Block Internet Access to a user using Group Policy on a 2003 Domain

Posted on 2004-09-22
Last Modified: 2013-12-04
Hi everyone

I've a 2003 server with 80 wokstarions and 120 users.

All workstation are P IV with XP Pro SP1

I do not have a proxy server.

I can buy one but I would like to know if group policy on a 2003 server domain can do the job.

I've tried to disable the use of IE to some users with Group Policy but that is made based on the .exe name and
they just install another browser or rename IE .exe name and I need to block MSN Messenger etc ....

On the same workstation I've users that need to access internet and others that do not and may not access

need help !

thank you all

Question by:Carlos-jm
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
LVL 16

Accepted Solution

JamesDS earned 500 total points
ID: 12121900
The most comprehensive method is to use IPSec policies to block port internet access:

There are variety of other methods by using faked proxy addresses and nobbling the hosts file, but all these methods can be removed or bypassed.

If the IPSec policy is too complex, then the next best thing is to block at your firewall or buy a proxy solution and block by username.

At it's simplest you could simply put in a server with an inbound and outbound NIC and install RRAS on it - this keeps the costs low as RRAS ships with Windows 2003 and the server does not need to be highly specced for only 80 workstations.



Author Comment

ID: 12123809
Hi jamesDS your post was great and I learn a lot with it.

But I still have a problem, or I'm not understanding right.

- Access block is assigned to a computer, I NEED IT to be assigned to a USER on any computer he uses

Thank you

LVL 16

Expert Comment

ID: 12124754
Assigning limited access to users is difficult - if they have local administrator privs.

However, you can set a non-existent proxy with GPOs and then use GPOs to deny access to the connections page on the IE options dialog. But this will not stop them installing a different browser.

I can give you the GPO options and settings if you think this is the route you want to take, but if they are prepared to install different browsers you cannot stop them without a proxy server that integrates into AD and is therefore capable of assigning access by user account.

I can also give you GPO settings that will remove them from the local administrators group on all machines!

How do you want to proceed?


LVL 24

Expert Comment

ID: 12126357
MS claims IE integral to OS.
To block, HW is still best.

A) Have no HW connected to internet
If you need internet, you should not block.
If you must block, then you have no need

B) Have the HW filter set up to deny access to IP addresses
Where you have one LAN for local net, one for all net, this is trivial

C) Allow surfing
If you cannot trust employee staff behavior, then you also do not need them to access any computer.
Where there is abuse, try replacing, it is currently a hirers market, with abundance of job seekers
LVL 16

Expert Comment

ID: 12130543
Not sure what you are trying to say here ?

Sure, the IE browser is integral to the OS, but that doesn't stop a local administrator user installing another browser. There are a variety of IE alternatives - none of which is forced to use the IE options controls and therefore is independant of the built in and default GPOs.

I disagree that access to the internet is either all or nothing, as you seem to be suggesting. Consider the call centre or the security guard on a night shift, who are given a machine for a specific task. These people have no business need for access to the internet, but the same people using the machine (with the same IP) at other times may have a legitimate use for it.

To be usefully controlled, internet access should be assigned by user.

In most operations users are not granted local administrative privs and so cannot install an alternate browser. This allows us to easily lock down internet access by user, using user-based GPOs and GPO apply groups. In this case the users are apparently local administrators, so access must be handled externally to the local machine and existing domain infrastructure with a proxy server - but still on a per-user basis.

There is a stark difference between trusting your users not to look at, and distribute illegal porn and trusting your users not to sit around all day and look at holiday websites and ebay. Many users do not see a problem with wasting company time on the internet. Further, you cannot fire someone (in the UK) for playing on the internet all day unless you go through a "3 strikes and you're out" type procedure - otherwise you are simply opening yourself up to an unfair dismissal lawsuit, which you will then lose.



Featured Post

Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Users of Windows 10 Professional can disable automatic reboots using the policy editor. This tool is not included in the Windows home edition. But don't worry! Follow the instructions below to install (a Win7) policy editor on your Windows 10 Home e…
OfficeMate Freezes on login or does not load after login credentials are input.
In this brief tutorial Pawel from AdRem Software explains how you can quickly find out which services are running on your network, or what are the IP addresses of servers responsible for each service. Software used is freeware NetCrunch Tools (https…
In this video you will find out how to export Office 365 mailboxes using the built in eDiscovery tool. Bear in mind that although this method might be useful in some cases, using PST files as Office 365 backup is troublesome in a long run (more on t…
Suggested Courses

628 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question