Cyberdyne

Contributors

  • Connor S

Cyberdyne

Cyberdyne is the core of the CIS class. It runs Windows Server 2019, and provides Domain Services to the entire class.

Hardware Configuration

CPU: AMD EPYC 7401P
RAM: Crucial 64GB (4 x 16GB) DDR4 ECC Registered 2133
Motherboard: Supermicro H11SSL-i
GPU: GTX 1650 Low Profile
PSU: Seasonic PRIME 80+ Titanium 650W
Case: SilverStone Technology CS380 8-Bay Compact ATX Tower case
Storage:

  • 1x Samsung 980 Pro 1TB
  • 8x Seagate IronWolf Pro 4TB 7200 RPM
    - 2 Hardware RAID 5's of 4 drives each
    - Each RAID 5 is combined into a stripped 22 TB array in windows
    Network adapter: TP-Link TX401 10GB PCIe Network Card

User Accounts

All user accounts are stored on Cyberdyne, and allows a student to log in to their account on any computer enrolled in the domain.

DNS

Cyberdyne also provides domain DNS related services.

Group Policy Overview

Administrator Policy

Computer Configuration

No settings defined.

User Configuration

Administrative Templates
Desktop/Desktop
Policy Setting Comment
Desktop Wallpaper Enabled Wallpaper Path: \cyberdyne\PublicShare\Admin.jpg
Start Menu and Taskbar
Policy Setting Comment
Add the Run command to the Start Menu Enabled

Class PC Policy

Computer Configuration

Security Settings
Account Policies/Password Policy
Policy Setting
Enforce password history 3 passwords remembered
Maximum password age 90 days
Minimum password age 30 days
Password must meet complexity requirements Enabled
Account Policies/Account Lockout Policy
Policy Setting
Account lockout duration 10 minutes
Account lockout threshold 5 invalid logon attempts
Reset account lockout counter after 10 minutes
Interactive Logon
Policy Setting
Interactive logon: Do not require CTRL+ALT+DEL Disabled
Interactive logon: Don't display last signed-in Enabled
Interactive logon: Message text for users attempting to log on This computer is for use by the CIS Program, Cybersecurity Program, and Computer Club only.
Interactive logon: Message title for users attempting to log on "Unauthorized Access Prohibited"
Administrative Templates
Control Panel
Policy Setting Comment
Settings Page Visibility Enabled showonly:bluetooth,sound,about,windowsupdate,troubleshoot
Control Panel/Personalization
Policy Setting Comment
Force a specific default lock screen and logon image Enabled Image path: \cyberdyne\PublicShare\lockscreen.jpg

Turn off fun facts, tips, tricks, and more on lock screen: Enabled
Prevent changing lock screen and logon image Enabled
Network/Network Connections/Windows Defender Firewall/Domain Profile
Policy Setting Comment
Windows Defender Firewall: Allow ICMP exceptions Enabled Allow outbound destination unreachable: Disabled
Allow outbound source quench: Disabled
Allow redirect: Disabled
Allow inbound echo request: Enabled
Allow inbound router request: Disabled
Allow outbound time exceeded: Disabled
Allow outbound parameter problem: Disabled
Allow inbound timestamp request: Disabled
Allow inbound mask request: Disabled
Allow outbound packet too big: Disabled
Windows Defender Firewall: Allow inbound remote administration exception Enabled
Start Menu and Taskbar
Policy Setting Comment
Remove "Recently added" list from Start Menu Enabled
System/Power Management
Policy Setting Comment
Select an active power plan Enabled Active Power Plan: High Performance
System/Windows Time Service/Time Providers
Policy Setting Comment
Configure Windows NTP Client Enabled NtpServer: 129.6.15.28
Type: NTP
CrossSiteSyncFlags: 2
ResolvePeerBackoffMinutes: 15
ResolvePeerBackoffMaxTimes: 7
SpecialPollInterval: 1024
EventLogFlags: 0
Enable Windows NTP Client Enabled
Windows Components/AutoPlay Policies
Policy Setting Comment
Set the default behavior for AutoRun Enabled Default AutoRun Behavior: Do not execute any autorun commands
Turn off Autoplay Enabled Turn off Autoplay on: All drives
Windows Components/BitLocker Drive Encryption
Policy Setting Comment
Store BitLocker recovery information in Active Directory Domain Services (Windows Server 2008 and Windows Vista) Enabled Require BitLocker backup to AD DS: Enabled
Select BitLocker recovery information to store: Recovery passwords and key packages
Windows Components/Data Collection and Preview Builds
Policy Setting Comment
Allow commercial data pipeline Disabled
Allow Desktop Analytics Processing Disabled
Allow device name to be sent in Windows diagnostic data Disabled
Allow Telemetry Disabled
Allow WUfB Cloud Processing Disabled
Limit Enhanced diagnostic data to the minimum required by Windows Analytics Disabled
Windows Components/Event Log Service/Application
Policy Setting Comment
Specify the maximum log file size (KB) Enabled Maximum Log Size (KB): 8192
Windows Components/Event Log Service/Security
Policy Setting Comment
Specify the maximum log file size (KB) Enabled Maximum Log Size (KB): 40960
Windows Components/Event Log Service/Setup
Policy Setting Comment
Specify the maximum log file size (KB) Enabled Maximum Log Size (KB): 8192
Turn on logging Enabled
Windows Components/Event Log Service/System
Policy Setting Comment
Specify the maximum log file size (KB) Enabled Maximum Log Size (KB): 8192
Windows Components/Find My Device
Policy Setting Comment
Turn On/Off Find My Device Disabled
Windows Components/Location and Sensors
Policy Setting Comment
Turn off location Enabled
Windows Components/OneDrive
Policy Setting Comment
Prevent the usage of OneDrive for file storage Enabled
Windows Components/Remote Desktop Services/Remote Desktop Session Host/Connections
Policy Setting Comment
Allow users to connect remotely by using Remote Desktop Services Enabled
Windows Components/Search
Policy Setting Comment
Allow Cloud Search Disabled
Allow Cortana Disabled
Allow Cortana above lock screen Disabled
Allow Cortana Page in OOBE on an AAD account Disabled
Allow search and Cortana to use location Disabled
Do not allow web search Enabled
Don't search the web or display web results in Search Enabled
Windows Components/Store
Policy Setting Comment
Turn off the offer to update to the latest version of Windows Enabled
Windows Components/Text Input
Policy Setting Comment
Allow uninstallation of language features when a language is uninstalled Disabled
Improve inking and typing recognition Disabled
Windows Components/Windows Color System
Policy Setting Comment
Prohibit installing or uninstalling color profiles Enabled
Windows Components/Windows Defender SmartScreen/Explorer
Policy Setting Comment
Configure Windows Defender SmartScreen Enabled Level: Warn
Windows Components/Windows Defender SmartScreen/Microsoft Edge
Policy Setting Comment
Configure Windows Defender SmartScreen Enabled
Windows Components/Windows Remote Shell
Policy Setting Comment
Allow Remote Shell Access Disabled
Windows Components/Windows Security/App and browser protection
Policy Setting Comment
Prevent users from modifying settings Enabled
Windows Components/Windows Security/Family options
Policy Setting Comment
Hide the Family options area Enabled
Windows Components/Windows Security/Systray
Policy Setting Comment
Hide Windows Security Systray Enabled
Windows Components/Windows Security/Virus and threat protection
Policy Setting Comment
Hide the Ransomware data recovery area Enabled
Hide the Virus and threat protection area Enabled
Windows Components/Windows Update
Policy Setting Comment
Configure Automatic Updates Enabled Configure automatic updating: 4 - Auto download and schedule the install
Install during automatic maintenance: Disabled
Scheduled install day: 0 - Every day
Scheduled install time: 03:00
Every week: Enabled
First week of the month: Disabled
Second week of the month: Disabled
Third week of the month: Disabled
Fourth week of the month: Disabled
Install updates for other Microsoft products: Enabled
Specify deadline before auto-restart for update installation Enabled Quality Updates (days): 7
Feature Updates (days): 7
Specify deadlines for automatic updates and restarts Enabled Quality Updates
Deadline (days): 7
Grace period (days): 2

Feature Updates
Deadline (days): 2
Grace Period (days): 7

Don't auto-restart until end of grace period: Yes
Turn off auto-restart for updates during active hours Enabled Active Hours
Start: 6 AM
End: 5 PM

User Configuration

Control Panel Settings
Scheduled Tasks

Scheduled Task (At least Windows 7): auto_shutdown

Task

Name auto_shutdown
Author SKYNET\cschuler
Description
Run only when user is logged on S4U
UserId System
Run with highest privileges LeastPrivilege
Hidden No
Configure for 1.2
Enabled Yes

Triggers

1. Daily
Activate 2/20/2025 2:30:00 PM Synchronize across time zones No
Enabled Yes
Recur every 1 days

Actions

1. Start a program
Program/script C:\Windows\System32\shutdown.exe
Arguments /s /t 0

Settings

Start the task only if the computer is idle for 15 minutes
Wait for idle for 2 hours
Stop if the computer ceases to be idle No
Restart if the idle state resumes No
Start the task only if the computer is on AC power No
Stop if the computer switches to battery power No
Allow task to be run on demand No
Stop task if it runs longer than Immediately
If the running task does not end when requested, force it to stop No
If the task is already running, then the following rule applies IgnoreNew

Options

Stop processing items on this extension if an error occurs on this item No
Run in logged-on user's security context (user policy option) No
Remove this item when it is no longer applied No
Apply once and do not reapply No

Default Domain Controller Policy

Computer Configuration

System/Windows Time Service/Time Providers
Policy Setting Comment
Configure Windows NTP Client Enabled NtpServer: 129.6.15.28
Type: NT5DS
CrossSiteSyncFlags: 2
ResolvePeerBackoffMinutes: 15
ResolvePeerBackoffMaxTimes: 7
SpecialPollInterval: 1024
EventLogFlags: 0
Enable Windows NTP Client Enabled

User Configuration

No settings defined.

Default Domain Policy

Computer Configuration

Security Settings
Account Policies/Password Policy
Policy Setting
Enforce password history 24 passwords remembered
Maximum password age 90 days
Minimum password age 1 days
Minimum password length 7 characters
Password must meet complexity requirements Enabled
Store passwords using reversible encryption Disabled
Account Policies/Account Lockout Policy
Policy Setting
Account lockout duration 10 minutes
Account lockout threshold 5 invalid logon attempts
Allow administrator account lockout Enabled
Reset account lockout counter after 10 minutes
Administrative Templates
System/Group Policy
Policy Setting Comment
Set Group Policy refresh interval for computers Enabled Interval: 15 min
Random Buffer: 5 min
System/Windows Time Service/Time Providers
Policy Setting Comment
Configure Windows NTP Client Enabled NtpServer: 129.6.15.28
Type: NT5DS
CrossSiteSyncFlags: 2
ResolvePeerBackoffMinutes: 15
ResolvePeerBackoffMaxTimes: 7
SpecialPollInterval: 1024
EventLogFlags: 0
Enable Windows NTP Client Enabled
Windows Components/Remote Desktop Services/Remote Desktop Session Host/Connections
Policy Setting Comment
Allow users to connect remotely by using Remote Desktop Services Enabled
Limit number of connections Enabled RD Maximum Connections allowed: 1
Windows Components/Remote Desktop Services/Remote Desktop Session Host/Session Time Limits
Policy Setting Comment
End session when time limits are reached Enabled
Set time limit for active but idle Remote Desktop Services sessions Enabled Idle session limit: 15 minutes
Set time limit for active Remote Desktop Services sessions Enabled Active session limit: 1 hour
Set time limit for disconnected sessions Enabled End a disconnected session: 5 minutes
Windows Components/Windows Remote Management (WinRM)/WinRM Service
Policy Setting Comment
Allow remote server management through WinRM Enabled

User Configuration

No settings defined.

Guest Policy

Computer Configuration

No settings defined.

User Configuration

Administrative Templates
Desktop/Desktop
Policy Setting Comment
Desktop Wallpaper Enabled Wallpaper Path: \cyberdyne\PublicShare\Guest.jpg

Level 1 Policy

Computer Configuration

No settings defined.

User Configuration

Administrative Templates
Desktop/Desktop
Policy Setting Comment
Desktop Wallpaper Enabled Wallpaper Path: \cyberdyne\PublicShare\L1.jpg

Level 2 Policy

Computer Configuration

No settings defined.

User Configuration

Administrative Templates
Desktop/Desktop
Policy Setting Comment
Desktop Wallpaper Enabled Wallpaper Path: \cyberdyne\PublicShare\L2.jpg

Level 3 Policy

Computer Configuration

No settings defined.

User Configuration

Administrative Templates
Desktop/Desktop
Policy Setting Comment
Desktop Wallpaper Enabled Wallpaper Path: \cyberdyne\PublicShare\L3.jpg