Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Locking down Wireless Profile

Posted on 2016-08-02
10
Medium Priority
?
47 Views
Last Modified: 2016-09-10
We have 2 wireless networks in our company, one hidden SSID which is the company network and the other one is the Public network for guests (not hidden) I have an employee that constantly keeps removing the wireless profile already set on her computer (the hidden one), after doing so she ends up connecting to our public Wi-Fi (not hidden) and keeps blaming that the computer is the problem. This is the 4th time that is happening and I need to "lock down" the actual profile hidden profile that was initially created so that she can't hit the "Remove" option on top but still be able to add other networks (e.g Starbucks, Hotel Wi-Fi) if she decides to take the work computer home or travel. Does anyone have any idea how to address this? Can GPO fix this or perhaps a PowerShell script can do the trick? I really need to grey out the

Grey Out or Block Remove Option
0
Comment
Question by:Diego B
  • 4
  • 4
  • 2
10 Comments
 
LVL 43

Expert Comment

by:Adam Brown
ID: 41739705
Go to this section of the registry:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles
and change the permissions on that folder and subfolders that denies delete permission to that user. She'll be able to create new profiles, but will not be able to delete any.
1
 

Author Comment

by:Diego B
ID: 41739721
Testing as we speak... thank you so much!
0
 
LVL 47

Assisted Solution

by:Craig Beck
Craig Beck earned 2000 total points (awarded by participants)
ID: 41739806
You can do this with GPO. It works much better than editing the registry and can force the client to oy connect to certain SSIDs while denying access to others.
1
 The Evil-ution of Network Security Threats

What are the hacks that forever changed the security industry? To answer that question, we created an exciting new eBook that takes you on a trip through hacking history. It explores the top hacks from the 80s to 2010s, why they mattered, and how the security industry responded.

 

Author Comment

by:Diego B
ID: 41739950
Adam any chance to revert back the permission issue in the registry? The implicit deny is there and now I can't revert the change.
0
 
LVL 43

Expert Comment

by:Adam Brown
ID: 41740017
Unless you set deny all permission for the user's group (Which is not what I recommended), you should be able to open the folder and set the permission. Otherwise, you'll have to use PSExec or a similar utility to open Regedit in the System context to modify the permissions.
0
 

Author Comment

by:Diego B
ID: 41747373
Craig you mentioned that GPO would be much easier than Adam's approach doing it through the Registry, can you please elaborate on the steps on how to do so?

thank you,
0
 
LVL 47

Accepted Solution

by:
Craig Beck earned 2000 total points (awarded by participants)
ID: 41747531
Sure can.

Have a look at this great article which shows you the steps...

http://www.petenetlive.com/KB/Article/0000923
0
 

Author Comment

by:Diego B
ID: 41747798
Thank you, Craig. Now if I use this GPO setting will the user be able to delete the profile or will it lock it down?
0
 
LVL 47

Expert Comment

by:Craig Beck
ID: 41765888
Depending on how you configure the GPO you can choose how much control you want the user to have. You can lock it down if you choose.
0
 
LVL 47

Expert Comment

by:Craig Beck
ID: 41792433
Best answer chosen
0

Featured Post

New feature and membership benefit!

New feature! Upgrade and increase expert visibility of your issues with Priority Questions.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to fix a SonicWall Gateway Anti-Virus firewall blocking automatic updates to apps like Windows, Adobe, Symantec, etc.
Last month Marc Laliberte, WatchGuard’s Senior Threat Analyst, contributed reviewed the three major email authentication anti-phishing technology standards: SPF, DKIM, and DMARC. Learn more in part 2 of the series originally posted in Cyber Defense …
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…

810 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question