Solved

Restrict application and internet access to a single workstation

Posted on 2010-11-21
12
550 Views
Last Modified: 2012-06-27
Hi Experts.

I was hoping for some advice for setting up a single public computer (in a children's orthodontic clinic) with access to one proprietary full-screen application (that requires internet access to one site).  The computer is basically dedicated to this application.

The computer is a HP 6000 Pro all-in-one running Windows 7 Pro (on a server 2008 domain).

In the past, I have tried a similar setup on a Dell touchscreen all-in-one PC running Arlington Kiosk Browser but the children were always able to 'sidestep' the in-built security measures.  We don't want them exiting the app and opening IE (for example).

There has been a suggestion of additionally restricting access by limiting things by DNS, but this is only a partial solution.

I know that I could script the application to open on login etc and create a restricted user on the domain, but I was hoping for some experienced folks to point me in the right direction.

Thanks everyone!
Aaron.
0
Comment
Question by:Aaronazz
  • 4
  • 3
  • 2
  • +1
12 Comments
 

Assisted Solution

by:Aaronazz
Aaronazz earned 0 total points
Comment Utility
I am going to try to create a new user on the server with limited permissions, script the app to load on login and limit access to the app only if I can work out how.  I've not needed to do much with group policy in the past.
0
 
LVL 66

Assisted Solution

by:johnb6767
johnb6767 earned 249 total points
Comment Utility
Windows SteadyState
http://www.microsoft.com/windows/products/winfamily/sharedaccess/default.mspx

 I use the ADM templates to create a GPO to manage the same settings. They are included with theinstallation of this app.
Lock it down using GPO, amd assign it to this PC. Can disable most anything. You can specify what sites are allowed via the proxy in IE.
0
 
LVL 66

Assisted Solution

by:johnb6767
johnb6767 earned 249 total points
Comment Utility
Oh, and yes, these similar features are already in GPO, but here they are all; included in a simple, easy to find location in a single ADM file....

Also, in the registry......

Change "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon", "Shell" value to your application.
In the same key, make sure that "AutoRestartShell" (DWORD) is also set to 0x1.....

That way, instead of a user's desktop, they get your app.....
0
 
LVL 7

Accepted Solution

by:
D_Vante earned 84 total points
Comment Utility
I think if you create two batch files and put the first one in the startup folder or the login and have the second one, HomeScreen.bat, call your app.
  The first one will wait for the second batch file to finish, then it will restart the computer and start over again.  Endless loop unless you escape out of it.


First Batch file

start /wait cmd /C "c:\batch\HomeScreen.bat"

c:\shutdown -r -f

0
 
LVL 47

Assisted Solution

by:dlethe
dlethe earned 167 total points
Comment Utility
Pretty much every router you can buy has a built-in firewall that can restrict traffic to machines with certain mac addresses in the NIC.  I would just do the work in the router.  
0
Are end users causing IT problems again?

You’ve taken the time to design and update all your end user’s email signatures, only to find out they’re messing up the HTML, changing the font and ruining the imagery. What can you do to prevent this? Find out how you can save your signatures from end users today.

 
LVL 66

Assisted Solution

by:johnb6767
johnb6767 earned 249 total points
Comment Utility
Any update?
0
 

Assisted Solution

by:Aaronazz
Aaronazz earned 0 total points
Comment Utility
Sorry there hasn't been an update.  I am waiting for after hours access to the machine to try the suggestions.  Thanks everyone for the input, I'll let you know how I got with it.

Aaron.
0
 

Assisted Solution

by:Aaronazz
Aaronazz earned 0 total points
Comment Utility
Sorry, no update yet.  I will post as soon as I can properly test.

Thanks again everyone.
0
 
LVL 47

Assisted Solution

by:dlethe
dlethe earned 167 total points
Comment Utility
Well all experts gave correct and valid information, as there are many ways to attack the problem.  I say split points evenly between experts who spent their time to answer the question.   There really is nothing here to "test", all are straightforward.
0
 

Author Closing Comment

by:Aaronazz
Comment Utility
Sorry, I'm still getting the hang of EE.  I asked the question when the issue was a higher priority, then the user requirements changed slightly delaying me from testing solutions.  Thanks for all who offered assistance.  I will use the suggestions, but I just can't put a time on it.
0

Featured Post

Are end users causing IT problems again?

You’ve taken the time to design and update all your end user’s email signatures, only to find out they’re messing up the HTML, changing the font and ruining the imagery. What can you do to prevent this? Find out how you can save your signatures from end users today.

Join & Write a Comment

New Windows 7 Installations take days for Windows-Updates to show up and install. This can easily be fixed. I have finally decided to write an article because this seems to get asked several times a day lately. This Article and the Links apply to…
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This Micro Tutorial will teach you how to change your appearance and customize your Windows 7 interface to your unique preference. This will be demonstrated using Windows 7 operating system.
This Micro Tutorial will go in depth within Systems and Security in Windows 7 and will go into detail regarding Action Center, Windows Firewall, System, etc. This will be demonstrated using Windows 7 operating system.

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now