RE: Restricted groups, where have you been....

2009-04-28 Thread Ziots, Edward
] Sent: Friday, April 24, 2009 4:43 AM To: NT System Admin Issues Subject: RE: Restricted groups, where have you been Yes, it will go on and on :-) That's the point - you can't really stop administrators from doing whatever they want on their own machines. You need something that&#

RE: Restricted groups, where have you been....

2009-04-24 Thread Free, Bob
.@nwea.org] Sent: Friday, April 24, 2009 7:02 AM To: NT System Admin Issues Subject: RE: Restricted groups, where have you been You guys realize in James' case you STILL need to have a clue what you need to do. Russinovich is not exactly a household name to non computer dorks, and

Re: Restricted groups, where have you been....

2009-04-24 Thread James Rankin
I've had a copy of that downloaded for a while now and have been meaning to give it a go...old (process monitor trawling) habits appear to die hard :-) 2009/4/24 Ben Scott > On Fri, Apr 24, 2009 at 4:41 AM, James Rankin > wrote: > > The question which I am asking, when I get a spare minute, is

Re: Restricted groups, where have you been....

2009-04-24 Thread Ben Scott
On Fri, Apr 24, 2009 at 4:41 AM, James Rankin wrote: > The question which I am asking, when I get a spare minute, is why the > scanning software in use needs admin privs anyway. A bit of process > monitor should hopefully provide the answer ... Use LUA BugLight instead. It does the same thing

Re: Restricted groups, where have you been....

2009-04-24 Thread James Rankin
April 23, 2009 8:18 PM > *To:* NT System Admin Issues > *Subject:* RE: Restricted groups, where have you been > > > > > > But in James' case, I can just bring my own copy of cacls.exe (or have a > scheduled job to make a copy of the existing one) and unless SeT

RE: Restricted groups, where have you been....

2009-04-24 Thread Kennedy, Jim
line. Not that our users are local admins. From: Ken Schaefer [mailto:k...@adopenstatic.com] Sent: Thursday, April 23, 2009 8:18 PM To: NT System Admin Issues Subject: RE: Restricted groups, where have you been But in James' case, I can just bring my own copy of cacls.exe (or h

RE: Restricted groups, where have you been....

2009-04-24 Thread David Lum
nplace there. Cheers Ken From: Free, Bob [r...@pge.com] Sent: Friday, 24 April 2009 2:18 AM To: NT System Admin Issues Subject: RE: Restricted groups, where have you been Before Russinovich blogged it you at least had to have a bit of a clue about GPO's to

RE: Restricted groups, where have you been....

2009-04-24 Thread Ken Schaefer
vich did a blog post on how admins can stop GPOs applying to their machines. Cheer Ken From: James Rankin [mailto:kz2...@googlemail.com] Sent: Friday, 24 April 2009 6:41 PM To: NT System Admin Issues Subject: Re: Restricted groups, where have you been I suppose this could go on and on :-)

Re: Restricted groups, where have you been....

2009-04-24 Thread James Rankin
:22 PM > > *To:* NT System Admin Issues > *Subject:* Re: Restricted groups, where have you been > > > > good point. SeTakeOwnershipPrivilege is now about to be removed. > > You probably are right, it would have been easier to configure at the > perimeter...but that is ma

RE: Restricted groups, where have you been....

2009-04-24 Thread Ken Schaefer
evice that's inplace there. Cheers Ken From: Free, Bob [r...@pge.com<mailto:r...@pge.com>] Sent: Friday, 24 April 2009 2:18 AM To: NT System Admin Issues Subject: RE: Restricted groups, where have you been Before Russinovich blogged it you at least had to

Re: Restricted groups, where have you been....

2009-04-24 Thread James Rankin
ever device that's inplace there. > > Cheers > Ken > > -- > *From:* Free, Bob [r...@pge.com] > *Sent:* Friday, 24 April 2009 2:18 AM > *To:* NT System Admin Issues > *Subject:* RE: Restricted groups, where have you been > > Before Russinovich blogged it

Re: Restricted groups, where have you been....

2009-04-24 Thread James Rankin
; > > > 2009/4/23 Ken Schaefer > >> > >> If they are administrators, they can defeat GPOs given sufficient > >> knowledge... > >> > >> Cheers > >> Ken > >> > >> ____________ > >> From: James

RE: Restricted groups, where have you been....

2009-04-23 Thread Ken Schaefer
_ From: Free, Bob [r...@pge.com] Sent: Friday, 24 April 2009 2:18 AM To: NT System Admin Issues Subject: RE: Restricted groups, where have you been Before Russinovich blogged it you at least had to have a bit of a clue about GPO’s to defeat them, now it is trivial…relatively From: Ke

Re: Restricted groups, where have you been....

2009-04-23 Thread Kurt Buff
>> Ken >> >> >> From: James Rankin [kz2...@googlemail.com] >> Sent: Thursday, 23 April 2009 5:12 PM >> To: NT System Admin Issues >> Subject: Re: Restricted groups, where have you been >> >> For those who can

RE: Restricted groups, where have you been....

2009-04-23 Thread Free, Bob
Before Russinovich blogged it you at least had to have a bit of a clue about GPO's to defeat them, now it is trivial...relatively From: Ken Schaefer [mailto:k...@adopenstatic.com] Sent: Thursday, April 23, 2009 12:26 AM To: NT System Admin Issues Subject: RE: Restricted groups, where hav

Re: Restricted groups, where have you been....

2009-04-23 Thread James Rankin
* NT System Admin Issues > *Subject:* Re: Restricted groups, where have you been > > For those who can remember the NT4 days, GPOs as a whole are an awesome > admin tool. When I managed an NT4 network with 10,000 users I actually had > batch scripts running overnight that reset the us

RE: Restricted groups, where have you been....

2009-04-23 Thread Ken Schaefer
If they are administrators, they can defeat GPOs given sufficient knowledge... Cheers Ken From: James Rankin [kz2...@googlemail.com] Sent: Thursday, 23 April 2009 5:12 PM To: NT System Admin Issues Subject: Re: Restricted groups, where have you been For

Re: Restricted groups, where have you been....

2009-04-23 Thread James Rankin
For those who can remember the NT4 days, GPOs as a whole are an awesome admin tool. When I managed an NT4 network with 10,000 users I actually had batch scripts running overnight that reset the user rights on all DCs and members servers, checked the local group memberships and altered them back to

RE: Restricted groups, where have you been....

2009-04-22 Thread Don Guyer
Amen, brother! When I first started here last year we had to do a major cleanup of Admin-related groups on our domain and still have to cleanup some local workstation groups that are controlled via GPOs. We just recently spun a portion of our users off into their own domain and we used Rest