Solved

GPO to lock down computers in a computer Lab

Posted on 2016-10-12
7
55 Views
Last Modified: 2016-11-06
I would like to know in detail if possible which gpo policys i need to change to lock down a pc.
Here is a list of things i would like to do. I would like this to be applied mainly for the "Student" user account.
IF you think i should add more please add them to the list
1.  Icons on the desktop cant be deleted.
2. When they click on start button they can only reboot.
3. IE, Chrome and Firefox, Office and Adobe Reader are allowed.
4. Task manager is disabled.
5. No Right Clicking on desktop so that cant modify background or create shortcuts.
5. Student account cant save any files to desktop and removable usb drives and optical are disabled.

thanks
0
Comment
Question by:noclav
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
7 Comments
 
LVL 7

Expert Comment

by:No More
ID: 41840456
1, Well are those computers use by different users than just Students?

2, Depending on point one to choose combination of user and computer GPO

3, For desktop icons, you could create share folder with icons they only need and redirect it using folder redirection and with not allow change in policy and only read and execute permission for share folder to specific group/users

4, Use Applocker policy to while list those apps, also if you remove Local Administrator rights from students they won't be able to install program anyway

5, Removable devices and task manager is the easy part

Let me know how these computers will be used  and how tight security you want to apply
0
 
LVL 7

Accepted Solution

by:
No More earned 500 total points
ID: 41840474
Remove Task manager - This policy setting prevents users from starting Task Manager.
USER Conf. /admin templates - System-ctrl-alt-delete - remove task manager

Removable storage access - If you enable this policy setting, no access is allowed to any removable storage class.
User Conf. /admin templates - System - Removable storage access  - All Removable storage classes: deny all access

User Conf. / admin templates -Desktop - Desktop Prohibit changes,  - More options here choose

User conf. / Admin Templates - Start menu and Taskbar = you will find a lot of policy options for your needs
0
 

Author Comment

by:noclav
ID: 41840482
thanks for the reply only one user account is used on this computer named "Student" This is a small school with out 3 computers in the lab. I would like to lock this down as much as possible as i am a part time IT guy for them. Less headaches for me the better. They only use the computers mainly for testing. so there is software that i installed for state testing.
0
 
LVL 7

Expert Comment

by:No More
ID: 41840494
And also User Conf. / control panel - Personalization -  Prevent changing ( multiple options)


Are you deploying that software through group policy ?


Group policy has a lot of options
0
 

Author Comment

by:noclav
ID: 41840504
at the moment im not pushing software from GPO i would like to but need to test that. For now i just install it.
0

Featured Post

The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Assume you have an outside contractor who comes in seasonally or once a week to do some work in your office, but you only want to give him access to the programs and files he needs and keep all other documents and programs private. Can you do this o…
When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…
If you’ve ever visited a web page and noticed a cool font that you really liked the look of, but couldn’t figure out which font it was so that you could use it for your own work, then this video is for you! In this Micro Tutorial, you'll learn yo…
Suggested Courses

623 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question