Group Policy Management
body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } }
Setting Path:
Explanation
No explanation is available for this setting.
Supported On:
Not available
NTC Student GPO
Data collected on: 16/07/2008 08:38:27
General
Details
Domainnorthfleet.int
OwnerNORTHFLEET\Domain Admins
Created27/06/2008 18:39:24
Modified15/07/2008 09:54:46
User Revisions352 (AD), 352 (sysvol)
Computer Revisions0 (AD), 0 (sysvol)
Unique ID{C365BD08-21E1-4A8E-8AEA-D6D89B153F90}
GPO StatusComputer settings disabled
Links
LocationEnforcedLink StatusPath
StudentsYesEnablednorthfleet.int/Students

This list only includes links in the domain of the GPO.
Security Filtering
The settings in this GPO can only apply to the following groups, users, and computers:
Name
NT AUTHORITY\Authenticated Users
WMI Filtering
WMI Filter NameNone
DescriptionNot applicable
Delegation
These groups and users have the specified permission for this GPO
NameAllowed PermissionsInherited
NORTHFLEET\Domain AdminsEdit settings, delete, modify securityNo
NORTHFLEET\Enterprise AdminsEdit settings, delete, modify securityNo
NT AUTHORITY\Authenticated UsersRead (from Security Filtering)No
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSReadNo
NT AUTHORITY\SYSTEMEdit settings, delete, modify securityNo
Computer Configuration (Disabled)
No settings defined.
User Configuration (Enabled)
Windows Settings
Security Settings
Public Key Policies/Autoenrollment Settings
PolicySetting
Enroll certificates automaticallyEnabled
Renew expired certificates, update pending certificates, and remove revoked certificatesDisabled
Update certificates that use certificate templatesDisabled
Software Restriction Policies
Enforcement
PolicySetting
Apply software restriction policies toAll software files except libraries (such as DLLs)
Apply software restriction policies to the following usersAll users
Designated File Types
File ExtensionFile Type
ADEMicrosoft Office Access Project Extension
ADPMicrosoft Office Access Project
BASBAS File
BATMS-DOS Batch File
CHMCompiled HTML Help file
CMDWindows NT Command Script
COMMS-DOS Application
CPLControl Panel extension
CRTSecurity Certificate
EXEApplication
HLPHelp File
HTAHTML Application
INFSetup Information
INSInternet Communication Settings
ISPInternet Communication Settings
LNKShortcut
MDBMicrosoft Office Access Database
MDEMicrosoft Office Access MDE Database
MSCMicrosoft Common Console Document
MSIWindows Installer Package
MSPWindows Installer Patch
MSTMST File
OCXActiveX Control
PCDPCD File
PIFShortcut to MS-DOS Program
REGRegistration Entries
SCRScreen Saver
SHSScrap object
URLInternet Shortcut
VBVB File
WSCWindows Script Component
Trusted Publishers
Allow the following users to select trusted publishersEnd users
Before trusting a publisher, check the following to determine if the certificate is revokedNone
Software Restriction Policies/Security Levels
PolicySetting
Default Security LevelUnrestricted
Software Restriction Policies/Additional Rules
Path Rules
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%
Security LevelUnrestricted
Description
Date last modified02/07/2008 14:43:57
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%*.exe
Security LevelUnrestricted
Description
Date last modified02/07/2008 14:43:57
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%System32\*.exe
Security LevelUnrestricted
Description
Date last modified02/07/2008 14:43:57
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir%
Security LevelUnrestricted
Description
Date last modified02/07/2008 14:43:57
\\northfleet\netlogon
Security LevelUnrestricted
Description
Date last modified02/07/2008 14:44:58
\\northfleet\sysvol
Security LevelUnrestricted
Description
Date last modified02/07/2008 14:45:08
\\poweredge\inspiration
Security LevelUnrestricted
Description
Date last modified02/07/2008 14:46:09
\\primary\applications
Security LevelUnrestricted
Description
Date last modified02/07/2008 14:45:20
\\primary\sme
Security LevelUnrestricted
Description
Date last modified02/07/2008 14:45:31
c:\
Security LevelUnrestricted
Description
Date last modified02/07/2008 14:44:17
d:\
Security LevelUnrestricted
Description
Date last modified02/07/2008 14:44:26
m:\
Security LevelUnrestricted
Description
Date last modified02/07/2008 14:44:36
p:\
Security LevelUnrestricted
Description
Date last modified02/07/2008 14:44:43
Folder Redirection
Desktop
Setting: Basic (Redirect everyone's folder to the same location)
Path: \\northfleet\sysvol\northfleet.int\Profiles\StudentRedirection\Desktop
Options
Grant user exclusive rights to DesktopDisabled
Move the contents of Desktop to the new locationDisabled
Policy Removal BehaviorLeave contents
My Documents
Setting: Basic (Redirect everyone's folder to the same location)
Path: \\%HOMESHARE%%HOMEPATH%
Options
Grant user exclusive rights to My DocumentsDisabled
Move the contents of My Documents to the new locationDisabled
Policy Removal BehaviorLeave contents
Start Menu
Setting: Basic (Redirect everyone's folder to the same location)
Path: \\northfleet\sysvol\northfleet.int\Profiles\StudentRedirection\Start
Options
Grant user exclusive rights to Start MenuDisabled
Move the contents of Start Menu to the new locationDisabled
Policy Removal BehaviorLeave contents
Internet Explorer Maintenance
Browser User Interface/Customized Title Bar
Title Bar Text
Northfleet Tehnology College
Connection/Proxy Settings
Enable proxy settings
ProtocolServerPort
HTTPinet1-54568080
Secureinet1-54568080
FTPinet1-54568080
Gopherinet1-54568080
Socksinet1-54568080
Exceptions:Do not use proxy server for addresses beginning with
Do not use proxy server for local (intranet) addressesEnabled
URLs/Important URLs
NameURL
Home page URLhttp://intranet/aup.html
Search bar URLNot configured
Online support page URLNot configured
Security/Security Zones and Content Ratings
Security Zones and Privacy
These settings will not apply to users that log on to computers that have the Internet Explorer Enhanced Security Configuration (ESC) enabled. To create settings for users on computers that have ESC enabled, create a new GPO and edit that GPO on a computer where ESC is enabled.
Internet (Security Level: Medium)
.NET Framework-reliant components
Run components not signed with AuthenticodeEnable
Run components signed with AuthenticodeEnable
ActiveX controls and plug-ins
Download signed ActiveX controlsPrompt
Download unsigned ActiveX controlsDisable
Initialize and script ActiveX controls not marked as safeDisable
Run ActiveX controls and plug-insEnable
Script ActiveX controls marked safe for scriptingEnable
Downloads
File downloadEnable
Font downloadEnable
Microsoft VM
Java permissionsHigh safety
Miscellaneous
Access data sources across domainsDisable
Allow META REFRESHEnable
Display mixed contentPrompt
Don't prompt for client certificate selection when no certificates or only one certificate existsDisable
Drag and drop or copy and paste filesEnable
Installation of desktop itemsPrompt
Launching applications and unsafe filesPrompt
Launching programs and files in an IFRAMEPrompt
Navigate sub-frames across different domainsDisable
Software channel permissionsMedium safety
Submit nonencrypted form dataEnable
Userdata persistenceEnable
Scripting
Active scriptingEnable
Allow paste operations via scriptPrompt
Scripting of Java appletsEnable
User Authentication
LogonAutomatic logon only in Intranet zone
Local intranet (Security Level: Custom)
.NET Framework-reliant components
Run components not signed with AuthenticodeEnable
Run components signed with AuthenticodeEnable
ActiveX controls and plug-ins
Download signed ActiveX controlsEnable
Download unsigned ActiveX controlsEnable
Initialize and script ActiveX controls not marked as safeEnable
Run ActiveX controls and plug-insEnable
Script ActiveX controls marked safe for scriptingEnable
Downloads
File downloadEnable
Font downloadEnable
Microsoft VM
Java permissionsMedium safety
Miscellaneous
Access data sources across domainsEnable
Allow META REFRESHEnable
Display mixed contentEnable
Don't prompt for client certificate selection when no certificates or only one certificate existsEnable
Drag and drop or copy and paste filesEnable
Installation of desktop itemsEnable
Launching applications and unsafe filesEnable
Launching programs and files in an IFRAMEEnable
Navigate sub-frames across different domainsEnable
Software channel permissionsLow safety
Submit nonencrypted form dataEnable
Userdata persistenceEnable
Scripting
Active scriptingEnable
Allow paste operations via scriptEnable
Scripting of Java appletsEnable
User Authentication
LogonAutomatic logon with current username and password
Sites
Require server verification (https:) for all sites in this zoneDisabled
Include all local (intranet) sites not listed in other zonesEnabled
Include all sites that bypass the proxy serverEnabled
Include all network paths (UNCs)Enabled
Sites in this zone
file://*.northfleet.int/
file://northfleet/
http://home.samlearning.com/
http://www.ntc.kent.sch.uk/
http://www.samlearning.co.uk/
intranet
Trusted sites (Security Level: Custom)
.NET Framework-reliant components
Run components not signed with AuthenticodeEnable
Run components signed with AuthenticodeEnable
ActiveX controls and plug-ins
Download signed ActiveX controlsPrompt
Download unsigned ActiveX controlsDisable
Initialize and script ActiveX controls not marked as safeDisable
Run ActiveX controls and plug-insEnable
Script ActiveX controls marked safe for scriptingEnable
Downloads
File downloadEnable
Font downloadEnable
Microsoft VM
Java permissionsHigh safety
Miscellaneous
Access data sources across domainsDisable
Allow META REFRESHEnable
Display mixed contentPrompt
Don't prompt for client certificate selection when no certificates or only one certificate existsDisable
Drag and drop or copy and paste filesEnable
Installation of desktop itemsPrompt
Launching applications and unsafe filesPrompt
Launching programs and files in an IFRAMEPrompt
Navigate sub-frames across different domainsDisable
Software channel permissionsMedium safety
Submit nonencrypted form dataEnable
Userdata persistenceEnable
Scripting
Active scriptingEnable
Allow paste operations via scriptPrompt
Scripting of Java appletsEnable
User Authentication
LogonAutomatic logon only in Intranet zone
Sites
Require server verification (https:) for all sites in this zoneDisabled
Sites in this zone
http://dida.edexcel.org.uk/
Restricted sites (Security Level: Custom)
.NET Framework-reliant components
Run components not signed with AuthenticodeDisable
Run components signed with AuthenticodeDisable
ActiveX controls and plug-ins
Download signed ActiveX controlsDisable
Download unsigned ActiveX controlsDisable
Initialize and script ActiveX controls not marked as safeDisable
Run ActiveX controls and plug-insDisable
Script ActiveX controls marked safe for scriptingDisable
Downloads
File downloadDisable
Font downloadPrompt
Microsoft VM
Java permissionsDisable Java
Miscellaneous
Access data sources across domainsDisable
Allow META REFRESHDisable
Display mixed contentPrompt
Don't prompt for client certificate selection when no certificates or only one certificate existsDisable
Drag and drop or copy and paste filesPrompt
Installation of desktop itemsDisable
Launching applications and unsafe filesDisable
Launching programs and files in an IFRAMEDisable
Navigate sub-frames across different domainsDisable
Software channel permissionsHigh safety
Submit nonencrypted form dataPrompt
Userdata persistenceDisable
Scripting
Active scriptingDisable
Allow paste operations via scriptDisable
Scripting of Java appletsDisable
User Authentication
LogonPrompt for user name and password
Sites
Sites in this zone
None
Privacy
Privacy LevelMedium
Web Sites
Always allowNone
Always blockNone
Administrative Templates
Control Panel
Control Panel/Add or Remove Programs
Control Panel/Display
Control Panel/Display/Desktop Themes
Control Panel/Printers
Control Panel/Regional and Language Options
PolicySetting
Restrict selection of Windows menus and dialogs languageEnabled
Restrict users to the following language:English
Desktop
Desktop/Active Directory
PolicySetting
Hide Active Directory folderEnabled
Network/Network Connections
Network/Offline Files
PolicySetting
Action on server disconnectEnabled
Specify how the system is to respond when a network server
becomes unavailable.
Action: Never go offline
Never go offline = Server's files are unavailable to local computer
Work offline = Server's files are available to local computer
PolicySetting
Do not automatically make redirected folders available offlineEnabled
Prevent use of Offline Files folderEnabled
Prohibit user configuration of Offline FilesEnabled
Prevents users from changing any cache configuration settings.
PolicySetting
Remove 'Make Available Offline'Enabled
Synchronize all offline files before logging offDisabled
Synchronize all offline files when logging onDisabled
Synchronize offline files before suspendDisabled
Turn off reminder balloonsEnabled
Shared Folders
PolicySetting
Allow shared folders to be publishedDisabled
Start Menu and Taskbar
System
PolicySetting
Code signing for device driversEnabled
When Windows detects a driver file without a digital signature:Ignore
PolicySetting
Don't display the Getting Started welcome screen at logonEnabled
Don't run specified Windows applicationsEnabled
List of disallowed applications
,shearst.exe
freecell.exe
pinball.exe
sol.exe
spider.exe
winmine.exe
PolicySetting
Prevent access to registry editing toolsEnabled
Disable regedit from running silently?No
PolicySetting
Prevent access to the command promptEnabled
Disable the command prompt script processing also?No
PolicySetting
Turn off AutoplayDisabled
Windows Automatic UpdatesDisabled
System/Ctrl+Alt+Del Options
System/Internet Communication Management/Internet Communication settings
System/Scripts
Windows Components/Application Compatibility
Windows Components/Attachment Manager
PolicySetting
Default risk level for file attachmentsEnabled
Set the default risk levelLow Risk
Windows Components/Internet Explorer
Windows Components/Internet Explorer/Administrator Approved Controls
PolicySetting
InvestorDisabled
Microsoft ChatDisabled
Microsoft Survey ControlDisabled
MSNBCDisabled
Windows Components/Internet Explorer/Browser menus
Windows Components/Internet Explorer/Internet Control Panel
Windows Components/Internet Explorer/Internet Control Panel/Advanced Page
Windows Components/Internet Explorer/Internet Control Panel/Security Page
Windows Components/Internet Explorer/Internet Control Panel/Security Page/Internet Zone
PolicySetting
Use Pop-up BlockerDisabled
Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone
PolicySetting
Access data sources across domainsEnabled
Access data sources across domainsEnable
PolicySetting
Allow active content over restricted protocols to access my computerEnabled
Allow active content over restricted protocols to access my computerEnable
PolicySetting
Allow active scriptingEnabled
Allow active scriptingEnable
PolicySetting
Allow binary and script behaviorsEnabled
Allow Binary and Script BehaviorsEnable
PolicySetting
Allow cut, copy or paste operations from the clipboard via scriptEnabled
Allow paste operations via scriptEnable
PolicySetting
Allow drag and drop or copy and paste filesEnabled
Allow drag and drop or copy and paste filesEnable
PolicySetting
Allow file downloadsEnabled
Allow file downloadsEnable
PolicySetting
Allow font downloadsEnabled
Allow font downloadsEnable
PolicySetting
Allow script-initiated windows without size or position constraintsEnabled
Allow script-initiated windows without size or position constraintsEnable
PolicySetting
Allow ScriptletsEnabled
ScriptletsEnable
PolicySetting
Automatic prompting for ActiveX controlsEnabled
Automatic prompting for ActiveX controlsEnable
PolicySetting
Automatic prompting for file downloadsEnabled
Automatic prompting for file downloadsEnable
PolicySetting
Display mixed contentEnabled
Display mixed contentEnable
PolicySetting
Do not prompt for client certificate selection when no certificates or only one certificate exists.Enabled
Do not prompt for client certificate selection when no certificates or only one certificate exists.Enable
PolicySetting
Download signed ActiveX controlsEnabled
Download signed ActiveX controlsEnable
PolicySetting
Download unsigned ActiveX controlsEnabled
Download unsigned ActiveX controlsEnable
PolicySetting
Initialize and script ActiveX controls not marked as safeEnabled
Initialize and script ActiveX controls not marked as safeEnable
PolicySetting
Java permissionsEnabled
Java permissionsLow safety
PolicySetting
Launching applications and files in an IFRAMEEnabled
Launching applications and files in an IFRAMEEnable
PolicySetting
Logon optionsEnabled
Logon optionsAutomatic logon with current username and password
PolicySetting
Navigate sub-frames across different domainsEnabled
Navigate sub-frames across different domainsEnable
PolicySetting
Run .NET Framework-reliant components not signed with AuthenticodeEnabled
Run .NET Framework-reliant components not signed with AuthenticodeEnable
PolicySetting
Run .NET Framework-reliant components signed with AuthenticodeEnabled
Run .NET Framework-reliant components signed with AuthenticodeEnable
PolicySetting
Run ActiveX controls and pluginsEnabled
Run ActiveX controls and pluginsEnable
PolicySetting
Script ActiveX controls marked safe for scriptingEnabled
Script ActiveX controls marked safe for scriptingEnable
PolicySetting
Scripting of Java appletsEnabled
Scripting of Java appletsEnable
PolicySetting
Submit non-encrypted form dataEnabled
Submit non-encrypted form dataEnable
PolicySetting
Use Pop-up BlockerEnabled
Use Pop-up BlockerDisable
Windows Components/Internet Explorer/Offline Pages
Windows Components/Internet Explorer/Toolbars
PolicySetting
Configure Toolbar ButtonsEnabled
Show Back buttonEnabled
Show Forward buttonEnabled
Show Stop buttonEnabled
Show Refresh buttonEnabled
Show Home buttonEnabled
Show Search buttonDisabled
Show Favorites buttonDisabled
Show History buttonDisabled
Show Folders buttonDisabled
Show Fullscreen buttonDisabled
Show Tools buttonDisabled
Show Mail buttonDisabled
Show Font size buttonEnabled
Show Print buttonEnabled
Show Edit buttonDisabled
Show Discussions buttonDisabled
Show Cut buttonEnabled
Show Copy buttonEnabled
Show Paste buttonEnabled
Show Encoding buttonDisabled
PolicySetting
Disable customizing browser toolbar buttonsEnabled
Disable customizing browser toolbarsEnabled
Windows Components/Microsoft Management Console
Windows Components/Microsoft Management Console/Restricted/Permitted snap-ins
PolicySetting
Active Directory Users and ComputersDisabled
Windows Components/NetMeeting
Windows Components/NetMeeting/Application Sharing
Windows Components/NetMeeting/Audio & Video
Windows Components/NetMeeting/Options Page
Windows Components/Task Scheduler
Windows Components/Windows Explorer
Windows Components/Windows Explorer/Common Open File Dialog
PolicySetting
Hide the common dialog places barEnabled
Windows Components/Windows Installer
Windows Components/Windows Media Player
Windows Components/Windows Media Player/Networking
PolicySetting
Hide Network TabEnabled
Windows Components/Windows Media Player/User Interface
PolicySetting
Hide Privacy TabEnabled
Hide Security TabEnabled
Windows Components/Windows Update
Extra Registry Settings
Display names for some settings cannot be found. You might be able to resolve this issue by updating the .ADM files used by Group Policy Management.

SettingState
Software\Policies\Microsoft\Internet Explorer\New Windows\Allow\http://dida.edexcel.org.uk/home/spb/sept07/unit1/http://dida.edexcel.org.uk/home/spb/sept07/unit1/
Software\Policies\Microsoft\Internet Explorer\New Windows\Allow\http://www1.edexcel.org.uk/spbs2007/d201-test/html/SPB201Index.shtmhttp://www1.edexcel.org.uk/spbs2007/d201-test/html/SPB201Index.shtm
Software\Policies\Microsoft\Internet Explorer\New Windows\Allow\www.ntc.kent.sch.ukwww.ntc.kent.sch.uk
Software\Policies\Microsoft\Internet Explorer\New Windows\ListBox_Support_Allow1