kevin_lane Posted February 27, 2014 Posted February 27, 2014 Yea sounds like you have some weird setup as we have uac turned off and a bunch of policies set in place and they have mandatory profiles too we also have it set that every time a computer boots up and logs off delprof2 is ran and all profiles get deleted I dont see the point in giving them access to cmd ok maybe useful to you but if they know what they are doing and the students are clear enough they could do damage e.g first point of attack is to gather data about the network and that can be done with cmd by using a net view command will give you a list of computers on the work and I know these are just kids but should still be savvy and not leave holes open. also aslong as ur students are just domain users then not alot they can do. I would creating a test ou and practice on how to use gp and secure the systems And as for uac well nice feature but can over kill esp if you need a driver installing
MordyT Posted February 27, 2014 Posted February 27, 2014 We do it here, they can't browse anywhere that starts with '\\' or by IP Address (even if they can connect to it anyway, for example, they can't browse to \\printserver\ even though they can print to printers on \\printserver\) That why I said make a shortcut... Not browse with explorer. Right click, new shortcut...
free780 Posted February 27, 2014 Posted February 27, 2014 Uac is fine. If you want to update a driver use sccm or a script as system.
this_is_gav Posted February 27, 2014 Author Posted February 27, 2014 Sounds to me as though he's in the local 'Administrators' group on the laptop and you have UAC disabled. No, first thing I checked was the local admin group (obviously have staff as local admins, but students only on netbooks they took home years ago).
Garacesh Posted February 28, 2014 Posted February 28, 2014 (edited) That why I said make a shortcut... Not browse with explorer. Right click, new shortcut... Yeah, I saw that - but denying them the ability to browse to any '\\' location stops that working because the shortcut points to a network path. Or so I thought... Testing it just to be sure show me that isn't the case. Thank you for bringing that to my attention. I'll explore further into this and see what 'damage' I can do on my test account. Edit: If you navigate to the command prompt it declares it has been disabled by the administrator. So that's good. Edited February 28, 2014 by Garacesh
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now