| PT-PO-WIN-C-Admin Settings Clear Security Logs | |
| Data collected on: 2-9-2025 11:38:02 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\brighton.6-adm |
| Created | 2-11-2023 09:47:22 |
| Modified | 21-5-2025 15:46:22 |
| User Revisions | 2 (AD), 2 (SYSVOL) |
| Computer Revisions | 64 (AD), 64 (SYSVOL) |
| Unique ID | {3e81efa7-209e-4bdd-b724-53c6731ce5c6} |
| GPO Status | User settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Clients | No | Enabled | emea.tpg.ads/PT/Systems/Clients |
| Name |
|---|
| EMEA\PT-G-ORG-Client System Clear Security Logs |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\brighton.6-adm | Edit settings, delete, modify security | No |
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\PT-G-ORG-Client System Clear Security Logs | Read (from Security Filtering) | No |
| EMEA\PT-L-SEC-Delegation Modify Group Policy Settings Access | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Policy | Setting |
|---|---|
| Audit account logon events | Success, Failure |
| Audit account management | Success, Failure |
| Audit directory service access | Success, Failure |
| Audit object access | Success, Failure |
| Audit policy change | Success, Failure |
| Audit system events | Success, Failure |
| Policy | Setting |
|---|---|
| Accounts: Guest account status | Disabled |
| Accounts: Rename administrator account | "PTAdministrator" |
| Accounts: Rename guest account | "PTGuest" |
| Policy | Setting |
|---|---|
| Audit: Shut down system immediately if unable to log security audits | Disabled |
| Policy | Setting |
|---|---|
| Microsoft network client: Digitally sign communications (always) | Enabled |
| Microsoft network client: Digitally sign communications (if server agrees) | Enabled |
| Policy | Setting |
|---|---|
| Microsoft network server: Digitally sign communications (always) | Enabled |
| Microsoft network server: Digitally sign communications (if client agrees) | Enabled |
| Policy | Setting |
|---|---|
| Network security: Do not store LAN Manager hash value on next password change | Enabled |
| Network security: Force logoff when logon hours expire | Enabled |
| Network security: LAN Manager authentication level | Send NTLMv2 response only. Refuse LM & NTLM |
| Policy | Setting |
|---|---|
| Maximum application log size | 512000 kilobytes |
| Maximum security log size | 3072000 kilobytes |
| Maximum system log size | 512000 kilobytes |
| Retain application log | 93 days |
| Retain system log | 93 days |
| Retention method for application log | By days |
| Retention method for security log | As needed |
| Retention method for system log | By days |
| Type | Name | Permission |
|---|---|---|
| Allow | BUILTIN\Administrators | Full Control |
| Allow | NT AUTHORITY\SYSTEM | Full Control |
| Allow | NT AUTHORITY\INTERACTIVE | Read |
| Type | Name | Access |
|---|---|---|
| Failure | Everyone | Full Control |
| Policy | Setting |
|---|---|
| Trusted Publishers can be managed by: | All administrators and users |
| Verify that certificate is not revoked when adding | Disabled |
| Verify that certificate has a valid time stamp when adding | Disabled |
| Enforcement | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Designated File Types | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Trusted Publishers | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
| Policy | Setting |
|---|---|
| Default Security Level | Unrestricted |
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% | ||||||
| ||||||
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% | ||||||
| ||||||
| C:\Program Files\MSN Gaming Zone\ | ||||||
|
| Policy | Setting |
|---|---|
| Audit Security Group Management | Success |
| Audit User Account Management | Success |
| Policy | Setting |
|---|---|
| Audit Process Creation | Success, Failure |
| Audit Process Termination | Success |
| Policy | Setting |
|---|---|
| Audit Account Lockout | Success |
| Audit Logoff | Success |
| Audit Logon | Success, Failure |
| Audit Special Logon | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Audit Policy Change | Success, Failure |
| Audit Authentication Policy Change | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Security State Change | Success, Failure |
| Audit System Integrity | Success, Failure |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Allow or Disallow use of the Offline Files feature | Disabled | |||
| Prevent use of Offline Files folder | Enabled | |||
| Prohibit user configuration of Offline Files | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Remove "Make Available Offline" command | Enabled | |||
| Synchronize all offline files before logging off | Disabled | |||
| Synchronize all offline files when logging on | Disabled | |||
| Synchronize offline files before suspend | Disabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Prohibit connection to non-domain networks when connected to domain authenticated network | Enabled | Wired or Wireless connection - 13245572 - No âmbito da auditoria de Segurança do projecto Facebook foi efectuado o seguinte pedido: TP should ensure that GPO settings are configured to restrict split tunnelling. |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn off Autoplay | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Require use of specific security layer for remote (RDP) connections | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Require user authentication for remote connections by using Network Level Authentication | Enabled | |||||
| Set client connection encryption level | Enabled | |||||
| ||||||
| Action | Replace |
| Source file(s) | \\emea.tpg.ads\pt\Lisbon-CIT\Clients\Settings\GPO\Wallpaper\TP-PT.jpg |
| Destination file | C:\Bin\TP-PT.jpg |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Copy Wallpaper File to C:\Bin (All Computers) |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.1\Client |
| Value name | DisabledByDefault |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Attribute | Value |
|---|---|
| bool | AND |
| not | 0 |
| class | NT |
| version | WIN7 |
| type | NE |
| edition | NE |
| sp | NE |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client |
| Value name | DisabledByDefault |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Attribute | Value |
|---|---|
| bool | AND |
| not | 0 |
| class | NT |
| version | WIN7 |
| type | NE |
| edition | NE |
| sp | NE |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.1\Server |
| Value name | DisabledByDefault |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Attribute | Value |
|---|---|
| bool | AND |
| not | 0 |
| class | NT |
| version | WIN7 |
| type | NE |
| edition | NE |
| sp | NE |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server |
| Value name | DisabledByDefault |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Attribute | Value |
|---|---|
| bool | AND |
| not | 0 |
| class | NT |
| version | WIN7 |
| type | NE |
| edition | NE |
| sp | NE |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum |
| Value name | {F02C1A0D-BE21-4350-88B0-7367FC96EF3C} |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Block Network Discovery |