# Can I Get Around Group Policy Restrictions?

**URL:** <https://boards.straightdope.com/t/can-i-get-around-group-policy-restrictions/696510>\
**Category:** Factual Questions\
**Created:** [August 25, 2014, 11:02pm UTC](https://boards.straightdope.com/t/can-i-get-around-group-policy-restrictions/696510 "2014-08-25T23:02:49Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Johnny\_Bravo](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnny_bravo/32/493_2.png) [@Johnny\_Bravo](https://boards.straightdope.com/u/Johnny_Bravo)\
**Post date:** [August 25, 2014, 11:02pm UTC](https://boards.straightdope.com/t/can-i-get-around-group-policy-restrictions/696510/1 "2014-08-25T23:02:49Z")

</div>

So here’s the deal. My company has installed a new image on my laptop which is locking me out of a lot of features that I want access to. Everything from customizing the toolbar to using the “run” function to accessing the registry.

I have access to the local administrator password, and can log in as the local admin. As the local admin, I have full access to the computer, but no access to the network (so effectively worthless for day-to-day operations). I’ve tried setting my own profile to the administrators group, but that hasn’t helped. If I use my primary account to log onto the domain, I’m locked out, which is why I think it’s group policy stuff (I am no network admin so I might be wrong there).

ANYWAY. Is there any way, using my local administrator access, to make the computer give me full rights when logged onto the domain, or am I stuck under the thumb of the IT department?

---

<div class="post-metadata">

**Author:** ![Number](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/number/32/242_2.png) [@Number](https://boards.straightdope.com/u/Number)\
**Post date:** [August 25, 2014, 11:36pm UTC](https://boards.straightdope.com/t/can-i-get-around-group-policy-restrictions/696510/2 "2014-08-25T23:36:41Z")

</div>

Yes. Request the appropriate level of access through your company’s established channels, citing the features you require and how the restrictions are hampering you in your job function.

If you can’t accept the result, find a different company.

---

<div class="post-metadata">

**Author:** ![Johnny\_Bravo](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnny_bravo/32/493_2.png) [@Johnny\_Bravo](https://boards.straightdope.com/u/Johnny_Bravo)\
**Post date:** [August 25, 2014, 11:38pm UTC](https://boards.straightdope.com/t/can-i-get-around-group-policy-restrictions/696510/3 "2014-08-25T23:38:55Z")

</div>

Yeah, I put this in GQ for a reason. If you want to answer a question I’m not asking, maybe do it in a different forum.

---

<div class="post-metadata">

**Author:** ![Reply](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/reply/32/15952_2.png) [@Reply](https://boards.straightdope.com/u/Reply)\
**Post date:** [August 25, 2014, 11:41pm UTC](https://boards.straightdope.com/t/can-i-get-around-group-policy-restrictions/696510/4 "2014-08-25T23:41:16Z")

</div>

This page suggests that the local admin can prevent network access to relevant registry keys on the local computer:

> **[Archived MSDN and TechNet Blogs](https://learn.microsoft.com/en-us/archive/blogs/)**

It’ll probably get ya fired if they find out, though.

---

<div class="post-metadata">

**Author:** ![Johnny\_Bravo](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnny_bravo/32/493_2.png) [@Johnny\_Bravo](https://boards.straightdope.com/u/Johnny_Bravo)\
**Post date:** [August 25, 2014, 11:46pm UTC](https://boards.straightdope.com/t/can-i-get-around-group-policy-restrictions/696510/5 "2014-08-25T23:46:04Z")

</div>

> [@Reply](#):
>
> It’ll probably get ya fired if they find out, though.

Hah, yeah, no doubt. I was hoping there’d be an answer a little less invasive than brute-forcing the registry. But good find on the page, thanks.

---

<div class="post-metadata">

**Author:** ![Reply](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/reply/32/15952_2.png) [@Reply](https://boards.straightdope.com/u/Reply)\
**Post date:** [August 25, 2014, 11:49pm UTC](https://boards.straightdope.com/t/can-i-get-around-group-policy-restrictions/696510/6 "2014-08-25T23:49:13Z")

</div>

Could you run the network login in a virtualized Windows under the local admin?

---

<div class="post-metadata">

**Author:** ![dstarfire](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dstarfire/32/5762_2.png) [@dstarfire](https://boards.straightdope.com/u/dstarfire)\
**Post date:** [August 25, 2014, 11:49pm UTC](https://boards.straightdope.com/t/can-i-get-around-group-policy-restrictions/696510/7 "2014-08-25T23:49:22Z")

</div>

You can run select applications as another user, but the app that manages the UI (explorer.exe) is the same one you’d use to browse network shares and the like.

What you want to do is something Windows is specifically designed to prevent.

Also, bypassing the domain restrictions is almost certainly a violation of company policy (look up “acceptable use” in your employee handbook).

---

<div class="post-metadata">

**Author:** ![Reply](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/reply/32/15952_2.png) [@Reply](https://boards.straightdope.com/u/Reply)\
**Post date:** [August 25, 2014, 11:51pm UTC](https://boards.straightdope.com/t/can-i-get-around-group-policy-restrictions/696510/8 "2014-08-25T23:51:10Z")

</div>

You can still runas explorer under another user, I’m pretty sure. It just opens another instance.

---

<div class="post-metadata">

**Author:** ![si\_blakely](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@si\_blakely](https://boards.straightdope.com/u/si_blakely)\
**Post date:** [August 26, 2014, 1:34am UTC](https://boards.straightdope.com/t/can-i-get-around-group-policy-restrictions/696510/9 "2014-08-26T01:34:35Z")

</div>

If you have Local Admin login, you can run cmd.exe using the Local Admin credentials (via the right-click menu Run as another User, or using the RunAs command in a cmd window). From the Local Admin CMD window, you can do some of the things you want (like RegEdit), but not all.

You certainly cannot do much about certain things (like the Toolbar) - if the IT policy locks those things down and enforces them via GPO, they will be refreshed at some point and wipe out your changes. Even with Local Admin rights, you cannot get around them (and I have been a Domain Admin and Systems troubleshooter and know all sorts of loopholes to get the access I needed to do my job).

However, it is worth raising the issue with IT - they may not actually be aware of the consequences of the lockdown and how it impacts users. Far easier to loosen the policy in response to a problem than have a company of unhappy users, particularly over something trivial like Toolbar preferences. However, I am also very aware that something like Toolbars can go badly wrong for a user, leaving IT with cases that require considerable time to resolve because a profile has lost all the Toolbar settings and cannot be reset. So I sympathise with the fix-it-once-fix-it-permanently mindset.

---

<div class="post-metadata">

**Author:** ![Colibri](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/colibri/32/1841_2.png) [@Colibri](https://boards.straightdope.com/u/Colibri)\
**Post date:** [August 26, 2014, 1:45am UTC](https://boards.straightdope.com/t/can-i-get-around-group-policy-restrictions/696510/10 "2014-08-26T01:45:21Z")

</div>

I don’t think that discussion of how to circumvent an employer’s IT policy is really appropriate for GQ. This is closed.

Colibri  
General Questions Moderator
