| RU-PO-WIN-C-Default Systems Policy | |
| Data collected on: 2-9-2025 08:51:00 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\seapol.6 |
| Created | 23-5-2014 11:02:06 |
| Modified | 6-3-2025 14:13:36 |
| User Revisions | 2 (AD), 2 (SYSVOL) |
| Computer Revisions | 673 (AD), 673 (SYSVOL) |
| Unique ID | {5be5c87d-4116-4618-9064-05abed4095d8} |
| GPO Status | User settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Systems | No | Enabled | emea.tpg.ads/RU/Systems |
| VDI Workstations | No | Enabled | emea.tpg.ads/RU/Systems/Clients/MOS/VDI Workstations |
| Name |
|---|
| NT AUTHORITY\Authenticated Users |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\RU-L-SEC-Delegation Group Policy Objects Modify Access | Edit settings, delete, modify security | No |
| EMEA\seapol.6 | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read (from Security Filtering) | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Policy | Setting |
|---|---|
| Audit account logon events | Success, Failure |
| Audit account management | Success, Failure |
| Audit logon events | Success, Failure |
| Audit object access | Success, Failure |
| Audit policy change | Success, Failure |
| Audit privilege use | Success, Failure |
| Audit process tracking | Success, Failure |
| Audit system events | Success, Failure |
| Policy | Setting |
|---|---|
| Deny log on as a batch job | BUILTIN\Guests |
| Deny log on as a service | BUILTIN\Guests |
| Deny log on locally | BUILTIN\Guests, EMEA\RU-L-SEC-GPO Deny log on locally |
| Deny log on through Terminal Services | BUILTIN\Guests, EMEA\RU-L-SEC-GPO Deny log on locally |
| Policy | Setting |
|---|---|
| Accounts: Guest account status | Disabled |
| Accounts: Limit local account use of blank passwords to console logon only | Enabled |
| Accounts: Rename administrator account | "uoincs" |
| Accounts: Rename guest account | "xGuest" |
| Policy | Setting |
|---|---|
| Audit: Audit the access of global system objects | Disabled |
| Audit: Audit the use of Backup and Restore privilege | Disabled |
| Audit: Shut down system immediately if unable to log security audits | Disabled |
| Policy | Setting |
|---|---|
| Domain member: Digitally encrypt or sign secure channel data (always) | Enabled |
| Domain member: Digitally encrypt secure channel data (when possible) | Enabled |
| Domain member: Digitally sign secure channel data (when possible) | Enabled |
| Domain member: Require strong (Windows 2000 or later) session key | Enabled |
| Policy | Setting |
|---|---|
| Interactive logon: Do not require CTRL+ALT+DEL | Disabled |
| Interactive logon: Don't display last signed-in | Enabled |
| Interactive logon: Message text for users attempting to log on | Эта компьютерная система (включая аппаратную часть, программное, обеспечение и периферийные устройства) является собственностью, компании Teleperformance. Использование этой компьютерной системы, ограничено потребностями рабочих процессов Teleperformance., Teleperformance сохраняет за собой право отслеживать доступ к этой, компьютерной системе в любое время. Использование этой системы, означает согласие на такой мониторинг. Любой несанкционированный, доступ, использование или изменение компьютерной системы может, привести к административной и/или уголовной ответственности., ---, This computer system (including all hardware, software, and peripheral, equipment) is the property of Teleperformance. Usage of this computer, system is restricted to official Teleperformance business., Teleperformance reserves the right to monitor usage of this computer, system at any time. Usage of this system constitutes consent to such, monitoring. Any unauthorized access, usage, or modification of this, computer system can result in civil liability and/or criminal penalties. |
| Interactive logon: Message title for users attempting to log on | "Предупреждение / Warning" |
| Interactive logon: Number of previous logons to cache (in case domain controller is not available) | 15 logons |
| Interactive logon: Prompt user to change password before expiration | 5 days |
| Policy | Setting |
|---|---|
| Microsoft network client: Digitally sign communications (always) | Enabled |
| Policy | Setting |
|---|---|
| Microsoft network server: Digitally sign communications (always) | Enabled |
| Microsoft network server: Digitally sign communications (if client agrees) | Enabled |
| Policy | Setting |
|---|---|
| Network access: Do not allow anonymous enumeration of SAM accounts | Enabled |
| Network access: Do not allow anonymous enumeration of SAM accounts and shares | Enabled |
| Network access: Let Everyone permissions apply to anonymous users | Disabled |
| Network access: Named Pipes that can be accessed anonymously | COMNAP, COMNODE, SQL\QUERY, SPOOLSS, NETLOGON, LSARPC, LLSRPC, SAMR |
| Network access: Sharing and security model for local accounts | Classic - local users authenticate as themselves |
| Policy | Setting |
|---|---|
| Network security: Do not store LAN Manager hash value on next password change | Enabled |
| Network security: Force logoff when logon hours expire | Disabled |
| Network security: LAN Manager authentication level | Send NTLMv2 response only. Refuse LM & NTLM |
| Policy | Setting |
|---|---|
| Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings | Enabled |
| Policy | Setting |
|---|---|
| Maximum security log size | 20480 kilobytes |
| Issued To | Issued By | Expiration Date | Intended Purposes |
|---|---|---|---|
| AddTrust External CA Root | AddTrust External CA Root | 30-5-2020 12:48:38 | <All> |
| AeroflotCA | AeroflotCA | 26-8-2038 06:59:00 | <All> |
| DST Root CA X3 | DST Root CA X3 | 30-9-2021 16:01:15 | <All> |
| DStver CA | DStver CA | 30-5-2031 10:56:12 | <All> |
| Mary-Kay-CA | Mary-Kay-CA | 29-10-2030 21:15:52 | <All> |
| Russian Trusted Root CA | Russian Trusted Root CA | 27-2-2032 22:04:15 | <All> |
| Issued To | Issued By | Expiration Date | Intended Purposes |
|---|---|---|---|
| LentaSubIntCA2012 | LentaRootCA | 18-7-2032 13:24:16 | <All> |
| Issued To | Issued By | Expiration Date | Intended Purposes |
|---|---|---|---|
| TPRUCodeSigningCertificate | DStver CA | 25-1-2017 11:52:19 | Time Stamping, Code Signing |
| TPRUCodeSigningCertificate | DStver CA | 25-1-2022 14:12:23 | Time Stamping, Code Signing |
| TPRUCodeSigningCertificate | DStver CA | 1-2-2027 13:03:35 | Time Stamping, Code Signing |
| TPRUPackagesSigningCertificate | DStver CA | 25-1-2022 16:04:08 | Time Stamping, Code Signing |
| TPRUPackagesSigningCertificate | DStver CA | 6-3-2017 14:42:46 | Time Stamping, Code Signing |
| TPRUPackagesSigningCertificate | DStver CA | 1-2-2027 13:06:20 | Time Stamping, Code Signing |
| Policy | Setting |
|---|---|
| Audit Credential Validation | Success, Failure |
| Audit Kerberos Authentication Service | Success, Failure |
| Audit Kerberos Service Ticket Operations | Success, Failure |
| Audit Other Account Logon Events | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Application Group Management | Success, Failure |
| Audit Computer Account Management | Success, Failure |
| Audit Distribution Group Management | No Auditing |
| Audit Other Account Management Events | Success, Failure |
| Audit Security Group Management | Success, Failure |
| Audit User Account Management | Success, Failure |
| Policy | Setting |
|---|---|
| Audit DPAPI Activity | No Auditing |
| Audit PNP Activity | No Auditing |
| Audit Process Creation | Success, Failure |
| Audit Process Termination | Success, Failure |
| Audit RPC Events | No Auditing |
| Policy | Setting |
|---|---|
| Audit Account Lockout | Success, Failure |
| Audit User / Device Claims | No Auditing |
| Audit IPsec Extended Mode | No Auditing |
| Audit IPsec Main Mode | No Auditing |
| Audit IPsec Quick Mode | No Auditing |
| Audit Logoff | Success, Failure |
| Audit Logon | Success, Failure |
| Audit Network Policy Server | Success, Failure |
| Audit Other Logon/Logoff Events | Success, Failure |
| Audit Special Logon | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Detailed File Share | No Auditing |
| Audit File Share | Failure |
| Audit Filtering Platform Connection | No Auditing |
| Audit Filtering Platform Packet Drop | No Auditing |
| Audit Handle Manipulation | No Auditing |
| Audit Kernel Object | No Auditing |
| Audit Other Object Access Events | No Auditing |
| Audit Registry | No Auditing |
| Audit Removable Storage | Success, Failure |
| Audit SAM | No Auditing |
| Audit Central Access Policy Staging | No Auditing |
| Policy | Setting |
|---|---|
| Audit Audit Policy Change | Success, Failure |
| Audit Authentication Policy Change | Success, Failure |
| Audit Authorization Policy Change | No Auditing |
| Audit Filtering Platform Policy Change | No Auditing |
| Audit MPSSVC Rule-Level Policy Change | No Auditing |
| Audit Other Policy Change Events | No Auditing |
| Policy | Setting |
|---|---|
| Audit Non Sensitive Privilege Use | No Auditing |
| Audit Other Privilege Use Events | No Auditing |
| Audit Sensitive Privilege Use | Success, Failure |
| Policy | Setting |
|---|---|
| Audit IPsec Driver | No Auditing |
| Audit Other System Events | Success, Failure |
| Audit Security State Change | Success, Failure |
| Audit Security System Extension | Success, Failure |
| Audit System Integrity | Success, Failure |
| Policy | Setting | Comment |
|---|---|---|
| Prevent changing lock screen and logon image | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Microsoft Peer-to-Peer Networking Services | Enabled |
| Policy | Setting | Comment | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Allow non-administrators to install drivers for these device setup classes | Enabled | ||||||||||||
| |||||||||||||
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Configure registry policy processing | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Specify workplace connectivity wait time for policy processing | Enabled | |||||
| ||||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off handwriting personalization data sharing | Enabled | |
| Turn off handwriting recognition error reporting | Enabled | |
| Turn off Internet Connection Wizard if URL connection is referring to Microsoft.com | Enabled | |
| Turn off Internet File Association service | Enabled | |
| Turn off printing over HTTP | Enabled | |
| Turn off Registration if URL connection is referring to Microsoft.com | Enabled | |
| Turn off Search Companion content file updates | Enabled | |
| Turn off the "Order Prints" picture task | Enabled | |
| Turn off the "Publish to Web" task for files and folders | Enabled | |
| Turn off the Windows Messenger Customer Experience Improvement Program | Enabled | |
| Turn off Windows Customer Experience Improvement Program | Enabled | |
| Turn off Windows Error Reporting | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Configure Offer Remote Assistance | Disabled | |
| Configure Solicited Remote Assistance | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Microsoft Support Diagnostic Tool: Turn on MSDT interactive communication with support provider | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Enable Windows NTP Client | Enabled | |
| Enable Windows NTP Server | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Disallow Autoplay for non-volume devices | Enabled | |||
| Set the default behavior for AutoRun | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn off Autoplay | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Do not display the password reveal button | Enabled | |
| Enumerate administrator accounts on elevation | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Join Microsoft MAPS | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent the usage of OneDrive for file storage | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow indexing of encrypted files | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Service Enabled | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Configure Windows Defender SmartScreen | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Configure Windows Defender SmartScreen | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Disable Windows Error Reporting | Enabled |
| Setting | State |
|---|---|
| Software\Policies\Microsoft\Windows\Skydrive\DisableFileSync | 1 |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Session Manager |
| Value name | CWDIllegalInDllSearch |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\CrashControl |
| Value name | CrashDumpEnabled |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings |
| Value name | EnableLegacyAutoProxyFeatures |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer |
| Value name | NoDriveTypeAutoRun |
| Value type | REG_DWORD |
| Value data | 0xFF (255) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows\GameDVR |
| Value name | AllowgameDVR |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\FileSystem |
| Value name | NtfsDisable8dot3NameCreation |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Services\KDService |
| Value name | ImagePath |
| Value type | REG_EXPAND_SZ |
| Value data | "C:\Program Files\KDService\bin\KDService.exe" |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Attribute | Value |
|---|---|
| bool | AND |
| not | 0 |
| type | MATCHVALUE |
| hive | HKEY_LOCAL_MACHINE |
| key | SYSTEM\CurrentControlSet\Services\KDService |
| valueName | ImagePath |
| valueType | REG_EXPAND_SZ |
| valueData | C:\Program Files\KDService\bin\KDService.exe |
| min | 0.0.0.0 |
| max | 0.0.0.0 |
| gte | 1 |
| lte | 0 |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Driver Signing |
| Value name | Policy |
| Value type | REG_BINARY |
| Value data | 01 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\QualityCompat |
| Value name | cadca5fe-87d3-4b96-b7fb-a231484277cc |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint |
| Value name | RestrictDriverInstallationToAdministrators |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\FileSystem |
| Value name | NtfsDisable8dot3NameCreation |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Attribute | Value |
|---|---|
| bool | AND |
| not | 0 |
| type | NETBIOS |
| name | rumossecd01 |
| Enable for McAfee ePO (needed) |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Skype\Phone |
| Value name | DisableFileTransfer |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Skype\Phone |
| Value name | DisableScreensharing |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_PRINT_INFO_DISCLOSURE_FIX |
| Value name | iexplore.exe |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_PRINT_INFO_DISCLOSURE_FIX |
| Value name | iexplore.exe |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Attribute | Value |
|---|---|
| bool | AND |
| not | 0 |
| variableName | PROCESSOR_ARCHITECTURE |
| value | AMD64 |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALLOW_USER32_EXCEPTION_HANDLER_HARDENING |
| Value name | iexplore.exe |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ALLOW_USER32_EXCEPTION_HANDLER_HARDENING |
| Value name | iexplore.exe |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\system_a.exe |
| Value name | Debugger |
| Value type | REG_SZ |
| Value data | "c:\windows\system32\systray.exe" /z |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows\Windows Feeds |
| Value name | EnableFeeds |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths |
| Value name | C:\ProgramData\Tanium |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths |
| Value name | C:\Program Files (x86)\Tanium |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |