Toggling between security configurations

G

Guest

This is probably basic, but I've spent hours browsing the site and can't find
information at the right level.

I'm trying to set up my lab so that users logging on to the clients via the
university's domain are quite severely restricted (e.g., no Run command,
obviously no regedit). As I understand it, any changes to User Configuration
in Local Computer Policy apply to all users, including Administrators,
whether local or on the domain. But obviously Administrator needs a much less
constrained environment. So as Administrator you can go through mmc and free
up the relevant components (like Regedit, Run). Then you have to remember to
restrict them again. There must be an easier way, but what is it? I have the
vague impression from various documents that you can apply a whole security
profile (=Group Profile?) with administrative templates. What I have in mind
is to run a single file (as Admin) to loosen things up, then another one to
tighten it up again. I'd very much appreciate it if someone could help me,
either by explaining how you can implement one security policy for
Administrator and another for everyone else, or else how you can do what I've
described - have a quick and easy routine for toggling all users between
loose and tight security.
 
S

Steven L Umbach

If you are using an Active Directory domain you can easily accomplish what
you want with Group Policy user configuration and then apply the GPO to only
the user accounts you want to restrict. For non domain computers the free
Shared Computer Toolkit from Microsoft would be well worth checking out as
shown in the link below.

Steve

http://www.microsoft.com/windowsxp/sharedaccess/default.mspx
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top