Jump to content

Recommended Posts

Posted

Until today I was under the impression that our students' account were pretty well locked down. Turns out they've figured out how to install a VPN app and were successfully bypassing our filtering.

 

They'd figured out that if they download a Microsoft store apps installer file directly they could install that. I have applocker in place, it however, wasn't restricting the running off store apps (it is now) probably as I had the store blocked

 

I've got the below in place:

 

 

  • File server resource manager blocking all installation files (exe's etc), only storage accessible to students being on our FS
  • App locker configured to only allow apps and scripts to be started from paths which are read only to students.
  • Web filter configured to block software downloads
  • Microsoft store disabled
  • Only packaged apps signed by Microsoft are able to run
  • Outbound only 80 and 443 accessible
  • LAPS enabled to prevent access to local admin account
  • Only admin accounts in the school are with myself or the break glass account in the safe

 

Is there anything I'm missing?

 

Any advise is greatly appreciated

Posted
Disable store source for winget, configure all browsers to lock down what extensions are installed, security policy to block writing to c:\, check for mock folders which can bypass app locker, increase your list of blocked extensions in applocker, don't allow any ports outgoing, only allow connections to proxy, monitor disk usage, out of space computers don't install updates, allowing future known exploits to be used. Update all apps each week, set policy that WU must be installed and rebooted in x days, same with Office
  • Thanks 1
Posted
Disable store source for winget, configure all browsers to lock down what extensions are installed, security policy to block writing to c:\, check for mock folders which can bypass app locker, increase your list of blocked extensions in applocker, don't allow any ports outgoing, only allow connections to proxy, monitor disk usage, out of space computers don't install updates, allowing future known exploits to be used. Update all apps each week, set policy that WU must be installed and rebooted in x days, same with Office

 

Already have most of that in place luckily

Posted

If you have a smoothwall you can disable connecting any connection if its just the IP without a domain name record (common for VPNs).

 

This should in theory block all VPN's but may have some more adverse effects on other things.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...