Locked-Down XP

M

Mick

We are converting our Library PCs from 2K to XP and as part of that process
I would like to do a better job than my predecessor at reducing the ongoing
work required to keep these machines clear of trojans, porn, spyware, etc.
We have a Windows 2000 domain and there is currently no proxy as we are not
allowed to restrict content, just a CISCO PIX. We use Norton AV.

We currently get members of the public installing all sorts of things from
the net that end up changing the home page, adding extra things to IE,
programs get installed in WINNT and added to Run= in the registry, icons get
added to the desktop, etc. The latest is they are bringing memory sticks in,
so I need to disable that also.

I intend to use GPMC and am starting with the MS "Implementing Common
Desktop Management Scenarios with the GPMC" document. I will have to go
with modified KIOS settings as well allow more than just IE, but I intend to
use the allowed run feature.

I want to make sure I can also lock down IE, but I still need to allow
people to download attachments from Hotmail/Yahoo which requires file
download and cookies.

Also need to restrict access to registry areas such as Run and prevent
modify access to \windows, etc.

After I double-check the licensing I would like to put add blocking, perhaps
the Google Tool bar, also interested in any other strategies to keep the
machine clear of junk (eg Window Washer, ???).

So I would appreciate any good suggestions you have.

Thanks in advance ...
 
R

Roger Abell [MVP]

If you use NTFS then
Also need to restrict access to registry areas such as Run and prevent
modify access to \windows, etc.
should pretty much be already done for you.
There is some Temp and a few other spots down within \Windows but
for the most part it is already protected against Write by Users, and
the registry is.

If you have the budget, you might want to look into a product
like Centurian or others that redirect all writes during boot and
discard them at reboot, leaving each reboot at exactly the
configuration you have prescribed. This will have some issues
on things link automatic updates and machine account password
changes, but there are ways to compensate. We use this in
classrooms and it is well worth the expense.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top