Re: Hackers - Prevent GPOs

Tech-Archive recommends: Fix windows errors by optimizing your registry



If the person had local admin rights, they can block certain registry
keys from getting updated simply by changing the permissions on the
registry key. For example, if your domain had a gpo that set a legal
notice that popped up before logon, the user who has local admin
access can simply set the applicable registry keys so the policy
cannot update them. Of course the event log will bleed lots of errors
about policy errors, not being applied, etc. but the legal notice in
this example would not get applied to that machine.

If the person in question has signed their agreement not to mess with
company equipment, circumvent policies, etc, then fire them.

HTH


"Drew" <Drew@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:

>Hello,
>
>In an effort to be proactive, I'm curious if there is any known registry
>hacks which can prevent domain policies from being applied to clients. Most
>users are administrators on their own machines, and the are a few machines
>that have had problems applying GPOs. Often times I'm worried that the users
>themselves are making changes that would prevent group policies from being
>applied, however I'm unaware of any hacks which can accomplish this. If there
>are any known ways to hack a machine to prevent GPOs from running, I would
>like to know, so I can take appropriate actions to try to prevent access to
>those particular keys.
>
>Does anyone know of any methods or web sites that have any of these hacks
>available?


Ha®®y

HarryKrishna.nospam@xxxxxxxxx
.



Relevant Pages

  • Re: Registry change
    ... > Can anyone have an idea how to give users access to add a registry key to ... > logon to dirrent terminal server each time. ... > local admin access to a terminal server. ...
    (microsoft.public.win2000.general)
  • Registry change
    ... Can anyone have an idea how to give users access to add a registry key to a ... logon to dirrent terminal server each time. ... The Registry key has been added to a batch file which runs as a part of the ... local admin access to a terminal server. ...
    (microsoft.public.win2000.general)
  • Re: "run as" command ?
    ... permissions on a registry key for those programs that insist upon ... running as local admin rather than doing a "run as" all the time. ... > machine while logged in as a local administrator to ...
    (microsoft.public.windows.server.sbs)
  • RE: GPO Software MSI over Wireless
    ... Add the registry Key. ... Policies now work and I'm happy. ... "shauncarter1" wrote: ... Settings\Security Settings container to no avail. ...
    (microsoft.public.windows.group_policy)
  • Security Policies in Registry
    ... For example I know that registry key 00001001 is the RAPI policy ... For example I have policies with ... registry entries of 00001025 and 00001024. ...
    (microsoft.public.pocketpc.developer)