Re: How to prevent users from installing programs.



RandyH <RHollaw@xxxxxxxxxxx> wrote:
ugh...you guys are right....Thanks for the all the help.

You're welcome. I know this isn't much fun when you're dealing with badly
written software, but 99.9999% of the time you can work around it. Oh, and
don't forget to holler at the developers who wrote the POS. And you know
which definition of that abbreviation I mean.


Lanwench [MVP - Exchange] wrote:
RandyH <RHollaw@xxxxxxxxxxx> wrote:
I was looking at Disable Windows Installer setting and see another
setting called, Prohibit User Installs.

Would that prevent users from installing programs?

The Disable Windows Installer, would that only apply to MSI's?

Thanks again,
RandyH

Did you try my suggestion? I think you're going to make yourself
crazy with this one. The right answer is to revoke the admin rights
(as well as run general policy lockdown). Anything else you do will
be a kluge and not a simple one.


Lanwench [MVP - Exchange] wrote:
RandyH <RHollaw@xxxxxxxxxxx> wrote:
I guess Disable Windows Installer could have been a good answer
too. Thanks for the KB, I had followed most of that article minus
the Disable Windows Installer setting.

do you know anything about Worldox? it's a POS and we've tried
what you have suggested in the past without success.

again, thanks for the KB...
No prob. I presume that by POS you don't mean "point of sale" but
something else. ;-)
And no, I'm not familiar with it. Just try the sysinternals
tool...it's very handy.

Lanwench [MVP - Exchange] wrote:
RandyH <RHollaw@xxxxxxxxxxx> wrote:
We have an app that requires users to be local admins, crappy I
know, but I how can i prevent users from installing programs?

If the TS has be in admin mode anyway, why would MS let programs
get installed otherwise????? - rant..
You can lock down most everything you need to --and should-- but
why not fix the underlying problem with this application first?
You should be able to identify the file system & registry areas
to which it wants access - try using Process Monitor from
Sysinternals (available for download on the MS website). Users
should not be admins on workstations, let alone servers & you
shouldn't have to leave them that way. Basics: you should be
running Terminal Services on a dedicated
member server with *no* other roles on the network. It should be
set up in its own OU, with a policy specifically for TS
(including loopback processing so that all users who log in get
the same settings, regardless of their own inherited user policy
settings). See KB 278295 for some good lockdown suggestions.
Also see MVP Patrick Rouse's articles at
http://www.sessioncomputing.com/articles.htm



.



Relevant Pages

  • Re: firewall on budget ?
    ... 1)Work in Admin mode, and through 'run as', browse ... If working in admin mode and doing runas to browse in a guest account. ... Installing a program, getting an error, then doing the run as, can be ... running as administrator all the time. ...
    (microsoft.public.windowsxp.security_admin)
  • RE: How to block users from installing other apps
    ... admin password. ... How to block users from installing other apps ... It's not hard to manipulate permissions for your apps so that these users ... |> SBC Yahoo! ...
    (Focus-Microsoft)
  • Re: Software Audit & Enforcement - Required?
    ... The local admin account on each laptop is disabled by default, ... get local admin access to their machine. ... well as the less likely privilege escalation bug installing software. ... unlicensed/against company policy installed. ...
    (microsoft.public.security)
  • Printer will only work in Admin Account
    ... I installed in my Admin account to the All Users Program files and it ... Home computer among the Admin and 2 limited users. ... > Users profile or ask the installing user if the program is to be ... > to All Users or just the installing user and put the program shortcuts ...
    (microsoft.public.windowsxp.print_fax)
  • Re: Error 372 - Failed to load control from
    ... may I know whether you are launching the VB6 app in Windows ... After installing an application to a Vista machine the following error is ... If the UAC was turned off and a member of the Admin group had attempted to ... Microsoft Online Community Support ...
    (microsoft.public.vb.bugs)