A | B | C | D | |
---|---|---|---|---|
1 | Policy Path | Policy Name | Windows Server 2016/2019 | Windows 10/Workstation |
2 | Welcome to my template for Windows GPOs. Please get familiar with the Group Policy Editor and AD, also know what you are editing before you use this list. If you are looking for GPOs that are under Computer Configuration/Windows Settings/Security Settings/ look at the LGPO chart because they are the same. Though if you are working with an AD I still suggest you check the other stuff under that path as well. This spreadsheet is split up into tabs. This sheet houses the main Computer Configuration ones, another holds GPOs for IE and Edge (there are lots and idk if they will give you points .. ugh what a pain) and then one will be for User Configuration. If there is a (maybe) consider your senario and/or the affect on your ability and ease to administrate the system. You should do with with all GPOs though. Notes: - Always consider your senario. There could be some gpos that you need to configure that are not here. For example your senario could say that the users should not be able to configure the desktop background. That can be found in User Configuration/Administrative Templates/Control Panel/Personalization. - If you are locked out of something it is most likely a GPO (or multiple that are stopping you) there has been only a few times I had to go into registry. Though more often than not you want to change the GPO so it doesnt revert on restart. - If you are working in an Active Directory make a new policy file for each GPO you change (with some common sense though). Make sure to enable and enforce the new policy (left click on it) and either restart (suggested) or run gpupdate /force - Might be worth it to check out User Configuration\Administrative Templates\Windows Components\Microsoft User Experience Virtualization\Applications if you need to disable microsoft applications like Microsoft Office *** Important Note: Account Lockout and Password Policy (if you are working with an AD) make sure to apply them across the domain if you are working with an AD *** *** Important Note 2: For policy changes to take effect LGPO or GPO restart (suggested) or run gpupdate /force in cmd *** | |||
3 | ||||
4 | Administrative Templates | |||
5 | Control Panel | Allow Online Tips | Disabled (privacy) | Disabled (privacy) |
6 | Control Panel/Personalization | Prevent enabling lock screen camera | Enabled | Enabled |
7 | Control Panel/Personalization | Prevent enabling lock screen slide show | Enabled | Enabled |
8 | Control Panel/Regional and Language Options | Allow users to enable online speech recognition services | Disabled | Disabled (maybe) |
9 | Control Panel/Regional and Language Options | Allow Input Personalization | Disabled | |
10 | Network/DNS Client | Turn off multicast name resolution | Enabled | Enabled |
11 | Network/Fonts | Enable Font Providers | Disabled | |
12 | Network/Lanman Workstation | Enable insecure guest logons | Disabled | Disabled |
13 | Network/Link-Layer Topology Discovery | Turn on Mapper I/O (LLTDIO) driver | Disabled | |
14 | Network/Link-Layer Topology Discovery | Turn on Responder (RSPNDR) driver | Disabled | |
15 | Network/Microsoft Peer-to-Peer Networking Services | Turn off Microsoft Peer-to-Peer Networking Services | Enabled | Enabled |
16 | Network/Network Connections | Prohibit installation and configuration of Network Bridge on your DNS domain network | Enabled (maybe, not really needed for comp imo) | |
17 | Network/Network Connections | Prohibit use of Internet Connection Sharing on your DNS domain network | Enabled | Enabled |
18 | Network/Network Connections | Require domain users to elevate when setting a network's location | Enabled | |
19 | Network/Network Provider | Hardened UNC Paths | \\*\SYSVOL = RequireMutualAuthentication=1,RequireIntegrity=1 \\*\NETLOGON = RequireMutualAuthentication=1,RequireIntegrity=1 | \\*\SYSVOL = RequireMutualAuthentication=1,RequireIntegrity=1 \\*\NETLOGON = RequireMutualAuthentication=1,RequireIntegrity=1 |
20 | Network/Windows Connect Now | Configuration of wireless settings using Windows Connect Now | Disabled | |
21 | Network/Windows Connect Now | Prohibit access of the Windows Connect Now wizards | Enabled | |
22 | Network/Windows Connection Manager | Minimize the number of simultaneous connections to the Internet or a Windows Domain | Enabled | |
23 | Network/Windows Connection Manager | Prohibit connection to non-domain networks when connected to domain authenticated network | Enabled | |
24 | Network/WLAN Service/WLAN Settings | Allow Windows to automatically connect to suggested open hotspots, to networks shared by contacts, and to hotspots offering paid services | Disabled | |
25 | Start Menu and Taskbar | Turn off notifications network usage | Enabled | Enabled |
26 | System | Display Shutdown Event Tracker | Enabled | Enabled (big maybe) |
27 | System/Audit Process Creation | Include command line in process creation events | Disabled | |
28 | System/Credentials Delegation | Encryption Oracle Remediation | Force Updated Clients | Force Updated Clients |
29 | System/Credentials Delegation | Remote host allows delegation of non-exportable credentials | Enabled | Enabled |
30 | System/Credentials Delegation | Restrict delegation of credentials to remote servers | Prefer remote credential guard | Prefer remote credential guard |
31 | System/Device Guard | Turn On Virtualization Based Security | Enabled Virtualization Based Protection of Code Integrity = Enabled with UEFI lock Credential Guard Configuration = Disabled Select Platform Security Level = Secure Boot Secure Launch Configuration = Enabled Require UEFI Memory Attributes Table = False | Enabled Virtualization Based Protection of Code Integrity = Enabled with UEFI lock Credential Guard Configuration = Disabled Select Platform Security Level = Secure Boot Secure Launch Configuration = Enabled Require UEFI Memory Attributes Table = False |
32 | System/Device Installation/Device Installation Restrictions | Prevent installation of devices that match any of these device IDs | Enabled Also apply to matching devices that are already installed = True 1 = PCI\CC_0C0A | |
33 | System/Device Installation/Device Installation Restrictions | Prevent installation of devices using drivers that match these device setup classes | Enabled Also apply to matching devices that are already installed = True 1 = {d48179be-ec20-11d1-b6b8-00c04fa372a7} | |
34 | System/Early Launch Antimalware | Boot-Start Driver Initialization Policy | Good, unknown and bad but critical | Good, unknown and bad but critical |
35 | System/Group Policy | Configure registry policy processing | Process even if the Group Policy objects have not changed = True Do not apply during periodic background processing = False | Process even if the Group Policy objects have not changed = True Do not apply during periodic background processing = False |
36 | System/Group Policy | Continue experiences on this device | Disabled | Disabled |
37 | System/Group Policy | Turn off background refresh of Group Policy | Disabled (if you dont want to have to restart gps) | Disabled (if you dont want to have to restart gps) |
38 | System/Internet Communication Management/Internet Communication settings | Turn off access to the Store | Enabled | Enabled (maybe) |
39 | System/Internet Communication Management/Internet Communication settings | Turn off downloading of print drivers over HTTP | Enabled | Enabled |
40 | System/Internet Communication Management/Internet Communication settings | Turn off handwriting personalization data sharing | Enabled | Enabled |
41 | System/Internet Communication Management/Internet Communication settings | Turn off handwriting recognition error reporting | Enabled | Enabled |
42 | System/Internet Communication Management/Internet Communication settings | Turn off Internet Connection Wizard if URL connection is referring to Microsoft.com | Enabled | Enabled |
43 | System/Internet Communication Management/Internet Communication settings | Turn off Internet download for Web publishing and online ordering wizards | Enabled | Enabled |
44 | System/Internet Communication Management/Internet Communication settings | Turn off printing over HTTP | Enabled | Enabled |
45 | System/Internet Communication Management/Internet Communication settings | Turn off Registration if URL connection is referring to Microsoft.com | Enabled | Enabled |
46 | System/Internet Communication Management/Internet Communication settings | Turn off Search Companion content file updates | Enabled (low risk) | Enabled (low risk) |
47 | System/Internet Communication Management/Internet Communication settings | Turn off the "Order Prints" picture task | Enabled | Enabled |
48 | System/Internet Communication Management/Internet Communication settings | Turn off the "Publish to Web" task for files and folders | Enabled | Enabled |
49 | System/Internet Communication Management/Internet Communication settings | Turn off the Windows Messenger Customer Experience Improvement Program | Enabled (more privacy) | Enabled (more privacy) |
50 | System/Internet Communication Management/Internet Communication settings | Turn off Windows Error Reporting | Enabled (more privacy) | Enabled (more privacy) |
51 | System/Kerberos | Support device authentication using certificate | Automatic (if you have a DC) | Automatic (if you have a DC) |
52 | System/Kernel DMA Protection | Enumeration policy for external devices incompatible with Kernel DMA Protection | Block all | Block all |
53 | System/Locale Services | Disallow copying of user input methods to the system account for sign-in | Enabled (do not suggest for comp) | Enabled (do not suggest for comp) |
54 | System/Logon | Block user from showing account details on sign-in | Enabled | Enabled |
55 | System/Logon | Do not display network selection UI | Enabled | Enabled |
56 | System/Logon | Do not enumerate connected users on domain-joined computers | Enabled | Enabled |
57 | System/Logon | Enumerate local users on domain-joined computers | Disabled | Disabled |
58 | System/Logon | Turn off app notifications on the lock screen | Enabled | Enabled |
59 | System/Logon | Turn on convenience PIN sign-in | Disabled | Disabled |
60 | System/Mitigation Options | Untrusted Font Blocking | Block untrusted fonts and log events | Block untrusted fonts and log events |
61 | System/Power Management/Sleep Settings | Allow network connectivity during connected-standby (on battery) | Disabled | Disabled |
62 | System/Power Management/Sleep Settings | Allow network connectivity during connected-standby (plugged in) | Disabled | Disabled |
63 | System/Power Management/Sleep Settings | Allow standby states (S1-S3) when sleeping (on battery) | Disabled | |
64 | System/Power Management/Sleep Settings | Allow standby states (S1-S3) when sleeping (plugged in) | Disabled | |
65 | System/Power Management/Sleep Settings | Require a password when a computer wakes (on battery) | Enabled | Enabled |
66 | System/Power Management/Sleep Settings | Require a password when a computer wakes (plugged in) | Enabled | Enabled |
67 | System/Remote Assistance | Configure Offer Remote Assistance | Disabled | Disabled |
68 | System/Remote Assistance | Configure Solicited Remote Assistance | Disabled Maximum ticket time (value) = [[[delete]]] Maximum ticket time (units) = [[[delete]]] Method for sending email invitations = [[[delete]]] Permit remote control of this computer = [[[delete]]] | Disabled Maximum ticket time (value) = [[[delete]]] Maximum ticket time (units) = [[[delete]]] Method for sending email invitations = [[[delete]]] Permit remote control of this computer = [[[delete]]] |
69 | System/Remote Procedure Call | Enable RPC Endpoint Mapper Client Authentication | Enabled [no DC] (maybe) | Enabled (maybe) |
70 | System/Remote Procedure Call | Restrict Unauthenticated RPC clients | Authenticated [*** NO DC ***] | Authenticated |
71 | System/Removable Storage Access | All Removable Storage classes: Deny all access | Enabled | Enabled |
72 | System/Troubleshooting and Diagnostics/Microsoft Support Diagnostic Tool | Microsoft Support Diagnostic Tool: Turn on MSDT interactive communication with support provider | Disabled (privacy) | Disabled (privacy) |
73 | System/Troubleshooting and Diagnostics/Windows Performance PerfTrack | Enable/Disable PerfTrack | Disabled (privacy) | Disabled (privacy) |
74 | System/User Profiles | Turn off the advertising ID | Enabled (privacy) | Enabled (privacy) |
75 | System/Windows Time Service/Time Providers | Enable Windows NTP Client | Enabled | Enabled |
76 | System/Windows Time Service/Time Providers | Enable Windows NTP Server | Disabled [no DC] | Disabled |
77 | Windows Components/App Package Deployment | Allow a Windows app to share application data between users | Disabled | Disabled |
78 | Windows Components/App Privacy | Let Windows apps access account information | Force Deny (privacy & maybe) | Force Deny (privacy & maybe) |
79 | Windows Components/App Privacy | Let Windows apps access call history | Force Deny (privacy & maybe) | Force Deny (privacy & maybe) |
80 | Windows Components/App Privacy | Let Windows apps access contacts | Force Deny (privacy & maybe) | Force Deny (privacy & maybe) |
81 | Windows Components/App Privacy | Let Windows apps access email | Force Deny (privacy & maybe) | Force Deny (privacy & maybe) |
82 | Windows Components/App Privacy | Let Windows apps access location | Force Deny (privacy & maybe) | Force Deny (privacy & maybe) |
83 | Windows Components/App Privacy | Let Windows apps access messaging | Force Deny (privacy & maybe) | Force Deny (privacy & maybe) |
84 | Windows Components/App Privacy | Let Windows apps access motion | Force Deny (privacy & maybe) | Force Deny (privacy & maybe) |
85 | Windows Components/App Privacy | Let Windows apps access the calendar | Force Deny (privacy & maybe) | Force Deny (privacy & maybe) |
86 | Windows Components/App Privacy | Let Windows apps access the camera | Force Deny (privacy & maybe) | Force Deny (privacy & maybe) |
87 | Windows Components/App Privacy | Let Windows apps access the microphone | Force Deny (privacy & maybe) | Force Deny (privacy & maybe) |
88 | Windows Components/App Privacy | Let Windows apps access trusted devices | Force Deny (privacy & maybe) | Force Deny (privacy & maybe) |
89 | Windows Components/App Privacy | Let Windows apps control radios | Force Deny (privacy & maybe) | Force Deny (privacy & maybe) |
90 | Windows Components/App Privacy | Let Windows apps sync with devices | Force Deny (privacy & maybe) | Force Deny (privacy & maybe) |
91 | Windows Components/App Privacy | Let Windows apps make phone calls | Force Deny (privacy & maybe) | Force Deny (privacy & maybe) |
92 | Windows Components/App Privacy | Let Windows apps access notifications | Force Deny (privacy & maybe) | Force Deny (privacy & maybe) |
93 | Windows Components/App Privacy | Let Windows apps activate with voice while the system is locked | Force Deny | Force Deny |
94 | Windows Components/App runtime | Allow Microsoft accounts to be optional | Enabled (maybe) | Enabled (maybe) |
95 | Windows Components/App runtime | Block launching Windows Store apps with Windows Runtime API access from hosted content | Enabled | Enabled |
96 | Windows Components/Application Compatibility | Turn off Inventory Collector | Enabled (privacy) | Enabled (privacy) |
97 | Windows Components/AutoPlay Policies | Disallow Autoplay for non-volume devices | Enabled (maybe) | Enabled (maybe) |
98 | Windows Components/AutoPlay Policies | Set the default behavior for AutoRun | Do not execute any autorun commands | Do not execute any autorun commands |
99 | Windows Components/AutoPlay Policies | Turn off Autoplay | All drives | All drives |
100 | Windows Components/Biometrics/Facial Features | Configure enhanced anti-spoofing | Enabled | Enabled |
101 | Windows Components/BitLocker Drive Encryption | Disable new DMA devices when this computer is locked | Enabled | |
102 | Windows Components/BitLocker Drive Encryption/Operating System Drives | Allow enhanced PINs for startup | Enabled | |
103 | Windows Components/BitLocker Drive Encryption/Removable Data Drives | Deny write access to removable drives not protected by BitLocker | Enabled Do not allow write access to devices configured in another organization = False | |
104 | Windows Components/Camera | Allow Use of Camera | Disabled | Disabled (maybe) |
105 | Windows Components/Cloud Content | Turn off Microsoft consumer experiences | Enabled | Enabled |
106 | Windows Components/Connect | Require pin for pairing | Enabled | Enabled |
107 | Windows Components/Credential User Interface | Do not display the password reveal button | Enabled (very low risk) | Enabled (very low risk) |
108 | Windows Components/Credential User Interface | Enumerate administrator accounts on elevation | Disabled | Disabled |
109 | Windows Components/Data Collection and Preview Builds | Allow Telemetry | 0 -Security [Enterprise Only] or 1 - Basic (if cant) | 0 -Security [Enterprise Only] or 1 - Basic (if cant) |
110 | Windows Components/Data Collection and Preview Builds | Disable pre-release features or settings | Disabled | Disabled |
111 | Windows Components/Data Collection and Preview Builds | Do not show feedback notifications | Enabled | Enabled |
112 | Windows Components/Data Collection and Preview Builds | Toggle user control over Insider builds | Disabled (maybe) | Disabled (maybe) |
113 | Windows Components/Event Log Service/Application | Control Event Log behavior when the log file reaches its maximum size | Disabled | Disabled |
114 | Windows Components/Event Log Service/Application | Specify the maximum log file size (KB) | 32768 | 32768 |
115 | Windows Components/Event Log Service/Security | Control Event Log behavior when the log file reaches its maximum size | Disabled | Disabled |
116 | Windows Components/Event Log Service/Security | Specify the maximum log file size (KB) | 196608 | 196608 |
117 | Windows Components/Event Log Service/Setup | Control Event Log behavior when the log file reaches its maximum size | Disabled | Disabled |
118 | Windows Components/Event Log Service/Setup | Specify the maximum log file size (KB) | 32768 | 32768 |
119 | Windows Components/Event Log Service/System | Control Event Log behavior when the log file reaches its maximum size | Disabled | Disabled |
120 | Windows Components/Event Log Service/System | Specify the maximum log file size (KB) | 32768 | 32768 |
121 | Windows Components/File Explorer | Configure Windows Defender SmartScreen or Configure Windows SmartScreen | Enabled Pick one of the following settings = Warn and prevent bypass | Enabled Pick one of the following settings = Warn and prevent bypass |
122 | Windows Components/File Explorer | Turn off Data Execution Prevention for Explorer | Disabled | Disabled |
123 | Windows Components/File Explorer | Turn off heap termination on corruption | Disabled | Disabled |
124 | Windows Components/File Explorer | Turn off shell protocol protected mode | Disabled | Disabled |
125 | Windows Components/Location and Sensors | Turn off location | Enabled (privacy) | Enabled (privacy) |
126 | Windows Components/OneDrive | Prevent the usage of OneDrive for file storage | Enabled (maybe) | Enabled (maybe) |
127 | Windows Components/Microsoft User Experience Virtualization/Windows Apps | Finance | Disabled (maybe & privacy) | Disabled (maybe & privacy) |
128 | Windows Components/Microsoft User Experience Virtualization/Windows Apps | Games | Disabled (maybe & privacy) | Disabled (maybe & privacy) |
129 | Windows Components/Microsoft User Experience Virtualization/Windows Apps | Maps | Disabled (maybe & privacy) | Disabled (maybe & privacy) |
130 | Windows Components/Microsoft User Experience Virtualization/Windows Apps | Music | Disabled (maybe & privacy) | Disabled (maybe & privacy) |
131 | Windows Components/Microsoft User Experience Virtualization/Windows Apps | News | Disabled (maybe & privacy) | Disabled (maybe & privacy) |
132 | Windows Components/Microsoft User Experience Virtualization/Windows Apps | Reader | Disabled (maybe & privacy) | Disabled (maybe & privacy) |
133 | Windows Components/Microsoft User Experience Virtualization/Windows Apps | Sports | Disabled (maybe & privacy) | Disabled (maybe & privacy) |
134 | Windows Components/Microsoft User Experience Virtualization/Windows Apps | Travel | Disabled (maybe & privacy) | Disabled (maybe & privacy) |
135 | Windows Components/Microsoft User Experience Virtualization/Windows Apps | Video | Disabled (maybe & privacy) | Disabled (maybe & privacy) |
136 | Windows Components/Microsoft User Experience Virtualization/Windows Apps | Weather | Disabled (maybe & privacy) | Disabled (maybe & privacy) |
137 | Windows Components/Remote Desktop Services/Remote Desktop Connection Client | Do not allow passwords to be saved | Enabled (careful if you're in rdp) | Enabled (careful if you're in rdp) |
138 | Windows Components/Remote Desktop Services/Remote Desktop Connection Client | Restrict Remote Desktop Services users to a single Remote Desktop Services session | Enabled (careful if you're in rdp) (maybe) | Enabled (careful if you're in rdp) (maybe) |
139 | Windows Components/Remote Desktop Services/Remote Desktop Session Host/Device and Resource Redirection | Do not allow COM port redirection | Enabled (careful) | Enabled (careful) |
140 | Windows Components/Remote Desktop Services/Remote Desktop Session Host/Device and Resource Redirection | Do not allow drive redirection | Enabled (careful if you're in rdp) | Enabled (careful if you're in rdp) |
141 | Windows Components/Remote Desktop Services/Remote Desktop Session Host/Device and Resource Redirection | Do not allow LPT port redirection | Enabled (careful) | Enabled (careful) |
142 | Windows Components/Remote Desktop Services/Remote Desktop Session Host/Device and Resource Redirection | Do not allow supported Plug and Play device redirection | Enabled | Enabled |
143 | Windows Components/Remote Desktop Services/Remote Desktop Session Host/Security | Always prompt for password upon connection | Enabled (careful if you're in rdp) | Enabled (careful if you're in rdp) |
144 | Windows Components/Remote Desktop Services/Remote Desktop Session Host/Security | Do not allow local administrators to customize permissions | Disabled (careful if you're in rdp) | Disabled (careful if you're in rdp) |
145 | Windows Components/Remote Desktop Services/Remote Desktop Session Host/Security | Require secure RPC communication | Enabled (careful if you're in rdp) | Enabled (careful if you're in rdp) |
146 | Windows Components/Remote Desktop Services/Remote Desktop Session Host/Security | Require use of specific security layer for remote (RDP) connections | SSH (careful if you're in rdp) | SSH (careful if you're in rdp) |
147 | Windows Components/Remote Desktop Services/Remote Desktop Session Host/Security | Require user authentication for remote connections by using Network Level Authentication | Enabled (careful if you're in rdp, i suggest you dont do this one if you are rdping in) | Enabled (careful if you're in rdp, i suggest you dont do this one if you are rdping in) |
148 | Windows Components/Remote Desktop Services/Remote Desktop Session Host/Security | Set client connection encryption level | High Level (careful if you're in rdp) | High Level (careful if you're in rdp) |
149 | Windows Components/Remote Desktop Services/Remote Desktop Session Host/Session Time Limits | Set time limit for active but idle Remote Desktop Services sessions | 300 | 300 |
150 | Windows Components/Remote Desktop Services/Remote Desktop Session Host/Session Time Limits | Set time limit for active Remote Desktop Services sessions | Enabled (careful if you're in rdp) | Enabled (careful if you're in rdp) |
151 | Windows Components/Remote Desktop Services/Remote Desktop Session Host/Session Time Limits | Set time limit for disconnected sessions | 60 | 60 |
152 | Windows Components/Remote Desktop Services/Remote Desktop Session Host/Temporary folders | Do not delete temp folders upon exit | Disabled | Disabled |
153 | Windows Components/Remote Desktop Services/Remote Desktop Session Host/Temporary folders | Do not use temporary folders per session | Disabled | Disabled |
154 | Windows Components/RSS Feeds | Prevent downloading of enclosures | Enabled | Enabled |
155 | Windows Components/Search | Allow Cortana | Disabled | Disabled |
156 | Windows Components/Search | Allow Cortana above lock screen | Disabled | Disabled |
157 | Windows Components/Search | Allow indexing of encrypted files | Disabled | Disabled |
158 | Windows Components/Search | Allow search and Cortana to use location | Disabled (privacy) | Disabled (privacy) |
159 | Windows Components/Software Protection Platform | Turn off KMS Client Online AVS Validation | Enabled (privacy) (maybe) | Enabled (privacy) (maybe) |
160 | Windows Components/Store | Disable all apps from Microsoft Store | Enabled (maybe) | Enabled (maybe) |
161 | Windows Components/Store | Turn off Automatic Download and Install of updates | Disabled | Disabled |
162 | Windows Components/Store | Turn off the offer to update to the latest version of Windows | Enabled (maybe) | Enabled (maybe) |
163 | Windows Components/Store | Turn off the Store application | Enabled (maybe) | Enabled (maybe) |
164 | Windows Components/Windows Defender Antivirus | Configure detection for potentially unwanted applications | Block | Block |
165 | Windows Components/Windows Defender Antivirus/MAPS | Join Microsoft MAPS | Advanced MAPS (secure) Disabled (private) | Advanced MAPS (secure) Disabled (private) |
166 | Windows Components/Windows Defender Antivirus/MAPS | Send file samples when further analysis is required | Send safe samples | Send safe samples |
167 | Windows Components/Windows Defender Antivirus/Real-time Protection | Turn on behavior monitoring | Enabled (secure) Disabled (private) | Enabled (secure) Disabled (private) |
168 | Windows Components/Windows Defender Antivirus/Reporting | Configure Watson events | Disabled | Disabled |
169 | Windows Components/Windows Defender Antivirus/Scan | Scan removable drives | Enabled | Enabled |
170 | Windows Components/Windows Defender Antivirus/Windows Defender Exploit Guard/Attack Surface Reduction | Configure Attack Surface Reduction rules | Enabled be9ba2d9-53ea-4cdc-84e5-9b1eeee46550 = 1 b2b3f03d-6a65-4f7b-a9c7-1c7ef74a9ba4 = 1 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2 = 1 d4f940ab-401b-4efc-aadc-ad5f3c50688a = 1 d3e037e1-3eb8-44c8-a917-57927947596d = 1 5beb7efe-fd9a-4556-801d-275e5ffc04cc = 1 3b576869-a4ec-4529-8536-b80a7769e899 = 1 26190899-1602-49e8-8b27-eb1d0a1ce869 = 1 92E97FA1-2EDF-4476-BDD6-9DD0B4DDDC7B = 1 7674ba52-37eb-4a4f-a9a1-f0f9a1619a2c = 1 75668c1f-73b5-4cf0-bb93-3ecf5cb7cc84 = 1 | Enabled be9ba2d9-53ea-4cdc-84e5-9b1eeee46550 = 1 b2b3f03d-6a65-4f7b-a9c7-1c7ef74a9ba4 = 1 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2 = 1 d4f940ab-401b-4efc-aadc-ad5f3c50688a = 1 d3e037e1-3eb8-44c8-a917-57927947596d = 1 5beb7efe-fd9a-4556-801d-275e5ffc04cc = 1 3b576869-a4ec-4529-8536-b80a7769e899 = 1 26190899-1602-49e8-8b27-eb1d0a1ce869 = 1 92E97FA1-2EDF-4476-BDD6-9DD0B4DDDC7B = 1 7674ba52-37eb-4a4f-a9a1-f0f9a1619a2c = 1 75668c1f-73b5-4cf0-bb93-3ecf5cb7cc84 = 1 |
171 | Windows Components/Windows Defender Antivirus/Windows Defender Exploit Guard/Network Protection | Prevent users and apps from accessing dangerous websites | Block | Block |
172 | Windows Components/Windows Defender SmartScreen/Explorer | Configure Windows Defender SmartScreen | Enabled Pick one of the following settings = Warn and prevent bypass | Enabled Pick one of the following settings = Warn and prevent bypass |
173 | Windows Components/Windows Defender SmartScreen/Microsoft Edge | Configure Windows Defender SmartScreen | Enabled | |
174 | Windows Components/Windows Defender SmartScreen/Microsoft Edge | Prevent bypassing Windows Defender SmartScreen prompts for sites | Enabled | |
175 | Windows Components/Windows Game Recording and Broadcasting | Enables or disables Windows Game Recording and Broadcasting | Disabled | |
176 | Windows Components/Windows Ink Workspace | Allow suggested apps in Windows Ink Workspace | Disabled | Disabled |
177 | Windows Components/Windows Ink Workspace | Allow Windows Ink Workspace | On, but disallow access above lock | On, but disallow access above lock |
178 | Windows Components/Windows Installer | Allow user control over installs (prohibit user install) | Disabled | Disabled |
179 | Windows Components/Windows Installer | Always install with elevated privileges | Disabled | Disabled |
180 | Windows Components/Windows Installer | Prevent Internet Explorer security prompt for Windows Installer scripts | Disabled | Disabled |
181 | Windows Components/Windows Logon Options | Sign-in and lock last interactive user automatically after a restart or Sign-in last interactive user automatically after a system-initiated restart | Disabled | Disabled |
182 | Windows Components/Windows PowerShell | Turn on PowerShell Script Block Logging | Disabled (some other sources say enabled in comp try both) Log script block invocation start / stop events = [[[delete]]] | Disabled (some other sources say enabled in comp try both) Log script block invocation start / stop events = [[[delete]]] |
183 | Windows Components/Windows PowerShell | Turn on PowerShell Transcription | Disabled | Disabled |
184 | Windows Components/Windows Remote Management (WinRM)/WinRM Client | Allow Basic authentication | Disabled | Disabled |
185 | Windows Components/Windows Remote Management (WinRM)/WinRM Client | Allow unencrypted traffic | Disabled | Disabled |
186 | Windows Components/Windows Remote Management (WinRM)/WinRM Client | Disallow Digest authentication | Enabled | Enabled |
187 | Windows Components/Windows Remote Management (WinRM)/WinRM Service | Allow Basic authentication | Disabled | Disabled |
188 | Windows Components/Windows Remote Management (WinRM)/WinRM Service | Allow remote server management through WinRM | Disabled | Disabled |
189 | Windows Components/Windows Remote Management (WinRM)/WinRM Service | Allow unencrypted traffic | Disabled | Disabled |
190 | Windows Components/Windows Remote Management (WinRM)/WinRM Service | Disallow WinRM from storing RunAs credentials | Enabled | Enabled |
191 | Windows Components/Windows Remote Shell | Allow Remote Shell Access | Disabled | Disabled |
192 | Windows Components/Windows Update | Turn off auto-restart for updates during active hours | Enabled | Enabled |
193 | Windows Components/Windows Update | Turn on recommended updates via Automatic Updates | Enabled | Enabled |
194 | Windows Components/Windows Update | No auto-restart with logged on users for scheduled automatic updates installations | Enabled | Enabled |
195 | Windows Components/Windows Update | Configure Automatic Updates | Enabled Auto download and schedule the install | Enabled Auto download and schedule the install |
196 | ||||
197 | LAPS Specific GPOs | |||
198 | LAPS | Do not allow password expiration time longer than required by policy | Enabled | Enabled |
199 | LAPS | Enable Local Admin Password Management | Enabled | Enabled |
200 | LAPS | Password Settings | Enabled Password Complexity = Large letters + small letters + numbers + special characters Password Length = 15 or more Password Age = 30 or fewer | Enabled Large letters + small letters + numbers + special characters |
201 | ||||
202 | MS (Member Server) Security Guide Specific GPOs | |||
203 | https://docs.microsoft.com/en-us/archive/blogs/secguide/security-baseline-final-for-windows-10-v1809-and-windows-server-2019 | |||
204 | MS Security Guide | Apply UAC restrictions to local accounts on network logons | Enabled | Enabled |
205 | MS Security Guide | Configure SMB v1 client driver | Disable driver (recommended) | Disable driver (recommended) |
206 | MS Security Guide | Configure SMB v1 server | Disabled | Disabled |
207 | MS Security Guide | Enable Structured Exception Handling Overwrite Protection (SEHOP) | Enabled | Enabled |
208 | MS Security Guide | Extended Protection for LDAP Authentication (Domain Controllers only) | Enabled, always (recommended) [DC] | |
209 | MS Security Guide | NetBT NodeType configuration | P-node (recommended) | P-node (recommended) |
210 | MS Security Guide | WDigest Authentication (disabling may require KB2871997) | Disabled | Disabled |
211 | ||||
212 | MSS Specific GPOs | |||
213 | https://docs.microsoft.com/en-us/archive/blogs/secguide/the-mss-settings | |||
214 | MSS (Legacy) | MSS: (AutoAdminLogon) Enable Automatic Logon (not recommended) | Disabled | Disabled |
215 | MSS (Legacy) | MSS: (DisableIPSourceRouting IPv6) IP source routing protection level (protects against packet spoofing) | Enabled Highest protection, source routing is completely disabled. | Enabled Highest protection, source routing is completely disabled. |
216 | MSS (Legacy) | MSS: (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing) | Enabled Highest protection, source routing is completely disabled. | Enabled Highest protection, source routing is completely disabled. |
217 | MSS (Legacy) | MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes | Disabled | Disabled |
218 | MSS (Legacy) | MSS: (KeepAliveTime) How often keep-alive packets are sent in milliseconds | 300000 | 300000 |
219 | MSS (Legacy) | MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers | Enabled | Enabled |
220 | MSS (Legacy) | MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses (couldlead to DoS) | Disabled | Disabled |
221 | MSS (Legacy) | MSS: (SafeDllSearchMode) Enable Safe DLL search mode (recommended) | Enabled | Enabled |
222 | MSS (Legacy) | MSS: (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires (0 recommended) | 5 sec or fewer (0) | 5 sec or fewer (0) |
223 | MSS (Legacy) | MSS:(TcpMaxDataRetransmissions IPv6) How many times unacknowledged data is retransmitted | 3 | 3 |
224 | MSS (Legacy) | MSS:(TcpMaxDataRetransmissions) How many times unacknowledged data is retransmitted | 3 | 3 |
225 | MSS (Legacy) | MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning | 90% or less | 90% or less |