PC Review


Reply
Thread Tools Rate Thread

Restricting/stopping users browsing the network throgh active directory

 
 
Jim Florence
Guest
Posts: n/a
 
      13th Aug 2003
Hello,

I'm 90% of the way through an AD design for a school and have hit a
stumbling block with security.

We need to stop the children being able to browse the network and active
directory in one fail swoop and I'm looking for pointers on the best way to
do this.

I know I can modify the security for AD objects and remove view access for
everyone and authenticated users but this also seems to cause problems with
group policy applied at lower levels.

We have a legacy NT4 domain that is also browsable and even though we are
confident that even thought they can see the shares and not access them, I'd
sleep better knowing they could see nothing at all.

We handle all directory and print mappings through login scripts so we can
tie down browsing completely.

Many thanks

Jim Florence


 
Reply With Quote
 
 
 
 
Sabin Nair[MSFT]
Guest
Posts: n/a
 
      13th Aug 2003
Hi Jim,

This should help:

Enable the following Group Policy settings under User
Configuration\Administrative
Templates to prevent browsing:

1. Windows Components\Windows Explorer: Enable "Remove Map Network Drive and
Disconnect Network Drive", "Search button from Windows Explorer", "No
computers
near me in My Network Places", and "No Entire Network in My Network Places".
2. Start Menu and Taskbar: Enable "Remove Run menu from Start Menu"
3. System: Enable "Disable the command prompt"

Thanks
Sabin Nair M.S(Computer Engg.), MCSE, MCSA
Directory Services Team

"Please do not send e-mail directly to this alias.
This alias is for newsgroup purposes only."

"Jim Florence" <(E-Mail Removed)> wrote in message
news:3f396e45$0$955$(E-Mail Removed)...
> Hello,
>
> I'm 90% of the way through an AD design for a school and have hit a
> stumbling block with security.
>
> We need to stop the children being able to browse the network and active
> directory in one fail swoop and I'm looking for pointers on the best way

to
> do this.
>
> I know I can modify the security for AD objects and remove view access for
> everyone and authenticated users but this also seems to cause problems

with
> group policy applied at lower levels.
>
> We have a legacy NT4 domain that is also browsable and even though we are
> confident that even thought they can see the shares and not access them,

I'd
> sleep better knowing they could see nothing at all.
>
> We handle all directory and print mappings through login scripts so we can
> tie down browsing completely.
>
> Many thanks
>
> Jim Florence
>
>



 
Reply With Quote
 
Jim Florence
Guest
Posts: n/a
 
      13th Aug 2003
Sabin

Many thanks for the amazingly quick reply.

I'll try that first thing tomorrow and let you know how I get on

Regards

Jim Florence

"Sabin Nair[MSFT]" <(E-Mail Removed)> wrote in message
news:%(E-Mail Removed)...
> Hi Jim,
>
> This should help:
>
> Enable the following Group Policy settings under User
> Configuration\Administrative
> Templates to prevent browsing:
>
> 1. Windows Components\Windows Explorer: Enable "Remove Map Network Drive

and
> Disconnect Network Drive", "Search button from Windows Explorer", "No
> computers
> near me in My Network Places", and "No Entire Network in My Network

Places".
> 2. Start Menu and Taskbar: Enable "Remove Run menu from Start Menu"
> 3. System: Enable "Disable the command prompt"
>
> Thanks
> Sabin Nair M.S(Computer Engg.), MCSE, MCSA
> Directory Services Team
>
> "Please do not send e-mail directly to this alias.
> This alias is for newsgroup purposes only."
>
> "Jim Florence" <(E-Mail Removed)> wrote in message
> news:3f396e45$0$955$(E-Mail Removed)...
> > Hello,
> >
> > I'm 90% of the way through an AD design for a school and have hit a
> > stumbling block with security.
> >
> > We need to stop the children being able to browse the network and active
> > directory in one fail swoop and I'm looking for pointers on the best way

> to
> > do this.
> >
> > I know I can modify the security for AD objects and remove view access

for
> > everyone and authenticated users but this also seems to cause problems

> with
> > group policy applied at lower levels.
> >
> > We have a legacy NT4 domain that is also browsable and even though we

are
> > confident that even thought they can see the shares and not access them,

> I'd
> > sleep better knowing they could see nothing at all.
> >
> > We handle all directory and print mappings through login scripts so we

can
> > tie down browsing completely.
> >
> > Many thanks
> >
> > Jim Florence
> >
> >

>
>



 
Reply With Quote
 
Jim Florence
Guest
Posts: n/a
 
      14th Aug 2003
Sabin,

I checked all these and unfortunately I have applied them all.

You can work around these by using the folders button in explorer and the
whole network pops up to browse down the right hand pane. Also if a user
creates or edits a shortcut with valid information they can still get to
certain areas.

The explorer problem is our biggest problem, any ideas

Many thanks for you assistance so far

Jim

"Jim Florence" <(E-Mail Removed)> wrote in message
news:3f397742$0$964$(E-Mail Removed)...
> Sabin
>
> Many thanks for the amazingly quick reply.
>
> I'll try that first thing tomorrow and let you know how I get on
>
> Regards
>
> Jim Florence
>
> "Sabin Nair[MSFT]" <(E-Mail Removed)> wrote in message
> news:%(E-Mail Removed)...
> > Hi Jim,
> >
> > This should help:
> >
> > Enable the following Group Policy settings under User
> > Configuration\Administrative
> > Templates to prevent browsing:
> >
> > 1. Windows Components\Windows Explorer: Enable "Remove Map Network Drive

> and
> > Disconnect Network Drive", "Search button from Windows Explorer", "No
> > computers
> > near me in My Network Places", and "No Entire Network in My Network

> Places".
> > 2. Start Menu and Taskbar: Enable "Remove Run menu from Start Menu"
> > 3. System: Enable "Disable the command prompt"
> >
> > Thanks
> > Sabin Nair M.S(Computer Engg.), MCSE, MCSA
> > Directory Services Team
> >
> > "Please do not send e-mail directly to this alias.
> > This alias is for newsgroup purposes only."
> >
> > "Jim Florence" <(E-Mail Removed)> wrote in message
> > news:3f396e45$0$955$(E-Mail Removed)...
> > > Hello,
> > >
> > > I'm 90% of the way through an AD design for a school and have hit a
> > > stumbling block with security.
> > >
> > > We need to stop the children being able to browse the network and

active
> > > directory in one fail swoop and I'm looking for pointers on the best

way
> > to
> > > do this.
> > >
> > > I know I can modify the security for AD objects and remove view access

> for
> > > everyone and authenticated users but this also seems to cause problems

> > with
> > > group policy applied at lower levels.
> > >
> > > We have a legacy NT4 domain that is also browsable and even though we

> are
> > > confident that even thought they can see the shares and not access

them,
> > I'd
> > > sleep better knowing they could see nothing at all.
> > >
> > > We handle all directory and print mappings through login scripts so we

> can
> > > tie down browsing completely.
> > >
> > > Many thanks
> > >
> > > Jim Florence
> > >
> > >

> >
> >

>
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Prevent Domain Users from Browsing Active Directory OUs Ehab Microsoft Windows 2000 Active Directory 4 27th May 2004 01:34 PM
Prevent Domain Users from Browsing Active Directory OUs Ehab Microsoft Windows 2000 Networking 2 27th May 2004 01:33 PM
Prevent Domain Users from Browsing Active Directory OUs Ehab Microsoft Windows 2000 Advanced Server 0 25th May 2004 11:31 AM
Prevent Domain Users from Browsing Active Directory OUs Ehab Microsoft Windows 2000 Group Policy 0 25th May 2004 11:28 AM
Restricting/stopping users browsing the network throgh active directory Jim Florence Microsoft Windows 2000 Active Directory 3 14th Aug 2003 12:25 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 10:29 AM.