Trilight Zone Forum Index Trilight Zone
Privacy & Anonymity is our speciality !
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

Preventing Group Policy Workarounds

 
Post new topic   Reply to topic    Trilight Zone Forum Index -> Networking
Author Message
digital8
Second Lieutenant


Joined: 29 Sep 2005
Posts: 1002

PostPosted: Sat Oct 01, 2005 7:40 am    Post subject: Preventing Group Policy Workarounds Reply with quote

A smart user who has local Administrator or Power Users privileges on their desktop computer may be able to circumvent Group Policy.
A smart user who has local Administrator or Power Users privileges on their desktop computer may be able to circumvent Group Policy. For example, they could write a registry script and use it to remove or overwrite registry-based (Administrative Template) policy settings applied by domain GPOs on their machines.

To prevent this, start by ensuring that users do not have local Administrator or Power Users privileges and are simple Domain Users instead. Unfortunately for certain applications users may require such elevated privileges, so in that case you can try upping the background refresh rate of Group Policy but be aware that this will increase background traffic a bit on your network (though this is usually not significant except over a WAN) and also increase the load on your domain controllers (test this carefully). You can do this using the Group Policy Refresh Interval For Computers policy under Computer Configuration\Administrative Templates\System\Group Policy. Once you do this however, you should also configure the Registry Policy Processing policy under the same location to ensure that registry-based policy settings are processed on the client during background refresh even if Group Policy settings haven't changed.
Back to top
Display posts from previous:   
Post new topic   Reply to topic    Trilight Zone Forum Index -> Networking All times are GMT
Page 1 of 1

 


Powered by phpBB © 2001, 2005 phpBB Group