| PT-PO-WIN-C-Client System Bolt | |
| Data collected on: 2-9-2025 11:31:48 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\junior.388-adm |
| Created | 15-9-2023 18:12:48 |
| Modified | 25-2-2025 12:40:16 |
| User Revisions | 2 (AD), 2 (SYSVOL) |
| Computer Revisions | 122 (AD), 122 (SYSVOL) |
| Unique ID | {545c1b9d-dd2b-4fe6-a880-06471d1c7fc6} |
| GPO Status | User settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Clients | No | Enabled | emea.tpg.ads/PT/Systems/Clients |
| Name |
|---|
| EMEA\PT-L-SEC-Client System Hardening Bolt |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\junior.388-adm | Edit settings, delete, modify security | No |
| EMEA\PT-L-SEC-Client System Hardening Bolt | Read (from Security Filtering) | No |
| EMEA\PT-L-SEC-Delegation Modify Group Policy Settings Access | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Name | Parameters |
|---|---|
| GroupsFSLogix.ps1 |
| Policy | Setting |
|---|---|
| Allow log on locally | BUILTIN\Administrators, EMEA\PTCIT-G-ORG-Users-TIER2, EMEA\PT-L-SEC-Operation Bolt |
| Policy | Setting |
|---|---|
| Interactive logon: Number of previous logons to cache (in case domain controller is not available) | 0 logons |
| Interactive logon: Require Domain Controller authentication to unlock workstation | Enabled |
| Policy | Setting |
|---|---|
| Network access: Do not allow storage of passwords and credentials for network authentication | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Delete Local Profile When VHD Should Apply | Enabled | |||
| Enabled | Enabled | |||
| Is Dynamic (VHD) | Enabled | |||
| Profile Type | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Redirection XML Source Folder | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Set Temp Folders to Local Path | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| VHD Locations | Disabled | |||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| CCD Locations | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Clear Cache on Logoff | Enabled | |||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| SID Directory Name Match | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| SID Directory Name Pattern | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Volume Type (VHD or VHDX) | Enabled | |||
| ||||
| Policy | Setting | Comment | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Clear Browsing Data on Exit | Enabled | ||||||||||||
| |||||||||||||
| Policy | Setting | Comment | |||||
|---|---|---|---|---|---|---|---|
| Configure extension, app, and user script install sources | Enabled | ||||||
| |||||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Allow sites configured for Internet Explorer mode to open in Microsoft Edge | Enabled | |||
| Configure Internet Explorer integration | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Configure the Enterprise Mode Site List | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Let Windows apps access the camera | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access the microphone | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Set a default associations configuration file | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Turn on Internet Explorer Standards Mode for local intranet | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| End session when time limits are reached | Enabled | CHG000504290 - automatic log off after 30 minutes | ||
| Set time limit for disconnected sessions | Enabled | CHG000504290 - automatic log off after 30 minutes | ||
| ||||
| Action | Replace |
| Source file(s) | \\emea.tpg.ads\pt\Lisbon-CIT\Clients\Settings\GPO\StartMenu\LocalStartMenuBolt.xml |
| Destination file | C:\Bin\LocalStartMenuBolt.xml |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Action | Replace |
| Source file(s) | \\emea.tpg.ads\pt\Lisbon-CIT\Clients\Settings\GPO\File Association\PDF_Chrome_OpenOffice.xml |
| Destination file | C:\Bin\PDF_Chrome_OpenOffice.xml |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Action | Delete |
| Destination file | C:\Bin\IdleTimeRebootBolt.ps1 |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Copia ficheiro para obrigar o Restart ás máquinas fisicas, para FsLogix não ficar com Profiles de tamanhos "Gigantes". |
| Action | Replace |
| Source file(s) | \\emea.tpg.ads\pt\Lisbon-CIT\Clients\Settings\GPO\Scripts\Logoff\IdleTimeBolt.ps1 |
| Destination file | C:\Bin\IdleTimeBolt.ps1 |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Force Logoff 12h |
| Action | Delete |
| Destination file | C:\Bin\IdleTimeRebootBolt.log |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Palo Alto Networks\GlobalProtect\PanSetup |
| Value name | Portal1 |
| Value type | REG_SZ |
| Value data | gp1110.teleperformance.pt |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Palo Alto Networks\GlobalProtect\CBL |
| Value name | Portal2 |
| Value type | REG_SZ |
| Value data | gp1710.teleperfromance.pt |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Palo Alto Networks\GlobalProtect\PanSetup |
| Value name | Portal |
| Value type | REG_SZ |
| Value data | gp1110.teleperformance.pt |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |
| Action | Update |
| Name | Logoff Bolt Machines | |||
| Author | EMEA\silva.12303-adm | |||
| Description | Force Logoff 12h Bolt Machines (FsLogix) | |||
| Run only when user is logged on | InteractiveToken | |||
| UserId | NT AUTHORITY\System | |||
| Run with highest privileges | HighestAvailable | |||
| Hidden | No | |||
| Configure for | 1.3 | |||
| Enabled | Yes |
| 1. Daily | ||||
| Repeat task every 1 hour for a duration of 1 day | ||||
| Stop all running tasks at end of repetition duration | No | |||
| Activate | 16-11-2023 22:30:00 | Synchronize across time zones | No | |
| Enabled | Yes | |||
| Recur every 1 days |
| 1. Start a program | ||||
| Program/script | C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe | |||
| Arguments | -ExecutionPolicy Bypass -File "C:\Bin\IdleTimeBolt.ps1" |
| Stop if the computer ceases to be idle | No | |||
| Restart if the idle state resumes | No | |||
| Start the task only if the computer is on AC power | No | |||
| Stop if the computer switches to battery power | No | |||
| Allow task to be run on demand | Yes | |||
| If the task fails, restart every | 5 minutes | |||
| Attempt to restart up to | 3 | |||
| Stop task if it runs longer than | 3 days | |||
| If the running task does not end when requested, force it to stop | No | |||
| If the task is already running, then the following rule applies | IgnoreNew |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |