by Darren Mar-Elia | Jan 29, 2011 | General Stuff, Group Policy
Someone asked me recently what I thought of using Deny ACEs on GPOs for security group filtering. First, a little background. As you probably know, you can control which users and computers will process a particular GPO by using security filtering on that GPO. The...
by Darren Mar-Elia | Nov 18, 2010 | General Stuff, Group Policy, PowerShell, Uncategorized
Someone recently asked about the best way to perform bulk GPO renames. Of course, there are probably many reasons why you would want to do this (e.g. moving to a standard naming convention, cleaning up mis-named GPOs, etc.) but for my money, there is one technology...
by Darren Mar-Elia | Oct 14, 2010 | General Stuff
I recently wrote a whitepaper for my friends over at Beyondtrust that talks about the challenges and choices of trying to get to what I call “Best Privilege” on Windows desktops. The idea here is that a secure Windows desktop is one in which the user is...
by Darren Mar-Elia | Jul 23, 2010 | General Stuff, Group Policy Preferences, Security-related
Microsoft recently announced a new security vulnerability in Windows shortcuts that affects all versions of Windows since XP! Its references here: https://support.microsoft.com/kb/2286198. This particular vulnerability takes advantage of the icon that appears in...
by Darren Mar-Elia | Jul 22, 2010 | General Stuff, Microsoft-Related, Security Policy, Security-related
Some of you may have seen a twitter post I did a while back letting folks know about the Security Compliance Manager, which is a tool from Microsoft that lets you manage, edit, report, search and export security templates and baselines. This tool is pretty cool, but...
by Darren Mar-Elia | Feb 5, 2010 | General Stuff
I had a question recently that I thought was worth blogging. The question was, “if I create a GPO using Windows 7, Server 2008 or similar newer platform”, then backup that GPO using XP or Server 2003, will it back up everything?”. The answer, not...