Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Windows 8 in the field, how to lock down

Posted on 2013-01-26
3
932 Views
Last Modified: 2013-02-18
Hi we are looking to deploy some Windows 8 tablets to our field staff to use the following

- Basic Email/Calendar (Using inbuilt mail/calendar apps)
- Filtereted Internet Access
- Remote desktop access via our gateway (using the inbuilt tool mstsc)
- Basic Office apps (word, excel)

As this is for some of our outdoor guys, it needs to be locked down to avoid any possible resource abuse.

I am needing to perform the following

1)  Lockdown the OS (In the form of a local group policy that dosnt apply to the admin acc) have the metro bar locked down
2) Maintain the computers (Thinking of Windows Intune for this)
3) Route all internet through a filtered proxy of some sort (OpenDNS with Dynamic IP client) or throught Sophos (we are a sophos house) using their external web client filter
4) Have a form of remote access to the machines (we will use our existing logmein for this)

So, seeking your advise/thoughts on the first three challenges?

Id like to configure my reference VM, then capture it
0
Comment
Question by:wsc-it
3 Comments
 
LVL 54

Expert Comment

by:McKnife
ID: 38824939
Hi.

If I were you, I would split this question into 4 smaller ones, each in a suitable forum. ee-guidelines advise so, too.
0
 
LVL 37

Expert Comment

by:ArneLovius
ID: 38829178
I would add encryption to the mix.
0
 
LVL 44

Accepted Solution

by:
Jackie Man earned 500 total points
ID: 38833804
My initial feedback to your questions are as follows:-

1)  Lockdown the OS (In the form of a local group policy that dosnt apply to the admin acc) have the metro bar locked down
What do you mean by lockdown? Do you mean Kiosk mode?
If yes, the info below might be useful for you.
According to Knuckle-Dragger, it says:-
...Depends on your definition of 'kiosk'.
Actually, you don't seem to be looking for a true kiosk, so it might be easy for you.   FYI, you don't need third party app to run a task at start-up.  
1)  Can throw a link/shortcut in your users or the shared start up folder. or
2)  There is a Group Policy logon script folder in system32 or
3)  Can alternatively use a scheduled task to pop your application
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp
C:\Users\[User]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
C:\Windows\System32\GroupPolicy\User\Scripts\Logon
Here is a similar thread about getting an app to pop at startup.
http://social.technet.microsoft.com/Forums/en-US/w8itproinstall/thread/0065fc23-2578-4165-8f38-c22675ae33ad
Source: http://social.technet.microsoft.com/Forums/en/w8itproinstall/thread/2f52d7ef-8597-43c1-9a36-7a69c4966091
2) Maintain the computers (Thinking of Windows Intune for this)
Intune can do but you need to integrate with System Center 2012 Configuration Manager in order to use it.
I will recommend zenprise as it is the market leader in mobile device management.
http://www.zenprise.com/company/news_and_events/press_releases/zenprise-announces-support-for-windows-8-windows-rt-windows-phone-81
3) Route all internet through a filtered proxy of some sort (OpenDNS with Dynamic IP client) or throught Sophos (we are a sophos house) using their external web client filter
Sophos UTM client is compatible with Windows 8.
4) Have a form of remote access to the machines (we will use our existing logmein for this)
There are many tools to perform the remote access function such as teamviewer, but it seems that logmein have a problem with Windows 8. Personally, I will try zenprise as I recalled from a seminar that remote admin and assistance is one of the zenprise's features.
0

Featured Post

U.S. Department of Agriculture and Acronis Access

With the new era of mobile computing, smartphones and tablets, wireless communications and cloud services, the USDA sought to take advantage of a mobilized workforce and the blurring lines between personal and corporate computing resources.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Ever wondered why Windows 8 and 10 don't seem to accept your GPO-based software deployment while Windows 7 does? Read on.
No matter the version of Windows you are using, you may have some problems with Windows Search running too slow or possibly not running at all. Before jumping into how you can solve this issue, just know there are many other viable alternative deskt…
The viewer will learn how to create a normally distributed random variable in Excel, use a normal distribution to simulate the return on an investment over a period of years, Create a Monte Carlo simulation using a normal random variable, and calcul…
This Micro Tutorial will teach you how to reformat your flash drive. Sometimes your flash drive may have issues carrying files so this will completely restore it to manufacturing settings. Make sure to backup all files before reformatting. This w…

837 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question