First I'll explain what I am trying to do. We have a stand-alone machine
that will be used in a public access environment. This machine will be
running Windows 2000 Professional. We need two user accounts, one for
Administrator with access to everything on the system, and one for the
public. The public account will restrict My Computer, Start Menu, Control
Panel and just about everything else than can be restricted to prevent the
users from changing anything on the system. They will only be allowed to run
specific programs as well.
I am familiar with implementing system policies like this on WinNT 4, but I
am not too familiar with how to go about doing this with Win2K. It is a
completely stand-alone machine, no domain controllers or anything like that.
If anyone has any suggestions, I would really appreciate it. Thanks for your
time,
Tom Vaughan
Ok, the best way to do this is to use profiles and Local
Group Policy.
The profiles are set up the same way as with NT 4. Create
the profile etc, probably best to make it a mandatory
profile.
To complete the lock down use the group policy editor
that comes with Win2k to set the local restrictions. This
system works the same as if the client was in a Windows
2000 domain except you manage it locally.
To help further have a look at these
http://www.microsoft.com/windows2000/techinfo/administrati
on/management/settings.asp
http://www.microsoft.com/windows2000/techinfo/howitworks/m
anagement/grouppolwp.asp
http://www.microsoft.com/windows2000/techinfo/howitworks/m
anagement/grouppolicyintro.asp
http://www.microsoft.com/windows2000/techinfo/howitworks/m
anagement/grouppolicy.asp
http://www.microsoft.com/WINDOWS2000/techinfo/reskit/en/De
ploy/dgbe_sec_wopt.htm
Hope this helps
Alan
This posting is provided "AS IS" with no warranties, and
confers no rights.
>.
>
Thanks very much, I'll read through some of those pages and give it a try.
Thanks,
Tom Vaughan
"Alan Le Marquand [MS]" <ala...@microsoft.com> wrote in message
news:811e01c16887$eb7d84f0$b1e62ecf@tkmsftngxa04...
I have a similar problem: Win2K Pro standalone machine with 2 groups of
users with different local restriction.
I see your point to use group policy object, but how do I actually go about
it? The problem is that win2000 Pro has no direct directory snap-in in the
management console and there I can not assign policies to users or groups.
Do I have to use Win NT poledit?
Please Help.
Markus
"Alan Le Marquand [MS]" <ala...@microsoft.com> wrote in message
news:811e01c16887$eb7d84f0$b1e62ecf@tkmsftngxa04...