Jump to content

Recommended Posts

Posted (edited)

I can't believe they rolled out an OS which allows you to block browsing UNC paths or drive letters, but their crappy cortana Type to Search overrides everything, allowing students to browse the mapped drives, any network share they like! Its a mess - it doesn't even follow its own policy settings.

 

And being W10, if you kill cortana from running, the start menu doesn't work at all. Genius.

 

How are you guys dealing with this in your W10 setups?

Edited by Sheridan
  • Thanks 3
Posted
I can't believe they rolled out an OS which allows you to block browsing UNC paths or drive letters, but their crappy cortana Type to Search overrides everything, allowing students to browse the mapped drives, any network share they like! Its a mess - it doesn't even follow its own policy settings.

 

And being W10, if you kill cortana from running, the start menu doesn't work at all. Genius.

 

How are you guys dealing with this in your W10 setups?

 

You need to set your NTFS ACLs so students can't access those drives.

 

As for the start menu, we use the reborn Classic Start program. I know, I know, I should get with the program and give users the 'proper' new wonderful Start Menu.... but I know they'd all hate it, so this is my solution. I've had zero complaints, and it's super easy to manage.

Posted (edited)
I can't believe they rolled out an OS which allows you to block browsing UNC paths or drive letters, but their crappy cortana Type to Search overrides everything, allowing students to browse the mapped drives, any network share they like! Its a mess - it doesn't even follow its own policy settings.

 

And being W10, if you kill cortana from running, the start menu doesn't work at all. Genius.

 

How are you guys dealing with this in your W10 setups?

 

I hadn't found that hole yet. I knew you could get mstsc from the Start Menu thanks to its stupid searching, even though I've turned off all the tracking based and shell based searching and what have you, but I hadn't realised it let you go through the UNC paths. Staff folders are protected by NTFS permissions, thankfully, but the student folders are bloody open thanks to the permissions inheritances set up. Guess that's my job for this morning, then...

 

:mad::mad::mad:

 

ETA: it lets you open services! Just type services and there it is! Auhfughuhgugh

 

Any ideas on how to block that? I'm wondering if there's ever any reason a user would need mmc.exe and if I can just block that outright, tbh...

Edited by sonofsanta
Posted

No major issues here with Windows 10 - always image to the current release over the Summer but they're a few annoyances that are winding me up a little. Have it running on approx 600 machines here. Always believe in trying to have the latest and greatest running where we can (yes, I do test and re-test).

 

  • Start Menu - It's got better, but the person/people in MS who wrote the code for it should be singled out and public humiliated - why it just stops working for no reason and all manor of so called repairs just don't work - re-image is the only solution.
  • Start Menu Layout XML Files - Again, just WTF? Work for one, and then doesn't for another. Seems worse in the latest release. However, we do build Start Menu's dynamically at logon using Burconix dependant on User, Location, etc. But Windows 10 Apps just seem to sit on the start menu regardless of what you want / don't want.
  • Windows 10 Apps - Oh God please, just go away. Still haven't really solved how to get these working properly.
  • Edge - Gave up on that - now disable it via AppLocker - which is a pain as it sits on the Computer Config GPO but I know you can use User Groups. But, would preferred it sat on User Config GPOs so it can be controlled in a more granular fashion like SRPs which are being deprecated.
  • No decent control of the file explorer ribbon interface via GPO - having to resort to hacking the Registry to disable certain elements (hidden items) for students. I know someone on here has created a custom admx template but not had a chance to look at that just yet.
  • Broken WSUS updating - eventually fixed in an update and now does seem to work well in current release.

 

Office has not be too much of an issue for us - now that I've sussed out Device Based Activation our imaging process (using MDT) seems to run like a breeze know and installs without any major issues. Worth noting that DBA will only allow a certain amount of activations until it starts to fail against a specific device - seems that deleting the '_DEVICE_*' entry in Office365 will allow it to work again. (Noticed this on doing when testing and re-testing the whole re-build process).

 

There should be more control for Admins with GPOs in Windows 10 - just seems to be so much know that is out of our control or having to fudge things to get it to behave how we as Network Admins need things to behave in a school environment.

 

Login times for us are around the 20 sec to 40 sec mark on a fresh profile. We used to re-direct things like the AppData for Students, but gave up on that and only have it working for Staff and things seem to tick along nicely. Having SSD in all our machines now makes a massive difference.

 

As already said, keeps us in a job.

 

Pete

Posted (edited)

Oh yes, I've got NTFS permissions and share permissions and Access Based Enumeration enabled, but it shows that W10 isn't a coherent OS - MS bludgeon'd cortana into the OS so it cannot be removed. If you disable it (by renaming the folder in SystemApps) then it works - by killing the start menu completely.

 

It ironic that if you type \\server\share into file explorer its blocked, but type that in the Start Menu - it opens...in file explorer.

 

My concern is we have licensed network software on some of these shares - nothing to stop them copying that off to their google drive now is there? Marking them as hidden doesn't work as they can unhide them (and you can't remove that either!)

 

Looks like LTSB2019 is our next rollout, either that or we seriously look down the line of ditching windows for good. We used to use CSM and it worked brilliantly - so the new version might be another option

Edited by Sheridan
Posted
I hadn't found that hole yet. I knew you could get mstsc from the Start Menu thanks to its stupid searching, even though I've turned off all the tracking based and shell based searching and what have you, but I hadn't realised it let you go through the UNC paths. Staff folders are protected by NTFS permissions, thankfully, but the student folders are bloody open thanks to the permissions inheritances set up. Guess that's my job for this morning, then...

 

:mad::mad::mad:

 

There'll be slicker and more up to date ways of achieving it than this, but I've always used Wisesoft NTFSFix to set up permissions on user areas in bulk (it's getting old and needs .NET 1, so am open for suggestions of an up to date alternative). You'll need something like that (or a script) if you remove students from ACLs higher up and subsequently need to repair the ACL for each user area. While you're at it, don't give students 'Full Control' on their own files, just Modify.

Posted
MS bludgeon'd cortana into the OS so it cannot be removed. If you disable it (by renaming the folder in SystemApps) then it works - by killing the start menu completely.

 

If you block the Cortana executable using AppLocker or via an SRP, the the Start menu still works. The first time it's opened after login it is non-functioning, but subsequent times it works as normal (just without the search functionality).

Posted
If you block the Cortana executable using AppLocker or via an SRP, the the Start menu still works. The first time it's opened after login it is non-functioning, but subsequent times it works as normal (just without the search functionality).

 

When I disabled SearchUI.exe, or renamed the cortana systemapps folder, it rendered the Start Menu completely unusable (greyed out icons)? How did you go about this?

Posted
For us, it's greyed out only the first time the Start menu is opened after login. After that, it works. We've not renamed the Cortana folder or exe though, just blocked it with an SRP rule. Under the hood the system is probably whinging the first time, but then doesn't bother after that. We tried scripting a couple of Ctrl+Esc keystrokes in a login script, so that by the time any actual user interaction occurs the Start menu is working, but it often didn't work because the timing didn't always fall right each time.
Posted
There'll be slicker and more up to date ways of achieving it than this, but I've always used Wisesoft NTFSFix to set up permissions on user areas in bulk (it's getting old and needs .NET 1, so am open for suggestions of an up to date alternative). You'll need something like that (or a script) if you remove students from ACLs higher up and subsequently need to repair the ACL for each user area. While you're at it, don't give students 'Full Control' on their own files, just Modify.

 

+1 for NTFSFix, I used to use that all the time for home drives when I did server migrations.

 

I got round the Dot Net 1 nonsense by tweaking the source MSI as I recall.

Posted
There'll be slicker and more up to date ways of achieving it than this, but I've always used Wisesoft NTFSFix to set up permissions on user areas in bulk (it's getting old and needs .NET 1, so am open for suggestions of an up to date alternative). You'll need something like that (or a script) if you remove students from ACLs higher up and subsequently need to repair the ACL for each user area. While you're at it, don't give students 'Full Control' on their own files, just Modify.
Same here. .NET 1.1 only needed for the installer, not the program itself - so if you extract the program it'll work fine on modern OSs. That's how I bulk sort our user area permissions - we have to do some weird and wonderful things to ensure the Macs map drives properly so students can view the root home directory share, have Modify permissions on their home folder (no Full Control) with Inheritance turned off so that other users can't view their files. Works well enough.
Posted
ETA: it lets you open services! Just type services and there it is! Auhfughuhgugh

Unless the user is a local admin, this doesn't matter - only admins can do anything to services. I agree that it should be restrict-able, but it's not a security hole.

  • Thanks 1
Posted
I hadn't found that hole yet. I knew you could get mstsc from the Start Menu thanks to its stupid searching, even though I've turned off all the tracking based and shell based searching and what have you, but I hadn't realised it let you go through the UNC paths. Staff folders are protected by NTFS permissions, thankfully, but the student folders are bloody open thanks to the permissions inheritances set up. Guess that's my job for this morning, then...

 

:mad::mad::mad:

 

ETA: it lets you open services! Just type services and there it is! Auhfughuhgugh

 

Any ideas on how to block that? I'm wondering if there's ever any reason a user would need mmc.exe and if I can just block that outright, tbh...

There's no reason an end use should ever be in MMC. We've got MMC blocked for staff and students through Admin Templates | Windows Components | Microsoft Management Console, and had no repercussions.

 

Our users can see Service.msc through idiot Cortana, but if they click to open it, nothing happens.

Posted (edited)
Unless the user is a local admin, this doesn't matter - only admins can do anything to services. I agree that it should be restrict-able, but it's not a security hole.

 

That looks to be mostly true (although is an improvement on my initial fear!)--strangely I can start certain services (e.g. Data Sharing Service, Office Source Engine, quite a few others but not all) and then can't do anything else to them. Which is probably not a problem? But is still something I shouldn't have to worry about! "The Start Menu should only show things actually in the Start Menu" doesn't seem like an unreasonable request, but oh no, got to make sure that Mixed Reality Viewer is available to everyone on our 7 year old i3 desktops...

 

There's no reason an end use should ever be in MMC. We've got MMC blocked for staff and students through Admin Templates | Windows Components | Microsoft Management Console, and had no repercussions.

 

Our users can see Service.msc through idiot Cortana, but if they click to open it, nothing happens.

 

Some of our staff use an MMC to enable Controlled Assessment accounts, with appropriate limited permissions granted on the relevant portion of the AD tree. That's the only thing that's come to mind for me so far, and so I can probably block for students and be comfortable with that compromise.

Edited by sonofsanta
Posted (edited)
That looks to be mostly true (although is an improvement on my initial fear!)--strangely I can start certain services (e.g. Data Sharing Service, Office Source Engine, quite a few others but not all) and then can't do anything else to them. Which is probably not a problem? But is still something I shouldn't have to worry about! "The Start Menu should only show things actually in the Start Menu" doesn't seem like an unreasonable request, but oh no, got to make sure that Mixed Reality Viewer is available to everyone on our 7 year old i3 desktops...

 

Yes, you can set ACLs on services to grant rights to do certain things to certain groups (exactly the same as with files and folders or registry keys), and some Office services are started on-demand by apps running as standard users, hence why you can start them. But good luck messing with, e.g., RPCSS or Netman as a standard user! Same goes for things like Impero or LanSchool, which will be running elevated.

 

Our users can see Service.msc through idiot Cortana, but if they click to open it, nothing happens.

 

You know you can just turn Cortana off with GPO?

 

Computer Configuration > Administrative Templates > Windows Components > Search > Allow Cortana

Edited by FishCustard
  • Thanks 1
Posted
Some of our staff use an MMC to enable Controlled Assessment accounts, with appropriate limited permissions granted on the relevant portion of the AD tree. That's the only thing that's come to mind for me so far, and so I can probably block for students and be comfortable with that compromise.

 

Definitely block completely for students, if you look into the policy settings above further though, you can block / allow individual MMC snap-ins.

Posted
You know you can just turn Cortana off with GPO?

Computer Configuration > Administrative Templates > Windows Components > Search > Allow Cortana

 

Yes, and no. We've got Cortana disabled by policy, but on Enterprise it's a fundamental part of the Start Menu so it's never completely off.

Posted
IIRC the GPO option for disallowing Cortana doesn't disable the basic Start menu search functionality, only the Cortana 'digital assistant' stuff. The Start menu will still surface program names, etc. as the user types.
Posted
You know you can just turn Cortana off with GPO?

 

Computer Configuration > Administrative Templates > Windows Components > Search > Allow Cortana

 

That setting got disabled on my very first pass through the GPO settings in the earliest days of configuring this bl%dy thing :) we've turned it off and disabled it in every way we can possibly find, and yet still, if you watch a UE-V folder the first time a user logs on, the very first settings that get synchronised are for flipping Cortana!

 

I've turned off User / ADM / Start Menu and Taskbar / Do not use the search-based method when resolving shell shortcuts (and tracking-based method) too, but if you type in exact command (e.g. mstsc) it doesn't need to search, technically speaking, and so shows the program even though no shortcut to the program exists on the redirected Start Menu.

 

I've disabled access to all MMC snap ins apart from ADUC (which would require us to provide the MMC file anyway, and has security set on the tree) and Event Viewer, which may well be useful to us at times without presenting much of a risk. Cheers for the heads up on that one.

Posted (edited)

No great security risks I guess, as long as your permissions are in good shape, but Cortana does expose a whole world of items that the end user shouldn't even have view access too.

 

Windows 10 modern apps as a whole have been a nightmare in terms of group policy control. Where there are administrative controls, such as Applocker, they're always very clunky. And you know what? For me, these apps have added nothing. The only ones we use existed as perfectly serviceable and GP managed regular executable before.

 

With Windows 10 it's like you've got bluesky thinkers in one room developing the product, and some poor souls in the next room who then have to try and add some control on afterwards, and the two never talk.

Edited by elsiegee40
Language
  • Thanks 1
Posted

Indeed. You need to make sure that your systems are fundamentally secure: set up your shares according to the principle of least privilege, etc. After that, it's mainly just a case of your own preference* as to whether things like services.msc are surfaced by the UI. Merely obscuring them away from the Start menu isn't doing the job of securing them.

 

*Personally, I'd rather lock the UI up just to have a quiet life and avoid having to deconstruct reports from across the school of kids "doing things" on the computers, simply because a window with lists of computery looking words gets minimised when teacher approaches. I suspect @mavhc takes a more permissive approach than me on that, but it's a separate set of decision from security.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...