Download Word Format

Computer Configuration (Enabled)
Windows Settings
Scripts
Startup
NameParameters
\\network.local\SysVol\network.local\scripts\DomainSettings.bat
\\network.local\SysVol\network.local\scripts\Kixscript.bat
\\network.local\SysVol\network.local\scripts\DefaultDomain.vbs
\\network.local\SysVol\network.local\scripts\NoirProfile.vbs
Security Settings
Local Policies/User Rights Assignment
PolicySetting
Allow log on through Terminal Servicesnetwork\Test Students, network\student, network\Installs, network\infotech10, network\Domain Admins, network\Administrator, network\admin
Local Policies/Security Options
Interactive Logon
PolicySetting
Interactive logon: Number of previous logons to cache (in case domain controller is not available)0 logons
System Services
Computer Browser (Startup Mode: Disabled)
Permissions No permissions specified
Auditing No auditing specified
Messenger (Startup Mode: Disabled)
Permissions No permissions specified
Auditing No auditing specified
Software Restriction Policies
Enforcement
PolicySetting
Apply software restriction policies toAll software files except libraries (such as DLLs)
Apply software restriction policies to the following usersAll users
Designated File Types
File ExtensionFile Type
ADEMicrosoft Office Access Project Extension
ADPMicrosoft Office Access Project
BASBAS File
BATMS-DOS Batch File
CHMCompiled HTML Help file
CMDWindows NT Command Script
COMMS-DOS Application
CPLControl Panel extension
CRTSecurity Certificate
EXEApplication
HLPHelp File
HTAHTML Application
INFSetup Information
INSInspiration 6 Document
ISPInternet Communication Settings
LNKShortcut
MDBMicrosoft Office Access Database
MDEMicrosoft Office Access MDE Database
MSCMicrosoft Common Console Document
MSIWindows Installer Package
MSPWindows Installer Patch
MSTMST File
OCXActiveX Control
PCDPCD File
PIFShortcut to MS-DOS Program
REGRegistration Entries
SCRScreen Saver
SHSScrap object
URLInternet Shortcut
VBVB File
WSCWindows Script Component
Trusted Publishers
Allow the following users to select trusted publishersEnd users
Before trusting a publisher, check the following to determine if the certificate is revokedNone
Software Restriction Policies/Security Levels
PolicySetting
Default Security LevelUnrestricted
Software Restriction Policies/Additional Rules
Path Rules
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%
Security LevelUnrestricted
Description
Date last modified1/18/2007 9:07:45 AM
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%*.exe
Security LevelUnrestricted
Description
Date last modified1/18/2007 9:07:45 AM
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%System32\*.exe
Security LevelUnrestricted
Description
Date last modified1/18/2007 9:07:45 AM
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir%
Security LevelUnrestricted
Description
Date last modified1/18/2007 9:07:45 AM
Administrative Templates
Network/Offline Files
PolicySetting
Allow or Disallow use of the Offline Files feature Disabled
System/Group Policy
PolicySetting
Internet Explorer Maintenance policy processing Enabled
Allow processing across a slow network connectionEnabled
Do not apply during periodic background processingDisabled
Process even if the Group Policy objects have not changedEnabled
PolicySetting
User Group Policy loopback processing mode Enabled
Mode:Merge
System/User Profiles
PolicySetting
Delete cached copies of roaming profiles Enabled
Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone
PolicySetting
Use Pop-up Blocker Enabled
Use Pop-up BlockerDisable
Windows Components/Internet Explorer/Internet Control Panel/Security Page/Trusted Sites Zone
PolicySetting
Use Pop-up Blocker Enabled
Use Pop-up BlockerDisable
Windows Components/Terminal Services
PolicySetting
Allow users to connect remotely using Terminal Services Enabled
Sets rules for remote control of Terminal Services user sessions Enabled
Options:Full Control without user's permission
Windows Components/Windows Update
PolicySetting
Allow Automatic Updates immediate installation Enabled
Configure Automatic Updates Enabled
Configure automatic updating:4 - Auto download and schedule the install
The following settings are only required
and applicable if 4 is selected.
Scheduled install day: 0 - Every day
Scheduled install time:18:00
PolicySetting
No auto-restart with logged on users for scheduled automatic updates installations Enabled
Reschedule Automatic Updates scheduled installations Disabled
Specify intranet Microsoft update service location Enabled
Set the intranet update service for detecting updates:http://server1
Set the intranet statistics server:http://server1
(example: http://IntranetUpd01)
User Configuration (Enabled)
Windows Settings
Internet Explorer Maintenance
Connection/Automatic Browser Configuration
PolicySetting
Automatically detect configuration settingsDisabled
Automatic Browser ConfigurationNot configured