| PT-PO-WIN-ADM-C-Restrictions PCI With New EMEA | |
| Data collected on: 2-9-2025 11:24:58 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\silva.12303-adm |
| Created | 24-7-2023 12:48:16 |
| Modified | 31-3-2025 17:49:02 |
| User Revisions | 0 (AD), 0 (SYSVOL) |
| Computer Revisions | 264 (AD), 264 (SYSVOL) |
| Unique ID | {0285d958-dddb-48ff-8d0c-fbebd842f9e1} |
| GPO Status | User settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Clients | No | Enabled | emea.tpg.ads/PT/Systems/Clients |
| Name |
|---|
| None |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\PT-L-SEC-C-W11 Hardening PCI | Custom | No |
| Name | Parameters |
|---|---|
| remove_winkey.bat |
| Policy | Setting |
|---|---|
| Network access: Do not allow storage of passwords and credentials for network authentication | Enabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Deny | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Enforcement | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Designated File Types | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Trusted Publishers | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
| Policy | Setting |
|---|---|
| Default Security Level | Unrestricted |
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% | ||||||
| ||||||
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% | ||||||
| ||||||
| C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy | ||||||
| ||||||
| C:\Windows\SystemApps\Microsoft.Windows.Search* | ||||||
|
| Policy | Setting | Comment |
|---|---|---|
| Allow Online Tips | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow user feedback | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Enable Google Cast | Disabled | 28467290 |
| Show the Google Cast toolbar icon | Disabled | 28467290 |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Ads setting for sites with intrusive ads | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow user feedback | Disabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Enable Google Cast | Disabled | 28467290 |
| Show the cast icon in the toolbar | Disabled | 28467290 |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Configure Logon Script Delay | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Show first sign-in animation | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Configure Scheduled Maintenance Behavior | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Application Telemetry | Enabled | |
| Turn off Inventory Collector | Enabled | |
| Turn off Steps Recorder | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not show Windows tips | Enabled | |
| Turn off Microsoft consumer experiences | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Allow Diagnostic Data | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not show feedback notifications | Enabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Turn off location | Enabled | |
| Turn off sensors | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Enable headless UI mode | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Configure Password Manager | Disabled | Block Credential Manager - 17577966 |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Prevent OneDrive files from syncing over metered connections | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Prevent the usage of OneDrive for file storage | Enabled | |||
| Prevent the usage of OneDrive for file storage on Windows 8.1 | Enabled | |||
| Save documents to OneDrive by default | Disabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Turn off Active Help | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Remove Windows Security item from Start menu | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow Cortana | Disabled | |
| Allow Cortana above lock screen | Disabled | |
| Do not allow web search | Enabled | |
| Don't search the web or display web results in Search | Enabled | |
| Fully disable Search UI | Enabled | Disable Search on StartMenu and TaskBar |
| Policy | Setting | Comment |
|---|---|---|
| Turn on Security Center (Domain PCs only) | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Only display the private store within the Microsoft Store | Enabled | |
| Turn off Automatic Download and Install of updates | Enabled | |
| Turn off the offer to update to the latest version of Windows | Enabled | |
| Turn off the Store application | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Do not sync | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not sync personalize | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off Windows Calendar | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Disable Windows Error Reporting | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Enables or disables Windows Game Recording and Broadcasting | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Use Windows Hello for Business | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Allow suggested apps in Windows Ink Workspace | Disabled | |||
| Allow Windows Ink Workspace | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off Windows Mail application | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do Not Show First Use Dialog Boxes | Enabled | |
| Prevent Automatic Updates | Enabled | |
| Prevent Desktop Shortcut Creation | Enabled | |
| Prevent Media Sharing | Enabled | |
| Prevent Quick Launch Toolbar Shortcut Creation | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not allow Windows Messenger to be run | Enabled | |
| Do not automatically start Windows Messenger initially | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Windows Mobility Center | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn on Script Execution | Enabled | |||
| ||||
| Action | Replace |
| Source file(s) | \\emea.tpg.ads\pt\Lisbon-CIT\Clients\Settings\GPO\Scripts\Altitude\DeleteXMLFilesAltitude.ps1 |
| Destination file | C:\Bin\DeleteXMLFilesAltitude.ps1 |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows Defender |
| Value name | DisableAntiSpyware |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsStore\WindowsUpdate |
| Value name | AutoDownload |
| Value type | REG_DWORD |
| Value data | 0x2 (2) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows\CloudContent |
| Value name | DisableWindowsConsumerFeatures |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Services\SecurityHealthService |
| Value name | Start |
| Value type | REG_DWORD |
| Value data | 0x3 (3) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows Defender\Systray |
| Value name | HideSystray |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows\Windows Feeds |
| Value name | EnableFeeds |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows\Windows Feeds |
| Value name | EnableFeeds |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{031E4825-7B94-4dc3-B131-E946B44C8DD5} |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer |
| Value name | NoRun |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft |
| Value name | EditFavoritesEnabled |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Prevent changes to Favorites on Microsoft Edge |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\ActionCenter\Quick Actions\All\SystemSettings_Device_BluetoothQuickAction |
| Value name | Type |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Remove "Bluetooh" form Action Center |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Keyboard Layout |
| Value name | Scancode Map |
| Value type | REG_BINARY |
| Value data | 0000000000000000040000002AE037E0000037E00000540000000000 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Disabling the Print Screen / PrtScrn key |
| Action | Create |
| Hive | HKEY_CURRENT_USER (HKU\.DEFAULT) |
| Key path | Software\Microsoft\Windows\CurrentVersion\Search |
| Value name | SearchboxTaskbarMode |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Deny Search Win10 (Cortana) |
| Action | Replace |
| Name | AltitudeDeleteXMLFiles | |||
| Author | EMEA\rodrigues.1104-adm | |||
| Description | ||||
| Run only when user is logged on | InteractiveToken | |||
| UserId | NT AUTHORITY\System | |||
| Run with highest privileges | HighestAvailable | |||
| Hidden | No | |||
| Configure for | 1.3 | |||
| Enabled | Yes |
| 1. Run at user logon | ||||
| Delay task for | 30 seconds | |||
| Activate | 23-9-2020 15:44:49 | Synchronize across time zones | No | |
| Enabled | Yes | |||
| 1. Start a program | ||||
| Program/script | %SystemRoot%\system32\WindowsPowerShell\v1.0\powershell.exe | |||
| Arguments | -ExecutionPolicy Bypass -File "C:\Bin\DeleteXMLFilesAltitude.ps1" |
| Stop if the computer ceases to be idle | No | |||
| Restart if the idle state resumes | No | |||
| Start the task only if the computer is on AC power | No | |||
| Stop if the computer switches to battery power | No | |||
| Allow task to be run on demand | No | |||
| Stop task if it runs longer than | 2 hours | |||
| If the running task does not end when requested, force it to stop | No | |||
| If the task is already running, then the following rule applies | IgnoreNew |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Service name | wmiApSrv |
| Action | Start service |
| Startup type: | Automatic |
| Wait timeout if service is locked: | 30 seconds |
| Log on service as: | No change |
| First failure: | No change |
| Second failure: | No change |
| Subsequent failures: | No change |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Service name | AppXSvc |
| Action | Stop service |
| Startup type: | Disabled |
| Wait timeout if service is locked: | 0 seconds |
| Log on service as: | No change |
| First failure: | No change |
| Second failure: | No change |
| Subsequent failures: | No change |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Service name | Sense |
| Action | Stop service |
| Startup type: | Disabled |
| Wait timeout if service is locked: | 0 seconds |
| Log on service as: | No change |
| First failure: | No change |
| Second failure: | No change |
| Subsequent failures: | No change |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Service name | WdNisSvc |
| Action | Stop service |
| Startup type: | Disabled |
| Wait timeout if service is locked: | 0 seconds |
| Log on service as: | No change |
| First failure: | No change |
| Second failure: | No change |
| Subsequent failures: | No change |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Service name | WinDefend |
| Action | Stop service |
| Startup type: | Disabled |
| Wait timeout if service is locked: | 0 seconds |
| Log on service as: | No change |
| First failure: | No change |
| Second failure: | No change |
| Subsequent failures: | No change |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Service name | bthserv |
| Action | Stop service |
| Startup type: | Disabled |
| Wait timeout if service is locked: | 0 seconds |
| Log on service as: | No change |
| First failure: | No change |
| Second failure: | No change |
| Subsequent failures: | No change |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Block Bluetooth |
| Service name | BTAGService |
| Action | Stop service |
| Startup type: | Disabled |
| Wait timeout if service is locked: | 0 seconds |
| Log on service as: | No change |
| First failure: | No change |
| Second failure: | No change |
| Subsequent failures: | No change |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Block Bluetooth |