| TPS-PO-WIN-C-Settings Azure Server Hardening | |
| Data collected on: 2-9-2025 10:49:29 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\Domain Admins |
| Created | 6-10-2022 10:36:46 |
| Modified | 9-2-2023 16:11:56 |
| User Revisions | 0 (AD), 0 (SYSVOL) |
| Computer Revisions | 50 (AD), 50 (SYSVOL) |
| Unique ID | {8b55af0c-14c4-4b21-bdf7-aeb1573ab6cf} |
| GPO Status | User settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| AZR | Yes | Enabled | emea.tpg.ads/TPS/Systems/Servers/AZR |
| Name |
|---|
| EMEA\AZCDEOBSERVER01$ |
| EMEA\AZCDETPC01$ |
| EMEA\AZCDETPC02$ |
| EMEA\AZCDETPC03$ |
| EMEA\AZCDETPC04$ |
| EMEA\THINSCALE01$ |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\AZCDEOBSERVER01$ | Read (from Security Filtering) | No |
| EMEA\AZCDETPC01$ | Read (from Security Filtering) | No |
| EMEA\AZCDETPC02$ | Read (from Security Filtering) | No |
| EMEA\AZCDETPC03$ | Read (from Security Filtering) | No |
| EMEA\AZCDETPC04$ | Read (from Security Filtering) | No |
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\Domain Computers | Read | No |
| EMEA\THINSCALE01$ | Read (from Security Filtering) | No |
| EMEA\zonja.5-adm | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| S-1-5-21-513466819-3096973226-347852806-569437 | Edit settings, delete, modify security | No |
| S-1-5-21-513466819-3096973226-347852806-613853 | Edit settings, delete, modify security | No |
| Policy | Setting |
|---|---|
| Minimum password length | 14 characters |
| Policy | Setting |
|---|---|
| Access this computer from the network | NT AUTHORITY\Authenticated Users, BUILTIN\Administrators |
| Allow log on locally | BUILTIN\Administrators |
| Bypass traverse checking | NT AUTHORITY\NETWORK SERVICE, NT AUTHORITY\LOCAL SERVICE, BUILTIN\Backup Operators, NT AUTHORITY\Authenticated Users, BUILTIN\Administrators |
| Deny access to this computer from the network | BUILTIN\Guests |
| Deny log on as a batch job | BUILTIN\Guests |
| Deny log on as a service | BUILTIN\Guests |
| Deny log on locally | BUILTIN\Guests |
| Deny log on through Terminal Services | BUILTIN\Guests |
| Policy | Setting |
|---|---|
| User Account Control: Admin Approval Mode for the Built-in Administrator account | Enabled |
| User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode | Prompt for consent on the secure desktop |
| User Account Control: Behavior of the elevation prompt for standard users | Automatically deny elevation requests |
| User Account Control: Run all administrators in Admin Approval Mode | Enabled |
| Policy | Setting |
|---|---|
| Network security: Allow Local System to use computer identity for NTLM | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Enable insecure guest logons | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Configure Solicited Remote Assistance | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Enable RPC Endpoint Mapper Client Authentication | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Disallow Autoplay for non-volume devices | Enabled | |||
| Set the default behavior for AutoRun | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Do not show feedback notifications | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Specify the maximum log file size (KB) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Specify the maximum log file size (KB) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Specify the maximum log file size (KB) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Specify the maximum log file size (KB) | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Do not allow passwords to be saved | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Always prompt for password upon connection | Enabled | |
| Require secure RPC communication | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Disallow Digest authentication | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Disallow WinRM from storing RunAs credentials | Enabled |