Jump to content

!! students have access to active directory, everything !!


Recommended Posts

Posted

It has been brought to my attention today, that students can get to pretty much all the server admin stuff.

 

They use the mmc.exe program, and then they are able to add snap-ins such as AD, DHCP, printers, pretty much everything.

 

Im not sure how long this has been going on as Ive not long taken over this network, but how can I stop them from doing this???

Posted
Don't use a software restriction policy, go to User Config -> Policies -> ADM templates -> Windows Components -> MMC and configure it all there.
  • Thanks 3
Posted
Don't use a software restriction policy, go to User Config -> Policies -> ADM templates -> Windows Components -> MMC and configure it all there.

Never noticed that before, that's much simpler. Thanks for the info.

Posted
Stop them from running ANY .exe's or you will have no network! :jaw:

 

Hmm, yes becuase if you stop all exes then you'll have a really useful network?!? What about basic things like winlogon.exe, explorer.exe, winword.exe calc.exe, paint.exe notepad.exe :crazy:

Posted

You'd be supprised what you can do with just domain user permissions. Users can, for example, edit certain fields on their own AD user, which is pretty annoying. However, when it comes to MMC stuff, they obviously don't have permissions to modify anything, they can, however, view almost anything, however, one question does present itself: Why do you have the AD management tools installed on the student computers in the first place?

 

Anyway, regardless of what MMC snapins you deny, they can still use VBScripts or powershell to access data on pretty much anything if they really wanted to.

Posted
It has been brought to my attention today, that students can get to pretty much all the server admin stuff.

 

Out of curiosity, Any reason they can even see the exe's to run?

 

Aren't all items like "run", control panel, etc etc be locked down in first place? So even if MMC is runnable, there's no way to it.

 

Just seems a bigger issue that it's accessible, than it's being run :p If that makes sense?

 

Steve

Posted
ok thats them locked out. Thanks heaps for that.

 

Is there anything else I should be thinking of about policies for the students a major as this?

 

Well for one, as mentioned above. Why can they even access it as it is? Seems like something's missing/adrift.

 

Steve

Posted
Out of curiosity, Any reason they can even see the exe's to run?

 

Aren't all items like "run", control panel, etc etc be locked down in first place? So even if MMC is runnable, there's no way to it.

 

Just seems a bigger issue that it's accessible, than it's being run :p If that makes sense?

 

Steve

 

all of the above are blcoked, but they still have access to the C: drive (which im trying to have blocked too... red tape...)

Posted
You'd be supprised what you can do with just domain user permissions. Users can, for example, edit certain fields on their own AD user, which is pretty annoying. However, when it comes to MMC stuff, they obviously don't have permissions to modify anything, they can, however, view almost anything, however, one question does present itself: Why do you have the AD management tools installed on the student computers in the first place?

 

Anyway, regardless of what MMC snapins you deny, they can still use VBScripts or powershell to access data on pretty much anything if they really wanted to.

 

These are just basic windows 7 enterprise installations. The AD pack hasnt been installed seperately.

Posted
Hmm, yes becuase if you stop all exes then you'll have a really useful network?!? What about basic things like winlogon.exe, explorer.exe, winword.exe calc.exe, paint.exe notepad.exe :crazy:

 

OK. from outside Program files I mean

Posted
You'd be supprised what you can do with just domain user permissions. Users can, for example, edit certain fields on their own AD user, which is pretty annoying. However, when it comes to MMC stuff, they obviously don't have permissions to modify anything, they can, however, view almost anything, however, one question does present itself: Why do you have the AD management tools installed on the student computers in the first place?

 

Anyway, regardless of what MMC snapins you deny, they can still use VBScripts or powershell to access data on pretty much anything if they really wanted to.

 

also, when i tested with a user account, they were able to modify AD, I changed the displayname of a teacher account..

Posted
all of the above are blcoked, but they still have access to the C: drive (which im trying to have blocked too... red tape...)

 

Block it, block it nowwww! :D

 

Steve

Posted
also, when i tested with a user account, they were able to modify AD, I changed the displayname of a teacher account..

 

Surely this is a permissions error?

Whats stopping anyone with an openLDAP client and valid domain credentials logging in and doing the same?

Posted
Whats stopping anyone with an openLDAP client and valid domain credentials logging in and doing the same?

 

Hopefully, software restriction policies to prevent the running and installation of foreign executables and software :)

Posted
Surely this is a permissions error?

Whats stopping anyone with an openLDAP client and valid domain credentials logging in and doing the same?

 

Unless it's being run as local admin. In a weird way.

 

But yeah without sounding rude, if they can access, C:\, run any exe, Full admin tools, and edit AD etc. Kind of says there's something majorly wrong with the restrictions in place. (If there are any?)

 

Might be worth checking all the restrictions to see what's missing, as I know you said you took over recently.

 

Better iron them out in advance, than catching up :D

 

Steve

Posted
also, when i tested with a user account, they were able to modify AD, I changed the displayname of a teacher account..

 

Check what user groups they are in.... Are you sure they aren't domain admins? (yes i've seen schools like that)....

 

Personally I would take away every group apart from the default users group and start rebuilding.

Posted
Hopefully, software restriction policies to prevent the running and installation of foreign executables and software :)

 

Unless it's being run as local admin. In a weird way.

 

But yeah without sounding rude, if they can access, C:\, run any exe, Full admin tools, and edit AD etc. Kind of says there's something majorly wrong with the restrictions in place. (If there are any?)

 

Might be worth checking all the restrictions to see what's missing, as I know you said you took over recently.

 

Better iron them out in advance, than catching up :D

 

Steve

 

You seem to be implying that it wouldn't be safe to run user owned equipment (iphones,blackberrys,linuxes etc) in an Active Directory environment incase they run a 3rd pary LDAP tool?

An openLDAP server (ie a linux Domain server) doesn't suffer from this problem. Is windows insecure? should I ditch AD? or is it a permission error on the AD like I stated ?

Posted
You seem to be implying that it wouldn't be safe to run user owned equipment (iphones,blackberrys,linuxes etc) in an Active Directory environment incase they run a 3rd pary LDAP tool?

An openLDAP server (ie a linux Domain server) doesn't suffer from this problem. Is windows insecure? should I ditch AD? or is it a permission error on the AD like I stated ?

 

Don't know where you read that at all. Not that I mentioned anything at all to do with anything you just said....

(And if you read my post I didn't quote webman anywhere)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...