| AEC01_ClientPolicy_ND_1.1 | |
| Data collected on: 26/05/2015 14:40:26 | |
| Domain | aecuk.aec.local |
| Owner | AECUK\Domain Admins |
| Created | 27/06/2013 10:11:54 |
| Modified | 27/06/2013 11:09:34 |
| User Revisions | 1 (AD), 1 (sysvol) |
| Computer Revisions | 1 (AD), 1 (sysvol) |
| Unique ID | {6E12F441-9E1F-4F87-92D9-F913FD11A5B7} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| AECTEST | No | Disabled | aecuk.aec.local/AECTEST |
| Name |
|---|
| NT AUTHORITY\Authenticated Users |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| AEC\Enterprise Admins | Edit settings, delete, modify security | No |
| AECUK\Domain Admins | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read (from Security Filtering) | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | CREATOR OWNER | Full control | Subkeys only |
| Allow | NT AUTHORITY\SYSTEM | Full control | This key and subkeys |
| Allow | BUILTIN\Administrators | Full control | This key and subkeys |
| Allow | AECUK\Domain Users | Full control | This key and subkeys |
| Allow | BUILTIN\Users | Read | This key and subkeys |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Policy | Setting |
|---|---|
| Policy version | Not Configured |
| Disable stateful FTP | Not Configured |
| Disable stateful PPTP | Not Configured |
| IPsec exempt | Not Configured |
| IPsec through NAT | Not Configured |
| Preshared key encoding | Not Configured |
| SA idle time | Not Configured |
| Strong CRL check | Not Configured |
| Policy | Setting |
|---|---|
| Firewall state | Off |
| Inbound connections | Not Configured |
| Outbound connections | Not Configured |
| Apply local firewall rules | Not Configured |
| Apply local connection security rules | Not Configured |
| Display notifications | Not Configured |
| Allow unicast responses | Not Configured |
| Log dropped packets | Not Configured |
| Log successful connections | Not Configured |
| Log file path | Not Configured |
| Log file maximum size (KB) | Not Configured |
| Policy | Setting | Comment |
|---|---|---|
| Windows Firewall: Protect all network connections | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Windows Firewall: Protect all network connections | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off background refresh of Group Policy | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Don't display the Getting Started welcome screen at logon | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Run logon scripts synchronously | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Add the Administrators security group to roaming user profiles | Enabled | |
| Do not check for user ownership of Roaming Profile Folders | Enabled | |
| Prompt user when a slow network connection is detected | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Java permissions | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Always install with elevated privileges | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Enable user to browse for source while elevated | Enabled | |||||
| Enable user to patch elevated products | Enabled | |||||
| Enable proxy settings | ||||||||||||||||||||
| ||||||||||||||||||||
| Exceptions: | Do not use proxy server for addresses beginning with | aecrev2.proxy, *.local, *.root.local, *.adphc.com, 126.14.40.85, Hrpsoft.goodrich.com, *.ecs.goodrich.com, 149.223.*, 168.204.*, talentstream.goodrich.com, onesite.goodrich.com, 10.102.95.*, 10.201.*, 10.204.*, travel.goodrich.com, exports.goodrich.com, km.goodrich.com, recordsmanagement.goodrich.com, hrpsoftnew.goodrich.com, *.itss.goodrich.com, 1.1.1.1, | ||||||||||||||||||
| Do not use proxy server for local (intranet) addresses | Enabled | |||||||||||||||||||
| |||||||||
| Policy | Setting |
|---|---|
| Place favorites and links at the top of the list in the order specified below | Not configured |
| Delete existing Favorites and Links, if present | Not configured |
| Delete existing channels, if present | Not configured |
| Favorites | ||||||||
| ||||||||
| Links | ||||||||
|
| Run components not signed with Authenticode | Enable |
| Run components signed with Authenticode | Enable |
| Download signed ActiveX controls | Prompt |
| Download unsigned ActiveX controls | Disable |
| Initialize and script ActiveX controls not marked as safe | Disable |
| Run ActiveX controls and plug-ins | Enable |
| Script ActiveX controls marked safe for scripting | Enable |
| File download | Enable |
| Font download | Enable |
| Java permissions | High safety |
| Access data sources across domains | Disable |
| Allow META REFRESH | Enable |
| Display mixed content | Prompt |
| Don't prompt for client certificate selection when no certificates or only one certificate exists | Disable |
| Drag and drop or copy and paste files | Enable |
| Installation of desktop items | Prompt |
| Launching programs and files in an IFRAME | Prompt |
| Navigate sub-frames across different domains | Disable |
| Submit nonencrypted form data | Enable |
| Userdata persistence | Enable |
| Active scripting | Enable |
| Allow paste operations via script | Prompt |
| Scripting of Java applets | Enable |
| Logon | Automatic logon only in Intranet zone |
| Run components not signed with Authenticode | Enable |
| Run components signed with Authenticode | Enable |
| Run ActiveX controls and plug-ins | Enable |
| Active scripting | Enable |
| Require server verification (https:) for all sites in this zone | Disabled |
| Include all local (intranet) sites not listed in other zones | Disabled |
| Include all sites that bypass the proxy server | Disabled |
| Include all network paths (UNCs) | Disabled |
| Sites in this zone |
|---|
| None |
| Run components not signed with Authenticode | Enable |
| Run components signed with Authenticode | Enable |
| Download signed ActiveX controls | Prompt |
| Download unsigned ActiveX controls | Prompt |
| Initialize and script ActiveX controls not marked as safe | Prompt |
| Run ActiveX controls and plug-ins | Enable |
| Script ActiveX controls marked safe for scripting | Enable |
| File download | Enable |
| Font download | Enable |
| Java permissions | High safety |
| Access data sources across domains | Enable |
| Allow META REFRESH | Enable |
| Display mixed content | Prompt |
| Don't prompt for client certificate selection when no certificates or only one certificate exists | Enable |
| Drag and drop or copy and paste files | Enable |
| Installation of desktop items | Enable |
| Launching applications and unsafe files | Enable |
| Launching programs and files in an IFRAME | Enable |
| Navigate sub-frames across different domains | Enable |
| Submit nonencrypted form data | Enable |
| Userdata persistence | Enable |
| Active scripting | Enable |
| Allow paste operations via script | Prompt |
| Scripting of Java applets | Enable |
| Logon | Automatic logon with current username and password |
| Require server verification (https:) for all sites in this zone | Enabled |
| Sites in this zone |
|---|
| None |
| Run components not signed with Authenticode | Disable |
| Run components signed with Authenticode | Disable |
| Run ActiveX controls and plug-ins | Disable |
| Java permissions | Disable Java |
| Active scripting | Disable |
| Sites in this zone |
|---|
| None |
| Privacy Level | Medium | ||||
| Web Sites | |||||
| |||||
| Policy | Setting | Comment | ||||||
|---|---|---|---|---|---|---|---|---|
| Enable screen saver | Enabled | |||||||
| Password protect the screen saver | Enabled | |||||||
| Prevent changing screen saver | Enabled | |||||||
| Screen saver timeout | Enabled | |||||||
| ||||||||
| Policy | Setting | Comment |
|---|---|---|
| Run logon scripts synchronously | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Empty Temporary Internet Files folder when browser is closed | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Java permissions | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| No Computers Near Me in Network Locations | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Hide the dropdown list of recent files | Disabled |