PC Review


Reply
Thread Tools Rate Thread

delprof.exe, deleting user profiles on logoff/shutdown

 
 
headbasher
Guest
Posts: n/a
 
      5th Oct 2009
we have laptops that we give to users, but we don't want them to save
anything or install anything anywhere on the laptop. if the laptop gets
stolen we don't want anybody accessing any saved files. these laptops are
part of the domain (but i've tried this after removing the laptop from the
domain), so when they log in at the office they can use redirected
MyDocuments folder, but the policy uses a proxy server, so when they take it
home they have to use a local user account.
we have provided secure flashdrives for people to use to save files.
i' ve set the group policies to hide and restrict access to local drives
abcd. i've set the common dialog box policy to only show the e drive for the
flash (but the desktop still shows as the first thing in the drive list).

msoffice and even notepad still allow saving to the desktop. how is that
possible with the drive restrictions?

i've tried to use delprof.exe in a shutdown/logoff script to delete profiles
on logoff or shutdown with the /q /i /d:0 options, but profiles still exist.
i've tried using the runas command in the script with a local administrator
account (not administrator, and an account that has never been logged on) and
even as 'nt authority\system' but it just appears to hang for a minute or
five before the computer shuts down and doesn't delete the profiles. if i try
to use it as a logon script the computer takes too long to boot and i get
group policy timeout/load errors in the logs.
i'm running XPSP3.

so how can i delete profiles or files so our system isn't compromised?

one simpler trick i tried that seems to work is running a logoff script that
has the command 'del /q "c:\documents and settings\%username%\desktop\*.*"'
(or "%userprofile%\desktop\*.*")as all the other apps and icons that should
be on the desktop are either in the Default or AllUsers profiles, but i'm
looking for a better solution if possible.

any answers? is there a solution?

and while i'm at it, is there a way to exempt certain users or groups from
local group policies?

 
Reply With Quote
 
 
 
 
SPAMCOP User
Guest
Posts: n/a
 
      6th Oct 2009

This is what my company uses for all 33, 000 laptops:

http://www.checkpoint.com/products/d.../pc/index.html

It's a pain in the neck but secure enough

--
SPAMCOP User

"headbasher" <(E-Mail Removed)> wrote in message
news:67C56610-BF7A-425D-A9A9-(E-Mail Removed)...
> we have laptops that we give to users, but we don't want them to save
> anything or install anything anywhere on the laptop. if the laptop gets
> stolen we don't want anybody accessing any saved files. these laptops are
> part of the domain (but i've tried this after removing the laptop from the
> domain), so when they log in at the office they can use redirected
> MyDocuments folder, but the policy uses a proxy server, so when they take
> it
> home they have to use a local user account.
> we have provided secure flashdrives for people to use to save files.
> i' ve set the group policies to hide and restrict access to local drives
> abcd. i've set the common dialog box policy to only show the e drive for
> the
> flash (but the desktop still shows as the first thing in the drive list).
>
> msoffice and even notepad still allow saving to the desktop. how is that
> possible with the drive restrictions?
>
> i've tried to use delprof.exe in a shutdown/logoff script to delete
> profiles
> on logoff or shutdown with the /q /i /d:0 options, but profiles still
> exist.
> i've tried using the runas command in the script with a local
> administrator
> account (not administrator, and an account that has never been logged on)
> and
> even as 'nt authority\system' but it just appears to hang for a minute or
> five before the computer shuts down and doesn't delete the profiles. if i
> try
> to use it as a logon script the computer takes too long to boot and i get
> group policy timeout/load errors in the logs.
> i'm running XPSP3.
>
> so how can i delete profiles or files so our system isn't compromised?
>
> one simpler trick i tried that seems to work is running a logoff script
> that
> has the command 'del /q "c:\documents and
> settings\%username%\desktop\*.*"'
> (or "%userprofile%\desktop\*.*")as all the other apps and icons that
> should
> be on the desktop are either in the Default or AllUsers profiles, but i'm
> looking for a better solution if possible.
>
> any answers? is there a solution?
>
> and while i'm at it, is there a way to exempt certain users or groups from
> local group policies?
>


 
Reply With Quote
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Event ID 1517 and 1527 - Not unloading user profiles at logoff buttoni Windows XP Basics 2 7th Mar 2009 01:58 AM
2nd user logoff results in shutdown =?Utf-8?B?V2lsbGlhbVc=?= Windows XP Configuration 0 25th Aug 2006 11:53 PM
Automatic shutdown on user logoff =?Utf-8?B?Um5hcmRlbGxp?= Windows XP Help 0 9th Sep 2005 06:36 AM
How to delete user profiles at logoff? Steven Jones Microsoft Windows 2000 1 1st May 2004 01:46 PM
user logoff/shutdown morris Microsoft Windows 2000 New Users 2 31st Mar 2004 08:11 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 11:20 PM.