RE: Domain vs. Local security policy

From: Arik Fletcher (arikf_at_joskos.com)
Date: 09/10/03

  • Next message: Martin, Olivier: "RE: GPO for one machine"
    Date: Wed, 10 Sep 2003 16:54:32 +0100
    To: <focus-ms@securityfocus.com>
    
    

    the only problem with that scenario is that if you wanted to change the policies of the local machines without affecting other PCs on the network, or having to stick them into a separate OU.
     
    But i suppose you could change the policies on one of the machines and the write a script that copies the
    %windir%\system32\GroupPolicy folder from the fixed machine to all other machines you would like changed...

            -----Original Message-----
            From: Streeter, Joseph (WI) [mailto:Joseph.Streeter@wi.ngb.army.mil]
            Sent: Tue 9/9/2003 7:36 PM
            To: 'focus-ms@securityfocus.com'
            Cc:
            Subject: RE: Domain vs. Local security policy
            
            

            It might be best to have the local GPO good and tight. That way there are
            fewer polices that have to be applied across the network at start up and
            logon. It's also the only policy to apply to local accounts on that machine.
            
            
            If you want to back off any of the local policies you can override them with
            the Domain or OU polcy.
            
            -----Original Message-----
            From: simonis [mailto:simonis@myself.com]
            Sent: Monday, September 08, 2003 1:26 PM
            To: Brad Renfro
            Cc: focus-ms@securityfocus.com
            Subject: Re: Domain vs. Local security policy
            
            Brad Renfro wrote:
    >
    > What is the residual risk of applying fairly strict domain wide security
    > policies on a LAN but leaving local security policy pretty much the
            default?
    >
            
            
            As far as I understand it, this would allow someone to remove the box
            from the domain and operate under the looser local policy. A larger
            question is of what benefit it is to you?
            
            -Ds
            
            ---------------------------------------------------------------------------
            KaVaDo provides the first and only integrated Web application scanner and
            firewall security suite that prevent Web applications attacks, the most
            common form of online exploitation. Download a FREE whitepaper on Security
            Policy Automation for Web Applications.
            http://www.securityfocus.com/sponsor/KaVaDo_focus-ms_030818
            ---------------------------------------------------------------------------
            
            ---------------------------------------------------------------------------
            KaVaDo provides the first and only integrated Web application scanner and
            firewall security suite that prevent Web applications attacks, the most
            common form of online exploitation. Download a FREE whitepaper on Security Policy Automation for Web Applications.
            http://www.securityfocus.com/sponsor/KaVaDo_focus-ms_030818
            ---------------------------------------------------------------------------
            
            


  • Next message: Martin, Olivier: "RE: GPO for one machine"

    Relevant Pages

    • Re: Not connecting to Domain
      ... The machines are all running windows XP Professional with service pack 2. ... The odd thing is this has suddenly happened on two machines in a network of 30, with no other PCs reporting the same problem. ... is your DNS configured properly? ...
      (microsoft.public.windowsxp.network_web)
    • Re: XP AND 2000
      ... There are around 14 PCs! ... The XP machines probably have the Windows Firewall on ... I came across a network setup with the following:- ...
      (microsoft.public.win2000.networking)
    • Re: Problem setting up new network/printer
      ... I've found in the past it seemed to work better when I let windows do ... The subnet is the same on all the machines. ... All the PCs go to a switch, which is connected to a DSL modem. ... network, the internet, and the printer. ...
      (microsoft.public.windowsxp.general)
    • Re: Very Slow browse peer-to-peer network
      ... It seems that after adding two new WinXP PCs lately, ... > browsing the network, just to see the other PCs, takes 20-30 seconds ... Check your event logs on the XP machines, to see if there are browser ...
      (microsoft.public.windowsxp.network_web)
    • Re: Aftermath of RDIRCMP.EXE?
      ... We are going to try creating a new OU, putting the machines in there, ... with Deny Read and Deny Apply Group Policy permissions on the Default Domain ... Ok, check the policy settings that you want (as I already said, some ... policies only work at domain level, ...
      (microsoft.public.windows.server.active_directory)

    Loading