home *** CD-ROM | disk | FTP | other *** search
/ PC World Komputer 2010 April / PCWorld0410.iso / WindowsServerTrial / server.iso / sources / install.wim / 2 / Windows / inf / dsupt.inf < prev    next >
Windows Setup INFormation  |  2008-01-19  |  43KB  |  371 lines

  1.  ■; Copyright (c) Microsoft Corporation.  All rights reserved.
  2. ;
  3. ; Security Configuration Template for Security Configuration Editor
  4. ;
  5. ; Template Name:        DSUpT.INF
  6. ; Template Version:     05.10.DT.0000
  7. ;
  8. ; Default Security for Windows NT 5.1 Terminal Servers that have been:
  9. ; 1. Upgraded from NT4 Terminal Server OR
  10. ; 2. Upgraded from Win2k Terminal Server that was running in App Mode.
  11. ; NOT used to upgrade Win2k\Whistler Terminal Servers running in remote admin mode (DSUp.inf should be used for that)
  12. [Profile Description]
  13. %SCEDSUpProfileDescription%
  14. [version]
  15. signature="$CHICAGO$"
  16. revision=1
  17. DriverVer=06/21/2006,6.0.6001.18000
  18. [System Access]
  19. ;----------------------------------------------------------------
  20. ;Local Policies - Security Options
  21. ;----------------------------------------------------------------
  22. LSAAnonymousNameLookup = 0
  23. ;----------------------------------------------------------------
  24. ;Event Log - Log Settings
  25. ;----------------------------------------------------------------
  26. [System Log]
  27. RestrictGuestAccess = 1
  28. [Security Log]
  29. RestrictGuestAccess = 1
  30. [Application Log]
  31. RestrictGuestAccess = 1
  32. ;----------------------------------------------------------------
  33. ;Registry Values
  34. ;----------------------------------------------------------------
  35. [Registry Values]
  36. ;On upgrade, we can only set reg values that meet the following criteria:
  37. ;a.) value did not exist on previous releases
  38. ;b.) default setting was changed from a less secure to a more secure state
  39. MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\UndockWithoutLogon=4,1
  40. MACHINE\System\CurrentControlSet\Control\Lsa\DisableDomainCreds=4,0
  41. MACHINE\System\CurrentControlSet\Control\Lsa\EveryoneIncludesAnonymous=4,0
  42. MACHINE\System\CurrentControlSet\Control\Lsa\ForceGuest=4,0
  43. MACHINE\System\CurrentControlSet\Control\Lsa\FIPSAlgorithmPolicy\Enabled=4,0
  44. MACHINE\System\CurrentControlSet\Control\Lsa\LimitBlankPasswordUse=4,1
  45. MACHINE\System\CurrentControlSet\Control\Lsa\LmCompatibilityLevel=4,3
  46. MACHINE\System\CurrentControlSet\Control\Lsa\RestrictAnonymousSAM=4,1
  47. MACHINE\System\CurrentControlSet\Control\SecurePipeServers\Winreg\AllowedPaths\Machine=8,Add:,Software\Microsoft\Windows NT\CurrentVersion\Print,Software\Microsoft\Windows NT\CurrentVersion\Windows,Remove:,System\CurrentControlSet\Control\ProductOptions,System\CurrentControlSet\Control\Server Applications,Software\Microsoft\Windows NT\CurrentVersion
  48. MACHINE\System\CurrentControlSet\Control\SecurePipeServers\Winreg\AllowedExactPaths\Machine=8,Add:,System\CurrentControlSet\Control\ProductOptions,System\CurrentControlSet\Control\Server Applications,Software\Microsoft\Windows NT\CurrentVersion
  49. MACHINE\System\CurrentControlSet\Control\Session Manager\Kernel\ObCaseInsensitive=4,1
  50. MACHINE\System\CurrentControlSet\Control\Session Manager\ProtectionMode=4,1
  51. MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters\RestrictNullSessAccess=4,1
  52. MACHINE\System\CurrentControlSet\Services\LDAP\LDAPClientIntegrity=4,1
  53. MACHINE\System\CurrentControlSet\Services\Netlogon\Parameters\RequireSignOrSeal=4,1
  54. ; remove lsarpc, samr and netlogon from anonymously accessible pipes
  55. MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\NullSessionPipes=8,Remove:,lsarpc,samr,netlogon
  56. ;We cannot set the following values which were new for Win2k, because
  57. ;Win2k customers may have already configured them differently.
  58. ;Therefore, the following may not be configured on upgrade from NT4.
  59. ;
  60. ;MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Setup\RecoveryConsole\SecurityLevel=4,0
  61. ;MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Setup\RecoveryConsole\SetCommand=4,0
  62. ;MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\ScRemoveOption=1,0
  63. [Privilege Rights]
  64. ;
  65. ;World                          S-1-1-0
  66. ;
  67. ;NT Authority                   S-1-5
  68. ;TERMINAL_SERVER                13
  69. ;LOCAL_SERVICE                  19
  70. ;NETWORK_SERVICE                20
  71. ;
  72. ;Built-In Domain SubAuthority = S-1-5-32
  73. ;ADMINISTRATORS                 544
  74. ;USERS                          545
  75. ;GUESTS                         546
  76. ;POWER_USERS  (DEPRECATED)
  77. ;ACCOUNT_OPS                    548
  78. ;SYSTEM_OPS                     549
  79. ;PRINT_OPS                      550
  80. ;BACKUP_OPS                     551
  81. ;REPLICATOR                     552
  82. ;RAS_SERVERS                    553
  83. ;PREW2KCOMPACCESS               554
  84. ;REMOTE_DESKTOP_USERS           555
  85. ;NETWORK_CONFIGURATION_OPS      556
  86. ;
  87. SeAssignPrimaryTokenPrivilege = Add:, *S-1-5-19, *S-1-5-20
  88. SeAuditPrivilege = Add:, *S-1-5-19, *S-1-5-20
  89. SeBatchLogonRight = Add:, *S-1-5-32-544, *S-1-5-32-551
  90. SeChangeNotifyPrivilege = Add:, *S-1-5-19, *S-1-5-20
  91. SeCreateGlobalPrivilege = Add:, *S-1-5-6, *S-1-5-32-544, *S-1-5-19, *S-1-5-20
  92. SeCreateSymbolicLinkPrivilege = Add:, *S-1-5-32-544
  93. SeImpersonatePrivilege = Add:, *S-1-5-6, *S-1-5-32-544, *S-1-5-19, *S-1-5-20
  94. ;SeIncreaseBasePriorityPrivilege = Remove:, *S-1-5-32-547
  95. SeIncreaseQuotaPrivilege = Add:, *S-1-5-19, *S-1-5-20
  96. SeIncreaseWorkingSetPrivilege = Add:, *S-1-5-32-545
  97. SeInteractiveLogonRight = Remove:, &-501
  98. SeManageVolumePrivilege = Add:, *S-1-5-32-544
  99. SeRemoteInteractiveLogonRight = Add:, *S-1-5-32-544, *S-1-5-32-555
  100. SeRemoteShutdownPrivilege = Remove:, *S-1-5-32-545, *S-1-1-0
  101. SeShutdownPrivilege = Remove:, *S-1-5-32-545, *S-1-1-0
  102. SeSystemTimePrivilege = Add:, *S-1-5-19, Remove:, *S-1-5-20
  103. SeTimeZonePrivilege = Add:, *S-1-5-32-544, *S-1-5-19
  104. ;Undock was added in Win2k.  Not adding Users because:
  105. ;a.) Win2k customers may have justifiably removed them.
  106. SeUndockPrivilege = Add:, *S-1-5-32-544
  107. ;[Group Membership]
  108. ;During upgrade, use net api's to
  109. ;1 - add Authenticated Users and Interactive into the Users group
  110. [Service General Setting]
  111. ;Note: startup type should not be configured during setup\dcpromo.
  112. ;autostarted on workstations and servers, standalone or joined
  113. Browser,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  114. TrkWks,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  115. Dnscache,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;NO)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  116. PolicyAgent,,"D:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  117. dmserver,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  118. PlugPlay,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  119. Spooler,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  120. ProtectedStorage,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  121. RpcSs,,"D:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLO;;;IU)(A;;CCLCSWRPLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  122. NtmsSvc,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  123. seclogon,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  124. SamSs,,"D:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLO;;;IU)(A;;CCLCSWLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  125. lanmanserver,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  126. SENS,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  127. Schedule,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  128. Sysmonlog,,"D:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCLCRPLOCR;;;LU)S:AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  129. LmHosts,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  130. LanmanWorkstation,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  131. RemoteRegistry,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  132. ClipSrv,,"D:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLO;;;IU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  133. NetDDE,,"D:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLO;;;IU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  134. NetDDEdsdm,,"D:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLO;;;IU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  135. EventSystem,,"D:(A;;CCLCSWRPLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  136. ;Not autostarted if machine is standalone
  137. ;Netlogon,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  138. ;W32Time,,"D:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLO;;;IU)(A;;CCLCSWRPLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  139. ;Server Only Services
  140. Dfs,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  141. LicenseService,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  142. ;IIS Specific Services - Leave them alone
  143. ;IISADMIN,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  144. ;W3SVC,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  145. ;MSFTPSVC,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  146. ;SMTPSVC,,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  147. ;
  148. ; set default startup for the following services - do not touch permissions
  149. ;
  150. TrkSvr,4,""
  151. [Registry Keys]
  152. ;Not same as parent, and this is the target of a symlink - set explicitly.
  153. "MACHINE\SOFTWARE\Microsoft\ADs\Providers\LDAP\Extensions",2,"D:P(A;CI;GR;;;BU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  154. "MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates",2,"D:P(A;CI;GR;;;BU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  155. "MACHINE\SOFTWARE\Microsoft\OLAP Server\CurrentVersion\SECURITY",1,"D:AR"
  156. "MACHINE\Software\Microsoft\Speech",2,"D:P(A;CI;GR;;;BU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  157. "MACHINE\SOFTWARE\Microsoft\SystemCertificates",2,"D:P(A;CI;GR;;;BU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  158. "MACHINE\SOFTWARE\Microsoft\SystemCertificates\Authroot",2,"D:AI(A;CIOI;GA;;;S-1-5-80-242729624-280608522-2219052887-3187409060-2225943459)"
  159. "MACHINE\SOFTWARE\Microsoft\Tracing",2,"D:P(A;CI;GR;;;BU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GR;;;S-1-5-13)"
  160. "MACHINE\SOFTWARE\Microsoft\Windows",0,"D:AR"
  161. "MACHINE\Software\Microsoft\Windows\CurrentVersion",0,"D:P(A;CI;GR;;;BU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  162. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders",2,"D:P(A;CI;GR;;;BU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  163. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx",2,"D:P(A;CI;GR;;;BU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  164. ;The following keys need to be writable by TERMINAL_SERVER_USER for App-Compat
  165. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths",2,"D:P(A;CI;GR;;;BU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GRGWSD;;;S-1-5-13)"
  166. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace",2,"D:P(A;CI;GR;;;BU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GRGWSD;;;S-1-5-13)"
  167. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks",2,"D:P(A;CI;GR;;;BU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GRGWSD;;;S-1-5-13)"
  168. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs",2,"D:P(A;CI;GR;;;BU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GRGWSD;;;S-1-5-13)"
  169. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall",2,"D:P(A;CI;GR;;;BU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GRGWSD;;;S-1-5-13)"
  170. ;The following keys do not exist when we run.
  171. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy",1,"D:AR"
  172. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies",1,"D:AR"
  173. "MACHINE\SOFTWARE\Microsoft\SMS",1,"D:AR"
  174. "MACHINE\SOFTWARE\Microsoft\Windows NT",0,"D:AR"
  175. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility",2,"D:P(A;CI;GR;;;BU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  176. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EFS",2,"D:P(A;CI;GR;;;BU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  177. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage",2,"D:P(A;CI;GR;;;BU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  178. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Ports",2,"D:P(A;CI;GR;;;BU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  179. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Setup\RecoveryConsole",2,"D:P(A;CI;GR;;;BU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  180. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing",2,"D:P(A;CI;GRGWSD;;;LS)(A;CI;GRGWSD;;;NS)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  181. "MACHINE\System",0,"D:P(A;CI;GR;;;BU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  182. "MACHINE\SYSTEM\Clone",1,"D:AR"
  183. "MACHINE\SYSTEM\ControlSet001",1,"D:AR"
  184. "MACHINE\SYSTEM\ControlSet002",1,"D:AR"
  185. "MACHINE\SYSTEM\ControlSet003",1,"D:AR"
  186. "MACHINE\SYSTEM\ControlSet004",1,"D:AR"
  187. "MACHINE\SYSTEM\ControlSet005",1,"D:AR"
  188. "MACHINE\SYSTEM\ControlSet006",1,"D:AR"
  189. "MACHINE\SYSTEM\ControlSet007",1,"D:AR"
  190. "MACHINE\SYSTEM\ControlSet008",1,"D:AR"
  191. "MACHINE\SYSTEM\ControlSet009",1,"D:AR"
  192. "MACHINE\SYSTEM\ControlSet010",1,"D:AR"
  193. "MACHINE\SYSTEM\CurrentControlSet\Control\Class",1,"D:AR"
  194. "MACHINE\SYSTEM\CurrentControlSet\Control\Keyboard Layouts",2,"D:(A;CI;GR;;;WD)"
  195. "MACHINE\SYSTEM\CurrentControlSet\Control\LSA\JD",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  196. "MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Skew1",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  197. "MACHINE\SYSTEM\CurrentControlSet\Control\LSA\GBG",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  198. "MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Data",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  199. "MACHINE\SYSTEM\CurrentControlSet\Control\Nsi",2,"D:P(A;CI;KR;;;BU)(A;CI;KA;;;BA)(A;CI;KA;;;SY)(A;CI;CCDCLCSWRPWPSDRC;;;NS)(A;CI;CCDCLCSWRPWPSDRC;;;LS)(A;CI;CCDCLCSWRPSDRC;;;NO)(A;CI;CCDCLCSWRPWPSDRC;;;S-1-5-80-2940520708-3855866260-481812779-327648279-1710889582)(A;CIIO;RC;;;S-1-3-4)"
  200. "MACHINE\SYSTEM\CurrentControlSet\Control\Nsi\{eb004a00-9b1a-11d4-9123-0050047759bc}\4",2,"D:P(A;CI;CCDCLCSWRPRC;;;AU)(A;CI;CCDCLCSWRPWPSDRC;;;LS)(A;CI;CCDCLCSWRPWPSDRC;;;NS)((A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CIIO;RC;;;S-1-3-4)"
  201. "MACHINE\SYSTEM\CurrentControlSet\Control\Nsi\{eb004a01-9b1a-11d4-9123-0050047759bc}\4",2,"D:P(A;CI;CCDCLCSWRPRC;;;AU)(A;CI;CCDCLCSWRPWPSDRC;;;LS)(A;CI;CCDCLCSWRPWPSDRC;;;NS)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CIIO;RC;;;S-1-3-4)"
  202. "MACHINE\SYSTEM\CurrentControlSet\Control\Nsi\{eb004a1C-9b1a-11d4-9123-0050047759bc}\0",2,"D:P(A;CI;CCDCLCSWRPRC;;;AU)(A;CI;CCDCLCSWRPWPSDRC;;;LS)(A;CI;CCDCLCSWRPWPSDRC;;;NS)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CIIO;RC;;;S-1-3-4)"
  203. "MACHINE\SYSTEM\CurrentControlSet\Enum",1,"D:AR"
  204. "MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles",1,"D:AR"
  205. ;Don't whack more restrictive security subkeys.
  206. "MACHINE\SYSTEM\CurrentControlSet\Services",0,"D:AR"
  207. ;Set security subkey permissions for those services created via default hives
  208. "MACHINE\SYSTEM\CurrentControlSet\Services\AppMgmt\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  209. "MACHINE\SYSTEM\CurrentControlSet\Services\kdc\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  210. "MACHINE\SYSTEM\CurrentControlSet\Services\LicenseInfo",2,"D:AR(A;CI;CCLCSWRPRC;;;NS)(A;CIIO;CCDCLCSWRPRC;;;NS)"
  211. "MACHINE\SYSTEM\CurrentControlSet\Services\SCardSvr\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  212. ;Set security subkey permissions for those services created in GUI-mode setup before SCE runs
  213. "MACHINE\SYSTEM\CurrentControlSet\Services\STISvc\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  214. "MACHINE\SYSTEM\CurrentControlSet\Services\SysmonLog\Log Queries",2,"D:(A;CI;GA;;;NS)(A;CI;CCDCLCSWSDRC;;;LU)"
  215. "USERS\.DEFAULT\SOFTWARE\Microsoft\SystemCertificates\Root\ProtectedRoots",1,"D:AR"
  216. [File Security]
  217. ;---------------------------------------------------------------------------------------
  218. ;System Drive
  219. ;---------------------------------------------------------------------------------------
  220. ;SetupSecurity will contain the new root acl.  Ignore docs and settings if it's reapplied (e.g. on conversion from FAT)
  221. ; Directories that might not exist when security is applied; but are listed here
  222. ; so that they get secured correctly on converting the file system to NTFS
  223. ;---------------------------------------------------------------------------------------------
  224. ;Program Files
  225. ;---------------------------------------------------------------------------------------------
  226. "%SceInfCommonProgramFiles%\SpeechEngines\Microsoft\TTS",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  227. ;---------------------------------------------------------------------------------------------
  228. ;Win64 ProgramFiles Directory
  229. ;---------------------------------------------------------------------------------------------
  230. ;---------------------------------------------------------------------------------------------
  231. ; ProgramData Folder (Typically \ProgramData)
  232. ;---------------------------------------------------------------------------------------------
  233. ;---------------------------------------------------------------------------------------------
  234. ;System Root (Typically \WINDOWS)
  235. ;---------------------------------------------------------------------------------------------
  236. ;Profile for LocalService and NetworkService, moved from Users in Longhorn, creator specifies security
  237. "%SystemRoot%\ServiceProfiles\LocalService",1,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;LS)"
  238. "%SystemRoot%\ServiceProfiles\NetworkService",1,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;NS)"
  239. ;---------------------------------------------------------------------------------------------
  240. ;System Directory (Typically \Windows\System32)
  241. ;---------------------------------------------------------------------------------------------
  242. ;Profile for system account - moved from Docs and Settings in Whistler. Creator specifies security.
  243. ;Directories with no legacy to preserve. Different from parent.
  244. "%SystemDirectory%\wbem\mof",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  245. ;Directories that do not exist when security applied during clean-install - Creator specifies directory security.
  246. ;We explicitly ignore so as not to whack the component-specified DIRECTORY security on upgrade or reapplication of defaults.
  247. "%SystemDirectory%\appmgmt",1,"D:AR"
  248. ; Directories that might not exist when security is applied; but are listed here
  249. ; so that they get secured correctly on converting the file system to NTFS
  250. ;-----------------------------------------------------------------------------------------
  251. ; SysWOW64 directories
  252. ;-----------------------------------------------------------------------------------------
  253. ;-----------------------------------------------------------------------------------------
  254. ;Individual File Settings.
  255. ;-----------------------------------------------------------------------------------------
  256. "%Systemroot%\repair\default",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  257. "%Systemroot%\repair\ntuser.dat",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  258. "%Systemroot%\repair\sam",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  259. "%Systemroot%\repair\security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  260. "%Systemroot%\repair\software",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  261. "%Systemroot%\repair\system",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  262. [Strings]
  263. SceInfAdministrator = "Administrator"
  264. SceInfAdmins = "Administrators"
  265. SceInfAcountOp = "Account Operators"
  266. SceInfAuthUsers = "Authenticated Users"
  267. SceInfInteractive = "INTERACTIVE"
  268. SceInfBackupOp = "Backup Operators"
  269. SceInfDomainAdmins = "Domain Admins"
  270. SceInfDomainGuests = "Domain Guests"
  271. SceInfDomainUsers = "Domain Users"
  272. SceInfEveryone = "Everyone"
  273. SceInfGuests = "Guests"
  274. SceInfGuest = "Guest"
  275. SceInfLocalService = "Local Service"
  276. SceInfNetworkService = "Network Service"
  277. SceInfPowerUsers = "Power Users"
  278. SceInfPrintOp = "Print Operators"
  279. SceInfReplicator = "Replicator"
  280. SceInfRemoteDesktopUsers = "Remote Desktop Users"
  281. SceInfServerOp = "Server Operators"
  282. SceInfUsers = "Users"
  283. SceInfProgramFiles = "%ProgramFiles%"
  284. SceInfProgramFilesx86 = "%ProgramFiles(x86)%"
  285. SceInfCommonProgramFiles = "%CommonProgramFiles%"
  286. SceDSUpProfileDescription = "Security applied to upgraded terminal servers"
  287. SCEInfSysdir1 = "edit.com"
  288. SCEInfSysdir2 = "edit.hlp"
  289. SCEInfHelp1 = "signin.hlp"
  290.