Page 2 of 2 FirstFirst 12
Results 17 to 31 of 31

Thread: System Admin: Need help with Logon Scripts, Group Policy Etc...

  1. #17
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    384 times in 313 posts
    is your activedirectory 200 or 2003 ?

    if it is 2003 , then look up software restriction policies

    The only problem with restricting access to IE is that it might well affect other parts of windows.

    you'd be better of to restrict IE to only be able to connect to trusted sites , then use that trusted site list to maintain a whitelist of sites , which may well just be the company main site , or intranet.
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  2. #18
    Squeeler Vini's Avatar
    Join Date
    Jul 2003
    Location
    Sheffield
    Posts
    1,769
    Thanks
    44
    Thanked
    8 times in 8 posts
    its 2003. the whitelist sounds like a good idea. excellent.

    thanks for your help MD!

  3. #19
    Squeeler Vini's Avatar
    Join Date
    Jul 2003
    Location
    Sheffield
    Posts
    1,769
    Thanks
    44
    Thanked
    8 times in 8 posts
    Quote Originally Posted by Moby-Dick
    you'd be better of to restrict IE to only be able to connect to trusted sites , then use that trusted site list to maintain a whitelist of sites , which may well just be the company main site , or intranet.
    thought it would be simple, however upon investigation doesnt appear to be so.

    where do these features/options sit in ad2003?

  4. #20
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    384 times in 313 posts
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  5. #21
    Squeeler Vini's Avatar
    Join Date
    Jul 2003
    Location
    Sheffield
    Posts
    1,769
    Thanks
    44
    Thanked
    8 times in 8 posts
    read through that and got a white list running but IE still seems to happily browse to all sites.

    that aside, can i run batch files as logon scripts?

  6. #22
    Nox
    Nox is offline
    Vorsprung durch Technik
    Join Date
    Oct 2003
    Location
    Hampshire
    Posts
    2,023
    Thanks
    2
    Thanked
    2 times in 2 posts
    • Nox's system
      • Motherboard:
      • Yes
      • CPU:
      • Yes
      • Memory:
      • Yes
      • Storage:
      • Yes
      • Graphics card(s):
      • Yes
      • PSU:
      • Yes
      • Case:
      • Yes
      • Monitor(s):
      • Yes
      • Internet:
      • Yes
    uninstall?

    or, if you follow this:

    create a group on the client machine, call it CLIENT-IE or something
    add this group to c:\program files\internet explorer and remove all non-admin rights. This should be applied to all sub-dirs too.

    great, now the only people who can use IE are people with local admin rights, or in this group. want easy admin of this group?

    create a domain group called DOM-IE, and add this into the CLIENT-IE group on the local machine. Now anyone in the DOM-IE group can use IE when they log on.

    you should be able to do this for anything, but will require a bit of experimenting. You may run into a few probs, but as long as the system has access to that dir you should be fine.

    oh, and that will work without this active dir malarky

    Nox
    Last edited by Nox; 07-06-2005 at 07:25 PM.

  7. #23
    Nox
    Nox is offline
    Vorsprung durch Technik
    Join Date
    Oct 2003
    Location
    Hampshire
    Posts
    2,023
    Thanks
    2
    Thanked
    2 times in 2 posts
    • Nox's system
      • Motherboard:
      • Yes
      • CPU:
      • Yes
      • Memory:
      • Yes
      • Storage:
      • Yes
      • Graphics card(s):
      • Yes
      • PSU:
      • Yes
      • Case:
      • Yes
      • Monitor(s):
      • Yes
      • Internet:
      • Yes
    Can you not block the sites on your proxy server ?

    Nox

  8. #24
    Registered+
    Join Date
    Mar 2005
    Posts
    33
    Thanks
    0
    Thanked
    0 times in 0 posts
    Quote Originally Posted by Nox
    uninstall?

    or, if you follow this:

    create a group on the client machine, call it CLIENT-IE or something
    add this group to c:\program files\internet explorer and remove all non-admin rights. This should be applied to all sub-dirs too.

    great, now the only people who can use IE are people with local admin rights, or in this group. want easy admin of this group?

    create a domain group called DOM-IE, and add this into the CLIENT-IE group on the local machine. Now anyone in the DOM-IE group can use IE when they log on.

    you should be able to do this for anything, but will require a bit of experimenting. You may run into a few probs, but as long as the system has access to that dir you should be fine.

    oh, and that will work without this active dir malarky

    Nox
    What is to stop people typing a URL into the Windows Explorer address bar?

    Blocking all but your site (or a site which says 'You do not have Internet access') is the best way to go if you want to block IE.

  9. #25
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    384 times in 313 posts
    hence needing somethign like dansguardian or websence
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  10. #26
    Senior Member
    Join Date
    Mar 2005
    Posts
    4,944
    Thanks
    171
    Thanked
    387 times in 314 posts
    • badass's system
      • Motherboard:
      • ASUS P8Z77-m pro
      • CPU:
      • Core i5 3570K
      • Memory:
      • 32GB
      • Storage:
      • 1TB Samsung 850 EVO, 2TB WD Green
      • Graphics card(s):
      • Radeon RX 580
      • PSU:
      • Corsair HX520W
      • Case:
      • Silverstone SG02-F
      • Operating System:
      • Windows 10 X64
      • Monitor(s):
      • Del U2311, LG226WTQ
      • Internet:
      • 80/20 FTTC
    Firewall+proxy settings defined by a GPO for people that are allowed access to the internet.
    block outgoing communication from the firewall apart from servers and then only allow for the services they run. Then use a proxy server for internet access for admins, with the proxy settings defined through group policy
    "In a perfect world... spammers would get caught, go to jail, and share a cell with many men who have enlarged their penises, taken Viagra and are looking for a new relationship."

  11. #27
    Squeeler Vini's Avatar
    Join Date
    Jul 2003
    Location
    Sheffield
    Posts
    1,769
    Thanks
    44
    Thanked
    8 times in 8 posts
    Config User / Admin template / System / Prevent users from using specific progrms

    disable access to iexplore.exe has worked fine..

    now im after a way to tidy up the start menu, showing only programs of my choice.

  12. #28
    Nox
    Nox is offline
    Vorsprung durch Technik
    Join Date
    Oct 2003
    Location
    Hampshire
    Posts
    2,023
    Thanks
    2
    Thanked
    2 times in 2 posts
    • Nox's system
      • Motherboard:
      • Yes
      • CPU:
      • Yes
      • Memory:
      • Yes
      • Storage:
      • Yes
      • Graphics card(s):
      • Yes
      • PSU:
      • Yes
      • Case:
      • Yes
      • Monitor(s):
      • Yes
      • Internet:
      • Yes
    Quote Originally Posted by rickyboy
    What is to stop people typing a URL into the Windows Explorer address bar?
    Windows NT here mate

    Vini did you check that you can't access websites from windows explorer?

    proxy server is the best way to go... by far.

    Nox

  13. #29
    Squeeler Vini's Avatar
    Join Date
    Jul 2003
    Location
    Sheffield
    Posts
    1,769
    Thanks
    44
    Thanked
    8 times in 8 posts
    cant access by:

    iexplore.exe
    windows explorer/my computer
    opening an application which "links to their homepage"
    windows update button
    any interactive cd which runs IE.

  14. #30
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    384 times in 313 posts
    so having a 2nd browser on a USB stick would get round that

    such as...

    http://johnhaller.com/jh/mozilla/portable_firefox/


    hence why your next mission is to ban USB drives & ipods - or prevent them from connecting to the network.

    just think how easy it woudl be from someone to plug a usb HD in an remove data from the network.

    or worse still , a trusted employee taking info home to work on ( eg sensetive stuff )
    but his usb HD get nicked on the way home.

    the same HD that contains confidential , yet unencrpyted data.

    its a nightmare just waiting to happen
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  15. #31
    Squeeler Vini's Avatar
    Join Date
    Jul 2003
    Location
    Sheffield
    Posts
    1,769
    Thanks
    44
    Thanked
    8 times in 8 posts
    nah, these machines are locked down enough for that not to be an issue, if they really do want to access the web its fine we dont have any *STRICT* rules, however this will put most off trying to access...

Page 2 of 2 FirstFirst 12

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Instance Walkthrough Guide
    By ERU in forum PC
    Replies: 1
    Last Post: 28-04-2005, 10:35 PM
  2. where are the logon scripts!
    By Crazy Fool in forum Help! Quick Relief From Tech Headaches
    Replies: 1
    Last Post: 17-01-2005, 07:13 PM
  3. Abit NF7-S revision 2 information
    By Lee H in forum SCAN.care@HEXUS
    Replies: 22
    Last Post: 30-10-2004, 07:13 PM
  4. Keeping your system healthy and secure
    By Paul Adams in forum Software
    Replies: 6
    Last Post: 12-10-2004, 09:35 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •