Solved

Locking down Wireless Profile

Posted on 2016-08-02
10
35 Views
Last Modified: 2016-09-10
We have 2 wireless networks in our company, one hidden SSID which is the company network and the other one is the Public network for guests (not hidden) I have an employee that constantly keeps removing the wireless profile already set on her computer (the hidden one), after doing so she ends up connecting to our public Wi-Fi (not hidden) and keeps blaming that the computer is the problem. This is the 4th time that is happening and I need to "lock down" the actual profile hidden profile that was initially created so that she can't hit the "Remove" option on top but still be able to add other networks (e.g Starbucks, Hotel Wi-Fi) if she decides to take the work computer home or travel. Does anyone have any idea how to address this? Can GPO fix this or perhaps a PowerShell script can do the trick? I really need to grey out the

Grey Out or Block Remove Option
0
Comment
Question by:Diego B
  • 4
  • 4
  • 2
10 Comments
 
LVL 38

Expert Comment

by:Adam Brown
ID: 41739705
Go to this section of the registry:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles
and change the permissions on that folder and subfolders that denies delete permission to that user. She'll be able to create new profiles, but will not be able to delete any.
1
 

Author Comment

by:Diego B
ID: 41739721
Testing as we speak... thank you so much!
0
 
LVL 45

Assisted Solution

by:Craig Beck
Craig Beck earned 500 total points (awarded by participants)
ID: 41739806
You can do this with GPO. It works much better than editing the registry and can force the client to oy connect to certain SSIDs while denying access to others.
1
 

Author Comment

by:Diego B
ID: 41739950
Adam any chance to revert back the permission issue in the registry? The implicit deny is there and now I can't revert the change.
0
 
LVL 38

Expert Comment

by:Adam Brown
ID: 41740017
Unless you set deny all permission for the user's group (Which is not what I recommended), you should be able to open the folder and set the permission. Otherwise, you'll have to use PSExec or a similar utility to open Regedit in the System context to modify the permissions.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 

Author Comment

by:Diego B
ID: 41747373
Craig you mentioned that GPO would be much easier than Adam's approach doing it through the Registry, can you please elaborate on the steps on how to do so?

thank you,
0
 
LVL 45

Accepted Solution

by:
Craig Beck earned 500 total points (awarded by participants)
ID: 41747531
Sure can.

Have a look at this great article which shows you the steps...

http://www.petenetlive.com/KB/Article/0000923
0
 

Author Comment

by:Diego B
ID: 41747798
Thank you, Craig. Now if I use this GPO setting will the user be able to delete the profile or will it lock it down?
0
 
LVL 45

Expert Comment

by:Craig Beck
ID: 41765888
Depending on how you configure the GPO you can choose how much control you want the user to have. You can lock it down if you choose.
0
 
LVL 45

Expert Comment

by:Craig Beck
ID: 41792433
Best answer chosen
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

On some Windows 7 (SP1) computers, Windows Update becomes super slow even the computer is reasonably fast.  There's one solution that seemed to have worked well for me (after trying a few other suggested solutions).
I had an issue with InstallShield not being able to use Computer Browser service on Windows Server 2012. Here is the solution I found.
This Micro Tutorial will give you a basic overview of Windows DVD Burner through its features and interface. This will be demonstrated using Windows 7 operating system.
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now