Enforcing separate sets of policy of compliance settings to users vs administrators

Need some advices.
I would like to achieve this:
Enforcing 2 different sets of security hardening settings to local users vs administrators using BigFix Compliance.
There is no AD in our environment,
Basically, the administrators when login can do almost anything that administrators is granted privilege with. The users when log on should see a locked down Windows, where only the specified application UI is available, no access to taskbar, start menu, Windows explorer, taskbar context menu, empty desktop.
I would like to do this through BigFix. What is the best way to do this?

The standard advice is to ask yourself ‘How would I do this using the command-line?’.

That done, you can then convert that to Bigfix.

Local security policies are likely to be the answer here.

Sounds like Kiosk Mode, that should help with googling. As @trn says, once you know the configuration that is needed, we can help you do it with BigFix.

I always posted queries only after I had exhausted Googling.
So far there isn’t any information on the Internet about how this can be done through command line.
Applying the compliance policy set to the whole computer and all the users on the computer can do this through BigFix, no problem about that.
To apply to specific users or groups, manually how this is being done:

  1. Create a Group Policy Object Editor MMC, scoped to specifc users or groups. In my requirement, I scoped to non-administrators.
  2. Use this mmc, set the required settings. Since the mmc scope to users or groups, only the User Configuration container is available.
  3. When settings are configured through this MMC, Windows creates a registry.pol under a subfolder (named according to the SID of the users or groups) under the %systemroot%\system32\GroupPolicyUsers directory. In the case of non-administrators, the SID is S-1-5-32-545, which is the SID of users group.
  4. This registry.pol can be copied to other computer to achieve the same results.

Based on this step, we should be able to do this through BigFix, should be something like this:

  1. Check the users’ membership, if users are non-administrators, then get the SID
  2. In Windows registry, go to HKU\SID, then set the corresponding registry values
  3. The relevant check must be done continuously, if users are added to administrators group, then the corresponding registry change must be reset. If new users are added to the users group, the fixlets must then be applied to corresponding keys\values under the new SID.

Can relevant check be done at every logon?

Ah, good find. If you have policies working already, then that’s not exactly the ‘Kiosk Mode’ I described earlier, this sound like more a case for Multiple Local Group Policies (MLGPO).

You won’t need Relevance to constantly evaluate a user’s group membership - instead you need to evaluate that your MLGPO is applied for whichever groups are of concern. I have some content at BigFix.me, check for LGPO or MLGPO. Most MLGPO examples are to apply one policy for Administrators and another for Users, but you can also target any arbitrary group using the group SID.

You can configure the policies using LGPO.exe. For Relevance evaluation, what I’ve done in the past is to build an Action to periodically export the registry.pol to text (also using lgpo.exe), and base the relevance evaluation on the text file contents.

In short, don’t configure per-user registries, configure per-group Local Group Policy.

A couple of examples

This one has the correct URL for LGPO.exe and an example of applying a policy
https://www.bigfix.me/fixlet/details/24619

This one is older, and used manual caching, but an example of exporting the LGPO to registry keys that can be used for relevance checking

https://bigfix.me/fixlet/details/22387

Sorry for asking, I would like to change the downloading from Internet to just upload the lgpo.exe file to the BigFix repository as our environment has no Internet access. Is it just to change the url and the hashes? Can I just do a copy of the file lgpo.exe to the %systemroot%\system32 of target computer so the computer will be able to just execute the lgpo command when needed? Any example actionscript I can refer to?

begin prefetch block

add prefetch item name=LGPO.zip sha1=0c74dac83aed569607aaa6df152206c709eef769 size=815660 url=https://download.microsoft.com/download/8/5/C/85C25433-A1B0-4FFA-9429-7E023E7DA8D8/LGPO.zip sha256=6ffb6416366652993c992280e29faea3507b5b5aa661c33ba1af31f48acea9c4

// Download UnZip utility
add prefetch item name=unzip.exe sha1=e1652b058195db3f5f754b7ab430652ae04a50b8 size=167936 url=http://software.bigfix.com/download/redist/unzip-5.52.exe sha256=8d9b5190aace52a1db1ac73a65ee9999c329157c8e88f61a772433323d6b7a4a

collect prefetch items
end prefetch block

I had done one testing using a simple fixlet based on your input:
begin prefetch block

add prefetch item name=LGPO.zip sha1=0c74dac83aed569607aaa6df152206c709eef769 size=815660 url=https://download.microsoft.com/download/8/5/C/85C25433-A1B0-4FFA-9429-7E023E7DA8D8/LGPO.zip sha256=6ffb6416366652993c992280e29faea3507b5b5aa661c33ba1af31f48acea9c4

// Download UnZip utility
add prefetch item name=unzip.exe sha1=e1652b058195db3f5f754b7ab430652ae04a50b8 size=167936 url=http://software.bigfix.com/download/redist/unzip-5.52.exe sha256=8d9b5190aace52a1db1ac73a65ee9999c329157c8e88f61a772433323d6b7a4a

collect prefetch items
end prefetch block

// Add LGPO.zip to the client utility cache
utility __Download\LGPO.zip

// Add unzip.exe to the client utility cache
utility __Download\unzip.exe

waithidden __Download\unzip.exe -o “{pathname of client folder of current site}__Download\LGPO.zip” -d “{pathname of client folder of current site}__Download”

action uses wow64 redirection false

delete __createfile
createfile until EOF_EOF_EOF
; ----------------------------------------------------------------------
; PARSING User:Non-Administrators POLICY
; Source file: c:\windows\system32\grouppolicyusers\S-1-5-32-545\user\registry.pol

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ShowTaskViewButton
DWORD:0

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Associations
BlockFileElevation
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Associations
BlockProtocolElevation
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\DataCollection
MicrosoftEdgeDataOptIn
DELETE

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoControlPanel
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoDesktop
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoClose
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoSetTaskbar
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoTrayContextMenu
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoWelcomeScreen
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoSMBalloonTip
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoCommonGroups
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoStartMenuMFUprogramsList
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoWindowsUpdate
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoNetworkConnections
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoStartMenuPinnedList
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoSearchComputerLinkInStartMenu
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoFind
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HideSCAPower
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HideSCANetwork
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HideSCAHealth
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HideSCAVolume
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoUserNameInStartMenu
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoStartMenuSubFolders
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
TaskbarNoNotification
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
QuickLaunchEnabled
DWORD:0

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoAutoTrayNotify
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Intellimenus
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
TaskbarNoThumbnail
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoInstrumentation
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoPublishingWizard
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoWebServices
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoOnlinePrintsWizard
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoInternetOpenWith
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
DontSetAutoplayCheckbox
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoAutorun
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoDriveTypeAutoRun
DWORD:255

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
RestrictWelcomeCenter
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoDrives
DWORD:67108863

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoManageMyComputerVerb
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoFolderOptions
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoComputersNearMe
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoViewOnDrive
DWORD:67108863

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
PreventItemCreationInUsersFilesFolder
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoNetConnectDisconnect
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoViewContextMenu
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoFileMenu
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoHardwareTab
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoShellSearchButton
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoSecurityTab
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoSharedDocuments
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoChangeKeyboardNavigationIndicators
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoChangeAnimation
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoThumbnailCache
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
DisableThumbnailsOnNetworkFolders
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
DisableThumbnails
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoWinKeys
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoToolbarsOnTaskbar
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoRecentDocsHistory
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoSearchCommInStartMenu
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoSearchFilesInStartMenu
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoSearchInternetInStartMenu
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoSearchProgramsInStartMenu
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoResolveSearch
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoResolveTrack
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoTrayItemsDisplay
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
TaskbarLockAll
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
LockTaskbar
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoTaskGrouping
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
TaskbarNoAddRemoveToolbar
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoChangeStartMenu
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
TaskbarNoRedock
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
TaskbarNoDragToolbar
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
TaskbarNoResize
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HideClock
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
ClearRecentDocsOnExit
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
ClearRecentProgForNewUserInStartMenu
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
ForceStartMenuLogOff
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
DisablePersonalDirChange
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoDesktopCleanupWizard
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoInternetIcon
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoNetHood
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoPropertiesMyComputer
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoPropertiesMyDocuments
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoRecentDocsNetHood
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoPropertiesRecycleBin
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoSaveSettings
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoCloseDragDropBands
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoMovingBands
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoActiveDesktop
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoStartMenuMorePrograms
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoSimpleStartMenu
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
StartMenuLogOff
DELETE

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\WAU
Disabled
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\MobilityCenter
NoMobilityCenter
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Network
NoEntireNetwork
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
{20D04FE0-3AEA-1069-A2D8-08002B30309D}
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
{450D8FBA-AD25-11D0-98A8-0800361B1103}
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
{645FF040-5081-101B-9F08-00AA002F954E}
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
DWORD:2

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableLockWorkstation
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Windows\Sidebar
TurnOffSidebar
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Windows\Sidebar
TurnOffUserInstalledGadgets
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Windows\Sidebar
TurnOffUnsignedGadgets
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Search
SearchboxTaskbarMode
DWORD:0

User:Non-Administrators
Software\Policies\Microsoft\Assistance\Client\1.0
NoOnlineAssist
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Assistance\Client\1.0
NoExplicitFeedback
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Assistance\Client\1.0
NoImplicitFeedback
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\InternetManagement
RestrictCommunication
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Messenger\Client
CEIP
DWORD:2

User:Non-Administrators
Software\Policies\Microsoft\Messenger\Client
PreventRun
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Messenger\Client
PreventAutoRun
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\PassportForWork
Enabled
DWORD:0

User:Non-Administrators
Software\Policies\Microsoft\PassportForWork
DisablePostLogonProvisioning
DWORD:0

User:Non-Administrators
Software\Policies\Microsoft\Windows\AppCompat
DisablePCA
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\CredUI
DisablePasswordReveal
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\CurrentVersion\PushNotifications
NoTileApplicationNotification
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\CurrentVersion\PushNotifications
NoToastApplicationNotificationOnLockScreen
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\CurrentVersion\PushNotifications
NoToastApplicationNotification
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\CurrentVersion\PushNotifications
DisallowNotificationMirroring
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\DataCollection
AllowTelemetry
DELETE

User:Non-Administrators
Software\Policies\Microsoft\Windows\Digital Locker
DoNotRunDigitalLocker
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\EdgeUI
AllowEdgeSwipe
DWORD:0

User:Non-Administrators
Software\Policies\Microsoft\Windows\EdgeUI
DisableHelpSticker
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\EdgeUI
DisableRecentApps
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\EdgeUI
ShowCommandPromptOnWinX
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\EdgeUI
DisableCharms
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\EdgeUI
TurnOffBackstack
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\EdgeUI
DisableMFUTracking
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
HideRecentlyAddedApps
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
DisableNotificationCenter
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
TaskbarNoPinnedList
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
NoSearchEverywhereLinkInStartMenu
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
HidePeopleBar
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
ShowWindowsStoreAppsOnTaskbar
DWORD:2

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
ShowRunAsDifferentUserInStart
DWORD:0

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
NoSystraySystemPromotion
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
NoBalloonFeatureAdvertisements
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
NoUseStoreOpenWith
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
NoAutoplayfornonVolume
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
TryHarderPinnedOpenSearch
DWORD:0

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
OpenSearch0
DELETE

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
OpenSearchLabel0
DELETE

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
OpenSearch1
DELETE

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
OpenSearchLabel1
DELETE

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
OpenSearch2
DELETE

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
OpenSearchLabel2
DELETE

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
OpenSearch3
DELETE

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
OpenSearchLabel3
DELETE

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
OpenSearch4
DELETE

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
OpenSearchLabel4
DELETE

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
NoSearchInternetTryHarderButton
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
DisableSearchBoxSuggestions
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
DisableThumbsDBOnNetworkFolders
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
HideContentViewModeSnippets
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
DisableIndexedLibraryExperience
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
AddSearchInternetLinkInStartMenu
DWORD:0

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
DisableContextMenusInStart
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
EnableLegacyBalloonNotifications
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
NoPinningToDestinations
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
NoPinningToTaskbar
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
NoPinningStoreToTaskbar
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
TaskbarNoMultimon
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
NoRemoteDestinations
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
NoUninstallFromStart
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
ClearTilesOnExit
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
NoWindowMinimizingShortcuts
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
LockedStartLayout
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
StartLayoutFile
EXSZ:C:\Windows\System32\GroupPolicyUsers\S-1-5-32-545\User\StartLayout.xml

User:Non-Administrators
Software\Policies\Microsoft\Windows\HandwritingErrorReports
PreventHandwritingErrorReports
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Installer
DisableMedia
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Installer
AlwaysInstallElevated
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\RemovableStorageDevices
Deny_All
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Settings
AllowConfigureTaskbarCalendar
DWORD:0

User:Non-Administrators
Software\Policies\Microsoft\Windows\Settings
ConfigureTaskbarCalendar
DELETE

User:Non-Administrators
Software\Policies\Microsoft\Windows\System
DisableCMD
DWORD:2

User:Non-Administrators
Software\Policies\Microsoft\Windows\TabletPC
PreventHandwritingDataSharing
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Windows Error Reporting
Disabled
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows NT\CurrentVersion\Software Protection Platform
NoGenTicket
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows NT\CurrentVersion\Software Protection Platform
AllowWindowsEntitlementReactivation
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows NT\Printers
DisableHTTPPrinting
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows NT\Printers
DisableWebPnPDownload
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\WindowsMovieMaker
WebHelp
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\WindowsMovieMaker
CodecDownload
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\WindowsMovieMaker
WebPublish
DWORD:1

; PARSING COMPLETED.
; ----------------------------------------------------------------------

EOF_EOF_EOF

delete regpol.txt
move __createfile regpol.txt

waithidden __Download\LGPO.exe /t regpol.txt
continue if {exit code of action = 0}


It returns Failed.

The Action execution detail:
The status after came back as failed, the action steps recorded as follows:
Completed // To use this template, update or remove the following blocks and replace the Relevance
Completed // Enter your action script here
Completed begin prefetch block
Completed add prefetch item name=LGPO.zip sha1=0c74dac83aed569607aaa6df152206c709eef769 size=815660 url=https://download.microsoft.com/download/8/5/C/85C25433-A1B0-4FFA-9429-7E023E7DA8D8/LGPO.zip sha256=6ffb6416366652993c992280e29faea3507b5b5aa661c33ba1af31f48acea9c4
Completed // Download UnZip utility
Completed add prefetch item name=unzip.exe sha1=e1652b058195db3f5f754b7ab430652ae04a50b8 size=167936 url=http://software.bigfix.com/download/redist/unzip-5.52.exe sha256=8d9b5190aace52a1db1ac73a65ee9999c329157c8e88f61a772433323d6b7a4a
Completed collect prefetch items
Completed end prefetch block
Completed // Add LGPO.zip to the client utility cache
Completed utility __Download\LGPO.zip
Completed // Add unzip.exe to the client utility cache
Completed utility __Download\unzip.exe
Completed waithidden __Download\unzip.exe -o “{pathname of client folder of current site}__Download\LGPO.zip” -d "{pathname of client folder of current site}__Download"
Completed action uses wow64 redirection false
Completed delete __createfile
Completed createfile until EOF_EOF_EOF
Completed ; ----------------------------------------------------------------------
Completed ; PARSING User:Non-Administrators POLICY
Completed ; Source file: c:\windows\system32\grouppolicyusers\S-1-5-32-545\user\registry.pol
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Completed ShowTaskViewButton
Completed DWORD:0
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Associations
Completed BlockFileElevation
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Associations
Completed BlockProtocolElevation
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\DataCollection
Completed MicrosoftEdgeDataOptIn
Completed DELETE
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoControlPanel
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoDesktop
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoClose
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoSetTaskbar
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoTrayContextMenu
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoWelcomeScreen
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoSMBalloonTip
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoCommonGroups
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoStartMenuMFUprogramsList
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoWindowsUpdate
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoNetworkConnections
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoStartMenuPinnedList
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoSearchComputerLinkInStartMenu
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoFind
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed HideSCAPower
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed HideSCANetwork
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed HideSCAHealth
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed HideSCAVolume
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoUserNameInStartMenu
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoStartMenuSubFolders
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed TaskbarNoNotification
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed QuickLaunchEnabled
Completed DWORD:0
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoAutoTrayNotify
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed Intellimenus
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed TaskbarNoThumbnail
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoInstrumentation
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoPublishingWizard
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoWebServices
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoOnlinePrintsWizard
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoInternetOpenWith
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed DontSetAutoplayCheckbox
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoAutorun
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoDriveTypeAutoRun
Completed DWORD:255
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed RestrictWelcomeCenter
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoDrives
Completed DWORD:67108863
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoManageMyComputerVerb
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoFolderOptions
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoComputersNearMe
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoViewOnDrive
Completed DWORD:67108863
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed PreventItemCreationInUsersFilesFolder
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoNetConnectDisconnect
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoViewContextMenu
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoFileMenu
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoHardwareTab
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoShellSearchButton
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoSecurityTab
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoSharedDocuments
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoChangeKeyboardNavigationIndicators
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoChangeAnimation
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoThumbnailCache
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed DisableThumbnailsOnNetworkFolders
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed DisableThumbnails
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoWinKeys
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoToolbarsOnTaskbar
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoRecentDocsHistory
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoSearchCommInStartMenu
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoSearchFilesInStartMenu
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoSearchInternetInStartMenu
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoSearchProgramsInStartMenu
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoResolveSearch
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoResolveTrack
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoTrayItemsDisplay
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed TaskbarLockAll
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed LockTaskbar
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoTaskGrouping
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed TaskbarNoAddRemoveToolbar
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoChangeStartMenu
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed TaskbarNoRedock
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed TaskbarNoDragToolbar
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed TaskbarNoResize
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed HideClock
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed ClearRecentDocsOnExit
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed ClearRecentProgForNewUserInStartMenu
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed ForceStartMenuLogOff
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed DisablePersonalDirChange
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoDesktopCleanupWizard
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoInternetIcon
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoNetHood
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoPropertiesMyComputer
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoPropertiesMyDocuments
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoRecentDocsNetHood
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoPropertiesRecycleBin
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoSaveSettings
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoCloseDragDropBands
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoMovingBands
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoActiveDesktop
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoStartMenuMorePrograms
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed NoSimpleStartMenu
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Completed StartMenuLogOff
Completed DELETE
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\WAU
Completed Disabled
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\MobilityCenter
Completed NoMobilityCenter
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\Network
Completed NoEntireNetwork
Completed DWORD:1
Completed
Completed User:Non-Administrators
Completed Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
Failed {20D04FE0-3AEA-1069-A2D8-08002B30309D}
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
{450D8FBA-AD25-11D0-98A8-0800361B1103}
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
{645FF040-5081-101B-9F08-00AA002F954E}
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
DWORD:2

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableLockWorkstation
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Windows\Sidebar
TurnOffSidebar
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Windows\Sidebar
TurnOffUserInstalledGadgets
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Policies\Windows\Sidebar
TurnOffUnsignedGadgets
DWORD:1

User:Non-Administrators
Software\Microsoft\Windows\CurrentVersion\Search
SearchboxTaskbarMode
DWORD:0

User:Non-Administrators
Software\Policies\Microsoft\Assistance\Client\1.0
NoOnlineAssist
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Assistance\Client\1.0
NoExplicitFeedback
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Assistance\Client\1.0
NoImplicitFeedback
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\InternetManagement
RestrictCommunication
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Messenger\Client
CEIP
DWORD:2

User:Non-Administrators
Software\Policies\Microsoft\Messenger\Client
PreventRun
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Messenger\Client
PreventAutoRun
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\PassportForWork
Enabled
DWORD:0

User:Non-Administrators
Software\Policies\Microsoft\PassportForWork
DisablePostLogonProvisioning
DWORD:0

User:Non-Administrators
Software\Policies\Microsoft\Windows\AppCompat
DisablePCA
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\CredUI
DisablePasswordReveal
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\CurrentVersion\PushNotifications
NoTileApplicationNotification
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\CurrentVersion\PushNotifications
NoToastApplicationNotificationOnLockScreen
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\CurrentVersion\PushNotifications
NoToastApplicationNotification
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\CurrentVersion\PushNotifications
DisallowNotificationMirroring
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\DataCollection
AllowTelemetry
DELETE

User:Non-Administrators
Software\Policies\Microsoft\Windows\Digital Locker
DoNotRunDigitalLocker
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\EdgeUI
AllowEdgeSwipe
DWORD:0

User:Non-Administrators
Software\Policies\Microsoft\Windows\EdgeUI
DisableHelpSticker
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\EdgeUI
DisableRecentApps
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\EdgeUI
ShowCommandPromptOnWinX
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\EdgeUI
DisableCharms
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\EdgeUI
TurnOffBackstack
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\EdgeUI
DisableMFUTracking
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
HideRecentlyAddedApps
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
DisableNotificationCenter
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
TaskbarNoPinnedList
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
NoSearchEverywhereLinkInStartMenu
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
HidePeopleBar
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
ShowWindowsStoreAppsOnTaskbar
DWORD:2

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
ShowRunAsDifferentUserInStart
DWORD:0

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
NoSystraySystemPromotion
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
NoBalloonFeatureAdvertisements
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
NoUseStoreOpenWith
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
NoAutoplayfornonVolume
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
TryHarderPinnedOpenSearch
DWORD:0

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
OpenSearch0
DELETE

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
OpenSearchLabel0
DELETE

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
OpenSearch1
DELETE

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
OpenSearchLabel1
DELETE

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
OpenSearch2
DELETE

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
OpenSearchLabel2
DELETE

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
OpenSearch3
DELETE

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
OpenSearchLabel3
DELETE

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
OpenSearch4
DELETE

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
OpenSearchLabel4
DELETE

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
NoSearchInternetTryHarderButton
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
DisableSearchBoxSuggestions
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
DisableThumbsDBOnNetworkFolders
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
HideContentViewModeSnippets
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
DisableIndexedLibraryExperience
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
AddSearchInternetLinkInStartMenu
DWORD:0

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
DisableContextMenusInStart
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
EnableLegacyBalloonNotifications
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
NoPinningToDestinations
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
NoPinningToTaskbar
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
NoPinningStoreToTaskbar
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
TaskbarNoMultimon
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
NoRemoteDestinations
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
NoUninstallFromStart
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
ClearTilesOnExit
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
NoWindowMinimizingShortcuts
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
LockedStartLayout
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Explorer
StartLayoutFile
EXSZ:C:\Windows\System32\GroupPolicyUsers\S-1-5-32-545\User\StartLayout.xml

User:Non-Administrators
Software\Policies\Microsoft\Windows\HandwritingErrorReports
PreventHandwritingErrorReports
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Installer
DisableMedia
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Installer
AlwaysInstallElevated
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\RemovableStorageDevices
Deny_All
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Settings
AllowConfigureTaskbarCalendar
DWORD:0

User:Non-Administrators
Software\Policies\Microsoft\Windows\Settings
ConfigureTaskbarCalendar
DELETE

User:Non-Administrators
Software\Policies\Microsoft\Windows\System
DisableCMD
DWORD:2

User:Non-Administrators
Software\Policies\Microsoft\Windows\TabletPC
PreventHandwritingDataSharing
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows\Windows Error Reporting
Disabled
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows NT\CurrentVersion\Software Protection Platform
NoGenTicket
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows NT\CurrentVersion\Software Protection Platform
AllowWindowsEntitlementReactivation
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows NT\Printers
DisableHTTPPrinting
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\Windows NT\Printers
DisableWebPnPDownload
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\WindowsMovieMaker
WebHelp
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\WindowsMovieMaker
CodecDownload
DWORD:1

User:Non-Administrators
Software\Policies\Microsoft\WindowsMovieMaker
WebPublish
DWORD:1

; PARSING COMPLETED.
; ----------------------------------------------------------------------

EOF_EOF_EOF
delete regpol.txt
move __createfile regpol.txt
waithidden __Download\LGPO.exe /t regpol.txt
continue if {exit code of action = 0}


Checking at the client side, nothing was done. Anyone can figure out what was wrong? Where can I check what went wrong?

Sorry, still scrolling my phone, catch up to you in a bit… :slight_smile:

Ok here I am …

Check the ‘Failed’ line. There’s a GUID in your text that is being evaluated as a Relevance Substitution . Change the { to {{
I’m also not sure that’s the right format for MLGPO. The LGPO download has a PDF in it with instructions, check that to be sure. I thought all the text should specify USER, and then in the LGPO.command line we specify which “User” it applies too, but I’m.not certain on that point.

Thank you.
I added the ‘{’ and ‘}’, this allow the execution of all the lines completed but it still show status of failed.
I checked at the target computer, the non-admin hardening is done. So, it works, though need to find out why status is ‘failed’.

For LGPO usage, we have to first parse registry.pol to .txt using LGPO /ua, then when apply the non-admin .txt to the target computer, run the GLPO.exe /t.

The setting contains one ‘Start Layout’ which requires an .xml file, so this file need to be copied to the location specified in the ‘start layout’ setting. any example actionscript for copying a file? I want it copied to %systemroot%\system32\grouppolicyusers\user.

A drawback of this method is that it only takes care of the settings in ‘Administrative Template’, the settings under ‘Windows Settings’ in GPO aren’t captured. In my requirement, I need a logon script, this isn’t incorporated, so the resultant GPO doesn’t have this setting.

I think the easiest way to do hardening when computers are not joined to domain, is simply just set up one machine, harden the necessary, then copy all the files under %systemroot%\system32\grouppolicy and %systemroot%\system32\grouppolicyusers to the target computer, then run a secedit or lgpo command to apply the .inf. The .inf can be obtained from running lgpo /b, then using lgpo /s to apply at the target, or using scedit export, then import. Or, a fixlet can be created to compose the .inf and run lgpo /s.
Then for Windows Firewall, have to export firewall rulse to .wfw and import into target, via netsh.

So far I find that if I use fixlets available in BigFix to harden the settings under Administrative Templates, they are able to set the registry values correctly but the settings value aren’t reflected in GPO, that is, in gpedit.msc, all the values in Administrative Templates remains as ‘Not Configured’. This may be correct behaviour of Windows but this doesn’t look good for auditing. However, if I simply copy the respective registry.pol files into the grouppolicy\user and grouppolicy\machine, then they show up correctly in gpedit.msc.

Maybe there is other better ways to accomplish this.