| RU-PO-SEC-C-Operators Workstations | |
| Data collected on: 2-9-2025 08:54:11 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\efimov.6 |
| Created | 29-4-2014 08:32:04 |
| Modified | 5-3-2025 12:04:52 |
| User Revisions | 50 (AD), 50 (SYSVOL) |
| Computer Revisions | 319 (AD), 319 (SYSVOL) |
| Unique ID | {08e13eea-ef28-45a8-b1ef-babbdd7b64b5} |
| GPO Status | User settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| AHA | No | Enabled | emea.tpg.ads/RU/Systems/Clients/AHA |
| Operators Workstations | No | Enabled | emea.tpg.ads/RU/Systems/Clients/KZN/Operators Workstations |
| Operators Workstations | No | Enabled | emea.tpg.ads/RU/Systems/Clients/MOS/Operators Workstations |
| Operators Workstations | No | Enabled | emea.tpg.ads/RU/Systems/Clients/REN/Operators Workstations |
| Operators Workstations | No | Enabled | emea.tpg.ads/RU/Systems/Clients/RND/Operators Workstations |
| Operators Workstations | No | Enabled | emea.tpg.ads/RU/Systems/Clients/TOI/Operators Workstations |
| Operators Workstations | No | Enabled | emea.tpg.ads/RU/Systems/Clients/TTI/Operators Workstations |
| Operators Workstations | No | Enabled | emea.tpg.ads/RU/Systems/Clients/VGG/Operators Workstations |
| Operators Workstations | No | Enabled | emea.tpg.ads/RU/Systems/Clients/VLD/Operators Workstations |
| Operators Workstations | No | Enabled | emea.tpg.ads/RU/Systems/Clients/VOG/Operators Workstations |
| Name |
|---|
| NT AUTHORITY\Authenticated Users |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\efimov.6 | Edit settings, delete, modify security | No |
| EMEA\RU-L-SEC-Delegation Group Policy Objects Modify Access | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read (from Security Filtering) | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Policy | Setting |
|---|---|
| Accounts: Guest account status | Disabled |
| Policy | Setting |
|---|---|
| Interactive logon: Don't display last signed-in | Enabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Users | Read and Execute | This folder only |
| Allow | BUILTIN\Users | Create folders / Append data, Write attributes, Write extended attributes | This folder only |
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read and Execute | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read and Execute | This folder, subfolders and files |
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read and Execute | This folder, subfolders and files |
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Full control | This key and subkeys |
| Allow | CREATOR OWNER | Full control | Subkeys only |
| Allow | NT AUTHORITY\SYSTEM | Full control | This key and subkeys |
| Allow | BUILTIN\Administrators | Full control | This key and subkeys |
| Allow | BUILTIN\Users | Read | This key and subkeys |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Hide the TaskView button | Enabled | |
| Remove pinned programs from the Taskbar | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Hide entry points for Fast User Switching | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| All Removable Storage classes: Deny all access | Enabled | |
| Removable Disks: Deny execute access | Enabled | |
| Removable Disks: Deny read access | Enabled | |
| Removable Disks: Deny write access | Enabled | |
| WPD Devices: Deny read access | Enabled | |
| WPD Devices: Deny write access | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Delete cached copies of roaming profiles | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off downloading of game information | Enabled | |
| Turn off game updates | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Make proxy settings per-machine (rather than per-user) | Disabled | |
| Prevent changing proxy settings | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Developer Tools | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow Developer Tools | Disabled | |
| Allow InPrivate browsing | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent the usage of OneDrive for file storage | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Specify SHA1 thumbprints of certificates representing trusted .rdp publishers | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off background synchronization for feeds and Web Slices | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not allow web search | Enabled | |
| Don't search the web or display web results in Search | Enabled | |
| Don't search the web or display web results in Search over metered connections | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Automatic Download and Install of updates | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow widgets | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Disable Windows Error Reporting | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off the communities features | Enabled | |
| Turn off Windows Mail application | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not allow Windows Messenger to be run | Enabled | |
| Do not automatically start Windows Messenger initially | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Windows SideShow | Enabled |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer |
| Value name | SpecialRoamingOverrideAllowed |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Attribute | Value |
|---|---|
| bool | AND |
| not | 0 |
| class | NT |
| version | WINTHRESHOLD |
| type | NE |
| edition | NE |
| sp | NE |
| Action | Update |
| Hive | HKEY_CLASSES_ROOT |
| Key path | CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder |
| Value name | Attributes |
| Value type | REG_DWORD |
| Value data | 0xB0940064 (2962489444) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION |
| Value name | AgentDesktop.exe |
| Value type | REG_DWORD |
| Value data | 0x2AF8 (11000) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Service name | BthHFSrv |
| Action | Stop service |
| Startup type: | Disabled |
| Wait timeout if service is locked: | 30 seconds |
| Log on service as: | No change |
| First failure: | No change |
| Second failure: | No change |
| Subsequent failures: | No change |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Service name | bthserv |
| Action | Stop service |
| Startup type: | Disabled |
| Wait timeout if service is locked: | 30 seconds |
| Log on service as: | No change |
| First failure: | No change |
| Second failure: | No change |
| Subsequent failures: | No change |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Service name | WlanSvc |
| Action | Stop service |
| Startup type: | Disabled |
| Wait timeout if service is locked: | 30 seconds |
| Log on service as: | No change |
| First failure: | No change |
| Second failure: | No change |
| Subsequent failures: | No change |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Policy | Setting | Comment |
|---|---|---|
| Turn off ActiveX Opt-In prompt | Enabled |
| Policy | Setting | Comment | ||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Site to Zone Assignment List | Enabled | |||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||