User Restictions on a Standalone Machine

  • Thread starter Christopher Harrison
  • Start date
C

Christopher Harrison

Hi,

I am running Win2k Professional on a standalone, non-networked machine.
It is to be deployed to users whom I don't want messing with my system!
What I would like to do is have an administrator account, with full
privileges (which I can manage to setup!) and a user account that is
severely restricted. In particular, I don't want them to have access to
the system folders or control panel, or be able to change any settings
-- just run programs (even restrict them to just a few applications,
but that might be asking too much), load/save/print documents and
shutdown the machine!

How do you do this!?

I have read-up on group policies and user profiles and I can't seem to
make the necessary changes to a particular user/group. The best I can
manage, so far, is adding the GPO snap-in to the MMC; but I haven't
messed any further because it implies that it affects the entire
machine, not one particular policy/profile.
Can you even do what I'm asking in Win2k Pro? It would seem an obvious
function of a multi-user OS; but I would have thought it would be at
least somewhat intuitive to set-up...

Many thanks;
Christopher Harrison
 
R

Roger Abell [MVP]

Christopher Harrison said:
Gosh -- that's a hack-and-a-half... but it works! Thanks :)

Yes indeed, and you're welcome.

Be careful in planning as the hack's real pain comes when you
decide you need to change policy settigs, again, and again . . .

(PS - one can also deny full to Administrators on the directory
system32\GroupPolicy, but this is quite drastic and requires an
unset to edit with certainty of remembering to re-deny).

Roger
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top