Skip to main content

When you remove the Run command from the start menu in a GPO, does it also remove it from the task manager?

Years back during the NT4/Win95 days, you were able to remove the users ability to run programs using the Windows NT4 system policies. The problem was that there were multiple ways to execute a program that the system policies did not address. Flash forward to Windows Sever 2008. By setting the Group Policy setting of User Configuration\Administrative Templates\Start Menu and Taskbar\

Remove Run menu from Start Menu to Enable, you will do the following.

· The Run command is removed from the Start menu.

· The New Task (Run) comm.

· and is removed from Task Manager.

· The user will be blocked from entering the following into the Internet

· Explorer Address Bar:

o A UNC path: \\\

o Accessing local drives: e.g., C:

o Accessing local folders: e.g., \temp>

David discovered that you can still get to the CMD window with this procedure:

· [Window Key] E will open Windows Explorer.

· Browse to C:\Windows\System32

· Launch CMD.exe.

To help curve any “work arounds”, set the following group policy objects in the appropriet place for your organization:

· User Config \ Admin Templates\ System\ Prevent access to the command prompt

· User Config \ Admin Templates\ System\ Ctrl+Alt+Del Options! Remove Task Manager

That prevents CMD.EXE but Command.com worked. OK, now we must set a software restriction policy to prevent Command.com for executing, no matter where the user moves it. For that, we will use the Hash software restriction policy:

In your Group Policy:

· Copy COMMAND.COM to your server at c:\Windows\System32.

· Computer Configuration à Policies à Windows Settings

· Right click Software Restriction Policy and click New Software Restriction Policies.

· Right click Additional Rules à New Hash Rule.

· Click Browse to C:\Windows\System32\Command.com

· Click OK

· To allow administrators to still be able to use the software that you have restricted:

o IN the Software Restriction GPO.

o Double click Enforcement

o Select All users except local administrators.

Since we used a Hash rule, moving or even renaming the file will not allow it to run.

Comments

Popular posts from this blog

Adding a Comment to a GPO with PowerShell

As I'm writing this article, I'm also writing a customization for a PowerShell course I'm teaching next week in Phoenix.  This customization deals with Group Policy and PowerShell.  For those of you who attend my classes may already know this, but I sit their and try to ask the questions to myself that others may ask as I present the material.  I finished up my customization a few hours ago and then I realized that I did not add in how to put a comment on a GPO.  This is a feature that many Group Policy Administrators may not be aware of. This past summer I attended a presentation at TechEd on Group Policy.  One organization in the crowd had over 5,000 Group Policies.  In an environment like that, the comment section can be priceless.  I always like to write in the comment section why I created the policy so I know its purpose next week after I've completed 50 other tasks and can't remember what I did 5 minutes ago. In the Group Policy module for PowerShell V3, th

Return duplicate values from a collection with PowerShell

If you have a collection of objects and you want to remove any duplicate items, it is fairly simple. # Create a collection with duplicate values $Set1 = 1 , 1 , 2 , 2 , 3 , 4 , 5 , 6 , 7 , 1 , 2   # Remove the duplicate values. $Set1 | Select-Object -Unique 1 2 3 4 5 6 7 What if you want only the duplicate values and nothing else? # Create a collection with duplicate values $Set1 = 1 , 1 , 2 , 2 , 3 , 4 , 5 , 6 , 7 , 1 , 2   #Create a second collection with duplicate values removed. $Set2 = $Set1 | Select-Object -Unique   # Return only the duplicate values. ( Compare-Object -ReferenceObject $Set2 -DifferenceObject $Set1 ) . InputObject | Select-Object – Unique 1 2 This works with objects as well as numbers.  The first command creates a collection with 2 duplicates of both 1 and 2.   The second command creates another collection with the duplicates filtered out.  The Compare-Object cmdlet will first find items that are diffe

How to list all the AD LDS instances on a server

AD LDS allows you to provide directory services to applications that are free of the confines of Active Directory.  To list all the AD LDS instances on a server, follow this procedure: Log into the server in question Open a command prompt. Type dsdbutil and press Enter Type List Instances and press Enter . You will receive a list of the instance name, both the LDAP and SSL port numbers, the location of the database, and its status.