Re: Blocking group policy extensions pocessing
- From: "Mark Heitbrink [MVP]" <spam-only@xxxxxxxxxxxxxxxxxxxxx>
- Date: Tue, 25 Oct 2005 22:12:49 +0200
Hi,
M. Eteum schrieb:
> No offense, but how do we prevent such action by users such as this
> original poster? I'm sure that he has his reasons to do it, but imagine
> if all the user has that capability to do as such?
There is no ... If I have physical access to the system, it´s mine.
If he doesn´t has local admin rights or the possibility to get
admin rights, because he knows the password, it is a lot harder,
to do such task during his usual work. He can´t delete files, or
unregsiter DLLs, he can´t delete registry settings or change
things like the computer membership etc.
But if he can access the system via a different boot medium (WinPE, Knoppix
whatever) he can manipulate the system offline.
You have to find a way where restriction can let him work properly and
not causing in a very lot of money you have to spend. In most cases a
regulation in his employment contract can create a psycholocical barriere.
If you can give the users a sense of why they are working in a restricted
environment and don´t only publish high restricted GPOs to them, without
any help or guess of "why", the user will always try to fend it.
So User training is another part of making it more secure.
If all this doesn´t help, lock down the system with 3rd Party like
SecureWave Device Control, restrict physical access to the system.
Lock down computer case, remove CD, Floppy, USB ... it´s endless :-(
At the end, to feel really secure, you are back at paper, pencel and
a abacus :-)
Mark
--
Mark Heitbrink - MVP Windows Server
Homepage: www.gruppenrichtlinien.de
W2K FAQ : http://w2k-faq.ebend.de
PM: Vorname@Homepage, Versende-Adresse wird nicht abgerufen.
.
- Follow-Ups:
- Re: Blocking group policy extensions pocessing
- From: xsityu
- Re: Blocking group policy extensions pocessing
- References:
- Blocking group policy extensions pocessing
- From: xsityu
- Re: Blocking group policy extensions pocessing
- From: Mark Heitbrink [MVP]
- Re: Blocking group policy extensions pocessing
- From: M. Eteum
- Blocking group policy extensions pocessing
- Prev by Date: Re: Deny Group Policy
- Next by Date: Re: Win2000 IE GPO settings
- Previous by thread: Re: Blocking group policy extensions pocessing
- Next by thread: Re: Blocking group policy extensions pocessing
- Index(es):
Relevant Pages
|
Loading