| PT-PO-WIN-C-NESSUS Vulnerabilities Servers ZTA Score EMEA ROLLBACK | |
| Data collected on: 2-9-2025 11:30:32 | |
| Domain | emea.tpg.ads |
| Owner | S-1-5-21-513466819-3096973226-347852806-510149 |
| Created | 11-9-2023 19:57:44 |
| Modified | 15-9-2023 13:18:20 |
| User Revisions | 1 (AD), 1 (SYSVOL) |
| Computer Revisions | 4 (AD), 4 (SYSVOL) |
| Unique ID | {c746aaaf-9ced-4bc9-8607-ff8ff13c5403} |
| GPO Status | User settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Servers | No | Enabled | emea.tpg.ads/PT/Systems/Servers |
| Name |
|---|
| EMEA\PTCITENGADB01$ |
| EMEA\PTCITENGAGE01$ |
| EMEA\PTCITNICESRC01$ |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\PTCITENGADB01$ | Read (from Security Filtering) | No |
| EMEA\PTCITENGAGE01$ | Read (from Security Filtering) | No |
| EMEA\PTCITNICESRC01$ | Read (from Security Filtering) | No |
| EMEA\PT-L-SEC-Delegation Modify Group Policy Settings Access | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| S-1-5-21-513466819-3096973226-347852806-510149 | Edit settings, delete, modify security | No |
| Name | Parameters |
|---|---|
| Disable Debug mode.bat | |
| Disable Test Signing.bat |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Update policy override default | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Update policy override | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Turn On Virtualization Based Security | Disabled | CO : Kernel Mode Code Integrity: Enabled Credential Guard: Enabled Hypervisor Code Integrity: Enabled Virtual Secure Mode: Enabled System Management Mode Protections: Enable |
| Policy | Setting | Comment |
|---|---|---|
| Enumeration policy for external devices incompatible with Kernel DMA Protection | Disabled | Enable Memory Access Protection - CO Notas: https://www.stigviewer.com/stig/windows_10/2020-06-15/finding/V-99557 |
| Policy | Setting | Comment |
|---|---|---|
| Toggle user control over Insider builds | Disabled | Disable Windows Insider Program - CO |
| Policy | Setting | Comment |
|---|---|---|
| Manage preview builds | Disabled | Disabled Windows Insider Program - CO |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows Security Health\State |
| Value name | Hardware_HVCI_Off |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Enable Kernel Mode Code Integrity - CO |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | Software\Policies\Microsoft\FVE |
| Value name | MorBehavior |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Enable Memory Overwrite Request Control - CO |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\DeviceGuard |
| Value name | EnableVirtualizationBasedSecurity |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Enable Hypervisor Code Integrity (Strict Mode) - CO Notas: https://learn.microsoft.com/en-us/windows/security/threat-protection/device-guard/enable-virtualization-based-protection-of-code-integrity#enable-memory-integrity-using-group-policy |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\DeviceGuard |
| Value name | RequirePlatformSecurityFeatures |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Enable Hypervisor Code Integrity (Strict Mode) - CO Notas: https://learn.microsoft.com/en-us/windows/security/threat-protection/device-guard/enable-virtualization-based-protection-of-code-integrity#enable-memory-integrity-using-group-policy |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\DeviceGuard |
| Value name | Locked |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Enable Hypervisor Code Integrity (Strict Mode) - CO Notas: https://learn.microsoft.com/en-us/windows/security/threat-protection/device-guard/enable-virtualization-based-protection-of-code-integrity#enable-memory-integrity-using-group-policy |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity |
| Value name | Enabled |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Enable Hypervisor Code Integrity (Strict Mode) - CO Notas: https://learn.microsoft.com/en-us/windows/security/threat-protection/device-guard/enable-virtualization-based-protection-of-code-integrity#enable-memory-integrity-using-group-policy |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity |
| Value name | Locked |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Enable Hypervisor Code Integrity (Strict Mode) - CO https://learn.microsoft.com/en-us/windows/security/threat-protection/device-guard/enable-virtualization-based-protection-of-code-integrity#enable-memory-integrity-using-group-policy |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity |
| Value name | WasEnabledBy |
| Value type | REG_DWORD |
| Value data | 0x2 (2) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Avaiable Mode-based execution control - CO Notas: https://learn.microsoft.com/en-us/windows/security/threat-protection/device-guard/enable-virtualization-based-protection-of-code-integrity#enable-memory-integrity-using-group-policy |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows NT\CurrentVersion\Virtualization |
| Value name | MinVmVersionForCpuBasedMitigations |
| Value type | REG_SZ |
| Value data | 1.0 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Branch Target Injection Mitigation: not disabled in the registry - CO Notas: https://support.microsoft.com/en-au/topic/kb4072698-windows-server-and-azure-stack-hci-guidance-to-protect-against-silicon-based-microarchitectural-and-speculative-execution-side-channel-vulnerabilities-2f965763-00e2-8f98-b632-0d96f30c8c8e |