Jump to content

Software Restriction Policy - Administrators are blocked too!!


Recommended Posts

Posted

Hello,

 

I am trying to apply a software restiction policy to a group of computers within an OU. The policy is applying however even domain administrators are being blocked and I can't figure out why.

 

I've linked a GPO to an OU containing computers.

I've gone to the Computer Configuration --> Windows Settings --> Security Settings --> Software Restriction Policies

I've set the Security levels to "Disallowed".

I've set "Enforcement" to "All Users except local administrators" as well as "All software files except libraries (such as DLLs)

 

When I go to the computers and log in as a non-administrator I can't run executables. This is as expected as I haven't added in any exceptions yet.

 

When I log in as a Domain Admin I still can't run any executables. I've checked that Domain Admins is a member of the Local Administrators group on the PC. I've even specifically added the domain admin into the local admin group but no luck. There are no other GPOs that are taking precedence over this GPO.

 

I'm pulling my hair out with this one. Can anyone help? I'm sure that I'm just missing something obvious!!!

 

Thanks in advance.

 

Paul

Posted (edited)
Hello,

 

I am trying to apply a software restiction policy to a group of computers within an OU. The policy is applying however even domain administrators are being blocked and I can't figure out why.

 

I've linked a GPO to an OU containing computers.

I've gone to the Computer Configuration --> Windows Settings --> Security Settings --> Software Restriction Policies

I've set the Security levels to "Disallowed".

I've set "Enforcement" to "All Users except local administrators" as well as "All software files except libraries (such as DLLs)

 

When I go to the computers and log in as a non-administrator I can't run executables. This is as expected as I haven't added in any exceptions yet.

 

When I log in as a Domain Admin I still can't run any executables. I've checked that Domain Admins is a member of the Local Administrators group on the PC. I've even specifically added the domain admin into the local admin group but no luck. There are no other GPOs that are taking precedence over this GPO.

 

I'm pulling my hair out with this one. Can anyone help? I'm sure that I'm just missing something obvious!!!

 

Thanks in advance.

 

Paul

 

Group Policies will apply whether you are Domain Admin or not depending on if you have any securiy filtering in place.

 

You could set a security so as to filter out Domain Admins??

Edited by Davit2005
Posted

Thank you for all of the replies so far!

 

In terms of AppLocker - yes I would like to take a look at this however I just wanted to setup some quick and dirty SRP's to get us going whilst I plan AppLocker. I'm more familiar with SRP's.

 

If I right click the file I can indeed run it using "Run as administrator".

 

I was thinking of setting the SRP's as a user-based GPO however, all of the documentation on the web that I've read always seem to tell you to make it a computer configuration rather than user. Is there a good reason for this? Does anyone on here apply their SRP's via the the user context of a GPO?

Posted
Thank you for all of the replies so far!

 

In terms of AppLocker - yes I would like to take a look at this however I just wanted to setup some quick and dirty SRP's to get us going whilst I plan AppLocker. I'm more familiar with SRP's.

 

If I right click the file I can indeed run it using "Run as administrator".

 

I was thinking of setting the SRP's as a user-based GPO however, all of the documentation on the web that I've read always seem to tell you to make it a computer configuration rather than user. Is there a good reason for this? Does anyone on here apply their SRP's via the the user context of a GPO?

 

Currently all my SRP are set on the user portion of the GPO. I am just in the process of playing about with applocker and I will use that in the future.

Posted
Thank you for all of the replies so far!

 

In terms of AppLocker - yes I would like to take a look at this however I just wanted to setup some quick and dirty SRP's to get us going whilst I plan AppLocker. I'm more familiar with SRP's.

 

If I right click the file I can indeed run it using "Run as administrator".

 

I was thinking of setting the SRP's as a user-based GPO however, all of the documentation on the web that I've read always seem to tell you to make it a computer configuration rather than user. Is there a good reason for this? Does anyone on here apply their SRP's via the the user context of a GPO?

 

Try adding your Domain Admin to the Administrator group as well as the Domain Admins group.

 

I've a feeling that User Access Control means that even though you are logged on as a Domain Admin and Domain Admins is a member of the local Administrators group, unless you right click and tell it to run as an administrator the SRP will still apply.

 

If you add the user directly, from memory, then the SRP will be exempt because the user is specifically a member of the group.

 

I might be wrong, but I moved on to AppLocker when I moved everythign over to Windows 7 and it is far simpler and more powerful. For the most part the same SRP policies applied to Staff and Students, the greater fleixibilty with Applocker means that I can still just push out one policy but enable and disable permission to run apps or scripts on a usergroup basis.

Posted

I set my SRPs as user-based GPOs. Worked like a charm.

 

I had already tried what Cache had suggested but it didn't work for me.

 

Now that I've got the SRPs in place, I'll take a look at AppLocker.

 

Thank you guys.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...