Re: preventing all user installs

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 01/09/04


Date: Thu, 08 Jan 2004 23:14:22 GMT

Exactly what settings did you implement? The best way would be to use Software
Restriction Policies using path/hash/certificate rules as described in the link
below. For instance if you restricted ntfs permissions on the root folder to where
users had read/list/execute permissions, then in a default installation the only
other place a user could save files would be their user profile. Then you could use
SRP to create a path rule to the my documents and settings folder with a disallowed
setting which would prevent them from running programs in their profile which would
include installing software. This all assumes you are talking about regular
sers. --- Steve

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/prodtechnol/winxppro/maintain/rstrplcy.asp
http://support.microsoft.com/?kbid=310791

"Steve" <anonymous@discussions.microsoft.com> wrote in message
news:03a101c3d633$19728e80$a401280a@phx.gbl...
> I've used settings in gpedit to limit user installs, but
> still users are installing some non-MS programs. Am I
> missing a setting to prevent users from istalling any
> software whatsoever?
>
> Thanks in advance for assistance.
>
> Steve


Quantcast