Solved

Public computer browsing a domain

Posted on 2004-07-30
5
253 Views
Last Modified: 2013-12-04
I am setting up a publicly accessed computer that is a member of my W3K Domain. How do I stop the user account that logs onto this computer from browsing the domain or accessing domain resources. I have locked down the account with a GPO with a read only profile?
0
Comment
Question by:fsaiexpert
5 Comments
 
LVL 4

Accepted Solution

by:
WerewolfTA earned 63 total points
ID: 11677438
What are you trying to keep them from getting to?  What have you already locked down with your gpo?

Just some ideas:

Remove all physical removable media drives (floppy, cd-rom)
Disable USB ports in BIOS and set a BIOS password
If you don't want them to access the Internet through your gateway, set a bogus gateway
Remove access to their network connections from the desktop and control panel
remove the run command
Prevent them from browsing the network places
Hide the C drive under My Computer
if you don't wan them to print to your network printers, prevent them from adding new printers
make the user who logs on a guest, deny guests from accessing your resources (the everyone group under 2k3 does not include the guests group by default)

And on and on.  It depends on what you need them to do with that computer (give them the minimum set of permissions necessary to do what you want them to do) and what you specifically want to keep them out of.
0
 
LVL 38

Assisted Solution

by:Rich Rumble
Rich Rumble earned 62 total points
ID: 11687619
Does the computer need to access file or print shares? If not... You could turn off File and Print Sharing to prevent the computer from accessing others PC's, the browsing is a bit harder to get rid off, you may try diabling NETBIOS over TCP/IP- but the "client for M$ windows" must stay enabled for AD to function on that PC... however, if you do disable it... and the Policy has been applied previously- it will not "un-apply" until told to do so by AD... so the current policy will stay in place, until Client for M$ is turned back on, and a new policy from AD is applied.
-rich
0

Featured Post

Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

As I write this article, I am finishing cleanup from the Qakbot virus variant found in the wild on April 18, 2011.  It was a messy beast that had varying levels of infection, speculated as being dependent on how long it resided on the infected syste…
Users of Windows 10 Professional can disable automatic reboots using the policy editor. This tool is not included in the Windows home edition. But don't worry! Follow the instructions below to install (a Win7) policy editor on your Windows 10 Home e…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
Although Jacob Bernoulli (1654-1705) has been credited as the creator of "Binomial Distribution Table", Gottfried Leibniz (1646-1716) did his dissertation on the subject in 1666; Leibniz you may recall is the co-inventor of "Calculus" and beat Isaac…

773 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question