Local Admin Access and Group Policy Don’t Mix
ID: ad9b2693-e387-5c96-912c-36b82da7bfa1
STIX ID: report--ad9b2693-e387-5c96-912c-36b82da7bfa1
Feed Name: TrustedSec blog
This write-up describes how Group Policy versioning and local policy copies work on Windows, demonstrates that local administrators can alter registry-applied policy values (e.g., disabling process command-line auditing) which will persist until a central policy version change or forced gpupdate, and recommends mitigations such as enabling 'Process even if the Group Policy objects have not changed', minimizing local admin access, and logging Group Policy activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
