Re: Locking down a Local User in XP Pro Sp 1

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Mr K N Cowans (manager_at_armthorpe.doncaster.sch.uk)
Date: 06/16/04

  • Next message: Felix Roth: "administrative template for autologon"
    Date: Wed, 16 Jun 2004 08:01:29 +0100
    
    

    Hello Mark

    Thanks for the suggestions.

    The reason I want to be able to do this is that these Laptops are used by
    pupils.

    It is fine when they are connected to the Network as the Domain Policy is
    enforced but the Laptops are also used when not connected to the Network and
    so the pupils have to Logon locally.

    Thanks in advance

    Kevin

    "Mark Renoden [MSFT]" <markreno@online.microsoft.com> wrote in message
    news:%23TPwVTyUEHA.3476@tk2msftngp13.phx.gbl...
    > Hi Kevin
    >
    > %systemroot%\system32\GroupPolicy contains the local GPO files. If you
    were
    > to replace these with a copy of the files associated with your domain
    based
    > policy, you'd get the settings applied locally. Problems I see with this:
    >
    > 1. Watch out you don't break the permissions in the directory structure
    when
    > you replace the local policy structure. You may want to run something
    like
    > cacls or xcacls and output to a text file to capture the current
    permissions
    > and then do it again afterwards to ensure nothing has changed.
    >
    > 2. If you apply policy here, it applies to everyone all the time. Anyone
    > who logs onto the machine including Administrators will be subject to the
    > restrictions imposed by the policy. This is possibly not what you want.
    >
    > 3. This is me making things up. I doubt this is a documented or supported
    > procedure.
    >
    > What is the necessity for doing this? Perhaps there's an alternate
    > approach?
    >
    > Kind regards
    > --
    > Mark Renoden [MSFT]
    > Windows Platform Support Team
    > Email: markreno@online.microsoft.com
    >
    > Please note you'll need to strip ".online" from my email address to email
    > me; I'll post a response back to the group.
    >
    > This posting is provided "AS IS" with no warranties, and confers no
    rights.
    >
    > "Kevin Cowans" <kevin@kncowans.demon.co.uk> wrote in message
    > news:uOyuUqwUEHA.644@tk2msftngp13.phx.gbl...
    > > Hello all
    > >
    > > I currently lock down our users (pupils) using Domain based Group
    Policies
    > > which are working great but now I need to be able to lock down a local
    > > user
    > > in XP Pro on Laptops.
    > >
    > > Is it possible to somehow transfer the settings from the Domain based
    > > Group
    > > Policy to the Laptop and use it for the Loca Policy settings?
    > >
    > > If this is not possible then does anyone have any suggestions as to how
    I
    > > can lock down a Local user on a Laptop.
    > >
    > > Thanks in advance
    > >
    > > Kevin
    > >
    > >
    >
    >


  • Next message: Felix Roth: "administrative template for autologon"

    Relevant Pages

    • Re: Howto, Apply Policy to specific OU only
      ... Same for computer settings. ... by using a GPO not linked to that OU but to one earlier in the GPO ... Policy 1 is to provide settings only when logged on to computers residing ... Policy 2 obvious is intended only for users who logon to laptops in OU ...
      (microsoft.public.windows.group_policy)
    • Re: Howto, Apply Policy to specific OU only
      ... Same for computer settings. ... by using a GPO not linked to that OU but to one earlier in the GPO ... Policy 1 is to provide settings only when logged on to computers residing ... Policy 2 obvious is intended only for users who logon to laptops in OU ...
      (microsoft.public.windows.group_policy)
    • Fwd: Notebook policy (need advice)
      ... The first thing you will need to do is get some sort of formal policy ... - Wireless - this is set to only connect to a known list of wireless networks. ... - Local Admin - unfortunately due to most users needing to be able to ... but this does mean some laptops aren't scanned as frequently ...
      (Security-Basics)
    • Fwd: Notebook policy (need advice)
      ... The first thing you will need to do is get some sort of formal policy ... - Wireless - this is set to only connect to a known list of wireless networks. ... - Local Admin - unfortunately due to most users needing to be able to ... but this does mean some laptops aren't scanned as frequently ...
      (Security-Basics)
    • RE: ScreenSaver timeout problem via GPO
      ... Number of Seconds to wait to enable the Screen Saver = Enabled at 0 Seconds ... give you some facts about these laptops so you know the situation. ... This policy is not enforced so if a lower OU blocks inheritance it ... loopback processing and it would still run if in the correct order. ...
      (microsoft.public.windows.server.active_directory)