Group Policy Results | |
TRC1\administrator on TRC1\DC01 | |
Data collected on: 1/1/2019 4:12:33 PM |
During last computer policy refresh on 1/1/2019 4:10:11 PM | |||||||||||||||||||||
|
During last user policy refresh on 1/1/2019 4:05:18 PM | |||||||||||||||||||
|
Computer name | TRC1\DC01 |
Domain | trc.int |
Site | Default-First-Site-Name |
Organizational Unit | trc.int/Domain Controllers |
Security Group Membership |
show
BUILTIN\Administrators
Everyone BUILTIN\Backup Operators BUILTIN\Users BUILTIN\Certificate Service DCOM Access BUILTIN\Pre-Windows 2000 Compatible Access BUILTIN\Windows Authorization Access Group NT AUTHORITY\NETWORK NT AUTHORITY\Authenticated Users NT AUTHORITY\This Organization TRC1\DC01$ TRC1\Domain Controllers NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS Authentication authority asserted identity TRC1\Cert Publishers TRC1\Denied RODC Password Replication Group Mandatory Label\System Mandatory Level |
Component Name | Status | Time Taken | Last Process Time | Event Log |
---|---|---|---|---|
Group Policy Infrastructure | Success | 143 Millisecond(s) | 1/1/2019 4:10:11 PM | View Log |
Group Policy Registry | Success | 172 Millisecond(s) | 1/1/2019 4:10:11 PM | View Log |
Internet Explorer Zonemapping | Success (no data) | 0 Millisecond(s) | 1/1/2019 4:00:10 PM | View Log |
Microsoft Offline Files | Success (no data) | 0 Millisecond(s) | 1/1/2019 4:10:11 PM | View Log |
Registry | Success | 109 Millisecond(s) | 1/1/2019 4:00:10 PM | View Log |
Scripts | Success | 31 Millisecond(s) | 1/1/2019 4:00:10 PM | View Log |
Security | Success | 547 Millisecond(s) | 1/1/2019 4:00:10 PM | View Log |
Name | Parameters | Last Run | Script Order in GPO | Winning GPO |
---|---|---|---|---|
installsnmp.ps1 | Windows PowerShell scripts will run first | SNMP Configuration |
Policy | Setting | Winning GPO |
---|---|---|
Enforce password history | 0 passwords remembered | Default Domain Policy |
Maximum password age | 0 days | Default Domain Policy |
Minimum password age | 0 days | Default Domain Policy |
Minimum password length | 0 characters | Default Domain Policy |
Password must meet complexity requirements | Disabled | Default Domain Policy |
Store passwords using reversible encryption | Disabled | Default Domain Policy |
Policy | Setting | Winning GPO |
---|---|---|
Enforce user logon restrictions | Enabled | Default Domain Policy |
Maximum lifetime for service ticket | 600 minutes | Default Domain Policy |
Maximum lifetime for user ticket | 10 hours | Default Domain Policy |
Maximum lifetime for user ticket renewal | 7 days | Default Domain Policy |
Maximum tolerance for computer clock synchronization | 5 minutes | Default Domain Policy |
Policy | Setting | Winning GPO |
---|---|---|
Access this computer from the network | Backup Operators, Pre-Windows 2000 Compatible Access, ENTERPRISE DOMAIN CONTROLLERS, Authenticated Users, Administrators, Everyone | Default Domain Controllers Policy |
Add workstations to domain | TRC1\M.Mousavi, TRC1\B.Bakhshiani, Authenticated Users | Default Domain Controllers Policy |
Adjust memory quotas for a process | Administrators, NETWORK SERVICE, LOCAL SERVICE | Default Domain Controllers Policy |
Allow log on locally | Print Operators, Server Operators, Account Operators, Backup Operators, Administrators | Default Domain Controllers Policy |
Back up files and directories | Server Operators, Backup Operators, Administrators | Default Domain Controllers Policy |
Bypass traverse checking | Pre-Windows 2000 Compatible Access, Authenticated Users, Administrators, NETWORK SERVICE, LOCAL SERVICE, Everyone | Default Domain Controllers Policy |
Change the system time | Server Operators, Administrators, LOCAL SERVICE | Default Domain Controllers Policy |
Create a pagefile | Administrators | Default Domain Controllers Policy |
Debug programs | Administrators | Default Domain Controllers Policy |
Enable computer and user accounts to be trusted for delegation | Administrators | Default Domain Controllers Policy |
Force shutdown from a remote system | Server Operators, Administrators | Default Domain Controllers Policy |
Generate security audits | NETWORK SERVICE, LOCAL SERVICE | Default Domain Controllers Policy |
Increase scheduling priority | Administrators | Default Domain Controllers Policy |
Load and unload device drivers | Print Operators, Administrators | Default Domain Controllers Policy |
Log on as a batch job | Performance Log Users, Backup Operators, Administrators, IIS_IUSRS | Default Domain Controllers Policy |
Manage auditing and security log | S-1-5-21-3978916455-91412154-593840236-2559, Administrators, TRC1\Exchange Servers | Default Domain Controllers Policy |
Modify firmware environment values | Administrators | Default Domain Controllers Policy |
Profile single process | Administrators | Default Domain Controllers Policy |
Profile system performance | Administrators | Default Domain Controllers Policy |
Remove computer from docking station | Administrators | Default Domain Controllers Policy |
Replace a process level token | NETWORK SERVICE, LOCAL SERVICE | Default Domain Controllers Policy |
Restore files and directories | Server Operators, Backup Operators, Administrators | Default Domain Controllers Policy |
Shut down the system | Print Operators, Server Operators, Backup Operators, Administrators | Default Domain Controllers Policy |
Take ownership of files or other objects | Administrators | Default Domain Controllers Policy |
Policy | Setting | Winning GPO |
---|---|---|
Domain controller: LDAP server signing requirements | None | Default Domain Controllers Policy |
Policy | Setting | Winning GPO |
---|---|---|
Domain member: Digitally encrypt or sign secure channel data (always) | Enabled | Default Domain Controllers Policy |
Policy | Setting | Winning GPO |
---|---|---|
Microsoft network server: Digitally sign communications (always) | Enabled | Default Domain Controllers Policy |
Microsoft network server: Digitally sign communications (if client agrees) | Enabled | Default Domain Controllers Policy |
Policy | Setting | Winning GPO |
---|---|---|
Network access: Allow anonymous SID/Name translation | Disabled | Default Domain Policy |
Policy | Setting | Winning GPO |
---|---|---|
Network security: Do not store LAN Manager hash value on next password change | Enabled | Default Domain Policy |
Network security: Force logoff when logon hours expire | Disabled | Default Domain Policy |
Network security: LAN Manager authentication level | Send NTLMv2 response only | Default Domain Controllers Policy |
Policy | Setting | Winning GPO | ||||||
---|---|---|---|---|---|---|---|---|
Automatic certificate management | Enabled | [Default setting] | ||||||
|
Issued To | Issued By | Expiration Date | Intended Purposes | Winning GPO |
---|---|---|---|---|
Administrator | Administrator | 9/6/2013 3:08:22 PM | File Recovery | Default Domain Policy |
Issued To | Issued By | Expiration Date | Intended Purposes | Winning GPO |
---|---|---|---|---|
CLASS 2 KEYNECTIS CA | Class 2 Primary CA | 7/6/2019 3:30:00 AM | <All> | Default Domain Policy |
Class 2 Primary CA | Class 2 Primary CA | 7/7/2019 3:29:59 AM | <All> | Default Domain Policy |
ex.tehranraymand.com | CLASS 2 KEYNECTIS CA | 7/12/2017 12:29:03 PM | Server Authentication, Client Authentication | Default Domain Policy |
ex.tehranraymand.com | CLASS 2 KEYNECTIS CA | 6/20/2018 11:34:20 AM | Server Authentication, Client Authentication | Default Domain Policy |
Policy | Setting | Winning GPO | ||
---|---|---|---|---|
DNS servers | Enabled | USBBlock | ||
|
Policy | Setting | Winning GPO | ||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Windows Firewall: Define inbound port exceptions | Enabled | Open TCP 4495 | ||||||||||||||||||||||||||||||||||||||||||||
|
Policy | Setting | Winning GPO |
---|---|---|
Allow or Disallow use of the Offline Files feature | Disabled | Disable Offline File |
Policy | Setting | Winning GPO | ||||
---|---|---|---|---|---|---|
Specify communities | Enabled | SNMP Configuration | ||||
|
Policy | Setting | Winning GPO | ||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Configure Windows NTP Client | Enabled | Default Domain Policy | ||||||||||||||
| ||||||||||||||||
Policy | Setting | Winning GPO | ||||||||||||||
Enable Windows NTP Client | Enabled | Default Domain Policy | ||||||||||||||
Enable Windows NTP Server | Enabled | Local Group Policy |
Link Location | trc.int/Domain Controllers |
Extensions Configured | Security |
Enforced | No |
Disabled | None |
Security Filters | NT AUTHORITY\Authenticated Users |
Revision | AD (16), SYSVOL (16) |
WMI Filter |
Link Location | trc.int |
Extensions Configured | {B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A} Group Policy Registry Security Internet Explorer Zonemapping Registry Group Policy Infrastructure |
Enforced | Yes |
Disabled | None |
Security Filters | NT AUTHORITY\Authenticated Users TRC1\Clinet_Camputer |
Revision | AD (191), SYSVOL (191) |
WMI Filter |
Link Location | trc.int |
Extensions Configured | Microsoft Offline Files Registry |
Enforced | Yes |
Disabled | None |
Security Filters | NT AUTHORITY\Authenticated Users |
Revision | AD (2), SYSVOL (2) |
WMI Filter |
Link Location | Local |
Extensions Configured | Registry |
Enforced | No |
Disabled | None |
Security Filters | |
Revision | AD (3), SYSVOL (3) |
WMI Filter |
Link Location | trc.int |
Extensions Configured | Registry |
Enforced | No |
Disabled | None |
Security Filters | NT AUTHORITY\Authenticated Users |
Revision | AD (1), SYSVOL (1) |
WMI Filter |
Link Location | trc.int |
Extensions Configured | Scripts Registry |
Enforced | Yes |
Disabled | None |
Security Filters | NT AUTHORITY\Authenticated Users |
Revision | AD (18), SYSVOL (18) |
WMI Filter |
Link Location | trc.int |
Extensions Configured | Registry |
Enforced | Yes |
Disabled | None |
Security Filters | Everyone |
Revision | AD (37), SYSVOL (37) |
WMI Filter |
Link Location | trc.int |
Extensions Configured | {B587E2B1-4D59-4E7E-AED9-22B9DF11D053} Security Registry |
Enforced | Yes |
Disabled | None |
Security Filters | TRC1\Domain Computers TRC1\Domain Users |
Revision | AD (19), SYSVOL (65535) |
WMI Filter | |
Reason Denied | Access Denied (Security Filtering) |
Link Location | trc.int |
Extensions Configured | Registry |
Enforced | No |
Disabled | None |
Security Filters | TRC1\Domain Computers |
Revision | AD (5), SYSVOL (65535) |
WMI Filter | |
Reason Denied | Access Denied (Security Filtering) |
Link Location | trc.int |
Extensions Configured | Registry |
Enforced | No |
Disabled | None |
Security Filters | TRC1\SRV-CC01$ |
Revision | AD (2), SYSVOL (65535) |
WMI Filter | |
Reason Denied | Access Denied (Security Filtering) |
Name | Value | Reference GPO(s) |
---|---|---|
None |
User name | TRC1\administrator |
Domain | trc.int |
Security Group Membership |
show
TRC1\Domain Users
Everyone BUILTIN\Administrators BUILTIN\Backup Operators BUILTIN\Users BUILTIN\Certificate Service DCOM Access BUILTIN\Pre-Windows 2000 Compatible Access NT AUTHORITY\REMOTE INTERACTIVE LOGON NT AUTHORITY\INTERACTIVE NT AUTHORITY\Authenticated Users NT AUTHORITY\This Organization LOCAL TRC1\WseRemoteAccessUsers TRC1\WseAlertAdministrators TRC1\WseAllowComputerAccess TRC1\WseAllowHomePageLinks TRC1\WseAllowAddInAccess TRC1\Domain Admins TRC1\WseAllowMediaAccess TRC1\WseRemoteWebAccessUsers TRC1\Group Policy Creator Owners TRC1\WseAllowDashboardAccess TRC1\WseAllowShareAccess TRC1\RTCUniversalReadOnlyAdmins TRC1\YARAN-PSLs TRC1\RTCUniversalServerAdmins TRC1\YARAN-PMTs TRC1\CSServerAdministrator TRC1\CSAdministrator TRC1\Piping Strees-s TRC1\InternalMail TRC1\CSUserAdministrator TRC1\AFTAB-PSLs TRC1\CSLocationAdministrator TRC1\RTCUniversalGlobalReadOnlyGroup TRC1\RTCUniversalUserAdmins TRC1\Schema Admins TRC1\Enterprise Admins TRC1\RTCUniversalUserReadOnlyGroup TRC1\RTCUniversalGlobalWriteGroup TRC1\Organization Management TRC1\RTCUniversalServerReadOnlyGroup TRC1\Piping Material-s TRC1\B1-Personnels-s TRC1\RTCUniversalConfigReplicator Authentication authority asserted identity TRC1\ReportingGroup {aafab9ba-758c-4ed8-9cde-4670c39251a9} TRC1\ReportingGroup {e4e3b17d-7201-4f27-96ca-65d12fe53121} TRC1\PrivReportingGroup {e4e3b17d-7201-4f27-96ca-65d12fe53121} TRC1\Denied RODC Password Replication Group Mandatory Label\High Mandatory Level |
Component Name | Status | Time Taken | Last Process Time | Event Log |
---|---|---|---|---|
Group Policy Infrastructure | Success | 140 Millisecond(s) | 1/1/2019 4:05:18 PM | View Log |
Registry | Success | 63 Millisecond(s) | 1/1/2019 4:00:11 PM | View Log |
Scripts | Success | 16 Millisecond(s) | 1/1/2019 4:00:11 PM | View Log |
Software Installation | Success | 46 Millisecond(s) | 1/1/2019 4:00:11 PM | View Log |
Winning GPO | ManageEngineAssetExplorerAgent |
Name | ManageEngine AssetExplorer Agent |
Version | 1.0 |
Language | English (United States) |
Platform | x86 |
Support URL |
General | Setting |
---|---|
Deployment type | Assigned |
Deployment source | \\dc01\MSIManageEngine\ManageEngineAssetExplorerAgent.msi |
Installation user interface options | Basic |
Uninstall this application when it falls out of the scope of management | Disabled |
Do not display this package in the Add/Remove Programs control panel | Disabled |
Install this application at logon | Enabled |
Advanced Deployment Options | Setting |
---|---|
Ignore language when deploying this package | Disabled |
Make this 32-bit X86 application available to Win64 computers | Enabled |
Include OLE class and product information | Disabled |
Diagnostic Information | Setting |
---|---|
Product code | {a8dae35f-bdf5-47d0-b588-409b6803e025} |
Deployment Count | 0 |
Type | Name | Permission | Inherited |
---|---|---|---|
Allow | TRC1\Domain Admins | Full control | No |
Allow | NT AUTHORITY\Authenticated Users | Read | No |
Allow | NT AUTHORITY\SYSTEM | Full control | No |
Allow | TRC1\Domain Admins | Read, Write | Yes |
Allow | TRC1\Enterprise Admins | Read, Write | Yes |
Allow | NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | Yes |
Allow | NT AUTHORITY\Authenticated Users | Read | Yes |
Allow | NT AUTHORITY\SYSTEM | Read, Write | Yes |
Allow | CREATOR OWNER | Read, Write | Yes |
Allow inheritable permissions from the parent to propagate to this object and all child objects | Enabled |
Upgrades | Setting | ||||
---|---|---|---|---|---|
Required upgrade for existing packages | Disabled | ||||
| |||||
|
Transforms |
---|
None |
This application was applied due to the following conditions: |
---|
The application was assigned. |
Its language matched the system language. |
Policy | Setting | Winning GPO |
---|---|---|
Ability to Enable/Disable a LAN connection | Disabled | USBBlock |
Enable Windows 2000 Network Connections settings for Administrators | Enabled | USBBlock |
Prohibit access to properties of a LAN connection | Enabled | USBBlock |
Prohibit access to properties of components of a LAN connection | Enabled | USBBlock |
Prohibit access to the New Connection Wizard | Enabled | USBBlock |
Prohibit adding and removing components for a LAN or remote access connection | Enabled | USBBlock |
Prohibit TCP/IP advanced configuration | Enabled | USBBlock |
Policy | Setting | Winning GPO |
---|---|---|
All Removable Storage classes: Deny all access | Enabled | USBBlock |
CD and DVD: Deny read access | Enabled | USBBlock |
CD and DVD: Deny write access | Enabled | USBBlock |
Removable Disks: Deny read access | Enabled | USBBlock |
Removable Disks: Deny write access | Enabled | USBBlock |
Tape Drives: Deny read access | Enabled | USBBlock |
Tape Drives: Deny write access | Enabled | USBBlock |
WPD Devices: Deny read access | Enabled | USBBlock |
WPD Devices: Deny write access | Enabled | USBBlock |
Link Location | Local |
Extensions Configured | {A2E30F80-D7DE-11D2-BBDE-00C04F86AE3B} |
Enforced | No |
Disabled | None |
Security Filters | |
Revision | AD (7), SYSVOL (7) |
WMI Filter |
Link Location | trc.int |
Extensions Configured | Software Installation |
Enforced | Yes |
Disabled | None |
Security Filters | NT AUTHORITY\Authenticated Users |
Revision | AD (3), SYSVOL (3) |
WMI Filter |
Link Location | trc.int |
Extensions Configured | Scripts |
Enforced | Yes |
Disabled | None |
Security Filters | NT AUTHORITY\Authenticated Users |
Revision | AD (2), SYSVOL (2) |
WMI Filter |
Link Location | trc.int |
Extensions Configured | Registry |
Enforced | Yes |
Disabled | None |
Security Filters | Everyone |
Revision | AD (28), SYSVOL (28) |
WMI Filter |
Link Location | trc.int |
Extensions Configured | {A2E30F80-D7DE-11D2-BBDE-00C04F86AE3B} {4CFB60C1-FAA6-47F1-89AA-0B18730C9FD3} Registry |
Enforced | Yes |
Disabled | None |
Security Filters | NT AUTHORITY\Authenticated Users TRC1\Clinet_Camputer |
Revision | AD (49), SYSVOL (65535) |
WMI Filter | |
Reason Denied | Access Denied (Security Filtering) |
Name | Value | Reference GPO(s) |
---|---|---|
None |