Re: Domain logon without network connection + group policies

From: Danny (nocmonkey_at_gmail.com)
Date: 01/27/05

  • Next message: Miroslaw Slawek Chorazy: "Re: Users "bypassing" Group Policy restrictions"
    Date: Thu, 27 Jan 2005 16:51:08 -0500
    To: Manuel Sousa <manuel.sousa@gmail.com>
    
    

    On Thu, 27 Jan 2005 12:57:33 +0000, Manuel Sousa <manuel.sousa@gmail.com> wrote:
    > Hi,
    >
    > I've realized that it's possible to logon to a domain without a
    > network connection and bypass the group policies.
    >
    > This provides false security when deploying policies that restrict
    > user permissions, so my question is:
    > 1. Is it possible to forbid logon if the workstation can't connect to
    > the Domain Controller;
    > 2. Or is it possible to have a cache of the group policies so that if
    > the workstation doesn't have network, it uses the last policies?
    >
    > One workaround is deploying the policies as local ones, but that
    > removes the flexibility of deploying / changing the policies from the
    > domain, so i'm open for other suggestions.

    Would disabling cached logins solve your problem?

    ...D

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Miroslaw Slawek Chorazy: "Re: Users "bypassing" Group Policy restrictions"

    Relevant Pages

    • Re: Group policy
      ... Group policies for users are automatically applied at logon and then by ... Computer policies are automatically applied at startup and then also every ... are available) command from your run command. ...
      (microsoft.public.windowsxp.security_admin)
    • Domain logon without network connection + group policies
      ... network connection and bypass the group policies. ... This provides false security when deploying policies that restrict ...
      (Focus-Microsoft)
    • Re: unable to logon to server 2003
      ... I did an rsop and check what policies were being applied the problem DC, ... This is obviously a replication issue because the domain ... logon to the DC’s but since no policies are being applied to then DC then it ... This server is behaving very strangely - dns and other stuff will not ...
      (microsoft.public.windows.server.active_directory)
    • Re: Assigning File and Folder Permissions Via Group Policy
      ... still pretty new to group policies and so wanted to double-check my ... so a few policies with a lot of settings in each policy may ... or two settings also may not be the best solution. ...
      (microsoft.public.windows.group_policy)
    • Re: Users cant use terminal services !!!
      ... About not seeing the "Logon through TS" user right: ... Are you editing the policies from your DC? ... MCSE, CCEA, Microsoft MVP - Terminal Server ... But with Terminal services they keep receiving the ...
      (microsoft.public.windows.terminal_services)