home *** CD-ROM | disk | FTP | other *** search
/ Venus 7000 / darktronics.iso / Software / Service Packs / Win2kSP4.exe / i386 / ia / defltdc.in_ / defltdc.inf
Encoding:
Windows Setup INFormation  |  2003-06-19  |  22.2 KB  |  355 lines

  1. ; (c) Microsoft Corporation 1997-2000
  2. ;
  3. ; Security Configuration Template for Security Configuration Editor
  4. ;
  5. ; Template Name:        DefltDC.INF
  6. ; Template Version:     05.00.DD.0000
  7. ;
  8. ; Default Template For Windows NT 5.0 Domain Controllers.
  9. ; This template should NOT be used on Workstations or Servers.
  10. ;
  11. ; Revision History
  12. ; 0000  -       Original.
  13. ;               Domain Policies not set.  Use DCFirst if first DC else from existing domain policy.
  14.  
  15. ;[Profile Description]
  16. %SCEDefltDCProfileDescription%
  17.  
  18. [version]
  19. signature="$CHICAGO$"
  20. revision=1
  21. DriverVer=06/19/2003,5.00.2195.6717
  22.  
  23. ;----------------------------------------------------------------
  24. ;Event Log - Log Settings
  25. ;----------------------------------------------------------------
  26. ;Audit Log Retention Period:
  27. ;0 = Overwrite Events As Needed
  28. ;1 = Overwrite Events As Specified by Retention Days Entry
  29. ;2 = Never Overwrite Events (Clear Log Manually)
  30.  
  31. [System Log]
  32. MaximumLogSize = 512
  33. AuditLogRetentionPeriod = 1
  34. RetentionDays = 7
  35. RestrictGuestAccess = 0
  36.  
  37. [Security Log]
  38. MaximumLogSize = 512
  39. AuditLogRetentionPeriod = 1
  40. RetentionDays = 7
  41. RestrictGuestAccess = 0
  42.  
  43. [Application Log]
  44. MaximumLogSize = 512
  45. AuditLogRetentionPeriod = 1
  46. RetentionDays = 7
  47. RestrictGuestAccess = 0
  48.  
  49. [Event Audit]
  50.  
  51. ;Auditing is Off by Default
  52. AuditSystemEvents = 0
  53. AuditLogonEvents = 0
  54. AuditObjectAccess = 0
  55. AuditPrivilegeUse = 0
  56. AuditPolicyChange = 0
  57. AuditProcessTracking = 0
  58. AuditDSAccess = 0
  59. AuditAccountLogon = 0
  60. AuditDSAccess=0
  61.  
  62. ;----------------------------------------------------------------
  63. ;Registry Values
  64. ;----------------------------------------------------------------
  65. [Registry Values]
  66. ; Registry value name in full path = Type, Value
  67. ; REG_SZ                      ( 1 )
  68. ; REG_EXPAND_SZ               ( 2 )  // with environment variables to expand
  69. ; REG_BINARY                  ( 3 )
  70. ; REG_DWORD                   ( 4 )
  71. ; REG_MULTI_SZ                ( 7 )
  72.  
  73. ;Copied to Default DC GPO
  74. ;We need to make sure Server-Side Packet Signing is on in the DC case.
  75. ;The rest of the registry values are maintained from the server.
  76. MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters\EnableSecuritySignature=4,1
  77.  
  78.  
  79. ;----------------------------------------------------------------------
  80. ;   Privileges & Rights
  81. ;----------------------------------------------------------------------
  82. ;
  83. ; Setting of privileges & logon rights for well-known users & groups.
  84. ;
  85. ;SeNetworkLogonRight            = Access this computer from the network
  86. ;SeTcbPrivilege                 = Act as part of the operating System           - (Advanced)
  87. ;SeMachineAccountPrivilege      = Add workstations to the domain                - (Advanced)
  88. ;SeBackupPrivilege              = Back up files and directories
  89. ;SeChangeNotifyPrivilege        = Bypass traverse checking                      - (Advanced)
  90. ;SeSystemtimePrivilege          = Change the system time
  91. ;SeCreatePagefilePrivilege      = Create a pagefile                             - (Advanced)
  92. ;SeCreateTokenPrivilege         = Create a token object                         - (Advanced)
  93. ;SeCreatePermanentPrivilege     = Create permanent shared objects               - (Advanced)
  94. ;SeDebugPrivilege               = Debug programs                                - (Advanced)
  95. ;SeRemoteShutdownPrivilege      = Force shutdown from a remote system
  96. ;SeAuditPrivilege               = Generate security audits                      - (Advanced)
  97. ;SeIncreaseQuotaPrivilege       = Increase quotas                               - (Advanced)
  98. ;SeIncreaseBasePriorityPrivilege= Increase scheduling priority                  - (Advanced)
  99. ;SeLoadDriverPrivilege          = Load and unload device drivers
  100. ;SeLockMemoryPrivilege          = Lock pages in memory                          - (Advanced)
  101. ;SeBatchLogonRight              = Log on as a batch job                         - (Advanced)
  102. ;SeServiceLogonRight            = Log on as a service                           - (Advanced)
  103. ;SeInteractiveLogonRight        = Log on locally                                - (Advanced)
  104. ;SeSecurityPrivilege            = Manage auditing and security log              - (Advanced)
  105. ;SeSystemEnvironmentPrivilege   = Modify firmware environment variables         - (Advanced)
  106. ;SeProfileSingleProcessPrivilege= Profile single process                        - (Advanced)
  107. ;SeSystemProfilePrivilege       = Profile system performance                    - (Advanced)
  108. ;SeAssignPrimaryTokenPrivilege  = Replace a process-level token                 - (Advanced)
  109. ;SeRestorePrivilege             = Restore files and directories
  110. ;SeShutdownPrivilege            = Shut down the system
  111. ;SeTakeOwnershipPrivilege       = Take ownership of files or other objects
  112. ;SeUnsolicitedInputPrivilege                                                    - (Advanced)
  113. ;
  114. [Privilege Rights]
  115. ;Add Whatever a DC should have by default.
  116. ;Remove Power Users from every right since it no longer exists but may have been added.
  117. ;Remove Whatever *Default* Server Rights don't belong on a DC
  118. ;If Server and DC Defaults are the same, then only power users is removed
  119. ;If You remove Everyone, Remove Authenticated Users as well.
  120. SeAssignPrimaryTokenPrivilege = Remove:, %SceInfPowerUsers%
  121. SeAuditPrivilege = Remove:, %SceInfPowerUsers%
  122. SeBackupPrivilege = Add:, %SceInfAdmins%, %SceInfBackupOp%, %SceInfServerOp%, Remove:, %SceInfPowerUsers%
  123. SeBatchLogonRight = Remove:, %SceInfPowerUsers%
  124. SeChangeNotifyPrivilege = Add:, %SceInfAdmins%, %SceInfAuthUsers%, %SceInfEveryone%, Remove:, %SceInfBackupOp%, %SceInfPowerUsers%, %SceInfUsers%
  125. SeCreatePagefilePrivilege = Add:, %SceInfAdmins%, Remove:, %SceInfPowerUsers%
  126. SeCreatePermanentPrivilege = Remove:, %SceInfPowerUsers%
  127. SeCreateTokenPrivilege = Remove:, %SceInfPowerUsers%
  128. SeDebugPrivilege = Add:, %SceInfAdmins%, Remove:, %SceInfPowerUsers%
  129. SeIncreaseBasePriorityPrivilege = Add:, %SceInfAdmins%, Remove:, %SceInfPowerUsers%
  130. SeIncreaseQuotaPrivilege = Add:, %SceInfAdmins%, Remove:, %SceInfPowerUsers%
  131. SeInteractiveLogonRight = Add:, %SceInfAcountOp%, %SceInfAdmins%, %SceInfBackupOp%, %SceInfServerOp%, %SceInfPrintOp%, Remove:, %SceInfPowerUsers%, %SceInfAuthUsers%, %SceInfGuests%, %SceInfGuest%, %SceInfUsers%, %SceInfEveryone%
  132. SeLoadDriverPrivilege = Add:, %SceInfAdmins%, Remove:, %SceInfPowerUsers%
  133. SeLockMemoryPrivilege = Remove:, %SceInfPowerUsers%
  134. SeMachineAccountPrivilege = Add:, %SceInfAuthUsers%, Remove:, %SceInfPowerUsers%
  135. SeNetworkLogonRight = Add:, %SceInfAdmins%, %SceInfAuthUsers%, %SceInfEveryone%, Remove:, %SceInfBackupOp%, %SceInfPowerUsers%, %SceInfGuests%, %SceInfGuest%, %SceInfUsers%
  136. SeProfileSingleProcessPrivilege = Add:, %SceInfAdmins%, Remove:, %SceInfPowerUsers%
  137. SeRemoteShutdownPrivilege = Add:, %SceInfAdmins%, %SceInfServerOp%, Remove:, %SceInfPowerUsers%
  138. SeRestorePrivilege = Add:, %SceInfAdmins%, %SceInfBackupOp%, %SceInfServerOp%, Remove:, %SceInfPowerUsers%
  139. SeSecurityPrivilege = Add:, %SceInfAdmins%, Remove:, %SceInfPowerUsers%
  140. SeServiceLogonRight = Remove:, %SceInfPowerUsers%
  141. SeShutdownPrivilege = Add:, %SceInfAcountOp%, %SceInfAdmins%, %SceInfBackupOp%, %SceInfServerOp%, %SceInfPrintOp%, Remove:, %SceInfPowerUsers%, %SceInfAuthUsers%, %SceInfGuests%, %SceInfGuest%, %SceInfUsers%, %SceInfEveryone%
  142. SeSystemEnvironmentPrivilege = Add:, %SceInfAdmins%, Remove:, %SceInfPowerUsers%
  143. SeSystemProfilePrivilege = Add:, %SceInfAdmins%, Remove:, %SceInfPowerUsers%
  144. SeSystemTimePrivilege = Add:, %SceInfAdmins%, %SceInfServerOp%, Remove:, %SceInfPowerUsers%
  145. SeTakeOwnershipPrivilege = Add:, %SceInfAdmins%, Remove:, %SceInfPowerUsers%
  146. SeTcbPrivilege = Remove:, %SceInfPowerUsers%
  147. ;
  148. SeDenyInteractiveLogonRight = Remove:, %SceInfPowerUsers%
  149. SeDenyBatchLogonRight = Remove:, %SceInfPowerUsers%
  150. SeDenyServiceLogonRight = Remove:, %SceInfPowerUsers%
  151. SeDenyNetworkLogonRight = Remove:, %SceInfPowerUsers%
  152. ;
  153. SeUndockPrivilege = Add:, %SceInfAdmins%, Remove:, %SceInfPowerUsers%, %SceInfUsers%
  154. SeSyncAgentPrivilege = Remove:, %SceInfPowerUsers%
  155. SeEnableDelegationPrivilege = Add:, %SceInfAdmins%, Remove:, %SceInfPowerUsers%
  156.  
  157. [Registry Keys]
  158.  
  159. "MACHINE\SOFTWARE",2,"D:P(A;CI;GR;;;AU)(A;CI;GRGWSD;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  160.  
  161. ;We have to update classes root because server sets PU there.
  162. "MACHINE\SOFTWARE\Classes",2,"D:(A;CI;GR;;;WD)"
  163.  
  164. "MACHINE\SOFTWARE\Microsoft\Command Processor",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  165.  
  166. "MACHINE\SOFTWARE\Microsoft\Cryptography",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  167. "MACHINE\SOFTWARE\Microsoft\DeviceManager",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  168. "MACHINE\SOFTWARE\Microsoft\Driver Signing",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  169. "MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  170. "MACHINE\SOFTWARE\Microsoft\Non-Driver Signing",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  171. "MACHINE\SOFTWARE\Microsoft\NetDDE",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)"
  172. "MACHINE\SOFTWARE\Microsoft\NTDS",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  173. "MACHINE\SOFTWARE\Microsoft\Ole",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  174. "MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider",1,"D:AR"
  175. "MACHINE\SOFTWARE\Microsoft\Rpc",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  176. "MACHINE\SOFTWARE\Microsoft\SystemCertificates",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  177.  
  178. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  179. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  180. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  181. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  182. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  183.  
  184. ;Don't overwrite the following keys which are protected and secured by the component
  185. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy",1,"D:AR"
  186. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer",1,"D:AR"
  187. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies",1,"D:AR"
  188.  
  189. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion",2,"D:(A;CI;GR;;;WD)"
  190. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  191. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AeDebug",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  192. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AsrCommands",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GRGWSD;;;BO)"
  193. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Classes",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  194. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  195. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EFS",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  196. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Font Drivers",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  197. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontMapper",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  198. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  199. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  200. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib",2,"D:P(A;CI;GR;;;IU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  201. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\009",1,"D:AR"
  202. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  203. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SecEdit",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  204. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  205. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  206. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  207.  
  208. "MACHINE\SOFTWARE\Policies",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  209.  
  210. "MACHINE\SYSTEM",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  211.  
  212. "MACHINE\SYSTEM\Clone",1,"D:AR"
  213.  
  214. "MACHINE\SYSTEM\ControlSet001",1,"D:AR"
  215. "MACHINE\SYSTEM\ControlSet002",1,"D:AR"
  216. "MACHINE\SYSTEM\ControlSet003",1,"D:AR"
  217. "MACHINE\SYSTEM\ControlSet004",1,"D:AR"
  218. "MACHINE\SYSTEM\ControlSet005",1,"D:AR"
  219. "MACHINE\SYSTEM\ControlSet006",1,"D:AR"
  220. "MACHINE\SYSTEM\ControlSet007",1,"D:AR"
  221. "MACHINE\SYSTEM\ControlSet008",1,"D:AR"
  222. "MACHINE\SYSTEM\ControlSet009",1,"D:AR"
  223. "MACHINE\SYSTEM\ControlSet010",1,"D:AR"
  224.  
  225. "MACHINE\SYSTEM\CurrentControlSet\Control",2,"D:P(A;CI;GR;;;AU)(A;CI;GRGWSD;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  226.  
  227.  
  228. "MACHINE\SYSTEM\CurrentControlSet\Control\Class",0,"D:AR"
  229. "MACHINE\SYSTEM\CurrentControlSet\Control\Keyboard Layout",2,"D:(A;CI;GR;;;WD)"
  230. "MACHINE\SYSTEM\CurrentControlSet\Control\Keyboard Layouts",2,"D:(A;CI;GR;;;WD)"
  231. "MACHINE\SYSTEM\CurrentControlSet\Control\GraphicsDrivers",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  232. "MACHINE\SYSTEM\CurrentControlSet\Control\LSA",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  233. "MACHINE\SYSTEM\CurrentControlSet\Control\LSA\JD",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  234. "MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Skew1",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  235. "MACHINE\SYSTEM\CurrentControlSet\Control\LSA\GBG",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  236. "MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Data",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  237. "MACHINE\SYSTEM\CurrentControlSet\Control\PriorityControl",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  238. "MACHINE\SYSTEM\CurrentControlSet\Control\ProductOptions",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)"
  239. "MACHINE\SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg",2,"D:P(A;CI;GA;;;BA)(A;CI;GR;;;BO)"
  240. "MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Security",2,"D:P(A;CI;GR;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  241.  
  242. ;Allowed Paths
  243. "MACHINE\SYSTEM\CurrentControlSet\Control\Computername",2,"D:(A;CI;GR;;;WD)"
  244. "MACHINE\SYSTEM\CurrentControlSet\Control\ContentIndex",2,"D:(A;CI;GR;;;WD)"
  245. "MACHINE\SYSTEM\CurrentControlSet\Control\ProductOptions",2,"D:(A;CI;GR;;;WD)"
  246. "MACHINE\SYSTEM\CurrentControlSet\Control\Print\Printers",2,"D:(A;CI;GR;;;WD)"
  247. "MACHINE\SYSTEM\CurrentControlSet\Services\EventLog",2,"D:(A;CI;GR;;;WD)"
  248. "MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip",2,"D:(A;CI;GR;;;WD)"
  249.  
  250. "MACHINE\SYSTEM\CurrentControlSet\Enum",1,"D:AR"
  251.  
  252. "MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles",1,"D:AR"
  253.  
  254. "MACHINE\SYSTEM\CurrentControlSet\Services",2,"D:P(A;CI;GR;;;AU)(A;CI;GRGWSD;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  255. "MACHINE\SYSTEM\CurrentControlSet\Services\EventLog",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  256. "MACHINE\SYSTEM\CurrentControlSet\Services\KDC",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  257. "MACHINE\SYSTEM\CurrentControlSet\Services\NTDS",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  258. "MACHINE\SYSTEM\CurrentControlSet\Services\NTFRS",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  259.  
  260. "MACHINE\SYSTEM\CurrentControlSet\Services\WinTrust",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  261.  
  262. "USERS\.DEFAULT",2,"D:P(A;CI;GR;;;AU)(A;CI;GR;;;SO)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  263. "USERS\.DEFAULT\Software\Microsoft\NetDDE",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)"
  264. "USERS\.DEFAULT\SOFTWARE\Microsoft\Protected Storage System Provider",1,"D:AR"
  265.  
  266.  
  267. [File Security]
  268.  
  269. ;---------------------------------------------------------------------------------------
  270. ;x86 Boot Files
  271. ;---------------------------------------------------------------------------------------
  272. "c:\boot.ini",2,"D:P(A;;GRGWGXSD;;;SO)(A;;GA;;;BA)(A;;GA;;;SY)"
  273. "c:\ntdetect.com",2,"D:P(A;;GRGWGXSD;;;SO)(A;;GA;;;BA)(A;;GA;;;SY)"
  274. "c:\ntldr",2,"D:P(A;;GRGWGXSD;;;SO)(A;;GA;;;BA)(A;;GA;;;SY)"
  275. "c:\ntbootdd.sys",2,"D:P(A;;GRGWGXSD;;;SO)(A;;GA;;;BA)(A;;GA;;;SY)"
  276. "c:\autoexec.bat",2,"D:P(A;;GRGX;;;AU)(A;;GRGWGXSD;;;SO)(A;;GA;;;BA)(A;;GA;;;SY)"
  277. "c:\config.sys",2,"D:P(A;;GRGX;;;AU)(A;;GRGWGXSD;;;SO)(A;;GA;;;BA)(A;;GA;;;SY)"
  278.  
  279. ;---------------------------------------------------------------------------------------------
  280. ;System Drive (\)
  281. ;---------------------------------------------------------------------------------------------
  282. "%SystemDrive%\%SCEInfProgramFiles%",2,"D:P(A;CIOI;GRGX;;;AU)(A;CIOI;GRGWGXSD;;;SO)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  283.  
  284. ;---------------------------------------------------------------------------------------------
  285. ;System Root (Typically \WINNT)
  286. ;---------------------------------------------------------------------------------------------
  287. "%SystemRoot%",2,"D:P(A;CIOI;GRGX;;;AU)(A;CIOI;GRGWGXSD;;;SO)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)(A;;GRGX;;;WD)"
  288. "%SystemRoot%\Debug\UserMode",2,"D:PAR(A;;0x00100023;;;AU)(A;OIIO;0x00100006;;;AU)(A;CIOI;GRGWGXSD;;;SO)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)"
  289. "%SystemRoot%\explorer.exe",2,"D:(A;;GRGX;;;WD)"
  290. "%SystemRoot%\Installer",1,"D:AR"
  291. "%SystemRoot%\Profiles",1,"D:AR"
  292. "%SystemRoot%\repair",2,"D:P(A;CI;GRGX;;;AU)(A;CIOI;GRGWGXSD;;;SO)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  293. "%SystemRoot%\security",2,"D:P(A;CIOI;GRGX;;;AU)(A;CIOI;GRGX;;;SO)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)"
  294. "%Systemroot%\tasks",1,"D:AR"
  295. "%SystemRoot%\Temp",2,"D:P(A;CI;0x100026;;;AU)(A;CIOI;GRGWGXSD;;;SO)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  296.  
  297. ;---------------------------------------------------------------------------------------------
  298. ;System Directory (Typically \Winnt\System32)
  299. ;---------------------------------------------------------------------------------------------
  300. "%SystemDirectory%",2,"D:P(A;CIOI;GRGX;;;AU)(A;CIOI;GRGWGXSD;;;SO)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)(A;OINP;GRGX;;;WD)"
  301. "%SystemDirectory%\config",2,"D:P(A;CI;GRGX;;;AU)(A;CI;GRGX;;;SO)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  302. "%SystemDirectory%\dhcp",2,"D:P(A;CIOI;GRGX;;;AU)(A;CIOI;GRGX;;;SO)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  303. "%SystemDirectory%\dllcache",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)"
  304. "%SystemDirectory%\ias",2,"D:P(A;CIOI;GRGWGXSD;;;SO)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  305. "%SystemDirectory%\GroupPolicy",2,"D:P(A;CIOI;GRGX;;;AU)(A;CIOI;GRGX;;;SO)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  306. "%SystemDirectory%\NTMSData",1,"D:AR"
  307. "%SystemDirectory%\spool",2,"D:(A;CIOI;GA;;;PO)"
  308.  
  309. "%SystemDirectory%\Autoexec.nt",2,"D:P(A;;GRGX;;;AU)(A;;GRGWGXSD;;;SO)(A;;GA;;;BA)(A;;GA;;;SY)"
  310. "%SystemDirectory%\CMOS.RAM",2,"D:P(A;;GRGX;;;AU)(A;;GRGWGXSD;;;SO)(A;;GA;;;BA)(A;;GA;;;SY)"
  311. "%SystemDirectory%\Config.nt",2,"D:P(A;;GRGX;;;AU)(A;;GRGWGXSD;;;SO)(A;;GA;;;BA)(A;;GA;;;SY)"
  312. "%SystemDirectory%\Midimap.cfg",2,"D:P(A;;GRGX;;;AU)(A;;GRGWGXSD;;;SO)(A;;GA;;;BA)(A;;GA;;;SY)"
  313.  
  314. "%SystemDirectory%\hpmon.dll",2,"D:(A;;GRGWGXSD;;;PO)"
  315. "%SystemDirectory%\hpmon.hlp",2,"D:(A;;GRGWGXSD;;;PO)"
  316.  
  317. ;---------------------------------------------------------------------------------------------
  318. ;DS Data and Log Directories.  THESE ENVIRONMENT VARIABLES MUST BE SET!!!!!!!!!!!!!!!!!!!!!!!!
  319. ;---------------------------------------------------------------------------------------------
  320. "%DSDIT%",2,"D:P(A;CIOI;GA;;;SY)(A;CIOI;GA;;;BA)"
  321. "%DSLOG%",2,"D:P(A;CIOI;GA;;;SY)(A;CIOI;GA;;;BA)"
  322.  
  323. ;---------------------------------------------------------------------------------------------
  324. ;Sysvol.                        THIS ENVIRONMENT VARIABLE MUST BE SET!!!!!!!!!!!!!!!!!!!!!!!!!
  325. ;---------------------------------------------------------------------------------------------
  326. "%Sysvol%",2,"D:P(A;CIOI;GRGX;;;AU)(A;CIOI;GRGX;;;SO)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  327. "%Sysvol%\domain\policies",2,"D:P(A;CIOI;GRGX;;;AU)(A;CIOI;GRGX;;;SO)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)(A;CIOI;GRGWGX;;;PA)"
  328. ;---------------------------------------------------------------------------------------------
  329. ;Default Domain Policy GPO and Default Domain Controllers Policy GPO
  330. ;---------------------------------------------------------------------------------------------
  331. "%Sysvol%\domain\policies\{31b2f340-016d-11d2-945f-00c04fb984f9}",2,"D:P(A;CIOI;GRGX;;;AU)(A;CIOI;GRGX;;;SO)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  332. "%Sysvol%\domain\policies\{6ac1786c-016f-11d2-945f-00c04fb984f9}",2,"D:P(A;CIOI;GRGX;;;AU)(A;CIOI;GRGX;;;SO)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  333.  
  334.  
  335. [Strings]
  336.  
  337. SceInfAdministrator = Administrator
  338. SceInfAdmins = Administrators
  339. SceInfAcountOp = Account Operators
  340. SceInfAuthUsers = Authenticated Users
  341. SceInfBackupOp = Backup Operators
  342. SceInfDomainAdmins = Domain Admins
  343. SceInfDomainGuests = Domain Guests
  344. SceInfDomainUsers = Domain Users
  345. SceInfEveryone = Everyone
  346. SceInfGuests = Guests
  347. SceInfGuest = Guest
  348. SceInfPowerUsers = Power Users
  349. SceInfPrintOp = Print Operators
  350. SceInfReplicator = Replicator
  351. SceInfServerOp = Server Operators
  352. SceInfUsers = Users
  353. SceInfProgramFiles = Program Files
  354. SceDefltDCProfileDescription = Default Security Settings applied during DCPromo. (Windows 2000 DC's)
  355.