Solved

XP Security Policies for User Group

Posted on 2004-03-21
5
302 Views
Last Modified: 2013-12-04
This is lengthy but please bear with me.  I have a question for my Windows XP SP1 stand alone computer.  I have noticed that the default permissions for a User Group account include access to: Internet Options and Administrative Tools.  I am new to configuring Group and User Permissions and XP Security.  What is the easiest way to set the Limited/Non-Admin. accounts to limit their access to 4 specific things: registry editing tools (regedit.exe, regedt32.exe), Internet Options, Adminstration Tools, and the Documents and Settings/UserName/Local Settings and Cookies hidden folders?  Specifically, I do not want non-admin. users to be able to view/change/delete IE History, Temp. Internet files and Cookies nor to make changes/view/change permissions to the registry nor to launch adminstrative tool applications including GPEDIT.MSC from the RUN Command line.  I realize that the OS must be able to access the user's profile but I do not want a user to be able to view these files in explorer.  Is it also possible to prevent User Group members from viewing the Security Tab in Properties for all Folders and Applications without hiding the Security Tab for Adminstrators?

If I used a registry key such as:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableRegistryTools"=dword:00000000
[HKEY_Local_Machine\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableRegistryTools"=dword:00000000

(this may be an inefficient way or wrong way to do this) do I have to be logged in as "Current User" to set this for a non-admin user?  Would this disable registry edit tools for ALL users? (Admin AND Limited) What is the difference betweeen the Current User and Local Machine registry locations and do both locations need the key in order for the change to take affect?

I'm assuming there is an admin tool or security tab approach to doing the all of the above without having to manually edit the registry but can do it if it is the only way.  Do registry edits need a reboot to take affect?

I'm also aware of the following keys:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoSecurityTab"=dword:00000001

and

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Restrictions]
"NoBrowserOptions"=dword:00000000
[HKEY_Local_Machine\Software\Microsoft\Internet Explorer\Restrictions]
"NoBrowserOptions"=dword:00000000


Thanks for your time and any help you can give.
0
Comment
Question by:jgoussy
  • 2
5 Comments
 
LVL 4

Accepted Solution

by:
jcoppin earned 500 total points
ID: 10646666
click start
goto run
type in gpedit.msc


Make the changes in here.
0
 
LVL 12

Expert Comment

by:trywaredk
ID: 10647193
The most easy way, is to make them member of the local guest group, and nothing else.

If they should be able to save files on drive c:, make a share, and grant everyone full control on the share, and then grant write permissions on ntfs.

Builtin and predefined groups in Windows XP
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/prodtechnol/winxppro/proddocs/lsm_local_groups.asp

Understanding NTFS permissions:
http://www.windowsitlibrary.com/Content/592/1.html

Many Regards
Jorgen Malmgren
IT-Supervisor
Denmark

:o) Your brain is like a parachute. It works best when it's open
0
 
LVL 12

Expert Comment

by:trywaredk
ID: 10647207
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

There are several problems reported according slow link speeds or poor performance in TMG 2010, UAG 2010 or ISA 2006. I want to collect here some of the common issues together to give a brief overview what can be the reason. Nevertheless, not all of…
Our Group Policy work started with Small Business Server in 2000. Microsoft gave us an excellent OU and GPO model in subsequent SBS editions that utilized WMI filters, OU linking, and VBS scripts. These are some of experiences plus our spending a lo…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now