Jump to content

Recommended Posts

Posted (edited)

Playing around with Microsoft Security Compliance Manager and trying to make a policy that fits microsofts recommended security settings, whether i really need to do this or not i don't know but i see a lot of things in the policy that, to my mind, are good practice to have forced on (or off).

 

I'm testing the policy and it seems to work perfectly with the exception of one problem....on the machine i'm testing, if i remote desktop to anything then keyboard input doesn't work at all. I can RDP from a machine without that policy and RDP works fine. Also the policy isn't deployed to the machine being RDP'd too.

 

I've attached a PDF with the export of the policy, can anyone identify anything that might be the cause? I'm racking my brains over this.

Windows 7 Security Compliance.pdf

Edited by mrbios
Posted

No idea if it counts as "remote" or "local" in terms of the GPO but you've got a fair few registry keys missing for RDP in regards to: "Network access: Remotely accessible registry paths and sub-paths"

 

e.g. Keyboard layout in RDP etc, might cause it to have a tiff?

 

Steve

Posted (edited)
No idea if it counts as "remote" or "local" in terms of the GPO but you've got a fair few registry keys missing for RDP in regards to: "Network access: Remotely accessible registry paths and sub-paths"

 

e.g. Keyboard layout in RDP etc, might cause it to have a tiff?

 

Steve

 

Strange thing is there's no others defined in the "Windows default" column, i don't think the microsoft recommended actually removes or adds anything, it just defines the policy.

 

There's a couple of settings that I'm unsure of, so I'm going through and googling a few to see what they do. I may do a copy of this policy and just trial and error setting the reverse settings on various things until i find what fixes it.

 

EDIT: I guess the other thing with the remote registry paths is that the policy isn't defined on the endpoint I'm connecting too, so i guess that rules that out?

 

EDIT2: Ignore this thread, i've fixed it, unrelated to the policy. A change occurred, or rather was removed, when i swapped the policies over. I'm an idiot, move along.

Edited by mrbios

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...