Re: Bypassing domain and OU GPO settings using the Security Configuration and Analysis MMC
- From: "Spin" <Spin@xxxxxxxxxxx>
- Date: Mon, 12 May 2008 21:04:36 -0400
I though Group Policy Refresh Interval was every 90 minutes +/- 30 by default. What is this 16 hours thing all about? That Group Policy is a template of settings being pushed to a machine, is the Client Side Extensions just basically Local Group Policy, in other words?
"Mark Heitbrink [MVP]" <spam-only@xxxxxxxxxxxxxxxxxxxxx> wrote in message news:OueAkmCtIHA.2188@xxxxxxxxxxxxxxxxxxxxxxx
Hi,
Spin schrieb:[...] You must be an admin on the machine to do this. My question is, isn't this a security risk in it's own right, bypassing domain> and OU GPO settings?
Sure, but what did you expect? An Adminis an Admin is an Admin.
Thats the reason why he is an Administrator.
He MUST be able to revert all settings, that unsuspecting user
possibly have made. An Administrator is a job or a role and being
an Administrator means that I know what I do by definition.
But here is your solution:
Because of the problem, that local Admins can override security settings
from the domain, the Client Side Extension of Security is running every
16 hours with a /FORCE option.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}
"MaxNoGPOListChangesInterval"=0x3C0 (960 minutes = 16 hours)
Just wait a day and everything will be fine agan, if the local
Administrator does not have find a much easier and more efectiv way
to block your settings.
Mark
--
Mark Heitbrink - MVP Windows Server - Group Policy
Homepage: www.gruppenrichtlinien.de - deutsch
Blog: gpupdate.spaces.live.com - english
.
- Follow-Ups:
- Re: Bypassing domain and OU GPO settings using the Security Configuration and Analysis MMC
- From: Mark Heitbrink [MVP]
- Re: Bypassing domain and OU GPO settings using the Security Configuration and Analysis MMC
- From: Florian Frommherz [MVP]
- Re: Bypassing domain and OU GPO settings using the Security Configuration and Analysis MMC
- References:
- Prev by Date: Re: policy to turn off protected mode in IE7/Vista
- Next by Date: Re: Changed admin password event ID 1030 Source Userenv
- Previous by thread: Re: Bypassing domain and OU GPO settings using the Security Configuration and Analysis MMC
- Next by thread: Re: Bypassing domain and OU GPO settings using the Security Configuration and Analysis MMC
- Index(es):
Relevant Pages
|
Loading