Re: locking down XP with NTFS permissions

From: Kent W. England [MVP] (kwe@mvps.org)
Date: 11/06/02


From: "Kent W. England [MVP]" <kwe@mvps.org>
Date: Tue, 5 Nov 2002 23:00:58 -0800


Group Policy objects are designed to do this. However, GPOs are applied
to all users in all groups, admins included. In addition to NTFS
permissions, you might use the registry keys associated with GPOs
instead of the GPO itself to impose some additional restrictions on the
user interface on a per-user basis.

In short, you have permissions that can apply to groups and policy keys
that can apply to individual accounts, as well as policy that is
machine-wide.

-- 
Kent W. England, MS MVP for Windows XP
(Please respond only in the newsgroup)
"Al" <smithal@hotmail.com> wrote
in message news:daa101c28550$cc9219c0$3bef2ecf@TKMSFTNGXA10...
> I'm trying to find a TID document which recommends the
> best way how to lock down the XP Professional Desktop with
> NTFS permissions.
>
> For example, I don't want my users to use nslookup.exe,
> system restore etc..I believe ZAK for NT covered of this
> but I can't find anything for XP..
>
> And help would be great
>


Relevant Pages

  • Re: Preventing browsing
    ... permissions are restrictive enough to prevent them from doing damage. ... ntfs permissions for the everyone group to read/list/execute. ... effective settings in Local Security Policy for those configurations. ...
    (microsoft.public.win2000.security)
  • Re: locking down XP with NTFS permissions
    ... I tried GP but it hid it from admin also. ... >Group Policy objects are designed to do this. ... GPOs are applied ... >permissions, you might use the registry keys associated ...
    (microsoft.public.windowsxp.security_admin)
  • Re: [RFC][PATCH] Privilege dropping security module
    ... dpriv.c contains the struct security_operations hooks for dpriv. ... You're masking file permissions. ... And stick with your namespace, ... * Parse policy lines one at a time. ...
    (Linux-Kernel)
  • [RFC][PATCH] Privilege dropping security module
    ... dpriv.c contains the struct security_operations hooks for dpriv. ... * under the terms of the GNU General Public License as published by the Free ... * Parse policy lines one at a time. ... * Open file descriptors and their implied permissions based on @policy ...
    (Linux-Kernel)
  • Re: Access to Network and Dial-Up Connections blocked
    ... John John wrote: ... if a NoPropertiesMyComputer policy exists: ... I re-enabled Remove Network Connection from ... If this is a permissions issue check and make sure that you have ...
    (microsoft.public.win2000.general)