ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Office applications Toolkit

Lockdown the desktop with policies

Jeff Davis

Published: 29 Apr 2003 10:57 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Network policies to back up the written policies
In one of the Fortune 500 shops where I consult as a technical writer, the network administrators and the help desk analysts joined forces to define the standard user configuration for end user desktop machines.

In this Windows 2000 environment, the standard user image is locked down by Group Policy Object (GPO) settings, or collections of settings that define the system and how it will behave for a specific group of users. For select power users and IT staff, the policies were less restrictive. However, for most end users, the following rules were in place:

  • No A or B drives. New end user machines are deployed without A or B drives. Machines already in service had those drives deactivated by policy.
  • The autorun feature is disabled for machines that have CD-ROM drives.
  • No Run option is available on the Start menu.
  • The number of Control Panel applets has been pared down to the bare minimum. Conspicuously absent is Add/Remove Programs.
  • The following file types are prohibited from running at any time: *.msi (Microsoft Install programs), *setup*.* and install*.* (no setup or installation programs of any kind will run), AOL*.* (because the company doesn't want AOL's Instant Messenger running on its network), and quake*.* (because the company doesn't want users chewing up bandwidth playing Quake).

With such policies in place, even if users open the box and install a new video card or their own modem, Windows 2000 won't let users see the new device. The policy protects the system at the level of the Hardware Abstraction Layer, affectionately known as HAL.

In this shop, the GPOs are managed using FullArmor's Zero Administration (FAZAM 2000) for Windows NT, a third party graphical tool that broadens the functionality and flexibility of Group Policy management under Windows 2000.

Lock them down now or clean up the mess later
Some of you may believe that policies that require locking down end user machines are too restrictive. Some of you believe companies should allow end users as much freedom to install applications or configure machines as they like.

If the users in your organisation can be trusted to add or remove hardware or software, more power to you and to them. And if you don't mind providing help desk support for the picture-maker-of-the-month and gamers on the network, more power to you.

Be forewarned, though. The first time a user inadvertently launches a virus or brings down the network, you'll wish you'd locked down your machines.

How do you lock down your end user machines? Tell us by mailing the Enterprise Mailroom.

For a weekly round-up of the enterprise IT news, sign up for the
Enterprise newsletter.

Tell us what you think in the
Enterprise Mailroom.

Next

Previous

1 2


  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with Konica

Did you find this article useful?
38 out of 60 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:










Featured Talkback

In association with Intel
Why do so many (virtually all) software packages think that they are so important that they have to be started automatically every time the computer boots? What is the largest number of "speed access", "update check", "camera download" and whatever other background programs you have ever seen running? Of those, how many did you really need?

By: J.A. Watson

Read full story:
Annoying software: a rogues' gallery

Discussions

sell001 sell001

www.sell-nike-shoes.com colorful nike...

Wednesday 15 October 2008, 5:17 PM

1 post
James B James B

Short throw projection from BenQ

Wednesday 15 October 2008, 4:22 PM

1 comment
Davep Davep

Truly Unbelievable

Wednesday 15 October 2008, 12:10 PM

8 comments
davidross davidross

xG update - money, mystery and more

Wednesday 15 October 2008, 12:05 PM

14 comments

Vista Upgrade Blog

Vista - Still Running and Stable After...

Six weeks ago, when I wrote Renewed Adventures with Vista, I wondered if Microsoft had finally managed to fix it sufficiently that I wouldn't be forced to give up on it after a few... More

Post a comment

Official MS Windows 7 Bloggers

Check this out: http://blogs.msdn.com/e7...spx Its an official blog "Engineering Windows 7" Nothing. That's what is revealed. Until there is real... More

5 comments

Microsoft's Mojave just a desert vista

It didn't seem fair to wade into Microsoft's “Mojave Experiment” advert quite so soon after the flat earth incident. But The Economist has no such qualms: in this week's issue, it wonders... More

6 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters