Group Policy Results | |
JDHLAB\rbiv on JDHLAB\CLIENT1 | |
Data collected on: 5/17/2011 2:14:39 PM |
Computer name | JDHLAB\CLIENT1 |
Domain | jdhlab.local |
Site | Default-First-Site-Name |
Last time Group Policy was processed | 5/17/2011 12:59:49 PM |
Name | Link Location | Revision |
---|---|---|
Local Group Policy | Local | AD (7), Sysvol (7) |
PSR | jdhlab.local | AD (2), Sysvol (2) |
TechEd | jdhlab.local | AD (18), Sysvol (18) |
WinRM Configuration | jdhlab.local | AD (15), Sysvol (15) |
Default Domain Policy | jdhlab.local | AD (13), Sysvol (13) |
Corp Desktop | jdhlab.local/Desktops | AD (15), Sysvol (15) |
Remote Assistance | jdhlab.local/Desktops | AD (4), Sysvol (4) |
Name | Link Location | Reason Denied |
---|---|---|
Network Config | jdhlab.local/Configuration/Sites/Default-First-Site-Name | Empty |
{B93E1E03-3D1D-417F-A17A-493116236D90} | jdhlab.local | Disabled Link |
Name | Value | Reference GPO(s) |
---|---|---|
None |
Component Name | Status | Last Process Time |
---|---|---|
Group Policy Infrastructure | Success | 5/17/2011 12:59:50 PM |
Group Policy Environment | Success | 5/17/2011 12:59:50 PM |
Group Policy Services | Success | 5/17/2011 12:59:50 PM |
Microsoft Offline Files | Success | 5/17/2011 12:59:50 PM |
Registry | Success | 5/16/2011 11:09:49 AM |
Security | Success | 5/16/2011 11:09:50 AM |
User name | JDHLAB\rbiv |
Domain | jdhlab.local |
Last time Group Policy was processed | 5/16/2011 10:32:58 AM |
Name | Link Location | Revision |
---|---|---|
TechEd | jdhlab.local | AD (17), Sysvol (17) |
Corp Desktop | jdhlab.local/Employees | AD (4), Sysvol (4) |
Executive Users | jdhlab.local/Employees/Executive | AD (4), Sysvol (4) |
Name | Link Location | Reason Denied |
---|---|---|
Local Group Policy | Local | Empty |
Network Config | jdhlab.local/Configuration/Sites/Default-First-Site-Name | Empty |
PSR | jdhlab.local | Empty |
{B93E1E03-3D1D-417F-A17A-493116236D90} | jdhlab.local | Disabled Link |
WinRM Configuration | jdhlab.local | Empty |
Default Domain Policy | jdhlab.local | Empty |
Name | Value | Reference GPO(s) |
---|---|---|
None |
Component Name | Status | Last Process Time |
---|---|---|
Group Policy Infrastructure | Success | 5/16/2011 10:33:03 AM |
Group Policy Drive Maps | Success | 5/16/2011 10:33:03 AM |
Group Policy Environment | Success | 5/16/2011 10:29:03 AM |
Group Policy Start Menu Settings | Success | 5/16/2011 9:35:54 AM |
Registry | Success | 5/16/2011 10:33:03 AM |
Policy | Setting | Winning GPO |
---|---|---|
Enforce password history | 12 passwords remembered | Default Domain Policy |
Maximum password age | 45 days | Default Domain Policy |
Minimum password age | 1 days | Default Domain Policy |
Minimum password length | 7 characters | Default Domain Policy |
Password must meet complexity requirements | Enabled | Default Domain Policy |
Store passwords using reversible encryption | Disabled | Default Domain Policy |
Policy | Setting | Winning GPO |
---|---|---|
Account lockout duration | 30 minutes | Default Domain Policy |
Account lockout threshold | 7 invalid logon attempts | Default Domain Policy |
Reset account lockout counter after | 30 minutes | Default Domain Policy |
Policy | Setting | Winning GPO |
---|---|---|
Network access: Allow anonymous SID/Name translation | Disabled | Default Domain Policy |
Policy | Setting | Winning GPO |
---|---|---|
Network security: Do not store LAN Manager hash value on next password change | Enabled | Default Domain Policy |
Network security: Force logoff when logon hours expire | Disabled | Default Domain Policy |
Policy | Setting | Winning GPO |
---|---|---|
Maximum application log size | 4096 kilobytes | TechEd |
Maximum security log size | 8192 kilobytes | TechEd |
Maximum system log size | 4096 kilobytes | TechEd |
Retention method for application log | As needed | TechEd |
Retention method for security log | As needed | TechEd |
Retention method for system log | As needed | TechEd |
Policy | Setting | Winning GPO |
---|---|---|
Policy version | 2.10 | WinRM Configuration |
Disable stateful FTP | Not Configured | |
Disable stateful PPTP | Not Configured | |
IPsec exempt | Not Configured | |
IPsec through NAT | Not Configured | |
Preshared key encoding | Not Configured | |
SA idle time | Not Configured | |
Strong CRL check | Not Configured |
Policy | Setting | Winning GPO |
---|---|---|
Firewall state | On | Corp Desktop |
Inbound connections | Not Configured | |
Outbound connections | Not Configured | |
Apply local firewall rules | Not Configured | |
Apply local connection security rules | Not Configured | |
Display notifications | Yes | Corp Desktop |
Allow unicast responses | No | Corp Desktop |
Log dropped packets | Not Configured | |
Log successful connections | Not Configured | |
Log file path | Not Configured | |
Log file maximum size (KB) | Not Configured |
Name | Description | Winning GPO | ||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Windows Remote Management (HTTP-In) | Inbound rule for Windows Remote Management via WS-Management. [TCP 5985] | WinRM Configuration | ||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||
Windows Remote Management (HTTP-In) | Inbound rule for Windows Remote Management via WS-Management. [TCP 5985] | WinRM Configuration | ||||||||||||||||||||||||||||||||||||
|
Policy | Setting | Winning GPO |
---|---|---|
Apply the default user logon picture to all users | Enabled | TechEd |
Policy | Setting | Winning GPO | ||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Windows Firewall: Allow ICMP exceptions | Enabled | Corp Desktop | ||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||
Policy | Setting | Winning GPO | ||||||||||||||||||||||||||||||||||||||||||||||
Windows Firewall: Allow inbound file and printer sharing exception | Enabled | Corp Desktop | ||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||
Policy | Setting | Winning GPO | ||||||||||||||||||||||||||||||||||||||||||||||
Windows Firewall: Allow inbound remote administration exception | Enabled | Corp Desktop | ||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||
Policy | Setting | Winning GPO | ||||||||||||||||||||||||||||||||||||||||||||||
Windows Firewall: Allow inbound Remote Desktop exceptions | Enabled | Corp Desktop | ||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||
Policy | Setting | Winning GPO | ||||||||||||||||||||||||||||||||||||||||||||||
Windows Firewall: Allow inbound UPnP framework exceptions | Enabled | Corp Desktop | ||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||
Policy | Setting | Winning GPO | ||||||||||||||||||||||||||||||||||||||||||||||
Windows Firewall: Allow local port exceptions | Disabled | Corp Desktop | ||||||||||||||||||||||||||||||||||||||||||||||
Windows Firewall: Define inbound port exceptions | Enabled | WinRM Configuration | ||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||
Policy | Setting | Winning GPO | ||||||||||||||||||||||||||||||||||||||||||||||
Windows Firewall: Prohibit notifications | Disabled | Corp Desktop | ||||||||||||||||||||||||||||||||||||||||||||||
Windows Firewall: Prohibit unicast response to multicast or broadcast requests | Enabled | Corp Desktop | ||||||||||||||||||||||||||||||||||||||||||||||
Windows Firewall: Protect all network connections | Enabled | Corp Desktop |
Policy | Setting | Winning GPO | ||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Windows Firewall: Allow ICMP exceptions | Disabled | Corp Desktop | ||||||||||||||||||||||||||||
Windows Firewall: Allow inbound file and printer sharing exception | Disabled | Corp Desktop | ||||||||||||||||||||||||||||
Windows Firewall: Allow inbound remote administration exception | Disabled | Corp Desktop | ||||||||||||||||||||||||||||
Windows Firewall: Allow inbound Remote Desktop exceptions | Enabled | Corp Desktop | ||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||
Policy | Setting | Winning GPO | ||||||||||||||||||||||||||||
Windows Firewall: Allow inbound UPnP framework exceptions | Disabled | Corp Desktop | ||||||||||||||||||||||||||||
Windows Firewall: Allow local port exceptions | Disabled | Corp Desktop | ||||||||||||||||||||||||||||
Windows Firewall: Prohibit notifications | Disabled | Corp Desktop | ||||||||||||||||||||||||||||
Windows Firewall: Prohibit unicast response to multicast or broadcast requests | Enabled | Corp Desktop | ||||||||||||||||||||||||||||
Windows Firewall: Protect all network connections | Enabled | Corp Desktop |
Policy | Setting | Winning GPO |
---|---|---|
Allow or Disallow use of the Offline Files feature | Disabled | Corp Desktop |
Policy | Setting | Winning GPO | ||||
---|---|---|---|---|---|---|
Registry policy processing | Enabled | Corp Desktop | ||||
|
Policy | Setting | Winning GPO |
---|---|---|
Turn off downloading of print drivers over HTTP | Enabled | Corp Desktop |
Turn off Internet download for Web publishing and online ordering wizards | Enabled | Corp Desktop |
Turn off printing over HTTP | Enabled | Corp Desktop |
Turn off Search Companion content file updates | Enabled | Corp Desktop |
Turn off the "Publish to Web" task for files and folders | Enabled | Corp Desktop |
Turn off the Windows Messenger Customer Experience Improvement Program | Enabled | Corp Desktop |
Turn off Windows Update device driver searching | Disabled | Corp Desktop |
Policy | Setting | Winning GPO | ||||
---|---|---|---|---|---|---|
Assign a default domain for logon | Enabled | Local Group Policy | ||||
|
Policy | Setting | Winning GPO | ||||||||
---|---|---|---|---|---|---|---|---|---|---|
Offer Remote Assistance | Enabled | Remote Assistance | ||||||||
| ||||||||||
Policy | Setting | Winning GPO | ||||||||
Solicited Remote Assistance | Enabled | Remote Assistance | ||||||||
| ||||||||||
Policy | Setting | Winning GPO | ||||||||
Turn on bandwidth optimization | Enabled | Remote Assistance | ||||||||
| ||||||||||
Policy | Setting | Winning GPO | ||||||||
Turn on session logging | Enabled | Remote Assistance |
Policy | Setting | Winning GPO | ||
---|---|---|---|---|
Restrictions for Unauthenticated RPC clients | Enabled | Corp Desktop | ||
| ||||
Policy | Setting | Winning GPO | ||
RPC Endpoint Mapper Client Authentication | Disabled | Corp Desktop |
Policy | Setting | Winning GPO |
---|---|---|
Turn off Problem Steps Recorder | Disabled | PSR |
Policy | Setting | Winning GPO |
---|---|---|
Turn off desktop gadgets | Enabled | TechEd |
Policy | Setting | Winning GPO |
---|---|---|
Disable Automatic Install of Internet Explorer components | Enabled | Corp Desktop |
Disable Periodic Check for Internet Explorer software updates | Enabled | Corp Desktop |
Disable software update shell notifications on program launch | Enabled | Corp Desktop |
Do not allow users to enable or disable add-ons | Enabled | Corp Desktop |
Make proxy settings per-machine (rather than per-user) | Enabled | Corp Desktop |
Security Zones: Do not allow users to add/delete sites | Enabled | Corp Desktop |
Security Zones: Do not allow users to change policies | Enabled | Corp Desktop |
Security Zones: Use only machine settings | Enabled | Corp Desktop |
Turn off Crash Detection | Enabled | Corp Desktop |
Policy | Setting | Winning GPO |
---|---|---|
Allow software to run or install even if the signature is invalid | Disabled | Corp Desktop |
Policy | Setting | Winning GPO |
---|---|---|
Internet Explorer Processes | Enabled | Corp Desktop |
Policy | Setting | Winning GPO |
---|---|---|
Internet Explorer Processes | Enabled | Corp Desktop |
Policy | Setting | Winning GPO |
---|---|---|
Internet Explorer Processes | Enabled | Corp Desktop |
Policy | Setting | Winning GPO |
---|---|---|
Internet Explorer Processes | Enabled | Corp Desktop |
Policy | Setting | Winning GPO |
---|---|---|
Internet Explorer Processes | Enabled | Corp Desktop |
Policy | Setting | Winning GPO |
---|---|---|
Internet Explorer Processes | Enabled | Corp Desktop |
Policy | Setting | Winning GPO |
---|---|---|
Internet Explorer Processes | Enabled | Corp Desktop |
Policy | Setting | Winning GPO | ||||
---|---|---|---|---|---|---|
Always prompt for password upon connection | Enabled | Corp Desktop | ||||
Set client connection encryption level | Enabled | Corp Desktop | ||||
|
Policy | Setting | Winning GPO |
---|---|---|
Do not allow Windows Messenger to be run | Enabled | Corp Desktop |
Policy | Setting | Winning GPO | ||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Trusted Hosts | Enabled | WinRM Configuration | ||||||||||||||||||||||||||||||
|
Policy | Setting | Winning GPO | ||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Allow automatic configuration of listeners | Enabled | WinRM Configuration | ||||||||||||||||||||||||||||
|
Policy | Setting | Winning GPO | ||
---|---|---|---|---|
Allow Remote Shell Access | Enabled | WinRM Configuration | ||
Specify maximum number of processes per Shell | Enabled | WinRM Configuration | ||
| ||||
Policy | Setting | Winning GPO | ||
Specify maximum number of remote shells per user | Enabled | WinRM Configuration | ||
|
Policy | Setting | Winning GPO | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|
Automatic Updates detection frequency | Enabled | Local Group Policy | ||||||||||
| ||||||||||||
Policy | Setting | Winning GPO | ||||||||||
Configure Automatic Updates | Enabled | Corp Desktop | ||||||||||
| ||||||||||||
Policy | Setting | Winning GPO | ||||||||||
Do not adjust default option to 'Install Updates and Shut Down' in Shut Down Windows dialog box | Disabled | Corp Desktop | ||||||||||
Do not display 'Install Updates and Shut Down' option in Shut Down Windows dialog box | Disabled | Corp Desktop | ||||||||||
Enable client-side targeting | Enabled | Local Group Policy | ||||||||||
| ||||||||||||
Policy | Setting | Winning GPO | ||||||||||
No auto-restart with logged on users for scheduled automatic updates installations | Disabled | Corp Desktop | ||||||||||
Reschedule Automatic Updates scheduled installations | Enabled | Corp Desktop | ||||||||||
| ||||||||||||
Policy | Setting | Winning GPO | ||||||||||
Specify intranet Microsoft update service location | Enabled | Local Group Policy | ||||||||||
| ||||||||||||
Policy | Setting | Winning GPO | ||||||||||
Turn on recommended updates via Automatic Updates | Enabled | Local Group Policy | ||||||||||
Turn on Software Notifications | Enabled | Local Group Policy |
Winning GPO | Corp Desktop |
Service name | Browser |
Action | Start service |
Startup type: | No change |
Wait timeout if service is locked: | 30 seconds |
Log on service as: | No change |
First failure: | Restart the service |
Second failure: | Restart the service |
Subsequent failures: | Take no action |
Reset fail count after: | 0 days |
Restart service after: | 1 minute |
Policy | Setting | Winning GPO |
---|---|---|
Don't save settings at exit | Enabled | TechEd |
Remove Recycle Bin icon from desktop | Enabled | TechEd |
Policy | Setting | Winning GPO | ||||||||
---|---|---|---|---|---|---|---|---|---|---|
Desktop Wallpaper | Enabled | TechEd | ||||||||
|
Policy | Setting | Winning GPO |
---|---|---|
Add Logoff to the Start Menu | Enabled | Corp Desktop |
Add the Run command to the Start Menu | Enabled | Corp Desktop |
Policy | Setting | Winning GPO | ||
---|---|---|---|---|
Prevent access to registry editing tools | Enabled | Corp Desktop | ||
|
Policy | Setting | Winning GPO |
---|---|---|
Remove Task Manager | Enabled | Executive Users |
Policy | Setting | Winning GPO |
---|---|---|
Prompt for password on resume from hibernate / suspend | Enabled | Executive Users |
Winning GPO | Executive Users |
Number of programs on the Start menu | 9 |
Computer | Display as a link |
Connect to | No |
Control Panel | Do not display this item |
Default Programs | Do not display this item |
Documents | Display as a menu |
Enable context menus and dragging and dropping | Yes |
Favorites | Do not display this item |
Games | Do not display this item |
Help | Display this item |
Highlight newly installed programs | No |
Music | Do not display this item |
Network | Do not display this item |
Open submenus when I pause on them with the mouse pointer | No |
Personal Folder | Display as a link |
Pictures | Display as a link |
Printers | Do not display this item |
Run command | Do not display this item |
Search | Yes |
Search Communications | No |
Search Favorites and history | No |
Search files | Search the user's files |
Search programs | Yes |
Sort All Programs menu by name | Yes |
System administrative tools | Do not display this item |
Use Large Icons | Yes |
List most recently used documents | Yes |
Clear recent documents list | No |