||
| Settings Page Visibility | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Show only specified Control Panel items | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Prevent changing desktop background | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Hide Network Locations icon on desktop | Enabled | |
| Remove the Desktop Cleanup Wizard | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow shared folders to be published | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Add Logoff to the Start Menu | Enabled | |
| Force classic Start Menu | Enabled | |
| Prevent users from customizing their Start Screen | Enabled | |
| Remove Help menu from Start Menu | Enabled | |
| Remove links and access to Windows Update | Enabled | |
| Remove Music icon from Start Menu | Enabled | |
| Remove Network Connections from Start Menu | Enabled | |
| Remove Network icon from Start Menu | Enabled | |
| Remove Pictures icon from Start Menu | Enabled | |
| Remove Recent Items menu from Start Menu | Enabled | |
| Remove Run menu from Start Menu | Enabled | |
| Remove user folder link from Start Menu | Enabled | |
| Show QuickLaunch on Taskbar | Enabled |
| Policy | Setting | Comment | |||||
|---|---|---|---|---|---|---|---|
| Don't run specified Windows applications | Enabled | ||||||
| |||||||
| Policy | Setting | Comment | |||||
| Prevent access to registry editing tools | Enabled | ||||||
| |||||||
| Policy | Setting | Comment | |||||
| Prevent access to the command prompt | Enabled | ||||||
| |||||||
| Policy | Setting | Comment |
|---|---|---|
| Remove Task Manager | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| CD and DVD: Deny read access | Enabled | |
| CD and DVD: Deny write access | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Default risk level for file attachments | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not preserve zone information in file attachments | Enabled | |||
| Inclusion list for low file types | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Do not allow Folder Options to be opened from the Options button on the View tab of the ribbon | Enabled | |||
| Hide these specified drives in My Computer | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Hides the Manage item on the File Explorer context menu | Enabled | |||
| No Computers Near Me in Network Locations | Enabled | |||
| No Entire Network in Network Locations | Enabled | |||
| Remove CD Burning features | Enabled | |||
| Remove File Explorer's default context menu | Disabled | |||
| Remove Shared Documents from My Computer | Enabled | |||
| Turn off caching of thumbnail pictures | Enabled | |||
| Turn off Windows Key hotkeys | Enabled | |||
| Turn on Classic Shell | Disabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Turn off tabbed browsing | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Disable the Advanced page | Enabled | |
| Disable the Connections page | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Empty Temporary Internet Files folder when browser is closed | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Computer Management | Disabled | |
| Local Users and Groups | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not allow Windows Messenger to be run | Enabled | |
| Do not automatically start Windows Messenger initially | Enabled |
| Setting | State |
|---|---|
| Software\Policies\Microsoft\WindowsMovieMaker\MovieMaker | 1 |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{031E4825-7B94-4dc3-B131-E946B44C8DD5} |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer |
| Value name | NoRun |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_CURRENT_USER |
| Key path | Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
| Value name | NoRun |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | Yes |
| Remove this item when it is no longer applied | Yes |
| Action | Replace |
| Hive | HKEY_CURRENT_USER |
| Key path | Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum |
| Value name | {59031a47-3f72-44a7-89c5-5595fe6b30ee} |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | Yes |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{26EE0668-A00A-44D7-9371-BEB064C98683} |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0} |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_CURRENT_USER |
| Key path | Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
| Value name | DisablePersonalDirChange |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | Yes |
| Remove this item when it is no longer applied | Yes |
| Main tab | https://plnews.emea.tpg.ads |
| Startup options | Start with tabs from the last session |
| Delete browsing history on exit | Yes |
| Internet | Medium-high |
| Enable Protected Mode | Enabled |
| Turn on Pop-up Blocker | Enabled |
| Never allow websites to request your physical location | Disabled |
| Disable toolbars and extensions when InPrivate Browsing starts | Enabled |
| Connection behavior | Never dial a connection |
| Automatically detect settings | No |
| Use automatic configuration script | http://deffmproxyrr.emea.tpg.ads/cfg/config.pac |
| Use a proxy server for your LAN (These settings will not apply to a dial-up or VPN connections) | No |
| Choose how you open links | Always in Internet Explorer on the desktop |
| Open Internet Explorer tiles on the desktop | Enabled |
| User software rendering instead of GPU rendering | Enabled |
| Always expand ALT text for images | Disabled |
| Enable Caret Browser for new windows and tabs | Disabled |
| Move system caret with focus/selection changes | Disabled |
| Play system sounds | Disabled |
| Reset text size to medium for new windows and tabs | Disabled |
| Reset Zoom level for new windows and tabs | Disabled |
| Automatically recover from page layout errors with Compatibility View | Enabled |
| Close unused folders in History and Favorites (requires restart) | Disabled |
| Disable Script debugging (Internet Explorer) | Enabled |
| Disable Script debugging (Other) | Enabled |
| Display a notification about every script error | Disabled |
| Display Accelerator button on selection | Disabled |
| Enable automatic crash recovery | Enabled |
| Enable flip ahead | Disabled |
| Enable FTP folder view (outside of Internet Explorer) | Enabled |
| Enable Suggested Sites | Disabled |
| Enable third-party browser extensions (requires restart) | Disabled |
| Enable visual styles on buttons and controls in webpages | Enabled |
| Enable websites to use the search pane | Disabled |
| Go to an intranet site for a single word entry in the Address bar | Disabled |
| Notify when downloads complete | Enabled |
| Reuse windows for launching shortcuts | Enabled |
| Show Friendly HTTP Error messages | Enabled |
| Tell me if Internet Explorer is not the default web browser | Enabled |
| Underline links | Always |
| Use inline AutoComplete | Enabled |
| Use inline Autocomplete in File Explorer and Run Dialog | Disabled |
| Use most recent order when switching tabs with Ctrl+Tab | Disabled |
| Use Passive FTP (for firewall and DSL model compatibility) | Enabled |
| Use smooth scrolling | Enabled |
| Use HTTP 1.1 | Enabled |
| Use HTTP 1.1 through proxy connections | Enabled |
| Always show encoded addresses | Disabled |
| Send IDN server names | Enabled |
| Send IDN server names for Intranet addresses | Disabled |
| Send UTF-8 URLs | Enabled |
| Show Information Bar for encoded addresses | Enabled |
| Enable alternative codecs in HTML5 media elements | Enabled |
| Enable Automatic Image Resizing | Enabled |
| Play animations in webpages | Disabled |
| Play sounds in webpages | Disabled |
| Show image download placeholders | Disabled |
| Show pictures | Enabled |
| Allow active content from CDs to run on My Computer | Disabled |
| Allow active content to run in files on My Computer | Disabled |
| Always send Do Not Track header | Disabled |
| Allow software to run or install even if the signature is invalid | Disabled |
| Block unsecured images with other mixed content | Disabled |
| Check for publisher's certificate revocation | Enabled |
| Check for server certificate revocation (requires restart) | Enabled |
| Check for signatures on downloaded programs | Enabled |
| Do not save encrypted pages to disk | Enabled |
| Empty Temporary Internet Files folder when browser is closed | Enabled |
| Enable memory protection to help mitigate online attacks | Disabled |
| Enable DOM Storage | Enabled |
| Enable Enhanced Protected Mode | Enabled |
| Enable Integrated Windows Authentication (requires restart) | Enabled |
| Enable native XMLHTTP support | Enabled |
| Enable SmartScreen Filter | Disabled |
| Use SSL 2.0 | Disabled |
| Use SSL 3.0 | Enabled |
| Use TLS 1.0 | Enabled |
| Use TLS 1.1 | Enabled |
| Use TLS 1.2 | Enabled |
| Warn about certificate address mismatch | Enabled |
| Warn if changing between secure and not secure mode | Enabled |
| Warn if POST submittal is redirected to a zone that does not permit posts | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |