| Ugrad User Group Policy | |
| Data collected on: 2/27/2013 3:05:33 PM | |
| Domain | phas.ubc.ca |
| Owner | PHAS\Domain Admins |
| Created | 8/30/2006 9:20:24 AM |
| Modified | 2/26/2013 4:22:10 PM |
| User Revisions | 98 (AD), 98 (sysvol) |
| Computer Revisions | 14 (AD), 14 (sysvol) |
| Unique ID | {D4140769-CE6B-49ED-BAE2-C9F06A9E1373} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Ugrads | No | Enabled | phas.ubc.ca/User Accounts/Ugrads |
| Name |
|---|
| PHAS\Ugrads |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| PHAS\Domain Admins | Edit settings, delete, modify security | No |
| PHAS\Enterprise Admins | Edit settings, delete, modify security | No |
| PHAS\Ugrads | Read (from Security Filtering) | No |
| Policy | Setting | Comment |
|---|---|---|
| Add the Administrators security group to roaming user profiles | Enabled |
| Setting | State |
|---|---|
| SYSTEM\CurrentControlSet\Services\USBSTOR\Start | 3 |
| Enforcement | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Designated File Types | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Trusted Publishers | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
| Policy | Setting |
|---|---|
| Default Security Level | Unrestricted |
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% | ||||||
| ||||||
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%\*.exe | ||||||
| ||||||
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%\System32\*.exe | ||||||
| ||||||
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% | ||||||
|
| Grant user exclusive rights to Desktop | Disabled |
| Move the contents of Desktop to the new location | Disabled |
| Also apply redirection policy to Windows 2000, Windows 2000 server, Windows XP, and Windows Server 2003 operating systems | Enabled |
| Policy Removal Behavior | Restore contents |
| Grant user exclusive rights to Start Menu | Disabled |
| Move the contents of Start Menu to the new location | Disabled |
| Also apply redirection policy to Windows 2000, Windows 2000 server, Windows XP, and Windows Server 2003 operating systems | Enabled |
| Policy Removal Behavior | Leave contents |
| |||||||||
| Run components not signed with Authenticode | Disable |
| Run components signed with Authenticode | Disable |
| Download signed ActiveX controls | Disable |
| Download unsigned ActiveX controls | Disable |
| Initialize and script ActiveX controls not marked as safe | Disable |
| Run ActiveX controls and plug-ins | Disable |
| Script ActiveX controls marked safe for scripting | Disable |
| File download | Disable |
| Font download | Disable |
| Java permissions | Disable Java |
| Access data sources across domains | Disable |
| Allow META REFRESH | Disable |
| Display mixed content | Prompt |
| Don't prompt for client certificate selection when no certificates or only one certificate exists | Disable |
| Drag and drop or copy and paste files | Disable |
| Installation of desktop items | Disable |
| Launching applications and unsafe files | Disable |
| Launching programs and files in an IFRAME | Disable |
| Navigate sub-frames across different domains | Disable |
| Software channel permissions | High safety |
| Submit nonencrypted form data | Enable |
| Userdata persistence | Disable |
| Active scripting | Disable |
| Allow paste operations via script | Disable |
| Scripting of Java applets | Disable |
| Logon | Prompt for user name and password |
| Run components not signed with Authenticode | Enable |
| Run components signed with Authenticode | Enable |
| Download signed ActiveX controls | Prompt |
| Download unsigned ActiveX controls | Disable |
| Initialize and script ActiveX controls not marked as safe | Disable |
| Run ActiveX controls and plug-ins | Enable |
| Script ActiveX controls marked safe for scripting | Enable |
| File download | Enable |
| Font download | Enable |
| Java permissions | Medium safety |
| Access data sources across domains | Prompt |
| Allow META REFRESH | Enable |
| Display mixed content | Prompt |
| Don't prompt for client certificate selection when no certificates or only one certificate exists | Enable |
| Drag and drop or copy and paste files | Enable |
| Installation of desktop items | Prompt |
| Launching applications and unsafe files | Enable |
| Launching programs and files in an IFRAME | Prompt |
| Navigate sub-frames across different domains | Enable |
| Software channel permissions | Medium safety |
| Submit nonencrypted form data | Enable |
| Userdata persistence | Enable |
| Active scripting | Enable |
| Allow paste operations via script | Enable |
| Scripting of Java applets | Enable |
| Logon | Automatic logon only in Intranet zone |
| Require server verification (https:) for all sites in this zone | Disabled |
| Include all local (intranet) sites not listed in other zones | Disabled |
| Include all sites that bypass the proxy server | Disabled |
| Include all network paths (UNCs) | Disabled |
| Sites in this zone |
|---|
| hcp:////system/ |
| http://localhost/ |
| https://localhost/ |
| Run components not signed with Authenticode | Enable |
| Run components signed with Authenticode | Enable |
| Download signed ActiveX controls | Prompt |
| Download unsigned ActiveX controls | Disable |
| Initialize and script ActiveX controls not marked as safe | Disable |
| Run ActiveX controls and plug-ins | Enable |
| Script ActiveX controls marked safe for scripting | Enable |
| File download | Enable |
| Font download | Enable |
| Java permissions | High safety |
| Access data sources across domains | Disable |
| Allow META REFRESH | Enable |
| Display mixed content | Prompt |
| Don't prompt for client certificate selection when no certificates or only one certificate exists | Disable |
| Drag and drop or copy and paste files | Enable |
| Installation of desktop items | Prompt |
| Launching applications and unsafe files | Prompt |
| Launching programs and files in an IFRAME | Prompt |
| Navigate sub-frames across different domains | Enable |
| Software channel permissions | Medium safety |
| Submit nonencrypted form data | Enable |
| Userdata persistence | Enable |
| Active scripting | Enable |
| Allow paste operations via script | Enable |
| Scripting of Java applets | Enable |
| Logon | Automatic logon only in Intranet zone |
| Require server verification (https:) for all sites in this zone | Disabled |
| Sites in this zone |
|---|
| about://*.security_mmc.exe/ |
| http://*.ubc.ca/ |
| http://*.update.microsoft.com/ |
| http://*.windowsupdate.com/ |
| http://*.windowsupdate.microsoft.com/ |
| http://downloadfinder.intel.com/ |
| http://downloadmirror.intel.com/ |
| http://go.microsoft.com/ |
| http://msdn.microsoft.com/ |
| http://mysearch.intel.com/ |
| http://oca.microsoft.com/ |
| http://search.it.ubc.ca/ |
| http://support.intel.com/ |
| http://support.microsoft.com/ |
| http://technet.microsoft.com/ |
| http://windowsupdate.microsoft.com/ |
| http://www.intel.com/ |
| http://www.it.ubc.ca/ |
| http://www.microsoft.com/ |
| http://www.ubc.ca/ |
| http://www.webct.com/ |
| https://*.update.microsoft.com/ |
| https://*.windowsupdate.microsoft.com/ |
| https://my.ubc.ca/ |
| https://oca.microsoft.com/ |
| https://windowsupdate.microsoft.com/ |
| Run components not signed with Authenticode | Disable |
| Run components signed with Authenticode | Disable |
| Download signed ActiveX controls | Disable |
| Download unsigned ActiveX controls | Disable |
| Initialize and script ActiveX controls not marked as safe | Disable |
| Run ActiveX controls and plug-ins | Disable |
| Script ActiveX controls marked safe for scripting | Disable |
| File download | Disable |
| Font download | Prompt |
| Java permissions | Disable Java |
| Access data sources across domains | Disable |
| Allow META REFRESH | Disable |
| Display mixed content | Prompt |
| Don't prompt for client certificate selection when no certificates or only one certificate exists | Disable |
| Drag and drop or copy and paste files | Prompt |
| Installation of desktop items | Disable |
| Launching applications and unsafe files | Disable |
| Launching programs and files in an IFRAME | Disable |
| Navigate sub-frames across different domains | Disable |
| Software channel permissions | High safety |
| Submit nonencrypted form data | Prompt |
| Userdata persistence | Disable |
| Active scripting | Disable |
| Allow paste operations via script | Disable |
| Scripting of Java applets | Disable |
| Logon | Prompt for user name and password |
| Sites in this zone |
|---|
| None |
| Privacy Level | Medium | ||||
| Web Sites | |||||
| |||||
| Policy | Setting | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Import the current program settings | Enabled | ||||||||||||
| |||||||||||||
| Internet Explorer should check to see whether it is the default browser | Disabled | ||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Prohibit access to the Control Panel | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Remove Add or Remove Programs | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Disable the Display Control Panel | Enabled | |
| Hide Settings tab | Enabled |
| Policy | Setting | Comment | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Enable screen saver | Disabled | |||||||||||||||||||
| Force a specific visual style file or force Windows Classic | Enabled | |||||||||||||||||||
| ||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||
| Password protect the screen saver | Disabled | |||||||||||||||||||
| Prevent changing desktop background | Enabled | |||||||||||||||||||
| Prevent changing desktop icons | Enabled | |||||||||||||||||||
| Prevent changing screen saver | Enabled | |||||||||||||||||||
| Prevent changing window color and appearance | Enabled | |||||||||||||||||||
| Screen saver timeout | Disabled | |||||||||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Browse the network to find printers | Disabled | |
| Prevent addition of printers | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Restrict selection of Windows menus and dialogs language | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Disable Active Desktop | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Prohibit adding items | Enabled | |||
| Prohibit changes | Enabled | |||
| Prohibit closing items | Enabled | |||
| Prohibit deleting items | Enabled | |||
| Prohibit editing items | Enabled | |||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Prevent use of Offline Files folder | Enabled | |||
| Prohibit user configuration of Offline Files | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Remove 'Make Available Offline' | Enabled | |||
| Synchronize all offline files before logging off | Disabled | |||
| Synchronize all offline files when logging on | Disabled | |||
| Synchronize offline files before suspend | Disabled | |||
| Policy | Setting | Comment | |||||||
|---|---|---|---|---|---|---|---|---|---|
| Don't display the Getting Started welcome screen at logon | Enabled | ||||||||
| Don't run specified Windows applications | Enabled | ||||||||
| |||||||||
| Policy | Setting | Comment | |||||||
| Prevent access to registry editing tools | Enabled | ||||||||
| |||||||||
| Policy | Setting | Comment | |||||||
| Prevent access to the command prompt | Enabled | ||||||||
| |||||||||
| Policy | Setting | Comment |
|---|---|---|
| Remove Change Password | Enabled | |
| Remove Lock Computer | Enabled | |
| Remove Task Manager | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not automatically make redirected folders available offline | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Internet download for Web publishing and online ordering wizards | Enabled | |
| Turn off the "Order Prints" picture task | Enabled | |
| Turn off the "Publish to Web" task for files and folders | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Run logon scripts synchronously | Enabled |
| Policy | Setting | Comment | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Exclude directories in roaming profile | Enabled | |||||||||||
| ||||||||||||
| Policy | Setting | Comment | ||||||||||
| Limit profile size | Enabled | |||||||||||
| ||||||||||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn off Autoplay | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Disable changing accessibility settings | Enabled | |||
| Disable changing Advanced page settings | Enabled | |||
| Disable changing Automatic Configuration settings | Enabled | |||
| Disable changing Calendar and Contact settings | Enabled | |||
| Disable changing certificate settings | Enabled | |||
| Disable changing color settings | Enabled | |||
| Disable changing connection settings | Enabled | |||
| Disable changing default browser check | Enabled | |||
| Disable changing font settings | Enabled | |||
| Disable changing home page settings | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Disable changing language settings | Enabled | |||
| Disable changing link color settings | Enabled | |||
| Disable changing Messaging settings | Enabled | |||
| Disable changing Profile Assistant settings | Enabled | |||
| Disable changing proxy settings | Enabled | |||
| Disable changing ratings settings | Enabled | |||
| Disable changing Temporary Internet files settings | Enabled | |||
| Disable the Reset Web Settings feature | Enabled | |||
| Do not allow users to enable or disable add-ons | Enabled | |||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Disable "Configuring History" | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Disable the Advanced page | Enabled | |
| Disable the Connections page | Enabled | |
| Disable the Content page | Enabled | |
| Disable the General page | Enabled | |
| Disable the Privacy page | Enabled | |
| Disable the Programs page | Enabled | |
| Disable the Security page | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Empty Temporary Internet Files folder when browser is closed | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Java permissions | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Scripting of Java applets | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Disable adding channels | Enabled | |
| Disable adding schedules for offline pages | Enabled | |
| Disable all scheduled offline pages | Enabled | |
| Disable channel user interface completely | Enabled | |
| Disable downloading of site subscription content | Enabled | |
| Disable editing and creating of schedule groups | Enabled | |
| Disable editing schedules for offline pages | Enabled | |
| Disable offline page hit logging | Enabled | |
| Disable removing channels | Enabled | |
| Disable removing schedules for offline pages | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Deny all add-ons unless specifically allowed in the Add-on List | Enabled |
| Policy | Setting | Comment | ||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Configure Toolbar Buttons | Enabled | |||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||||||||||||||||||||||||||
| Disable customizing browser toolbar buttons | Enabled | |||||||||||||||||||||||||||||||||||||||||
| Disable customizing browser toolbars | Enabled | |||||||||||||||||||||||||||||||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Restrict the user from entering author mode | Enabled | |
| Restrict users to the explicitly permitted list of snap-ins | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Disable Chat | Enabled | |
| Disable Directory services | Enabled | |
| Disable NetMeeting 2.x Whiteboard | Enabled | |
| Disable Whiteboard | Enabled | |
| Prevent adding Directory servers | Enabled | |
| Prevent viewing Web directory | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Hide Advanced Properties Checkbox in Add Scheduled Task Wizard | Enabled | |
| Hide Property Pages | Enabled | |
| Prevent Task Run or End | Enabled | |
| Prohibit Browse | Enabled | |
| Prohibit Drag-and-Drop | Enabled | |
| Prohibit New Task Creation | Enabled | |
| Prohibit Task Deletion | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Hide the common dialog back button | Enabled | |
| Hide the common dialog places bar | Enabled | |
| Hide the dropdown list of recent files | Enabled | |
| Items displayed in Places Bar | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent removable media source for any install | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not allow Windows Messenger to be run | Enabled | |
| Do not automatically start Windows Messenger initially | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Remove access to use all Windows Update features | Enabled | |||
| ||||
| Setting | State |
|---|---|
| Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Btn_Media | 2 |
| Software\Policies\Microsoft\PCHealth\HelpSvc\Headlines | 1 |