Re: Windows Desktop Lockdown on 2000 Server Environment

From: Steven L Umbach (n9rouz_at_nscomcast.net)
Date: 12/03/03


Date: Wed, 03 Dec 2003 17:12:23 GMT

Group Policy does hide a lot of access. You really need to be sure that ntfs
permissions are locked down to prevent a user from accessing what they should not. By
default, XP has pretty good ntfs security. You may want to remove the write
permission for the users group from the drive/root folder and leave them with
read/list/execute. Check the advanced page of the security page to check advanced
permissions also for the users group. On XP Pro, I really don't thing you need extra
program because Software Restriction Policies are very powerful and can be configured
to lock a user down like a coffin lid. I also suggest that you read the free
Microsoft XP Security Guide. --- Steve

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/prodtech/winclnt/secwinxp/default.asp
http://www.infosec.uga.edu/windows.html -- Great list of security guides.

<anonymous@discussions.microsoft.com> wrote in message
news:078601c3b95a$6e096310$a301280a@phx.gbl...
> Thanks for the response Steve! I've been working with
> GPO on a test OU and have made some progress. I'm still
> pruning for a more direct approach to suffice my goal.
> I've found that GPO works well but I'm worried about
> those "Genius" who search for other ways of breaking
> through that level of Windows Security. I've been
> searching for desktop management software but haven't
> found one. Any suggestions?
>
> >-----Original Message-----
> >Check Group Policy user configuration/administrative
> templates for several options to
> >limit users. To limit the desktop, you may want to look
> into mandatory profiles which
> >will not allow any changes to be saved to the profile.
> XP Pro has Software
> >Restriction Policies that can be used to lock down a
> users ability to install and run
> >software and even prevent a lot of malicious
> programs/scripts [.vbs and such] from
> >executing which is a huge improvement over W2K. I
> suggest that you set up a test
> >Organizational Unit with it's own GPO to tweak your
> settings before rolling out. ---
> >Steve
> >
> >http://www.microsoft.com/technet/treeview/default.asp?
> url=/technet/prodtechnol/winxppro/maintain/rstrplcy.asp
> >http://support.microsoft.com/?kbid=310791
> >http://support.microsoft.com/default.aspx?scid=kb;en-
> us;307900
> >
> >"Marvin" <mnurse@seedschooldc.org> wrote in message
> >news:067101c3b888$2dfec440$a401280a@phx.gbl...
> >> I'm trying to lockdown several workstations running
> >> Windows XP Pro. on a Windows 2000 Server using Group
> >> Policies. Any suggestions will help. I'm basically
> just
> >> trying to have a limited desktop and specified apps
> >> running on these workstations. Thank you for your
> >> assistance....
> >
> >
> >.
> >



Relevant Pages

  • Re: Q.) NTFS rights - How to Append NTFS assignments
    ... The Share is setup to Everyone with Full access and the NTFS ... security restricts the permissions to only those authorized. ... via NTFS from the parent folder being requested to change - however I ... permissions on subfolders, set up different *shares* for your departments.. ...
    (microsoft.public.windows.server.sbs)
  • Re: Why does Everyone have Full Control of everthing?
    ... Analysis snap-in to apply the Setup Security template to my machine, ... Perhaps I should have only applied the file permissions ... using the personal account created at setup. ... >list of default NTFS permissions for Windows 2000. ...
    (microsoft.public.windowsxp.general)
  • Re: Q.) NTFS rights - How to Append NTFS assignments
    ... The Share is setup to Everyone with Full access and the NTFS ... security restricts the permissions to only those authorized. ... permissions on subfolders, set up different *shares* for your departments. ...
    (microsoft.public.windows.server.sbs)
  • Re: Cannot write to shared folder on W2K8 server
    ... Folder Sharing Security. ... NTFS permissions are also valid with only SYSTEM ...
    (microsoft.public.windows.server.general)
  • Re: applying SP4 across the network
    ... The group 'domain computers' needs to have the permissions, ... did you use the UNC path when telling the GPO where the update.msi ... On the Security for the GPO itself you can leave the Authenticated Users ... You could have added that specific computer account (in place ...
    (microsoft.public.win2000.setup_deployment)

Loading