XP Security Policies for User Group
Posted on 2004-03-21
This is lengthy but please bear with me. I have a question for my Windows XP SP1 stand alone computer. I have noticed that the default permissions for a User Group account include access to: Internet Options and Administrative Tools. I am new to configuring Group and User Permissions and XP Security. What is the easiest way to set the Limited/Non-Admin. accounts to limit their access to 4 specific things: registry editing tools (regedit.exe, regedt32.exe), Internet Options, Adminstration Tools, and the Documents and Settings/UserName/Local Settings and Cookies hidden folders? Specifically, I do not want non-admin. users to be able to view/change/delete IE History, Temp. Internet files and Cookies nor to make changes/view/change permissions to the registry nor to launch adminstrative tool applications including GPEDIT.MSC from the RUN Command line. I realize that the OS must be able to access the user's profile but I do not want a user to be able to view these files in explorer. Is it also possible to prevent User Group members from viewing the Security Tab in Properties for all Folders and Applications without hiding the Security Tab for Adminstrators?
If I used a registry key such as:
(this may be an inefficient way or wrong way to do this) do I have to be logged in as "Current User" to set this for a non-admin user? Would this disable registry edit tools for ALL users? (Admin AND Limited) What is the difference betweeen the Current User and Local Machine registry locations and do both locations need the key in order for the change to take affect?
I'm assuming there is an admin tool or security tab approach to doing the all of the above without having to manually edit the registry but can do it if it is the only way. Do registry edits need a reboot to take affect?
I'm also aware of the following keys:
Thanks for your time and any help you can give.