| Default Domain Policy | |
| Data collected on: 8/30/2006 2:12:31 PM | |
| Domain | netid.washington.edu |
| Owner | NETID\Domain Admins |
| Created | 6/13/2006 11:11:18 PM |
| Modified | 8/11/2006 10:53:42 AM |
| User Revisions | 3 (AD), 3 (sysvol) |
| Computer Revisions | 103 (AD), 103 (sysvol) |
| Unique ID | {31B2F340-016D-11D2-945F-00C04FB984F9} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| netid | No | Enabled | netid.washington.edu |
| Name |
|---|
| NT AUTHORITY\Authenticated Users |
| WMI Filter Name | None |
| Description | Not applicable |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| NETID\Domain Admins | Edit settings, delete, modify security | No |
| NETID\Enterprise Admins | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read (from Security Filtering) | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| Policy | Setting |
|---|---|
| Enforce password history | 0 passwords remembered |
| Maximum password age | 0 days |
| Minimum password age | 0 days |
| Minimum password length | 1 characters |
| Password must meet complexity requirements | Disabled |
| Store passwords using reversible encryption | Disabled |
| Policy | Setting |
|---|---|
| Enforce user logon restrictions | Enabled |
| Maximum lifetime for service ticket | 600 minutes |
| Maximum lifetime for user ticket | 10 hours |
| Maximum lifetime for user ticket renewal | 7 days |
| Maximum tolerance for computer clock synchronization | 5 minutes |
| Policy | Setting |
|---|---|
| Audit account logon events | Success, Failure |
| Audit account management | Success, Failure |
| Audit logon events | Success, Failure |
| Audit object access | Success, Failure |
| Audit policy change | Success, Failure |
| Audit privilege use | Failure |
| Audit system events | Success, Failure |
| Policy | Setting |
|---|---|
| Accounts: Guest account status | Disabled |
| Accounts: Limit local account use of blank passwords to console logon only | Enabled |
| Policy | Setting |
|---|---|
| Domain member: Digitally encrypt secure channel data (when possible) | Enabled |
| Domain member: Digitally sign secure channel data (when possible) | Enabled |
| Policy | Setting |
|---|---|
| Microsoft network client: Digitally sign communications (if server agrees) | Enabled |
| Microsoft network client: Send unencrypted password to third-party SMB servers | Disabled |
| Policy | Setting |
|---|---|
| Microsoft network server: Digitally sign communications (if client agrees) | Enabled |
| Policy | Setting |
|---|---|
| Network access: Allow anonymous SID/Name translation | Disabled |
| Network access: Do not allow anonymous enumeration of SAM accounts | Enabled |
| Network access: Do not allow anonymous enumeration of SAM accounts and shares | Enabled |
| Network access: Let Everyone permissions apply to anonymous users | Disabled |
| Policy | Setting |
|---|---|
| Network security: Do not store LAN Manager hash value on next password change | Enabled |
| Network security: LAN Manager authentication level | Send NTLMv2 response only\refuse LM & NTLM |
| Policy | Setting |
|---|---|
| Maximum application log size | 16384 kilobytes |
| Maximum security log size | 50240 kilobytes |
| Maximum system log size | 16384 kilobytes |
| Prevent local guests group from accessing application log | Enabled |
| Prevent local guests group from accessing security log | Enabled |
| Prevent local guests group from accessing system log | Enabled |
| Retention method for application log | As needed |
| Retention method for security log | As needed |
| Retention method for system log | As needed |
| Policy | Setting | ||||
|---|---|---|---|---|---|
| Enroll certificates automatically | Enabled | ||||
| |||||
| Policy | Setting |
|---|---|
| Allow users to encrypt files using Encrypting File System (EFS) | Enabled |
| Issued To | Issued By | Expiration Date | Intended Purposes |
|---|---|---|---|
| administrator | administrator | 6/12/2009 11:15:54 PM | File Recovery |
| Policy | Setting |
|---|---|
| Allow users to select new root certification authorities (CAs) to trust | Enabled |
| Client computers can trust the following certificate stores | Third-Party Root Certification Authorities and Enterprise Root Certification Authorities |
| To perform certificate-based authentication of users and computers, CAs must meet the following criteria | Registered in Active Directory only |
| Issued To | Issued By | Expiration Date | Intended Purposes |
|---|---|---|---|
| UW Services CA | UW Services CA | 9/3/2030 11:25:09 AM | <All> |
| Policy | Setting | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Allow Cross-Forest User Policy and Roaming User Profiles | Enabled | ||||||||||||||||
| Group Policy refresh interval for computers | Enabled | ||||||||||||||||
| |||||||||||||||||
| Policy | Setting | ||||||||||||||||
| Group Policy refresh interval for domain controllers | Enabled | ||||||||||||||||
| |||||||||||||||||
| Policy | Setting | ||||||||||||||||
| IP Security policy processing | Enabled | ||||||||||||||||
| |||||||||||||||||
| Policy | Setting | ||||||||||||||||
| Registry policy processing | Enabled | ||||||||||||||||
| |||||||||||||||||
| Policy | Setting | ||||||||||||||||
| Security policy processing | Enabled | ||||||||||||||||
| |||||||||||||||||
| Policy | Setting |
|---|---|
| Add the Administrators security group to roaming user profiles | Enabled |
| Policy | Setting | ||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Global Configuration Settings | Enabled | ||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||
| Policy | Setting |
|---|---|
| Enable Windows NTP Client | Enabled |
| Policy | Setting |
|---|---|
| Prompt for password on resume from hibernate / suspend | Enabled |