Subject: Re: Information PC
Date: Tue, 10 Feb 2004 23:22:22 -0700
Lines: 61
X-Priority: 3
X-MSMail-Priority: Normal
X-Newsreader: Microsoft Outlook Express 6.00.2800.1158
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Message-ID: <#
[email protected]>
Newsgroups: microsoft.public.windowsxp.security_admin
NNTP-Posting-Host: as5100ff-06.inre.asu.edu 129.219.105.122
Path: cpmsftngxa07.phx.gbl!cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP10.
phx.gbl
Xref: cpmsftngxa07.phx.gbl microsoft.public.windowsxp.security_admin:111799
X-Tomcat-NG: microsoft.public.windowsxp.security_admin
Curtis Koenig said:
Create an OU that the machines will be members of then create a policy for
that OU that only allows the actions you want to allow.
--
Curtis Koenig
Support Engineer
Product Support Services, Security Team
MCSE, MCSES, CISSP
Hi Curtis,
You know that, since W2k released, MS has answered this
kiosk type of post much as you have just done.
However, I have yet to see a template that actually does do
this. W2k is known to be exceedingly difficult to truly and fully
restrict so that no one can escape in any way to a shell, prompt,
etc.. XP and W2k3 have improved on things, but it would seem
that MS could provide an actually example of doing this.
Please understand, I am not trying to pick on you. Not at all.
If anything I am wanting to raise some awareness that we see
posts like this fairly regularly. Yet since late 1999 I have yet
to see people rapidly step up to answer these postings, and
when they do it is usually with info on only the first steps down
the road.
So, if you have a mind to, pass the feedback along would you ?
There should be a paper / KB : How to build a bullet-proof
public access kiosk machine with Windows XP
Thx,