Russinovich on Circumventing Group Policy Settings

Software restriction policies help prevent users from circumventing Group Policy.

ITPro Today

December 11, 2005

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Windows IT Pro Magazine columnist Mark Russinovich posted an article, "Circumventing Group Policy Settings," in his Sysinternals Blog that makes excellent reading for all you security admins. Here are a couple of snippets:

"Windows administrators should be aware that if a user, even one running with a limited account, can execute just one program of their choice that they also can circumvent many group policy settings, including ones aimed specifically at tightening security such as Software Restriction Policies and Internet Explorer Zones."

[... huge snip ...]

"The bottom lines is that full control of an end-user environment is possible only with strict lock-down of the programs they run, something that you can accomplish by using SRP in white-list mode, for example. Note that this is not a bug in Windows, but rather a design decision made by the Group Policy team."

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like