A Windows Vista forum. Vista Banter

Welcome to Vista Banter.

You are currently viewing our boards as a guest which gives you limited access to view most discussions, articles and access our other FREE features. By joining our free community you will have access to ask questions and reply to others posts, upload your own photos and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact support.

Go Back   Home » Vista Banter forum » Microsoft Windows Vista » Security and Windows Vista
Site Map Home Register Authors List Search Today's Posts Mark Forums Read Web Partners

Security and Windows Vista A forum for discussion on security issues with Windows Vista. (microsoft.public.windows.vista.security)

GPO - Removable Storage Access (Bypass)



 
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old April 19th 07, 11:26 PM posted to microsoft.public.windows.vista.security
AdrianSa
external usenet poster
 
Posts: 5
Default GPO - Removable Storage Access (Bypass)

Escenario:

- Active Directory Domain

- Pc whit Winddows Vista (for this example Bussiness)

- Config. a GPO (Computer and User config)

Administrative Templates \ System \ Removable Storage Access

“Removable Disks: Deny write access” Enable


- Apply the GPO in the OU for Windows Vista computers.

- gpupdate /force


And the configuration registry is: (1) for:

HKEY_CURRENT_USER\Software\Policies\Microsoft\Wind ows\RemovableStorageDevices

HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Win dows\RemovableStorageDevices


Insert a USB in you computer and dont cant write in the USB.


Now, change this value to "0" in the configuration registry

LogOff/LogOn and now you can write in the USB.


The question is,

Why the Windows VISTA don't refresh the policy? and reconfigure the value?

I shutdown/logoff/logon/logon-otheruser/ and vista never refresh the
configuration.


----------------
This post is a suggestion for Microsoft, and Microsoft responds to the
suggestions with the most votes. To vote for this suggestion, click the "I
Agree" button in the message pane. If you do not see the button, follow this
link to open the suggestion in the Microsoft Web-based Newsreader and then
click "I Agree" in the message pane.

http://windowshelp.microsoft.com/com...sta.sec urity
  #2 (permalink)  
Old April 20th 07, 12:42 AM posted to microsoft.public.windows.vista.security
Jesper
external usenet poster
 
Posts: 839
Default GPO - Removable Storage Access (Bypass)

That's how Group Policy works. There is no enforcement. Every 90 minutes the
system checks if the policies have changed on the DC, and if there is no
server-side change they are not reapplied. There is more info he
http://technet2.microsoft.com/window...ed/gp/faq.mspx

In addition, GP is reapplied on certain events (startup for HKLM settings,
logon for HKCU). A local admin can therefore easily change HKLM settings and
override the policies.
---
Your question may already be answered in Windows Vista Security:
http://www.amazon.com/gp/product/047...otectyourwi-20


"AdrianSa" wrote:

Escenario:

- Active Directory Domain

- Pc whit Winddows Vista (for this example Bussiness)

- Config. a GPO (Computer and User config)

Administrative Templates \ System \ Removable Storage Access

“Removable Disks: Deny write access” Enable


- Apply the GPO in the OU for Windows Vista computers.

- gpupdate /force


And the configuration registry is: (1) for:

HKEY_CURRENT_USER\Software\Policies\Microsoft\Wind ows\RemovableStorageDevices

HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Win dows\RemovableStorageDevices


Insert a USB in you computer and dont cant write in the USB.


Now, change this value to "0" in the configuration registry

LogOff/LogOn and now you can write in the USB.


The question is,

Why the Windows VISTA don't refresh the policy? and reconfigure the value?

I shutdown/logoff/logon/logon-otheruser/ and vista never refresh the
configuration.


----------------
This post is a suggestion for Microsoft, and Microsoft responds to the
suggestions with the most votes. To vote for this suggestion, click the "I
Agree" button in the message pane. If you do not see the button, follow this
link to open the suggestion in the Microsoft Web-based Newsreader and then
click "I Agree" in the message pane.

http://windowshelp.microsoft.com/com...sta.sec urity

 




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 09:32 AM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.Search Engine Optimization by vBSEO 3.0.0 RC6
Copyright 2004-2024 Vista Banter.
The comments are property of their posters.