Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17


Block Internet Access to a user using Group Policy on a 2003 Domain

Posted on 2004-09-22
Medium Priority
Last Modified: 2013-12-04
Hi everyone

I've a 2003 server with 80 wokstarions and 120 users.

All workstation are P IV with XP Pro SP1

I do not have a proxy server.

I can buy one but I would like to know if group policy on a 2003 server domain can do the job.

I've tried to disable the use of IE to some users with Group Policy but that is made based on the .exe name and
they just install another browser or rename IE .exe name and I need to block MSN Messenger etc ....

On the same workstation I've users that need to access internet and others that do not and may not access

need help !

thank you all

Question by:Carlos-jm
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
LVL 16

Accepted Solution

JamesDS earned 2000 total points
ID: 12121900
The most comprehensive method is to use IPSec policies to block port internet access:

There are variety of other methods by using faked proxy addresses and nobbling the hosts file, but all these methods can be removed or bypassed.

If the IPSec policy is too complex, then the next best thing is to block at your firewall or buy a proxy solution and block by username.

At it's simplest you could simply put in a server with an inbound and outbound NIC and install RRAS on it - this keeps the costs low as RRAS ships with Windows 2003 and the server does not need to be highly specced for only 80 workstations.



Author Comment

ID: 12123809
Hi jamesDS your post was great and I learn a lot with it.

But I still have a problem, or I'm not understanding right.

- Access block is assigned to a computer, I NEED IT to be assigned to a USER on any computer he uses

Thank you

LVL 16

Expert Comment

ID: 12124754
Assigning limited access to users is difficult - if they have local administrator privs.

However, you can set a non-existent proxy with GPOs and then use GPOs to deny access to the connections page on the IE options dialog. But this will not stop them installing a different browser.

I can give you the GPO options and settings if you think this is the route you want to take, but if they are prepared to install different browsers you cannot stop them without a proxy server that integrates into AD and is therefore capable of assigning access by user account.

I can also give you GPO settings that will remove them from the local administrators group on all machines!

How do you want to proceed?


LVL 24

Expert Comment

ID: 12126357
MS claims IE integral to OS.
To block, HW is still best.

A) Have no HW connected to internet
If you need internet, you should not block.
If you must block, then you have no need

B) Have the HW filter set up to deny access to IP addresses
Where you have one LAN for local net, one for all net, this is trivial

C) Allow surfing
If you cannot trust employee staff behavior, then you also do not need them to access any computer.
Where there is abuse, try replacing, it is currently a hirers market, with abundance of job seekers
LVL 16

Expert Comment

ID: 12130543
Not sure what you are trying to say here ?

Sure, the IE browser is integral to the OS, but that doesn't stop a local administrator user installing another browser. There are a variety of IE alternatives - none of which is forced to use the IE options controls and therefore is independant of the built in and default GPOs.

I disagree that access to the internet is either all or nothing, as you seem to be suggesting. Consider the call centre or the security guard on a night shift, who are given a machine for a specific task. These people have no business need for access to the internet, but the same people using the machine (with the same IP) at other times may have a legitimate use for it.

To be usefully controlled, internet access should be assigned by user.

In most operations users are not granted local administrative privs and so cannot install an alternate browser. This allows us to easily lock down internet access by user, using user-based GPOs and GPO apply groups. In this case the users are apparently local administrators, so access must be handled externally to the local machine and existing domain infrastructure with a proxy server - but still on a per-user basis.

There is a stark difference between trusting your users not to look at, and distribute illegal porn and trusting your users not to sit around all day and look at holiday websites and ebay. Many users do not see a problem with wasting company time on the internet. Further, you cannot fire someone (in the UK) for playing on the internet all day unless you go through a "3 strikes and you're out" type procedure - otherwise you are simply opening yourself up to an unfair dismissal lawsuit, which you will then lose.



Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Article by: btan
The intent is not to repeat what many has know about Ransomware but more to join its dots of what is it, who are the victims, why it exists, when and how we respond on infection. Lastly, sum up in a glance to share such information with more to help…
Security measures require Windows be logged in using Standard User login (not Administrator).  Yet, sometimes an application has to be run “As Administrator” from a Standard User login.  This paper describes how to create a shortcut icon to launch a…
Monitoring a network: how to monitor network services and why? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the philosophy behind service monitoring and why a handshake validation is critical in network monitoring. Software utilized …
Visualize your data even better in Access queries. Given a date and a value, this lesson shows how to compare that value with the previous value, calculate the difference, and display a circle if the value is the same, an up triangle if it increased…
Suggested Courses

664 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question