Group Policy Management
body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } }
Setting Path:
Explanation
No explanation is available for this setting.
Supported On:
Not available
Wallpaper
Data collected on: 2/2/2026 4:58:56 PM
General
Details
Domain JoeCorp.lan
Owner JOECORP\Domain Admins
Created 1/26/2026 6:09:14 PM
Modified 1/26/2026 6:20:26 PM
User Revisions 1 (AD), 1 (SYSVOL)
Computer Revisions 0 (AD), 0 (SYSVOL)
Unique ID {1BC1EBE0-08F0-40A2-966D-C7753F932BCD}
GPO Status Enabled
Links
Location Enforced Link Status Path
Standard Users No Enabled JoeCorp.lan/UsersOU/Standard Users

This list only includes links in the domain of the GPO.
Security Filtering
The settings in this GPO can only apply to the following groups, users, and computers:
Name
JOECORP\Employees
Delegation
These groups and users have the specified permission for this GPO
Name Allowed Permissions Inherited
JOECORP\Domain Admins Edit settings, delete, modify security No
JOECORP\Employees Read (from Security Filtering) No
JOECORP\Enterprise Admins Edit settings, delete, modify security No
NT AUTHORITY\Authenticated Users Read No
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS Read No
NT AUTHORITY\SYSTEM Edit settings, delete, modify security No
Computer Configuration (Enabled)
No settings defined.
User Configuration (Enabled)
Policies
Administrative Templates
Policy definitions (ADMX files) retrieved from the local computer.
Desktop/Desktop
Policy Setting Comment
Desktop Wallpaper Enabled
Wallpaper Name: \\SRV01.JoeCorp.lan\Data\wallpaper.png
Example: Using a local path: C:\windows\web\wallpaper\home.jpg
Example: Using a UNC path: \\Server\Share\Corp.jpg
Wallpaper Style: Center
Lockdown
Group Policy Management
body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } }
Setting Path:
Explanation
No explanation is available for this setting.
Supported On:
Not available
Lockdown
Data collected on: 2/2/2026 4:58:57 PM
General
Details
Domain JoeCorp.lan
Owner JOECORP\Domain Admins
Created 1/26/2026 5:56:42 PM
Modified 1/26/2026 6:31:32 PM
User Revisions 16 (AD), 16 (SYSVOL)
Computer Revisions 0 (AD), 0 (SYSVOL)
Unique ID {2731E5FC-7A8B-4B3E-AC79-CAB92AEEA191}
GPO Status Enabled
Links
Location Enforced Link Status Path
Standard Users No Enabled JoeCorp.lan/UsersOU/Standard Users

This list only includes links in the domain of the GPO.
Security Filtering
The settings in this GPO can only apply to the following groups, users, and computers:
Name
JOECORP\Employees
Delegation
These groups and users have the specified permission for this GPO
Name Allowed Permissions Inherited
JOECORP\Domain Admins Edit settings, delete, modify security No
JOECORP\Employees Read (from Security Filtering) No
JOECORP\Enterprise Admins Edit settings, delete, modify security No
NT AUTHORITY\Authenticated Users Read No
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS Read No
NT AUTHORITY\SYSTEM Edit settings, delete, modify security No
Computer Configuration (Enabled)
No settings defined.
User Configuration (Enabled)
Policies
Administrative Templates
Policy definitions (ADMX files) retrieved from the local computer.
Control Panel
Policy Setting Comment
Prohibit access to Control Panel and PC settings Enabled
Desktop
Policy Setting Comment
Prohibit User from manually redirecting Profile Folders Enabled
Start Menu and Taskbar
Policy Setting Comment
Prevent users from customizing their Start Screen Enabled
Prevent users from uninstalling applications from Start Enabled
Remove access to the context menus for the taskbar Enabled
Remove Quick Settings Enabled
Remove Run menu from Start Menu Enabled
System
Policy Setting Comment
Prevent access to registry editing tools Enabled
Disable regedit from running silently? Yes
Policy Setting Comment
Prevent access to the command prompt Enabled
Disable the command prompt script processing also? No
System/Ctrl+Alt+Del Options
Policy Setting Comment
Remove Change Password Enabled
Remove Lock Computer Enabled
Remove Logoff Enabled
Remove Task Manager Enabled
Windows Components/File Explorer
Policy Setting Comment
Hide these specified drives in My Computer Enabled
Pick one of the following combinations Restrict C drive only
Policy Setting Comment
Prevent access to drives from My Computer Enabled
Pick one of the following combinations Restrict C drive only
Policy Setting Comment
Turn off Windows Key hotkeys Enabled
Folder Redirection
Group Policy Management
body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } }
Setting Path:
Explanation
No explanation is available for this setting.
Supported On:
Not available
Folder Redirection
Data collected on: 2/2/2026 4:58:57 PM
General
Details
Domain JoeCorp.lan
Owner JOECORP\Domain Admins
Created 1/16/2026 5:48:54 PM
Modified 1/16/2026 6:18:50 PM
User Revisions 26 (AD), 26 (SYSVOL)
Computer Revisions 0 (AD), 0 (SYSVOL)
Unique ID {2C846B00-8D39-47EC-BEC4-30AD47B42B09}
GPO Status Enabled
Links
Location Enforced Link Status Path
GPO No Enabled JoeCorp.lan/GPO
Standard Users No Enabled JoeCorp.lan/UsersOU/Standard Users

This list only includes links in the domain of the GPO.
Security Filtering
The settings in this GPO can only apply to the following groups, users, and computers:
Name
JOECORP\HomeDriveUsers
Delegation
These groups and users have the specified permission for this GPO
Name Allowed Permissions Inherited
JOECORP\Domain Admins Edit settings, delete, modify security No
JOECORP\Enterprise Admins Edit settings, delete, modify security No
JOECORP\HomeDriveUsers Read (from Security Filtering) No
NT AUTHORITY\Authenticated Users Read No
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS Read No
NT AUTHORITY\SYSTEM Edit settings, delete, modify security No
Computer Configuration (Enabled)
No settings defined.
User Configuration (Enabled)
Policies
Windows Settings
Folder Redirection
AppData(Roaming)
Setting: Basic (Redirect everyone's folder to the same location)
Path: \\SRV01.JoeCorp.lan\Home$\%USERNAME%\AppData\Roaming
Options
Grant user exclusive rights to AppData(Roaming) Enabled
Move the contents of AppData(Roaming) to the new location Enabled
Also apply redirection policy to Windows 2000, Windows 2000 server, Windows XP, and Windows Server 2003 operating systems Disabled
Policy Removal Behavior Restore contents
Configuration Control Group Policy
Primary Computer Evaluation Not evaluated because primary computer policy is not enabled
Contacts
Setting: Basic (Redirect everyone's folder to the same location)
Path: \\SRV01.JoeCorp.lan\Home$\%USERNAME%\Contacts
Options
Grant user exclusive rights to Contacts Enabled
Move the contents of Contacts to the new location Enabled
Also apply redirection policy to Windows 2000, Windows 2000 server, Windows XP, and Windows Server 2003 operating systems Disabled
Policy Removal Behavior Restore contents
Configuration Control Group Policy
Primary Computer Evaluation Not evaluated because primary computer policy is not enabled
Desktop
Setting: Basic (Redirect everyone's folder to the same location)
Path: \\SRV01.JoeCorp.lan\Home$\%USERNAME%\Desktop
Options
Grant user exclusive rights to Desktop Enabled
Move the contents of Desktop to the new location Enabled
Also apply redirection policy to Windows 2000, Windows 2000 server, Windows XP, and Windows Server 2003 operating systems Disabled
Policy Removal Behavior Restore contents
Configuration Control Group Policy
Primary Computer Evaluation Not evaluated because primary computer policy is not enabled
Documents
Setting: Basic (Redirect everyone's folder to the same location)
Path: \\SRV01.JoeCorp.lan\Home$\%USERNAME%\Documents
Options
Grant user exclusive rights to Documents Enabled
Move the contents of Documents to the new location Enabled
Also apply redirection policy to Windows 2000, Windows 2000 server, Windows XP, and Windows Server 2003 operating systems Disabled
Policy Removal Behavior Restore contents
Configuration Control Group Policy
Primary Computer Evaluation Not evaluated because primary computer policy is not enabled
Downloads
Setting: Basic (Redirect everyone's folder to the same location)
Path: \\SRV01.JoeCorp.lan\Home$\%USERNAME%\Downloads
Options
Grant user exclusive rights to Downloads Enabled
Move the contents of Downloads to the new location Enabled
Also apply redirection policy to Windows 2000, Windows 2000 server, Windows XP, and Windows Server 2003 operating systems Disabled
Policy Removal Behavior Restore contents
Configuration Control Group Policy
Primary Computer Evaluation Not evaluated because primary computer policy is not enabled
Favorites
Setting: Basic (Redirect everyone's folder to the same location)
Path: \\SRV01.JoeCorp.lan\Home$\%USERNAME%\Favorites
Options
Grant user exclusive rights to Favorites Enabled
Move the contents of Favorites to the new location Enabled
Also apply redirection policy to Windows 2000, Windows 2000 server, Windows XP, and Windows Server 2003 operating systems Disabled
Policy Removal Behavior Restore contents
Configuration Control Group Policy
Primary Computer Evaluation Not evaluated because primary computer policy is not enabled
Links
Setting: Basic (Redirect everyone's folder to the same location)
Path: \\SRV01.JoeCorp.lan\Home$\%USERNAME%\Links
Options
Grant user exclusive rights to Links Enabled
Move the contents of Links to the new location Enabled
Also apply redirection policy to Windows 2000, Windows 2000 server, Windows XP, and Windows Server 2003 operating systems Disabled
Policy Removal Behavior Restore contents
Configuration Control Group Policy
Primary Computer Evaluation Not evaluated because primary computer policy is not enabled
Music
Setting: Basic (Redirect everyone's folder to the same location)
Path: \\SRV01.JoeCorp.lan\Home$\%USERNAME%\Music
Options
Grant user exclusive rights to Music Enabled
Move the contents of Music to the new location Enabled
Also apply redirection policy to Windows 2000, Windows 2000 server, Windows XP, and Windows Server 2003 operating systems Disabled
Policy Removal Behavior Restore contents
Configuration Control Group Policy
Primary Computer Evaluation Not evaluated because primary computer policy is not enabled
Pictures
Setting: Basic (Redirect everyone's folder to the same location)
Path: \\SRV01.JoeCorp.lan\Home$\%USERNAME%\Pictures
Options
Grant user exclusive rights to Pictures Enabled
Move the contents of Pictures to the new location Enabled
Also apply redirection policy to Windows 2000, Windows 2000 server, Windows XP, and Windows Server 2003 operating systems Disabled
Policy Removal Behavior Restore contents
Configuration Control Group Policy
Primary Computer Evaluation Not evaluated because primary computer policy is not enabled
Saved Games
Setting: Basic (Redirect everyone's folder to the same location)
Path: \\SRV01.JoeCorp.lan\Home$\%USERNAME%\Saved Games
Options
Grant user exclusive rights to Saved Games Enabled
Move the contents of Saved Games to the new location Enabled
Also apply redirection policy to Windows 2000, Windows 2000 server, Windows XP, and Windows Server 2003 operating systems Disabled
Policy Removal Behavior Restore contents
Configuration Control Group Policy
Primary Computer Evaluation Not evaluated because primary computer policy is not enabled
Searches
Setting: Basic (Redirect everyone's folder to the same location)
Path: \\SRV01.JoeCorp.lan\Home$\%USERNAME%\Searches
Options
Grant user exclusive rights to Searches Enabled
Move the contents of Searches to the new location Enabled
Also apply redirection policy to Windows 2000, Windows 2000 server, Windows XP, and Windows Server 2003 operating systems Disabled
Policy Removal Behavior Restore contents
Configuration Control Group Policy
Primary Computer Evaluation Not evaluated because primary computer policy is not enabled
Start Menu
Setting: Basic (Redirect everyone's folder to the same location)
Path: \\SRV01.JoeCorp.lan\Home$\%USERNAME%\Start Menu
Options
Grant user exclusive rights to Start Menu Enabled
Move the contents of Start Menu to the new location Enabled
Also apply redirection policy to Windows 2000, Windows 2000 server, Windows XP, and Windows Server 2003 operating systems Disabled
Policy Removal Behavior Restore contents
Configuration Control Group Policy
Primary Computer Evaluation Not evaluated because primary computer policy is not enabled
Videos
Setting: Basic (Redirect everyone's folder to the same location)
Path: \\SRV01.JoeCorp.lan\Home$\%USERNAME%\Videos
Options
Grant user exclusive rights to Videos Enabled
Move the contents of Videos to the new location Enabled
Also apply redirection policy to Windows 2000, Windows 2000 server, Windows XP, and Windows Server 2003 operating systems Disabled
Policy Removal Behavior Restore contents
Configuration Control Group Policy
Primary Computer Evaluation Not evaluated because primary computer policy is not enabled
Default Domain Policy
Group Policy Management
body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } }
Setting Path:
Explanation
No explanation is available for this setting.
Supported On:
Not available
Default Domain Policy
Data collected on: 2/2/2026 4:58:57 PM
General
Details
Domain JoeCorp.lan
Owner JOECORP\Domain Admins
Created 1/10/2026 4:02:40 PM
Modified 1/10/2026 4:02:40 PM
User Revisions 0 (AD), 0 (SYSVOL)
Computer Revisions 1 (AD), 1 (SYSVOL)
Unique ID {31B2F340-016D-11D2-945F-00C04FB984F9}
GPO Status Enabled
Links
Location Enforced Link Status Path
JoeCorp No Enabled JoeCorp.lan

This list only includes links in the domain of the GPO.
Security Filtering
The settings in this GPO can only apply to the following groups, users, and computers:
Name
NT AUTHORITY\Authenticated Users
Delegation
These groups and users have the specified permission for this GPO
Name Allowed Permissions Inherited
NT AUTHORITY\Authenticated Users Read (from Security Filtering) No
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS Read No
NT AUTHORITY\SYSTEM Edit settings, delete, modify security No
Computer Configuration (Enabled)
Policies
Windows Settings
Security Settings
Account Policies/Password Policy
Policy Setting
Enforce password history 24 passwords remembered
Maximum password age 42 days
Minimum password age 1 days
Minimum password length 7 characters
Password must meet complexity requirements Enabled
Store passwords using reversible encryption Disabled
Account Policies/Account Lockout Policy
Policy Setting
Account lockout threshold 0 invalid logon attempts
Account Policies/Kerberos Policy
Policy Setting
Enforce user logon restrictions Enabled
Maximum lifetime for service ticket 600 minutes
Maximum lifetime for user ticket 10 hours
Maximum lifetime for user ticket renewal 7 days
Maximum tolerance for computer clock synchronization 5 minutes
Local Policies/Security Options
Network Access
Policy Setting
Network access: Allow anonymous SID/Name translation Disabled
Network Security
Policy Setting
Enabled
Network security: Force logoff when logon hours expire Disabled
User Configuration (Enabled)
No settings defined.
Default Domain Controllers Policy
Group Policy Management
body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } }
Setting Path:
Explanation
No explanation is available for this setting.
Supported On:
Not available
Default Domain Controllers Policy
Data collected on: 2/2/2026 4:58:57 PM
General
Details
Domain JoeCorp.lan
Owner JOECORP\Domain Admins
Created 1/10/2026 4:02:40 PM
Modified 1/10/2026 4:02:40 PM
User Revisions 0 (AD), 0 (SYSVOL)
Computer Revisions 1 (AD), 1 (SYSVOL)
Unique ID {6AC1786C-016F-11D2-945F-00C04fB984F9}
GPO Status Enabled
Links
Location Enforced Link Status Path
Domain Controllers No Enabled JoeCorp.lan/Domain Controllers

This list only includes links in the domain of the GPO.
Security Filtering
The settings in this GPO can only apply to the following groups, users, and computers:
Name
NT AUTHORITY\Authenticated Users
Delegation
These groups and users have the specified permission for this GPO
Name Allowed Permissions Inherited
NT AUTHORITY\Authenticated Users Read (from Security Filtering) No
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS Read No
NT AUTHORITY\SYSTEM Edit settings, delete, modify security No
Computer Configuration (Enabled)
Policies
Windows Settings
Security Settings
Local Policies/User Rights Assignment
Policy Setting
Access this computer from the network BUILTIN\Pre-Windows 2000 Compatible Access, NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS, NT AUTHORITY\Authenticated Users, BUILTIN\Administrators, Everyone
Add workstations to domain NT AUTHORITY\Authenticated Users
Adjust memory quotas for a process BUILTIN\Administrators, NT AUTHORITY\NETWORK SERVICE, NT AUTHORITY\LOCAL SERVICE
Allow log on locally NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS, BUILTIN\Print Operators, BUILTIN\Server Operators, BUILTIN\Account Operators, BUILTIN\Backup Operators, BUILTIN\Administrators
Back up files and directories BUILTIN\Server Operators, BUILTIN\Backup Operators, BUILTIN\Administrators
Bypass traverse checking BUILTIN\Pre-Windows 2000 Compatible Access, NT AUTHORITY\Authenticated Users, BUILTIN\Administrators, NT AUTHORITY\NETWORK SERVICE, NT AUTHORITY\LOCAL SERVICE, Everyone
Change the system time BUILTIN\Server Operators, BUILTIN\Administrators, NT AUTHORITY\LOCAL SERVICE
Create a pagefile BUILTIN\Administrators
Debug programs BUILTIN\Administrators
Enable computer and user accounts to be trusted for delegation BUILTIN\Administrators
Force shutdown from a remote system BUILTIN\Server Operators, BUILTIN\Administrators
Generate security audits NT AUTHORITY\NETWORK SERVICE, NT AUTHORITY\LOCAL SERVICE
Increase scheduling priority Window Manager\Window Manager Group, BUILTIN\Administrators
Load and unload device drivers BUILTIN\Print Operators, BUILTIN\Administrators
Log on as a batch job BUILTIN\Performance Log Users, BUILTIN\Backup Operators, BUILTIN\Administrators
Manage auditing and security log BUILTIN\Administrators
Modify firmware environment values BUILTIN\Administrators
Profile single process BUILTIN\Administrators
Profile system performance NT SERVICE\WdiServiceHost, BUILTIN\Administrators
Remove computer from docking station BUILTIN\Administrators
Replace a process level token NT AUTHORITY\NETWORK SERVICE, NT AUTHORITY\LOCAL SERVICE
Restore files and directories BUILTIN\Server Operators, BUILTIN\Backup Operators, BUILTIN\Administrators
Shut down the system BUILTIN\Print Operators, BUILTIN\Server Operators, BUILTIN\Backup Operators, BUILTIN\Administrators
Take ownership of files or other objects BUILTIN\Administrators
Local Policies/Security Options
Domain Controller
Policy Setting
Domain controller: LDAP server signing requirements None
Domain Member
Policy Setting
Domain member: Digitally encrypt or sign secure channel data (always) Enabled
Microsoft Network Server
Policy Setting
Microsoft network server: Digitally sign communications (always) Enabled
Microsoft network server: Digitally sign communications (if client agrees) Enabled
User Configuration (Enabled)
No settings defined.
PerfSettings
Group Policy Management
body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } }
Setting Path:
Explanation
No explanation is available for this setting.
Supported On:
Not available
PerfSettings
Data collected on: 2/2/2026 4:58:57 PM
General
Details
Domain JoeCorp.lan
Owner JOECORP\Domain Admins
Created 1/16/2026 8:17:04 PM
Modified 1/16/2026 8:46:00 PM
User Revisions 48 (AD), 48 (SYSVOL)
Computer Revisions 0 (AD), 0 (SYSVOL)
Unique ID {B468B8D7-E0EC-4F75-947F-60590DBB8A0C}
GPO Status Enabled
Links
Location Enforced Link Status Path
UsersOU No Enabled JoeCorp.lan/UsersOU

This list only includes links in the domain of the GPO.
Security Filtering
The settings in this GPO can only apply to the following groups, users, and computers:
Name
JOECORP\Domain Users
Delegation
These groups and users have the specified permission for this GPO
Name Allowed Permissions Inherited
JOECORP\Domain Admins Edit settings, delete, modify security No
JOECORP\Domain Computers Read No
JOECORP\Domain Users Read (from Security Filtering) No
JOECORP\Enterprise Admins Edit settings, delete, modify security No
NT AUTHORITY\Authenticated Users Read No
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS Read No
NT AUTHORITY\SYSTEM Edit settings, delete, modify security No
Computer Configuration (Enabled)
No settings defined.
User Configuration (Enabled)
Preferences
Windows Settings
Registry
VisualFXSetting (Order: 1)
General
Action Replace
Properties
Hive HKEY_CURRENT_USER
Key path Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects
Value name VisualFXSetting
Value type REG_DWORD
Value data 0x2 (2)
Common
Options
Stop processing items on this extension if an error occurs on this item No
Run in logged-on user's security context (user policy option) Yes
Remove this item when it is no longer applied No
Apply once and do not reapply No
UserPreferencesMask (Order: 2)
General
Action Replace
Properties
Hive HKEY_CURRENT_USER
Key path Control Panel\Desktop
Value name UserPreferencesMask
Value type REG_BINARY
Value data 9012038010000000
Common
Options
Stop processing items on this extension if an error occurs on this item No
Run in logged-on user's security context (user policy option) Yes
Remove this item when it is no longer applied No
Apply once and do not reapply No
DragFullWindows (Order: 3)
General
Action Replace
Properties
Hive HKEY_CURRENT_USER
Key path Control Panel\Desktop
Value name DragFullWindows
Value type REG_SZ
Value data 0
Common
Options
Stop processing items on this extension if an error occurs on this item No
Run in logged-on user's security context (user policy option) No
Remove this item when it is no longer applied No
Apply once and do not reapply No
MinAnimate (Order: 4)
General
Action Replace
Properties
Hive HKEY_CURRENT_USER
Key path Control Panel\Desktop\WindowMetrics
Value name MinAnimate
Value type REG_SZ
Value data 0
Common
Options
Stop processing items on this extension if an error occurs on this item No
Run in logged-on user's security context (user policy option) No
Remove this item when it is no longer applied No
Apply once and do not reapply No
DataDriveMount
Group Policy Management
body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } }
Setting Path:
Explanation
No explanation is available for this setting.
Supported On:
Not available
DataDriveMount
Data collected on: 2/2/2026 4:58:57 PM
General
Details
Domain JoeCorp.lan
Owner JOECORP\Domain Admins
Created 1/16/2026 6:39:54 PM
Modified 1/16/2026 7:04:04 PM
User Revisions 16 (AD), 16 (SYSVOL)
Computer Revisions 0 (AD), 0 (SYSVOL)
Unique ID {D57A2155-6FAB-42E9-8018-DD2DA86EFD55}
GPO Status Enabled
Links
Location Enforced Link Status Path
GPO No Enabled JoeCorp.lan/GPO
UsersOU No Enabled JoeCorp.lan/UsersOU

This list only includes links in the domain of the GPO.
Security Filtering
The settings in this GPO can only apply to the following groups, users, and computers:
Name
JOECORP\DataUsers
Delegation
These groups and users have the specified permission for this GPO
Name Allowed Permissions Inherited
JOECORP\DataUsers Read (from Security Filtering) No
JOECORP\Domain Admins Edit settings, delete, modify security No
JOECORP\Enterprise Admins Edit settings, delete, modify security No
NT AUTHORITY\Authenticated Users Read No
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS Read No
NT AUTHORITY\SYSTEM Edit settings, delete, modify security No
Computer Configuration (Enabled)
No settings defined.
User Configuration (Enabled)
Preferences
Windows Settings
Drive Maps
Drive Map (Drive: J)
J: (Order: 1)
General
Action Update
Properties
Letter J
Location \\SRV01.JoeCorp.lan\Data
Reconnect Enabled
Label as Corporate Data
Use first available Disabled
Hide/Show this drive Show
Hide/Show all drives No change
Common
Options
Stop processing items on this extension if an error occurs on this item No
Run in logged-on user's security context (user policy option) Yes
Remove this item when it is no longer applied No
Apply once and do not reapply No