RE: How to block users from installing other apps

From: Shackleford, Dave (znz1_at_cdc.gov)
Date: 06/26/03

  • Next message: Wallace.Nathan: "RE: How to block users from installing other apps"
    To: 'Jane Han' <janehan22@yahoo.com>, focus-ms@securityfocus.com
    Date: Wed, 25 Jun 2003 21:48:50 -0400
    
    

    Hi Jane-

    Having your users as Local Admin is definitely a security issue going
    forward. You can definitely use GP to push out some local restrictions if
    they are logging into the domain, but if they log in to the local machine
    they can still do anything they want, which is an issue. You can disable IE,
    but that leads to disgruntled employees, which will make them want to do
    more harm, in my experience. Your best bet is to either:

    1) Create an OU with Admin privileges that is set to last for 24 hours.
    Attach a GPO to this OU that is very restrictive in terms of extraneous
    tasks/options available to the user. Then allow them to log in to the
    domain, put their user objects in this OU temporarily, and the next time
    they log in they will be in this group for a limited time. They can install
    the apps, but the next time they log in, they will be kicked back out into
    the normal User group. This is not altogether secure.

    2) Only allow specific apps to be run. In Group Policy, go to
    Domain Policy-->User Configuration-->Admin. Templates-->System-->"Run only
    allowed Windows Applications". Then allow this to be run from a shared
    location, or something similar.

    If you only need Admin privileges to install the app, that isn't SO bad, but
    to run it every time? You are really better off changing that 'feature'.

    Hope this helps.

    --Dave

    > -----Original Message-----
    > From: Jane Han [mailto:janehan22@yahoo.com]
    > Sent: Wednesday, June 25, 2003 15:22
    > To: focus-ms@securityfocus.com
    > Subject: How to block users from installing other apps
    >
    > Due to several customized inhouse applications, the
    > users need to be local aministrator to lauch the
    > applications.  Since most users are local
    > admin, they can download and install applications such
    > as games, AOL instant messages...from internet.
    >
    > Is it possible to block users from installing
    > applications through Group Policy in this case?  or
    > disable internet explorer?
    >
    > Any solutions or suggestions?
    >
    >
    > Thanks in advance,
    > Jane
    >
    >
    > __________________________________
    > Do you Yahoo!?
    > SBC Yahoo! DSL - Now only $29.95 per month!
    > http://sbc.yahoo.com
    >
    > --------------------------------------------------------------------------
    > ---
    > --------------------------------------------------------------------------
    > ----

    ----------------------------------------------------------------------------
    -
    ----------------------------------------------------------------------------

    --
    -----------------------------------------------------------------------------
    ------------------------------------------------------------------------------
    

  • Next message: Wallace.Nathan: "RE: How to block users from installing other apps"

    Relevant Pages

    • Re: Is There a Downside to Trying a Different a Desktop (eg Gnome/KDE)?
      ... I notice that when compiling applications, ... If I install a new desktop, will I have to recompile a bunch of apps? ... If I install a bunch of desktops, will future compiles of applications ... I use Gnome as a rule, but there are specific KDE apps that I really like. ...
      (comp.os.linux.misc)
    • Re: OSD with ZTI - loading applications
      ... (My session is named "OSD FP Internals - A geeks guide to the Galaxy") ... applications within the OSD process with ZTI. ... I want all these apps to load in a specific sequence ... ZTI process then I cannot install them using the SMS packages. ...
      (microsoft.public.sms.tools)
    • Re: asp.net 1.1 application on 2.0
      ... and all the 2.0 apps in a different Application Pool. ... Of course, if you have a very critical application, you could place it in an Application Pool ... If you want to run both 1.1 and 2.0 ASP.NET applications on the same server, ... Note: you should also install the .Net Framework SP1: ...
      (microsoft.public.dotnet.framework.aspnet)
    • Re: how to control Application load order
      ... We place two applications (actually more ... > install itself and the other bundle software 'B also start to install ... If the othe application B 's window is not a top window, ... >> If you're in control of the apps then mutexes will work. ...
      (microsoft.public.pocketpc.developer)
    • Re: Norton Internet Security 2005 Personal Firewall slows down Windows XP startup
      ... I run windows xp pro as admin always, you can't install apps as ... Joe, you're wrong, you can install the apps as Administrator and then ... runs as a User account all the time. ...
      (comp.security.firewalls)