How to Secure Group Policy, Detect Unauthorized Changes, Prevent Configuration Disasters and Recover When Necessary

6/27/2017 11:00:00 AM [(UTC-05:00) Eastern Time (US & Canada)] - Can't make the live event? Register anyway to receive a link to the recording.

Other Time Zones

GMT Standard Time-(UTC+00:00) Dublin, Edinburgh, Lisbon, London    6/27/2017 4:00:00 PM
Show/Hide All Time Zones

All Time Zones

Dateline Standard Time-(UTC-12:00) International Date Line West 6/27/2017 3:00:00 AM
UTC-11-(UTC-11:00) Coordinated Universal Time-11 6/27/2017 4:00:00 AM
Aleutian Standard Time-(UTC-10:00) Aleutian Islands 6/27/2017 6:00:00 AM
Hawaiian Standard Time-(UTC-10:00) Hawaii 6/27/2017 5:00:00 AM
Marquesas Standard Time-(UTC-09:30) Marquesas Islands 6/27/2017 5:30:00 AM
Alaskan Standard Time-(UTC-09:00) Alaska 6/27/2017 7:00:00 AM
UTC-09-(UTC-09:00) Coordinated Universal Time-09 6/27/2017 6:00:00 AM
Pacific Standard Time (Mexico)-(UTC-08:00) Baja California 6/27/2017 8:00:00 AM
UTC-08-(UTC-08:00) Coordinated Universal Time-08 6/27/2017 7:00:00 AM
Pacific Standard Time-(UTC-08:00) Pacific Time (US & Canada) 6/27/2017 8:00:00 AM
US Mountain Standard Time-(UTC-07:00) Arizona 6/27/2017 8:00:00 AM
Mountain Standard Time (Mexico)-(UTC-07:00) Chihuahua, La Paz, Mazatlan 6/27/2017 9:00:00 AM
Mountain Standard Time-(UTC-07:00) Mountain Time (US & Canada) 6/27/2017 9:00:00 AM
Central America Standard Time-(UTC-06:00) Central America 6/27/2017 9:00:00 AM
Central Standard Time-(UTC-06:00) Central Time (US & Canada) 6/27/2017 10:00:00 AM
Easter Island Standard Time-(UTC-06:00) Easter Island 6/27/2017 9:00:00 AM
Central Standard Time (Mexico)-(UTC-06:00) Guadalajara, Mexico City, Monterrey 6/27/2017 10:00:00 AM
Canada Central Standard Time-(UTC-06:00) Saskatchewan 6/27/2017 9:00:00 AM
SA Pacific Standard Time-(UTC-05:00) Bogota, Lima, Quito, Rio Branco 6/27/2017 10:00:00 AM
Eastern Standard Time (Mexico)-(UTC-05:00) Chetumal 6/27/2017 10:00:00 AM
Eastern Standard Time-(UTC-05:00) Eastern Time (US & Canada) 6/27/2017 11:00:00 AM
Haiti Standard Time-(UTC-05:00) Haiti 6/27/2017 10:00:00 AM
Cuba Standard Time-(UTC-05:00) Havana 6/27/2017 11:00:00 AM
US Eastern Standard Time-(UTC-05:00) Indiana (East) 6/27/2017 11:00:00 AM
Paraguay Standard Time-(UTC-04:00) Asuncion 6/27/2017 11:00:00 AM
Atlantic Standard Time-(UTC-04:00) Atlantic Time (Canada) 6/27/2017 12:00:00 PM
Venezuela Standard Time-(UTC-04:00) Caracas 6/27/2017 11:00:00 AM
Central Brazilian Standard Time-(UTC-04:00) Cuiaba 6/27/2017 11:00:00 AM
SA Western Standard Time-(UTC-04:00) Georgetown, La Paz, Manaus, San Juan 6/27/2017 11:00:00 AM
Pacific SA Standard Time-(UTC-04:00) Santiago 6/27/2017 11:00:00 AM
Turks And Caicos Standard Time-(UTC-04:00) Turks and Caicos 6/27/2017 11:00:00 AM
Newfoundland Standard Time-(UTC-03:30) Newfoundland 6/27/2017 12:30:00 PM
Tocantins Standard Time-(UTC-03:00) Araguaina 6/27/2017 12:00:00 PM
E. South America Standard Time-(UTC-03:00) Brasilia 6/27/2017 12:00:00 PM
SA Eastern Standard Time-(UTC-03:00) Cayenne, Fortaleza 6/27/2017 12:00:00 PM
Argentina Standard Time-(UTC-03:00) City of Buenos Aires 6/27/2017 12:00:00 PM
Greenland Standard Time-(UTC-03:00) Greenland 6/27/2017 1:00:00 PM
Montevideo Standard Time-(UTC-03:00) Montevideo 6/27/2017 12:00:00 PM
Magallanes Standard Time-(UTC-03:00) Punta Arenas 6/27/2017 12:00:00 PM
Saint Pierre Standard Time-(UTC-03:00) Saint Pierre and Miquelon 6/27/2017 1:00:00 PM
Bahia Standard Time-(UTC-03:00) Salvador 6/27/2017 12:00:00 PM
UTC-02-(UTC-02:00) Coordinated Universal Time-02 6/27/2017 1:00:00 PM
Mid-Atlantic Standard Time-(UTC-02:00) Mid-Atlantic - Old 6/27/2017 2:00:00 PM
Azores Standard Time-(UTC-01:00) Azores 6/27/2017 3:00:00 PM
Cape Verde Standard Time-(UTC-01:00) Cabo Verde Is. 6/27/2017 2:00:00 PM
UTC-(UTC) Coordinated Universal Time 6/27/2017 3:00:00 PM
Morocco Standard Time-(UTC+00:00) Casablanca 6/27/2017 3:00:00 PM
GMT Standard Time-(UTC+00:00) Dublin, Edinburgh, Lisbon, London 6/27/2017 4:00:00 PM
Greenwich Standard Time-(UTC+00:00) Monrovia, Reykjavik 6/27/2017 3:00:00 PM
W. Europe Standard Time-(UTC+01:00) Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna 6/27/2017 5:00:00 PM
Central Europe Standard Time-(UTC+01:00) Belgrade, Bratislava, Budapest, Ljubljana, Prague 6/27/2017 5:00:00 PM
Romance Standard Time-(UTC+01:00) Brussels, Copenhagen, Madrid, Paris 6/27/2017 5:00:00 PM
Central European Standard Time-(UTC+01:00) Sarajevo, Skopje, Warsaw, Zagreb 6/27/2017 5:00:00 PM
W. Central Africa Standard Time-(UTC+01:00) West Central Africa 6/27/2017 4:00:00 PM
Namibia Standard Time-(UTC+01:00) Windhoek 6/27/2017 4:00:00 PM
Jordan Standard Time-(UTC+02:00) Amman 6/27/2017 6:00:00 PM
GTB Standard Time-(UTC+02:00) Athens, Bucharest 6/27/2017 6:00:00 PM
Middle East Standard Time-(UTC+02:00) Beirut 6/27/2017 6:00:00 PM
Egypt Standard Time-(UTC+02:00) Cairo 6/27/2017 5:00:00 PM
E. Europe Standard Time-(UTC+02:00) Chisinau 6/27/2017 6:00:00 PM
Syria Standard Time-(UTC+02:00) Damascus 6/27/2017 6:00:00 PM
West Bank Standard Time-(UTC+02:00) Gaza, Hebron 6/27/2017 6:00:00 PM
South Africa Standard Time-(UTC+02:00) Harare, Pretoria 6/27/2017 5:00:00 PM
FLE Standard Time-(UTC+02:00) Helsinki, Kyiv, Riga, Sofia, Tallinn, Vilnius 6/27/2017 6:00:00 PM
Israel Standard Time-(UTC+02:00) Jerusalem 6/27/2017 6:00:00 PM
Kaliningrad Standard Time-(UTC+02:00) Kaliningrad 6/27/2017 5:00:00 PM
Libya Standard Time-(UTC+02:00) Tripoli 6/27/2017 5:00:00 PM
Arabic Standard Time-(UTC+03:00) Baghdad 6/27/2017 6:00:00 PM
Turkey Standard Time-(UTC+03:00) Istanbul 6/27/2017 6:00:00 PM
Arab Standard Time-(UTC+03:00) Kuwait, Riyadh 6/27/2017 6:00:00 PM
Belarus Standard Time-(UTC+03:00) Minsk 6/27/2017 6:00:00 PM
Russian Standard Time-(UTC+03:00) Moscow, St. Petersburg, Volgograd 6/27/2017 6:00:00 PM
E. Africa Standard Time-(UTC+03:00) Nairobi 6/27/2017 6:00:00 PM
Iran Standard Time-(UTC+03:30) Tehran 6/27/2017 7:30:00 PM
Arabian Standard Time-(UTC+04:00) Abu Dhabi, Muscat 6/27/2017 7:00:00 PM
Astrakhan Standard Time-(UTC+04:00) Astrakhan, Ulyanovsk 6/27/2017 7:00:00 PM
Azerbaijan Standard Time-(UTC+04:00) Baku 6/27/2017 7:00:00 PM
Russia Time Zone 3-(UTC+04:00) Izhevsk, Samara 6/27/2017 7:00:00 PM
Mauritius Standard Time-(UTC+04:00) Port Louis 6/27/2017 7:00:00 PM
Saratov Standard Time-(UTC+04:00) Saratov 6/27/2017 7:00:00 PM
Georgian Standard Time-(UTC+04:00) Tbilisi 6/27/2017 7:00:00 PM
Caucasus Standard Time-(UTC+04:00) Yerevan 6/27/2017 7:00:00 PM
Afghanistan Standard Time-(UTC+04:30) Kabul 6/27/2017 7:30:00 PM
West Asia Standard Time-(UTC+05:00) Ashgabat, Tashkent 6/27/2017 8:00:00 PM
Ekaterinburg Standard Time-(UTC+05:00) Ekaterinburg 6/27/2017 8:00:00 PM
Pakistan Standard Time-(UTC+05:00) Islamabad, Karachi 6/27/2017 8:00:00 PM
India Standard Time-(UTC+05:30) Chennai, Kolkata, Mumbai, New Delhi 6/27/2017 8:30:00 PM
Sri Lanka Standard Time-(UTC+05:30) Sri Jayawardenepura 6/27/2017 8:30:00 PM
Nepal Standard Time-(UTC+05:45) Kathmandu 6/27/2017 8:45:00 PM
Central Asia Standard Time-(UTC+06:00) Astana 6/27/2017 9:00:00 PM
Bangladesh Standard Time-(UTC+06:00) Dhaka 6/27/2017 9:00:00 PM
Omsk Standard Time-(UTC+06:00) Omsk 6/27/2017 9:00:00 PM
Myanmar Standard Time-(UTC+06:30) Yangon (Rangoon) 6/27/2017 9:30:00 PM
SE Asia Standard Time-(UTC+07:00) Bangkok, Hanoi, Jakarta 6/27/2017 10:00:00 PM
Altai Standard Time-(UTC+07:00) Barnaul, Gorno-Altaysk 6/27/2017 10:00:00 PM
W. Mongolia Standard Time-(UTC+07:00) Hovd 6/27/2017 10:00:00 PM
North Asia Standard Time-(UTC+07:00) Krasnoyarsk 6/27/2017 10:00:00 PM
N. Central Asia Standard Time-(UTC+07:00) Novosibirsk 6/27/2017 10:00:00 PM
Tomsk Standard Time-(UTC+07:00) Tomsk 6/27/2017 10:00:00 PM
China Standard Time-(UTC+08:00) Beijing, Chongqing, Hong Kong, Urumqi 6/27/2017 11:00:00 PM
North Asia East Standard Time-(UTC+08:00) Irkutsk 6/27/2017 11:00:00 PM
Singapore Standard Time-(UTC+08:00) Kuala Lumpur, Singapore 6/27/2017 11:00:00 PM
W. Australia Standard Time-(UTC+08:00) Perth 6/27/2017 11:00:00 PM
Taipei Standard Time-(UTC+08:00) Taipei 6/27/2017 11:00:00 PM
Ulaanbaatar Standard Time-(UTC+08:00) Ulaanbaatar 6/27/2017 11:00:00 PM
North Korea Standard Time-(UTC+08:30) Pyongyang 6/27/2017 11:30:00 PM
Aus Central W. Standard Time-(UTC+08:45) Eucla 6/27/2017 11:45:00 PM
Transbaikal Standard Time-(UTC+09:00) Chita 6/28/2017 12:00:00 AM
Tokyo Standard Time-(UTC+09:00) Osaka, Sapporo, Tokyo 6/28/2017 12:00:00 AM
Korea Standard Time-(UTC+09:00) Seoul 6/28/2017 12:00:00 AM
Yakutsk Standard Time-(UTC+09:00) Yakutsk 6/28/2017 12:00:00 AM
Cen. Australia Standard Time-(UTC+09:30) Adelaide 6/28/2017 12:30:00 AM
AUS Central Standard Time-(UTC+09:30) Darwin 6/28/2017 12:30:00 AM
E. Australia Standard Time-(UTC+10:00) Brisbane 6/28/2017 1:00:00 AM
AUS Eastern Standard Time-(UTC+10:00) Canberra, Melbourne, Sydney 6/28/2017 1:00:00 AM
West Pacific Standard Time-(UTC+10:00) Guam, Port Moresby 6/28/2017 1:00:00 AM
Tasmania Standard Time-(UTC+10:00) Hobart 6/28/2017 1:00:00 AM
Vladivostok Standard Time-(UTC+10:00) Vladivostok 6/28/2017 1:00:00 AM
Lord Howe Standard Time-(UTC+10:30) Lord Howe Island 6/28/2017 1:30:00 AM
Bougainville Standard Time-(UTC+11:00) Bougainville Island 6/28/2017 2:00:00 AM
Russia Time Zone 10-(UTC+11:00) Chokurdakh 6/28/2017 2:00:00 AM
Magadan Standard Time-(UTC+11:00) Magadan 6/28/2017 2:00:00 AM
Norfolk Standard Time-(UTC+11:00) Norfolk Island 6/28/2017 2:00:00 AM
Sakhalin Standard Time-(UTC+11:00) Sakhalin 6/28/2017 2:00:00 AM
Central Pacific Standard Time-(UTC+11:00) Solomon Is., New Caledonia 6/28/2017 2:00:00 AM
Russia Time Zone 11-(UTC+12:00) Anadyr, Petropavlovsk-Kamchatsky 6/28/2017 3:00:00 AM
New Zealand Standard Time-(UTC+12:00) Auckland, Wellington 6/28/2017 3:00:00 AM
UTC+12-(UTC+12:00) Coordinated Universal Time+12 6/28/2017 3:00:00 AM
Fiji Standard Time-(UTC+12:00) Fiji 6/28/2017 3:00:00 AM
Kamchatka Standard Time-(UTC+12:00) Petropavlovsk-Kamchatsky - Old 6/28/2017 4:00:00 AM
Chatham Islands Standard Time-(UTC+12:45) Chatham Islands 6/28/2017 3:45:00 AM
UTC+13-(UTC+13:00) Coordinated Universal Time+13 6/28/2017 4:00:00 AM
Tonga Standard Time-(UTC+13:00) Nuku'alofa 6/28/2017 4:00:00 AM
Samoa Standard Time-(UTC+13:00) Samoa 6/28/2017 4:00:00 AM
Line Islands Standard Time-(UTC+14:00) Kiritimati Island 6/28/2017 5:00:00 AM

Webinar Registration

Group policy is a powerful 2-edged source. Case in point: last week I was in a rush, I needed to generate a group policy change event in the security log. I flipped to the Group Policy Editor window already open on a test GPO, picked a setting at random and enabled it. I got my audit event and moved on.

After lunch I came back and attempted to logon with my finger print to my Windows 10 desktop. Nothing doing. Tried my PIN and finally my password. Then I read the message: “Smartcard required”.

Yep. That was the setting I picked at random to enable: Interactive logon: Require smart card. And it turns out, because I switch between unrelated tasks like many others, there was more than one Group Policy Editor window open. And instead of enabling this policy on the Test GPO, I enabled it on Default Domain Policy.

So that locked me out of interactive logon and remote desktop logon to EVERY computer in the domain including domain controllers. I didn't feel like walking downstairs to try logging on the domain controllers' local console to see if they were an exception to the rule. Instead I edited the actual text file in the sysvol folder where a GPO's settings are actually stored and incremented the version number on the groupPolicyContainer object in AD using ADSI Edit. But for a while it was touch and go. Now of course you wouldn't make a mistake like this but are you so sure about your colleagues.

Important take-aways:

  • It's really easy to “hose” your domain without stringent group policy change controls
  • Bad guys with sufficient permissions can bypass Group Policy Editor to make changes to group policy
  • You need to lock down group policy access so that people like me can't run amok
  • You need an audit trail to enforce accountability and to detect unauthorized changes as soon as they occur
  • You need recovery options

In this real training for free ™ webinar I will show you the security controls available in Windows and Active Directory that control who can make changes to group policy objects as well as group policy related attributes on other objects like Organizational Units and Domain roots.

The latter is an important point because changing the gpLink or gpOptions attribution on an OU can be just as disruptive as editing an actual GPO.

So it's important to carefully manage the permissions on

  • The GPO itself
  • The System/Policies folder in AD
  • The sysvol folder on domain controllers
  • The gpLink and gpOptions attributes on the domain root and organizational units

I'll also show you what's available in Windows and AD for auditing group policy changes. The good news is that you can instantly know when anything group policy related is changed in your domain and who did it. The bad news is that the audit log is cryptic and doesn't tell you which policies inside a GPO were changed. But there's ways to figure this out – especially if you are saving backups of group policy objects on a regular basis and especially before making changes.

I'll show you how to backup group policy and how to compare one version of a GPO to another.

Finally we'll look at some strategies for limiting the damage of group policy configuration mistakes when they do happen. For instance, I’m going to erect a barrier above the Domain Controller's OU and change the permissions on Default Domain Controllers GPO so that I can't accidentally edit it with my every day admin account. There's a more “enterprise best practice” way to do this in your environments – mine is just a lab.

Quest is sponsoring this real-training-for-free ™ event and Quest product manager Chris Ashley will briefly show you their super-powerful GPOADmin product which automates much of what I show you and wraps vulnerable group policy objects in a workflow environment with version comparison, rapid rollback, approvals, history and more.

First Name:   
Last Name:   
Work Email:  
Phone:  
Job Title:  
Organization:  
Country:    
Address:  
City:  
State:  
Zip/Postal Code:  
Public sector:
 

Your information will be shared with the sponsor.


 

 

Additional Resources