| TR-PO-WIN-ADM-U-Log On To Script Test | |
| Data collected on: 2-9-2025 11:55:31 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\kaya.30-adm |
| Created | 7-2-2024 11:49:06 |
| Modified | 2-4-2024 15:52:12 |
| User Revisions | 493 (AD), 493 (SYSVOL) |
| Computer Revisions | 142 (AD), 142 (SYSVOL) |
| Unique ID | {33070cb2-9e65-42f8-9da7-c25113a895b5} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| TR | No | Enabled | emea.tpg.ads/TR |
| Name |
|---|
| None |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\baran.27 | Edit settings, delete, modify security | No |
| EMEA\dalbudak.7 | Edit settings, delete, modify security | No |
| EMEA\dirlik.6 | Edit settings, delete, modify security | No |
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\Domain Computers | Read | No |
| EMEA\kaya.30-adm | Edit settings, delete, modify security | No |
| EMEA\TR-L-SEC-Delegation Modify Group Policy Settings Access | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Enforcement | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Designated File Types | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Trusted Publishers | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
| Policy | Setting |
|---|---|
| Default Security Level | Unrestricted |
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% | ||||||
| ||||||
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% | ||||||
|
| Action | Replace |
| Source file(s) | \\emea.tpg.ads\SysVol\emea.tpg.ads\Policies\{33070CB2-9E65-42F8-9DA7-C25113A895B5}\User\Scripts\Logon\test.ps1 |
| Destination file | C:\Sec\test.ps1 |
| Suppress errors on individual file actions | Disabled |
| Read-only | Enabled |
| Hidden | Enabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Attribute | Value |
|---|---|
| bool | AND |
| not | 0 |
| name | EMEA\test.5 |
| sid | S-1-5-21-513466819-3096973226-347852806-1340335 |
| Action | Replace |
| Source file(s) | \\emea.tpg.ads\SysVol\emea.tpg.ads\Policies\{33070CB2-9E65-42F8-9DA7-C25113A895B5}\User\Scripts\Logon\Test.csv |
| Destination file | C:\Sec\Test.csv |
| Suppress errors on individual file actions | Disabled |
| Read-only | Enabled |
| Hidden | Enabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Attribute | Value |
|---|---|
| bool | AND |
| not | 0 |
| name | EMEA\test.5 |
| sid | S-1-5-21-513466819-3096973226-347852806-1340335 |
| Action | Replace |
| Path | C:Sec |
| Read-only | Enabled |
| Hidden | Enabled |
| Archive | Enabled |
| Delete this folder (if emptied) | Disabled |
| Recursively delete all subfolders (if emptied) | Disabled |
| Delete all files in the folder(s) | Disabled |
| Allow deletion of read-only files/folders | Disabled |
| Ignore errors for files/folders that cannot be deleted | Disabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Attribute | Value |
|---|---|
| bool | AND |
| not | 0 |
| name | EMEA\test.5 |
| sid | S-1-5-21-513466819-3096973226-347852806-1340335 |
| Action | Replace |
| Name | TPSecurty | |||
| Author | EMEA\baran.27 | |||
| Description | ||||
| Run only when user is logged on | InteractiveToken | |||
| UserId | NT AUTHORITY\System | |||
| Run with highest privileges | LeastPrivilege | |||
| Hidden | No | |||
| Configure for | 1.2 | |||
| Enabled | Yes |
| 1. Run at user logon | ||||
| Activate | 18-2-2024 11:20:33 | Synchronize across time zones | No | |
| Enabled | Yes | |||
| UserId | EMEA\test.5 | |||
| 2. On workstation lock | ||||
| Enabled | Yes | |||
| UserId | EMEA\test.5 | |||
| 3. On workstation unlock | ||||
| Enabled | Yes | |||
| UserId | EMEA\test.5 | |||
| 4. On remote connection to user session | ||||
| Enabled | Yes | |||
| UserId | EMEA\test.5 | |||
| 5. On remote disconnect from user session | ||||
| Enabled | Yes | |||
| UserId | EMEA\test.5 | |||
| 6. On an event | ||||
| Enabled | Yes | |||
| Subscription | <QueryList><Query Id="0" Path="Microsoft-Windows-Security-Audit-Configuration-Client/Operational"><Select Path="Microsoft-Windows-Security-Audit-Configuration-Client/Operational">*[System[Provider[@Name='Microsoft-Windows-Security-Audit-Configuration-Client'] and EventID=4778]]</Select></Query></QueryList> | |||
| 7. On an event | ||||
| Enabled | Yes | |||
| Subscription | <QueryList><Query Id="0" Path="Microsoft-Windows-Security-Audit-Configuration-Client/Operational"><Select Path="Microsoft-Windows-Security-Audit-Configuration-Client/Operational">*[System[Provider[@Name='Microsoft-Windows-Security-Audit-Configuration-Client'] and EventID=4779]]</Select></Query></QueryList> | |||
| 8. On an event | ||||
| Enabled | Yes | |||
| Subscription | <QueryList><Query Id="0" Path="Microsoft-Windows-Security-Audit-Configuration-Client/Operational"><Select Path="Microsoft-Windows-Security-Audit-Configuration-Client/Operational">*[System[Provider[@Name='Microsoft-Windows-Security-Audit-Configuration-Client'] and EventID=4624]]</Select></Query></QueryList> | |||
| 9. On an event | ||||
| Enabled | Yes | |||
| Subscription | <QueryList><Query Id="0" Path="Microsoft-Windows-Security-Audit-Configuration-Client/Operational"><Select Path="Microsoft-Windows-Security-Audit-Configuration-Client/Operational">*[System[Provider[@Name='Microsoft-Windows-Security-Audit-Configuration-Client'] and EventID=4672]]</Select></Query></QueryList> |
| 1. Start a program | ||||
| Program/script | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | |||
| Arguments | -ExecutionPolicy Bypass -File C:\Sec\test.ps1 |
| Stop if the computer ceases to be idle | Yes | |||
| Restart if the idle state resumes | No | |||
| Start the task only if the computer is on AC power | No | |||
| Stop if the computer switches to battery power | Yes | |||
| Allow task to be run on demand | Yes | |||
| Run task as soon as possible after a scheduled start is missed | Yes | |||
| Stop task if it runs longer than | 3 days | |||
| If the running task does not end when requested, force it to stop | Yes | |||
| If the task is already running, then the following rule applies | IgnoreNew |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Attribute | Value |
|---|---|
| bool | AND |
| not | 0 |
| name | EMEA\test.5 |
| sid | S-1-5-21-513466819-3096973226-347852806-1340335 |