2023-11-29 17:01:08 +01:00

499 lines
58 KiB
XML
Raw Blame History

This file contains invisible Unicode characters

This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

<?xml version="1.0" encoding="utf-16"?>
<GPO xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.microsoft.com/GroupPolicy/Settings">
<Identifier>
<Identifier xmlns="http://www.microsoft.com/GroupPolicy/Types">{57494173-6721-4C0F-A2CB-BE6083AD5991}</Identifier>
<Domain xmlns="http://www.microsoft.com/GroupPolicy/Types">azureblog.pl</Domain>
</Identifier>
<Name>Tier2 Restrict Workstation Logon</Name>
<IncludeComments>true</IncludeComments>
<CreatedTime>2020-05-23T17:58:51</CreatedTime>
<ModifiedTime>2020-05-23T18:42:49</ModifiedTime>
<ReadTime>2020-05-23T19:06:22.0804607Z</ReadTime>
<SecurityDescriptor>
<SDDL xmlns="http://www.microsoft.com/GroupPolicy/Types/Security">O:DAG:DAD:PAI(OA;CI;CR;edacfd8f-ffb3-11d1-b41d-00a0c968f939;;AU)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;CI;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;CI;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-657827913-1895599540-1755036276-519)(A;CI;LCRPLORC;;;ED)(A;CI;LCRPLORC;;;AU)(A;CI;CCDCLCSWRPWPDTLOSDRCWDWO;;;SY)(A;CIIO;CCDCLCSWRPWPDTLOSDRCWDWO;;;CO)S:AI(OU;CIIDSA;WPWD;;f30e3bc2-9ff0-11d1-b603-0000f80367c1;WD)(OU;CIIOIDSA;WP;f30e3bbe-9ff0-11d1-b603-0000f80367c1;bf967aa5-0de6-11d0-a285-00aa003049e2;WD)(OU;CIIOIDSA;WP;f30e3bbf-9ff0-11d1-b603-0000f80367c1;bf967aa5-0de6-11d0-a285-00aa003049e2;WD)</SDDL>
<Owner xmlns="http://www.microsoft.com/GroupPolicy/Types/Security">
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-512</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Domain Admins</Name>
</Owner>
<Group xmlns="http://www.microsoft.com/GroupPolicy/Types/Security">
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-512</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Domain Admins</Name>
</Group>
<PermissionsPresent xmlns="http://www.microsoft.com/GroupPolicy/Types/Security">true</PermissionsPresent>
<Permissions xmlns="http://www.microsoft.com/GroupPolicy/Types/Security">
<InheritsFromParent>false</InheritsFromParent>
<TrusteePermissions>
<Trustee>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-9</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS</Name>
</Trustee>
<Type xsi:type="PermissionType">
<PermissionType>Allow</PermissionType>
</Type>
<Inherited>false</Inherited>
<Applicability>
<ToSelf>true</ToSelf>
<ToDescendantObjects>false</ToDescendantObjects>
<ToDescendantContainers>true</ToDescendantContainers>
<ToDirectDescendantsOnly>false</ToDirectDescendantsOnly>
</Applicability>
<Standard>
<GPOGroupedAccessEnum>Read</GPOGroupedAccessEnum>
</Standard>
<AccessMask>0</AccessMask>
</TrusteePermissions>
<TrusteePermissions>
<Trustee>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-18</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">NT AUTHORITY\SYSTEM</Name>
</Trustee>
<Type xsi:type="PermissionType">
<PermissionType>Allow</PermissionType>
</Type>
<Inherited>false</Inherited>
<Applicability>
<ToSelf>true</ToSelf>
<ToDescendantObjects>false</ToDescendantObjects>
<ToDescendantContainers>true</ToDescendantContainers>
<ToDirectDescendantsOnly>false</ToDirectDescendantsOnly>
</Applicability>
<Standard>
<GPOGroupedAccessEnum>Edit, delete, modify security</GPOGroupedAccessEnum>
</Standard>
<AccessMask>0</AccessMask>
</TrusteePermissions>
<TrusteePermissions>
<Trustee>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-512</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Domain Admins</Name>
</Trustee>
<Type xsi:type="PermissionType">
<PermissionType>Allow</PermissionType>
</Type>
<Inherited>false</Inherited>
<Applicability>
<ToSelf>true</ToSelf>
<ToDescendantObjects>false</ToDescendantObjects>
<ToDescendantContainers>true</ToDescendantContainers>
<ToDirectDescendantsOnly>false</ToDirectDescendantsOnly>
</Applicability>
<Standard>
<GPOGroupedAccessEnum>Edit, delete, modify security</GPOGroupedAccessEnum>
</Standard>
<AccessMask>0</AccessMask>
</TrusteePermissions>
<TrusteePermissions>
<Trustee>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-11</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">NT AUTHORITY\Authenticated Users</Name>
</Trustee>
<Type xsi:type="PermissionType">
<PermissionType>Allow</PermissionType>
</Type>
<Inherited>false</Inherited>
<Applicability>
<ToSelf>true</ToSelf>
<ToDescendantObjects>false</ToDescendantObjects>
<ToDescendantContainers>true</ToDescendantContainers>
<ToDirectDescendantsOnly>false</ToDirectDescendantsOnly>
</Applicability>
<Standard>
<GPOGroupedAccessEnum>Apply Group Policy</GPOGroupedAccessEnum>
</Standard>
<AccessMask>0</AccessMask>
</TrusteePermissions>
<TrusteePermissions>
<Trustee>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-519</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Enterprise Admins</Name>
</Trustee>
<Type xsi:type="PermissionType">
<PermissionType>Allow</PermissionType>
</Type>
<Inherited>false</Inherited>
<Applicability>
<ToSelf>true</ToSelf>
<ToDescendantObjects>false</ToDescendantObjects>
<ToDescendantContainers>true</ToDescendantContainers>
<ToDirectDescendantsOnly>false</ToDirectDescendantsOnly>
</Applicability>
<Standard>
<GPOGroupedAccessEnum>Edit, delete, modify security</GPOGroupedAccessEnum>
</Standard>
<AccessMask>0</AccessMask>
</TrusteePermissions>
</Permissions>
<AuditingPresent xmlns="http://www.microsoft.com/GroupPolicy/Types/Security">false</AuditingPresent>
</SecurityDescriptor>
<FilterDataAvailable>true</FilterDataAvailable>
<Computer>
<VersionDirectory>11</VersionDirectory>
<VersionSysvol>11</VersionSysvol>
<Enabled>true</Enabled>
<ExtensionData>
<Extension xmlns:q1="http://www.microsoft.com/GroupPolicy/Settings/Security" xsi:type="q1:SecuritySettings">
<q1:UserRightsAssignment>
<q1:Name>SeDenyBatchLogonRight</q1:Name>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-32-548</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">BUILTIN\Account Operators</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-32-544</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">BUILTIN\Administrators</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-512</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Domain Admins</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-516</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Domain Controllers</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-519</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Enterprise Admins</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-520</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Group Policy Creator Owners</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-521</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Read-only Domain Controllers</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-518</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Schema Admins</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-3102</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Tier0PAWMaint</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-3101</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Tier0PAWUsers</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-2101</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Tier0ReplicationMaintenance</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-2105</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\tier1admins</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-3104</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Tier1PAWMaint</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-3103</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Tier1PAWUsers</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-2102</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Tier1ServerMaintenance</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-32-551</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">BUILTIN\Backup Operators</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-32-569</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">BUILTIN\Cryptographic Operators</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-32-550</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">BUILTIN\Print Operators</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-32-549</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">BUILTIN\Server Operators</Name>
</q1:Member>
</q1:UserRightsAssignment>
<q1:UserRightsAssignment>
<q1:Name>SeDenyInteractiveLogonRight</q1:Name>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-32-549</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">BUILTIN\Server Operators</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-32-550</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">BUILTIN\Print Operators</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-32-569</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">BUILTIN\Cryptographic Operators</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-32-551</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">BUILTIN\Backup Operators</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-2102</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Tier1ServerMaintenance</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-3103</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Tier1PAWUsers</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-3104</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Tier1PAWMaint</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-2105</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\tier1admins</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-2101</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Tier0ReplicationMaintenance</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-3101</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Tier0PAWUsers</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-3102</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Tier0PAWMaint</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-518</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Schema Admins</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-521</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Read-only Domain Controllers</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-520</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Group Policy Creator Owners</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-519</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Enterprise Admins</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-516</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Domain Controllers</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-512</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Domain Admins</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-32-548</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">BUILTIN\Account Operators</Name>
</q1:Member>
</q1:UserRightsAssignment>
<q1:UserRightsAssignment>
<q1:Name>SeDenyRemoteInteractiveLogonRight</q1:Name>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-32-549</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">BUILTIN\Server Operators</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-32-550</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">BUILTIN\Print Operators</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-32-569</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">BUILTIN\Cryptographic Operators</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-32-551</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">BUILTIN\Backup Operators</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-2102</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Tier1ServerMaintenance</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-3103</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Tier1PAWUsers</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-3104</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Tier1PAWMaint</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-2105</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\tier1admins</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-2101</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Tier0ReplicationMaintenance</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-3101</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Tier0PAWUsers</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-3102</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Tier0PAWMaint</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-518</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Schema Admins</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-521</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Read-only Domain Controllers</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-520</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Group Policy Creator Owners</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-519</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Enterprise Admins</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-516</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Domain Controllers</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-512</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Domain Admins</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-32-544</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">BUILTIN\Administrators</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-32-548</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">BUILTIN\Account Operators</Name>
</q1:Member>
</q1:UserRightsAssignment>
<q1:UserRightsAssignment>
<q1:Name>SeDenyServiceLogonRight</q1:Name>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-32-549</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">BUILTIN\Server Operators</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-32-550</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">BUILTIN\Print Operators</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-32-569</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">BUILTIN\Cryptographic Operators</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-32-551</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">BUILTIN\Backup Operators</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-2102</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Tier1ServerMaintenance</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-3103</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Tier1PAWUsers</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-3104</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Tier1PAWMaint</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-2105</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\tier1admins</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-2101</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Tier0ReplicationMaintenance</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-3101</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Tier0PAWUsers</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-3102</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Tier0PAWMaint</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-518</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Schema Admins</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-521</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Read-only Domain Controllers</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-520</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Group Policy Creator Owners</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-519</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Enterprise Admins</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-516</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Domain Controllers</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-512</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Domain Admins</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-32-544</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">BUILTIN\Administrators</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-32-548</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">BUILTIN\Account Operators</Name>
</q1:Member>
</q1:UserRightsAssignment>
<q1:UserRightsAssignment>
<q1:Name>SeInteractiveLogonRight</q1:Name>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-2104</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Tier2WorkstationMaintenance</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-2103</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Tier2ServiceDeskOperators</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-32-544</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">BUILTIN\Administrators</Name>
</q1:Member>
</q1:UserRightsAssignment>
<q1:UserRightsAssignment>
<q1:Name>SeRemoteInteractiveLogonRight</q1:Name>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-2104</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Tier2WorkstationMaintenance</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-21-657827913-1895599540-1755036276-2103</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">AZUREBLOG\Tier2ServiceDeskOperators</Name>
</q1:Member>
<q1:Member>
<SID xmlns="http://www.microsoft.com/GroupPolicy/Types">S-1-5-32-544</SID>
<Name xmlns="http://www.microsoft.com/GroupPolicy/Types">BUILTIN\Administrators</Name>
</q1:Member>
</q1:UserRightsAssignment>
<q1:Blocked>false</q1:Blocked>
</Extension>
<Name>Security</Name>
</ExtensionData>
</Computer>
<User>
<VersionDirectory>2</VersionDirectory>
<VersionSysvol>2</VersionSysvol>
<Enabled>false</Enabled>
</User>
<LinksTo>
<SOMName>Workstations</SOMName>
<SOMPath>azureblog.pl/Workstations</SOMPath>
<Enabled>true</Enabled>
<NoOverride>false</NoOverride>
</LinksTo>
<LinksTo>
<SOMName>Devices</SOMName>
<SOMPath>azureblog.pl/Admin/Tier2/Devices</SOMPath>
<Enabled>true</Enabled>
<NoOverride>false</NoOverride>
</LinksTo>
</GPO>