| TR-PO-WIN-ADM-U-Restrictions GISP | |
| Data collected on: 2-9-2025 12:45:24 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\aygin.6-adm |
| Created | 23-2-2025 22:28:40 |
| Modified | 18-6-2025 14:32:30 |
| User Revisions | 84 (AD), 84 (SYSVOL) |
| Computer Revisions | 253 (AD), 253 (SYSVOL) |
| Unique ID | {c31ed4af-081f-436d-95f2-b557c2089871} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| TR | No | Enabled | emea.tpg.ads/TR |
| Name |
|---|
| None |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\TRBAL-G-ORG-TrendyolSellerMgmtIBChat Agent | Custom | No |
| Type | Name | Permission |
|---|---|---|
| Allow | NT AUTHORITY\SYSTEM | Full Control |
| Allow | BUILTIN\Administrators | Full Control |
| Allow | EMEA\Domain Users | Read |
| Allow | NT AUTHORITY\INTERACTIVE | Read |
| Type | Name | Access |
|---|---|---|
| Failure | Everyone | Full Control |
| Policy | Setting |
|---|---|
| Enforce rules of this type | True |
| Action | User | Name | Rule Type | Exceptions |
|---|---|---|---|---|
| Deny | EMEA\Domain Users | Packaged app: AppUp.IntelGraphicsExperience signed by INTEL CORP | Publisher | No |
| Deny | EMEA\Domain Users | Packaged app: Microsoft.Todos signed by Microsoft Corporation | Publisher | No |
| Deny | EMEA\Domain Users | Packaged app: Microsoft.OutlookForWindows signed by Microsoft Corporation | Publisher | No |
| Deny | EMEA\Domain Users | Packaged app: Microsoft.BingNews signed by Microsoft Corporation | Publisher | No |
| Deny | EMEA\Domain Users | Packaged app: WavesAudio.MaxxAudioProforDell2020 signed by Waves Audio | Publisher | No |
| Deny | EMEA\Domain Users | Packaged app: Microsoft.Copilot signed by Microsoft Corporation | Publisher | No |
| Deny | EMEA\Domain Users | Packaged app: Windows.PrintDialog signed by Microsoft Corporation | Publisher | No |
| Deny | EMEA\Domain Users | Packaged app: Clipchamp.Clipchamp signed by Microsoft Corp. | Publisher | No |
| Deny | EMEA\Domain Users | Packaged app: Microsoft.WidgetsPlatformRuntime signed by Microsoft Corporation | Publisher | No |
| Deny | EMEA\Domain Users | Packaged app: Microsoft.Windows.CapturePicker signed by Microsoft Corporation | Publisher | No |
| Deny | EMEA\Domain Users | Packaged app: Microsoft.GamingApp signed by Microsoft Corporation | Publisher | No |
| Deny | EMEA\Domain Users | Microsoft.XboxGameCallableUl, version 0.0.0.0 and above, from CN=MICROSOFT CORPORATION, O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Deny | EMEA\Domain Users | Packaged app: WavesAudio.WavesMaxxAudioProforDell signed by Waves Audio | Publisher | No |
| Deny | EMEA\Domain Users | Microsoft.WindowsStore, version 0.0.0.0 and above, from CN=MICROSOFT CORPORATION, O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Deny | EMEA\Domain Users | COM.TINYSPECK.SLACKDESKTOP, version 4.41.0.0 and above, from CN="SLACK TECHNOLOGIES, LLC", O="SLACK TECHNOLOGIES, LLC", L=SAN FRANCISCO, S=CALIFORNIA, C=US | Publisher | No |
| Deny | EMEA\Domain Users | Packaged app: Microsoft.Paint signed by Microsoft Corporation | Publisher | No |
| Allow | EMEA\Domain Computers | All signed packaged apps | Publisher | No |
| Deny | EMEA\Domain Users | Packaged app: AppUp.IntelOptaneMemoryandStorageManagement signed by INTEL CORP | Publisher | No |
| Deny | EMEA\Domain Users | Packaged app: Microsoft.WindowsTerminal signed by Microsoft Corporation | Publisher | No |
| Allow | EMEA\Domain Users | All signed packaged apps | Publisher | No |
| Deny | EMEA\Domain Users | Packaged app: Microsoft.BingSearch signed by Microsoft Corporation | Publisher | No |
| Deny | EMEA\Domain Users | Packaged app: Microsoft.PowerAutomateDesktop signed by Microsoft Corporation | Publisher | No |
| Deny | EMEA\Domain Users | Packaged app: Microsoft.OneDriveSync signed by CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US | Publisher | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{e88865ea-0e1c-4e20-9aa6-edcd0212c87c} |
| Value name | HiddenByDefault |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| File Explorer üzerinde Gallery özelliğini kaydetmek için yapıldı . Aynı zamanda kullanıcı Save As işlemi yaptığında Gallery bölümüne dosya kaydetmesini engellemek için yapıldı. |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum |
| Value name | {e88865ea-0e1c-4e20-9aa6-edcd0212c87c} |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| File Explorer üzerinde Gallery özelliğini kaydetmek için yapıldı . Aynı zamanda kullanıcı Save As işlemi yaptığında Gallery bölümüne dosya kaydetmesini engellemek için yapıldı. |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum |
| Value name | {e88865ea-0e1c-4e20-9aa6-edcd0212c87c} |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| File Explorer üzerinde Gallery özelliğini kaydetmek için yapıldı . Aynı zamanda kullanıcı Save As işlemi yaptığında Gallery bölümüne dosya kaydetmesini engellemek için yapıldı. |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{e88865ea-0e1c-4e20-9aa6-edcd0212c87c} |
| Value name | HiddenByDefault |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| File Explorer üzerinde Gallery özelliğini kaydetmek için yapıldı . Aynı zamanda kullanıcı Save As işlemi yaptığında Gallery bölümüne dosya kaydetmesini engellemek için yapıldı. |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum |
| Value name | {031E4825-7B94-4dc3-B131-E946B44C8DD5} |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| File Explorer üzerinde Library özelliğini kaydetmek için yapıldı . Aynı zamanda kullanıcı Save As işlemi yaptığında Library bölümüne dosya kaydetmesini engellemek için yapıldı. |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum |
| Value name | {031E4825-7B94-4dc3-B131-E946B44C8DD5} |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| File Explorer üzerinde Library özelliğini kaydetmek için yapıldı . Aynı zamanda kullanıcı Save As işlemi yaptığında Library bölümüne dosya kaydetmesini engellemek için yapıldı. |
| Enforcement | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Designated File Types | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Trusted Publishers | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
| Policy | Setting |
|---|---|
| Default Security Level | Unrestricted |
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% | ||||||
| ||||||
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% | ||||||
| ||||||
| %programfiles%\WindowsApps\Microsoft.WindowsStore* | ||||||
| ||||||
| %programfiles%\WindowsApps\MSTeams_* | ||||||
| ||||||
| %WINDIR%\HelpPane.exe | ||||||
| ||||||
| %windir%\system32\msinfo32.exe | ||||||
| ||||||
| %WINDIR%\winhlp32.exe | ||||||
| ||||||
| C:\Program Files (x86)\Windows Media Player\wmplayer.exe | ||||||
| ||||||
| C:\Program Files\Windows Media Player\wmplayer.exe | ||||||
|
| Policy | Setting | Comment | |||||||
|---|---|---|---|---|---|---|---|---|---|
| Hide specified Control Panel items | Enabled | ||||||||
| |||||||||
| Policy | Setting | Comment | |||||||
| Prohibit access to Control Panel and PC settings | Enabled | ||||||||
| Show only specified Control Panel items | Enabled | ||||||||
| |||||||||
| Policy | Setting | Comment |
|---|---|---|
| Prevent changing desktop background | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Hide Network Locations icon on desktop | Enabled | |
| Prevent adding, dragging, dropping and closing the Taskbar's toolbars | Enabled | |
| Prohibit User from manually redirecting Profile Folders | Enabled | |
| Remove Computer icon on the desktop | Enabled | |
| Remove My Documents icon on the desktop | Enabled | |
| Remove Properties from the Computer icon context menu | Enabled | |
| Remove Properties from the Documents icon context menu | Enabled | |
| Remove the Desktop Cleanup Wizard | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Always Open PDF files externally | Enabled | |
| Ask where to save each file before downloading | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow sites configured for Internet Explorer mode to open in Microsoft Edge | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Clear history of recently opened documents on exit | Enabled | |||
| Clear the recent programs list for new users | Enabled | |||
| Do not keep history of recently opened documents | Enabled | |||
| Do not search communications | Enabled | |||
| Do not search for files | Enabled | |||
| Do not search Internet | Enabled | |||
| Do not search programs and Control Panel items | Enabled | |||
| Hide the TaskView button | Enabled | |||
| Pin Apps to Start when installed | Disabled | |||
| Prevent users from customizing their Start Screen | Enabled | |||
| Prevent users from uninstalling applications from Start | Enabled | |||
| Remove "Recently added" list from Start Menu | Enabled | |||
| Remove All Programs list from the Start menu | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Remove Balloon Tips on Start Menu items | Enabled | |||
| Remove common program groups from Start Menu | Enabled | |||
| Remove Default Programs link from the Start menu. | Enabled | |||
| Remove Documents icon from Start Menu | Enabled | |||
| Remove Downloads link from Start Menu | Enabled | |||
| Remove Favorites menu from Start Menu | Enabled | |||
| Remove frequent programs list from the Start Menu | Enabled | |||
| Remove Games link from Start Menu | Enabled | |||
| Remove Help menu from Start Menu | Enabled | |||
| Remove Homegroup link from Start Menu | Enabled | |||
| Remove links and access to Windows Update | Enabled | |||
| Remove Music icon from Start Menu | Enabled | |||
| Remove Network Connections from Start Menu | Enabled | |||
| Remove Network icon from Start Menu | Enabled | |||
| Remove Notifications and Action Center | Enabled | |||
| Remove Personalized Website Recommendations from the Recommended section in the Start Menu | Enabled | |||
| Remove Pictures icon from Start Menu | Enabled | |||
| Remove pinned programs list from the Start Menu | Enabled | |||
| Remove programs on Settings menu | Enabled | |||
| Remove Recent Items menu from Start Menu | Enabled | |||
| Remove Recommended section from Start Menu | Enabled | |||
| Remove Recorded TV link from Start Menu | Enabled | |||
| Remove Run menu from Start Menu | Enabled | |||
| Remove Search Computer link | Enabled | |||
| Remove Search link from Start Menu | Enabled | |||
| Remove See More Results / Search Everywhere link | Enabled | |||
| Remove the "Undock PC" button from the Start Menu | Enabled | |||
| Remove the Meet Now icon | Enabled | |||
| Remove the People Bar from the taskbar | Enabled | |||
| Remove the Security and Maintenance icon | Enabled | |||
| Remove user folder link from Start Menu | Enabled | |||
| Remove user's folders from the Start Menu | Disabled | |||
| Remove Videos link from Start Menu | Enabled | |||
| Show or hide "Most used" list from Start menu | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Show QuickLaunch on Taskbar | Disabled | |||
| Show Windows Store apps on the taskbar | Disabled | |||
| Turn off feature advertisement balloon notifications | Enabled | |||
| Turn off personalized menus | Enabled | |||
| Policy | Setting | Comment | |||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Don't run specified Windows applications | Enabled | ||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||
| Policy | Setting | Comment | |||||||||||||||||||||||||||||
| Prevent access to registry editing tools | Enabled | ||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||
| Policy | Setting | Comment | |||||||||||||||||||||||||||||
| Prevent access to the command prompt | Enabled | ||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Remove Task Manager | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| All Removable Storage classes: Deny all access | Enabled | |
| Removable Disks: Deny read access | Enabled | |
| Removable Disks: Deny write access | Enabled | |
| WPD Devices: Deny read access | Enabled | |
| WPD Devices: Deny write access | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn off Autoplay | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Do not allow Folder Options to be opened from the Options button on the View tab of the ribbon | Enabled | |||
| Hide these specified drives in My Computer | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| No Computers Near Me in Network Locations | Enabled | |||
| No Entire Network in Network Locations | Enabled | |||
| Prevent access to drives from My Computer | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Remove CD Burning features | Enabled | |||
| Remove File Explorer's default context menu | Enabled | |||
| Remove Hardware tab | Enabled | |||
| Remove Search button from File Explorer | Enabled | |||
| Remove Shared Documents from My Computer | Enabled | |||
| Turn off display of recent search entries in the File Explorer search box | Disabled | |||
| Turn off Windows Key hotkeys | Enabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Disable the Connections page | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Empty Temporary Internet Files folder when browser is closed | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Restrict the user from entering author mode | Enabled | |
| Restrict users to the explicitly permitted list of snap-ins | Enabled |
| Policy | Setting | Comment | ||||||
|---|---|---|---|---|---|---|---|---|
| Allow persisting automatic acceptance of Calls | Enabled | |||||||
| Disable Chat | Enabled | |||||||
| Disable Directory services | Enabled | |||||||
| Disable NetMeeting 2.x Whiteboard | Enabled | |||||||
| Disable Whiteboard | Enabled | |||||||
| Limit the size of sent files | Enabled | |||||||
| ||||||||
| Policy | Setting | Comment | ||||||
| Prevent adding Directory servers | Enabled | |||||||
| Prevent automatic acceptance of Calls | Enabled | |||||||
| Prevent changing Call placement method | Enabled | |||||||
| Prevent receiving files | Enabled | |||||||
| Prevent sending files | Enabled | |||||||
| Prevent viewing Web directory | Enabled | |||||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off the Store application | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not allow Snipping Tool to run | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Windows Copilot | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Use Windows Hello for Business | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not allow Windows Media Center to run | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not allow Windows Messenger to be run | Enabled | |
| Do not automatically start Windows Messenger initially | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn on Script Execution | Disabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_USERS |
| Key path | %LogonUserSid%\Software\Microsoft\Windows\CurrentVersion\Policies\SnippingTool |
| Value name | AllowScreenRecorder |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_CURRENT_USER |
| Key path | Software\Microsoft\Windows\CurrentVersion\Policies\SnippingTool |
| Value name | AllowScreenRecorder |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_CURRENT_USER |
| Key path | Software\Microsoft\Windows\CurrentVersion\Search |
| Value name | SearchboxTaskbarMode |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |