RE: Disabling sharing and group policies

From: Laura A. Robinson (larobins_at_bellatlantic.net)
Date: 09/18/03

  • Next message: JF Pivonka: "RE: Blank passwords, TsInternetUser added to Administrators"
    To: "'Sergey V. Gordeychik'" <gordey@infosec.ru>, <robert@snrdesigns.com>, "'Focus-Ms'" <focus-ms@securityfocus.com>
    Date: Thu, 18 Sep 2003 12:38:06 -0400
    
    

    Again, this is not the case. A user with local Administrator rights to
    his/her machine *can* exempt his/her machine from group policy application.
    No ifs, ands or buts.

    Laura

    > -----Original Message-----
    > From: Sergey V. Gordeychik [mailto:gordey@infosec.ru]
    > Sent: Thursday, September 18, 2003 1:59 AM
    > To: larobins@bellatlantic.net; robert@snrdesigns.com; Focus-Ms
    > Subject: RE: Disabling sharing and group policies
    >
    >
    > If you disable Group Policy loopback mode in domain-level
    > GPO, local administrator will unable to change group policy
    > on computer. Yes, administrator can modify some settings, but
    > these settings will replaced when GPO applied again.
    >
    > Simplest way to disable sharing for any user with
    > administrative rights
    > - it's filter CIFS/SMB/Netbios servers (TCP/UDP 445, 139)
    > packets with IPSec packet filter policies (SPD).
    > Even user share something on computer - filters will drop
    > connection packets and prevent network sharing.
    > In policy you can also allow CIFS/Netbios connections from
    > management stations for logs collection, etc.
    > Information about IPSec filtering you can find, for example,
    > in Windows Server 2003 Security Guide:
    >
    http://www.microsoft.com/technet/treeview/default.asp?url=/technet/secur
    ity/prodtech/Windows/Win2003/W2003HG/SGCH04.asp

    Regards,
    Sergey V. Gordeychik.

    -----Original Message-----
    From: Laura A. Robinson [mailto:larobins@bellatlantic.net]
    Sent: Tuesday, September 16, 2003 6:47 PM
    To: robert@snrdesigns.com; 'Focus-Ms'
    Subject: RE: Disabling sharing and group policies

    Actually, as I said, anybody with administrative rights on his/her machine
    can exempt his/her machine from group policy application- *regardless* of
    whether or not that machine is a domain member. The local admin does
    *not*
    have to leave the domain to accomplish this.

    Laura

    ---------------------------------------------------------------------------
    KaVaDo provides the first and only integrated Web application scanner and
    firewall security suite that prevent Web applications attacks, the most
    common form of online exploitation. Download a FREE whitepaper on Security Policy Automation for Web Applications.
    http://www.securityfocus.com/sponsor/KaVaDo_focus-ms_030818
    ---------------------------------------------------------------------------


  • Next message: JF Pivonka: "RE: Blank passwords, TsInternetUser added to Administrators"

    Relevant Pages

    • Re: Group Policy for detached domain client
      ... Once they are off the LAN they log into ... > their machines as usuall but do not have administrative rights. ... > saying that once the machine is off the network, the group policy does not ... apart from manually adding them to the local policy on each ...
      (microsoft.public.win2000.group_policy)
    • Re: Restoring Administrative Rights to domain computers
      ... As Lanwench indicated you can use a Group Policy startup script. ... in the local administrators group is enforced by two possible methods. ... to restrict the Administrative Rights on the system. ...
      (microsoft.public.security)
    • Re: No access to Group Policy Object
      ... | unspecified error with the message: No access to Group Policy Object on ... | this computer(you may not have administrative rights)! ... | I am trying to do this for a reason: I cannot turn off System Restore ...
      (microsoft.public.windowsxp.security_admin)
    • Can user change IP settings with Group Policy Enabled
      ... We have group policy in almost a locked down state, ... account doing it. ... were no patterns between the computers. ...
      (microsoft.public.windowsxp.network_web)
    • Group Policy and restricting local administrators
      ... I am currently working on developing a group policy on a AD container ... I certain users to have virtually local administrator ... access to a series of servers, but there are a few things I do not want ... users inside of a container from be able to access the User Management ...
      (microsoft.public.windows.server.general)