?
Solved

Best practice for locking down Windows 7 OS for image deployment (SOE)

Posted on 2012-09-13
9
Medium Priority
?
905 Views
Last Modified: 2012-09-26
There are 2 questions for this.

1. What is the best practice for creating a Windows 7 Image for deployment. Eg Locking down the OS, Sysprep, Capture and deploy. Basically any changes made to lock down the OS need to be retained in the image. My understanding is that after running sysprep, many of the changes made are reverted back to default.

2. What is the best "Freeware" imaging product. 95% of our clients are Thin clients, so we only really need to image laptops from time to time.
0
Comment
Question by:Howzatt
  • 4
  • 4
9 Comments
 
LVL 22

Assisted Solution

by:Rick Hobbs
Rick Hobbs earned 400 total points
ID: 38399895
If you use sysprep, all lockdown choices are gone.

best free imager: Macrium Reflect Free Edition
0
 
LVL 84

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 1600 total points
ID: 38400391
making images for deployment, legally requires sysprep and volume media to create the master image.

You may disagree with, find another way of doing it but in doing so you are violating the terms of licensing agreement between you and Microsoft. You have been warned.
0
 

Author Comment

by:Howzatt
ID: 38408121
Understood, so Legally I cannot lock down an image?
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 84

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 1600 total points
ID: 38408367
I use Windows Post Install unless the systems are on a domain in which i use group policy

In the post install wizard I add all of the registry entries that need to be modified.
0
 

Author Comment

by:Howzatt
ID: 38408405
Post install tasks seem to be the go.

Anywhere i can find a list of recommended post install tasks? I can pick out which I will use.
0
 
LVL 84

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 1600 total points
ID: 38412707
What do you want locked down or installed? Each situation is entirely different. Other than installing windows updates and Microsoft Security Essentials.. Windows 7 is a pretty secure operating system.. use a product like Macecraft jv16 tools and capture the registry.. do your customization then capture the registry again.. compare the differences and put the registry changes into either 1 .reg file or a bunch of .reg files and then script it to install each registry file..

You may want to run sysprep.. then at the oobe logon press shift-ctrl-f3 to get into administrative mode now capture the registry and compare the differences between the customized system and the sysprep'd system.. this will show you what customizations did not make it past the sysprep.
0
 

Author Comment

by:Howzatt
ID: 38420110
Thanks for that. I am not sure exactly what I want to lock down at this stage.

Mainly just want to make the laptop a thin client for the users to run their Citrix Published Desktops on. But woud also like to keep some element of functionality on their local PC too.

My plan was to review the best practices and work from there.
0
 
LVL 84

Accepted Solution

by:
David Johnson, CD, MVP earned 1600 total points
ID: 38420472
It comes installed with all best practices enabled. What is a best practice and what works under ALL circumstances can come into conflict.

Keep UAC turned on and run all users as STANDARD users is about the most effective best practice for user desktops
0
 

Author Comment

by:Howzatt
ID: 38430826
I am sure it is already loaded with the best practices. However I am sure there must be a list out there somewhere of recommended policies etc for me to work from?
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

First some basics on Windows 7 Backup.  It has 2 components one is a file based backup which is stored in .zip files each zip is split at around 200 Megabytes and there is the Image Backup which is as the name implies a total image of the partition …
There are many software programs on offer that will claim to magically speed up your computer. The best advice I can give you is to avoid them like the plague, because they will often cause far more problems than they solve. Try some of these "do it…
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
This Micro Tutorial will teach you how to change your appearance and customize your Windows 7 interface to your unique preference. This will be demonstrated using Windows 7 operating system.
Suggested Courses

864 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question