Re: Applying SAFER policies via GPO, is this the right newsgroup to post in
- From: "Edward Ray" <ewray@xxxxxxxxxxxxxxxx>
- Date: Thu, 30 Mar 2006 12:43:45 -0800
If you want your users to have the ability to install and run programs, then
local admin with Internet is the way to go. In a small business (< 100
employees) we do not have the time or money to employ a huge IT dept with
help desk. Prefer to train users properly (SANS classes are great) and give
them local admin privileges. For secretaries and support personnel I agree;
they only have user privileges. But most other users (especially laptop
users and engineers) need local admin rights.
Easier to lock down the internet facing programs, as that is where 100% of
the attack vectors come from anyway. IE, Firefox, Outlook, Outlook Express,
WMP, Real, Quicktime, etc.
Although these days it looks like all programs communicate with the Internet
:)
"NickvW" <me@xxxxxxxxxxx> wrote in message
news:O$3EXZBVGHA.1688@xxxxxxxxxxxxxxxxxxxxxxx
"Edward Ray" <ewray@xxxxxxxxxxxxxxxx> wrote in message
news:%23n6K8qpUGHA.5808@xxxxxxxxxxxxxxxxxxxxxxx
I've always used GPR wherever possible for troubleshooting GPO applicationAre you saying that GPR shows these extensions to SAFER but that GPM
doesn't?
Yes!
(or not).
Just goes to show these RSoP simulations are just that.
BTW, don't you think that logging on with an ordinary user account and
then using runas with shortcuts, mmc etc is a better way to go than
logging on as an admin then relying on SAFER to limit the privileges of
'dangerous' processes that you start in that session?
I'd be interested to know what the business need is that requires an admin
to always be logged on as an admin. I would create two accounts.
.
- References:
- Applying SAFER policies via GPO, is this the right newsgroup to post in
- From: Edward Ray
- Re: Applying SAFER policies via GPO, is this the right newsgroup to post in
- From: NickvW
- Re: Applying SAFER policies via GPO, is this the right newsgroup to post in
- From: Edward Ray
- Re: Applying SAFER policies via GPO, is this the right newsgroup to post in
- From: NickvW
- Re: Applying SAFER policies via GPO, is this the right newsgroup to post in
- From: Edward Ray
- Re: Applying SAFER policies via GPO, is this the right newsgroup to post in
- From: NickvW
- Applying SAFER policies via GPO, is this the right newsgroup to post in
- Prev by Date: Re: Hundreds of failed login attempts
- Next by Date: Re: Remote desktop: cannot logon interactively (please help...)
- Previous by thread: Re: Applying SAFER policies via GPO, is this the right newsgroup to post in
- Next by thread: Re: Applying SAFER policies via GPO, is this the right newsgroup to post in
- Index(es):
Relevant Pages
|
|