Re: Deny Software Installation to Students

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 05/27/05


Date: Thu, 26 May 2005 19:48:04 -0500

You should consider the possibility that students may be local
administrators. You should check a couple of those computers to see. There
are easily available fee tools on the internet that allow any user who can
boot a computer from a floppy or cdrom to become local administrator by
resetting the password of the local administrator account to a password that
they know. Configuring cmos to not allow booting from anything other than
the system disk will help but you still would need to password protect the
cmos settings and make sure they can not open the computer case to reset the
cmos. Even after doing that there may be ways to discover the cmos password.

Having said that you can use Group Policy Restricted Groups to enforce local
administrator membership though be default that setting will be applied only
every 90 minutes though that period can be reduced for computer
configuration. XP Pro will allow you to use Software Restriction Policies to
manage what software users can run and install and most XP Pro Group Policy
including Software Restriction Policies [computer configuration only I
believe though] can be managed in a Windows 2000 domain. Windows 2000 does
not include SRP. You need to rely on group membership, ntfs permissions, and
Group Policy Windows application settings available under user
configuration/administrative templates/ system to manage application use
though if a user can rename an application/executable they can bypass that
Group Policy settings. To start with add setup.exe, install.exe, and
msiexec.exe to the disallowed list. The links below should help get you
started. --- Steve

http://support.microsoft.com/default.aspx?scid=kb;en-us;323525
http://support.microsoft.com/?kbid=310791
http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/rstrplcy.mspx
http://support.microsoft.com/default.aspx?scid=kb;en-us;203607
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/TechRef/156780ef-eb36-4433-b3fe-1b1a15c18f6a.mspx

"B. Meincke" <garyallan@highschool.ca> wrote in message
news:A438E710-899F-4CA5-8023-4BB013802094@microsoft.com...
> Could someone please help me find a way to deny members of a certain
> domain
> group (students, in this case) from installing software on our domain's
> 2K/XP
> clients? I understood that as limited users, this would not be possible,
> but
> students still seem able to install such things as Winamp...etc. Ideally,
> I
> would like to create a group policy on the server so that I don't have to
> impliment changes over dozens of clients.
>
> Thank you in advance for any insight in this manner.
> --
> BJM
> ACE Assistant
> Gary Allan High School



Relevant Pages

  • Re: Administrator restricted - Control Panel Missing
    ... If you did not specifically set up Group Policy to restrict access to ... The command net users will display user accounts and net user username will ... type of administrator. ... the control panel was missing. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Domain Users to have Local Admin rights
    ... Group Policy because a new policy doesn't wana work. ... to local Administrator group on all the computers. ... We have various admin accounts other then administrator ...
    (microsoft.public.windows.server.security)
  • Re: lockdown desktop without Group Policy
    ... security groups were removed from the list. ... I can now no longer edit group policy. ... Logon as an administrator ... Create a new local group named "GP Editors" ...
    (microsoft.public.windows.terminal_services)
  • RE: services running in windows domain (winXP clients)
    ... registry changes and permissions. ... i mean if someone is administrator can change the ... (Maybe create a group policy setting this ...
    (Focus-Microsoft)
  • Re: Help Please: XP Recovery Console Administrator Password Problem
    ... Is your Windows XP CD at SP1 or better? ... with XP Home being that there is no Group Policy ... Recovery Console with Group Policy, it's in the Local Security Policy. ... the built-in administrator account, not your administrator account. ...
    (microsoft.public.windowsxp.general)