Installing XP Pro Tablet Edition and restricting users?

P

Pheasant Plucker®

Hi there,

I have 10 IBM Thinkpad X41 TabletPC systems to setup and wondered if some
kind soul could help me please?

I wish to restrict access to the user so he is able to use applications such
as Office etc. but prevent the same user from installing other applications
and changing things like date/time and possibly even passwords etc.

If I could ask for clarification/guidance on the following please?

1. Unlike earlier O/S setups XP by default does not allow you to set up a
user called Administrator. I am guessing that the first username entered
becomes the equivalent of Administrator - would this be correct?
Interestingly during setup I entered a password and also setup the one &
only user account (Admin) but have never been prompted for the password
since!

2. Assuming it is then if I setup a User called Admin with a password I can
apply all the Security updates from MS & Symantec, install the applications
etc. and then create the main user name with limited access? I will then be
able to logon at any time as Admin with my chosen password for full access
much like earlier OS installations?

3. I wish to lock down many systemwide settings but do not want this to
prevent downloading & installing any MS or Symantec security updates - I
also do not wish to be getting calls every five minutes because the user is
prevented from actually using the TabletPC applications such as Office etc.
How best would I achieve this? Is there a good resource that details the
best way to configure access rights etc?

4. I would like to use RemoteDesktop to fix any problems, carry out any
installs, upgrades etc. I use this to support other clients fixed sites with
success. Is it just a simple matter of enabling RemoteDesktop and ensuring
the relevant ports are open in both Windows Firewall & NAV2005 etc?
Presumably I could carry out any remote works whenever the TabletPC is
connected to the Internet with the users consent of course?

5. I also wish to setup email access for the users but would prefer them
only to be able to email the office or other 'legitimate' users? How best to
achieve this using Outlook 2003? Is there a way I could also restrict
receipt of incoming emails from legitimate named sources? Rules for example?

6. There is a need for them to connect to the Internet to transfer data
to/from a custom application that is currently in Beta which will replace
their existing iPAQ handheld devices. With the above restrictions will this
impact the ability to do so?

7. Any other help/advice on the above would also be much appreciated.

Thanks in advance and kind regards,
-=pp=-
 
C

Carey Frisch [MVP]

One can be logged on as the "Administrator" or logged on
as a member of the "Administrators Group" in order to
install Windows Updates.

You can configure Automatic Updates by using Group Policy
in an Active Directory environment, or by using registry settings
in a non-Active Directory environment. For more information
about how to configure Automatic Updates by using these methods,
click the following article number to view the article in the
Microsoft Knowledge Base:

How to configure automatic updates by using Group Policy or registry settings
http://support.microsoft.com/kb/328010/

"Administrator" is an account. If a permission or privilege
is granter to the Administrator, it can be done only by someone
logged in with the Administrator account. That is, the account
whose name defaults to "Administrator".

"Administrators", on the other hand, is a "group". If you are
a member of the "Administrators Group", you have been granted
administrator privileges on that particular computer. It is
membership in the "Administrators Group" that people refer to
when they say things like "I'm an administrator on this computer".

How to use the Group Policy Editor to change default systems settings
http://www.windowsnetworking.com/j_helmig/winxpgpe.htm

Microsoft Shared Computer Toolkit for Windows XP
http://www.microsoft.com/windowsxp/sharedaccess/default.mspx

--
Carey Frisch
Microsoft MVP
Windows - Shell/User
Microsoft Community Newsgroups
news://msnews.microsoft.com/

---------------------------------------------------------------------------­----------------

:

| Hi there,
|
| I have 10 IBM Thinkpad X41 TabletPC systems to setup and wondered if some
| kind soul could help me please?
|
| I wish to restrict access to the user so he is able to use applications such
| as Office etc. but prevent the same user from installing other applications
| and changing things like date/time and possibly even passwords etc.
|
| If I could ask for clarification/guidance on the following please?
|
| 1. Unlike earlier O/S setups XP by default does not allow you to set up a
| user called Administrator. I am guessing that the first username entered
| becomes the equivalent of Administrator - would this be correct?
| Interestingly during setup I entered a password and also setup the one &
| only user account (Admin) but have never been prompted for the password
| since!
|
| 2. Assuming it is then if I setup a User called Admin with a password I can
| apply all the Security updates from MS & Symantec, install the applications
| etc. and then create the main user name with limited access? I will then be
| able to logon at any time as Admin with my chosen password for full access
| much like earlier OS installations?
|
| 3. I wish to lock down many systemwide settings but do not want this to
| prevent downloading & installing any MS or Symantec security updates - I
| also do not wish to be getting calls every five minutes because the user is
| prevented from actually using the TabletPC applications such as Office etc.
| How best would I achieve this? Is there a good resource that details the
| best way to configure access rights etc?
|
| 4. I would like to use RemoteDesktop to fix any problems, carry out any
| installs, upgrades etc. I use this to support other clients fixed sites with
| success. Is it just a simple matter of enabling RemoteDesktop and ensuring
| the relevant ports are open in both Windows Firewall & NAV2005 etc?
| Presumably I could carry out any remote works whenever the TabletPC is
| connected to the Internet with the users consent of course?
|
| 5. I also wish to setup email access for the users but would prefer them
| only to be able to email the office or other 'legitimate' users? How best to
| achieve this using Outlook 2003? Is there a way I could also restrict
| receipt of incoming emails from legitimate named sources? Rules for example?
|
| 6. There is a need for them to connect to the Internet to transfer data
| to/from a custom application that is currently in Beta which will replace
| their existing iPAQ handheld devices. With the above restrictions will this
| impact the ability to do so?
|
| 7. Any other help/advice on the above would also be much appreciated.
|
| Thanks in advance and kind regards,
| -=pp=-
 
P

Pheasant Plucker®

Hi Carey,

Thanks for the quick reply.

I do not use AD and I will sit down and take a minute to get my head round
the info you posted...

I will take a look at the links you gave - thanks.

Kind regards,
-=pp=-
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top