Jump to content

CD Writing Wizard breaks after applying security policy


Recommended Posts

Guest awrightus@gmail.com
Posted

Using Windows 2003 Standard. Prior to implementing a custom local

security policy, the CD Writing Wizard (native Win2K CD burning) works

fine. IMAPI service starts, no problems. After applying my custom

template, the CD Writing Wizard gets to the point where you select

"Write these files to CD", assign label, and then it says there's no

disc in the drive. My security template is definitely breaking this.

"Recording" tab on device still has CD recording "enabled". Not using

"Restrict CD-ROM access to locally logged-on user only" in my policy.

Here's the kicker. I have determined that if I grant the "Lock pages

in memory" right in my local security policy (to my administrator

account), then the CD Writing Wizard again works. But that particular

user right isn't granted by default prior to implementing my policy,

so what else would be coming into play here? Any insight

appreciated. Thanks.

 

Steve

  • Replies 1
  • Created
  • Last Reply

Popular Days

Guest awrightus@gmail.com
Posted

Re: CD Writing Wizard breaks after applying security policy

 

On Oct 16, 9:16 am, awrigh...@gmail.com wrote:

> Using Windows 2003 Standard.  Prior to implementing a custom local

> security policy, the CD Writing Wizard (native Win2K CD burning) works

> fine.  IMAPI service starts, no problems.  After applying my custom

> template, the CD Writing Wizard gets to the point where you select

> "Write these files to CD", assign label, and then it says there's no

> disc in the drive.  My security template is definitely breaking this.

> "Recording" tab on device still has CD recording "enabled".  Not using

> "Restrict CD-ROM access to locally logged-on user only" in my policy.

> Here's the kicker.  I have determined that if I grant the "Lock pages

> in memory" right in my local security policy (to my administrator

> account), then the CD Writing Wizard again works.  But that particular

> user right isn't granted by default prior to implementing my policy,

> so what else would be coming into play here?  Any insight

> appreciated.  Thanks.

>

> Steve

 

Here's my custom template:

 

[unicode]

Unicode=yes

 

[system Access]

MinimumPasswordAge = 1

MaximumPasswordAge = 60

MinimumPasswordLength = 9

PasswordComplexity = 1

PasswordHistorySize = 5

LockoutBadCount = 3

ResetLockoutCount = 60

LockoutDuration = 60

RequireLogonToChangePassword = 0

ForceLogoffWhenHourExpire = 1

NewAdministratorName = "other_admin"

NewGuestName = "other_guest"

ClearTextPassword = 0

LSAAnonymousNameLookup = 0

EnableGuestAccount = 0

 

[system Log]

MaximumLogSize = 16384

AuditLogRetentionPeriod = 2

RestrictGuestAccess = 1

 

[security Log]

MaximumLogSize = 81920

AuditLogRetentionPeriod = 2

RestrictGuestAccess = 1

 

[Application Log]

MaximumLogSize = 16384

AuditLogRetentionPeriod = 2

RestrictGuestAccess = 1

 

[Event Audit]

AuditSystemEvents = 1

AuditLogonEvents = 3

AuditObjectAccess = 2

AuditPrivilegeUse = 2

AuditPolicyChange = 1

AuditAccountManage = 3

AuditAccountLogon = 3

 

[File Security]

%SystemRoot%\regedit.exe,2,"D:PAR(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)"

%SystemRoot%\system32\arp.exe,2,"D:PAR(A;OICI;FA;;;BA)

(A;OICI;FA;;;SY)"

%SystemRoot%\system32\at.exe,2,"D:PAR(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)"

%SystemRoot%\system32\attrib.exe,2,"D:PAR(A;OICI;FA;;;BA)

(A;OICI;FA;;;SY)"

%SystemRoot%\system32\cacls.exe,2,"D:PAR(A;OICI;FA;;;BA)

(A;OICI;FA;;;SY)"

%SystemRoot%\system32\debug.exe,2,"D:PAR(A;OICI;FA;;;BA)

(A;OICI;FA;;;SY)"

%SystemRoot%\system32\edlin.exe,2,"D:PAR(A;OICI;FA;;;BA)

(A;OICI;FA;;;SY)"

%SystemRoot%\system32\eventcreate.exe,2,"D:PAR(A;OICI;FA;;;BA)

(A;OICI;FA;;;SY)"

%SystemRoot%\system32\eventtriggers.exe,2,"D:PAR(A;OICI;FA;;;BA)

(A;OICI;FA;;;SY)"

%SystemRoot%\system32\ftp.exe,2,"D:PAR(A;OICI;FA;;;BA)

(A;OICI;FA;;;SY)"

%SystemRoot%\system32\nbtstat.exe,2,"D:PAR(A;OICI;FA;;;BA)

(A;OICI;FA;;;SY)"

%SystemRoot%\system32\net.exe,2,"D:PAR(A;OICI;FA;;;BA)

(A;OICI;FA;;;SY)"

%SystemRoot%\system32\net1.exe,2,"D:PAR(A;OICI;FA;;;BA)

(A;OICI;FA;;;SY)"

%SystemRoot%\system32\netsh.exe,2,"D:PAR(A;OICI;FA;;;BA)

(A;OICI;FA;;;SY)"

%SystemRoot%\system32\netstat.exe,2,"D:PAR(A;OICI;FA;;;BA)

(A;OICI;FA;;;SY)"

%SystemRoot%\system32\nslookup.exe,2,"D:PAR(A;OICI;FA;;;BA)

(A;OICI;FA;;;SY)"

%SystemRoot%\system32\ntbackup.exe,2,"D:PAR(A;OICI;FA;;;BA)

(A;OICI;FA;;;SY)"

%SystemRoot%\system32\rcp.exe,2,"D:PAR(A;OICI;FA;;;BA)

(A;OICI;FA;;;SY)"

%SystemRoot%\system32\reg.exe,2,"D:PAR(A;OICI;FA;;;BA)

(A;OICI;FA;;;SY)"

%SystemRoot%\system32\regedt32.exe,2,"D:PAR(A;OICI;FA;;;BA)

(A;OICI;FA;;;SY)"

%SystemRoot%\system32\regini.exe,2,"D:PAR(A;OICI;FA;;;BA)

(A;OICI;FA;;;SY)"

%SystemRoot%\system32\regsvr32.exe,2,"D:PAR(A;OICI;FA;;;BA)

(A;OICI;FA;;;SY)"

%SystemRoot%\system32\rexec.exe,2,"D:PAR(A;OICI;FA;;;BA)

(A;OICI;FA;;;SY)"

%SystemRoot%\system32\route.exe,2,"D:PAR(A;OICI;FA;;;BA)

(A;OICI;FA;;;SY)"

%SystemRoot%\system32\rsh.exe,2,"D:PAR(A;OICI;FA;;;BA)

(A;OICI;FA;;;SY)"

%SystemRoot%\system32\sc.exe,2,"D:PAR(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)"

%SystemRoot%\system32\secedit.exe,2,"D:PAR(A;OICI;FA;;;BA)

(A;OICI;FA;;;SY)"

%SystemRoot%\system32\subst.exe,2,"D:PAR(A;OICI;FA;;;BA)

(A;OICI;FA;;;SY)"

%SystemRoot%\system32\systeminfo.exe,2,"D:PAR(A;OICI;FA;;;BA)

(A;OICI;FA;;;SY)"

%SystemRoot%\system32\telnet.exe,2,"D:PAR(A;OICI;FA;;;BA)

(A;OICI;FA;;;SY)"

%SystemRoot%\system32\tftp.exe,2,"D:PAR(A;OICI;FA;;;BA)

(A;OICI;FA;;;SY)"

%SystemRoot%\system32\tlntsvr.exe,2,"D:PAR(A;OICI;FA;;;BA)

(A;OICI;FA;;;SY)"

 

[service General Setting]

Alerter,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

ALG,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)

(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

AppMgmt,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

aspnet_state,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

CiSvc,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)

(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

ClipSrv,4,"D:AR(A;OICI;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

COMSysApp,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

ERSvc,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)

(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

helpsvc,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

HidServ,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

LicenseService,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

Messenger,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

mnmsrvc,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

MSDTC,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)

(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

NetDDE,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

NetDDEdsdm,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

RasAuto,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

RasMan,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

RDSessMgr,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

RemoteAccess,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

RemoteRegistry,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

RSoPProv,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

sacsvr,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

SharedAccess,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

stisvc,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

TapiSrv,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

TermService,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

Themes,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

TlntSvr,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

TrkSvr,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

TrkWks,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

Tssdis,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

uploadmgr,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

vds,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)

(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

wuauserv,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

WebClient,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

WinHttpAutoProxySvc,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

WmdmPmSN,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

WZCSVC,4,"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)"

 

[Version]

signature="$CHICAGO$"

Revision=1

 

[Privilege Rights]

 

; Access this computer from the network

SeNetworkLogonRight = *S-1-5-32-544,Web Users,Operator_Acct

 

; Act as a part of the operating system

SeTcbPrivilege =

 

; Add workstations to domain

semachineaccountprivilege =

 

; Adjust memory quotas for a process

seincreasequotaprivilege = *S-1-5-32-544,*S-1-5-19,*S-1-5-20

 

;Allow log on locally

SeInteractiveLogonRight = *S-1-5-32-551,*S-1-5-32-544,Operator_Acct

 

; Allow log on through Terminal Services

SeRemoteInteractiveLogonRight =

 

; Back up files and directories

sebackupprivilege = *S-1-5-32-544,*S-1-5-32-551

 

; Bypass traverse checking

sechangenotifyprivilege = *S-1-5-11

 

; Change the system time

sesystemtimeprivilege = *S-1-5-32-544,*S-1-5-19

 

; Create a pagefile

secreatepagefileprivilege = *S-1-5-32-544

 

; Create a token object

secreatetokenprivilege =

 

; Create global objects

SeCreateGlobalPrivilege = *S-1-5-32-544,*S-1-5-6

 

; Create permanent shaerd objects

secreatepermanentprivilege =

 

; Debug programs

sedebugprivilege =

 

; Deny access to this computer from the network

sedenynetworklogonright = *S-1-5-7,*S-1-5-32-546,Support_388945a0

 

; Deny log on as a batch job

sedenybatchlogonright = *S-1-5-32-546,Support_388945a0

 

; Deny log on as a service

sedenyservicelogonright =

 

; Deny log on locally

sedenyinteractivelogonright = *S-1-5-32-546,Support_388945a0,Web Users

 

; Deny log on through Terminal Services

SeDenyRemoteInteractiveLogonRight = *S-1-1-0

 

; Enable computer and user accounts to be trusted for delegation

seenabledelegationprivilege = *S-1-5-32-544

 

; Force shutdown from a remote system

seremoteshutdownprivilege = *S-1-5-32-544

 

; Generate security audits

seauditprivilege = *S-1-5-19,*S-1-5-20

 

; Impersonate a client after authentication

SeImpersonatePrivilege = *S-1-5-32-544,*S-1-5-6

 

; Increase scheduling priority

seincreasebasepriorityprivilege = *S-1-5-32-544

 

; Load and unload device drivers

seloaddriverprivilege = *S-1-5-32-544

 

; Lock pages in memory

selockmemoryprivilege =

 

;Logon on as a batch job

SeBatchLogonRight =

 

; Logon on as a service

SeServiceLogonRight = *S-1-5-20

 

; Manage auditing and security log

SeSecurityPrivilege = Auditors

 

; Modify firmware environment values

sesystemenvironmentprivilege = *S-1-5-32-544

 

; Perform volume maintenance tasks

SeManageVolumePrivilege = *S-1-5-32-544

 

; Profile single process

seprofilesingleprocessprivilege = *S-1-5-32-544

 

; Profile system performance

sesystemprofileprivilege = *S-1-5-32-544

 

; Remove computer from docking station

seundockprivilege = *S-1-5-32-544

 

; Replace a process level token

seassignprimarytokenprivilege = *S-1-5-19,*S-1-5-20

 

; Restore files and directories

serestoreprivilege = *S-1-5-32-544,*S-1-5-32-551

 

; Shut down the system

seshutdownprivilege = *S-1-5-32-544,Operator_Acct

 

; Synchronize directory service data

sesyncagentprivilege =

 

; Take ownership of files or other objects

setakeownershipprivilege = *S-1-5-32-544

 

 

[Group Membership]

Power Users__Memberof =

Power Users__Members =

 

[Registry Values]

MACHINE\SOFTWARE\Microsoft\Driver Signing\Policy=3,1

MACHINE\SOFTWARE\Microsoft\non-driver signing\policy=3,1

MACHINE\SOFTWARE\Microsoft\Windows NT\currentversion\setup

\recoveryconsole\securitylevel=4,0

MACHINE\SOFTWARE\Microsoft\Windows NT\currentversion\setup

\recoveryconsole\setcommand=4,0

MACHINE\SOFTWARE\Microsoft\Windows NT\currentversion\winlogon

\allocatedasd=1,"0"

MACHINE\SOFTWARE\Microsoft\Windows NT\currentversion\winlogon

\allocatefloppies=1,"1"

MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

\AutoAdminLogon=1,"0"

MACHINE\SOFTWARE\Microsoft\Windows NT\currentversion\winlogon

\cachedlogonscount=1,"2"

MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

\ForceUnlockLogon=4,1

MACHINE\SOFTWARE\Microsoft\Windows NT\currentversion\winlogon

\passwordexpirywarning=4,14

MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

\ScreenSaverGracePeriod=4,0

MACHINE\SOFTWARE\Microsoft\Windows NT\currentversion\winlogon

\scremoveoption=1,"1"

MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket

\NukeOnDelete=4,1

MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer

\NoDriveTypeAutoRun=4,255

MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies

\NetworkHideSharePwds=4,1

MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies

\NetworkNoDialIn=4,1

MACHINE\SOFTWARE\Microsoft\Windows\currentversion\policies\system

\disablecad=4,0

MACHINE\SOFTWARE\Microsoft\Windows\currentVersion\policies\system

\DontDisplayLastUserName=4,1

MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System

\LegalNoticeCaption=1,"SECURITY BANNER"

MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System

\LegalNoticeText=7,PUT SECURITY BANNER HERE.

MACHINE\SOFTWARE\Microsoft\Windows\currentversion\policies\system

\shutdownwithoutlogon=4,0

MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System

\UndockWithoutLogon=4,0

MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon

\ScreenSaverGracePeriod=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Conferencing\NoRDS=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Cryptography

\ForceKeyProtection=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Control Panel

\Autoconfig=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Control Panel

\DisableDeleteBrowsingHistory=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Control Panel

\DisableRIED=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Control Panel

\History=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Download

\CheckExeSignatures=1,"yes"

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Download

\RunInvalidSignatures=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\InfoDelivery

\Restrictions\NoJITSetup=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\InfoDelivery

\Restrictions\NoSplash=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\InfoDelivery

\Restrictions\NoUpdateCheck=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main

\DisableFirstRunCustomize=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main

\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL\(Reserved)=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main

\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL\explorer.exe=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main

\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL\iexplore.exe=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main

\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\Settings

\LOCALMACHINE_CD_UNLOCK=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main

\FeatureControl\FEATURE_MIME_HANDLING\(Reserved)=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main

\FeatureControl\FEATURE_MIME_HANDLING\explorer.exe=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main

\FeatureControl\FEATURE_MIME_HANDLING\iexplore.exe=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main

\FeatureControl\FEATURE_MIME_SNIFFING\(Reserved)=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main

\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL\(Reserved)=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main

\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL\explorer.exe=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main

\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL\iexplore.exe=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main

\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\(Reserved)=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main

\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\explorer.exe=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main

\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\iexplore.exe=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main

\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\(Reserved)=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main

\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\explorer.exe=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main

\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\iexplore.exe=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main

\FeatureControl\FEATURE_ZONE_ELEVATION\(Reserved)=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main

\FeatureControl\FEATURE_ZONE_ELEVATION\explorer.exe=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main

\FeatureControl\FEATURE_ZONE_ELEVATION\iexplore.exe=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main

\NoUpdateCheck=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main

\Update_Check_Interval=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main

\Update_Check_Page=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\PhishingFilter

\Enabled=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Restrictions

\NoCrashDetection=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Security

\DisableSecuritySettingsCheck=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\SQM

\DisableCustomerImprovementProgram=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Messenger\Client\{9b017612-

c9f1-11d2-8d9f-0000f875c541\Disabled=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Messenger\Client

\PreventAutoRun=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Messenger\Client\PreventRun=4,1

MACHINE\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting

\DoReport=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\Winlogon

\SyncForegroundPolicy=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DCOM

\MachineAccessRestriction=1,"O:BAG:BAD:(A;;CCDC;;;AN)

(A;;CCDCLC;;;S-1-5-32-562)(A;;CCDCLC;;;WD)"

MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DCOM

\MachineLaunchRestriction=1,"O:BAG:BAD:(A;;CCDCLCSWRP;;;BA)

(A;;CCDCLCSWRP;;;S-1-5-32-562)(A;;CCDCSW;;;WD)"

MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Printers

\DisableWebPrinting=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Printers

\KMPrintersAreBlocked=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services

\DeleteTempDirsOnExit=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services

\fAllowToGetHelp=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services

\fAllowUnsolicited=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services

\fEncryptRPCTraffic=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services

\fPromptForPassword=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services

\fReconnectSame=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services

\fResetBroken=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services

\fSingleSessionPerUser=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services

\fWritableTSCCPermTab=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services

\MaxDisconnectionTime=4,60000

MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services

\MaxIdleTime=4,900000

MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services

\MaxInstanceCount=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services

\MinEncryptionLevel=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services

\PerSessionTempDir=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services

\Shadow=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\CertificateRevocation=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Lockdown_Zones\0\1C00=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Lockdown_Zones\1\1C00=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Lockdown_Zones\2\1C00=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Lockdown_Zones\3\1C00=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Lockdown_Zones\4\1C00=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\ProxySettingsPerUser=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Security_HKLM_only=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Security_Options_Edit=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Security_Zones_Map_Edit=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Url History\DaysToKeep=4,40

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\ZoneMap\UNCAsIntranet=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\0\1C00=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\1\1C00=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\2\1C00=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\3\1001=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\3\1004=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\3\1201=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\3\1208=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\3\1209=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\3\1406=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\3\1407=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\3\1604=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\3\1606=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\3\1607=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\3\1800=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\3\1802=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\3\1804=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\3\1809=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\3\1A00=4,65536

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\3\1C00=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\3\1E05=4,1

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\3\2100=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\3\2101=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\3\2102=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\3\2103=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\3\2200=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\3\2402=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\1001=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\1004=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\1200=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\1201=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\1208=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\1400=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\1402=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\1405=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\1406=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\1407=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\1604=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\1606=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\1607=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\1608=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\1800=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\1802=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\1803=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\1804=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\1809=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\1A00=4,196608

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\1C00=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\1E05=4,65536

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\2000=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\2001=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\2004=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\2100=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\2101=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\2102=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\2103=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\2200=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet

Settings\Zones\4\2402=4,3

MACHINE\SOFTWARE\Policies\Microsoft\Windows\Group Policy

\{35378EAC-683F-11D2-A89A-00C04FBBCFA2\NoBackgroundPolicy=4,0

MACHINE\SOFTWARE\Policies\Microsoft\Windows\Group Policy

\{35378EAC-683F-11D2-A89A-00C04FBBCFA2\NoGPOListChanges=4,0

MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers

\AuthenticodeEnabled=4,1

MACHINE\SOFTWARE\Policies\Microsoft\WindowsMediaPlayer

\DisableAutoupdate=4,1

MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AuditBaseObjects=4,0

MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\CrashOnAuditFail=4,0

MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\DisableDomainCreds=4,1

MACHINE\SYSTEM\CurrentControlSet\Control\Lsa

\EveryoneIncludesAnonymous=4,0

MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\FIPSAlgorithmPolicy=4,1

MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\ForceGuest=4,0

MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\FullPrivilegeAuditing=3,0

MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\LimitBlankPasswordUse=4,1

MACHINE\SYSTEM\CurrentControlSet\Control\lsa\lmcompatibilitylevel=4,5

MACHINE\SYSTEM\CurrentControlSet\Control\Lsa

\MSV1_0\NTLMMinClientSec=4,537395248

MACHINE\SYSTEM\CurrentControlSet\Control\Lsa

\MSV1_0\NTLMMinServerSec=4,537395248

MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\NoDefaultAdminOwner=4,1

MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\NoLMHash=4,1

MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\RestrictAnonymous=4,1

MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\RestrictAnonymousSAM=4,1

MACHINE\SYSTEM\CurrentControlSet\Control\print\providers\lanman print

services\servers\addprinterdrivers=4,1

MACHINE\SYSTEM\CurrentControlSet\Control\SecurePipeServers\Winreg

\AllowedExactPaths\Machine=7,System\CurrentControlSet\Control

\ProductOptions,System\CurrentControlSet\Control\Server

Applications,Software\Microsoft\Windows NT\CurrentVersion

MACHINE\SYSTEM\CurrentControlSet\Control\SecurePipeServers\Winreg

\AllowedPaths\Machine=7,Software\Microsoft\Windows NT\CurrentVersion

\Print,Software\Microsoft\Windows NT\CurrentVersion\Windows,System

\CurrentControlSet\Control\Print\Printers,System\CurrentControlSet

\Services\Eventlog,Software\Microsoft\OLAP Server,System

\CurrentControlSet\Control\ContentIndex,System\CurrentControlSet

\Control\Terminal Server,System\CurrentControlSet\Control\Terminal

Server\UserConfig,System\CurrentControlSet\Control\Terminal Server

\DefaultUserConfiguration,Software\Microsoft\Windows NT\CurrentVersion

\Perflib,System\CurrentControlSet\Services\SysmonLog

MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Kernel

\ObCaseInsensitive=4,1

MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory

Management\ClearPageFileAtShutdown=4,1

MACHINE\SYSTEM\CurrentControlSet\Control\session manager

\protectionmode=4,1

MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager

\SafeDllSearchMode=4,1

MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems

\optional=7,

MACHINE\SYSTEM\CurrentControlSet\Services\AFD\Parameters

\DynamicBacklogGrowthDelta=4,10

MACHINE\SYSTEM\CurrentControlSet\Services\AFD\Parameters

\EnableDynamicBacklog=4,1

MACHINE\SYSTEM\CurrentControlSet\Services\AFD\Parameters

\MaximumDynamicBacklog=4,20000

MACHINE\SYSTEM\CurrentControlSet\Services\AFD\Parameters

\MinimumDynamicBacklog=4,10

MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Autorun=4,0

MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security

\WarningLevel=4,90

MACHINE\SYSTEM\CurrentControlSet\Services\HTTP\Parameters

\EnableNonUTF8=4,1

MACHINE\SYSTEM\CurrentControlSet\Services\HTTP\Parameters

\FavorUTF8=4,1

MACHINE\SYSTEM\CurrentControlSet\Services\HTTP\Parameters

\PercentUAllowed=4,0

MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters

\autodisconnect=4,15

MACHINE\SYSTEM\CurrentControlSet\Services\LanManServer\Parameters

\EnableForcedLogOff=4,1

MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters

\enablesecuritysignature=4,1

MACHINE\SYSTEM\CurrentControlSet\Services\LanManServer\Parameters

\NullSessionPipes=7,COMNAP,COMNODE,SQL

\QUERY,SPOOLSS,LLSRPC,Netlogon,Lsarpc,Samr,Browser

MACHINE\SYSTEM\CurrentControlSet\Services\LanManServer\Parameters

\NullSessionShares=7,

MACHINE\SYSTEM\CurrentControlSet\Services\LanManServer\Parameters

\RequireSecuritySignature=4,1

MACHINE\SYSTEM\CurrentControlSet\Services\LanManServer\Parameters

\RestrictNullSessAccess=4,1

MACHINE\SYSTEM\CurrentControlSet\Services\lanmanworkstation\parameters

\enableplaintextpassword=4,0

MACHINE\SYSTEM\CurrentControlSet\Services\lanmanworkstation\parameters

\enablesecuritysignature=4,1

MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters

\RequireSecuritySignature=4,1

MACHINE\SYSTEM\CurrentControlSet\Services\LDAP\LDAPClientIntegrity=4,1

MACHINE\SYSTEM\CurrentControlSet\Services\Netbt\Parameters

\NoNameReleaseOnDemand=4,1

MACHINE\SYSTEM\CurrentControlSet\Services\netlogon\parameters

\disablepasswordchange=4,0

MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters

\MaximumPasswordAge=4,30

MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters

\RequireSignOrSeal=4,1

MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters

\RequireStrongKey=4,1

MACHINE\SYSTEM\CurrentControlSet\Services\netlogon\parameters

\sealsecurechannel=4,1

MACHINE\SYSTEM\CurrentControlSet\Services\netlogon\parameters

\signsecurechannel=4,1

MACHINE\SYSTEM\CurrentControlSet\Services\Rasman\Parameters

\DisableSavePassword=4,1

MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters

\DisableIPSourceRouting=4,2

MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters

\EnableDeadGWDetect=4,0

MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters

\EnableICMPRedirect=4,0

MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters

\KeepAliveTime=4,300000

MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters

\PerformRouterDiscovery=4,0

MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters

\SynAttackProtect=4,1

MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters

\TcpMaxConnectResponseRetransmissions=4,2

MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters

\TcpMaxDataRetransmissions=4,3

MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters

\TCPMaxPortsExhausted=4,5

 

[Profile Description]

Description=Custom security template


×
×
  • Create New...