| PT-PO-WIN-ADM-U-Restrictions PCI LITE | |
| Data collected on: 2-9-2025 09:08:06 | |
| Domain | emea.tpg.ads |
| Owner | S-1-5-21-513466819-3096973226-347852806-386608 |
| Created | 14-11-2017 12:55:36 |
| Modified | 28-11-2024 17:03:46 |
| User Revisions | 147 (AD), 147 (SYSVOL) |
| Computer Revisions | 1 (AD), 1 (SYSVOL) |
| Unique ID | {fc8a8284-8c42-4299-bbab-758ba1d921b1} |
| GPO Status | Computer settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| PT | No | Enabled | emea.tpg.ads/PT |
| Name |
|---|
| None |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\PT-L-SEC-U-W11 Hardening PCI | Custom | No |
| Name | Parameters |
|---|---|
| DisableDesktop.ps1 | |
| Restore_PWA_Edge_Chrome.ps1 |
| Enforcement | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Designated File Types | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Trusted Publishers | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
| Policy | Setting |
|---|---|
| Default Security Level | Unrestricted |
| Policy | Setting | Comment | |||||||
|---|---|---|---|---|---|---|---|---|---|
| Always open All Control Panel Items when opening Control Panel | Enabled | ||||||||
| Show only specified Control Panel items | Enabled | ||||||||
| |||||||||
| Policy | Setting | Comment |
|---|---|---|
| Prevent changing desktop background | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not add shares of recently opened documents to Network Locations | Enabled | |
| Hide and disable all items on the desktop | Enabled | GESCP: #22032762 |
| Hide Network Locations icon on desktop | Enabled | |
| Prevent adding, dragging, dropping and closing the Taskbar's toolbars | Enabled | |
| Prohibit User from manually redirecting Profile Folders | Enabled | |
| Remove My Documents icon on the desktop | Enabled | |
| Remove Properties from the Computer icon context menu | Enabled | |
| Remove Properties from the Documents icon context menu | Enabled | |
| Remove Properties from the Recycle Bin context menu | Enabled | |
| Remove Recycle Bin icon from desktop | Enabled | |
| Remove the Desktop Cleanup Wizard | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Disable all items | Enabled | GESCP: #22032762 |
| Prohibit adding items | Enabled | GESCP: #22032762 |
| Policy | Setting | Comment |
|---|---|---|
| Enable Translate | Disabled |
| Policy | Setting | Comment | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Allow importing of payment info | Disabled | |||||||||
| Allow importing of saved passwords | Disabled | |||||||||
| Allow user feedback | Disabled | |||||||||
| Block access to a list of URLs | Enabled | |||||||||
| ||||||||||
| Policy | Setting | Comment | ||||||||
| Control where developer tools can be used | Enabled | GESCP | ||||||||
| ||||||||||
| Policy | Setting | Comment | ||||||||
| Define a list of allowed URLs | Enabled | |||||||||
| ||||||||||
| Policy | Setting | Comment | ||||||||
| Enable AutoFill for addresses | Disabled | |||||||||
| Enable AutoFill for payment instruments | Disabled | |||||||||
| Enable the Collections feature | Disabled | CO 439951 - Disable "Enable Collections feature" | ||||||||
| Enable the Screenshot (previously named Web Capture) feature in Microsoft Edge | Disabled | GESCP | ||||||||
| Hide the First-run experience and splash screen | Enabled | |||||||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Configure cookies | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Control which extensions cannot be installed | Enabled | #23405718 - Block Edge Extensions | ||||
| ||||||
| Policy | Setting | Comment |
|---|---|---|
| Enable saving passwords to the password manager | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow shared folders to be published | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Add Logoff to the Start Menu | Enabled | |
| Disable context menus in the Start Menu | Enabled | |
| Do not search communications | Enabled | |
| Do not search for files | Enabled | |
| Do not search Internet | Enabled | |
| Do not search programs and Control Panel items | Enabled | |
| Force classic Start Menu | Enabled | |
| Prevent users from customizing their Start Screen | Enabled | |
| Prevent users from resizing the taskbar | Enabled | |
| Remove common program groups from Start Menu | Enabled | |
| Remove Default Programs link from the Start menu. | Enabled | |
| Remove Documents icon from Start Menu | Enabled | |
| Remove Favorites menu from Start Menu | Enabled | |
| Remove Help menu from Start Menu | Enabled | |
| Remove links and access to Windows Update | Enabled | |
| Remove Music icon from Start Menu | Enabled | |
| Remove Network Connections from Start Menu | Enabled | |
| Remove Network icon from Start Menu | Enabled | |
| Remove Pictures icon from Start Menu | Enabled | |
| Remove Recent Items menu from Start Menu | Enabled | |
| Remove Run menu from Start Menu | Enabled | |
| Remove Search link from Start Menu | Enabled | |
| Remove user folder link from Start Menu | Enabled | |
| Show QuickLaunch on Taskbar | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Prevent access to registry editing tools | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Prevent access to the command prompt | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Remove Task Manager | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| All Removable Storage classes: Deny all access | Enabled | |
| CD and DVD: Deny read access | Enabled | |
| CD and DVD: Deny write access | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Default risk level for file attachments | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not preserve zone information in file attachments | Enabled | |||
| Inclusion list for low file types | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Do not allow Folder Options to be opened from the Options button on the View tab of the ribbon | Enabled | |||
| Hide these specified drives in My Computer | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Hides the Manage item on the File Explorer context menu | Enabled | |||
| No Computers Near Me in Network Locations | Enabled | |||
| No Entire Network in Network Locations | Enabled | |||
| Prevent access to drives from My Computer | Disabled | |||
| Remove "Map Network Drive" and "Disconnect Network Drive" | Enabled | |||
| Remove CD Burning features | Enabled | |||
| Remove DFS tab | Enabled | CO 388190 | ||
| Remove File Explorer's default context menu | Disabled | |||
| Remove File menu from File Explorer | Enabled | CO 388190 | ||
| Remove Hardware tab | Enabled | CO 388190 | ||
| Remove Search button from File Explorer | Enabled | |||
| Remove Security tab | Enabled | CO 388190 | ||
| Remove Shared Documents from My Computer | Enabled | |||
| Turn off caching of thumbnail pictures | Enabled | |||
| Turn off Windows Key hotkeys | Enabled | |||
| Turn on Classic Shell | Disabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Hide previous versions list for local files | Enabled | CO 388190 |
| Hide previous versions list for remote files | Enabled | CO 388190 |
| Hide previous versions of files on backup location | Enabled | CO 388190 |
| Prevent restoring local previous versions | Enabled | CO 388190 |
| Prevent restoring previous versions from backups | Enabled | CO 388190 |
| Prevent restoring remote previous versions | Enabled | CO 388190 |
| Policy | Setting | Comment |
|---|---|---|
| Do not allow users to enable or disable add-ons | Enabled | CO 388190 |
| Turn off tabbed browsing | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Tools menu: Disable Internet Options... menu option | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Empty Temporary Internet Files folder when browser is closed | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Computer Management | Disabled | |
| Local Users and Groups | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not allow Windows Messenger to be run | Enabled | |
| Do not automatically start Windows Messenger initially | Enabled |
| Setting | State |
|---|---|
| Software\Policies\Microsoft\WindowsMovieMaker\MovieMaker | 1 |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{031E4825-7B94-4dc3-B131-E946B44C8DD5} |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer |
| Value name | NoRun |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_CURRENT_USER |
| Key path | Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
| Value name | NoRun |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | Yes |
| Remove this item when it is no longer applied | Yes |
| Action | Replace |
| Hive | HKEY_CURRENT_USER |
| Key path | Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum |
| Value name | {59031a47-3f72-44a7-89c5-5595fe6b30ee} |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | Yes |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{26EE0668-A00A-44D7-9371-BEB064C98683} |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0} |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | software\policies\microsoft\office\16.0\common\insert media\screenshot |
| Value name | disablescreenclippings |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| #28014264 - Block Clipping - ScreenShot O365 |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Control Panel\Accessibility\Keyboard Response |
| Value name | AutoRepeatDelay |
| Value type | REG_SZ |
| Value data | 0 |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| CO488542 - Block AutoRepeat Keyboard |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Control Panel\Accessibility\Keyboard Response |
| Value name | AutoRepeatRate |
| Value type | REG_SZ |
| Value data | 0 |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| CO488542 - Block AutoRepeat Keyboard |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Control Panel\Accessibility\Keyboard Response |
| Value name | BounceTime |
| Value type | REG_SZ |
| Value data | 0 |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| CO488542 - Block AutoRepeat Keyboard |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Control Panel\Accessibility\Keyboard Response |
| Value name | DelayBeforeAcceptance |
| Value type | REG_SZ |
| Value data | 0 |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| CO488542 - Block AutoRepeat Keyboard |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Control Panel\Accessibility\Keyboard Response |
| Value name | Flags |
| Value type | REG_SZ |
| Value data | 31 |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| CO488542 - Block AutoRepeat Keyboard |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Control Panel\Accessibility\Keyboard Response |
| Value name | Last BounceKey Setting |
| Value type | REG_DWORD |
| Value data | 0x1F4 (500) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| CO488542 - Block AutoRepeat Keyboard |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Control Panel\Accessibility\Keyboard Response |
| Value name | Last Valid Delay |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| CO488542 - Block AutoRepeat Keyboard |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Control Panel\Accessibility\Keyboard Response |
| Value name | Last Valid Repeat |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| CO488542 - Block AutoRepeat Keyboard |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Control Panel\Accessibility\Keyboard Response |
| Value name | Last Valid Wait |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| CO488542 - Block AutoRepeat Keyboard |