Users "bypassing" Group Policy restrictions

From: Edward VanDewars (gt4200b_at_yahoo.com)
Date: 01/27/05

  • Next message: Marc Fossi: "SecurityFocus Microsoft Newsletter #225"
    Date: Thu, 27 Jan 2005 05:28:40 -0800 (PST)
    To: focus-ms@securityfocus.com
    
    

    We utilize Group Policies and Software Restriction
    Policies as the primary means of limiting unwanted
    user actions on our desktop machines.

    Recently, however, several of our more "creative"
    users have discovered that if they remove the ethernet
    cable from the computer immediately after logging in
    (i.e. as soon as their credentials are accepted) GPs
    are not downloaded/applied. These users then are able
    to use "net use" commands to map their necessary
    network drives so they can work with full access to
    resources usually mapped by GPs but without any of the
    restrictions/limitations we impose and without
    Software Restriction Policies preventing unwanted
    programs from running (i.e. my nightmare).

    Short of gluing in the ethernet cables, how can I
    prevent this bypassing of GPs? It appears that this
    is only an issue if a cached local profile does not
    exist on the computer. However, these computers use
    drive "freezing" software to make changes to local
    disks non-persistent. Thus, at each reboot a local
    cache of their profile is gone. I tried shortening
    the "Group Policy refresh interval for users" but
    obviously if they don't download the policy in the
    first place the computer will not see the shortened
    refresh interval.

    Any advice is greatly appreciated; thanks in advance.

                    
    __________________________________
    Do you Yahoo!?
    All your favorites on one personal page – Try My Yahoo!
    http://my.yahoo.com

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Marc Fossi: "SecurityFocus Microsoft Newsletter #225"

    Relevant Pages

    • Re: Securing XP from teenager
      ... > In addition to other advice you also want to do the basics of firewall, ... > will also scan all emails and keep itself updated such as Norton. ... In addition XP Pro has "Software Restriction ... > policies. ...
      (microsoft.public.security)
    • Re: cmd and command
      ... >group policy to disable the command prompt. ... >> policies. ...
      (microsoft.public.win2000.security)
    • Temp Profile are not deleted after Software Restriction is activated
      ... I want to secure our Serverfarm with software restriction ... policies. ... But when i enable the GPO link, ... The temp profiles are still not deleted. ...
      (microsoft.public.windows.terminal_services)
    • Re: Netlogon share denies access to script
      ... policies are set to unrestricted. ... I cannot execute wscript/csript on the client machine under a domain user ... I mean can you list the script file or copy it to local ... the problem should be related to the Software restriction ...
      (microsoft.public.scripting.wsh)