Locking down a workstation.

From: tim border (tim.border@scott.af.mil)
Date: 03/12/03


From: "tim border" <tim.border@scott.af.mil>
Date: Wed, 12 Mar 2003 12:12:39 -0800


In the local security policy (or group policy for that
server) modify the attributes for the "Log on locally"
user right assignment. That'll keep domain users from
casually logging in but by itself won't be sufficient to
call the box secure. You'll want to dig through the
security policy. There's a ton of other stuff you'll want
to do. Several articles exist that deal with placing
computers in common areas. To keep this post quick you'll
also want to consider removing all removable media devices
from the boot order and locking the bios. A padlock on
the server would not be a bad idea either.

>-----Original Message-----
>OK, I have been forced to put a server in an open area of
an office
>building. I know that to minimize problems, I need to
restrict physical
>access but can't, so let's not go there. I would like to
know what other
>steps I can take to prevent domain users from logging in
to this server.
>However, I still want access, at least by Administrators,
via remote desktop
>connections, and local Admins.
>
>Thanks
>Carl
>
>
>.
>



Relevant Pages

  • Secedit Export and Password complexity is missing.
    ... My server is a W2K server configured to the domain server and the domain ... When I open the Local Security Policy and it ...
    (microsoft.public.win2000.group_policy)
  • Re: user permisions
    ... You need to modify the user right for shut down the system to be what you ... Local Security Policy for that user right and you can use the support tool ... gpresult to see what Group Policies are being applied to that server. ...
    (microsoft.public.win2000.security)
  • Re: IIS FTP Logon
    ... > I have installed my W2k Server as domain controler with Active> Directory. ... and I found out that I have to add them to Logon> Locally. ... > Administrative Tools> Local Security Policy and i have added the> ftpusers group to logon locally, as user_a, and b are member of that> group. ...
    (microsoft.public.inetserver.iis.security)
  • local policy
    ... Just recently for some unknown reason my local security policy on a Windows ... 2000 server acting as a stand alone server on a Windows NT domain changed. ...
    (microsoft.public.win2000.security)
  • Domain Controller Security Policy errors
    ... Security Policy or the Domain Controller Security Policy. ... The DC is also a print and file server. ... The domain controller for Group Policy operations is not available. ...
    (microsoft.public.win2000.active_directory)