Group Policy Management
body { font-size:68%;font-family:Tahoma; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:Tahoma; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:tahoma; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } }
Setting Path:
Explanation
No explanation is available for this setting.
Supported On:
Not available

Stanford Windows Infrastructure Documentation

The Stanford Windows Infrastructure Group Policies

"Mandatory Domain Policy"

Computer Configuration (Enabled)
Windows Settings
Security Settings
Local Policies/Security Options
Interactive Logon
PolicySetting
Interactive logon: Message text for users attempting to log onOnly authorized Stanford users are permitted to use and access this computer and the computer networks and systems of Stanford University. If you are not an authorized user, do not login to this system. Authorized users are advised that files and transmissions on this system may be intercepted, monitored, recorded, copied, reviewed, inspected and disclosed as set forth in Administrative Guide Memorandum 62 (http://adminguide.stanford.edu/62.pdf), ., All use of this system is also subject to Stanford University's rules and regulations, including without limitation the Stanford University Administrative Guide, which is available for your review at http://adminguide.stanford.edu/. You agree not to use this system for any illegal purpose, any purpose that would violate Stanford University rules and regulations, or to make unauthorized use of another party's intellectual property., ., By logging on to this computer, you acknowledge and agree to comply with the above terms., ., Windows administrators will use their administrative accounts to accomplish their responsibilities, respecting the policies noted in http://windows.stanford.edu/Public/Infrastructure/WinPolicyGuide.htm
Interactive logon: Message title for users attempting to log on"Computer and Network Policy Notice"
Microsoft Network Client
PolicySetting
Microsoft network client: Send unencrypted password to third-party SMB serversDisabled

"Domain Password Policy"

Computer Configuration (Enabled)
Windows Settings
Security Settings
Account Policies/Password Policy
PolicySetting
Enforce password history1 passwords remembered
Maximum password age0 days
Minimum password age0 days
Minimum password length6 characters
Password must meet complexity requirementsDisabled
Store passwords using reversible encryptionDisabled
Account Policies/Account Lockout Policy
PolicySetting
Account lockout threshold0 invalid logon attempts
Account Policies/Kerberos Policy
PolicySetting
Enforce user logon restrictionsEnabled
Maximum lifetime for service ticket1500 minutes
Maximum lifetime for user ticket25 hours
Maximum lifetime for user ticket renewal7 days
Maximum tolerance for computer clock synchronization5 minutes

"Best Practices Domain Policy"

Computer Configuration (Enabled)
Windows Settings
Security Settings
Local Policies/Audit Policy
PolicySetting
Audit account logon eventsSuccess, Failure
Audit account managementSuccess, Failure
Audit directory service accessSuccess, Failure
Audit logon eventsSuccess, Failure
Audit object accessSuccess, Failure
Audit policy changeSuccess, Failure
Audit privilege useSuccess, Failure
Audit system eventsSuccess, Failure
Local Policies/Security Options
Accounts
PolicySetting
Accounts: Limit local account use of blank passwords to console logon onlyEnabled
Audit
PolicySetting
Audit: Audit the use of Backup and Restore privilegeEnabled
Domain Member
PolicySetting
Domain member: Digitally encrypt secure channel data (when possible)Enabled
Domain member: Digitally sign secure channel data (when possible)Enabled
Interactive Logon
PolicySetting
Interactive logon: Do not require CTRL+ALT+DELDisabled
Microsoft Network Client
PolicySetting
Microsoft network client: Digitally sign communications (if server agrees)Enabled
Microsoft Network Server
PolicySetting
Microsoft network server: Digitally sign communications (if client agrees)Enabled
Network Access
PolicySetting
Network access: Allow anonymous SID/Name translationDisabled
Network access: Do not allow anonymous enumeration of SAM accountsEnabled
Network access: Do not allow anonymous enumeration of SAM accounts and sharesEnabled
Network Security
PolicySetting
Network security: LAN Manager authentication levelSend NTLMv2 response only. Refuse LM & NTLM
Network security: Minimum session security for NTLM SSP based (including secure RPC) clientsEnabled
Require NTLMv2 session securityEnabled
Require 128-bit encryptionEnabled
Network security: Minimum session security for NTLM SSP based (including secure RPC) serversEnabled
Require NTLMv2 session securityEnabled
Require 128-bit encryptionEnabled
Shutdown
PolicySetting
Shutdown: Allow system to be shut down without having to log onDisabled
System Objects
PolicySetting
System objects: Strengthen default permissions of internal system objects (e.g. Symbolic Links)Enabled
Other
PolicySetting
Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settingsEnabled
Network security: Configure encryption types allowed for KerberosEnabled
DES_CBC_CRCEnabled
DES_CBC_MD5Enabled
RC4_HMAC_MD5Enabled
AES128_HMAC_SHA1Enabled
AES256_HMAC_SHA1Enabled
Future encryption typesEnabled
Event Log
PolicySetting
Maximum application log size20480 kilobytes
Maximum security log size102400 kilobytes
Maximum system log size20480 kilobytes
Prevent local guests group from accessing application logEnabled
Prevent local guests group from accessing security logEnabled
Prevent local guests group from accessing system logEnabled
Retain application log7 days
Retain system log7 days
Retention method for application logBy days
Retention method for security logAs needed
Retention method for system logBy days
Public Key Policies/Certificate Services Client - Auto-Enrollment Settings
PolicySetting
Automatic certificate managementEnabled
OptionSetting
Enroll new certificates, renew expired certificates, process pending certificate requests and remove revoked certificatesEnabled
Update and manage certificates that use certificate templates from Active DirectoryEnabled
Public Key Policies/Certificate Path Validation Settings/Stores
PolicySetting
Allow user trusted root Certificate Authorities (CAs) to be used to validate certificatesEnabled
Allow users to trust peer trust certificatesEnabled
Peer trust certificate purposes:Client Authentication; Secure Email; Encrypting File System
Root CAs that client computers can trust:Third-Party Root Certification Authorities and Enterprise Root Certification Authorities
For certificate-based authentication of users and computers, along with CAs that are registered in Active Directory, the client computer must use should also use user principal name (UPN) constraint compliant CAsDisabled
Public Key Policies/Encrypting File System
Properties
PolicySetting
Allow users to encrypt files using Encrypting File System (EFS)Enabled
Encrypt the contents of the user's Documents folderDisabled
Require a smart card for EFSDisabled
Create caching-capable user key from smart cardEnabled
Enable pagefile encryptionDisabled
Display key backup notifications when user key is created or changedDisabled
Allow EFS to generate self-signed certificates when a certification authority is not availableDisabled
Key size for self-signed certificatesDisabled
EFS template for automatic certificate requestsEFS
Cache timeout480
Clear cache when user locks workstationDisabled
Certificates
Issued ToIssued ByExpiration DateIntended Purposes
***File Recovery

For additional information about individual settings, launch Group Policy Object Editor.
Public Key Policies/Trusted Root Certification Authorities
Properties
PolicySetting
Allow users to select new root certification authorities (CAs) to trustEnabled
Client computers can trust the following certificate storesThird-Party Root Certification Authorities and Enterprise Root Certification Authorities
To perform certificate-based authentication of users and computers, CAs must meet the following criteriaRegistered in Active Directory only
Administrative Templates
Network/DNS Client
PolicySetting
DNS Suffix Search ListEnabled
DNS Suffixes:stanford.edu,*.stanford.edu (child domain),*.stanford.edu (root domain)
PolicySettingComment
Dynamic UpdateDisabled
Primary DNS SuffixEnabled
Enter a primary DNS suffix:stanford.edu
Windows Components/BitLocker Drive Encryption
PolicySettingComment
Control Panel Setup: Enable advanced startup optionsEnabled
Allow BitLocker without a compatible TPMDisabled
(requires a startup key on a USB flash drive)
Settings for computers with a TPM:
Configure TPM startup key option:Allow user to create or skip
Configure TPM startup PIN option:Allow user to create or skip
IMPORTANT: If you require the startup key,
you must disallow the startup PIN.
If you require the startup PIN,
you must disallow the startup key.
Otherwise, a policy error occurs.
Note: Disallow both startup key and startup key
options to hide the advanced page on computers
with a TPM.
PolicySettingComment
Turn on BitLocker backup to Active Directory Domain ServicesEnabled
Require BitLocker backup to AD DSEnabled
If selected, cannot turn on BitLocker if backup fails
(recommended default).
If not selected, can turn on BitLocker even if backup
fails. Backup is not automatically retried.
Select BitLocker recovery information to store:Recovery passwords and key packages
A recovery password is a 48-digit number that unlocks
access to a BitLocker-protected volume.
A key package contains a volume's BitLocker encryption
key secured by one or more recovery passwords
Key packages may help perform specialized recovery
when the disk is damaged or corrupted.

"Admin Accounts OU Policy"

Computer Configuration (Enabled)
Windows Settings
Security Settings
Account Policies/Account Lockout Policy
PolicySetting
Account lockout duration0 minutes
Account lockout threshold5 invalid logon attempts
Reset account lockout counter after20 minutes

"Domain Controllers OU Policy"

Computer Configuration (Enabled)
Windows Settings
Security Settings
Local Policies/Audit Policy
PolicySetting
Audit account logon eventsSuccess, Failure
Audit account managementSuccess, Failure
Audit directory service accessSuccess, Failure
Audit logon eventsSuccess, Failure
Audit object accessSuccess, Failure
Audit policy changeSuccess, Failure
Audit privilege useSuccess, Failure
Audit process trackingNo auditing
Audit system eventsSuccess, Failure
Local Policies/User Rights Assignment
PolicySetting
Access this computer from the networkEveryone, NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS, NT AUTHORITY\Authenticated Users, BUILTIN\Administrators
Act as part of the operating system
Allow log on locallyBUILTIN\Administrators
Change the system timeBUILTIN\Administrators, NT AUTHORITY\LOCAL SERVICE
Create a pagefileBUILTIN\Administrators
Debug programsBUILTIN\Administrators
Enable computer and user accounts to be trusted for delegationBUILTIN\Administrators
Force shutdown from a remote systemBUILTIN\Administrators
Load and unload device driversBUILTIN\Administrators
Log on as a batch jobBUILTIN\Administrators
Manage auditing and security logWIN\Exchange Servers, <DOMAIN>\Exchange Enterprise Servers, BUILTIN\Administrators
Modify firmware environment valuesBUILTIN\Administrators
Profile single processBUILTIN\Administrators
Profile system performanceBUILTIN\Administrators
Remove computer from docking stationBUILTIN\Administrators
Restore files and directoriesBUILTIN\Backup Operators, BUILTIN\Administrators
Shut down the systemBUILTIN\Administrators
Take ownership of files or other objectsBUILTIN\Administrators
Local Policies/Security Options
Accounts
PolicySetting
Accounts: Guest account statusDisabled
Audit
PolicySetting
Audit: Audit the access of global system objectsDisabled
Audit: Audit the use of Backup and Restore privilegeEnabled
Devices
PolicySetting
Devices: Restrict CD-ROM access to locally logged-on user onlyEnabled
Devices: Restrict floppy access to locally logged-on user onlyEnabled
Domain Controller
PolicySetting
Domain controller: Allow server operators to schedule tasksDisabled
Domain controller: LDAP server signing requirementsNone
Domain Member
PolicySetting
Domain member: Digitally encrypt or sign secure channel data (always)Enabled
Domain member: Digitally encrypt secure channel data (when possible)Enabled
Domain member: Digitally sign secure channel data (when possible)Enabled
Interactive Logon
PolicySetting
Interactive logon: Do not require CTRL+ALT+DELDisabled
Microsoft Network Client
PolicySetting
Microsoft network client: Digitally sign communications (always)Enabled
Microsoft network client: Digitally sign communications (if server agrees)Enabled
Microsoft network client: Send unencrypted password to third-party SMB serversDisabled
Microsoft Network Server
PolicySetting
Microsoft network server: Digitally sign communications (always)Enabled
Microsoft network server: Digitally sign communications (if client agrees)Enabled
Network Access
PolicySetting
Network access: Allow anonymous SID/Name translationDisabled
Network access: Do not allow anonymous enumeration of SAM accountsEnabled
Network access: Do not allow anonymous enumeration of SAM accounts and sharesEnabled
Network Security
PolicySetting
Network security: Do not store LAN Manager hash value on next password changeEnabled
Network security: LAN Manager authentication levelSend NTLMv2 response only. Refuse LM & NTLM
Shutdown
PolicySetting
Shutdown: Allow system to be shut down without having to log onDisabled
Event Log
PolicySetting
Maximum application log size51200 kilobytes
Maximum security log size1048576 kilobytes
Maximum system log size51200 kilobytes
Prevent local guests group from accessing application logEnabled
Prevent local guests group from accessing security logEnabled
Prevent local guests group from accessing system logEnabled
Retain application log10 days
Retain security log1 days
Retain system log10 days
Retention method for application logBy days
Retention method for security logBy days
Retention method for system logBy days
Restricted Groups
GroupMembersMember of
BUILTIN\Administrators...
<DOMAIN>\Domain Admins...
Public Key Policies/Certificate Services Client - Auto-Enrollment Settings
PolicySetting
Automatic certificate managementEnabled
OptionSetting
Enroll new certificates, renew expired certificates, process pending certificate requests and remove revoked certificatesEnabled
Update and manage certificates that use certificate templates from Active DirectoryEnabled
Public Key Policies/Automatic Certificate Request Settings
Automatic Certificate Request
Domain Controller

For additional information about individual settings, launch Group Policy Object Editor.
Public Key Policies/Trusted Root Certification Authorities
Properties
PolicySetting
Allow users to select new root certification authorities (CAs) to trustEnabled
Client computers can trust the following certificate storesThird-Party Root Certification Authorities and Enterprise Root Certification Authorities
To perform certificate-based authentication of users and computers, CAs must meet the following criteriaRegistered in Active Directory only
Administrative Templates
Network/DNS Client
PolicySettingComment
Dynamic UpdateEnabled
Primary DNS SuffixEnabled
Enter a primary DNS suffix:*.stanford.edu (domain DNS name)

Created: April 22, 2008 by Ross Wilper
Last modified: November 06, 2009 by Ross Wilper
©2009 Trustees of the Leland Stanford Junior University
Information Technology Systems and Services