| UA-PO-SEC-C-Workstations common policy | |
| Data collected on: 2-9-2025 08:51:31 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\efimov.6 |
| Created | 9-9-2014 12:28:12 |
| Modified | 4-10-2024 13:36:58 |
| User Revisions | 1 (AD), 1 (SYSVOL) |
| Computer Revisions | 128 (AD), 128 (SYSVOL) |
| Unique ID | {34b593e0-0fe2-4d40-a0b1-3726712ae171} |
| GPO Status | User settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Clients | No | Enabled | emea.tpg.ads/UA/Systems/Clients |
| Name |
|---|
| NT AUTHORITY\Authenticated Users |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\efimov.6 | Edit settings, delete, modify security | No |
| EMEA\UA-L-SEC-Delegation Full Access | Edit settings, delete, modify security | No |
| EMEA\UA-L-SEC-Delegation Group Policy Objects Modify Access | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read (from Security Filtering) | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| S-1-5-21-513466819-3096973226-347852806-203252 | Read | No |
| Policy | Setting |
|---|---|
| Maximum security log size | 3145728 kilobytes |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Users | Read and Execute | This folder, subfolders and files |
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read and Execute | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Users | Read and Execute | This folder, subfolders and files |
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read and Execute | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Issued To | Issued By | Expiration Date | Intended Purposes |
|---|---|---|---|
| plwa2fwvip.emea.tpg.ads | plwa2fwvip.emea.tpg.ads | 31-3-2025 11:35:16 | <All> |
| Zscaler Root CA | Zscaler Root CA | 6-5-2042 02:27:55 | <All> |
| Issued To | Issued By | Expiration Date | Intended Purposes |
|---|---|---|---|
| plwa2fwvip.emea.tpg.ads | plwa2fwvip.emea.tpg.ads | 31-3-2025 11:35:16 | <All> |
| Policy | Setting |
|---|---|
| Policy version | Not Configured |
| Disable stateful FTP | Not Configured |
| Disable stateful PPTP | Not Configured |
| IPsec exempt | Not Configured |
| IPsec through NAT | Not Configured |
| Preshared key encoding | Not Configured |
| SA idle time | Not Configured |
| Strong CRL check | Not Configured |
| Policy | Setting |
|---|---|
| Firewall state | Off |
| Inbound connections | Not Configured |
| Outbound connections | Not Configured |
| Apply local firewall rules | Not Configured |
| Apply local connection security rules | Not Configured |
| Display notifications | Not Configured |
| Allow unicast responses | Not Configured |
| Log dropped packets | Not Configured |
| Log successful connections | Not Configured |
| Log file path | Not Configured |
| Log file maximum size (KB) | Not Configured |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Connection-specific DNS suffix | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Dynamic update | Enabled | |||
| Primary DNS suffix | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Register DNS records with connection-specific DNS suffix | Enabled | |||
| Register PTR records | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| IPv6 Configuration Policy | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Prohibit use of Internet Connection Firewall on your DNS domain network | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Windows Defender Firewall: Protect all network connections | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Windows Defender Firewall: Protect all network connections | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Configure Logon Script Delay | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Specify startup policy processing wait time | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Specify workplace connectivity wait time for policy processing | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Always wait for the network at computer startup and logon | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Wait for remote user profile | Enabled |
| Policy | Setting | Comment | ||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Let Windows apps access the calendar | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Disallow Autoplay for non-volume devices | Enabled | |||
| Set the default behavior for AutoRun | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn off Autoplay | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Require additional authentication at startup | Enabled | |||||||||||||||
| ||||||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Allow device name to be sent in Windows diagnostic data | Disabled | |
| Allow Diagnostic Data | Disabled | |
| Do not show feedback notifications | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow Cloud Search | Disabled | |
| Allow Cortana | Disabled | |
| Allow Cortana above lock screen | Disabled | |
| Allow Cortana Page in OOBE on an AAD account | Disabled | |
| Allow search and Cortana to use location | Disabled | |
| Do not allow web search | Enabled | |
| Don't search the web or display web results in Search | Enabled | |
| Don't search the web or display web results in Search over metered connections | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Configure App Install Control | Disabled | |
| Configure Windows Defender SmartScreen | Disabled |
| Action | Replace |
| Source file(s) | \\emea.tpg.ads\SYSVOL\emea.tpg.ads\Policies\{34B593E0-0FE2-4D40-A0B1-3726712AE171}\Machine\files\hosts |
| Destination file | %SystemRoot%\System32\drivers\etc\hosts |
| Suppress errors on individual file actions | Enabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Source file(s) | \\uachefs01.emea.tpg.ads\REMINST\Software\KeePass\*.* |
| Destination folder | c:\PortableApps\KeePass |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Attribute | Value | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| bool | AND | ||||||||||||
| not | 0 | ||||||||||||
Item-level targeting: File Match
| |||||||||||||
| Action | Replace |
| Source file(s) | \\uachefs01.emea.tpg.ads\REMINST\Software\KeePass\XSL\*.* |
| Destination folder | c:\PortableApps\KeePass\XSL |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Attribute | Value | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| bool | AND | ||||||||||||
| not | 0 | ||||||||||||
Item-level targeting: File Match
| |||||||||||||
| Action | Replace |
| Source file(s) | \\emea.tpg.ads\SYSVOL\emea.tpg.ads\Policies\{34B593E0-0FE2-4D40-A0B1-3726712AE171}\Machine\files\ua_remove_nrpt.reg |
| Destination file | c:\temp\ua_remove_nrpt.reg |
| Suppress errors on individual file actions | Enabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon |
| Value name | Shell |
| Value type | REG_SZ |
| Value data | explorer.exe |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Wow6432Node\Microsoft\Silverlight |
| Value name | AllowElevatedTrustAppsInBrowser |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Wow6432Node\Microsoft\Silverlight |
| Value name | AllowLaunchOfElevatedTrustApps |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Silverlight |
| Value name | AllowElevatedTrustAppsInBrowser |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Create |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Silverlight |
| Value name | AllowLaunchOfElevatedTrustApps |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon |
| Value name | GpNetworkStartTimeoutPolicyValue |
| Value type | REG_DWORD |
| Value data | 0x3C (60) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Attribute | Value |
|---|---|
| bool | AND |
| not | 0 |
| path | c:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe |
| type | EXISTS |
| folder | 0 |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Skype\Phone |
| Value name | DisableVersionCheck |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 128/128 |
| Value name | Enable |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 40/128 |
| Value name | Enable |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 56/128 |
| Value name | Enable |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Name | Restart McpService.exe | |||
| Author | EMEA\kornev.5-adm | |||
| Description | ||||
| Run only when user is logged on | ||||
| GroupId | NT AUTHORITY\System | |||
| Run with highest privileges | HighestAvailable | |||
| Hidden | No | |||
| Configure for | 1.2 | |||
| Enabled | Yes |
| 1. Run at user logon | ||||
| Delay task for | 1 minute | |||
| Activate | 13-10-2021 15:31:49 | Synchronize across time zones | No | |
| Enabled | Yes | |||
| 1. Start a program | ||||
| Program/script | taskkill.exe | |||
| Arguments | /IM McpService.exe /F |
| Stop if the computer ceases to be idle | No | |||
| Restart if the idle state resumes | No | |||
| Start the task only if the computer is on AC power | No | |||
| Stop if the computer switches to battery power | No | |||
| Allow task to be run on demand | Yes | |||
| Stop task if it runs longer than | 3 days | |||
| If the running task does not end when requested, force it to stop | Yes | |||
| If the task is already running, then the following rule applies | IgnoreNew |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |