| Local Policies Security Options |
| Accounts Enable Administrator Account Status | Enable |
| Accounts Enable Guest Account Status | Disable |
| Accounts Limit Local Account Use Of Blank Passwords To Console Logon Only | Enabled |
| Interactive Logon Smart Card Removal Behavior | Lock Workstation |
| Microsoft Network Client Digitally Sign Communications Always | Enable |
| Microsoft Network Client Send Unencrypted Password To Third Party SMB Servers | Disable |
| Microsoft Network Server Digitally Sign Communications Always | Enable |
| Network Access Do Not Allow Anonymous Enumeration Of SAM Accounts | Enabled |
| Network Access Do Not Allow Anonymous Enumeration Of Sam Accounts And Shares | Enabled |
| Network Access Restrict Anonymous Access To Named Pipes And Shares | Enable |
| Network Access Restrict Clients Allowed To Make Remote Calls To SAM | O:BAG:BAD:(A;;RC;;;BA) |
| Network Security Do Not Store LAN Manager Hash Value On Next Password Change | Enable |
| Network Security LAN Manager Authentication Level | Send NTLMv2 responses only. Refuse LM and NTLM |
| Network Security Minimum Session Security For NTLMSSP Based Clients | Require NTLM and 128-bit encryption |
| Network Security Minimum Session Security For NTLMSSP Based Servers | Require NTLM and 128-bit encryption |
| User Account Control Behavior Of The Elevation Prompt For Administrators | Prompt for consent on the secure desktop |
| User Account Control Behavior Of The Elevation Prompt For Standard Users | Prompt for credentials on the secure desktop |
| User Account Control Detect Application Installations And Prompt For Elevation | Enable |
| User Account Control Only Elevate UI Access Applications That Are Installed In Secure Locations | Enabled: Application runs with UIAccess integrity only if it resides in secure location. |
| User Account Control Run All Administrators In Admin Approval Mode | Enabled |
| User Account Control Switch To The Secure Desktop When Prompting For Elevation | Enabled |
| User Account Control Use Admin Approval Mode | Enable |
| User Account Control Virtualize File And Registry Write Failures To Per User Locations | Enabled |