ÿþ<html dir="ltr" xmlns:v="urn:schemas-microsoft-com:vml" gpmc_reportInitialized="false"> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-16" /> <title>UC - Domain Controller</title> <!-- Styles --> <style type="text/css"> body { background-color:#FFFFFF; border:1px solid #666666; color:#000000; font-size:68%; font-family:Tahoma; margin:0,0,10px,0; word-break:normal; word-wrap:break-word; } table { font-size:100%; table-layout:fixed; width:100%; } td,th { overflow:visible; text-align:left; vertical-align:top; white-space:normal; } .title { background:#FFFFFF; border:none; color:#333333; display:block; height:24px; margin:0px,0px,-1px,0px; padding-top:4px; position:relative; table-layout:fixed; width:100%; z-index:5; } .he0_expanded { background-color:#FEF7D6; border:1px solid #BBBBBB; color:#3333CC; cursor:hand; display:block; font-family:Tahoma; font-size:100%; font-weight:bold; height:2.25em; margin-bottom:-1px; margin-left:0px; margin-right:0px; padding-left:8px; padding-right:5em; padding-top:4px; position:relative; width:100%; } .he1_expanded { background-color:#A0BACB; border:1px solid #BBBBBB; color:#000000; cursor:hand; display:block; font-family:Tahoma; font-size:100%; font-weight:bold; height:2.25em; margin-bottom:-1px; margin-left:10px; margin-right:0px; padding-left:8px; padding-right:5em; padding-top:4px; position:relative; width:100%; } .he1 { background-color:#A0BACB; border:1px solid #BBBBBB; color:#000000; cursor:hand; display:block; font-family:Tahoma; font-size:100%; font-weight:bold; height:2.25em; margin-bottom:-1px; margin-left:10px; margin-right:0px; padding-left:8px; padding-right:5em; padding-top:4px; position:relative; width:100%; } .he2 { background-color:#C0D2DE; border:1px solid #BBBBBB; color:#000000; cursor:hand; display:block; font-family:Tahoma; font-size:100%; font-weight:bold; height:2.25em; margin-bottom:-1px; margin-left:20px; margin-right:0px; padding-left:8px; padding-right:5em; padding-top:4px; position:relative; width:100%; } .he3 { background-color:#D9E3EA; border:1px solid #BBBBBB; color:#000000; cursor:hand; display:block; font-family:Tahoma; font-size:100%; font-weight:bold; height:2.25em; margin-bottom:-1px; margin-left:30px; margin-right:0px; padding-left:11px; padding-right:5em; padding-top:4px; position:relative; width:100%; } .he4 { background-color:#E8E8E8; border:1px solid #BBBBBB; color:#000000; cursor:hand; display:block; font-family:Tahoma; font-size:100%; font-weight:bold; height:2.25em; margin-bottom:-1px; margin-left:40px; margin-right:0px; padding-left:11px; padding-right:5em; padding-top:4px; position:relative; width:100%; } .he4h { background-color:#E8E8E8; border:1px solid #BBBBBB; color:#000000; cursor:hand; display:block; font-family:Tahoma; font-size:100%; font-weight:bold; height:2.25em; margin-bottom:-1px; margin-left:45px; margin-right:0px; padding-left:11px; padding-right:5em; padding-top:4px; position:relative; width:100%; } .he4i { background-color:#F9F9F9; border:1px solid #BBBBBB; color:#000000; display:block; font-family:Tahoma; font-size:100%; margin-bottom:-1px; margin-left:45px; margin-right:0px; padding-bottom:5px; padding-left:21px; padding-top:4px; position:relative; width:100%; } .he5 { background-color:#E8E8E8; border:1px solid #BBBBBB; color:#000000; cursor:hand; display:block; font-family:Tahoma; font-size:100%; font-weight:bold; height:2.25em; margin-bottom:-1px; margin-left:50px; margin-right:0px; padding-left:11px; padding-right:5em; padding-top:4px; position:relative; width:100%; } .he5h { background-color:#E8E8E8; border:1px solid #BBBBBB; color:#000000; cursor:hand; display:block; font-family:Tahoma; font-size:100%; padding-left:11px; padding-right:5em; padding-top:4px; margin-bottom:-1px; margin-left:55px; margin-right:0px; position:relative; width:100%; } .he5i { background-color:#F9F9F9; border:1px solid #BBBBBB; color:#000000; display:block; font-family:Tahoma; font-size:100%; margin-bottom:-1px; margin-left:55px; margin-right:0px; padding-left:21px; padding-bottom:5px; padding-top: 4px; position:relative; width:100%; } DIV .expando { color:#000000; text-decoration:none; display:block; font-family:Tahoma; font-size:100%; font-weight:normal; position:absolute; right:10px; text-decoration:underline; z-index: 0; } .he0 .expando { font-size:100%; } .info, .info3, .info4, .disalign { line-height:1.6em; padding:0px,0px,0px,0px; margin:0px,0px,0px,0px; } .disalign TD { padding-bottom:5px; padding-right:10px; } .info TD { padding-right:10px; width:50%; } .info3 TD { padding-right:10px; width:33%; } .info4 TD, .info4 TH { padding-right:10px; width:25%; } .info TH, .info3 TH, .info4 TH, .disalign TH { border-bottom:1px solid #CCCCCC; padding-right:10px; } .subtable, .subtable3 { border:1px solid #CCCCCC; margin-left:0px; background:#FFFFFF; margin-bottom:10px; } .subtable TD, .subtable3 TD { padding-left:10px; padding-right:5px; padding-top:3px; padding-bottom:3px; line-height:1.1em; width:10%; } .subtable TH, .subtable3 TH { border-bottom:1px solid #CCCCCC; font-weight:normal; padding-left:10px; line-height:1.6em; } .subtable .footnote { border-top:1px solid #CCCCCC; } .subtable3 .footnote, .subtable .footnote { border-top:1px solid #CCCCCC; } .subtable_frame { background:#D9E3EA; border:1px solid #CCCCCC; margin-bottom:10px; margin-left:15px; } .subtable_frame TD { line-height:1.1em; padding-bottom:3px; padding-left:10px; padding-right:15px; padding-top:3px; } .subtable_frame TH { border-bottom:1px solid #CCCCCC; font-weight:normal; padding-left:10px; line-height:1.6em; } .subtableInnerHead { border-bottom:1px solid #CCCCCC; border-top:1px solid #CCCCCC; } .explainlink { color:#000000; text-decoration:none; cursor:hand; } .explainlink:hover { color:#0000FF; text-decoration:underline; } .spacer { background:transparent; border:1px solid #BBBBBB; color:#FFFFFF; display:block; font-family:Tahoma; font-size:100%; height:10px; margin-bottom:-1px; margin-left:43px; margin-right:0px; padding-top: 4px; position:relative; } .filler { background:transparent; border:none; color:#FFFFFF; display:block; font:100% Tahoma; line-height:8px; margin-bottom:-1px; margin-left:43px; margin-right:0px; padding-top:4px; position:relative; } .container { display:block; position:relative; } .rsopheader { background-color:#A0BACB; border-bottom:1px solid black; color:#333333; font-family:Tahoma; font-size:130%; font-weight:bold; padding-bottom:5px; text-align:center; } .rsopname { color:#333333; font-family:tahoma; font-size:130%; font-weight:bold; padding-left:11px; } .gponame{ color:#333333; font-family:Tahoma; font-size:130%; font-weight:bold; padding-left:11px; } .gpotype{ color:#333333; font-family:Tahoma; font-size:100%; font-weight:bold; padding-left:11px; } #uri { color:#333333; font-family:Tahoma; font-size:100%; padding-left:11px; } #dtstamp{ color:#333333; font-family:Tahoma; font-size:100%; padding-left:11px; text-align:left; width:30%; } #objshowhide { color:#000000; cursor:hand; font-family:Tahoma; font-size:100%; font-weight:bold; margin-right:0px; padding-right:10px; text-align:right; text-decoration:underline; z-index:2; word-wrap:normal; } #gposummary { display:block; } #gpoinformation { display:block; } @media print { #objshowhide{ display:none; } body { color:#000000; border:1px solid #000000; } .title { color:#000000; border:1px solid #000000; } .he0_expanded { color:#000000; border:1px solid #000000; } .he1_expanded { color:#000000; border:1px solid #000000; } .he1 { color:#000000; border:1px solid #000000; } .he2 { color:#000000; background:#EEEEEE; border:1px solid #000000; } .he3 { color:#000000; border:1px solid #000000; } .he4 { color:#000000; border:1px solid #000000; } .he4h { color:#000000; border:1px solid #000000; } .he4i { color:#000000; border:1px solid #000000; } .he5 { color:#000000; border:1px solid #000000; } .he5h { color:#000000; border:1px solid #000000; } .he5i { color:#000000; border:1px solid #000000; } } v\:* {behavior:url(#default#VML);} </style> <!-- Script 1 --> <script language="vbscript"> <!-- '================================================================================ ' String "strShowHide(0/1)" ' 0 = Hide all mode. ' 1 = Show all mode. strShowHide = 1 'Localized strings strShow = "show" strHide = "hide" strShowAll = "show all" strHideAll = "hide all" strShown = "shown" strHidden = "hidden" strExpandoNumPixelsFromEdge = "10px" Function IsSectionHeader(obj) IsSectionHeader = (obj.className = "he0_expanded") Or (obj.className = "he1_expanded") Or (obj.className = "he1") Or (obj.className = "he2") Or (obj.className = "he3") Or (obj.className = "he4") Or (obj.className = "he4h") Or (obj.className = "he5") Or (obj.className = "he5h") End Function Function IsSectionExpandedByDefault(objHeader) IsSectionExpandedByDefault = (Right(objHeader.className, Len("_expanded")) = "_expanded") End Function ' strState must be show | hide | toggle Sub SetSectionState(objHeader, strState) ' Get the container object for the section. It's the first one after the header obj. i = objHeader.sourceIndex Set all = objHeader.parentElement.document.all While (all(i).className <> "container") i = i + 1 Wend Set objContainer = all(i) If strState = "toggle" Then If objContainer.style.display = "none" Then SetSectionState objHeader, "show" Else SetSectionState objHeader, "hide" End If Else Set objExpando = objHeader.children.item(1) If strState = "show" Then objContainer.style.display = "block" objExpando.innerText = strHide ElseIf strState = "hide" Then objContainer.style.display = "none" objExpando.innerText = strShow End If End If End Sub Sub ShowSection(objHeader) SetSectionState objHeader, "show" End Sub Sub HideSection(objHeader) SetSectionState objHeader, "hide" End Sub Sub ToggleSection(objHeader) SetSectionState objHeader, "toggle" End Sub '================================================================================ ' When user clicks anywhere in the document body, determine if user is clicking ' on a header element. '================================================================================ Function document_onclick() Set strsrc = window.event.srcElement While (strsrc.className = "sectionTitle" Or strsrc.className = "expando" Or strsrc.className = "vmlimage") Set strsrc = strsrc.parentElement Wend ' Only handle clicks on headers. If Not IsSectionHeader(strsrc) Then Exit Function ToggleSection strsrc window.event.returnValue = False End Function '================================================================================ ' link at the top of the page to collapse/expand all collapsable elements '================================================================================ Function objshowhide_onClick() Set objBody = document.body.all Select Case strShowHide Case 0 strShowHide = 1 objshowhide.innerText = strShowAll For Each obji In objBody If IsSectionHeader(obji) Then HideSection obji End If Next Case 1 strShowHide = 0 objshowhide.innerText = strHideAll For Each obji In objBody If IsSectionHeader(obji) Then ShowSection obji End If Next End Select End Function '================================================================================ ' onload collapse all except the first two levels of headers (he0, he1) '================================================================================ Function window_onload() ' Only initialize once. The UI may reinsert a report into the webbrowser control, ' firing onLoad multiple times. If UCase(document.documentElement.getAttribute("gpmc_reportInitialized")) <> "TRUE" Then ' Initialize sections to default expanded/collapsed state. Set objBody = document.body.all For Each obji in objBody If IsSectionHeader(obji) Then If IsSectionExpandedByDefault(obji) Then ShowSection obji Else HideSection obji End If End If Next objshowhide.innerText = strShowAll document.documentElement.setAttribute "gpmc_reportInitialized", "true" End If End Function '================================================================================ ' When direction (LTR/RTL) changes, change adjust for readability '================================================================================ Function document_onPropertyChange() If window.event.propertyName = "dir" Then Call fDetDir(UCase(document.dir)) End If End Function Function fDetDir(strDir) strDir = UCase(strDir) Select Case strDir Case "LTR" Set colRules = document.styleSheets(0).rules For i = 0 To colRules.length -1 Set nug = colRules.item(i) strClass = nug.selectorText If nug.style.textAlign = "right" Then nug.style.textAlign = "left" End If Select Case strClass Case "DIV .expando" nug.style.Left = "" nug.style.right = strExpandoNumPixelsFromEdge Case "#objshowhide" nug.style.textAlign = "right" End Select Next Case "RTL" Set colRules = document.styleSheets(0).rules For i = 0 To colRules.length -1 Set nug = colRules.item(i) strClass = nug.selectorText If nug.style.textAlign = "left" Then nug.style.textAlign = "right" End If Select Case strClass Case "DIV .expando" nug.style.Left = strExpandoNumPixelsFromEdge nug.style.right = "" Case "#objshowhide" nug.style.textAlign = "left" End Select Next End Select End Function '================================================================================ 'When printing reports, if a given section is expanded, let's says "shown" (instead of "hide" in the UI). '================================================================================ Function window_onbeforeprint() For Each obji In document.all If obji.className = "expando" Then If obji.innerText = strHide Then obji.innerText = strShown If obji.innerText = strShow Then obji.innerText = strHidden End If Next End Function '================================================================================ 'If a section is collapsed, change to "hidden" in the printout (instead of "show"). '================================================================================ Function window_onafterprint() For Each obji In document.all If obji.className = "expando" Then If obji.innerText = strShown Then obji.innerText = strHide If obji.innerText = strHidden Then obji.innerText = strShow End If Next End Function '================================================================================ ' Adding keypress support for accessibility '================================================================================ Function document_onKeyPress() If window.event.keyCode = "32" Or window.event.keyCode = "13" Or window.event.keyCode = "10" Then 'space bar (32) or carriage return (13) or line feed (10) If window.event.srcElement.className = "expando" Then Call document_onclick() : window.event.returnValue = false If window.event.srcElement.className = "sectionTitle" Then Call document_onclick() : window.event.returnValue = false If window.event.srcElement.id = "objshowhide" Then Call objshowhide_onClick() : window.event.returnValue = false End If End Function --> </script> <!-- Script 2 --> <script language="javascript"> <!-- function getExplainWindowTitle() { return document.getElementById("explainText_windowTitle").innerHTML; } function getExplainWindowStyles() { return document.getElementById("explainText_windowStyles").innerHTML; } function getExplainWindowSettingPathLabel() { return document.getElementById("explainText_settingPathLabel").innerHTML; } function getExplainWindowExplainTextLabel() { return document.getElementById("explainText_explainTextLabel").innerHTML; } function getExplainWindowPrintButton() { return document.getElementById("explainText_printButton").innerHTML; } function getExplainWindowCloseButton() { return document.getElementById("explainText_closeButton").innerHTML; } function getNoExplainTextAvailable() { return document.getElementById("explainText_noExplainTextAvailable").innerHTML; } function getExplainWindowSupportedLabel() { return document.getElementById("explainText_supportedLabel").innerHTML; } function getNoSupportedTextAvailable() { return document.getElementById("explainText_noSupportedTextAvailable").innerHTML; } function showExplainText(srcElement) { var strSettingName = srcElement.getAttribute("gpmc_settingName"); var strSettingPath = srcElement.getAttribute("gpmc_settingPath"); var strSettingDescription = srcElement.getAttribute("gpmc_settingDescription"); if (strSettingDescription == "") { strSettingDescription = getNoExplainTextAvailable(); } var strSupported = srcElement.getAttribute("gpmc_supported"); if (strSupported == "") { strSupported = getNoSupportedTextAvailable(); } var strHtml = "<html>\n"; strHtml += "<head>\n"; strHtml += "<title>" + getExplainWindowTitle() + "</title>\n"; strHtml += "<style type='text/css'>\n" + getExplainWindowStyles() + "</style>\n"; strHtml += "</head>\n"; strHtml += "<body>\n"; strHtml += "<div class='head'>" + strSettingName +"</div>\n"; strHtml += "<div class='path'><b>" + getExplainWindowSettingPathLabel() + "</b><br/>" + strSettingPath +"</div>\n"; strHtml += "<div class='path'><b>" + getExplainWindowSupportedLabel() + "</b><br/>" + strSupported +"</div>\n"; strHtml += "<div class='info'>\n"; strHtml += "<div class='hdr'>" + getExplainWindowExplainTextLabel() + "</div>\n"; strHtml += "<div class='bdy'>" + strSettingDescription + "</div>\n"; strHtml += "<div class='btn'>"; strHtml += getExplainWindowPrintButton(); strHtml += getExplainWindowCloseButton(); strHtml += "</div></body></html>"; var strDiagArgs = "height=360px, width=630px, status=no, toolbar=no, scrollbars=yes, resizable=yes "; var expWin = window.open("", "expWin", strDiagArgs); expWin.document.write(""); expWin.document.close(); expWin.document.write(strHtml); expWin.document.close(); expWin.focus(); //cancels navigation for IE. if(navigator.userAgent.indexOf("MSIE") > 0) { window.event.returnValue = false; } return false; } --> </script> </head> <body> <!-- HTML resources --> <div style="display:none;"> <div id="explainText_windowTitle">Group Policy Management</div> <div id="explainText_windowStyles"> body { font-size:68%;font-family:Tahoma; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:Tahoma; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:tahoma; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } } </div> <div id="explainText_settingPathLabel">Setting Path:</div> <div id="explainText_explainTextLabel">Explanation</div> <div id="explainText_printButton"> <button name="Print" onClick="window.print()" accesskey="P"><u>P</u>rint</button> </div> <div id="explainText_closeButton"> <button name="Close" onClick="window.close()" accesskey="C"><u>C</u>lose</button> </div> <div id="explainText_noExplainTextAvailable">No explanation is available for this setting.</div> <div id="explainText_supportedLabel">Supported On:</div> <div id="explainText_noSupportedTextAvailable">Not available</div> </div><table class="title" cellpadding="0" cellspacing="0"> <tr><td colspan="2" class="gponame">UC - Domain Controller</td></tr> <tr> <td id="dtstamp">Data collected on: 8/29/2003 3:10:29 PM</td> <td><div id="objshowhide" tabindex="0"></div></td> </tr> </table> <div class="gposummary"> <div class="he0_expanded"><span class="sectionTitle" tabindex="0">General</span><a class="expando" href="#"></a></div> <div class="container"><div class="he1"><span class="sectionTitle" tabindex="0">Details</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><td scope="row">Domain</td><td>uc.berkeley.edu</td></tr> <tr><td scope="row">Owner</td><td>UC\Domain Admins</td></tr> <tr><td scope="row">Created</td><td>11/21/2001 1:05:12 PM</td></tr> <tr><td scope="row">Modified</td><td>7/17/2003 1:19:06 PM</td></tr> <tr><td scope="row">User Revisions</td><td>0 (AD), 0 (sysvol)</td></tr> <tr><td scope="row">Computer Revisions</td><td>113 (AD), 113 (sysvol)</td></tr> <tr><td scope="row">Unique ID</td><td>{9DB135E4-4468-46AA-A57A-661115723908}</td></tr> <tr><td scope="row">GPO Status</td><td>User settings disabled</td></tr> </table></div></div> <div class="filler"></div> <div class="he1"><span class="sectionTitle" tabindex="0">Links</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info3" cellpadding="0" cellspacing="0"><tr><th scope="col">Location</th><th scope="col">Enforced</th><th scope="col">Link Status</th><th scope="col">Path</th></tr> <tr><td>Domain Controllers</td><td>No</td><td>Enabled</td><td>uc.berkeley.edu/Domain Controllers</td></tr> </table> <br/>This list only includes links in the domain of the GPO.</div></div> <div class="filler"></div> <div class="he1"><span class="sectionTitle" tabindex="0">Security Filtering</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><b>The settings in this GPO can only apply to the following groups, users, and computers:</b></div> <div class="he4i"> <table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Name</th></tr><tr><td>NT AUTHORITY\Authenticated Users</td></tr></table> </div> </div> <div class="filler"></div> <div class="he1"><span class="sectionTitle" tabindex="0">WMI Filtering</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><td scope="row"><b>WMI Filter Name</b></td><td>None</td></tr> <tr><td scope="row"><b>Description</b></td><td>Not applicable</td></tr> </table></div></div> <div class="filler"></div> <div class="he1"><span class="sectionTitle" tabindex="0">Delegation</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><b>These groups and users have the specified permission for this GPO</b></div> <div class="he4i"> <table class="info3" cellpadding="0" cellspacing="0"> <tr><th scope="col">Name</th><th scope="col">Allowed Permissions</th><th scope="col">Inherited</th></tr> <tr><td>NT AUTHORITY\Authenticated Users</td><td>Read (from Security Filtering)</td><td>No</td></tr> <tr><td>NT AUTHORITY\SYSTEM</td><td>Edit settings, delete, modify security</td><td>No</td></tr> <tr><td>UC\Domain Admins</td><td>Edit settings, delete, modify security</td><td>No</td></tr> <tr><td>UC\Enterprise Admins</td><td>Edit settings, delete, modify security</td><td>No</td></tr> </table> </div></div></div> <div class="filler"></div> </div> <div class="he0_expanded"><span class="sectionTitle" tabindex="0">Computer Configuration (Enabled)</span><a class="expando" href="#"></a></div> <div class="container"><div class="he1_expanded"><span class="sectionTitle" tabindex="0">Windows Settings</span><a class="expando" href="#"></a></div> <div class="container"><div class="he2"><span class="sectionTitle" tabindex="0">Scripts</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4"><span class="sectionTitle" tabindex="0">Shutdown</span><a class="expando" href="#"></a></div> <div class="container"> <div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Name</th><th scope="col">Parameters</th></tr> <tr><td>RPC_Ports.cmd</td><td></td></tr> </table> </div></div></div><div class="he2"><span class="sectionTitle" tabindex="0">Security Settings</span><a class="expando" href="#"></a></div> <div class="container"><div class="he3"><span class="sectionTitle" tabindex="0">Local Policies/Audit Policy</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td>Audit account logon events</td><td>Success, Failure</td></tr> <tr><td>Audit account management</td><td>Success, Failure</td></tr> <tr><td>Audit directory service access</td><td>Failure</td></tr> <tr><td>Audit logon events</td><td>Success, Failure</td></tr> <tr><td>Audit object access</td><td>Failure</td></tr> <tr><td>Audit policy change</td><td>Success, Failure</td></tr> <tr><td>Audit privilege use</td><td>Failure</td></tr> <tr><td>Audit process tracking</td><td>No auditing</td></tr> <tr><td>Audit system events</td><td>Success, Failure</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Local Policies/User Rights Assignment</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td>Access this computer from the network</td><td>BUILTIN\Administrators, NT AUTHORITY\Authenticated Users</td></tr> <tr><td>Act as part of the operating system</td><td></td></tr> <tr><td>Add workstations to domain</td><td></td></tr> <tr><td>Adjust memory quotas for a process</td><td>BUILTIN\Administrators</td></tr> <tr><td>Allow log on locally</td><td>BUILTIN\Administrators</td></tr> <tr><td>Back up files and directories</td><td>BUILTIN\Administrators</td></tr> <tr><td>Bypass traverse checking</td><td>NT AUTHORITY\Authenticated Users</td></tr> <tr><td>Change the system time</td><td>BUILTIN\Administrators</td></tr> <tr><td>Create a pagefile</td><td>BUILTIN\Administrators</td></tr> <tr><td>Create a token object</td><td></td></tr> <tr><td>Create permanent shared objects</td><td></td></tr> <tr><td>Debug programs</td><td></td></tr> <tr><td>Deny access to this computer from the network</td><td></td></tr> <tr><td>Deny log on as a batch job</td><td></td></tr> <tr><td>Deny log on as a service</td><td></td></tr> <tr><td>Deny log on locally</td><td></td></tr> <tr><td>Enable computer and user accounts to be trusted for delegation</td><td>BUILTIN\Administrators</td></tr> <tr><td>Force shutdown from a remote system</td><td>BUILTIN\Administrators</td></tr> <tr><td>Generate security audits</td><td></td></tr> <tr><td>Increase scheduling priority</td><td>BUILTIN\Administrators</td></tr> <tr><td>Load and unload device drivers</td><td>BUILTIN\Administrators</td></tr> <tr><td>Lock pages in memory</td><td></td></tr> <tr><td>Log on as a batch job</td><td></td></tr> <tr><td>Log on as a service</td><td>UC\!svcRoboMon</td></tr> <tr><td>Manage auditing and security log</td><td>BUILTIN\Administrators</td></tr> <tr><td>Modify firmware environment values</td><td>BUILTIN\Administrators</td></tr> <tr><td>Profile single process</td><td>BUILTIN\Administrators</td></tr> <tr><td>Profile system performance</td><td>BUILTIN\Administrators</td></tr> <tr><td>Remove computer from docking station</td><td></td></tr> <tr><td>Replace a process level token</td><td></td></tr> <tr><td>Restore files and directories</td><td>BUILTIN\Administrators</td></tr> <tr><td>Shut down the system</td><td>BUILTIN\Administrators</td></tr> <tr><td>Synchronize directory service data</td><td></td></tr> <tr><td>Take ownership of files or other objects</td><td>BUILTIN\Administrators</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Local Policies/Security Options</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4h"><span class="sectionTitle" tabindex="0">Other</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td>Audit: Audit the access of global system objects</td><td>Enabled</td></tr> <tr><td>Audit: Audit the use of Backup and Restore privilege</td><td>Enabled</td></tr> <tr><td>Audit: Shut down system immediately if unable to log security audits</td><td>Disabled</td></tr> <tr><td>Devices: Allowed to format and eject removable media</td><td>Administrators</td></tr> <tr><td>Devices: Disable Media Autoplay (UCB)</td><td>All Drives</td></tr> <tr><td>Devices: Prevent users from installing printer drivers</td><td>Enabled</td></tr> <tr><td>Devices: Restrict CD-ROM access to locally logged-on user only</td><td>Enabled</td></tr> <tr><td>Devices: Restrict floppy access to locally logged-on user only</td><td>Enabled</td></tr> <tr><td>Devices: Unsigned driver installation behavior</td><td>Silently succeed </td></tr> <tr><td>Devices: Unsigned non-driver installation behavior (UCB)</td><td>Silently succeed </td></tr> <tr><td>Domain controller: Allow server operators to schedule tasks</td><td>Disabled</td></tr> <tr><td>Domain member: Digitally encrypt or sign secure channel data (always)</td><td>Disabled</td></tr> <tr><td>Domain member: Digitally encrypt secure channel data (when possible)</td><td>Enabled</td></tr> <tr><td>Domain member: Digitally sign secure channel data (when possible)</td><td>Enabled</td></tr> <tr><td>Domain member: Disable machine account password changes</td><td>Disabled</td></tr> <tr><td>Domain member: Require strong (Windows 2000 or later) session key</td><td>Disabled</td></tr> <tr><td>Interactive logon: Allow Automatic Administrator Logon (UCB)</td><td>Disabled</td></tr> <tr><td>Interactive logon: Do not display last user name</td><td>Enabled</td></tr> <tr><td>Interactive logon: Do not require CTRL+ALT+DEL</td><td>Disabled</td></tr> <tr><td>Interactive logon: Number of previous logons to cache (in case domain controller is not available)</td><td>0 logons</td></tr> <tr><td>Interactive logon: Prompt user to change password before expiration</td><td>14 days</td></tr> <tr><td>Interactive logon: Smart card removal behavior</td><td>Lock Workstation</td></tr> <tr><td>Microsoft network client: Digitally sign communications (always)</td><td>Disabled</td></tr> <tr><td>Microsoft network client: Digitally sign communications (if server agrees)</td><td>Enabled</td></tr> <tr><td>Microsoft network client: Send unencrypted password to third-party SMB servers</td><td>Disabled</td></tr> <tr><td>Microsoft network server: Amount of idle time required before suspending session</td><td>30 minutes</td></tr> <tr><td>Microsoft network server: Digitally sign communications (always)</td><td>Disabled</td></tr> <tr><td>Microsoft network server: Digitally sign communications (if client agrees)</td><td>Enabled</td></tr> <tr><td>Microsoft network server: Disconnect clients when logon hours expire</td><td>Enabled</td></tr> <tr><td>Network access: Do not allow anonymous enumeration of SAM accounts and shares</td><td>Enabled</td></tr> <tr><td>Network access: Remotely accessible registry paths and sub-paths</td><td>Software\Microsoft\Windows NT\CurrentVersion</td></tr> <tr><td>Network security: DoS: Computer does not release its NetBIOS name when it receives a name-release request from the network (UCB)</td><td>Enabled</td></tr> <tr><td>Network security: DoS: Controls whether Windows 2000 will alter its route table in response to ICMP redirect messages (UCB)</td><td>Disabled</td></tr> <tr><td>Network security: DoS: How often TCP attempts to verify that an idle connection is still intact by sending a keep-alive packet (UCB)</td><td>300000</td></tr> <tr><td>Network security: DoS: Number of connections in the SYN-RCVD state allowed before SYN-ATTACK protection begins to operate (UCB)</td><td>Advanced Server</td></tr> <tr><td>Network security: DoS: Number of connections in the SYN-RCVD state for which there has been at least one retransmission of the SYN sent before SYN-ATTACK attack protection begins to operate (UCB)</td><td>Advanced Server</td></tr> <tr><td>Network security: DoS: Syn attack protection (UCB)</td><td>Reduced retransmission retries &amp; delayed RCE creation</td></tr> <tr><td>Network security: DoS: TCP attempts to discover the MTU over the path to a remote host (UCB)</td><td>Enabled</td></tr> <tr><td>Network security: DoS: TCP is allowed to perform dead-gateway detection (UCB)</td><td>Disabled</td></tr> <tr><td>Network security: LAN Manager authentication level</td><td>Send NTLMv2 response only\refuse LM &amp; NTLM</td></tr> <tr><td>Network security: Minimum session security for NTLM SSP based (including secure RPC) clients</td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable" cellpadding="0" cellspacing="0"><tr><td>Require message integrity</td><td>Enabled</td></tr> <tr><td>Require message confidentiality</td><td>Enabled</td></tr> <tr><td>Require NTLMv2 session security</td><td>Enabled</td></tr> <tr><td>Require 128-bit encryption</td><td>Enabled</td></tr> </table></td></tr><tr><td>Network security: Minimum session security for NTLM SSP based (including secure RPC) servers</td><td>Enabled</td></tr> <tr><td colspan="2"><table class="subtable" cellpadding="0" cellspacing="0"><tr><td>Require message integrity</td><td>Enabled</td></tr> <tr><td>Require message confidentiality</td><td>Enabled</td></tr> <tr><td>Require NTLMv2 session security</td><td>Enabled</td></tr> <tr><td>Require 128-bit encryption</td><td>Enabled</td></tr> </table></td></tr><tr><td>Recovery console: Allow automatic administrative logon</td><td>Disabled</td></tr> <tr><td>Recovery console: Allow floppy copy and access to all drives and all folders</td><td>Disabled</td></tr> <tr><td>Shutdown: Allow system to be shut down without having to log on</td><td>Disabled</td></tr> <tr><td>Shutdown: Clear virtual memory pagefile</td><td>Enabled</td></tr> <tr><td>System objects: Strengthen default permissions of internal system objects (e.g. Symbolic Links)</td><td>Enabled</td></tr> <tr><td>WSH: Allow remote scripts to execute on this machine (UCB)</td><td>Disabled</td></tr> </table> </div></div><div class="he4h"><span class="sectionTitle" tabindex="0">Registry Values</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td>MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\NoLMHash\NOP</td><td>1</td></tr> </table> </div></div></div><div class="he3"><span class="sectionTitle" tabindex="0">Event Log</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td>Maximum application log size</td><td>99968 kilobytes</td></tr> <tr><td>Maximum security log size</td><td>99968 kilobytes</td></tr> <tr><td>Maximum system log size</td><td>99968 kilobytes</td></tr> <tr><td>Prevent local guests group from accessing application log</td><td>Enabled</td></tr> <tr><td>Prevent local guests group from accessing security log</td><td>Enabled</td></tr> <tr><td>Prevent local guests group from accessing system log</td><td>Enabled</td></tr> <tr><td>Retain application log</td><td>7 days</td></tr> <tr><td>Retain security log</td><td>7 days</td></tr> <tr><td>Retain system log</td><td>7 days</td></tr> <tr><td>Retention method for application log</td><td>As needed</td></tr> <tr><td>Retention method for security log</td><td>As needed</td></tr> <tr><td>Retention method for system log</td><td>As needed</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Restricted Groups</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info3" cellpadding="0" cellspacing="0"> <tr><th scope="col">Group</th><th scope="col">Members</th><th scope="col">Member of</th></tr> <tr><td>BUILTIN\Account Operators</td><td></td><td></td></tr> <tr><td>BUILTIN\Administrators</td><td>CAMPUS\CCS-Projects-OA-gs, UC\!svchfnetchk, UC\!svcRoboMon, UC\Domain Admins, UC\Enterprise Admins, UC\Krishna</td><td></td></tr> <tr><td>BUILTIN\Backup Operators</td><td></td><td></td></tr> <tr><td>BUILTIN\Print Operators</td><td></td><td></td></tr> <tr><td>BUILTIN\Replicator</td><td></td><td></td></tr> <tr><td>BUILTIN\Server Operators</td><td></td><td></td></tr> <tr><td>Pre-Windows 2000 Compatible Access</td><td></td><td></td></tr> <tr><td>UC\DnsAdmins</td><td></td><td></td></tr> <tr><td>UC\DnsUpdateProxy</td><td></td><td></td></tr> <tr><td>UC\Domain Admins</td><td>UC\!010024528-ua, UC\!apineda-ua, uc\!eric-ua, UC\!o-o-ua, UC\!svcRoboMon</td><td>BUILTIN\Administrators</td></tr> <tr><td>UC\Domain Guests</td><td>UC\Guest</td><td>BUILTIN\Guests</td></tr> <tr><td>UC\Group Policy Creator Owners</td><td></td><td></td></tr> <tr><td>UC\RAS and IAS Servers</td><td></td><td></td></tr> <tr><td>UC\TelnetClients</td><td></td><td></td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">System Services</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4h"><span class="sectionTitle" tabindex="0">Computer Browser (Startup Mode: Disabled)</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><b>Permissions</b><table class="subtable3" cellpadding="0" cellspacing="0"> <tr><th scope="col">Type</th><th scope="col">Name</th><th scope="col">Permission</th></tr><tr><td>Allow</td><td>BUILTIN\Administrators</td><td>Full Control</td></tr><tr><td>Allow</td><td>NT AUTHORITY\SYSTEM</td><td>Full Control</td></tr></table> </div><div class="he4i"><b>Auditing</b><br/>No auditing specified</div></div><div class="he4h"><span class="sectionTitle" tabindex="0">fax (Startup Mode: Disabled)</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><b>Permissions</b><table class="subtable3" cellpadding="0" cellspacing="0"> <tr><th scope="col">Type</th><th scope="col">Name</th><th scope="col">Permission</th></tr><tr><td>Allow</td><td>NT AUTHORITY\Authenticated Users</td><td>Read</td></tr><tr><td>Allow</td><td>CAMPUS\Domain Admins</td><td>Full Control</td></tr><tr><td>Allow</td><td>NT AUTHORITY\SYSTEM</td><td>Full Control</td></tr></table> </div><div class="he4i"><b>Auditing</b><br/>No auditing specified</div></div><div class="he4h"><span class="sectionTitle" tabindex="0">iisadmin (Startup Mode: Disabled)</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><b>Permissions</b><table class="subtable3" cellpadding="0" cellspacing="0"> <tr><th scope="col">Type</th><th scope="col">Name</th><th scope="col">Permission</th></tr><tr><td>Allow</td><td>BUILTIN\Administrators</td><td>Full Control</td></tr><tr><td>Allow</td><td>NT AUTHORITY\SYSTEM</td><td>Full Control</td></tr></table> </div><div class="he4i"><b>Auditing</b><br/>No auditing specified</div></div><div class="he4h"><span class="sectionTitle" tabindex="0">LicenseService (Startup Mode: Disabled)</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><b>Permissions</b><table class="subtable3" cellpadding="0" cellspacing="0"> <tr><th scope="col">Type</th><th scope="col">Name</th><th scope="col">Permission</th></tr><tr><td>Allow</td><td>BUILTIN\Administrators</td><td>Full Control</td></tr><tr><td>Allow</td><td>NT AUTHORITY\SYSTEM</td><td>Full Control</td></tr></table> </div><div class="he4i"><b>Auditing</b><br/>No auditing specified</div></div><div class="he4h"><span class="sectionTitle" tabindex="0">msftpsvc (Startup Mode: Disabled)</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><b>Permissions</b><table class="subtable3" cellpadding="0" cellspacing="0"> <tr><th scope="col">Type</th><th scope="col">Name</th><th scope="col">Permission</th></tr><tr><td>Allow</td><td>BUILTIN\Administrators</td><td>Full Control</td></tr><tr><td>Allow</td><td>NT AUTHORITY\SYSTEM</td><td>Full Control</td></tr></table> </div><div class="he4i"><b>Auditing</b><br/>No auditing specified</div></div><div class="he4h"><span class="sectionTitle" tabindex="0">nntpsvc (Startup Mode: Disabled)</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><b>Permissions</b><table class="subtable3" cellpadding="0" cellspacing="0"> <tr><th scope="col">Type</th><th scope="col">Name</th><th scope="col">Permission</th></tr><tr><td>Allow</td><td>BUILTIN\Administrators</td><td>Full Control</td></tr><tr><td>Allow</td><td>NT AUTHORITY\SYSTEM</td><td>Full Control</td></tr></table> </div><div class="he4i"><b>Auditing</b><br/>No auditing specified</div></div><div class="he4h"><span class="sectionTitle" tabindex="0">smtpsvc (Startup Mode: Disabled)</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><b>Permissions</b><table class="subtable3" cellpadding="0" cellspacing="0"> <tr><th scope="col">Type</th><th scope="col">Name</th><th scope="col">Permission</th></tr><tr><td>Allow</td><td>BUILTIN\Administrators</td><td>Full Control</td></tr><tr><td>Allow</td><td>NT AUTHORITY\SYSTEM</td><td>Full Control</td></tr></table> </div><div class="he4i"><b>Auditing</b><br/>No auditing specified</div></div><div class="he4h"><span class="sectionTitle" tabindex="0">Telephony (Startup Mode: Manual)</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><b>Permissions</b><table class="subtable3" cellpadding="0" cellspacing="0"> <tr><th scope="col">Type</th><th scope="col">Name</th><th scope="col">Permission</th></tr><tr><td>Allow</td><td>BUILTIN\Administrators</td><td>Full Control</td></tr><tr><td>Allow</td><td>NT AUTHORITY\Authenticated Users</td><td>Read</td></tr><tr><td>Allow</td><td>NT AUTHORITY\SYSTEM</td><td>Full Control</td></tr></table> </div><div class="he4i"><b>Auditing</b><br/>No auditing specified</div></div><div class="he4h"><span class="sectionTitle" tabindex="0">Telnet (Startup Mode: Disabled)</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><b>Permissions</b><table class="subtable3" cellpadding="0" cellspacing="0"> <tr><th scope="col">Type</th><th scope="col">Name</th><th scope="col">Permission</th></tr><tr><td>Allow</td><td>BUILTIN\Administrators</td><td>Full Control</td></tr><tr><td>Allow</td><td>NT AUTHORITY\SYSTEM</td><td>Full Control</td></tr></table> </div><div class="he4i"><b>Auditing</b><br/>No auditing specified</div></div><div class="he4h"><span class="sectionTitle" tabindex="0">w3svc (Startup Mode: Disabled)</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><b>Permissions</b><table class="subtable3" cellpadding="0" cellspacing="0"> <tr><th scope="col">Type</th><th scope="col">Name</th><th scope="col">Permission</th></tr><tr><td>Allow</td><td>BUILTIN\Administrators</td><td>Full Control</td></tr><tr><td>Allow</td><td>NT AUTHORITY\SYSTEM</td><td>Full Control</td></tr></table> </div><div class="he4i"><b>Auditing</b><br/>No auditing specified</div></div></div><div class="he3"><span class="sectionTitle" tabindex="0">Registry</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4h"><span class="sectionTitle" tabindex="0">classes_root</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i">Configure this key then: Replace existing permissions on all subkeys with inheritable permissions</div><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><td scope="row"><b>Owner</b></td><td></td></tr> </table> </div><div class="he4i"><b>Permissions</b><table class="subtable3" cellpadding="0" cellspacing="0"> <tr><th scope="col">Type</th><th scope="col">Name</th><th scope="col">Permission</th><th scope="col">Apply To</th></tr><tr><td>Allow</td><td>BUILTIN\Administrators</td><td>Full control</td><td>This key and subkeys</td></tr><tr><td>Allow</td><td>NT AUTHORITY\Authenticated Users</td><td>Read</td><td>This key and subkeys</td></tr><tr><td>Allow</td><td>CREATOR OWNER</td><td>Full control</td><td>Subkeys only</td></tr><tr><td>Allow</td><td>NT AUTHORITY\SYSTEM</td><td>Full control</td><td>This key and subkeys</td></tr></table> <table class="subtable" cellspacing="0" cellpadding="0"> <tr><td scope="row">Allow inheritable permissions from the parent to propagate to this object and all child objects</td><td>Disabled</td></tr> </table> </div><div class="he4i"><b>Auditing</b><br/>No auditing specified</div></div><div class="he4h"><span class="sectionTitle" tabindex="0">machine\software</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i">Configure this key then: Replace existing permissions on all subkeys with inheritable permissions</div><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><td scope="row"><b>Owner</b></td><td></td></tr> </table> </div><div class="he4i"><b>Permissions</b><table class="subtable3" cellpadding="0" cellspacing="0"> <tr><th scope="col">Type</th><th scope="col">Name</th><th scope="col">Permission</th><th scope="col">Apply To</th></tr><tr><td>Allow</td><td>BUILTIN\Administrators</td><td>Full control</td><td>This key and subkeys</td></tr><tr><td>Allow</td><td>NT AUTHORITY\Authenticated Users</td><td>Read</td><td>This key and subkeys</td></tr><tr><td>Allow</td><td>CREATOR OWNER</td><td>Full control</td><td>Subkeys only</td></tr><tr><td>Allow</td><td>NT AUTHORITY\SYSTEM</td><td>Full control</td><td>This key and subkeys</td></tr></table> <table class="subtable" cellspacing="0" cellpadding="0"> <tr><td scope="row">Allow inheritable permissions from the parent to propagate to this object and all child objects</td><td>Disabled</td></tr> </table> </div><div class="he4i"><b>Auditing</b><br/>No auditing specified</div></div><div class="he4h"><span class="sectionTitle" tabindex="0">machine\software\microsoft\netdde</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i">Configure this key then: Replace existing permissions on all subkeys with inheritable permissions</div><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><td scope="row"><b>Owner</b></td><td></td></tr> </table> </div><div class="he4i"><b>Permissions</b><table class="subtable3" cellpadding="0" cellspacing="0"> <tr><th scope="col">Type</th><th scope="col">Name</th><th scope="col">Permission</th><th scope="col">Apply To</th></tr><tr><td>Allow</td><td>BUILTIN\Administrators</td><td>Full control</td><td>This key and subkeys</td></tr><tr><td>Allow</td><td>NT AUTHORITY\SYSTEM</td><td>Full control</td><td>This key and subkeys</td></tr></table> <table class="subtable" cellspacing="0" cellpadding="0"> <tr><td scope="row">Allow inheritable permissions from the parent to propagate to this object and all child objects</td><td>Disabled</td></tr> </table> </div><div class="he4i"><b>Auditing</b><br/>No auditing specified</div></div><div class="he4h"><span class="sectionTitle" tabindex="0">machine\software\microsoft\os/2 subsystem for nt</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i">Configure this key then: Replace existing permissions on all subkeys with inheritable permissions</div><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><td scope="row"><b>Owner</b></td><td></td></tr> </table> </div><div class="he4i"><b>Permissions</b><table class="subtable3" cellpadding="0" cellspacing="0"> <tr><th scope="col">Type</th><th scope="col">Name</th><th scope="col">Permission</th><th scope="col">Apply To</th></tr><tr><td>Allow</td><td>BUILTIN\Administrators</td><td>Full control</td><td>This key and subkeys</td></tr><tr><td>Allow</td><td>CREATOR OWNER</td><td>Full control</td><td>Subkeys only</td></tr><tr><td>Allow</td><td>NT AUTHORITY\SYSTEM</td><td>Full control</td><td>This key and subkeys</td></tr></table> <table class="subtable" cellspacing="0" cellpadding="0"> <tr><td scope="row">Allow inheritable permissions from the parent to propagate to this object and all child objects</td><td>Disabled</td></tr> </table> </div><div class="he4i"><b>Auditing</b><br/>No auditing specified</div></div><div class="he4h"><span class="sectionTitle" tabindex="0">machine\software\microsoft\protected storage system provider</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i">Do not allow permissions on this key to be replaced</div></div><div class="he4h"><span class="sectionTitle" tabindex="0">machine\software\microsoft\windows nt\currentversion\asrcommands</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i">Configure this key then: Replace existing permissions on all subkeys with inheritable permissions</div><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><td scope="row"><b>Owner</b></td><td></td></tr> </table> </div><div class="he4i"><b>Permissions</b><table class="subtable3" cellpadding="0" cellspacing="0"> <tr><th scope="col">Type</th><th scope="col">Name</th><th scope="col">Permission</th><th scope="col">Apply To</th></tr><tr><td>Allow</td><td>BUILTIN\Administrators</td><td>Full control</td><td>This key and subkeys</td></tr><tr><td>Allow</td><td>NT AUTHORITY\Authenticated Users</td><td>Read</td><td>This key and subkeys</td></tr><tr><td>Allow</td><td>CREATOR OWNER</td><td>Full control</td><td>Subkeys only</td></tr><tr><td>Allow</td><td>NT AUTHORITY\SYSTEM</td><td>Full control</td><td>This key and subkeys</td></tr></table> <table class="subtable" cellspacing="0" cellpadding="0"> <tr><td scope="row">Allow inheritable permissions from the parent to propagate to this object and all child objects</td><td>Disabled</td></tr> </table> </div><div class="he4i"><b>Auditing</b><br/>No auditing specified</div></div><div class="he4h"><span class="sectionTitle" tabindex="0">machine\software\microsoft\windows nt\currentversion\perflib</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i">Configure this key then: Replace existing permissions on all subkeys with inheritable permissions</div><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><td scope="row"><b>Owner</b></td><td></td></tr> </table> </div><div class="he4i"><b>Permissions</b><table class="subtable3" cellpadding="0" cellspacing="0"> <tr><th scope="col">Type</th><th scope="col">Name</th><th scope="col">Permission</th><th scope="col">Apply To</th></tr><tr><td>Allow</td><td>NT AUTHORITY\INTERACTIVE</td><td>Read</td><td>This key and subkeys</td></tr><tr><td>Allow</td><td>BUILTIN\Administrators</td><td>Full control</td><td>This key and subkeys</td></tr><tr><td>Allow</td><td>NT AUTHORITY\SYSTEM</td><td>Full control</td><td>This key and subkeys</td></tr><tr><td>Allow</td><td>CREATOR OWNER</td><td>Full control</td><td>This key and subkeys</td></tr></table> <table class="subtable" cellspacing="0" cellpadding="0"> <tr><td scope="row">Allow inheritable permissions from the parent to propagate to this object and all child objects</td><td>Disabled</td></tr> </table> </div><div class="he4i"><b>Auditing</b><br/>No auditing specified</div></div><div class="he4h"><span class="sectionTitle" tabindex="0">machine\software\microsoft\windows\currentversion\group policy</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i">Configure this key then: Propagate inheritable permissions to all subkeys</div><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><td scope="row"><b>Owner</b></td><td></td></tr> </table> </div><div class="he4i"><b>Permissions</b><table class="subtable3" cellpadding="0" cellspacing="0"> <tr><th scope="col">Type</th><th scope="col">Name</th><th scope="col">Permission</th><th scope="col">Apply To</th></tr><tr><td>Allow</td><td>BUILTIN\Administrators</td><td>Full control</td><td>This key and subkeys</td></tr><tr><td>Allow</td><td>NT AUTHORITY\Authenticated Users</td><td>Read</td><td>This key and subkeys</td></tr><tr><td>Allow</td><td>NT AUTHORITY\SYSTEM</td><td>Full control</td><td>This key and subkeys</td></tr></table> <table class="subtable" cellspacing="0" cellpadding="0"> <tr><td scope="row">Allow inheritable permissions from the parent to propagate to this object and all child objects</td><td>Disabled</td></tr> </table> </div><div class="he4i"><b>Auditing</b><br/>No auditing specified</div></div><div class="he4h"><span class="sectionTitle" tabindex="0">machine\software\microsoft\windows\currentversion\installer</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i">Configure this key then: Propagate inheritable permissions to all subkeys</div><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><td scope="row"><b>Owner</b></td><td></td></tr> </table> </div><div class="he4i"><b>Permissions</b><table class="subtable3" cellpadding="0" cellspacing="0"> <tr><th scope="col">Type</th><th scope="col">Name</th><th scope="col">Permission</th><th scope="col">Apply To</th></tr><tr><td>Allow</td><td>BUILTIN\Administrators</td><td>Full control</td><td>This key and subkeys</td></tr><tr><td>Allow</td><td>NT AUTHORITY\Authenticated Users</td><td>Read</td><td>This key and subkeys</td></tr><tr><td>Allow</td><td>NT AUTHORITY\SYSTEM</td><td>Full control</td><td>This key and subkeys</td></tr></table> <table class="subtable" cellspacing="0" cellpadding="0"> <tr><td scope="row">Allow inheritable permissions from the parent to propagate to this object and all child objects</td><td>Disabled</td></tr> </table> </div><div class="he4i"><b>Auditing</b><br/>No auditing specified</div></div><div class="he4h"><span class="sectionTitle" tabindex="0">machine\software\microsoft\windows\currentversion\policies</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i">Configure this key then: Propagate inheritable permissions to all subkeys</div><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><td scope="row"><b>Owner</b></td><td></td></tr> </table> </div><div class="he4i"><b>Permissions</b><table class="subtable3" cellpadding="0" cellspacing="0"> <tr><th scope="col">Type</th><th scope="col">Name</th><th scope="col">Permission</th><th scope="col">Apply To</th></tr><tr><td>Allow</td><td>BUILTIN\Administrators</td><td>Full control</td><td>This key and subkeys</td></tr><tr><td>Allow</td><td>NT AUTHORITY\Authenticated Users</td><td>Read</td><td>This key and subkeys</td></tr><tr><td>Allow</td><td>NT AUTHORITY\SYSTEM</td><td>Full control</td><td>This key and subkeys</td></tr></table> <table class="subtable" cellspacing="0" cellpadding="0"> <tr><td scope="row">Allow inheritable permissions from the parent to propagate to this object and all child objects</td><td>Disabled</td></tr> </table> </div><div class="he4i"><b>Auditing</b><br/>No auditing specified</div></div><div class="he4h"><span class="sectionTitle" tabindex="0">machine\system</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i">Configure this key then: Replace existing permissions on all subkeys with inheritable permissions</div><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><td scope="row"><b>Owner</b></td><td></td></tr> </table> </div><div class="he4i"><b>Permissions</b><table class="subtable3" cellpadding="0" cellspacing="0"> <tr><th scope="col">Type</th><th scope="col">Name</th><th scope="col">Permission</th><th scope="col">Apply To</th></tr><tr><td>Allow</td><td>BUILTIN\Administrators</td><td>Full control</td><td>This key and subkeys</td></tr><tr><td>Allow</td><td>NT AUTHORITY\Authenticated Users</td><td>Read</td><td>This key and subkeys</td></tr><tr><td>Allow</td><td>CREATOR OWNER</td><td>Full control</td><td>Subkeys only</td></tr><tr><td>Allow</td><td>NT AUTHORITY\SYSTEM</td><td>Full control</td><td>This key and subkeys</td></tr></table> <table class="subtable" cellspacing="0" cellpadding="0"> <tr><td scope="row">Allow inheritable permissions from the parent to propagate to this object and all child objects</td><td>Disabled</td></tr> </table> </div><div class="he4i"><b>Auditing</b><br/>No auditing specified</div></div><div class="he4h"><span class="sectionTitle" tabindex="0">machine\system\clone</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i">Do not allow permissions on this key to be replaced</div></div><div class="he4h"><span class="sectionTitle" tabindex="0">machine\system\controlset001</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i">Configure this key then: Propagate inheritable permissions to all subkeys</div><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><td scope="row"><b>Owner</b></td><td></td></tr> </table> </div><div class="he4i"><b>Permissions</b><table class="subtable3" cellpadding="0" cellspacing="0"> <tr><th scope="col">Type</th><th scope="col">Name</th><th scope="col">Permission</th><th scope="col">Apply To</th></tr><tr><td>Allow</td><td>BUILTIN\Administrators</td><td>Full control</td><td>This key and subkeys</td></tr><tr><td>Allow</td><td>NT AUTHORITY\Authenticated Users</td><td>Read</td><td>This key and subkeys</td></tr><tr><td>Allow</td><td>CREATOR OWNER</td><td>Full control</td><td>Subkeys only</td></tr><tr><td>Allow</td><td>NT AUTHORITY\SYSTEM</td><td>Full control</td><td>This key and subkeys</td></tr></table> <table class="subtable" cellspacing="0" cellpadding="0"> <tr><td scope="row">Allow inheritable permissions from the parent to propagate to this object and all child objects</td><td>Disabled</td></tr> </table> </div><div class="he4i"><b>Auditing</b><br/>No auditing specified</div></div><div class="he4h"><span class="sectionTitle" tabindex="0">machine\system\controlset002</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i">Configure this key then: Propagate inheritable permissions to all subkeys</div><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><td scope="row"><b>Owner</b></td><td></td></tr> </table> </div><div class="he4i"><b>Permissions</b><table class="subtable3" cellpadding="0" cellspacing="0"> <tr><th scope="col">Type</th><th scope="col">Name</th><th scope="col">Permission</th><th scope="col">Apply To</th></tr><tr><td>Allow</td><td>BUILTIN\Administrators</td><td>Full control</td><td>This key and subkeys</td></tr><tr><td>Allow</td><td>NT AUTHORITY\Authenticated Users</td><td>Read</td><td>This key and subkeys</td></tr><tr><td>Allow</td><td>CREATOR OWNER</td><td>Full control</td><td>Subkeys only</td></tr><tr><td>Allow</td><td>NT AUTHORITY\SYSTEM</td><td>Full control</td><td>This key and subkeys</td></tr></table> <table class="subtable" cellspacing="0" cellpadding="0"> <tr><td scope="row">Allow inheritable permissions from the parent to propagate to this object and all child objects</td><td>Disabled</td></tr> </table> </div><div class="he4i"><b>Auditing</b><br/>No auditing specified</div></div><div class="he4h"><span class="sectionTitle" tabindex="0">machine\system\controlset003</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i">Configure this key then: Propagate inheritable permissions to all subkeys</div><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><td scope="row"><b>Owner</b></td><td></td></tr> </table> </div><div class="he4i"><b>Permissions</b><table class="subtable3" cellpadding="0" cellspacing="0"> <tr><th scope="col">Type</th><th scope="col">Name</th><th scope="col">Permission</th><th scope="col">Apply To</th></tr><tr><td>Allow</td><td>BUILTIN\Administrators</td><td>Full control</td><td>This key and subkeys</td></tr><tr><td>Allow</td><td>NT AUTHORITY\Authenticated Users</td><td>Read</td><td>This key and subkeys</td></tr><tr><td>Allow</td><td>CREATOR OWNER</td><td>Full control</td><td>Subkeys only</td></tr><tr><td>Allow</td><td>NT AUTHORITY\SYSTEM</td><td>Full control</td><td>This key and subkeys</td></tr></table> <table class="subtable" cellspacing="0" cellpadding="0"> <tr><td scope="row">Allow inheritable permissions from the parent to propagate to this object and all child objects</td><td>Disabled</td></tr> </table> </div><div class="he4i"><b>Auditing</b><br/>No auditing specified</div></div><div class="he4h"><span class="sectionTitle" tabindex="0">machine\system\controlset004</span><a class="expando" href="#"></a