| XKPRN-PO-WIN-C-PCI_GESCP_Restrictions-All | |
| Data collected on: 2-9-2025 09:57:13 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\bahtiri.5-adm |
| Created | 7-5-2021 23:09:56 |
| Modified | 1-4-2025 11:34:38 |
| User Revisions | 2 (AD), 2 (SYSVOL) |
| Computer Revisions | 117 (AD), 117 (SYSVOL) |
| Unique ID | {262b20fc-3c75-4473-b206-ed462b4ad7e7} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| PRN | No | Enabled | emea.tpg.ads/XK/Systems/Clients/PRN |
| Name |
|---|
| EMEA\XK-L-SEC-Computer PCI Restrictions Test |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\bahtiri.5-adm | Edit settings, delete, modify security | No |
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\Domain Computers | Read | No |
| EMEA\XK-G-ORG-OU Admins | Edit settings, delete, modify security | No |
| EMEA\XK-L-SEC-Computer PCI Restrictions Test | Read (from Security Filtering) | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Policy | Setting |
|---|---|
| Audit account logon events | Success, Failure |
| Audit account management | Success, Failure |
| Audit directory service access | Success, Failure |
| Audit logon events | Success, Failure |
| Audit object access | Success, Failure |
| Audit policy change | Success, Failure |
| Audit privilege use | Success, Failure |
| Audit process tracking | Success, Failure |
| Audit system events | Success, Failure |
| Policy | Setting |
|---|---|
| Accounts: Administrator account status | Enabled |
| Accounts: Guest account status | Disabled |
| Accounts: Rename administrator account | "tpaxkadm" |
| Accounts: Rename guest account | "localguest" |
| Policy | Setting |
|---|---|
| Domain member: Maximum machine account password age | 60 days |
| Policy | Setting |
|---|---|
| Interactive logon: Do not require CTRL+ALT+DEL | Disabled |
| Interactive logon: Don't display last signed-in | Enabled |
| Interactive logon: Message text for users attempting to log on | This computer system is the property of Teleperformance., Use of this computer system is restricted to official Teleperformance business., Teleperformance reserves the right to monitor use of the computer system at any time., Use of this system constitutes consent to such monitoring., Any unauthorized access, use, or modification of the computer system can result in civil, liability and/or criminal penalties. |
| Interactive logon: Message title for users attempting to log on | "WARNING: IF YOU ARE NOT AUTHORIZED TO LOGON TO THIS PC,DON'T TRY TO LOGON!" |
| Interactive logon: Number of previous logons to cache (in case domain controller is not available) | 0 logons |
| Interactive logon: Prompt user to change password before expiration | 14 days |
| Interactive logon: Require Domain Controller authentication to unlock workstation | Enabled |
| Policy | Setting |
|---|---|
| Microsoft network client: Digitally sign communications (if server agrees) | Enabled |
| Microsoft network client: Send unencrypted password to third-party SMB servers | Disabled |
| Policy | Setting |
|---|---|
| Microsoft network server: Digitally sign communications (always) | Enabled |
| Microsoft network server: Digitally sign communications (if client agrees) | Enabled |
| Policy | Setting |
|---|---|
| Network access: Do not allow anonymous enumeration of SAM accounts and shares | Enabled |
| Policy | Setting |
|---|---|
| Network security: Do not store LAN Manager hash value on next password change | Enabled |
| Network security: LAN Manager authentication level | Send NTLMv2 response only. Refuse LM & NTLM |
| Policy | Setting |
|---|---|
| Shutdown: Clear virtual memory pagefile | Enabled |
| Policy | Setting |
|---|---|
| Interactive logon: Machine account lockout threshold | 5 invalid logon attempts |
| Interactive logon: Machine inactivity limit | 300 seconds |
| Policy | Setting |
|---|---|
| Policy version | 2.28 |
| Disable stateful FTP | Not Configured |
| Disable stateful PPTP | Not Configured |
| IPsec exempt | Not Configured |
| IPsec through NAT | Not Configured |
| Preshared key encoding | Not Configured |
| SA idle time | Not Configured |
| Strong CRL check | Not Configured |
| Policy | Setting |
|---|---|
| Firewall state | On |
| Inbound connections | Not Configured |
| Outbound connections | Not Configured |
| Apply local firewall rules | Not Configured |
| Apply local connection security rules | Not Configured |
| Display notifications | No |
| Allow unicast responses | Yes |
| Log dropped packets | Not Configured |
| Log successful connections | Not Configured |
| Log file path | Not Configured |
| Log file maximum size (KB) | Not Configured |
| Name | Description | ||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| IN Domain ANY ANY | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
| Name | Description | ||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| OUT Domain ANY ANY | |||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||
| Policy | Setting |
|---|---|
| Audit Credential Validation | Success, Failure |
| Audit Kerberos Authentication Service | Success, Failure |
| Audit Kerberos Service Ticket Operations | Success, Failure |
| Audit Other Account Logon Events | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Application Group Management | Success, Failure |
| Audit Computer Account Management | Success, Failure |
| Audit Distribution Group Management | Success, Failure |
| Audit Other Account Management Events | Success, Failure |
| Audit Security Group Management | Success, Failure |
| Audit User Account Management | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Process Creation | Success, Failure |
| Audit Process Termination | Success, Failure |
| Audit RPC Events | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Directory Service Access | Success, Failure |
| Audit Directory Service Changes | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Account Lockout | Success, Failure |
| Audit User / Device Claims | Success, Failure |
| Audit Logoff | Success, Failure |
| Audit Logon | Success, Failure |
| Audit Other Logon/Logoff Events | Success, Failure |
| Audit Special Logon | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Audit Policy Change | Success, Failure |
| Audit Authentication Policy Change | Success, Failure |
| Audit Authorization Policy Change | Success, Failure |
| Audit Other Policy Change Events | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Non Sensitive Privilege Use | Success, Failure |
| Audit Other Privilege Use Events | Success, Failure |
| Audit Sensitive Privilege Use | Success, Failure |
| Policy | Setting |
|---|---|
| Audit IPsec Driver | Success, Failure |
| Audit Other System Events | Success, Failure |
| Audit Security State Change | Success, Failure |
| Audit Security System Extension | Success, Failure |
| Audit System Integrity | Success, Failure |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| DNS suffix search list | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| IPv6 Configuration Policy | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Windows Defender Firewall: Allow ICMP exceptions | Enabled | |||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||||||||||||
| Windows Defender Firewall: Allow inbound file and printer sharing exception | Enabled | |||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||||||||||||
| Windows Defender Firewall: Allow inbound remote administration exception | Enabled | |||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||||||||||||
| Windows Defender Firewall: Allow inbound Remote Desktop exceptions | Enabled | |||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||||||||||||
| Windows Defender Firewall: Allow local program exceptions | Enabled | |||||||||||||||||||||||||||||
| Windows Defender Firewall: Prohibit notifications | Enabled | |||||||||||||||||||||||||||||
| Windows Defender Firewall: Prohibit unicast response to multicast or broadcast requests | Disabled | |||||||||||||||||||||||||||||
| Windows Defender Firewall: Protect all network connections | Enabled | |||||||||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Windows Defender Firewall: Allow ICMP exceptions | Enabled | |||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||||||||||||
| Windows Defender Firewall: Allow inbound file and printer sharing exception | Enabled | |||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||||||||||||
| Windows Defender Firewall: Allow inbound remote administration exception | Enabled | |||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||||||||||||
| Windows Defender Firewall: Allow inbound Remote Desktop exceptions | Enabled | |||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||||||||||||
| Windows Defender Firewall: Allow local program exceptions | Enabled | |||||||||||||||||||||||||||||
| Windows Defender Firewall: Prohibit notifications | Enabled | |||||||||||||||||||||||||||||
| Windows Defender Firewall: Prohibit unicast response to multicast or broadcast requests | Disabled | |||||||||||||||||||||||||||||
| Windows Defender Firewall: Protect all network connections | Enabled | |||||||||||||||||||||||||||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Allow or Disallow use of the Offline Files feature | Disabled | |||
| Prevent use of Offline Files folder | Enabled | |||
| Prohibit user configuration of Offline Files | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Remove "Make Available Offline" command | Enabled | |||
| Synchronize all offline files before logging off | Disabled | |||
| Synchronize all offline files when logging on | Disabled | |||
| Synchronize offline files before suspend | Disabled | |||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Configure user Group Policy loopback processing mode | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Always wait for the network at computer startup and logon | Enabled | |
| Hide entry points for Fast User Switching | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow Clipboard synchronization across devices | Disabled | |
| Allow publishing of User Activities | Disabled | |
| Allow upload of User Activities | Disabled | |
| Enables Activity Feed | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Delete user profiles older than a specified number of days on system restart | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Do not log users on with temporary profiles | Enabled | |||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn off Autoplay | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Restrict unpacking and installation of gadgets that are not digitally signed. | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Allow edge swipe | Disabled | |
| Disable help tips | Enabled |
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Require use of specific security layer for remote (RDP) connections | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Require user authentication for remote connections by using Network Level Authentication | Enabled | |||||
| Set client connection encryption level | Enabled | |||||
| ||||||
| Policy | Setting | Comment |
|---|---|---|
| Do Not Show First Use Dialog Boxes | Enabled | |
| Prevent Automatic Updates | Enabled | |
| Prevent Desktop Shortcut Creation | Enabled | |
| Prevent Media Sharing | Enabled | |
| Prevent Quick Launch Toolbar Shortcut Creation | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not allow Windows Messenger to be run | Enabled |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Control\Session Manager |
| Value name | CWDIllegalInDllSearch |
| Value type | REG_DWORD |
| Value data | 0x2 (2) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters |
| Value name | DisabledComponents |
| Value type | REG_DWORD |
| Value data | 0xFF (255) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Microsoft\.NETFramework\v2.0.50727 |
| Value name | SchUseStrongCrypto |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v2.0.50727 |
| Value name | SchUseStrongCrypto |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| User name | Administrator (built-in) |
| User must change password at next logon | False |
| User cannot change password | False |
| Password never expires | False |
| Account is disabled | False |
| Account expires | 5/18/2019 |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | Yes |