Jump to content

Recommended Posts

Posted

Hi Guys,

 

I'm moving to WDS/MDT from FOG so i'm very very green here.

 

I've managed to get wds to pxe my hyper-v Windows 10 vm, however with fog, if i selected anything on the menu it was password protected.

 

With PXE/WDS i seem to be able to snoop around and even press f8 on the menu and run diskpart.

 

Is there anyway i can protect the "F12" option.

 

Maybe i'm totally over looking something here. I've not even looked at mdt yet. I'm currently capturing my "FAT Image" that i used on FOG.

 

Thanks in advance

Posted
I think you would have to have a BIOS password so you cant get to the PXE option until the BIOS password is input.

 

This is just protects the clients from not being able to boot from nic.

 

I've unplugged a staff pc in a classroom and just connected my laptop. I can get to the PXE menus/image.

Posted

Setting a Bios password to restrict the network boot option on the device is the first option, as without that the device can't get into the PXE boot option.

 

We only have our MDT Litetouch image enabled in WDS, which starts the workstation off on a full rebuild without any user intervention.

When most of our devices just used normal BIOS and not UEFI, we updated the bootloader for the WDS PXE to be a linux one so that we could have a menu structure and for it to require a password to boot into the main PXE loader, but these days we don't bother.

Posted
For those few computers that don't have the Network Boot option secured by password in the Bios/UEFI, then yes they could rebuild the workstation if they really tried.. and it would just put back on the same OS and software as defined in our MDT and SCCM settings.
Posted
This is just protects the clients from not being able to boot from nic.

 

I've unplugged a staff pc in a classroom and just connected my laptop. I can get to the PXE menus/image.

 

OK - but if you set the BIOS settings correctly on a student/staff machine, they can't do that... they don't tend to carry around their own machines.

 

With MDT, you can get it to require a password on start by removing the settings in bootstrap.ini, it'll then prompt for login details to access where the MDT content is stored. See here: https://social.technet.microsoft.com/Forums/en-US/09911b92-86d4-4217-9c6e-8d73437bc668/how-to-require-an-administrator-password-to-allow-mdt-deployment-to-start?forum=mdt

 

With SCCM, you can have it so your WinPE image requires a password before you can do anything.

 

If you are concerned about the fact that someone could in theory plug an unsecured laptop into your network and PXE boot, you're looking at this from the wrong viewpoint, that isn't a PXE boot/MDT issue, that's a network security issue and would be better off using VLANs (where PXE is restricted to certain ones) or port security, but that's usually a bit extra for a school network.

Posted
OK - but if you set the BIOS settings correctly on a student/staff machine, they can't do that... they don't tend to carry around their own machines.

 

With MDT, you can get it to require a password on start by removing the settings in bootstrap.ini, it'll then prompt for login details to access where the MDT content is stored. See here: https://social.technet.microsoft.com/Forums/en-US/09911b92-86d4-4217-9c6e-8d73437bc668/how-to-require-an-administrator-password-to-allow-mdt-deployment-to-start?forum=mdt

 

With SCCM, you can have it so your WinPE image requires a password before you can do anything.

 

If you are concerned about the fact that someone could in theory plug an unsecured laptop into your network and PXE boot, you're looking at this from the wrong viewpoint, that isn't a PXE boot/MDT issue, that's a network security issue and would be better off using VLANs (where PXE is restricted to certain ones) or port security, but that's usually a bit extra for a school network.

 

Thank for that link, like i say i'm Coming from FOG so totally new to WDS/MDT. Just used to being asked for a password if anything other than "boot from hard drive" was selected from the PXE menu.

 

Thanks again, i'll do some more reading

Posted
I leave PXE available, I have the bios to only pxe boot on a wol. even so if a pupil gets to the PXE menu and picks an image they need an admin password to actually install it. They could breakout using alt-f10 but that hasn't happened yet.
Posted

That's not the PXE menu, that's the next stage along, the windows PE menu in your boot.wim file

 

You can a) set WDS to only respond to known computers, b) set a bios password on some bios's, c) set a password on the share with the wim files in.

 

Best not to have pxe enabled by default, just turn it on when needed, or have it on a secure vlan, makes it simple to get local admin, same as booting from a usb.

 

https://www.riskinsight-wavestone.com/en/2020/01/taking-over-windows-workstations-pxe-laps/

 

https://docs.microsoft.com/en-us/mem/configmgr/osd/plan-design/security-and-privacy-for-operating-system-deployment

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...