Solved

Locking Down XP

Posted on 2004-10-19
5
155 Views
Last Modified: 2013-12-04
I am updating a number of business PC's to XP Pro. This seems like a good time to increase security. I want to know if I can use group policy to prevent users (or hackers) from installing programs or visiting unapproved websites. These users only need to visit 4 or 5 business related sites, and I can install any needed programs with the "install as" option.   Thanks
0
Comment
Question by:mr_kev
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 18

Accepted Solution

by:
luv2smile earned 100 total points
ID: 12360946
The first step would be to not grant them admin rights....most programs require admin rights to install

There are software restriction policies that you can set up with group policy, but here's the thing: You either have to 1.  block all programs except ones that you specify or 2.  know the programs you wish to block.

http://support.microsoft.com/default.aspx?scid=kb;en-us;324036

1. is very hard to setup and is often full of problems, etc. and takes a long time to perfect.
0
 
LVL 16

Assisted Solution

by:kbbcnet
kbbcnet earned 100 total points
ID: 12440343
Make everyone other than you part of the "Users" group, not "Power User" or "Administrator" groups.  This way they can't install programs; however, this will not stop all installations, such as screensavers, wallpapers, spyware, etc.

The MS article referenced above is also a good starting point, however complex to implement.  

You may want to try a third party solution to assist you in this task such as "Deep Freeze" by Faronics.  See their webpage - http://www.faronics.com/.  This product will basically make an image of the PC's O/S then restore it everytime you reboot....no installation crap to worry about then; just reboot it.

There are a number of internet content filtering products out there for blocking access to various websites.  They typically include 'black lists' for bad sites and 'white lists' for approved sites.  Most of these programs allow you to specify 'custom' lists of webpages you want to deny access to.

Good luck!
0

Featured Post

Transaction Monitoring Vs. Real User Monitoring

Synthetic Transaction Monitoring Vs. Real User Monitoring: When To Use Each Approach? In this article, we will discuss two major monitoring approaches: Synthetic Transaction and Real User Monitoring.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

No security measures warrant 100% as a "silver bullet". The truth is we also cannot assume anything but a defensive and vigilance posture. Adopt no trust by default and reveal in assumption. Only assume anonymity or invisibility in the reverse. Safe…
Security measures require Windows be logged in using Standard User login (not Administrator).  Yet, sometimes an application has to be run “As Administrator” from a Standard User login.  This paper describes how to create a shortcut icon to launch a…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Monitoring a network: how to monitor network services and why? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the philosophy behind service monitoring and why a handshake validation is critical in network monitoring. Software utilized …

724 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question