Group Policy Management
body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } }
Setting Path:
Explanation
No explanation is available for this setting.
Supported On:
Not available
ROBUH-PO-WIN-C-DESKTOP HARDENING-WL APPS-ANT
Data collected on: 2-9-2025 11:34:52
General
Details
Domainemea.tpg.ads
OwnerEMEA\trifan.5-adm
Created11-10-2023 10:11:00
Modified12-10-2023 08:59:30
User Revisions183 (AD), 183 (SYSVOL)
Computer Revisions30 (AD), 30 (SYSVOL)
Unique ID{eaeb694e-b60f-49c8-9e59-677547b9f450}
GPO StatusEnabled
Links
LocationEnforcedLink StatusPath
ANTNoEnabledemea.tpg.ads/RO/Systems/Clients/ANT

This list only includes links in the domain of the GPO.
Security Filtering
The settings in this GPO can only apply to the following groups, users, and computers:
Name
EMEA\ROBU1VMANT01$
S-1-5-21-513466819-3096973226-347852806-1108829
S-1-5-21-513466819-3096973226-347852806-1504198
Delegation
These groups and users have the specified permission for this GPO
NameAllowed PermissionsInherited
EMEA\Domain AdminsEdit settings, delete, modify securityNo
EMEA\ROBU1VMANT01$Read (from Security Filtering)No
EMEA\RO-G-ORG-OU AdminsEdit settings, delete, modify securityNo
EMEA\trifan.5-admEdit settings, delete, modify securityNo
NT AUTHORITY\Authenticated UsersReadNo
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSReadNo
NT AUTHORITY\SYSTEMEdit settings, delete, modify securityNo
ROOT\Enterprise AdminsEdit settings, delete, modify securityNo
S-1-5-21-513466819-3096973226-347852806-1108829Read (from Security Filtering)No
S-1-5-21-513466819-3096973226-347852806-1504198Read (from Security Filtering)No
Computer Configuration (Enabled)
Policies
Windows Settings
Security Settings
System Services
Print Spooler (Startup Mode: Disabled)
Permissions
No permissions specified
Auditing
No auditing specified
Administrative Templates
Policy definitions (ADMX files) retrieved from the central store.
Control Panel/Personalization
PolicySettingComment
Prevent changing lock screen and logon imageEnabled
Control Panel/Regional and Language Options
PolicySettingComment
Force selected system UI language to overwrite the user UI languageEnabled
Printers
PolicySettingComment
Printer browsingDisabled
Windows Components/Windows Installer
PolicySettingComment
Turn off Windows InstallerEnabled
Disable Windows InstallerFor non-managed applications only
Preferences
Control Panel Settings
Services
Service (Name: BTAGService)
BTAGService (Order: 1)
General
Service nameBTAGService
ActionStop service
Startup type:Automatic
Wait timeout if service is locked:30 seconds
Service Account
Log on service as:No change
Recovery
First failure:No change
Second failure:No change
Subsequent failures:No change
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Apply once and do not reapplyNo
Service (Name: bthserv)
bthserv (Order: 2)
General
Service namebthserv
ActionStart service
Startup type:Automatic
Wait timeout if service is locked:30 seconds
Service Account
Log on service as:No change
Recovery
First failure:No change
Second failure:No change
Subsequent failures:No change
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Apply once and do not reapplyNo
Service (Name: BluetoothUserService_e5396)
BluetoothUserService_e5396 (Order: 3)
General
Service nameBluetoothUserService_e5396
ActionNo change
Startup type:Automatic
Wait timeout if service is locked:30 seconds
Service Account
Log on service as:No change
Recovery
First failure:No change
Second failure:No change
Subsequent failures:No change
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Apply once and do not reapplyNo
User Configuration (Enabled)
Policies
Windows Settings
Security Settings
Software Restriction Policies
Enforcement
PolicySetting
Apply Software Restriction Policies to the followingAll software files except libraries (such as DLLs)
Apply Software Restriction Policies to the following usersAll users except local administrators
When applying Software Restriction PoliciesIgnore certificate rules
Designated File Types
File ExtensionFile Type
ADEADE File
ADPADP File
BASBAS File
BATWindows Batch File
CHMCompiled HTML Help file
CMDWindows Command Script
COMMS-DOS Application
CPLControl panel item
CRTSecurity Certificate
EXEApplication
HLPHelp file
HTAHTML Application
INFSetup Information
INSINS File
ISPISP File
LNKShortcut
MDBMDB File
MDEMDE File
MSCMicrosoft Common Console Document
MSIWindows Installer Package
MSPWindows Installer Patch
MSTMST File
OCXActiveX control
PCDPCD File
PIFShortcut to MS-DOS Program
REGRegistration Entries
SCRScreen saver
SHSSHS File
URLInternet Shortcut
VBVisual Basic Source File
WSCWindows Script Component
Trusted Publishers
Trusted publisher managementAllow all administrators and users to manage user's own Trusted Publishers
Certificate verificationNone
Software Restriction Policies/Security Levels
PolicySetting
Default Security LevelDisallowed
Software Restriction Policies/Additional Rules
Path Rules
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:21:00
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir%
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:21:00
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir(x86)%
Security LevelDisallowed
Description
Date last modified11-10-2023 10:24:59
%logonserver%\netlogon\*\*.vbs
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:26:43
%Program Files%\BlueJeans
Security LevelDisallowed
Description
Date last modified11-10-2023 10:25:30
%PROGRAMFILES%\SogouInput\
Security LevelDisallowed
Description
Date last modified11-10-2023 10:25:43
\\teleperformancemy.com\SysVol\
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:26:28
\\zca-fs-01.teleperformancemy.com\store\IT\Netlogon\keyboard\koreakeyboard.bat
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:26:16
\\zca-fs-01.teleperformancemy.com\store\IT\Netlogon\keyboard\koreakeyboard.ps1
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:27:14
\\zca-fs-01.teleperformancemy.com\Troubleshoot Tools\winauth.bat
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:27:22
\\zca-fs-01\Troubleshoot Tools\winauth.bat
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:27:30
C:\BGInfo
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:27:42
C:\deletedesktopfile.bat
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:27:54
C:\Program Files (x86)\Avaya
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:28:05
C:\Program Files (x86)\Citrix
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:28:22
C:\Program Files (x86)\Google
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:28:15
C:\Program Files (x86)\Microsoft\
Security LevelDisallowed
Description
Date last modified11-10-2023 10:28:33
C:\Program Files (x86)\Microsoft\Edge
Security LevelDisallowed
Description
Date last modified11-10-2023 10:28:45
C:\Program Files (x86)\Windows Media Player
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:28:56
C:\Program Files (x86)\ZOHO Corp
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:29:07
C:\Program Files\CONEXANT
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:29:14
C:\Program Files\CrowdStrike
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:29:22
C:\Program Files\Google\Chrome\Application
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:29:33
C:\Program Files\Microsoft Office
Security LevelDisallowed
Description
Date last modified11-10-2023 10:29:59
C:\Program Files\OpenVPN Connect
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:30:12
C:\Program Files\Tenable
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:30:22
C:\Program Files\TPSentinel
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:30:28
C:\Program Files\Windows Media Player
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:30:39
C:\Program Files\WindowsApps\22094SynapticsIncorporate.AudioControls*
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:30:47
C:\Program Files\WindowsApps\Microsoft.MicrosoftStickyNotes_4.1.6.0_x64__8wekyb3d8bbwe
Security LevelDisallowed
Description
Date last modified11-10-2023 10:30:58
C:\Program Files\WindowsApps\Microsoft.Windows.Photos*
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:31:05
C:\Program Files\WindowsApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy
Security LevelDisallowed
Description
Date last modified11-10-2023 10:31:44
C:\Program Files\WindowsApps\Microsoft.WindowsStore*
Security LevelDisallowed
Description
Date last modified11-10-2023 10:32:27
C:\Program Files\Zscaler
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:32:38
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
Security LevelDisallowed
Description
Date last modified11-10-2023 10:33:17
C:\Users\%username%\AppData\Local\BlueJeans
Security LevelDisallowed
Description
Date last modified11-10-2023 10:34:18
C:\Users\%Username%\AppData\Local\Google
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:34:40
C:\Users\%Username%\Appdata\Roaming\WinAuth
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:34:51
C:\Users\%username%\Desktop\winauth reset.bat
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:35:06
C:\Users\%username%\Desktop\WinAuth.exe
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:35:25
C:\Windows\System32\osk.exe
Security LevelUnrestricted
Description
Date last modified11-10-2023 10:35:35
Administrative Templates
Policy definitions (ADMX files) retrieved from the central store.
Control Panel
PolicySettingComment
Prohibit access to Control Panel and PC settingsDisabled
Settings Page VisibilityEnabled
Settings Page Visibility:showonly:keyboard;regionlanguage;sound
PolicySettingComment
Show only specified Control Panel itemsEnabled
List of allowed Control Panel items
Microsoft.DefaultPrograms
Control Panel/Personalization
PolicySettingComment
Prevent changing desktop iconsEnabled
Control Panel/Printers
PolicySettingComment
Browse the network to find printersEnabled
Prevent addition of printersEnabled
Control Panel/Programs
PolicySettingComment
Hide "Programs and Features" pageEnabled
Control Panel/Regional and Language Options
PolicySettingComment
Restricts the UI languages Windows should use for the selected userDisabled
Google/Google Chrome
PolicySettingComment
Allow download restrictionsEnabled
Download restrictionsBlock malicious downloads and dangerous file types.
PolicySettingComment
Control where Developer Tools can be usedEnabled
Control where Developer Tools can be usedDisallow usage of the Developer Tools
PolicySettingComment
Disable saving browser historyEnabled
Incognito mode availabilityEnabled
Incognito mode availabilityIncognito mode disabled
Google/Google Chrome/Content settings
PolicySettingComment
Default cookies settingEnabled
Default cookies settingKeep cookies for the duration of the session
Start Menu and Taskbar
PolicySettingComment
Do not allow pinning programs to the TaskbarEnabled
Do not allow pinning Store app to the TaskbarEnabled
Do not search for filesEnabled
Do not search InternetEnabled
Do not search programs and Control Panel itemsEnabled
Do not use the search-based method when resolving shell shortcutsEnabled
Lock the TaskbarEnabled
Prevent changes to Taskbar and Start Menu SettingsEnabled
Remove All Programs list from the Start menuEnabled
Choose one of the following actionsRemove and disable setting
PolicySettingComment
Remove Documents icon from Start MenuEnabled
Remove Downloads link from Start MenuEnabled
Remove frequent programs list from the Start MenuEnabled
Remove Games link from Start MenuEnabled
Remove Help menu from Start MenuEnabled
Remove Homegroup link from Start MenuEnabled
Remove Music icon from Start MenuEnabled
Remove Network Connections from Start MenuEnabled
Remove Network icon from Start MenuEnabled
Remove Pictures icon from Start MenuEnabled
Remove pinned programs from the TaskbarEnabled
Remove programs on Settings menuEnabled
Remove Recorded TV link from Start MenuEnabled
Remove Search Computer linkEnabled
Remove See More Results / Search Everywhere linkEnabled
Remove Videos link from Start MenuEnabled
Start LayoutEnabled
Start Layout File\\MYKCPANTDC01\GPOrelated\FBK\cms-startlayout-fb.xml
Reapply layout at every logonDisabled
System
PolicySettingComment
Don't run specified Windows applicationsEnabled
List of disallowed applications
µTorrent.exe
avant.exe
azureus.exe
bitcomet.exe
bittorrent.exe
bling.exe
cmd.exe
ctorrent.exe
command.com
DbxSvc.exe
del.exe
Dropbox.exe
FirefoxPortable.exe
gator.exe
HelpPane.exe
kaz.exe
limewire.exe
kazaa.exe
Microsoft.Notes.exe
Microsoft.Notes.exe
mmc.exe
msblast.exe
mspaint.exe
mstsc.exe
ncrvs.exe
notepad.exe
nvscv32.exe
powershell.exe
powershell_ise.exe
pp.exe
q7i1j3n9q3s.exe
regedit.exe
regedit32.exe
rnathchk.exe
runouce.exe
sample.exe
ScreenSketch.exe
secsvc.exe
skype.exe
snippingtool
snippingtool.exe
StikyNot.exe
Swin32ssr.exe
tds.exe
torrent.exe
tov.exe
U.exe
UniKeyNT.exe
utorrent.exe
viber.exe
vuze.exe
WhatsApp.exe
wordpad.exe
WORDVIEW.EXE
ziptorrent.exe
PPTVIEW.EXE
PolicySettingComment
Prevent access to registry editing toolsEnabled
Disable regedit from running silently?No
PolicySettingComment
Prevent access to the command promptEnabled
Disable the command prompt script processing also?No
System/Ctrl+Alt+Del Options
PolicySettingComment
Remove Task ManagerEnabled
System/Group Policy
PolicySettingComment
Set Group Policy refresh interval for usersEnabled
This setting allows you to customize how often Group Policy is applied
to users. The range is 0 to 44640 minutes (31 days).
Minutes:60
This is a random time added to the refresh interval to prevent
all clients from requesting Group Policy at the same time.
The range is 0 to 1440 minutes (24 hours)
Minutes:30
System/Removable Storage Access
PolicySettingComment
All Removable Storage classes: Deny all accessEnabled
CD and DVD: Deny read accessEnabled
CD and DVD: Deny write accessEnabled
Removable Disks: Deny read accessEnabled
Removable Disks: Deny write accessEnabled
WPD Devices: Deny read accessEnabled
WPD Devices: Deny write accessEnabled
Windows Components/AutoPlay Policies
PolicySettingComment
Turn off AutoplayEnabled
Turn off Autoplay on:All drives
Windows Components/File Explorer
PolicySettingComment
Hide these specified drives in My ComputerEnabled
Pick one of the following combinationsRestrict all drives
PolicySettingComment
No Computers Near Me in Network LocationsEnabled
Prevent access to drives from My ComputerEnabled
Pick one of the following combinationsRestrict all drives
PolicySettingComment
Remove "Map Network Drive" and "Disconnect Network Drive"Enabled
Remove File Explorer's default context menuEnabled
Turn off Windows Key hotkeysEnabled
Windows Components/Internet Explorer
PolicySettingComment
Prevent access to Internet Explorer HelpEnabled
Turn on the auto-complete feature for user names and passwords on formsDisabled
Windows Components/Internet Explorer/Browser menus
PolicySettingComment
File menu: Disable Open menu optionEnabled
Tools menu: Disable Internet Options... menu optionEnabled
Windows Components/Microsoft Management Console/Restricted/Permitted snap-ins
PolicySettingComment
Computer ManagementEnabled
Device ManagerEnabled
Event ViewerEnabled
Event Viewer (Windows Vista)Enabled
ServicesEnabled
Preferences
Windows Settings
Files
File (Target Path: C:\Users\Public\Desktop\Microsoft Edge.lnk)
Microsoft Edge.lnk (Order: 1)
General
ActionDelete
Properties
Destination fileC:\Users\Public\Desktop\Microsoft Edge.lnk
Suppress errors on individual file actionsDisabled
Attributes
Read-onlyDisabled
HiddenDisabled
ArchiveEnabled
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)No
Apply once and do not reapplyNo
Shortcuts
Shortcut (Path: %CommonDesktopDir%\Microsoft Edge.lnk)
Microsoft Edge.lnk (Order: 1)
General
ActionDelete
Attributes
Target typeFile system object
Shortcut path%CommonDesktopDir%\Microsoft Edge.lnk
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Run in logged-on user's security context (user policy option)Yes
Apply once and do not reapplyNo