| XK-PO-WIN-C-MFA Network Configurations | |
| Data collected on: 2-9-2025 09:50:49 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\likaj.7-adm |
| Created | 5-11-2020 09:59:22 |
| Modified | 9-2-2023 14:56:32 |
| User Revisions | 1 (AD), 1 (SYSVOL) |
| Computer Revisions | 7 (AD), 7 (SYSVOL) |
| Unique ID | {d9f1f2d1-df6d-4eb0-984c-f351c3c785aa} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| PRN | No | Enabled | emea.tpg.ads/XK/Systems/Clients/PRN |
| Name |
|---|
| EMEA\XK-L-SEC-Computer Configuration MFA |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\AL-G-ORG-OU Admins | Edit settings, delete, modify security | No |
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\Domain Computers | Read | No |
| EMEA\likaj.7-adm | Edit settings, delete, modify security | No |
| EMEA\XK-G-ORG-OU Admins | Edit settings, delete, modify security | No |
| EMEA\XK-L-SEC-Computer Configuration MFA | Read (from Security Filtering) | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Name | MIC MFA Configuration |
| Description | Enabl MFA auth on NIC |
| Setting | Value |
|---|---|
| Use Windows wired LAN network services for clients | Enabled |
| Shared user credentials for network authentication | Enabled |
| Enable use of IEEE 802.1X authentication for network access | Enabled |
| Enforce use of IEEE 802.1X authentication for network access | Disabled |
| Computer Authentication | User re-authentication |
| Maximum Authentication Failures | 1 |
| Maximum EAPOL-Start Messages Sent | |
| Held Period (seconds) | |
| Start Period (seconds) | |
| Authentication Period (seconds) |
| Authentication method | Protected EAP (PEAP) |
| Validate server certificate | Disabled |
| Enable fast reconnect | Enabled |
| Disconnect if server does not present cryptobinding TLV | Disabled |
| Enforce network access protection | Disabled |
| Authentication method | Secured password (EAP-MSCHAP v2) |
| Automatically use my Windows logon name and password(and domain if any) | Enabled |
| Service name | dot3svc |
| Action | Start service |
| Startup type: | Automatic |
| Wait timeout if service is locked: | 30 seconds |
| Log on service as: | No change |
| First failure: | Restart the service |
| Second failure: | Restart the service |
| Subsequent failures: | No change |
| Reset fail count after: | 0 days |
| Restart service after: | 1 minute |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |