Solved

GPO for Screensaver Timeout - How to avoid override?

Posted on 2009-03-31
4
3,515 Views
Last Modified: 2012-05-06
Environment: Windows 2003 Active Directory. All workstations are windows xp.
We have a gpo on workstations to start the screensaver after 15 minutes and require password to unlock using the following :
User Configuration/Administrative Templates/Control Panel/Display
 Password protect the screen saver - Enabled
 Screen Saver - Enabled
 Screen Saver Timeout - Enabled
 Number of seconds to wait to enable the screen saver seconds: 900

Some crafty users found a way around this by changing the following registry keys:
[HKEY_USERS\S-1-5-21-1214440339-854245398-1177238915-2872\Software\Policies\Microsoft\Windows\Control Panel\Desktop]
"ScreenSaverIsSecure"="0"
"ScreenSaveTimeOut"="0"
"ScreenSaveActive"="0"

This would be fine if the normal group policy refresh would overwrite this and change it back, but it doesn't.  The only way to set it back is to do a gpupdate /force on the workstation. Do you have any ideas on how to get these users policy back without having to visit each workstation? Secondly, how do i prevent them from doing it again?
0
Comment
Question by:bgcpc
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 18

Accepted Solution

by:
Americom earned 150 total points
ID: 24034201
You can make the GPO to process even if the GPO has not changed:
Computer Configuration>Administrative Templates>System>Group Policy>Registry policy processing>Enable and select "Process even if the Group Policy objects".

Since you have set GPO and if the user still change the registry, then he/she violate the company policy, take them out of the Administrators group of their machine.
0
 
LVL 47

Assisted Solution

by:Donald Stewart
Donald Stewart earned 50 total points
ID: 24035097
You could also.....

Disable registry editing tools

User Configuration\Administrative Templates\System
0
 
LVL 66

Assisted Solution

by:johnb6767
johnb6767 earned 50 total points
ID: 24035773
And for the craftiest of the crafty, disable access to reg.exe......
0
 
LVL 1

Author Comment

by:bgcpc
ID: 24038436
Thanks, looks like this should do the trick.
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A project that enables an administrator to perform actions within a user session context not just at the time of login but any time later on day(s) or week(s) later.
Active Directory security has been a hot topic of late, and for good reason. With 90% of the world’s organization using this system to manage access to all parts of their IT infrastructure, knowing how to protect against threats and keep vulnerabil…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question