Solved

Public computer browsing a domain

Posted on 2004-07-30
5
256 Views
Last Modified: 2013-12-04
I am setting up a publicly accessed computer that is a member of my W3K Domain. How do I stop the user account that logs onto this computer from browsing the domain or accessing domain resources. I have locked down the account with a GPO with a read only profile?
0
Comment
Question by:fsaiexpert
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 4

Accepted Solution

by:
WerewolfTA earned 63 total points
ID: 11677438
What are you trying to keep them from getting to?  What have you already locked down with your gpo?

Just some ideas:

Remove all physical removable media drives (floppy, cd-rom)
Disable USB ports in BIOS and set a BIOS password
If you don't want them to access the Internet through your gateway, set a bogus gateway
Remove access to their network connections from the desktop and control panel
remove the run command
Prevent them from browsing the network places
Hide the C drive under My Computer
if you don't wan them to print to your network printers, prevent them from adding new printers
make the user who logs on a guest, deny guests from accessing your resources (the everyone group under 2k3 does not include the guests group by default)

And on and on.  It depends on what you need them to do with that computer (give them the minimum set of permissions necessary to do what you want them to do) and what you specifically want to keep them out of.
0
 
LVL 38

Assisted Solution

by:Rich Rumble
Rich Rumble earned 62 total points
ID: 11687619
Does the computer need to access file or print shares? If not... You could turn off File and Print Sharing to prevent the computer from accessing others PC's, the browsing is a bit harder to get rid off, you may try diabling NETBIOS over TCP/IP- but the "client for M$ windows" must stay enabled for AD to function on that PC... however, if you do disable it... and the Policy has been applied previously- it will not "un-apply" until told to do so by AD... so the current policy will stay in place, until Client for M$ is turned back on, and a new policy from AD is applied.
-rich
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In today's information driven age, entrepreneurs have so many great tools and options at their disposal to help turn good ideas into a thriving business. With cloud-based online services, such as Amazon's Web Services (AWS) or Microsoft's Azure, bus…
No security measures warrant 100% as a "silver bullet". The truth is we also cannot assume anything but a defensive and vigilance posture. Adopt no trust by default and reveal in assumption. Only assume anonymity or invisibility in the reverse. Safe…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
Monitoring a network: how to monitor network services and why? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the philosophy behind service monitoring and why a handshake validation is critical in network monitoring. Software utilized …

695 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question