Solved

Laptop GPO lockdown

Posted on 2004-08-17
7
663 Views
Last Modified: 2012-06-21
Is there a way to apply a group policy to a XPpro laptop when it's off the Win 2K network, and keep my clients from loading programs and accepting addware?
0
Comment
Question by:rikicsofde
  • 3
  • 2
  • 2
7 Comments
 
LVL 104

Expert Comment

by:Sembee
ID: 11820150
If the machine is part of the domain and the machine can dial in to the domain then it is quite simple.

Get the user to connect to the network at the login prompt using "Connecting using Dial up Networking". This will make the machine act as part of the domain - meaning that the GP setting will be applied from the server. That setting will then stick until the machine is removed from the domain or gets an updated GP.

You can also use this process to keep online and offline passwords in sync by getting the user to change their password after logging in to the maching in this way.

Simon.
0
 

Author Comment

by:rikicsofde
ID: 11820677
The proplem isn't that simple. The client is the CEO and what to be able to connect to the internet anytime, anywhere without worry his computer will be open to programs he did not want.
0
 
LVL 104

Expert Comment

by:Sembee
ID: 11820763
It will be almost impossible to lock a machine down that hard. You would have to run a "block everything but..." list. This would very difficult to create. Windows has many small executables that it uses all the time (take a look at task manager) all of which would be have to be listed.

I am afraid to say that there isn't a technical solution to this problem.

Simon.
0
Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

 

Author Comment

by:rikicsofde
ID: 11821417
Thank you simon this is the conclusion I came up with as well.  Is it possible to to stop clients from doing this thru local group policy?
0
 

Accepted Solution

by:
SilverSox earned 500 total points
ID: 11821749
You could install spybot S&D this comes with an immunization tool that stops most spyware / addware, also get him to use a different web browser as IE will accept anything !! FireFox is the one I use and it has some great features including popup blocking software!
0
 

Author Comment

by:rikicsofde
ID: 11821848
Thank you for the guideance... We seem to be on the same page.

Rik.
0
 

Expert Comment

by:SilverSox
ID: 11828479
At the end of the day you’ve got to keep it simple.

I use group policy for desktop machines but laptops are in a world of there own and when your dealing with “suits” you cant afford to be trying out new things out!

Spybot is the best in the business even Microsoft recommend it on there site ans they don’t have anything themselves! Just be sure to update it when you install it and run the immunize tool it’s the business.

Keep windows updated, your Anti Virus updated and your already ahead of the competition!

Its all about layered security!

Good Luck  
0

Featured Post

Courses: Start Training Online With Pros, Today

Brush up on the basics or master the advanced techniques required to earn essential industry certifications, with Courses. Enroll in a course and start learning today. Training topics range from Android App Dev to the Xen Virtualization Platform.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This is the first one of a series of articles I’ll be writing to address technical issues that are always referred to as network problems. The network boundaries have changed, therefore having an understanding of how each piece in the network  puzzl…
Trying to figure out group policy inheritance and which settings apply where can be a chore.  Here's a very simple summary I've written which might help.  Keep in mind, this is just a high-level conceptual overview where I try to avoid getting bogge…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

785 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question