Solved

Creating Group Policy

Posted on 2004-04-27
8
709 Views
Last Modified: 2010-04-13
Need a crash course in setting up a Windows2000 system with an administrator profile that has the system "wide open" for configuring by an Administrator and a profile for the user that locks down everything.  Looking at Microsoft documents just isn't working.  I am thinking I can set up Group Policy and apply the user to a group policy but can't figure it out..  

We are on a Novell Network and have 25 Windows 2000 Computers to roll out to our production floor.  
0
Comment
Question by:Trygve Thayer
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
8 Comments
 
LVL 20

Expert Comment

by:What90
ID: 10935068
What are you trying to lock down?
A GPO has over 200 settings

If you could describe what you trying to do, then we could point you in the right direction.
0
 
LVL 11

Accepted Solution

by:
adonis1976 earned 500 total points
ID: 10935185
here are some links that might help

http://www.jsiinc.com/subk/tip5200/rh5237.htm

http://www.oreilly.com/catalog/win2000ads/chapter/ch08.html

How do I distribute Local Group Policy to Windows 2000 clients in a non-Active Directory domain or workgroup?
http://www.jsiinc.com/subh/tip3600/rh3612.htm

Local Group Policy Objects cannot be set on a per-user basis.
http://www.jsiinc.com/sube/tip2300/rh2388.htm

How do I apply local policies to all users, except administrators, on a Windows 2000-based computer that is in a workgroup setting?
http://www.jsiinc.com/subl/tip5600/rh5619.htm

http://www.2000trainers.com/activedirectory/coursesandarticles/jason/70-219-5.html
0
 
LVL 3

Author Comment

by:Trygve Thayer
ID: 10935205
We have user on the manufacturing floor that constantly change the display.....Mess around in control panel, change screen savers, change windows colors, etc.  I am use to policy editor (poledit) on Win95 and Win98.
0
Ransomware: The New Cyber Threat & How to Stop It

This infographic explains ransomware, type of malware that blocks access to your files or your systems and holds them hostage until a ransom is paid. It also examines the different types of ransomware and explains what you can do to thwart this sinister online threat.  

 
LVL 20

Expert Comment

by:What90
ID: 10935268
No comment has been added to this question in more than 21 days, so it is now classified as abandoned.

I will leave the following recommendation for this question in the Cleanup topic area:
   Delete/ No Refund

Any objections should be posted here in the next 4 days. After that time, the question will be closed.

What90
EE Cleanup Volunteer
0
 
LVL 20

Expert Comment

by:What90
ID: 10935295
Whoops, ignore that !

Doing too many things at once.....

The links above posted by  adonis1976 will help.

Basically if you can create and OU and put the trouble machine and users in to that OU, then create a GPO to lock down the machine (GPO setting are very straight forward and easier the NT 4 policies) That'll do the trick.
0
 
LVL 3

Author Comment

by:Trygve Thayer
ID: 10945201
I have been working all day and about have it.  This Microsoft stuff is not as simple as it appears.  The link I have been working from was posted by adonis1976.   I was frustrated but finally realized after I logged all users in with the policy I wanted I needed to log off and back on as administrator before moving the backup policy back in place.  I was doing it all in the same session.  I don't understand how this works but am getting somewhere.  How does the system know what profile the Administrator has and what profile the user has.  I assume the users is comming from c:\winnt\system32\group Policy\user\registry.pol but where is the Administrators comming from ?
0
 
LVL 20

Expert Comment

by:What90
ID: 10945257
GPO are pushed from Active directory not policy files!

You apply GPO to containers not users, groups or computers

The Don't apply GPO to the default containers (Computer and Users) but create new one (Factory) and apply the GPO to that.

Then move the users and computers you want the GPO to effect in to th new factory container.

Log out the users in the new factory container and log them back in for the GPO to work.
0
 
LVL 3

Author Comment

by:Trygve Thayer
ID: 10983253
I have been able to take a Windows 2000 stand-alone system and set it up so that when I login as administrator I have full rights.  When I log in as one of the other users they are now locked down so tight they have given up in only one day.  Yea!!!!!    I am awarding  adonis1976  with the points as one of the links gave me the exact information I needed.
0

Featured Post

Get 15 Days FREE Full-Featured Trial

Benefit from a mission critical IT monitoring with Monitis Premium or get it FREE for your entry level monitoring needs.
-Over 200,000 users
-More than 300,000 websites monitored
-Used in 197 countries
-Recommended by 98% of users

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
There are times when I have encountered the need to decompress a response from a PHP request. This is how it's done, but you must have control of the request and you can set the Accept-Encoding header.
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
If you’ve ever visited a web page and noticed a cool font that you really liked the look of, but couldn’t figure out which font it was so that you could use it for your own work, then this video is for you! In this Micro Tutorial, you'll learn yo…

634 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question