Enforcing Group Policy

| | No TrackBacks
Local administrator accounts on Windows workstations can arbitrarily edit the registry and thus override many Group Policy settings initially applied. The best approach is not to grant local administrative privileges but it can't always be done, and in most cases isn't convenient.

For example, a number of pieces of software will only run as privileged user. Installing software will also require administrative privileges in many cases.

To prevent Group Policy workaround, the following might be a solution:

Open
Computer Configuration \ Administrative Templates \ System \ Group Policy

Look for the policies with names ending in "...policy processing". Open every such policy and select the checkbox "Process even if the Group Policy objects have not changed". This will force these policies to always be applied regardless of whether the GPO settings have actually changed or not.

This will make any local changes be undone next time the Group Policy is refreshed in the background.

No TrackBacks

TrackBack URL: /blog/mt-tb.cgi/28

blog comments powered by Disqus

About this Entry

This page contains a single entry by Konstantin Boyandin published on December 10, 2009 7:28 PM.

How To: Choose a VPN Auth Protocol was the previous entry in this blog.

Port 445 And Trust Creation is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.