Prevent users from disjoining from domain using GPO

Posted on October 29th, 2009 in Active Directory, GPO, Microsoft, Vista, Windows 7, Windows XP by Gil Kreslavsky

 

There is no 100% foolproof  solution that blocks local admin users access the option of disjoining their computer from domain , but you can make it harder to get to system menu.

I remove the "properties" from when you right click on my computer.
Then i also remove system applet from control panel menu ,and disable registry editing.

To disable right click on my computer go to Group Policy.
Navigate to  User Configuration>Administrative templates>Desktop
Locate “Remove Properties from the My Computer context menu” and set it to “Enable

You should check also How disable  Right Click Properties on my computer on windows 7/Vista

Remove Properties from the My Computer

Than navigate to User Configuration>Administrative templates>Control PanelLocate “Hide specified Control Panel applets”Set it to “Enabled” and add Sysdm.cpl to the list of disallowed Control Panel applets.

list of disallowed Control Panel applets

To block Sysdm.cpl  from executing

Navigate to User Configuration>Administrative Templates>System

Navigate to “Don’t run specified Windows application” set it to “Enabled” and add Sysdm.cpl  to the list of disallowed applications

Don’t run specified Windows application

Related Articles

Post a comment

CommentLuv Enabled





Search Kreslavsky.com
Custom Search