<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wikicyber.org/index.php?action=history&amp;feed=atom&amp;title=Draft%3AIntroduction_to_Group_Policy</id>
	<title>Draft:Introduction to Group Policy - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wikicyber.org/index.php?action=history&amp;feed=atom&amp;title=Draft%3AIntroduction_to_Group_Policy"/>
	<link rel="alternate" type="text/html" href="https://wikicyber.org/index.php?title=Draft:Introduction_to_Group_Policy&amp;action=history"/>
	<updated>2026-09-24T04:43:40Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.46.0</generator>
	<entry>
		<id>https://wikicyber.org/index.php?title=Draft:Introduction_to_Group_Policy&amp;diff=181&amp;oldid=prev</id>
		<title>MigrationBot: Backfill (v3.0 review queue): added to the review queue</title>
		<link rel="alternate" type="text/html" href="https://wikicyber.org/index.php?title=Draft:Introduction_to_Group_Policy&amp;diff=181&amp;oldid=prev"/>
		<updated>2026-09-22T05:42:50Z</updated>

		<summary type="html">&lt;p&gt;Backfill (v3.0 review queue): added to the review queue&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw-interface=&quot;&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 05:42, 22 September 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l88&quot;&gt;Line 88:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 88:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Windows Group Policy|006]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Windows Group Policy|006]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Migrated from cypat.guide]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Migrated from cypat.guide]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[Category:Pending review]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key wikicyber:diff:1.41:old-101:rev-181:php=table --&gt;
&lt;/table&gt;</summary>
		<author><name>MigrationBot</name></author>
	</entry>
	<entry>
		<id>https://wikicyber.org/index.php?title=Draft:Introduction_to_Group_Policy&amp;diff=101&amp;oldid=prev</id>
		<title>MigrationBot: Import from cypat.guide: docs/windows/group_policy/intro_group_policy.md</title>
		<link rel="alternate" type="text/html" href="https://wikicyber.org/index.php?title=Draft:Introduction_to_Group_Policy&amp;diff=101&amp;oldid=prev"/>
		<updated>2026-09-18T17:06:33Z</updated>

		<summary type="html">&lt;p&gt;Import from cypat.guide: docs/windows/group_policy/intro_group_policy.md&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Submit}}&lt;br /&gt;
&amp;lt;!-- Migrated from https://cypat.guide/docs/windows/group_policy/intro_group_policy (source: docs/windows/group_policy/intro_group_policy.md) --&amp;gt;&lt;br /&gt;
-----&lt;br /&gt;
&lt;br /&gt;
Author(s): a_person&lt;br /&gt;
&lt;br /&gt;
Last Updated: 07-03-2025&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;mw-collapsible mw-collapsed wikitable&amp;quot; style=&amp;quot;width:100%&amp;quot;&lt;br /&gt;
! Recommended Prerequisites (click to expand)&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
None&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== What is it? ==&lt;br /&gt;
&lt;br /&gt;
Group Policy is a feature in Microsoft Windows that allows administrators to manage settings for users and computers. It provides centralized configuration and enforcement of operating systems, applications, and user settings. It&amp;#039;s used in either networks or locally.&lt;br /&gt;
&lt;br /&gt;
== Concepts ==&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Where Group Policy settings are stored:&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
** &amp;#039;&amp;#039;&amp;#039;Registry Keys:&amp;#039;&amp;#039;&amp;#039; The actual policy settings are written to these protected registry locations, overriding standard user or application settings.&lt;br /&gt;
*** &amp;lt;code&amp;gt;HKEY_LOCAL_MACHINE\Software\Policies&amp;lt;/code&amp;gt; (for computer settings)&lt;br /&gt;
*** &amp;lt;code&amp;gt;HKEY_CURRENT_USER\Software\Policies&amp;lt;/code&amp;gt; (for user settings)&lt;br /&gt;
*** &amp;#039;&amp;#039;(And the corresponding ...\Microsoft\Windows\CurrentVersion\Policies locations)&amp;#039;&amp;#039;&lt;br /&gt;
** &amp;#039;&amp;#039;&amp;#039;File System:&amp;#039;&amp;#039;&amp;#039; The &amp;lt;code&amp;gt;%SystemRoot%\System32\GroupPolicy\&amp;lt;/code&amp;gt; directory stores the files that make up a GPO, including administrative templates and script files.&lt;br /&gt;
&lt;br /&gt;
== Group Policy vs Registry ==&lt;br /&gt;
&lt;br /&gt;
They are both used to configure settings, but Registry is basically an unc. Here are the main differences:&lt;br /&gt;
&lt;br /&gt;
* Each registry is local to its respective machine, while Group Policies can be applied to multiple computers&lt;br /&gt;
* Group policy is more persistent as group policies apply during startup.&lt;br /&gt;
* Group Policy is much easier to use as it gives setting names and explanations.&lt;br /&gt;
&lt;br /&gt;
== How do I change Group Policies ==&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;gpedit.msc&amp;lt;/code&amp;gt;&lt;br /&gt;
** Locally. You can edit them just by selecting the policies you want to set.&lt;br /&gt;
* &amp;lt;code&amp;gt;gpmc.msc&amp;lt;/code&amp;gt; - For groups.&lt;br /&gt;
** For groups. You can edit them by selecting them on the sidebar.&lt;br /&gt;
&lt;br /&gt;
== Local Security Policy ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;secpol.msc&amp;lt;/code&amp;gt; is a specific section of the local group policy(&amp;lt;code&amp;gt;Computer Configuration &amp;amp;gt; Windows Settings &amp;amp;gt; Security Settings&amp;lt;/code&amp;gt;). Any change you make in &amp;lt;code&amp;gt;secpol.msc&amp;lt;/code&amp;gt; is actually being made within the Local Group Policy (&amp;lt;code&amp;gt;gpedit.msc&amp;lt;/code&amp;gt;) and can be viewed there.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Main Settings Configured in &amp;lt;code&amp;gt;secpol.msc&amp;lt;/code&amp;gt;:&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Account Policies&amp;#039;&amp;#039;&amp;#039; - This is where you configure password requirements (length, complexity, history) and account lockout policies (e.g., lock an account after 5 bad password attempts).&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Audit Policy&amp;#039;&amp;#039;&amp;#039; - Determines which security-related events are logged in the Windows Security Event Log. For example, you can audit successful or failed logon attempts.&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;User Rights Assignment&amp;#039;&amp;#039;&amp;#039; - Controls the specific rights and privileges that users and groups have on the local machine, such as &amp;amp;quot;Shut down the system&amp;amp;quot; or &amp;amp;quot;Back up files and directories.&amp;amp;quot;&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Security Options&amp;#039;&amp;#039;&amp;#039; - A large collection of miscellaneous security settings, such as &amp;amp;quot;Interactive logon: Do not display last user name&amp;amp;quot; or policies related to User Account Control (UAC).&lt;br /&gt;
&lt;br /&gt;
== Tools for automation and compliance ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.microsoft.com/en-us/download/details.aspx?id=55319 LGPO] - Allows you to import and export GPOs&lt;br /&gt;
* [https://github.com/scipag/HardeningKitty Hardening Kitty] - Similar to lgpo, and has diverse modes which can allow you to see the most critical policies that are set incorrectly. It also contains some premade baselines.&lt;br /&gt;
* [https://public.cyber.mil/stigs/scap/ SCC] - Developed by the Department of Defense. SCC has Security Content Automation Protocol (SCAP) content and tools to help with security compliance and automation.&lt;br /&gt;
&lt;br /&gt;
== Premade baselines ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.cisecurity.org/cis-benchmarks CIS Benchmarks] - Baselines made by the Center for Internet Security. It provides two levels of baselining and is widely used.&lt;br /&gt;
* [https://stigviewer.com/stigs DoD Stigs] - Security baselines created by the Department of Defense. These guides are used to harden military networks and systems.&lt;br /&gt;
&lt;br /&gt;
== Practice ==&lt;br /&gt;
&lt;br /&gt;
ALL images except for images like the persistence image contain Group Policy points:&amp;lt;br /&amp;gt;&lt;br /&gt;
images.cypat.guide&lt;br /&gt;
&lt;br /&gt;
-----&lt;br /&gt;
&lt;br /&gt;
=== References, Further Reading, &amp;amp;amp; Tools Mentioned ===&lt;br /&gt;
&lt;br /&gt;
* https://en.wikipedia.org/wiki/Group_Policy&lt;br /&gt;
* https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/group-policy/group-policy-overview&lt;br /&gt;
* https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/group-policy/group-policy-management-console&lt;br /&gt;
* https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn265982(v=ws.11)&lt;br /&gt;
* https://www.microsoft.com/en-us/download/details.aspx?id=55319&lt;br /&gt;
* https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/security-policy-settings/how-to-configure-security-policy-settings&lt;br /&gt;
* https://github.com/scipag/HardeningKitty&lt;br /&gt;
* https://public.cyber.mil/stigs/scap/&lt;br /&gt;
* https://www.cisecurity.org/cis-benchmarks&lt;br /&gt;
* https://stigviewer.com/stigs&lt;br /&gt;
&lt;br /&gt;
[[Category:Windows Group Policy|006]]&lt;br /&gt;
[[Category:Migrated from cypat.guide]]&lt;/div&gt;</summary>
		<author><name>MigrationBot</name></author>
	</entry>
</feed>