Download Word Format

Computer Configuration (Enabled)
Windows Settings
Scripts
Startup
NameParameters
\\Network.local\sysvol\Network.local\scripts\TimeSrv.bat
Security Settings
Account Policies/Password Policy
PolicySetting
Enforce password history1 passwords remembered
Maximum password age0 days
Minimum password age0 days
Minimum password length5 characters
Password must meet complexity requirementsDisabled
Store passwords using reversible encryptionDisabled
Account Policies/Account Lockout Policy
PolicySetting
Account lockout duration2 minutes
Account lockout threshold10 invalid logon attempts
Reset account lockout counter after2 minutes
Account Policies/Kerberos Policy
PolicySetting
Enforce user logon restrictionsEnabled
Maximum lifetime for service ticket600 minutes
Maximum lifetime for user ticket10 hours
Maximum lifetime for user ticket renewal7 days
Maximum tolerance for computer clock synchronization5 minutes
Local Policies/Security Options
Accounts
PolicySetting
Accounts: Rename guest account"other"
Interactive Logon
PolicySetting
Interactive logon: Do not display last user nameEnabled
Interactive logon: Number of previous logons to cache (in case domain controller is not available)0 logons
Network Security
PolicySetting
Network security: Force logoff when logon hours expireDisabled
Public Key Policies/Autoenrollment Settings
PolicySetting
Enroll certificates automaticallyEnabled
Renew expired certificates, update pending certificates, and remove revoked certificatesDisabled
Update certificates that use certificate templatesDisabled
Public Key Policies/Encrypting File System
Properties
PolicySetting
Allow users to encrypt files using Encrypting File System (EFS)Enabled
Certificates
Issued ToIssued ByExpiration DateIntended Purposes
AdministratorAdministrator6/27/2005 2:37:50 PMFile Recovery
Public Key Policies/Trusted Root Certification Authorities
Properties
PolicySetting
Allow users to select new root certification authorities (CAs) to trustEnabled
Client computers can trust the following certificate storesThird-Party Root Certification Authorities and Enterprise Root Certification Authorities
To perform certificate-based authentication of users and computers, CAs must meet the following criteriaRegistered in Active Directory only
Administrative Templates
Network/Network Connections
PolicySetting
Prohibit use of Internet Connection Firewall on your DNS domain network Enabled
Prohibit use of Internet Connection Sharing on your DNS domain network Enabled
Network/Network Connections/Windows Firewall/Domain Profile
PolicySetting
Windows Firewall: Protect all network connections Disabled
Network/Network Connections/Windows Firewall/Standard Profile
PolicySetting
Windows Firewall: Protect all network connections Disabled
Network/Offline Files
PolicySetting
At logoff, delete local copy of user's offline files Enabled
Causes the local copy of any offline file accessed by the user
to be deleted when the user logs off of the computer.
Delete only the temporary offline files.Disabled
PolicySetting
Default cache size Enabled
Value entered is [ percent disk used * 10,000 ].
For example, to indicate 12.53%, enter 1253.
Default cache size: 100
PolicySetting
Files not cached Enabled
Files may be excluded from caching on auto-cache shared folders based
on their extension. Enter a list of extensions to be excluded. Extensions
must be preceded by an asterisk and period. "e.g. *.dbf;*.ndx;*.lnk
Extensions: *.exe,*.dot,*.htm,*.js,*.asp,*.dll,*.cab,*.bin,*.url,*.html,*.lnk,*.dat,*.jpg,*.txt
PolicySetting
Synchronize all offline files when logging on Disabled
System/Logon
PolicySetting
Always wait for the network at computer startup and logon Enabled
System/User Profiles
PolicySetting
Delete cached copies of roaming profiles Enabled
Wait for remote user profile Enabled
Windows Components/Windows Messenger
PolicySetting
Do not allow Windows Messenger to be run Enabled
Do not automatically start Windows Messenger initially Enabled
User Configuration (Enabled)
Windows Settings
Remote Installation Services
Client Installation Wizard options
PolicySetting
Custom SetupDisabled
Restart SetupDisabled
ToolsDisabled
Scripts
Logon
NameParameters
\\Network.local\sysvol\Network.local\scripts\logon.bat
\\Network.local\sysvol\Network.local\scripts\FavRegistry.vbs
Internet Explorer Maintenance
Connection/Automatic Browser Configuration
PolicySetting
Automatically detect configuration settingsDisabled
Automatic Browser ConfigurationNot configured
Security/Security Zones and Content Ratings
Security Zones and Privacy
These settings will not apply to users that log on to computers that have the Internet Explorer Enhanced Security Configuration (ESC) enabled. To create settings for users on computers that have ESC enabled, create a new GPO and edit that GPO on a computer where ESC is enabled.
Internet (Security Level: Custom)
.NET Framework-reliant components
Run components not signed with AuthenticodeEnable
Run components signed with AuthenticodeEnable
ActiveX controls and plug-ins
Download signed ActiveX controlsPrompt
Download unsigned ActiveX controlsDisable
Initialize and script ActiveX controls not marked as safeDisable
Run ActiveX controls and plug-insEnable
Script ActiveX controls marked safe for scriptingEnable
Downloads
File downloadEnable
Font downloadEnable
Microsoft VM
Java permissionsHigh safety
Miscellaneous
Access data sources across domainsEnable
Allow META REFRESHEnable
Display mixed contentPrompt
Don't prompt for client certificate selection when no certificates or only one certificate existsDisable
Drag and drop or copy and paste filesEnable
Installation of desktop itemsPrompt
Launching applications and unsafe filesPrompt
Launching programs and files in an IFRAMEPrompt
Navigate sub-frames across different domainsEnable
Software channel permissionsMedium safety
Submit nonencrypted form dataPrompt
Userdata persistenceEnable
Scripting
Active scriptingEnable
Allow paste operations via scriptEnable
Scripting of Java appletsEnable
User Authentication
LogonAutomatic logon only in Intranet zone
Local intranet (Security Level: Low)
.NET Framework-reliant components
Run components not signed with AuthenticodeEnable
Run components signed with AuthenticodeEnable
ActiveX controls and plug-ins
Download signed ActiveX controlsEnable
Download unsigned ActiveX controlsPrompt
Initialize and script ActiveX controls not marked as safePrompt
Run ActiveX controls and plug-insEnable
Script ActiveX controls marked safe for scriptingEnable
Downloads
File downloadEnable
Font downloadEnable
Microsoft VM
Java permissionsLow safety
Miscellaneous
Access data sources across domainsEnable
Allow META REFRESHEnable
Display mixed contentPrompt
Don't prompt for client certificate selection when no certificates or only one certificate existsEnable
Drag and drop or copy and paste filesEnable
Installation of desktop itemsEnable
Launching applications and unsafe filesEnable
Launching programs and files in an IFRAMEEnable
Navigate sub-frames across different domainsEnable
Software channel permissionsLow safety
Submit nonencrypted form dataEnable
Userdata persistenceEnable
Scripting
Active scriptingEnable
Allow paste operations via scriptEnable
Scripting of Java appletsEnable
User Authentication
LogonAutomatic logon with current username and password
Sites
Require server verification (https:) for all sites in this zoneDisabled
Include all local (intranet) sites not listed in other zonesEnabled
Include all sites that bypass the proxy serverEnabled
Include all network paths (UNCs)Enabled
Sites in this zone
*.Network.local
http://172.16.2.15/
Trusted sites (Security Level: Low)
.NET Framework-reliant components
Run components not signed with AuthenticodeEnable
Run components signed with AuthenticodeEnable
ActiveX controls and plug-ins
Download signed ActiveX controlsEnable
Download unsigned ActiveX controlsPrompt
Initialize and script ActiveX controls not marked as safePrompt
Run ActiveX controls and plug-insEnable
Script ActiveX controls marked safe for scriptingEnable
Downloads
File downloadEnable
Font downloadEnable
Microsoft VM
Java permissionsLow safety
Miscellaneous
Access data sources across domainsEnable
Allow META REFRESHEnable
Display mixed contentPrompt
Don't prompt for client certificate selection when no certificates or only one certificate existsEnable
Drag and drop or copy and paste filesEnable
Installation of desktop itemsEnable
Launching applications and unsafe filesEnable
Launching programs and files in an IFRAMEEnable
Navigate sub-frames across different domainsEnable
Software channel permissionsLow safety
Submit nonencrypted form dataEnable
Userdata persistenceEnable
Scripting
Active scriptingEnable
Allow paste operations via scriptEnable
Scripting of Java appletsEnable
User Authentication
LogonAutomatic logon with current username and password
Sites
Require server verification (https:) for all sites in this zoneDisabled
Sites in this zone
http://webmail.sd61.bc.ca/
https://lyra.sd61.bc.ca/
Restricted sites (Security Level: High)
.NET Framework-reliant components
Run components not signed with AuthenticodeDisable
Run components signed with AuthenticodeDisable
ActiveX controls and plug-ins
Download signed ActiveX controlsDisable
Download unsigned ActiveX controlsDisable
Initialize and script ActiveX controls not marked as safeDisable
Run ActiveX controls and plug-insDisable
Script ActiveX controls marked safe for scriptingDisable
Downloads
File downloadDisable
Font downloadPrompt
Microsoft VM
Java permissionsDisable Java
Miscellaneous
Access data sources across domainsDisable
Allow META REFRESHDisable
Display mixed contentPrompt
Don't prompt for client certificate selection when no certificates or only one certificate existsDisable
Drag and drop or copy and paste filesPrompt
Installation of desktop itemsDisable
Launching applications and unsafe filesPrompt
Launching programs and files in an IFRAMEDisable
Navigate sub-frames across different domainsDisable
Software channel permissionsHigh safety
Submit nonencrypted form dataPrompt
Userdata persistenceDisable
Scripting
Active scriptingDisable
Allow paste operations via scriptDisable
Scripting of Java appletsDisable
User Authentication
LogonPrompt for user name and password
Sites
Sites in this zone
None
Privacy
Privacy LevelMedium
Web Sites
Always allowNone
Always blockNone
Administrative Templates
Microsoft Office 2003/Shared paths
PolicySetting
Workgroup templates path Enabled
Workgroup templates path\\Server\Office\FILES\NewTemplates
Microsoft Office Access 2007/Miscellaneous
PolicySetting
Default file format Enabled
Access 2002-2003
Microsoft Office Excel 2003/Block file formats/Open
PolicySetting
Block opening binary file types Disabled
Block opening Database and Datasource files Disabled
Block opening DBF 2 (dBASE II) (*.dbf) files Disabled
Block opening DIF and SYLK file types Disabled
Block opening Html and Xmlss file types Disabled
Block opening Lotus and Quattro files Disabled
Block opening Microsoft Excel 4.0 Charts (*.xlc) files Disabled
Block opening text file types Disabled
Block opening through converters Disabled
Block opening Xll file types Disabled
Block opening Xml file types Disabled
Microsoft Office Excel 2003/Block file formats/Save
PolicySetting
Block saving binary file types Disabled
Block saving Database and Datasource files Disabled
Block saving DBF 2 (dBASE II) (*.dbf) files Disabled
Block saving DIF and SYLK file types Disabled
Block saving Html and Xmlss file types Disabled
Block saving Lotus and Quattro files Disabled
Block saving Microsoft Excel 4.0 Charts (*.xlc) files Disabled
Block saving text file types Disabled
Block saving through converters Disabled
Block saving Xml file types Disabled
Microsoft Office Excel 2007/Block file formats/Open
PolicySetting
Block opening of Binary 12 file types Disabled
Block opening of Binary file types Disabled
Block opening of DIF and SYLK file types Disabled
Block opening of Html and Xmlss files types Disabled
Block opening of Open XML file types Disabled
Block opening of pre-release versions of file formats new to Excel 2007 Disabled
Block opening of Text file types Disabled
Block opening of Xll file type Disabled
Block opening of Xml file types Disabled
Microsoft Office Excel 2007/Block file formats/Save
PolicySetting
Block saving DIF and SYLK file types Disabled
Block saving of Binary file types Disabled
Block saving of Binary12 file types Disabled
Block saving of Html and Xmlss file types Disabled
Block saving of Open Xml file types Disabled
Block saving of Text file types Disabled
Block saving Xml file types Disabled
Microsoft Office Excel 2007/Excel Options/Save
PolicySetting
Save Excel files as Enabled
Save Excel files asExcel 97-2003 Workbook (*.xls)
Microsoft Office PowerPoint 2003/Block file formats/Open
PolicySetting
Block open Html file types Disabled
Block opening binary file types Disabled
Block opening files before PowerPoint 97 Disabled
Block opening Outlines Disabled
Block opening through converters Disabled
Microsoft Office PowerPoint 2003/Block file formats/Save
PolicySetting
Block saving binary file types Disabled
Block saving files before PowerPoint 97 Disabled
Block saving graphic filters Disabled
Block saving Html file types Disabled
Block saving Outlines Disabled
Block saving through converters Disabled
Microsoft Office PowerPoint 2007/PowerPoint Options/Save
PolicySetting
Save files in this format Enabled
Save files in this formatPowerPoint 97-2003 Presentation (*.ppt)
Microsoft Office Publisher 2007/Tools | Options.../General
PolicySetting
Show Publication Types when starting Publisher Disabled
Microsoft Office Word 2003/Block file formats/Open
PolicySetting
Block opening binary file types Disabled
Block opening files before version Enabled
Word 4.x for Macintosh
This policy will prevent opening Word documents with versions below the default version value specified in the dropdown list.
As an example, the default value of this key is set to 'Word 6.0 for Windows'. So under this policy all Word documents starting
from Word 1.x for Windows up to Word 2.x for Windows Taiwan are blocked from opening. You have the option to increase or
decrease the default version. The versions specified in the dropdown list are in ascending order.
PolicySetting
Block opening Html file types Disabled
Block opening internal files Disabled
Block opening Rtf file types Disabled
Block opening text file types Disabled
Block opening through converters Disabled
Block opening WLL files Disabled
Block opening Word 2003 Xml file types Disabled
Microsoft Office Word 2003/Block file formats/Save
PolicySetting
Block saving binary file types Disabled
Block saving Html file types Disabled
Block saving Rtf file types Disabled
Block saving text file types Disabled
Block saving through converters Disabled
Block saving Word 2003 Xml file types Disabled
Microsoft Office Word 2007/Block file formats/Open
PolicySetting
Block open Converters Disabled
Block opening of Binary file types Disabled
Block opening of files before version Disabled
Block opening of HTML file types Disabled
Block opening of Internal file types Disabled
Block opening of Open XML file types Disabled
Block opening of pre-release versions of file formats new to Word 2007 Disabled
Block opening of RTF file types Disabled
Block opening of Text file types Disabled
Block opening of Word 2003 XML file types Disabled
Microsoft Office Word 2007/Block file formats/Save
PolicySetting
Block saving of Binary file types Disabled
Block saving of Converters Disabled
Block saving of HTML file types Disabled
Block saving of Open XML file types Disabled
Block saving of RTF file types Disabled
Block saving of Text file types Disabled
Block saving of Word 2003 XML file types Disabled
Microsoft Office Word 2007/Word Options/Save
PolicySetting
Save files in this format Enabled
Save files in this formatWord 97 - 2003 Document (*.doc)
Network/Offline Files
PolicySetting
Do not automatically make redirected folders available offline Enabled
Synchronize all offline files before logging off Enabled
Synchronize all offline files when logging on Disabled
System
PolicySetting
Don't display the Getting Started welcome screen at logon Enabled
Windows Components/Windows Messenger
PolicySetting
Do not allow Windows Messenger to be run Enabled
Do not automatically start Windows Messenger initially Enabled
Extra Registry Settings
Display names for some settings cannot be found. You might be able to resolve this issue by updating the .ADM files used by Group Policy Management.

SettingState
Software\Policies\Microsoft\Office\9.0\Common\General\SharedTemplates\\Server\Office\FILES\NewTemplates