Locking XP Pro pleb lusers wallpaper and desktops

From: Geoff Roberts (geoffrobx@stmarksx.ppx.catholicx.edux.aux)
Date: 08/14/02


From: "Geoff Roberts" <geoffrobx@stmarksx.ppx.catholicx.edux.aux>
Date: Wed, 14 Aug 2002 19:06:26 +0930

Probably a FAQ, if so, please indicate where it is and I will shut up and go
away.

Situation:
XP Pro. Novell Network IPX only, with IP for Internet access via NAT in the
Novell server.
(There are no NT/2k servers on the network.) Novell Client 4.83 for XP/NT/2K
Two XP User accounts on the XP boxes. Administrator and Me
Administrator used only by tech support staff.
Me used by the plain vanilla lusers. We do not allow individual desktops on
shared machines.

Mission:
Disable the ability of Me lusers to change wallpaper/backgrounds and rename
Desktop icons.
We have tried Winlock, which prevents access to the control panels ok, but
it does NOT disable the
ability to right click on a file and 'Set as wallpaper', except by removing
right click in toto.
This bypasses the inability to access the control panel and sets the
wallpaper regardless.

Considerations:
It is not acceptable to disable the right click function in toto as it is
required for legitimate purposes.
I'd settle for being able to remove the 'Set as wallpaper' from the right
click menu.
I'm considering a remote registry option, (the machines are all identical)
but wary of making the systems too dependent on the server,
ie can I do remote registry but have the machines still useable if the
server is offline for some reason.
Can I even do Remote Registry from a Novell server using the 32bit Netware
Client?
If so can someone point me to a how-to?

We have no plans to migrate to MS servers now or ever, so "Get a 2k Server"
is not a workable solution.

This might seem like a minor irritant, but this is a school and some images
that are installed as wallpaper have been
somewhat offensive. While we're at it, some way to audit (mis)use would be
good, stuff done on the server is
audited and we have no issues there, but I am looking for something that
will log changes to the local environment,
renaming files, changing wallpaper etc, unobtrusively and identify the user.
(To do this it must log the username that is used to log into the Novell
Network, faithfully recording that x was done by "Me" is not useful.) I
have Netspy but it's really only useful for monitoring Internet useage,
though it DOES record the login name and login/logout times correctly.
ReGhosting machines at the end of the day or simply resetting wallpaper etc
is possible, but tedious, and I really need a way to stop it happening
rather than cleaning up afterwards.

Thanks in Advance

Geoff Roberts
Computer Systems Manager
Saint Mark's College
Port Pirie, South Australia
geoffrob at stmarks dot pp dot catholic dot edu dot au



Relevant Pages

  • Re: desktop picture with terminal services?
    ... Both have terminal services set-up on them and this works fine as other machines on the network can remote desktop to them. ... However from my XP Pro SP2 machine even when remoting to the server ... it only appears on the login dialog, once logged in the wallpaper ...
    (microsoft.public.windows.server.general)
  • Networking with XP vs 98SE
    ... run on some customer software that only runs on Novell). ... XP machines in house. ... we use Client for Microsoft Networks to log onto our Win2000 ... set the default server to our Novell server name. ...
    (microsoft.public.windowsxp.network_web)
  • desktop picture with terminal services?
    ... Just got 2 brand new servers that came with Win2K3 Server Standard Edition. ... Both have terminal services set-up on them and this works fine as other ... machines on the network can remote desktop to them. ... once logged in the wallpaper disappears. ...
    (microsoft.public.windows.server.general)
  • Re: Mapped Network Drive Issue
    ... Our Novell ... server has recently died, so im mapping users to a new server for ... - Are these accounts local accounts or domain accounts? ... on the machines belonging to the problem users, ...
    (microsoft.public.windows.server.general)
  • Re: connect to network drive
    ... Even people who are under two different server clients, ... User in different location and a Novell client but has access to AD. ... routing between the two machines and there is no firewall in the way. ...
    (microsoft.public.scripting.vbscript)