Re: what do I do?



On 24/03/2007 "Roger Abell [MVP]" <mvpNoSpam@xxxxxxx> wrote:

"timj" <timj@xxxxxxxxxxx> wrote in message
news:ubQ0dgkbHHA.4176@xxxxxxxxxxxxxxxxxxxxxxx
Hi,

I work for a School Board and lately we have found that the kids can by
pass the GPO's. They put their login id and password in then ok, to
login. Once the login process starts they unplug the ethernet cable, they
get a few errors about their profile but now have full access to their
local pc.

Is there a way to stop it?

We use Windows 2000 server and Windows 2003 server.

Thanks

T.

There are a few tricks, like a login script that checks
for a mapped drive (such as to sysvol ?) and if it does
not exist does a logoff, if it does disconnects the share.
There is a group policy setting that requires background
application of policy to be disallowed (i.e. require that
policy is processed synchronously).
One could disable local caching of past logins (set the
number of logins cached to 0)




Hi,

I like your idea about the scripts do you have a sample I could look
at. Our users home directory is set to H: so I guess I could use that mapped
drive.

Thanks

T
.



Relevant Pages

  • Re: Editing gpedit.msc for Certain users only
    ... (server is on the domain), the RUN option is not available on the Start ... Any other users or group who login to serverXYZ will be able to see the ... But when groupABC login to any other servers on the network, ... > that OU create a policy that specifically couteracts the one that you have ...
    (microsoft.public.win2000.dns)
  • Re: Administrator cant log in locally
    ... the server, thus no remote administration. ... local login the question of 'did a patch or update cause this' makes ... I wouldn't think Microsoft would lock the local administrator ... 'dos' utility that would allow the administrator to change the policy ...
    (microsoft.public.windows.server.sbs)
  • Re: nach herabstufen eines DC kein zugriff mehr auf die Resourcen
    ... Kein Login weder an der Domäne oder LOKAL. ... Lokal bekomme ich Die meldung das die Policy das nicht zuläßt. ... >> Server sauber demote worden ist. ...
    (microsoft.public.de.german.win2000.active_directory)
  • Login Interactively
    ... We're running a domain with a Windows 2003 server as the pdc and a Windows ... I just enabled group policy so that all of the machines would get automatic ... If I reboot sometimes it will let them login. ...
    (microsoft.public.windows.server.security)
  • Re: Remote office users slow logon
    ... I am running SBS 2003 standard and Server 2003. ... Each user sees the black login script window and we are waiting for the ... It sounds like your login script is running something across the WAN. ... the default sbs_login.bat batch file and that the batch file is ...
    (microsoft.public.windows.server.sbs)