RE: Disabling sharing and group policies

From: Sergey V. Gordeychik (gordey_at_infosec.ru)
Date: 09/18/03

  • Next message: Laura A. Robinson: "RE: Disabling sharing and group policies"
    Date: Thu, 18 Sep 2003 09:59:10 +0400
    To: <larobins@bellatlantic.net>, <robert@snrdesigns.com>, "Focus-Ms" <focus-ms@securityfocus.com>
    
    

    If you disable Group Policy loopback mode in domain-level GPO, local
    administrator will unable to change group policy on computer.
    Yes, administrator can modify some settings, but these settings will
    replaced when GPO applied again.

    Simplest way to disable sharing for any user with administrative rights
    - it's filter CIFS/SMB/Netbios servers (TCP/UDP 445, 139) packets with
    IPSec packet filter policies (SPD).
    Even user share something on computer - filters will drop connection
    packets and prevent network sharing.
    In policy you can also allow CIFS/Netbios connections from management
    stations for logs collection, etc.
    Information about IPSec filtering you can find, for example, in Windows
    Server 2003 Security Guide:

    http://www.microsoft.com/technet/treeview/default.asp?url=/technet/secur
    ity/prodtech/Windows/Win2003/W2003HG/SGCH04.asp

    Regards,
    Sergey V. Gordeychik.

    -----Original Message-----
    From: Laura A. Robinson [mailto:larobins@bellatlantic.net]
    Sent: Tuesday, September 16, 2003 6:47 PM
    To: robert@snrdesigns.com; 'Focus-Ms'
    Subject: RE: Disabling sharing and group policies

    Actually, as I said, anybody with administrative rights on his/her
    machine
    can exempt his/her machine from group policy application- *regardless*
    of
    whether or not that machine is a domain member. The local admin does
    *not*
    have to leave the domain to accomplish this.

    Laura

    ---------------------------------------------------------------------------
    KaVaDo provides the first and only integrated Web application scanner and
    firewall security suite that prevent Web applications attacks, the most
    common form of online exploitation. Download a FREE whitepaper on Security Policy Automation for Web Applications.
    http://www.securityfocus.com/sponsor/KaVaDo_focus-ms_030818
    ---------------------------------------------------------------------------


  • Next message: Laura A. Robinson: "RE: Disabling sharing and group policies"

    Relevant Pages

    • Re: creator/owner NTFS permissions
      ... I believe it is also a security issue in that an administrator can not access files ... A Vax or AS400 does this just fine, but Windows is still in the ... >> Windows XP has a Group Policy setting to disable the security tab on folder ... >> full explaination as disabling the command prompt can cause some scripts to ...
      (microsoft.public.win2000.security)
    • Re: Is there a way to set a local policy to disable adhoc, non Act
      ... policy via GPMC it requires you to log in as a domain administrator. ... +Software Settings ... Under Windows Settings there is a Security Settings, ... another Group Policy MVP - he posted these steps on ...
      (microsoft.public.windows.group_policy)
    • "please contact your system administrator"... I *am* the administrator
      ... son is a little bit funny and keeps trying to lock the rest of the family ... Group Policy via Start> run> "gpedit.msc" to enable security settings. ... Administrator, the system is not allowing access to the Console. ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Bypassing domain and OU GPO settings using the Security Configuration and Analysis MMC
      ... That Group Policy is a template of settings being pushed to a machine, is the Client Side Extensions just basically Local Group Policy, in other words? ... An Adminis an Admin is an Admin. ... Thats the reason why he is an Administrator. ...
      (microsoft.public.windows.group_policy)
    • Re: Timed lockout set by Admin in Work Group
      ... You can do that with Group Policy. ... The only settings that need to be enabled are password ... protect the screen saver and screen saver timeout. ... administrator can use gpedit.msc however. ...
      (microsoft.public.windowsxp.security_admin)