Re: Prevent users installing software



By default in a domain configuration the only thing that is stopping any
user from accessing domain resources is credentials. In other words a user
on a Windows 98 computer or Apple Mac laptop could potentially access files
on a domain file server if they new the logon/password of a domain user that
had access to the file server. The administrator of the domain could
implement ipsec require policy for that file server that would make it
impossible for non domain users to access the domain file server because
ipsec by default requires that the domain computers authenticate with each
other via Kerberos before network communications can begin. Other concerns
[particularly if ipsec is not used] is that a public user computer could be
infected with a worm that could attempt to infect the whole network
including domain computers via file and print sharing. That can happen even
if the credentials of the other users are not known if the worm exploits a
vulnerability of the operating system like blaster did for RPC. That is one
reason it is very important to keep your computers current with critical
security updates that could expose your computers to such threats. ---
Steve


"jeffuk123" <jeffuk123@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:E8857C66-50C2-4E93-B78A-711F87186727@xxxxxxxxxxxxxxxx
Thanks Guys,

Apart from these users members of the public need to be able to access the
internet if they take their own laptops to the mobile classroom.

I thought that being on a workgroup users would have access to network
resources and the whole point of being on a domain was to prevent this!!!

Many thanks

"Leythos" wrote:

In article <65B0DA00-AFF6-42C0-B1D7-77962CAC845F@xxxxxxxxxxxxx>,
jeffuk123@xxxxxxxxxxxxxxxxxxxxxxxxx says...
Hello to all,

I would be most grateful if anyone could give me some guidance on how
to
prevent users from installing software and changing settings on a
standalone
windows xp laptop or PC.

Basically, the users will only have Internet access and will be taking
the
laptops away with them from the workplace, but must have basic user
accounts.

The other way, although this may not be within the realms of this
thread.
Our cleint has a windows 2003 server and the new laptops must not have
access
to exisitng network resources also. How could I set this up on the
domain
controller whereby users can access the internet, but not be able to
access
the exisiting network resources. I was wondering if I could join the
laptops
to the existing domain and create a group for these users and then deny
this
group access to the existing network resources, and prevent them from
being
able to change settings and install software through group policy.
However,
where in group policy does this occur and would it be best to create
mandatory profiles?

Any idea and guidance would really be appreciated about how to set this
up.

Many thanks to all,

Computers that are part of a "Workgroup" and never having been part of
the "Domain" that don't have complementary accounts on the domain, don't
have access to the Server files, but they could get access to DHCP and
internet depending on how you have your Internet firewall setup.

--

spam999free@xxxxxxxxxx
remove 999 in order to email me



.



Relevant Pages

  • Re: object system...
    ... entropy either remains constant or declines. ... Nevertheless we do know how to create computers and how to write software ... Emulating life will never give us any ... We observe that the same tasks require more resources than ...
    (comp.object)
  • Re: Renaming computer error
    ... this case meaning all mapped resources. ... The forward slash is correct. ... I went to my command prompt screen. ... >>> We have about 150 computers divided into three domains. ...
    (microsoft.public.windowsxp.network_web)
  • Re: XP Networking with NT4 Server
    ... >>>having difficultly connect all the resources on the network. ... Are computers 1,2,3,4,5 all Win98? ... >> using Guest, or non-Guest accounts, on the server? ...
    (microsoft.public.windowsxp.network_web)
  • Re: AD Design Question
    ... HR Computers ... Delegate Authority (to junior or local admins) ... Groups are used primarily for granting access to resources. ... of handling outside contacts as well as contacts for our parent company. ...
    (microsoft.public.windows.server.active_directory)
  • Re: disable internet but allow network access
    ... What version of XP is on the workstation, ... By "allow access to network resources" I assume that you mean lan ... unrestricted administrator account to do updates, maintenance, etc. ...
    (microsoft.public.windowsxp.security_admin)