Bob_the_Goon Posted April 14, 2016 Posted April 14, 2016 Hello, I am trying to apply a software restiction policy to a group of computers within an OU. The policy is applying however even domain administrators are being blocked and I can't figure out why. I've linked a GPO to an OU containing computers. I've gone to the Computer Configuration --> Windows Settings --> Security Settings --> Software Restriction Policies I've set the Security levels to "Disallowed". I've set "Enforcement" to "All Users except local administrators" as well as "All software files except libraries (such as DLLs) When I go to the computers and log in as a non-administrator I can't run executables. This is as expected as I haven't added in any exceptions yet. When I log in as a Domain Admin I still can't run any executables. I've checked that Domain Admins is a member of the Local Administrators group on the PC. I've even specifically added the domain admin into the local admin group but no luck. There are no other GPOs that are taking precedence over this GPO. I'm pulling my hair out with this one. Can anyone help? I'm sure that I'm just missing something obvious!!! Thanks in advance. Paul
Bob_the_Goon Posted April 14, 2016 Author Posted April 14, 2016 I forgot to mention that if I log in as the THE local administrator, executables will run.
Cache Posted April 14, 2016 Posted April 14, 2016 Try right clicking and Run As Administrator - it is probably User Access Control blocking it.
Davit2005 Posted April 15, 2016 Posted April 15, 2016 (edited) Hello, I am trying to apply a software restiction policy to a group of computers within an OU. The policy is applying however even domain administrators are being blocked and I can't figure out why. I've linked a GPO to an OU containing computers. I've gone to the Computer Configuration --> Windows Settings --> Security Settings --> Software Restriction Policies I've set the Security levels to "Disallowed". I've set "Enforcement" to "All Users except local administrators" as well as "All software files except libraries (such as DLLs) When I go to the computers and log in as a non-administrator I can't run executables. This is as expected as I haven't added in any exceptions yet. When I log in as a Domain Admin I still can't run any executables. I've checked that Domain Admins is a member of the Local Administrators group on the PC. I've even specifically added the domain admin into the local admin group but no luck. There are no other GPOs that are taking precedence over this GPO. I'm pulling my hair out with this one. Can anyone help? I'm sure that I'm just missing something obvious!!! Thanks in advance. Paul Group Policies will apply whether you are Domain Admin or not depending on if you have any securiy filtering in place. You could set a security so as to filter out Domain Admins?? Edited April 15, 2016 by Davit2005
Bob_the_Goon Posted April 15, 2016 Author Posted April 15, 2016 Thank you for all of the replies so far! In terms of AppLocker - yes I would like to take a look at this however I just wanted to setup some quick and dirty SRP's to get us going whilst I plan AppLocker. I'm more familiar with SRP's. If I right click the file I can indeed run it using "Run as administrator". I was thinking of setting the SRP's as a user-based GPO however, all of the documentation on the web that I've read always seem to tell you to make it a computer configuration rather than user. Is there a good reason for this? Does anyone on here apply their SRP's via the the user context of a GPO?
jertsy Posted April 15, 2016 Posted April 15, 2016 Thank you for all of the replies so far! In terms of AppLocker - yes I would like to take a look at this however I just wanted to setup some quick and dirty SRP's to get us going whilst I plan AppLocker. I'm more familiar with SRP's. If I right click the file I can indeed run it using "Run as administrator". I was thinking of setting the SRP's as a user-based GPO however, all of the documentation on the web that I've read always seem to tell you to make it a computer configuration rather than user. Is there a good reason for this? Does anyone on here apply their SRP's via the the user context of a GPO? Currently all my SRP are set on the user portion of the GPO. I am just in the process of playing about with applocker and I will use that in the future.
Cache Posted April 15, 2016 Posted April 15, 2016 Thank you for all of the replies so far! In terms of AppLocker - yes I would like to take a look at this however I just wanted to setup some quick and dirty SRP's to get us going whilst I plan AppLocker. I'm more familiar with SRP's. If I right click the file I can indeed run it using "Run as administrator". I was thinking of setting the SRP's as a user-based GPO however, all of the documentation on the web that I've read always seem to tell you to make it a computer configuration rather than user. Is there a good reason for this? Does anyone on here apply their SRP's via the the user context of a GPO? Try adding your Domain Admin to the Administrator group as well as the Domain Admins group. I've a feeling that User Access Control means that even though you are logged on as a Domain Admin and Domain Admins is a member of the local Administrators group, unless you right click and tell it to run as an administrator the SRP will still apply. If you add the user directly, from memory, then the SRP will be exempt because the user is specifically a member of the group. I might be wrong, but I moved on to AppLocker when I moved everythign over to Windows 7 and it is far simpler and more powerful. For the most part the same SRP policies applied to Staff and Students, the greater fleixibilty with Applocker means that I can still just push out one policy but enable and disable permission to run apps or scripts on a usergroup basis.
Bob_the_Goon Posted April 16, 2016 Author Posted April 16, 2016 I set my SRPs as user-based GPOs. Worked like a charm. I had already tried what Cache had suggested but it didn't work for me. Now that I've got the SRPs in place, I'll take a look at AppLocker. Thank you guys.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now