Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-Microsoft
[Top] [All Lists]

RE: Users "bypassing" Group Policy restrictions

Subject: RE: Users "bypassing" Group Policy restrictions
Date: Thu, 27 Jan 2005 17:18:04 -0700
I can think of three possibilities.

1)  Policies set to affect the machine (Computer configuration) are
persistant even if the network is not present.  The only way to bypass
machine policies (that I am aware of) is to pull the system from the
domain.  By moving enough of the AD restrictions to the machine policy,
you may make it no longer worthwhile for your users to take the extra
hassle of pulling the network cable.

2) Go admin - find a manager/supervisor/what not and make it all
official like and bring the hammer down on those who deliberatly bypass
security policies.


3) Go diplomatic - These are your users, not your enemy.  If they have a
legitimate beef with how the AD policies are interferring with their
job, try and find a compromise that allows them to remain productive.  
But - I've been in situations where an out-of-control security policy
was so restrictive that people were pulling their machines from the
network - flat out giving up on email and going back sneakernet for file
sharing - just to avoid all of the hassles with having a "secure"
computer.  
But it's up to you to determine if these are users with a legitimate
beef, or just some gits who are enjoying "breaking the system".

Allan Seyberth


---------------------------------------------------------------------------
---------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>