C
C
Chronic 862018-07-14 20:18:58
Active Directory
Chronic 86, 2018-07-14 20:18:58

How to intercept shutdown.exe call?

Essence of the question. The GPO is configured to turn off the computer by time, there are several computers that cannot be extinguished. Creating separate groups is not an option for too much bureaucracy.
The idea is to intercept the call to the shutdown.exe file, check for some external conditions and then make a decision.
What are the options for resolving the issue? Or at least point me in the direction.

Answer the question

In order to leave comments, you need to log in

2 answer(s)
V
vreitech, 2018-07-14
@fzfx

in principle, this is implemented using subscriptions to wmi events. "subscription to wmi mof events" - keywords for Google. The topic is not easy, experiment.
not quite what you need, but it will help you understand the principle: samag.ru/archive/article/634

0
074909, 2018-07-15
@074909

"According to GPO" how exactly is this? By adding a task?
In general, at the level of file permissions, add prohibitions for the account on behalf of which the shutdown is being pulled.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question