Skip to main content
Question

EFI protection

  • January 21, 2011
  • 2 replies
  • 3 views

Forum|alt.badge.img+12

I know I am missing something fundamental here, but it sadly escapes me, so
I will ask: how does your dummy receipt policy detect the changes?
Thanks,
Sean

2 replies

Forum|alt.badge.img+31
  • Honored Contributor
  • January 21, 2011

Just a shell script that loops through current users and checks if they are members of the admin group. This can be done with extension attributes but I haven't upgraded yet so still using dummy receipts.


Forum|alt.badge.img+24
  • Valued Contributor
  • January 21, 2011

Tom-

I think the hangup may be that Sean thinks you've made a magical dummy package that automatically detects admin users. Rather, I assume you run a script from a policy that lays down a dummy receipt if it finds an admin user. Then it runs a recon which places them into a smart group, which I'm assuming sends you an email indicating that the user is about to get their hands slapped.

j
--
Jared F. Nichols
Desktop Engineer, Client Services
Information Services Department
MIT Lincoln Laboratory
244 Wood Street
Lexington, Massachusetts 02420
781.981.5436