• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Locking down machines??

QwertyJuan

[H]F Junkie
Joined
Aug 17, 2000
Messages
11,285
We are looking at allowing some students to use their own personal machines here at a private school where I work. How can we lock down these machines while they are here? According to a guy here, some testing places have software that does this?

Thanks so much.
 
Lock-down how? Do you mean not allow them to install software? Or not allow them to go to certain web-sites? Could you be a little more specific?
 
Like COMPLETELY lock them down.... limit use of programs except for one or two. No abilities to change network settings, etc.

As far as websites, that can be locked down at the router.
 
it is their pesonal computers, technically you cant, unless you get them to sign some contract or usage agreement giving you access to control their computers.

you would need to join it to a domain and force it through a proxy or something, which then how do you force them to log into and not use a normal account and use some wireless AP around..

personally i would not let you touch my personal laptop, how would you do it so that it is only active while at school...

If you want to limit internet usage, that is another story and easy with something like pfsense or untangle
 
it is their pesonal computers, technically you cant, unless you get them to sign some contract or usage agreement giving you access to control their computers.

you would need to join it to a domain and force it through a proxy or something, which then how do you force them to log into and not use a normal account and use some wireless AP around..

personally i would not let you touch my personal laptop, how would you do it so that it is only active while at school...

If you want to limit internet usage, that is another story and easy with something like pfsense or untangle

I am just asking questions... this isn't my idea. :)

What we are saying is that joining it to the personal domain would be the only way? They log onto our domain while they are here, then log into their own machine while at home??

Thanks.
 
There are somethings you can do at the network layer. you can make them go through a proxy, you can also make them have a valid antivirus or they won't be able to get out. Those are not really software solutions though.

The proxy to the Internet can be software, or hardware, or some combination.

The making them have a valid up to date antivirus is a function of Cisco devices, but it has been a long time since I read about that, so I am not sure if that is still a valid product or what you need to do it.

Also it doesn't sound like what you are trying to do anyways.
 
You won't be able to pull this off. You can't modify a policy in the way that you'll want to do it and then just make it disappear when users aren't in the office. However, if you gave a little more detail as to what you wanted to lock down, you might be able to get somewhere.

What I would do --
I would stand up a VDI solution. When the students connect to the network, their devices are routed so that they can only access the VDI portion of the network. From there, they can start a Virtual Desktop.

You can lock down the virtual any way you want. You also don't touch anything on their machines, but you stil retain security (they can only talk to the VDIs) and you don't cause problems with their personal machine.

The first time someone can't go home and play wow... you're going to hear about it! And how are you going to handle support after studends leave the school? If you lock down their machine, would have to undo everything that was done to it. It'll quickly become a nightmare.

Give them a virtual, let them access it from home or school, and be done with it. Citrix XenDesktop is a good product for VDI Provisioning, but it isn't cheap.
 
You will only be able to lock down their network access. Since these are their personal machines you have no control over the OS. I do not recommend adding personal machines to your domain that has bad news written all over it. What we do for personal laptops is have a pna network setup where they login via accounts (kind of like airport wireless). The accounts are monitored and regulated so they don't goto places they shouldn't and if they do something bad we know who is responsible.

or yea VDI but that's very expensive and you will still have to do some networking stuff so they can only communicate with the vdi servers.
 
I do not recommend adding personal machines to your domain that has bad news written all over it.

Ok, can I have reasons so that I can give those reasons to someone else if asked??

Thanks.
 
There are just too many unknown variables to handle. Their computer might be infected. Their OS might be damaged requiring extra work. They may not have the correct version of a program or configuration of a program more work. There will be a mix of os versions you will have to make sure your scripts handle. Users are admins. You can keep going form there.
 
Posts 8, 10 and 12 pretty well sum it up...bad idea. It's going to cost less to get the students inexpensive school laptops that are fully configured they way you want, than to try dealing with their personal ones.
 
Run them as a limited user and use software like Deep Freeze for added protection. If they are XP machines you can use Steady State from Microsoft, for free.
 
Run them as a limited user and use software like Deep Freeze for added protection. If they are XP machines you can use Steady State from Microsoft, for free.

I don't think any of that would fly if the school didn't provide the machines... I think I would flat out refuse to use my machines if my employeer (or school) was going to do something like that on them...
 
I don't think any of that would fly if the school didn't provide the machines... I think I would flat out refuse to use my machines if my employeer (or school) was going to do something like that on them...
Oh missed the part about them using their own machines.

OP it's easy, Just provide them Internet access that's VLANED right to the Internet. They could do whatever they wanted without seeing the internal network, and it could still be filtered.
 
Oh missed the part about them using their own machines.

OP it's easy, Just provide them Internet access that's VLANED right to the Internet. They could do whatever they wanted without seeing the internal network, and it could still be filtered.

that wouldn't prevent an adhoc network to be setup between personal machines though right?? :)
 
This is where I would start. Give them a limited domain account.

Which is what I am going to have to do. I will have to join the machine to the domain, then when at school, they can log in to the domain. When home, they can log in to the personal machines.
 
Which is what I am going to have to do. I will have to join the machine to the domain, then when at school, they can log in to the domain. When home, they can log in to the personal machines.

Better hope someone doesn't lock their account or need elevated privledges while they're at home (maybe they just bought some software and want to install it?). If you put them in the domain -- it will be identical to logging in while attached to your network. The restrictions and policies you setup aren't going to magically disappear when they are at home. They'll log in with cached credentials and see everything except the network resources. If they so much as lock their account, they won't even be able to use their computer until they attach it to the network. It's *NOT* a good solution for someones personal computer.

And the thing that hasn't been mentioned - You're dealing with personal machines. The odds that they have a professional version of Windows is going to be rather slim. Odds are, you won't even be able to join them to the domain.
 
that wouldn't prevent an adhoc network to be setup between personal machines though right?? :)

Pretty much nothing you can do to prevent communication between personally owned machines. Personally owned means you are dealing with any/all OS and any/all hardware. Maybe jammers somehow but that'll light off a shitstorm and probably not legal or practical (you would have to jam every wireless form including all manner of cell tethering etc. so no not gonna happen)

"Lock down" is impossible in this case. Perfect example, we live right across from the campus, we have our own AP at the house. The school can not stop me from connecting to it at will. Even without the AP I can just tether my cell or use wimax. Say they force me to use their specified windows OS and join their domain and whatever else. I can still boot to dozens of OS's on the same machine. The school can not stop me from booting my own machine to my choice of OS regardless of what they install. And I'm just an average enthusiast. Heaven forbid you get a kid with true skills that decides to "experiment" with your network or other students' machines.
 
Last edited:
I still think the easiest thing to do would be to get a Cisco NAC Appliance in the network instead of messing with the individual machines. There are just too many support issues that could come up if you start joining their machines to the domain.

  • Support; Who supports these machines when they can't access something?
  • What if the user wants to install software?
  • What happens when they can't reach the domain?
  • Are you responsible for support once they leave the school?

With a NAC and a Proxy server you can control them having antivirus.

With Cisco NAC Appliance, you can:
  • Recognize users, their devices, and their roles in the network
  • Evaluate whether machines are compliant with security policies
  • Enforce security policies by blocking, isolating, and repairing noncompliant machines
  • Provide easy and secure guest access
  • Simplify non-authenticating device access
  • Audit and report whom is on the network
 
Better hope someone doesn't lock their account or need elevated privledges while they're at home (maybe they just bought some software and want to install it?). If you put them in the domain -- it will be identical to logging in while attached to your network. The restrictions and policies you setup aren't going to magically disappear when they are at home. They'll log in with cached credentials and see everything except the network resources. If they so much as lock their account, they won't even be able to use their computer until they attach it to the network. It's *NOT* a good solution for someones personal computer.

And the thing that hasn't been mentioned - You're dealing with personal machines. The odds that they have a professional version of Windows is going to be rather slim. Odds are, you won't even be able to join them to the domain.

you can have a domain account and local computer account on the same machine , the domain account has no limitation over the local account.

So when they are at home they log in with

My-PC\My account - gives them local account access they had before with all permissions they had before.

at school they log in with their domain account.
 
Support Nightmare.

Anyone thats been support for any reasonable amount will recognize it.

you can have a domain account and local computer account on the same machine , the domain account has no limitation over the local account.

So when they are at home they log in with

My-PC\My account - gives them local account access they had before with all permissions they had before.

at school they log in with their domain account.

And you've now just punched a hole in your own security. As soon as you put them in the domain, the domain security and group policies are going to apply. And you now have two choices -- leave the local accounts on there as Administrators, or remove them.

You remove them, you get complaining users. You leave them, then you might as well not even bother locking them down becuase you've just provided a back door for them to use.

There is nothing you can do to have policies undo themselves if they aren't on the corporate network.
 
If you can figure out how to lock it down I can figure out how to bypass it...
 
And the thing that hasn't been mentioned - You're dealing with personal machines. The odds that they have a professional version of Windows is going to be rather slim. Odds are, you won't even be able to join them to the domain.

The good ones will have Win 7 Home, the netbooks will have Win 7 Starter.
 
Which is what I am going to have to do. I will have to join the machine to the domain, then when at school, they can log in to the domain. When home, they can log in to the personal machines.

This is a really stupid idea, and if you have to ask why you have no business trying to play Sys-Admin. Your asking stupid questions that are obvious to anyone that has an A+ cert.
 
Back
Top