Re: Users "bypassing" Group Policy restrictions

From: Bryan S. Sampsel (bsampsel_at_libertyactivist.org)
Date: 01/27/05

  • Next message: STEVE MAKOUSKY: "Re: Domain logon without network connection + group policies"
    Date: Thu, 27 Jan 2005 15:12:40 -0700 (MST)
    To: "Edward VanDewars" <gt4200b@yahoo.com>
    
    

    First question. Are there company management policies in place to deal
    with this? For instance, some employers will fire offending employees for
    violating such policies.

    Second question. Have you even talked to management about the activities
    of some employees in this situation?

    First, a company needs some documented (and preferably, signed
    acknowledgements) policies. Second, when you find a violation, collect
    the PC up as evidence...treating the situation like you would for any
    investigation. I'd recommend using the CISSP type guidelines: unplug the
    PC (powered up or not) and image the drive for evidence. Then present the
    evidence to management to take appropriate action.

    Caveat: do not make policies without consulting legal experts. The laws
    and ruling vary greatly depending on where you live.

    Second, if everything is set up, this is an issue for management. And if
    you can get the backing, disconnect the PC entirely from the network until
    management has resolved the issue and given you a green light to reconnect
    the system.

    Sincerely,

    Bryan S. Sampsel
    LibertyActivist.org

    Edward VanDewars said:
    > We utilize Group Policies and Software Restriction
    > Policies as the primary means of limiting unwanted
    > user actions on our desktop machines.
    >
    > Recently, however, several of our more "creative"
    > users have discovered that if they remove the ethernet
    > cable from the computer immediately after logging in
    > (i.e. as soon as their credentials are accepted) GPs
    > are not downloaded/applied. These users then are able
    > to use "net use" commands to map their necessary
    > network drives so they can work with full access to
    > resources usually mapped by GPs but without any of the
    > restrictions/limitations we impose and without
    > Software Restriction Policies preventing unwanted
    > programs from running (i.e. my nightmare).
    >
    > Short of gluing in the ethernet cables, how can I
    > prevent this bypassing of GPs? It appears that this
    > is only an issue if a cached local profile does not
    > exist on the computer. However, these computers use
    > drive "freezing" software to make changes to local
    > disks non-persistent. Thus, at each reboot a local
    > cache of their profile is gone. I tried shortening
    > the "Group Policy refresh interval for users" but
    > obviously if they don't download the policy in the
    > first place the computer will not see the shortened
    > refresh interval.
    >
    > Any advice is greatly appreciated; thanks in advance.
    >
    >
    >
    >
    > __________________________________
    > Do you Yahoo!?
    > All your favorites on one personal page – Try My Yahoo!
    > http://my.yahoo.com
    >
    > ---------------------------------------------------------------------------
    > ---------------------------------------------------------------------------
    >

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: STEVE MAKOUSKY: "Re: Domain logon without network connection + group policies"

    Relevant Pages

    • Re: career doldrums
      ... At every place I've worked for, big and small, I've eventually found that company policies actually prevent me from doing my job properly, and that drives me NUTS. ... As a result, management at all levels tell their underlings how to get the job done by side-stepping the policies, even if the policy states you'll be terminated for doing so. ... - a couple of idiots can demoralize a thousand good employees. ... Cut too many costs and pull a few bone head moves and those good people might as well stay in their offices and play with themselves. ...
      (sci.research.careers)
    • Re: 16GB limit
      ... Just like data retention policies - ... > have>16gb of mail then you have a admin and management ... > head around mailstore limits and start encouraging users ... > closely at the message size limits you allow - do this as ...
      (microsoft.public.exchange2000.information.store)
    • Re: career doldrums
      ... I'm learning now (now that I'm working for a huge corporation for the first time) that once companys reach a certain size they establish policies that actually prevent productivity. ... they can see who is eligible to be eventually welcomed into the domain of management. ...
      (sci.research.careers)
    • Re: restrict permissions to distribution lists
      ... And logging turned on so you can fire them when they ignore the policies! ... >> This is a management issue where, IMO you need a written policy about ... >> joke that goes out to a dozen people who each take 10 minutes reading and ... >>> Is there a way to restrict permissions on who can access and send mail ...
      (microsoft.public.windows.server.sbs)
    • Re: Wal-Mart benefits from deaths...
      ... Armatrout was one of about 350,000 employees Wal-Mart secretly insured nationwide, said Texas attorney Michael D. Myers, who estimated the company collected on 75 to 100 policies involving Florida employees who died. ... Myers is seeking to make the Armatrout lawsuit a class-action case on behalf of the estates of all the Florida employees who died while unwittingly insured by Wal-Mart. ... "If you ask the executives that decided to buy these policies and the insurance companies that sold them, they would say this was designed to create tax benefits for the company, which would use the benefits for benevolent purposes such as buying employee medical benefits. ...
      (rec.sport.pro-wrestling)