Instructions for Use 5 ConfigurationCLARUS® 500 5.11 System Administration2660021171806 Rev. A 2019-01 87 / 192Policy SettingAccounts: Guest account status DisabledAccounts: Limit local account use of blank passwords to console logon only EnabledAccounts: Rename administrator account ZeissAdminAccounts: Rename guest account Not UsedAct as part of the operating system No OneAdjust memory quotas for a process Administrators,Local Service,Network ServiceAllow all trusted apps to install DisabledAllow Basic authentication DisabledAllow Cortana DisabledAllow indexing of encrypted files DisabledAllow log on locally Administrators,UsersAllow Microsoft accounts to be optional EnabledAllow Telemetry 0 - Off (Enterprise Only) EnabledAllow unencrypted traffic DisabledAllow user control over installs DisabledAllow users to connect remotely by using Remote Desktop Services DisabledAllow Windows to automatically connect to suggested open hotspots, tonetworks shared by contacts, and to hotspots offering paid servicesDisabledAlways install with elevated privileges DisabledAlways prompt for password upon connection EnabledApply UAC restrictions to local accounts on network logons EnabledAudit Policy: Account Logon: Credential Validation Success andFailureAudit Policy: Account Management: Other Account Management Events Success andFailureAudit Policy: Account Management: Security Group Management Success andFailureAudit Policy: Account Management: User Account Management Success andFailureAudit Policy: Detailed Tracking: Process Creation SuccessAudit Policy: Logon-Logoff: Account Lockout Success