Restrictions on Internet Content

No admin rights is pretty standard. There should be a process to control what applications are installed and when they are updated. No users should have admin access to their desktops.

The disabling of task manager is probably linked to this. With admin access to the task manager you can easily dump the lsass password hashes.

Its crazy though to have multiple AV products installed - these could clash when scanning files and could cause all sorts of issues.

Sounds like they have a almost decent DLP policy in place to prevent data leakage but then I question why you still have access to Twitter and FB.
 
No admin rights is pretty standard. There should be a process to control what applications are installed and when they are updated. No users should have admin access to their desktops.

The disabling of task manager is probably linked to this. With admin access to the task manager you can easily dump the lsass password hashes.

Its crazy though to have multiple AV products installed - these could clash when scanning files and could cause all sorts of issues.

Sounds like they have a almost decent DLP policy in place to prevent data leakage but then I question why you still have access to Twitter and FB.
Going to be a bitch coding on such a pc.
 
Dont use company devices for personal things.
absolutely 100% end of discussion.
It's locked down for a reason - for you to not load personal/visit unauthorized websites, albeit with some of those being questionable.

Nabb a cheap laptop/desktop and be done with it, leave work devices for work.
 
Restrictive laptop policies are there to protect the company from noobs, disgruntled and malicious employees. That said it's annoying as hell for skilled and trustworthy employees. My work laptop has the following restrictions which actually impact my ability to perform my job well.
  • No gmail, no google calendar, no dropbox, no whatsapp, most websites are blocked, except Facebook and Twitter (strangely)
  • No admin rights so can't install anything, nor can I update any software
  • 2-factor auth into every app, with most requiring re-authentication multiple times a day (annoying!)
  • I connect to 3 different domains so I have to manage multiple passwords and associated policies (aside from the various application passwords that I need to manage)
  • USB devices blocked
  • No access to Task manager so I can't kill any malfunctioning apps, and have to restart if I have issues
  • It's got several AV and endpoint products installed which suck up at least 25% of the CPU at all times
  • It overheats quickly because of the load on the CPU and I've had to have the battery replaced twice in the last year because they expanded and cracked the casing and warped the keyboard
Many security departments are staffed by idiots. All those agents in the stack and they probably still couldn't find their asses to shove their heads up into.

The best security is the most stream lined.

The funniest thing with these corporate lockdowns is when the network breaks the people who are meant to fix it are locked out of using tools to fix it...

PS: Why 3 domains?
 
Last edited:
Sounds like they have a almost decent DLP policy in place to prevent data leakage but then I question why you still have access to Twitter and FB.
Probably pressure from the marketing department. They believe that the only marketing that happens is on those. Anything else does not exist and has been retired.
Also you'll have a Windows shop and marketing and infosec will be on Macs because they are special people.
 
Last edited:
Restrictive laptop policies are there to protect the company from noobs, disgruntled and malicious employees. That said it's annoying as hell for skilled and trustworthy employees. My work laptop has the following restrictions which actually impact my ability to perform my job well.
  • No gmail, no google calendar, no dropbox, no whatsapp, most websites are blocked, except Facebook and Twitter (strangely)
  • No admin rights so can't install anything, nor can I update any software
  • 2-factor auth into every app, with most requiring re-authentication multiple times a day (annoying!)
  • I connect to 3 different domains so I have to manage multiple passwords and associated policies (aside from the various application passwords that I need to manage)
  • USB devices blocked
  • No access to Task manager so I can't kill any malfunctioning apps, and have to restart if I have issues
  • It's got several AV and endpoint products installed which suck up at least 25% of the CPU at all times
  • It overheats quickly because of the load on the CPU and I've had to have the battery replaced twice in the last year because they expanded and cracked the casing and warped the keyboard
I have a company issued Mac in a heavily MS centric company, none of their tools work on Mac so I dont get any restrictions. The Windows users on the other hand are exactly as you mention above.
 
Many security departments are staffed by idiots. All those agents in the stack and they probably still couldn't find their asses to shove their heads up into.

The best security is the most stream lined.

PS: Why 3 domains?
I think it's mostly a case of one hand not speaking to the other within the organisation and each division having their own legacy infrastructure. Rather typical for a bank.

The best security is the most stream lined.
This is very true. Some policies often have the opposite effect on user behaviour - like asking your users to change their password every month... and they simply make their password "April2022!"
 
No admin rights is pretty standard. There should be a process to control what applications are installed and when they are updated. No users should have admin access to their desktops.
Yeah. A company purchased laptop is a single purpose device dedicated to the policy of the company.

The OP should instead of hacking it, clarify and have the policy creation justified. Its implementation is not the point of debate. (Except as a curiosity when its badly done.)
 
I have a company issued Mac in a heavily MS centric company, none of their tools work on Mac so I dont get any restrictions. The Windows users on the other hand are exactly as you mention above.
Which is a bad implementation that negates the policy. The Windows users have a right to bitch about being treated differently via a policy implementation.
BTW: Many of the MS tools now work on Mac as well.
 
Last edited:
This is very true. Some policies often have the opposite effect on user behaviour - like asking your users to change their password every month... and they simply make their password "April2022!"

Yes, even MS now says non-expiring passwords with 2FA is more secure than passwords being changed each month.
 
Not sure if the OP really needs help/advice/"fix".

- They are blocking DNS queries to the blocked domains, that is why it is not working. Change the DNS settings and you should be able to access the domains.
- The USB drive is most probably just disabled in Windows, you should be able to boot from it.

Do this at your own caution.

My wife has a locked down laptop as well, it is frustrating since her AV definitions takes weeks to update. I could hack the password and uninstall it but since it their equipment, I leave it. I just make sure my home network is secure.
 
Top
Sign up to the MyBroadband newsletter
X