Solved

I would like to disable the run menu for all my users on my network, except for the administrator.  How do i do that?

Posted on 2006-07-24
10
194 Views
Last Modified: 2013-12-04
Hello,

I would like to disable the RUN menu for the startup menu for all my network users.  At the same time leaving the access available for the administrator only.

How do i accomplish that?
thanks you for your assistance.

0
Comment
Question by:dominicait
10 Comments
 
LVL 5

Expert Comment

by:floorman67
ID: 17168321
Group Policy Editor (XP Professional, Server 2003, NT, 2000, 2000 server)

here are some interesting links on it i googled http://www.google.com/search?hl=en&lr=&q=remove+RUN+command
0
 
LVL 5

Expert Comment

by:floorman67
ID: 17168333
you can do it through the registry of your win.ver doesnt support a policy editor
0
 
LVL 1

Expert Comment

by:rimba_
ID: 17176389
Hi,

on the GPO (group policy object) of the group u want to disable the run as.. go to:
User configuration -> Administrative Templates ->Start Menu & Toolbar, In the right panel find "Remove Run from start menu", double click on it and choose enable

i hope this helps
0
Use Case: Protecting a Hybrid Cloud Infrastructure

Microsoft Azure is rapidly becoming the norm in dynamic IT environments. This document describes the challenges that organizations face when protecting data in a hybrid cloud IT environment and presents a use case to demonstrate how Acronis Backup protects all data.

 

Author Comment

by:dominicait
ID: 17176779
Hey Rimba,

granted what you have contributed has made the most logical answer what i was looking for however, is to exclude the administrators from this setting.

What i have gathered thus far is that i need to create a new group of users with only those that i want affected by this new policy, however what i don't understand, and others out there reading this may also want to ship in, is how do i set this policy to only affect the users that i choose.  Please note that i don't want it to affect all my users, only a select few.

Thanks for your inputs thus far.

regards.
0
 
LVL 1

Accepted Solution

by:
rimba_ earned 125 total points
ID: 17176926
2 options: you add a gpo for the administrator where u disable this option, or you enable oit on the computer itself (on each user u want to forbid this) for the second option you could create a value on the registry:

In: HKEY_CURRENT_USER
Key: Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Name: NoRun
Type: REG_DWORD
Value: 1
0
 
LVL 1

Expert Comment

by:butterrfly
ID: 17204340
If you're in a workgroup then I don't think you can choose which users the policy will apply to. However, you can do the reverse: choose the users you DON'T want to be affected by the policy:

1. Use Local Group Policy and set the policy to remove it from the Start Menu, as Rimba had suggested.
2. Set Deny permissions to Administrators on the hidden folder %systemroot%\system32\GroupPolicy (or anyone you don't want the policy to apply to)
*All other users will be affected

It's easier if it's in a domain:
Link the GPO to the OU/container where the affected user objects are stored
-or- set permissions on the GPO and allow only the users you choose
0
 
LVL 1

Expert Comment

by:rimba_
ID: 17402472
i trhink doing the gpo deny option and the allow it to the admin is the easier way to solve this.
0

Featured Post

Live: Real-Time Solutions, Start Here

Receive instant 1:1 support from technology experts, using our real-time conversation and whiteboard interface. Your first 5 minutes are always free.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In a recent article here at Experts Exchange (http://www.experts-exchange.com/articles/18880/PaperPort-14-in-Windows-10-A-First-Look.html), I discussed my nine-month sandbox testing of the Windows 10 Technical Preview, specifically with respect to r…
Recently, I read that Microsoft has analysed statistics for their security intelligence report. It revealed: still, the clear majority of windows users do their daily work as administrator. An administrative account is a burden, security-wise. My ar…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now