Re: Screensaver lockout in Group Policy

From: Kevin Sullivan (ksullivan_at_autoprof.com)
Date: 09/29/04


Date: Wed, 29 Sep 2004 08:51:51 -0400

Craig,

What exact policy setting are you working with? Please specify the path. But
off of the top of my head I think you are saying you 'lock the workstation'
after so much time. This will not 'logoff' the user. In other words work in
process will not be lost. They just have to supply the credentials to
'unlock' the system.

In policy you have "Hide Screen Saver", which hides the screen saver tab
from the display control panel. You have "Screen Saver", which simply
enables the screen saver. You have "Screensaver executable name" self
explanatory. Another is "Password protect the screen saver" this means that
when a screen saver is activeated in order to get back to your system you
must supply your password (I think this is the one you are talking about?).
Another is "Screensaver timeout", this is how much time the system is idle
before lauching the screensaver. And you have "Allow screen saver during
playback", this one is realted to Windows Media Player I believe and it
simply says while WMP is running the screen saver can activate.

So unless you are using the logoff.scr from the resource kit or another
solution to actually logoff a system after an idle period than no users are
negatively affected by the setting. If you are logging off the user than you
so run the risk of losing work depending on how you are doing this. If you
are using the logoff.scr you will need to deploy this file to all systems
who are configured to run it. Deployment of files is not available
functionality with any of Microsoft's 11 extensions. The method for
deployment/distribution of the file needs to be something like a script,
SMS, LanDesk whatever mechanism you use. To truly move data around, transfer
files, collect files etc. through Group Policy you would need to use
something like the file extension that we provide with Policy Maker.

Hope that helps...

Kevin
AutoProf
http://www.autoprof.com/policy
"Craig" <anonymous@discussions.microsoft.com> wrote in message
news:153501c4a619$d1182430$a601280a@phx.gbl...
> Hi.
>
> I am going to be implementing a group policy where if a
> users pc is unattended for at least 30 min, the
> screensaver lockout policy will lock their workstation
> and that they will have to log back in after it has taken
> affect. But my question is this:
> If it locks the user out, and if the user has processes
> running in the background, applications open,
> applications that chamge pages, will they get affected? I
> really don't want to apply this policy and have a machine
> stop running these apps and processes when it locks out
> the person.
>
> Could somebody please give me some insight to this, as I
> would like to do this today.
>
> Thanks much
>
> Craig



Relevant Pages

  • RE: Best Practice for Screen Savers
    ... but how do you enforce such a policy? ... forgetting to log out or lock their computer is a tad harsh for most ... For these reasons we have the ploicy that everybody has ... > set my companies screen saver password timeout to. ...
    (Security-Basics)
  • Re: Loopback processing not working
    ... Well you could just deny the right to apply the policy for the screen saver ... I understand that loopback processing within a policy is the route to go ... Policy Setting ... Password protect the screen saver Enabled ...
    (microsoft.public.windows.server.active_directory)
  • Re: Reverting GPO settings back to Default
    ... Well, keep in mind that Screen Saver policy is per-user, so if the user account isn't moving to a different OU as well, then nothing is going to change for that user, regardless of where their laptop computer account resides. ... Speed Group Policy Troubleshooting with the NEW GPHealth Reporter tool at http://www.sdmsoftware.com/products.php ...
    (microsoft.public.windows.group_policy)
  • RE: ScreenSaver timeout problem via GPO
    ... Number of Seconds to wait to enable the Screen Saver = Enabled at 0 Seconds ... give you some facts about these laptops so you know the situation. ... This policy is not enforced so if a lower OU blocks inheritance it ... loopback processing and it would still run if in the correct order. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Automated logoff using Winexit.scr
    ... If a non-administrative user attemps to use the WinExit screen saver, ... You can use RegDACL to set these permissions in batch. ... are not servers in our domain. ... I have tried creating a group policy ...
    (microsoft.public.windows.group_policy)