How disable domain logon scripts?

From: Robert Wong (robertwong_at_hotmail.com)
Date: 06/30/03


Date: Mon, 30 Jun 2003 09:38:00 -0400


Hi there,

Software: Windows 2000 Professional

I have always logon to a domain controller for a corporate network and
lately I noticed them are pushing programs from the logon scripts? I used
to have MacAfee 4.51 and they are pushing 7.0. 7.0 seems to be slow and
buggy.

Anyway, is there a way to prevent logon scripts from pushing programs? I
know that the logon scripts also map network drives, those are safe.
Pushing programs and executing them are definitely not safe.

Someone with access as a domain controller may try to push harmful software.
What can be done at the user level?

Robert



Relevant Pages

  • Re: Auditing User logon/logoff events.
    ... u say in the document like i enabled "Account logon events" only in domain ... Then i am getting 672,673 event ids in my domain controllers event viewer. ... can see this log in domain controller security log. ...
    (microsoft.public.win2000.security)
  • Re: remote desktop rights on domain controller
    ... First of for domain controllers user rights must be configured in Domain ... Controller Security Policy - not local policy. ... The user right for logon ... Group on the domain controller if using Windows 2003. ...
    (microsoft.public.windows.server.security)
  • Re: How to remove a cached password?
    ... See if another domain user can logon to it or not, ... a domain controller is that it has incorrect dns settings. ... The login used on the laptop is the same ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Why allow log on locally" is not configured by default??
    ... To logon locally you would have to be sitting in front of the console or use ... There are two policy under admin tools -> domain controller security ... Domain Controller policy impacts ALL dc's in your network. ... asking it if it is ok that this user log onto this workstation, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Custom rights
    ... By default any user can log onto a server other than domain controller. ... allow then to logon to a domain controller give them the logon locally user ... To add computers to the domain go to AD Users and Computers. ... > Look into AD delegation, though you may need to do some custom delegation. ...
    (microsoft.public.win2000.security)