| XK-PO-WIN-C-Local Policy Audit | |
| Data collected on: 2-9-2025 10:07:13 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\bahtiri.5-adm |
| Created | 2-12-2021 12:33:06 |
| Modified | 29-5-2025 15:08:02 |
| User Revisions | 2 (AD), 2 (SYSVOL) |
| Computer Revisions | 227 (AD), 227 (SYSVOL) |
| Unique ID | {05da31f1-6a36-444d-b1b9-637ff116abe6} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| PRN | No | Enabled | emea.tpg.ads/XK/Systems/Clients/PRN |
| Name |
|---|
| EMEA\XKPRN-G-ORG-Computers |
| EMEA\XKPRN-G-ORG-Computers ADAC |
| EMEA\XKPRN-G-ORG-Computers ARD ZDF |
| EMEA\XKPRN-G-ORG-Computers BAT |
| EMEA\XKPRN-G-ORG-Computers BP Castrol |
| EMEA\XKPRN-G-ORG-Computers Douglas |
| EMEA\XKPRN-G-ORG-Computers GoDaddy |
| EMEA\XKPRN-G-ORG-Computers HDPLUS |
| EMEA\XKPRN-G-ORG-Computers Hewlett Packard |
| EMEA\XKPRN-G-ORG-Computers IKANO |
| EMEA\XKPRN-G-ORG-Computers Kaizen |
| EMEA\XKPRN-G-ORG-Computers Lidl |
| EMEA\XKPRN-G-ORG-Computers LLS |
| EMEA\XKPRN-G-ORG-Computers Lufthansa AG |
| EMEA\XKPRN-G-ORG-Computers Lufthansa GenRes |
| EMEA\XKPRN-G-ORG-Computers PayPal |
| EMEA\XKPRN-G-ORG-Computers Sky |
| EMEA\XKPRN-G-ORG-Computers Sunrise |
| EMEA\XKPRN-G-ORG-Computers Tchibo |
| EMEA\XKPRN-G-ORG-Computers Telefonica |
| EMEA\XKPRN-G-ORG-Computers UPS |
| EMEA\XKPRN-G-ORG-Computers Vatenfall |
| EMEA\XKPRN-G-ORG-DAZN-Computers DAZN |
| EMEA\XKPRN-L-SEC-Computer Configuration OTTO |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\bahtiri.5-adm | Edit settings, delete, modify security | No |
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\Domain Computers | Read | No |
| EMEA\XK-G-ORG-OU Admins | Edit settings, delete, modify security | No |
| EMEA\XKPRN-G-ORG-Computers | Read (from Security Filtering) | No |
| EMEA\XKPRN-G-ORG-Computers ADAC | Read (from Security Filtering) | No |
| EMEA\XKPRN-G-ORG-Computers ARD ZDF | Read (from Security Filtering) | No |
| EMEA\XKPRN-G-ORG-Computers BAT | Read (from Security Filtering) | No |
| EMEA\XKPRN-G-ORG-Computers BP Castrol | Read (from Security Filtering) | No |
| EMEA\XKPRN-G-ORG-Computers Douglas | Read (from Security Filtering) | No |
| EMEA\XKPRN-G-ORG-Computers GoDaddy | Read (from Security Filtering) | No |
| EMEA\XKPRN-G-ORG-Computers HDPLUS | Read (from Security Filtering) | No |
| EMEA\XKPRN-G-ORG-Computers Hewlett Packard | Read (from Security Filtering) | No |
| EMEA\XKPRN-G-ORG-Computers IKANO | Read (from Security Filtering) | No |
| EMEA\XKPRN-G-ORG-Computers Kaizen | Read (from Security Filtering) | No |
| EMEA\XKPRN-G-ORG-Computers Lidl | Read (from Security Filtering) | No |
| EMEA\XKPRN-G-ORG-Computers LLS | Read (from Security Filtering) | No |
| EMEA\XKPRN-G-ORG-Computers Lufthansa AG | Read (from Security Filtering) | No |
| EMEA\XKPRN-G-ORG-Computers Lufthansa GenRes | Read (from Security Filtering) | No |
| EMEA\XKPRN-G-ORG-Computers PayPal | Read (from Security Filtering) | No |
| EMEA\XKPRN-G-ORG-Computers Sky | Read (from Security Filtering) | No |
| EMEA\XKPRN-G-ORG-Computers Sunrise | Read (from Security Filtering) | No |
| EMEA\XKPRN-G-ORG-Computers Tchibo | Read (from Security Filtering) | No |
| EMEA\XKPRN-G-ORG-Computers Telefonica | Read (from Security Filtering) | No |
| EMEA\XKPRN-G-ORG-Computers UPS | Read (from Security Filtering) | No |
| EMEA\XKPRN-G-ORG-Computers Vatenfall | Read (from Security Filtering) | No |
| EMEA\XKPRN-G-ORG-DAZN-Computers DAZN | Read (from Security Filtering) | No |
| EMEA\XKPRN-L-SEC-Computer Configuration OTTO | Read (from Security Filtering) | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Name | Parameters |
|---|---|
| ClearEventLog.bat |
| Name | Parameters |
|---|---|
| ClearEventLog.bat |
| Policy | Setting |
|---|---|
| Audit account logon events | Success, Failure |
| Audit account management | Success, Failure |
| Audit directory service access | Success, Failure |
| Audit logon events | Success, Failure |
| Audit object access | Success, Failure |
| Audit policy change | Success, Failure |
| Audit privilege use | Success, Failure |
| Audit process tracking | Success, Failure |
| Audit system events | Success, Failure |
| Policy | Setting |
|---|---|
| Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings | Enabled |
| Policy | Setting |
|---|---|
| Maximum application log size | 1048576 kilobytes |
| Maximum security log size | 1048576 kilobytes |
| Maximum system log size | 1048576 kilobytes |
| Retain application log | 90 days |
| Retain security log | 90 days |
| Retain system log | 90 days |
| Retention method for application log | By days |
| Retention method for security log | By days |
| Retention method for system log | By days |
| Policy | Setting |
|---|---|
| Audit Credential Validation | Success, Failure |
| Audit Kerberos Authentication Service | Success, Failure |
| Audit Kerberos Service Ticket Operations | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Computer Account Management | Success, Failure |
| Audit Security Group Management | Success, Failure |
| Audit User Account Management | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Process Creation | Success, Failure |
| Audit Process Termination | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Directory Service Access | Success, Failure |
| Audit Directory Service Changes | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Account Lockout | Success |
| Audit Logoff | Success |
| Audit Logon | Success, Failure |
| Audit Special Logon | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Audit Policy Change | Success, Failure |
| Audit Authentication Policy Change | Success, Failure |
| Policy | Setting |
|---|---|
| Audit IPsec Driver | Success, Failure |
| Audit Security State Change | Success, Failure |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolsv.exe |
| Value name | Debbuger |
| Value type | REG_SZ |
| Value data | "c:\windows\system32\systray.exe" /z |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolsv.exe |
| Value name | Debbuger |
| Value type | REG_SZ |
| Value data | "c:\windows\system32\systray.exe" /z |
| Stop processing items on this extension if an error occurs on this item | No |
| Run in logged-on user's security context (user policy option) | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |