[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

Public computer browsing a domain

Posted on 2004-07-30
5
Medium Priority
?
259 Views
Last Modified: 2013-12-04
I am setting up a publicly accessed computer that is a member of my W3K Domain. How do I stop the user account that logs onto this computer from browsing the domain or accessing domain resources. I have locked down the account with a GPO with a read only profile?
0
Comment
Question by:fsaiexpert
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 4

Accepted Solution

by:
WerewolfTA earned 189 total points
ID: 11677438
What are you trying to keep them from getting to?  What have you already locked down with your gpo?

Just some ideas:

Remove all physical removable media drives (floppy, cd-rom)
Disable USB ports in BIOS and set a BIOS password
If you don't want them to access the Internet through your gateway, set a bogus gateway
Remove access to their network connections from the desktop and control panel
remove the run command
Prevent them from browsing the network places
Hide the C drive under My Computer
if you don't wan them to print to your network printers, prevent them from adding new printers
make the user who logs on a guest, deny guests from accessing your resources (the everyone group under 2k3 does not include the guests group by default)

And on and on.  It depends on what you need them to do with that computer (give them the minimum set of permissions necessary to do what you want them to do) and what you specifically want to keep them out of.
0
 
LVL 38

Assisted Solution

by:Rich Rumble
Rich Rumble earned 186 total points
ID: 11687619
Does the computer need to access file or print shares? If not... You could turn off File and Print Sharing to prevent the computer from accessing others PC's, the browsing is a bit harder to get rid off, you may try diabling NETBIOS over TCP/IP- but the "client for M$ windows" must stay enabled for AD to function on that PC... however, if you do disable it... and the Policy has been applied previously- it will not "un-apply" until told to do so by AD... so the current policy will stay in place, until Client for M$ is turned back on, and a new policy from AD is applied.
-rich
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Many of us in IT utilize a combination of roaming profiles and folder redirection to ensure user information carries over from one workstation to another; in my environment, it was to enable virtualization without needing a separate desktop for each…
Our Group Policy work started with Small Business Server in 2000. Microsoft gave us an excellent OU and GPO model in subsequent SBS editions that utilized WMI filters, OU linking, and VBS scripts. These are some of experiences plus our spending a lo…
In this video, Percona Solutions Engineer Barrett Chambers discusses some of the basic syntax differences between MySQL and MongoDB. To learn more check out our webinar on MongoDB administration for MySQL DBA: https://www.percona.com/resources/we…
This lesson discusses how to use a Mainform + Subforms in Microsoft Access to find and enter data for payments on orders. The sample data comes from a custom shop that builds and sells movable storage structures that are delivered to your property. …
Suggested Courses

656 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question