| Faculty User Group Policy | |
| Data collected on: 3/1/2013 3:55:49 PM | |
| Domain | phas.ubc.ca |
| Owner | PHAS\Domain Admins |
| Created | 11/10/2006 2:54:06 PM |
| Modified | 9/27/2011 10:00:26 AM |
| User Revisions | 6 (AD), 6 (sysvol) |
| Computer Revisions | 6 (AD), 6 (sysvol) |
| Unique ID | {B976960A-A76D-4563-9415-DC6A3B282BE0} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Faculty | No | Enabled | phas.ubc.ca/User Accounts/Faculty |
| Visitor | No | Enabled | phas.ubc.ca/User Accounts/Visitor |
| Name |
|---|
| PHAS\Faculty |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| PHAS\Domain Admins | Edit settings, delete, modify security | No |
| PHAS\Enterprise Admins | Edit settings, delete, modify security | No |
| PHAS\Faculty | Read (from Security Filtering) | No |
| Policy | Setting |
|---|---|
| Audit account logon events | Success, Failure |
| Audit logon events | Success, Failure |
| Policy | Setting |
|---|---|
| Change the system time | PHAS\staff |
| Load and unload device drivers | BUILTIN\Administrators, NT AUTHORITY\Authenticated Users, Everyone, PHAS\Domain Users |
| Manage auditing and security log | PHAS\staff |
| Policy | Setting |
|---|---|
| Devices: Allowed to format and eject removable media | Administrators and Interactive Users |
| Devices: Prevent users from installing printer drivers | Enabled |
| Policy | Setting |
|---|---|
| Interactive logon: Do not display last user name | Enabled |
| Policy | Setting |
|---|---|
| MACHINE\Software\Microsoft\Driver Signing\Policy | 1 |
| Policy | Setting | Comment |
|---|---|---|
| Disable CD-ROM | Disabled | |
| Disable Floppy | Disabled | |
| Disable USB | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Add the Administrators security group to roaming user profiles | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Restrict Remote Desktop Services users to a single Remote Desktop Services session | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Remove "Disconnect" option from Shut Down dialog | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Always install with elevated privileges | Disabled | |||
| Disable Windows Installer | Disabled | |||
| Enable user control over installs | Enabled | |||
| Prohibit User Installs | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Allow non-administrators to receive update notifications | Enabled | |||||||||||
| Configure Automatic Updates | Enabled | |||||||||||
| ||||||||||||
| Policy | Setting | Comment | ||||||||||
| Delay Restart for scheduled installations | Enabled | |||||||||||
| ||||||||||||
| Policy | Setting | Comment | ||||||||||
| No auto-restart with logged on users for scheduled automatic updates installations | Enabled | |||||||||||
| Re-prompt for restart with scheduled installations | Enabled | |||||||||||
| ||||||||||||
| Enforcement | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Designated File Types | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Trusted Publishers | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
| Policy | Setting |
|---|---|
| Default Security Level | Unrestricted |
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% | ||||||
| ||||||
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%\*.exe | ||||||
| ||||||
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%\System32\*.exe | ||||||
| ||||||
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% | ||||||
|
| |||||||||
| Run components not signed with Authenticode | Disable |
| Run components signed with Authenticode | Disable |
| Download signed ActiveX controls | Disable |
| Download unsigned ActiveX controls | Disable |
| Initialize and script ActiveX controls not marked as safe | Disable |
| Run ActiveX controls and plug-ins | Disable |
| Script ActiveX controls marked safe for scripting | Disable |
| File download | Disable |
| Font download | Prompt |
| Java permissions | Disable Java |
| Access data sources across domains | Disable |
| Allow META REFRESH | Disable |
| Display mixed content | Prompt |
| Don't prompt for client certificate selection when no certificates or only one certificate exists | Disable |
| Drag and drop or copy and paste files | Prompt |
| Installation of desktop items | Disable |
| Launching applications and unsafe files | Enable |
| Launching programs and files in an IFRAME | Disable |
| Navigate sub-frames across different domains | Disable |
| Software channel permissions | High safety |
| Submit nonencrypted form data | Prompt |
| Userdata persistence | Disable |
| Active scripting | Disable |
| Allow paste operations via script | Disable |
| Scripting of Java applets | Disable |
| Logon | Prompt for user name and password |
| Run components not signed with Authenticode | Enable |
| Run components signed with Authenticode | Enable |
| Download signed ActiveX controls | Prompt |
| Download unsigned ActiveX controls | Disable |
| Initialize and script ActiveX controls not marked as safe | Disable |
| Run ActiveX controls and plug-ins | Enable |
| Script ActiveX controls marked safe for scripting | Enable |
| File download | Enable |
| Font download | Enable |
| Java permissions | Medium safety |
| Access data sources across domains | Prompt |
| Allow META REFRESH | Enable |
| Display mixed content | Prompt |
| Don't prompt for client certificate selection when no certificates or only one certificate exists | Enable |
| Drag and drop or copy and paste files | Enable |
| Installation of desktop items | Prompt |
| Launching applications and unsafe files | Enable |
| Launching programs and files in an IFRAME | Prompt |
| Navigate sub-frames across different domains | Enable |
| Software channel permissions | Medium safety |
| Submit nonencrypted form data | Enable |
| Userdata persistence | Enable |
| Active scripting | Enable |
| Allow paste operations via script | Enable |
| Scripting of Java applets | Enable |
| Logon | Automatic logon only in Intranet zone |
| Require server verification (https:) for all sites in this zone | Disabled |
| Include all local (intranet) sites not listed in other zones | Disabled |
| Include all sites that bypass the proxy server | Disabled |
| Include all network paths (UNCs) | Disabled |
| Sites in this zone |
|---|
| hcp:////system/ |
| http://localhost/ |
| https://localhost/ |
| Run components not signed with Authenticode | Enable |
| Run components signed with Authenticode | Enable |
| Download signed ActiveX controls | Prompt |
| Download unsigned ActiveX controls | Disable |
| Initialize and script ActiveX controls not marked as safe | Disable |
| Run ActiveX controls and plug-ins | Enable |
| Script ActiveX controls marked safe for scripting | Enable |
| File download | Enable |
| Font download | Enable |
| Java permissions | High safety |
| Access data sources across domains | Disable |
| Allow META REFRESH | Enable |
| Display mixed content | Prompt |
| Don't prompt for client certificate selection when no certificates or only one certificate exists | Disable |
| Drag and drop or copy and paste files | Enable |
| Installation of desktop items | Prompt |
| Launching applications and unsafe files | Prompt |
| Launching programs and files in an IFRAME | Prompt |
| Navigate sub-frames across different domains | Enable |
| Software channel permissions | Medium safety |
| Submit nonencrypted form data | Enable |
| Userdata persistence | Enable |
| Active scripting | Enable |
| Allow paste operations via script | Enable |
| Scripting of Java applets | Enable |
| Logon | Automatic logon only in Intranet zone |
| Require server verification (https:) for all sites in this zone | Disabled |
| Sites in this zone |
|---|
| about://*.security_mmc.exe/ |
| http://*.windowsupdate.com/ |
| http://*.windowsupdate.microsoft.com/ |
| http://ardownload.adobe.com/ |
| http://chuangtzu.acc.umu.se/ |
| http://download.microsoft.com/ |
| http://easynews.dl.sourceforge.net/ |
| http://ftp-mozilla.netscape.com/ |
| http://mozilla-chi.osuosl.org/ |
| http://oca.microsoft.com/ |
| http://prdownloads.sourceforge.net/ |
| http://rad.microsoft.com/ |
| http://search.microsoft.com/ |
| http://support.microsoft.com/ |
| http://update.microsoft.com/ |
| http://windowsupdate.microsoft.com/ |
| http://www.7-zip.org/ |
| http://www.adobe.com/ |
| http://www.google.ca/ |
| http://www.microsoft.com/ |
| http://www.mirekw.com/ |
| http://www.mozilla.com/ |
| http://www.msn.com/ |
| http://www.petri.co.il/ |
| http://www.windowsitpro.com/ |
| http://www.windowsnetworking.com/ |
| https://oca.microsoft.com/ |
| Run components not signed with Authenticode | Disable |
| Run components signed with Authenticode | Disable |
| Download signed ActiveX controls | Disable |
| Download unsigned ActiveX controls | Disable |
| Initialize and script ActiveX controls not marked as safe | Disable |
| Run ActiveX controls and plug-ins | Disable |
| Script ActiveX controls marked safe for scripting | Disable |
| File download | Disable |
| Font download | Prompt |
| Java permissions | Disable Java |
| Access data sources across domains | Disable |
| Allow META REFRESH | Disable |
| Display mixed content | Prompt |
| Don't prompt for client certificate selection when no certificates or only one certificate exists | Disable |
| Drag and drop or copy and paste files | Prompt |
| Installation of desktop items | Disable |
| Launching applications and unsafe files | Disable |
| Launching programs and files in an IFRAME | Disable |
| Navigate sub-frames across different domains | Disable |
| Software channel permissions | High safety |
| Submit nonencrypted form data | Prompt |
| Userdata persistence | Disable |
| Active scripting | Disable |
| Allow paste operations via script | Disable |
| Scripting of Java applets | Disable |
| Logon | Prompt for user name and password |
| Sites in this zone |
|---|
| None |
| Privacy Level | Medium | ||||
| Web Sites | |||||
| |||||
| Policy | Setting | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Import the current program settings | Enabled | ||||||||||||
| |||||||||||||
| Internet Explorer should check to see whether it is the default browser | Disabled | ||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Always open All Control Panel Items when opening Control Panel | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Remove Add or Remove Programs | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Disable the Display Control Panel | Disabled | |
| Hide Settings tab | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent changing desktop background | Disabled | |
| Prevent changing desktop icons | Disabled | |
| Prevent changing window color and appearance | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Hide Network Locations icon on desktop | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Disable Active Desktop | Disabled | |||
| Enable Active Desktop | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Prevent use of Offline Files folder | Enabled | |||
| Prohibit user configuration of Offline Files | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Remove 'Make Available Offline' | Enabled | |||
| Synchronize all offline files before logging off | Disabled | |||
| Synchronize all offline files when logging on | Disabled | |||
| Synchronize offline files before suspend | Disabled | |||
| Turn off reminder balloons | Enabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Do not display any custom toolbars in the taskbar | Disabled | |
| Force classic Start Menu | Enabled | |
| Lock the Taskbar | Disabled | |
| Prevent changes to Taskbar and Start Menu Settings | Disabled | |
| Remove access to the context menus for the taskbar | Disabled | |
| Remove Network Connections from Start Menu | Enabled | |
| Remove Network icon from Start Menu | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Don't display the Getting Started welcome screen at logon | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not automatically make redirected folders available offline | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Run logon scripts synchronously | Enabled |
| Policy | Setting | Comment | ||||||
|---|---|---|---|---|---|---|---|---|
| Exclude directories in roaming profile | Enabled | |||||||
| ||||||||
| Policy | Setting | Comment |
|---|---|---|
| Disable the Programs page | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Disable adding channels | Enabled | |
| Disable adding schedules for offline pages | Enabled | |
| Disable all scheduled offline pages | Enabled | |
| Disable channel user interface completely | Enabled | |
| Disable downloading of site subscription content | Enabled | |
| Disable editing and creating of schedule groups | Enabled | |
| Disable editing schedules for offline pages | Enabled | |
| Disable offline page hit logging | Enabled | |
| Disable removing channels | Enabled | |
| Disable removing schedules for offline pages | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Restrict users to the explicitly permitted list of snap-ins | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Device Manager | Enabled | |
| Disk Defragmenter | Enabled | |
| Disk Management | Enabled | |
| Event Viewer | Enabled | |
| Removable Storage Management | Enabled | |
| Security Configuration and Analysis | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Device Manager | Enabled | |
| Logical and Mapped Drives | Enabled | |
| Removable Storage | Enabled | |
| System Properties | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Display confirmation dialog when deleting files | Enabled | |||
| Hide these specified drives in My Computer | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Prevent access to drives from My Computer | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Remove DFS tab | Enabled | |||
| Remove Security tab | Enabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Always install with elevated privileges | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not automatically start Windows Messenger initially | Enabled |
| Setting | State |
|---|---|
| Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Btn_Media | 2 |
| Software\Policies\Microsoft\PCHealth\HelpSvc\Headlines | 1 |