Source code of Windows XP (NT5)
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

339 lines
18 KiB

  1. @*:This file defines default security settings.
  2. @*:Please do not edit. Instead, email kirksol with the requested change.
  3. @*:Thanks!
  4. ; (c) Microsoft Corporation 1997-2000
  5. ;
  6. ; Security Configuration Template for Security Configuration Manager
  7. ;
  8. ; Template Name: DPUp.INF copied to DWUp.INF on the Personal SKU as specified in the layout.inf for personal.
  9. ;
  10. ; Applied on Personal to Personal Upgrade.
  11. ; Upgrades from Win9x are treated as clean-installs.
  12. ; Therefore settings are defined only in the following circumstances:
  13. ; 1. OS-Specific Objects that users nor apps should change.
  14. ; 2. Setting did not exist on previous builds.
  15. ; 3. Setting changed from less secure to more secure value.
  16. [Profile Description]
  17. %SCEDefltProfileDescription%
  18. [version]
  19. signature="$CHICAGO$"
  20. revision=1
  21. [System Access]
  22. ;Clean up Beta accounts that did not have password never expires flag set
  23. MaximumPasswordAge = -1
  24. LSAAnonymousNameLookup = 0
  25. ;----------------------------------------------------------------
  26. ;Event Log - Log Settings
  27. ;----------------------------------------------------------------
  28. ;Audit Log Retention Period:
  29. ;0 = Overwrite Events As Needed
  30. ;1 = Overwrite Events As Specified by Retention Days Entry
  31. ;2 = Never Overwrite Events (Clear Log Manually)
  32. [System Log]
  33. AuditLogRetentionPeriod = 0
  34. [Security Log]
  35. AuditLogRetentionPeriod = 0
  36. [Application Log]
  37. AuditLogRetentionPeriod = 0
  38. ;----------------------------------------------------------------------
  39. ; Local Policies\Audit Policy
  40. ;----------------------------------------------------------------------
  41. [Event Audit]
  42. AuditSystemEvents = 3
  43. AuditPolicyChange = 3
  44. AuditAccountManage = 3
  45. AuditAccountLogon = 3
  46. AuditLogonEvents = 3
  47. ;----------------------------------------------------------------
  48. ;Registry Values
  49. ;----------------------------------------------------------------
  50. [Registry Values]
  51. ;Changes from Beta Releases
  52. MACHINE\System\CurrentControlSet\Control\Lsa\DisableDomainCreds=4,0
  53. MACHINE\System\CurrentControlSet\Control\Lsa\FIPSAlgorithmPolicy=4,0
  54. MACHINE\System\CurrentControlSet\Control\Lsa\LimitBlankPasswordUse=4,1
  55. MACHINE\System\CurrentControlSet\Control\Lsa\NoDefaultAdminOwner=4,1
  56. MACHINE\System\CurrentControlSet\Control\Lsa\RestrictAnonymousSAM=4,1
  57. MACHINE\System\CurrentControlSet\Control\Session Manager\Kernel\ObCaseInsensitive=4,1
  58. MACHINE\System\CurrentControlSet\Services\LDAP\LDAPClientIntegrity=4,1
  59. MACHINE\System\CurrentControlSet\Services\Netlogon\Parameters\RequireSignOrSeal=4,1
  60. MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\UndockWithoutLogon=4,1
  61. [Privilege Rights]
  62. ;
  63. ;World S-1-1-0
  64. ;
  65. ;NT Authority S-1-5
  66. ;LOCAL_SERVICE 19
  67. ;NETWORK_SERVICE 20
  68. ;
  69. ;Built-In Domain SubAuthority = S-1-5-32
  70. ;ADMINISTRATORS 544
  71. ;USERS 545
  72. ;GUESTS 546
  73. ;POWER_USERS 547
  74. ;ACCOUNT_OPS 548
  75. ;SYSTEM_OPS 549
  76. ;PRINT_OPS 550
  77. ;BACKUP_OPS 551
  78. ;REPLICATOR 552
  79. ;RAS_SERVERS 553
  80. ;PREW2KCOMPACCESS 554
  81. ;REMOTE_DESKTOP_USERS 555
  82. ;NETWORK_CONFIGURATION_OPS 556
  83. ;Changes from B1
  84. SeAssignPrimaryTokenPrivilege = Add:, *S-1-5-19, *S-1-5-20
  85. SeIncreaseQuotaPrivilege = Add:, *S-1-5-19, *S-1-5-20
  86. SeSystemTimePrivilege = Remove:, *S-1-5-19, *S-1-5-20
  87. [Service General Setting]
  88. ;Note - SCECLI is hooked so that startup mode is not configured during setup or dcpromo
  89. ;autostarted on workstations and servers, standalone or joined - Remove PU ability to stop\start.
  90. Browser,2,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  91. Dhcp,2,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRRC;;;NO)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  92. TrkWks,2,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  93. Dnscache,2,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRRC;;;NO)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  94. Eventlog,2,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  95. PolicyAgent,2,"D:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  96. dmserver,2,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  97. Messenger,2,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  98. PlugPlay,2,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  99. Spooler,2,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  100. ProtectedStorage,2,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  101. RpcSs,2,"D:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLO;;;IU)(A;;CCLCSWRPLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  102. NtmsSvc,2,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  103. seclogon,2,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  104. SamSs,2,"D:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLO;;;IU)(A;;CCLCSWRPLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  105. lanmanserver,2,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  106. SENS,2,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  107. Schedule,2,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  108. LmHosts,2,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  109. LanmanWorkstation,2,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  110. RemoteRegistry,2,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  111. ;Not autostarted, but non-default DACL - Remove PU ability to change template
  112. ClipSrv,3,"D:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLO;;;IU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  113. NetDDE,3,"D:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLO;;;IU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  114. NetDDEdsdm,3,"D:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLO;;;IU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  115. AppMgmt,3,"D:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLO;;;IU)(A;;CCLCSWRPLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  116. EventSystem,3,"D:(A;;CCLCSWRPLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  117. ;Not autostarted if machine is standalone
  118. Netlogon,3,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  119. W32Time,3,"D:(A;;CCLCSWLORC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLO;;;IU)(A;;CCLCSWRPLO;;;BU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  120. ;Not autostarted if Wksta
  121. ;Alerter,2,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  122. ;MSDTC,2,"D:(A;;CCLCSWRPLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLORC;;;NS)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  123. ;Server Only Services
  124. ;Dfs,2,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  125. ;LicenseService,2,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  126. ;SMTPSVC,2,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  127. ;IIS Specific Services - Leave them alone
  128. ;IISADMIN,2,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  129. ;W3SVC,2,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  130. ;MSFTPSVC,2,"D:(A;;CCLCSWLOCRRC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"
  131. [Registry Keys]
  132. "MACHINE\Software",0,"D:P(A;CI;GR;;;BU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  133. ;Same as parent, but this is the target of a symlink - set explicitly.
  134. "MACHINE\SOFTWARE\Classes",2,"D:P(A;CI;GR;;;BU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  135. "MACHINE\SOFTWARE\Microsoft\Cryptography\Calais",2,"D:AR(A;CI;GRGWSD;;;LS)"
  136. "MACHINE\SOFTWARE\Microsoft\NetDDE",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  137. "MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider",1,"D:AR"
  138. ;The following keys do not exist when we run
  139. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy",1,"D:AR"
  140. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer",1,"D:AR"
  141. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies",1,"D:AR"
  142. "MACHINE\SOFTWARE\Microsoft\MSDTC",1,"D:AR"
  143. "MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony",2,"D:P(A;CIOI;GR;;;BU)(A;CIOI;GRGWSD;;;PU)(A;CIOI;GA;;;NS)(A;CIOI;GA;;;LS)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  144. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib",2,"D:P(A;CI;GR;;;IU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)(A;CI;GR;;;NS)"
  145. "MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\009",1,"D:AR"
  146. "MACHINE\System",2,"D:P(A;CI;GR;;;BU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  147. "MACHINE\SYSTEM\Clone",1,"D:AR"
  148. "MACHINE\SYSTEM\ControlSet001",1,"D:AR"
  149. "MACHINE\SYSTEM\ControlSet002",1,"D:AR"
  150. "MACHINE\SYSTEM\ControlSet003",1,"D:AR"
  151. "MACHINE\SYSTEM\ControlSet004",1,"D:AR"
  152. "MACHINE\SYSTEM\ControlSet005",1,"D:AR"
  153. "MACHINE\SYSTEM\ControlSet006",1,"D:AR"
  154. "MACHINE\SYSTEM\ControlSet007",1,"D:AR"
  155. "MACHINE\SYSTEM\ControlSet008",1,"D:AR"
  156. "MACHINE\SYSTEM\ControlSet009",1,"D:AR"
  157. "MACHINE\SYSTEM\ControlSet010",1,"D:AR"
  158. "MACHINE\SYSTEM\CurrentControlSet\Control\Class",0,"D:AR"
  159. "MACHINE\SYSTEM\CurrentControlSet\Control\Keyboard Layout",2,"D:(A;CI;GR;;;WD)"
  160. "MACHINE\SYSTEM\CurrentControlSet\Control\Keyboard Layouts",2,"D:(A;CI;GR;;;WD)"
  161. "MACHINE\SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg",2,"D:P(A;CI;GA;;;BA)(A;CI;GR;;;LS)"
  162. "MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Security",2,"D:P(A;CI;GR;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  163. "MACHINE\SYSTEM\CurrentControlSet\Enum",1,"D:AR"
  164. "MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles",1,"D:AR"
  165. ;Don't whack more restrictive security subkeys.
  166. "MACHINE\SYSTEM\CurrentControlSet\Services",0,"D:AR"
  167. ;Set security subkey permissions for those services created via default hives
  168. "MACHINE\SYSTEM\CurrentControlSet\Services\AppMgmt\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  169. "MACHINE\SYSTEM\CurrentControlSet\Services\ClipSrv\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  170. "MACHINE\SYSTEM\CurrentControlSet\Services\CryptSvc\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  171. "MACHINE\SYSTEM\CurrentControlSet\Services\ERSvc\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  172. "MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  173. @@:@6:"MACHINE\SYSTEM\CurrentControlSet\Services\IASJet\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  174. "MACHINE\SYSTEM\CurrentControlSet\Services\NetDDE\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  175. "MACHINE\SYSTEM\CurrentControlSet\Services\NetDDEdsdm\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  176. "MACHINE\SYSTEM\CurrentControlSet\Services\RpcSs\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  177. "MACHINE\SYSTEM\CurrentControlSet\Services\Samss\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  178. "MACHINE\SYSTEM\CurrentControlSet\Services\ScardDrv\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  179. "MACHINE\SYSTEM\CurrentControlSet\Services\SCardSvr\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  180. "MACHINE\SYSTEM\CurrentControlSet\Services\TapiSrv\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  181. "MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  182. ;Set security subkey permissions for those services created in GUI-mode setup before SCE runs
  183. "MACHINE\SYSTEM\CurrentControlSet\Services\IREnum\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  184. "MACHINE\SYSTEM\CurrentControlSet\Services\STISvc\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  185. "MACHINE\SYSTEM\CurrentControlSet\Services\WMI\Security",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  186. "MACHINE\SYSTEM\CurrentControlSet\Services\SysmonLog\Log Queries",2,"D:(A;CI;GA;;;NS)"
  187. "USERS\.DEFAULT",2,"D:P(A;CI;GR;;;BU)(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  188. "USERS\.DEFAULT\Software\Microsoft\NetDDE",2,"D:P(A;CI;GA;;;BA)(A;CI;GA;;;SY)(A;CI;GA;;;CO)"
  189. "USERS\.DEFAULT\SOFTWARE\Microsoft\Protected Storage System Provider",1,"D:AR"
  190. "USERS\.DEFAULT\SOFTWARE\Microsoft\SystemCertificates\Root\ProtectedRoots",1,"D:AR"
  191. [File Security]
  192. ;---------------------------------------------------------------------------------------
  193. ;x86 Boot Files
  194. ;---------------------------------------------------------------------------------------
  195. @@:@i:"%BootDrive%\boot.ini",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  196. @@:@i:"%BootDrive%\ntdetect.com",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  197. @@:@i:"%BootDrive%\ntldr",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  198. @@:@i:"%BootDrive%\ntbootdd.sys",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  199. @@:@i:"%BootDrive%\autoexec.bat",2,"D:P(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  200. @@:@i:"%BootDrive%\config.sys",2,"D:P(A;;GRGX;;;BU)(A;;GA;;;BA)(A;;GA;;;SY)"
  201. ;---------------------------------------------------------------------------------------
  202. ;amd64 Boot Files
  203. ;---------------------------------------------------------------------------------------
  204. @@:@a:"%BootDrive%\boot.ini",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  205. @@:@a:"%BootDrive%\ntdetect.com",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  206. @@:@a:"%BootDrive%\ntldr",2,"D:P(A;;GA;;;BA)(A;;GA;;;SY)"
  207. ;SetupSecurity will contain the new root acl. Ignore docs and settings if it's reapplied (e.g. on conversion from FAT)
  208. ;Probably not necessary on upgrade, but just in case.
  209. "%SystemDrive%\Documents and Settings",1,"D:AR"
  210. ;---------------------------------------------------------------------------------------------
  211. ;ProgramFiles
  212. ;---------------------------------------------------------------------------------------------
  213. "%SceInfProgramFiles%",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  214. ;---------------------------------------------------------------------------------------------
  215. ;System Root (Typically \WINDOWS)
  216. ;---------------------------------------------------------------------------------------------
  217. "%SystemRoot%",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  218. ;Differences from parent
  219. "%SystemRoot%\Debug\UserMode",2,"D:PAR(A;;0x00100023;;;BU)(A;OIIO;0x00100006;;;BU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)"
  220. "%SystemRoot%\repair",2,"D:P(A;CI;GRGX;;;BU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  221. "%SystemRoot%\Temp",2,"D:P(A;CI;0x100026;;;BU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  222. ;Directories that do not exist when security applied during clean-install - Creator specifies directory security.
  223. ;We explicitly ignore so as not to whack the component-specified DIRECTORY security on upgrade or reapplication of defaults.
  224. "%SystemRoot%\CSC",1,"D:AR"
  225. "%SystemRoot%\Installer",1,"D:AR"
  226. "%SystemRoot%\Prefetch",1,"D:AR"
  227. "%SystemRoot%\Profiles",1,"D:AR"
  228. "%SystemRoot%\Registration",1,"D:AR"
  229. "%SystemRoot%\Tasks",1,"D:AR"
  230. ;Directories that do not exist when security applied during setup - Creator does not specify directory security.
  231. ;Creator should specify FILE security in optional component INF that gets applied on clean-install AND upgrade.
  232. ;Omit (rather than ignore) to allow component-specified file security to be set on reapplication of defaults.
  233. ;Use MARTA (rather than omit) for any components that set protected run-time security.
  234. ;"%SystemRoot%\Downloaded Program Files",0,"D:AR"
  235. ;"%SystemRoot%\Offline Web Pages",0,"D:AR"
  236. ;"%SystemRoot%\IME",0,"D:AR"
  237. ;"%SystemRoot%\mww32",0,"D:AR"
  238. ;"%SystemRoot%\PCHEALTH",0,"D:AR"
  239. ;"%SystemRoot%\SchCache",0,"D:AR"
  240. ;"%SystemRoot%\srchasst",0,"D:AR"
  241. "%SystemDirectory%",2,"D:P(A;CIOI;GRGX;;;BU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  242. ;Differences from parent
  243. "%SystemDirectory%\config",2,"D:P(A;CI;GRGX;;;BU)(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  244. ;Profile for system account - moved from Docs and Settings in Whistler. Creator specifies security.
  245. "%SystemDirectory%\config\systemprofile",1,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)"
  246. "%SystemDirectory%\dllcache",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  247. "%SystemDirectory%\ias",2,"D:P(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
  248. ;So spooler can load drivers while impersonating the forced Guest
  249. "%SystemDirectory%\spool\drivers",2,"D:(A;CIOI;GRGX;;;WD)"
  250. ;Directories that do not exist when security applied during clean-install - Creator specifies directory security.
  251. ;We explicitly ignore so as not to whack the component-specified DIRECTORY security on upgrade or reapplication of defaults.
  252. "%SystemDirectory%\appmgmt",1,"D:AR"
  253. "%SystemDirectory%\DTCLog",1,"D:AR"
  254. "%SystemDirectory%\GroupPolicy",1,"D:AR"
  255. "%SystemDirectory%\msdtc",1,"D:AR"
  256. "%SystemDirectory%\NTMSData",1,"D:AR"
  257. "%SystemDirectory%\ReinstallBackups",1,"D:AR"
  258. "%SystemDirectory%\repl",1,"D:AR"
  259. "%SystemDirectory%\Setup",1,"D:AR"
  260. "%SystemDirectory%\spool\printers",1,"D:AR"
  261. ;Directories that do not exist when security applied during setup - Creator does not specify directory security.
  262. ;Creator should specify FILE security in optional component INF that gets applied on clean-install AND upgrade.
  263. ;Omit (rather than ignore) to allow component-specified file security to be set on reapplication of defaults.
  264. ;Use MARTA (rather than omit) for any components that set protected run-time security.
  265. ;"%SystemDirectory%\Cache",0,"D:AR"
  266. ;"%SystemDirectory%\Com",0,"D:AR"
  267. ;"%SystemDirectory%\clients",0,"D:AR"
  268. ;"%SystemDirectory%\inetsrv",0,"D:AR"
  269. ;"%SystemDirectory%\LogFiles",0,"D:AR"
  270. ;"%SystemDirectory%\Microsoft",0,"D:AR"
  271. ;"%SystemDirectory%\npp",0,"D:AR"
  272. ;"%SystemDirectory%\oobe",0,"D:AR"
  273. ;"%SystemDirectory%\restore",0,"D:AR"
  274. ;"%SystemDirectory%\reminst",0,"D:AR"
  275. ;"%SystemDirectory%\rocket",0,"D:AR"
  276. ;"%SystemDirectory%\usmt",0,"D:AR"