| TN-PO-WIN-C-Windows 10 Hardening RollOut | |
| Data collected on: 2-9-2025 12:50:47 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\toumi.80-adm |
| Created | 3-4-2025 18:36:36 |
| Modified | 9-4-2025 16:02:40 |
| User Revisions | 1 (AD), 1 (SYSVOL) |
| Computer Revisions | 45 (AD), 45 (SYSVOL) |
| Unique ID | {56d5fd22-ab5a-4630-ac99-9aa28bee5453} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| None | |||
| Name |
|---|
| None |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\TN-G-ORG-OU Admins | Edit settings, delete, modify security | No |
| EMEA\TN-L-SEC-Delegation Modify Group Policy Settings Access | Edit settings, delete, modify security | No |
| EMEA\toumi.80-adm | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Policy | Setting |
|---|---|
| Deny log on locally | EMEA\TN-L-SEC-GPO-WAHA-User-Configuration, TN-L-SEC-Folder_Redirection_Startmenu_WAHA |
| Policy | Setting |
|---|---|
| User Account Control: Admin Approval Mode for the Built-in Administrator account | Disabled |
| User Account Control: Behavior of the elevation prompt for standard users | Prompt for credentials |
| User Account Control: Detect application installations and prompt for elevation | Enabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Deny | EMEA\TN-L-SEC Disable Win10 Features | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Deny | EMEA\TNKR2-G-ORG-TikTok_Disable_Win10_Features_TikTok | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read and Execute | This folder, subfolders and files |
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Users | Read and Execute | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Deny | EMEA\TN-L-SEC Disable Win10 Features | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Deny | EMEA\TN-L-SEC Disable Win10 Features | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Deny | EMEA\TN-L-SEC Disable Win10 Features | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Deny | EMEA\TN-L-SEC Disable Win10 Features | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Deny | EMEA\TNKR2-G-ORG-TikTok_Disable_Win10_Features_TikTok | Full Control | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Issued To | Issued By | Expiration Date | Intended Purposes |
|---|---|---|---|
| Sectigo RSA Organization Validation Secure Server CA | USERTrust RSA Certification Authority | 1-1-2031 00:59:59 | Server Authentication, Client Authentication |
| USERTrust ECC Certification Authority | USERTrust ECC Certification Authority | 19-1-2038 00:59:59 | Time Stamping, Encrypting File System, IP security tunnel termination, Server Authentication, IP security user, Client Authentication, Secure Email, Code Signing |
| USERTrust RSA Certification Authority | USERTrust RSA Certification Authority | 19-1-2038 00:59:59 | <All> |
| UTN-USERFirst-Object | UTN-USERFirst-Object | 9-7-2019 20:40:36 | Code Signing, Time Stamping, Encrypting File System |
| Enforcement | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Designated File Types | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Trusted Publishers | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
| Policy | Setting |
|---|---|
| Default Security Level | Unrestricted |
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% | ||||||
| ||||||
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% | ||||||
| ||||||
| %programfiles%\WindowsApps\Microsoft.WindowsStore* | ||||||
|
| Policy | Setting | Comment |
|---|---|---|
| Allow users to enable online speech recognition services | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off automatic learning | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Allow or block video capture | Disabled | |||
| Allow or deny screen capture | Disabled | |||
| Allow pages to send synchronous XHR requests during page dismissal (obsolete) | Disabled | |||
| Allow personalization of ads, Microsoft Edge, search, news and other Microsoft services by sending browsing history, favorites and collections, usage and other browsing data to Microsoft | Disabled | |||
| Allow Pin to taskbar wizard | Disabled | |||
| Allow suggestions from local providers | Disabled | |||
| Allow users to open files using the ClickOnce protocol | Disabled | |||
| Allow users to open files using the DirectInvoke protocol | Disabled | |||
| Block third party cookies | Enabled | |||
| Browser sign-in settings | Disabled | |||
| Clear browsing data when Microsoft Edge closes | Disabled | |||
| Configure Online Text To Speech | Disabled | |||
| Enable guest mode | Disabled | |||
| Enable online OCSP/CRL checks | Disabled | |||
| Enable search suggestions | Disabled | |||
| Enable site isolation for every site | Disabled | |||
| Enable Translate | Disabled | |||
| Enforce Bing SafeSearch | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Enforce Google SafeSearch | Disabled | |||
| Extend Adobe Flash content setting to all content (obsolete) | Disabled | |||
| Manage exposure of local IP addressess by WebRTC | Disabled | |||
| Show an "Always open" checkbox in external protocol dialog | Disabled | |||
| Specify if online OCSP/CRL checks are required for local trust anchors | Enabled | |||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Control use of the Web Bluetooth API | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Control use of the WebUSB API | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Default Adobe Flash setting (obsolete) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Supported authentication schemes | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| IPv6 Configuration Policy | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Allow or Disallow use of the Offline Files feature | Disabled | |||
| Prohibit user configuration of Offline Files | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Start Layout | Enabled | |||||
| ||||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off access to the Store | Enabled | |
| Turn off handwriting personalization data sharing | Enabled | |
| Turn off handwriting recognition error reporting | Enabled | |
| Turn off Help and Support Center "Did you know?" content | Enabled | |
| Turn off the Windows Messenger Customer Experience Improvement Program | Enabled | |
| Turn off Windows Error Reporting | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Always wait for the network at computer startup and logon | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow publishing of User Activities | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn Off the hard disk (plugged in) | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Allow standby states (S1-S3) when sleeping (on battery) | Disabled | |
| Allow standby states (S1-S3) when sleeping (plugged in) | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow restore of system to default state | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Configuration | Enabled | |
| Turn off System Restore | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not log users on with temporary profiles | Enabled | |
| Turn off the advertising ID | Enabled |
| Policy | Setting | Comment | ||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Let Windows apps access account information | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access call history | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access contacts | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access diagnostic information about other apps | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access email | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access location | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access messaging | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access motion | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access notifications | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access Tasks | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access the calendar | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access the camera | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access the microphone | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps access trusted devices | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps communicate with unpaired devices | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps control radios | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps make phone calls | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||
| Let Windows apps run in the background | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Remove Program Compatibility Property Page | Enabled | |
| Turn off Application Compatibility Engine | Enabled | |
| Turn off Application Telemetry | Enabled | |
| Turn off Inventory Collector | Enabled | |
| Turn off Program Compatibility Assistant | Enabled | |
| Turn off Steps Recorder | Enabled | |
| Turn off SwitchBack Compatibility Engine | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not show Windows tips | Enabled | |
| Turn off Microsoft consumer experiences | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Allow Diagnostic Data | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Configure the Commercial ID | Disabled | |||
| Do not show feedback notifications | Enabled | |||
| Limit optional diagnostic data for Desktop Analytics | Disabled | |||
| Toggle user control over Insider builds | Disabled | |||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Download Mode | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off desktop gadgets | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Do not show the 'new application installed' notification | Enabled | |||
| Set a default associations configuration file | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Start File Explorer with ribbon minimized | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off File History | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn On/Off Find My Device | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off downloading of game information | Enabled | |
| Turn off game updates | Enabled | |
| Turn off tracking of last play time of games in the Games folder | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off location | Enabled | |
| Turn off sensors | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Windows Location Provider | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Block all consumer Microsoft account user authentication | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Microsoft Defender Antivirus | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Configure local setting override for reporting to Microsoft MAPS | Disabled | |||
| Join Microsoft MAPS | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Send file samples when further analysis is required | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Monitor file and program activity on your computer | Disabled | |
| Turn off real-time protection | Disabled | |
| Turn on behavior monitoring | Disabled | |
| Turn on process scanning whenever real-time protection is enabled | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow clearing browsing data on exit | Enabled | |
| Allow InPrivate browsing | Disabled | |
| Allow search engine customization | Disabled | |
| Prevent access to the about:flags page in Microsoft Edge | Enabled | |
| Prevent the First Run webpage from opening on Microsoft Edge | Enabled | |
| Send all intranet sites to Internet Explorer 11 | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Prevent OneDrive files from syncing over metered connections | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Prevent OneDrive from generating network traffic until the user signs in to OneDrive | Enabled | |||
| Prevent the usage of OneDrive for file storage | Enabled | |||
| Prevent the usage of OneDrive for file storage on Windows 8.1 | Enabled | |||
| Save documents to OneDrive by default | Disabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Turn off Active Help | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Push To Install service | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Allow Cloud Search | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Allow Cortana | Disabled | |||
| Allow Cortana above lock screen | Disabled | |||
| Allow indexing of encrypted files | Disabled | |||
| Allow search and Cortana to use location | Disabled | |||
| Do not allow web search | Enabled | |||
| Don't search the web or display web results in Search | Enabled | |||
| Set what information is shared in Search | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Turn on Security Center (Domain PCs only) | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow Automatic Update of Speech Data | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Disable all apps from Microsoft Store | Enabled | |
| Only display the private store within the Microsoft Store | Enabled | |
| Turn off the Store application | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off automatic learning | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Configure Windows Defender SmartScreen | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Configure Windows Defender SmartScreen | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Automatically send memory dumps for OS-generated error reports | Disabled | |
| Disable Windows Error Reporting | Enabled | |
| Do not send additional data | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Enables or disables Windows Game Recording and Broadcasting | Disabled |
| Setting | State |
|---|---|
| Software\Policies\Microsoft\Windows\PreviewBuilds\EnableConfigFlighting | 1 |
| Software\Policies\Microsoft\Windows\PreviewBuilds\EnableExperimentation | 1 |
| Action | Delete |
| Destination file | C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2 |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Enabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Destination file | C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3 |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Enabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Destination file | C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group1 |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Enabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows Defender |
| Value name | DisableAntiSpyware |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsStore\WindowsUpdate |
| Value name | AutoDownload |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows\CloudContent |
| Value name | DisableWindowsConsumerFeatures |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Services\SecurityHealthService |
| Value name | Start |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Config |
| Value name | DownloadMode |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\WindowsStore |
| Value name | AutoDownload |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Services\CSC\Parameters |
| Value name | FormatDatabase |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |