?
Solved

Disabling GPO and Killpol

Posted on 2013-12-20
4
Medium Priority
?
3,379 Views
Last Modified: 2013-12-30
1) How does Killpol disable the applied GPO ? How does it revert the GPO ?
2) How can I create a simple BATCH file to perform similar functions ?
0
Comment
Question by:kaerez
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
4 Comments
 
LVL 79

Expert Comment

by:arnold
ID: 39733067
Check the GPO properties on what happens when it no longer applies.
Once you make sure the GPO settings will revert when it no longer applies.  Let the GPO remain in place for a week or so to make sure the changes if made will have enough time to propagate. Then unlink/remove the policy from applying.  Depending on the settings it control that may not revert.
0
 
LVL 12

Expert Comment

by:Dave
ID: 39740300
I don't know how Killpol disables GPOs and it appears to no longer be available for download so its hard to find out. Policies to be applied end up stored in:-

HKEY_LOCAL_MACHINE\Software\Policies\

and

HKEY_CURRENT_USER\Software\Policies\

generally removing the keys causes the policies to be removed instantly. They automatically re-apply after 15 minutes. So in order to remove "most" policies all you need to do is delete the key in question AND prevent the policy being re-applied.

So check the above keys in the registry and see what KillPol does to them Then replicate this in a batch script.
0
 
LVL 12

Accepted Solution

by:
Dave earned 2000 total points
ID: 39740318
Ok found how to stop them re-applying here:-

http://blogs.technet.com/b/markrussinovich/archive/2005/04/30/circumventing-group-policy-settings.aspx

....to stop GP from reapplying.

To change the refresh interval for computers:
Registry key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\ System
Name: GroupPolicyRefreshTime
Type: REG_DWORD
Valid range for data (in minutes): 0 to 64800

• To change the offset interval for computers:
Registry key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\ System
Name: GroupPolicyRefreshTimeOffset
Type: REG_DWORD
Valid range for data (in minutes): 0 to 1440



To change the refresh interval for users:
Registry key: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\ System
Name: GroupPolicyRefreshTime
Type: REG_DWORD
Valid range for data (in minutes): 0 to 64800

• To change the offset interval for users:
Registry key: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\ System
Name: GroupPolicyRefreshTimeOffset
Type: REG_DWORD
Valid range for data (in minutes): 0 to 1440


0 == Never
0
 
LVL 12

Expert Comment

by:Dave
ID: 39740329
Sorry you can use the "reg delete" to delete the values you want to delete.
0

Featured Post

Video: Liquid Web Managed WordPress Comparisons

If you run run a WordPress, you understand the potential headaches you may face when updating your plugins and themes. Do you choose to update on the fly and risk taking down your site; or do you set up a staging, keep it in sync with your live site and use that to test updates?

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article is a collection of issues that people face from time to time and possible solutions to those issues. I hope you enjoy reading it.
I was prompted to write this article after the recent World-Wide Ransomware outbreak. For years now, System Administrators around the world have used the excuse of "Waiting a Bit" before applying Security Patch Updates. This type of reasoning to me …
As developers, we are not limited to the functions provided by the VBA language. In addition, we can call the functions that are part of the Windows operating system. These functions are part of the Windows API (Application Programming Interface). U…
In this video, viewers are given an introduction to using the Windows 10 Snipping Tool, how to quickly locate it when it's needed and also how make it always available with a single click of a mouse button, by pinning it to the Desktop Task Bar. Int…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question