Re: Spying in a corporate environment



On Nov 23, 2007 3:08 PM, Ansgar -59cobalt- Wiechers
<bugtraq@xxxxxxxxxxxxxxxx> wrote:
<snip>

However, while being logged into the local machine instead of the domain
domain policies are not re-applied. An administrator can now manually
change/remove those policies. At least AFAICS. Someone correct me if I'm
wrong.

Regards
Ansgar Wiechers

Administrators can always access the registry and update whatever they
like, getting the settings re-applied by GPO the next time it runs
(every 90 mins or so). I'm pretty sure the GUI doesn't let you do what
you describe, in fact I just logged into my desktop as local admin and
I cannot edit the WSUS or Firewall rules as they are controlled by
GPO.

Of course there is a registry key to stop all GPO processing on a
client - this includes password policy, complex passwords the lot...

None of this is a big problem, as long as our users are not technical! :)

I have enough information to go looking for a tool, in fact I have
someone writing something for me that will address the USB memory
stick question, the others are covered by the 5 different tools I've
had recommended on this list.

Thanks for all the replies, I'm well aware of the issues we face
because the CIO wants everyone to have admin rights its a daily
discussion in our office :)

Cheers.
Colin.



Relevant Pages

  • Re: Camera Plug and Play
    ... > I have a test computer thta works fine with the camera. ... On the Client:>> In the Computer Admin area, the user id is administrator. ... >> I just find it odd that when logged into the local machine it all works>> fine. ...
    (microsoft.public.backoffice.smallbiz)
  • RE: Local Accounts
    ... domain user accounts administrators on the local machine. ... This will give them admin rights on the local machine ... though I can do this for the Administrator account as well. ...
    (microsoft.public.windows.server.sbs)
  • Re: Local user privileges
    ... > When I looked at an user account both local and domain accounts where set as ... > should not have administrator privileges ever his local machine. ... Lock in as administrator and remove the dom-user from the local ...
    (microsoft.public.win2000.group_policy)
  • Re: sbs installation and clients not opening encrypted files
    ... How do I log onto the local machine without getting on the sbs2003 domain? ... > Usually the local administrator is the EFS recovery Agent on local ... >> Administrator may not be sufficient. ... >> You have to logon as the original User who encrypted the ...
    (microsoft.public.windows.server.sbs)
  • Re: Domain-to-Workgroup: Cannot log on to computer
    ... > accounts are defined on the local machine ... ... you might try to reset the local Administrator ... Microsoft MVP Scripting and WMI, ...
    (microsoft.public.windowsxp.security_admin)