Re: WinXp PRO Accounts and GPEDIT

From: JW (JustPostYourReply_at_ToTheNewsGroup.pls)
Date: 06/23/04


Date: Tue, 22 Jun 2004 19:08:58 -0500

For both question #1 and #2, it would help to get familiar with Local Users
and Groups in Computer Management (right-click My Computer, and select
Manage). You can do lots more stuff than you can with User Accounts in
Control Panel. With Local Users and Groups, double-click Groups,
right-click a Group Name, and select Properties. Now you can easily assign
a User Account to a different Group. You have more groups to choose from,
but it takes 2 steps. You'll have to add the User to a new Group, and
remove him from the old Group. To get Norton to stop balking, try (1)
giving Write and Modify permission to Chris, only on the folder named in the
Error message Norton is choking on, or (2) adding Chris to the Group named
Power Users, which ever makes you more comfortable.

Since the Administrator and Power Users group have lots more authority and
permission than Limited Accounts (Users group), I would recommend you not
surf the wild wild web using these accounts. Any vermin that slips through
your defenses would have the same permission/authority as the account you
logged on with. Instead, I have found a great deal of success and comfort
surfing the web with a special account set up for only that purpose, that
has all NTFS permissions except Read/Execute removed from \Windows and
\Program Files. It doesn't remove the need for anti-virus, anti-spyware,
and firewall programs, because it doesn't stop vermin from corrupting the
folders within this user account, e.g. Favorites, Cookies, Desktop,
Documents, Settings, etc. What I have noticed though, since I enabled
auditing on folders named \Windows and \Program Files, is that the Security
Log in Event Viewer shows failed attempts every day by some web pest trying
unsuccessfully to infect files in these folders like Explorer.exe.

Can't help with question # 3

"eschatonik" <usenet@eschatonik(removethis).com> wrote in message
news:3A%Bc.4847$E84.2712@edtnps89...
I just got a new laptop and this is the first time i have had XP PRO (i have
had XP HOME and 2000 before).

I have 2 questions:

1. I want the built-in "Administrator" account to be the Admin and "Chris"
to be a limited user. But XP wont let me take admin priviledges away from
"Chris", even when I am logged into the "Administrator" account ("limited
account" is greyed out in the User Accounts control panel). I need to set up
a third account, give it admin priviledges, and then take them away from
"Chris" to have it the way I want it. It's like XP dosen't count
"Administrator" and having admin priviledges. Why the need for 3 accounts?
Is there a way around this?

2. Even once I did that, and made "Chris" a limited account, Norton AV2004
complains at logon about not having priviledges. Is there a way to make
Norton AV2004 shut up, or can I give "Chris" priviledges for certain things,
but not others, to keep the account safer? Also, is there a solid tutorial
out there for configuring user accounts with GPEDIT? I want to customize the
security for the limited account, but I don't want to mess with things until
i RTFM.

OK, that's more like 3 questions. Thanks.

--
Chris


Relevant Pages

  • Re: 1 of 4 users has a locked desktop Addl Info
    ... "Chris" to an Admin account. ... Then I logged out of Chris, switched to my profile as Admin, changed his ...
    (microsoft.public.windowsxp.general)
  • WinXp PRO Accounts and GPEDIT
    ... But XP wont let me take admin priviledges away from ... even when I am logged into the "Administrator" account ("limited ... "Chris" to have it the way I want it. ... Even once I did that, and made "Chris" a limited account, Norton AV2004 ...
    (microsoft.public.windowsxp.security_admin)
  • Re: WinXp PRO Accounts and GPEDIT
    ... Per user Group Policy Restrictions for XP Home and XP Pro ... But XP wont let me take admin priviledges away from ... > account" is greyed out in the User Accounts control panel). ... > "Chris" to have it the way I want it. ...
    (microsoft.public.windowsxp.security_admin)
  • RE: Need help with sharepointsystem account
    ... \par Microsoft Global Technical Support Center ... \par of the top level site again with the correct limited access permission role. ... \par chris ...
    (microsoft.public.sharepoint.portalserver)
  • Re: FC3, GNOME question
    ... If this is a new install as root create a new user account for ... There is a home directory for my normal account "chris", ... Feb 21 14:40:19 localhost gconfd: Resolved address ...
    (Fedora)