| RU-PO-WIN-C-Servers Hardening Policy | |
| Data collected on: 2-9-2025 11:00:20 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\efimov.6-adm |
| Created | 14-12-2022 10:39:02 |
| Modified | 13-2-2025 14:57:24 |
| User Revisions | 0 (AD), 0 (SYSVOL) |
| Computer Revisions | 67 (AD), 67 (SYSVOL) |
| Unique ID | {ea654257-fb2c-4386-8bae-99e35b540254} |
| GPO Status | User settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Servers | No | Enabled | emea.tpg.ads/RU/Systems/Servers |
| Name |
|---|
| NT AUTHORITY\Authenticated Users |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\efimov.6-adm | Edit settings, delete, modify security | No |
| EMEA\RU-L-SEC-Delegation Group Policy Objects Modify Access | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read (from Security Filtering) | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Policy | Setting |
|---|---|
| Shut down the system | BUILTIN\Administrators |
| Policy | Setting |
|---|---|
| Devices: Allowed to format and eject removable media | Administrators |
| Policy | Setting |
|---|---|
| Interactive logon: Number of previous logons to cache (in case domain controller is not available) | 0 logons |
| Interactive logon: Require Domain Controller authentication to unlock workstation | Enabled |
| Policy | Setting | ||||
|---|---|---|---|---|---|
| Network security: Minimum session security for NTLM SSP based (including secure RPC) servers | Enabled | ||||
| |||||
| Policy | Setting | Comment |
|---|---|---|
| Limits print driver installation to Administrators | Enabled |
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Require use of specific security layer for remote (RDP) connections | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Server authentication certificate template | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Set client connection encryption level | Enabled | |||||
| ||||||
| Policy | Setting | Comment |
|---|---|---|
| Allow ECC certificates to be used for logon and authentication | Enabled |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Cryptography\Wintrust\Config |
| Value name | EnableCertPaddingCheck |
| Value type | REG_SZ |
| Value data | 1 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Wow6432Node\Microsoft\Cryptography\Wintrust\Config |
| Value name | EnableCertPaddingCheck |
| Value type | REG_SZ |
| Value data | 1 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Service name | SCardSvr |
| Action | No change |
| Startup type: | Automatic |
| Wait timeout if service is locked: | 30 seconds |
| Log on service as: | No change |
| First failure: | No change |
| Second failure: | No change |
| Subsequent failures: | No change |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |