| XKPRN-PO-WIN-U-Block Powershell and cmd | |
| Data collected on: 2-9-2025 09:58:19 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\bahtiri.5-adm |
| Created | 9-6-2021 09:18:26 |
| Modified | 7-6-2023 16:52:12 |
| User Revisions | 16 (AD), 16 (SYSVOL) |
| Computer Revisions | 0 (AD), 0 (SYSVOL) |
| Unique ID | {66cd2438-64e3-464b-a77b-8dc21d5eaf15} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| XK | No | Enabled | emea.tpg.ads/XK |
| Name |
|---|
| EMEA\XK-L-SEC-Block Powershell and CMD |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\bahtiri.5-adm | Edit settings, delete, modify security | No |
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\XK-L-SEC-Block Powershell and CMD | Read (from Security Filtering) | No |
| EMEA\XK-L-SEC-Delegation Modify Group Policy Settings Access | Edit settings, delete, modify security | No |
| EMEA\XK-L-SEC-Delegation Read Group Policy Results Data Access | Read | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Enforcement | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Designated File Types | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Trusted Publishers | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
| Policy | Setting |
|---|---|
| Default Security Level | Unrestricted |
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% | ||||||
| ||||||
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% | ||||||
| ||||||
| %SystemRoot%\system32\WindowsPowerShell\v1.0\powershell.exe | ||||||
| ||||||
| %SystemRoot%\syswow64\WindowsPowerShell\v1.0\powershell.exe | ||||||
| ||||||
| %windir%\system32\cmd* | ||||||
| ||||||
| %windir%\system32\WindowsPowerShell\v1.0\PowerShell_ISE.exe | ||||||
| ||||||
| %windir%\syswow64\WindowsPowerShell\v1.0\PowerShell_ISE.exe | ||||||
|