Announcement

Collapse
No announcement yet.

GPO Settings for blocking User Access

Collapse
X
  • Filter
  • Time
  • Show
Clear All
new posts

  • GPO Settings for blocking User Access

    Hi ,

    We are using SBS 2000, we do have a AD implemented in our domain ...GPO is also implemented for strong password ,.,Now i want to implement the settings in GPO so that user can not add/remove a program but atleaset start stop the installed programs service e.g MySQL server ....also they should not be to access registry settings by start-run-cmd-regedit .....

    so how can i implement this via GPO...

    Please help ....

  • #2
    Re: GPO Settings for blocking User Access

    Remove admin privileges from the users (users shouldn't be admins). If necessary, modify the permissions on the relevant services to allow standard users to be able to start and stop them.

    Using group policy, you can modify the permissions on services (System Services) and control who is a member of the local administrators group (Restricted Groups) under Computer > Windows Settings. Don't forget to also make sure the users aren't domain admins.
    Gareth Howells

    BSc (Hons), MBCS, MCP, MCDST, ICCE

    Any advice is given in good faith and without warranty.

    Please give reputation points if somebody has helped you.

    "For by now I could have stretched out my hand and struck you and your people with a plague that would have wiped you off the Earth." (Exodus 9:15) - I could kill you with my thumb.

    "Everything that lives and moves will be food for you." (Genesis 9:3) - For every animal you don't eat, I'm going to eat three.

    Comment


    • #3
      Re: GPO Settings for blocking User Access

      Hi ,

      Thanks for providing tips ..now one more thing i want to know is how to block all web sites accept 2-3 for a specific OU ..using GPO. I know

      http://forums.petri.com/showthread.php?t=20198

      but if suppose i want to block all sites expect yahoo for marketing OU is it possible via gpo ...

      Also some times my users in domain delete the files from c:\windows\ or c:\windws\system32 ...so how can i prevent it ...

      Please help ....


      Thanks ...

      Comment


      • #4
        Re: GPO Settings for blocking User Access

        Originally posted by nehanda View Post
        Also some times my users in domain delete the files from c:\windows\ or c:\windws\system32 ...so how can i prevent it ...
        Don't make them administrators.

        Originally posted by nehanda View Post
        Thanks for providing tips ..now one more thing i want to know is how to block all web sites accept 2-3 for a specific OU ..using GPO
        You need a proxy server. Use Group Policy to configure IE to use the proxy.
        Gareth Howells

        BSc (Hons), MBCS, MCP, MCDST, ICCE

        Any advice is given in good faith and without warranty.

        Please give reputation points if somebody has helped you.

        "For by now I could have stretched out my hand and struck you and your people with a plague that would have wiped you off the Earth." (Exodus 9:15) - I could kill you with my thumb.

        "Everything that lives and moves will be food for you." (Genesis 9:3) - For every animal you don't eat, I'm going to eat three.

        Comment

        Working...
        X