Jump to content

Recommended Posts

Posted

For years we've had laptops that are joined to the domain but also have a completely seperate local account login (i.e for home or external use)

 

To keep this secure we ran gpedit.msc on the machine, and then denied Read permissions to the \Windows\System32\Group Policy folder for Administrators, so that only non admins would be able to read and apply this.

 

Obviously when on the domain the users got standard GPO's, and the local copies were effectively a duplicate for local users and it worked very well.

 

However somethign must have changed - now the fact that the local Group Policy folder is there makes it do something very odd to domain logins.

 

For example, standard domain user here can't get the Run dialogue, this was also in the local GPO. However now when a domain users logs into one of these laptops they get the Run dialogue! So a double negative becomes a positive if you see what I mean!

 

The local user option has worked so well I'd like to keep it, but something is wrong now, and it does the same in Windows 10 as well. Anyone got any experience doing it like this?

Posted
Never found out why this started happening, but denying access to the GroupPolicy folder for all users except the local account sorted this out!
Posted
That sounds really janky but also why local accounts? Domain accounts work just fine at home

 

It's a mixture of things, and some legacy things. People got so used to the dual logins it was difficult to break out of.

 

Plus there are issues with domain accounts used offline, such as redirected desktops, and allowing certain things to home users but not to domain users when online such as adding printers or connecting to home wifi, so the offline login worked very well!

Posted
It's a mixture of things, and some legacy things. People got so used to the dual logins it was difficult to break out of.

 

Plus there are issues with domain accounts used offline, such as redirected desktops, and allowing certain things to home users but not to domain users when online such as adding printers or connecting to home wifi, so the offline login worked very well!

 

 

I'd suggest taking another look at it when you next do a roll out or something, all of these are solvable with group policies etc :) Once it's setup your administration will be tons easier!

Posted
Well,the deny for everyone but the local account works well. I know it's not the most elegant solution but it works so well, staff login as normal on the network, but at home or offsite login with an offline account that has a lighter set of policies so they can change wifi/printers etc. They can store files on the locally encrypted drive and copy them to the network when back onsite, job done and dead easy to use.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...