A Windows Vista forum. Vista Banter

Welcome to Vista Banter.

You are currently viewing our boards as a guest which gives you limited access to view most discussions, articles and access our other FREE features. By joining our free community you will have access to ask questions and reply to others posts, upload your own photos and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact support.

Go Back   Home » Vista Banter forum » Microsoft Windows Vista » Security and Windows Vista
Site Map Home Register Authors List Search Today's Posts Mark Forums Read Web Partners

Security and Windows Vista A forum for discussion on security issues with Windows Vista. (microsoft.public.windows.vista.security)

Customizing User Accounts



 
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old June 14th 07, 10:36 PM posted to microsoft.public.windows.vista.security
Aetherial
external usenet poster
 
Posts: 2
Default Customizing User Accounts

I need to set up a user in Vista with less permission than the standard user
account. For example, I don't want the user to be able to create ANY files
outside of the profile. I don't want the user to be able to change the
wallpaper or the screen saver. I need to limit the user's access to the
Control Panel more than usual.
Etcetera, etcetera.
How can I customize the account in this way?
  #2 (permalink)  
Old June 14th 07, 11:55 PM posted to microsoft.public.windows.vista.security
David Dickinson
external usenet poster
 
Posts: 139
Default Customizing User Accounts

"Aetherial" wrote in message
...
I need to set up a user in Vista with less permission than the standard
user
account. For example, I don't want the user to be able to create ANY files
outside of the profile. I don't want the user to be able to change the
wallpaper or the screen saver. I need to limit the user's access to the
Control Panel more than usual.
Etcetera, etcetera.
How can I customize the account in this way?


Exactly how will this computer be used? Different methods are available for
different types of uses. For instance, a public computer needs more
restrictions than an office machine meant for sales people to keep their
records. In general, however, you can:

1) Create a custom user group. Make it a member of the User's group

2) Create the user, adding them to that group and removing that specific
account from the Users group.

3) In NTFS permissions for the Public folders and other folders to which the
Users group can write, use Advanced to deny the custom user group create,
append, and write permissions.

4) Use the group policy snap-in to limit other system options.

Will these less-than-standard users need actually to save documents
permanently? If not, then consider using the Guest account. Any changes
they make to the desktop will be forgotten when they log off, and you can
similarly use group policy to limit them even more from those parts of they
system that you don't want them in. However, if they need to save documents
permanently, you can create a special folder for them.

There are other things to consider in accomplishing what you want, too.
Hopefully, others will reply with their ideas. And if this machine is part
of a domain, the procedure is different.

I recommend consulting a professional for help with this. You might miss
something important or restrict too much.

--
David Dickinson
eveningstar at die-spammer-die dash mvps dot org
Please reply only to the newsgroup, not by email.

  #3 (permalink)  
Old June 15th 07, 02:45 AM posted to microsoft.public.windows.vista.security
Aetherial
external usenet poster
 
Posts: 2
Default Customizing User Accounts

I work at a public special-purpose lab attached to a university domain. We
are upgrading to Vista over the summer.
We are also changing the way the lab computers work with the university
domain. Currently, being attached to the domain on XP gives us problems
because users log in using their university account. We don't want them to do
this, so we are limiting domain access. Instead we are making a standard disk
image with the user accounts as we want them, then deploying that image among
all the lab computers.
We considered Guest accounts, but ultimately decided against it because we
need some files and application shortcuts always available, and because we
had problems with using certain system features as Guest. Instead, the
standard account runs a script from a local server which cleans out the
account info between uses. This will also be changed if we find a better
solution.
Essentially, the account I'm working on needs to be only somewhat more
relaxed than say, a public library or internet cafe. The main difference is
that we need a variety of applications to run without a problem on that
account.
  #4 (permalink)  
Old June 15th 07, 05:16 AM posted to microsoft.public.windows.vista.security
David Dickinson
external usenet poster
 
Posts: 139
Default Customizing User Accounts

"Aetherial" wrote in message
news
Essentially, the account I'm working on needs to be only somewhat more
relaxed than say, a public library or internet cafe. The main difference
is
that we need a variety of applications to run without a problem on that
account.


Then my original suggestion may suffice. But every time you login on the
machine as an administrator, you'll have to use the group policy object
editor snap-in to allow the administrator to do what needs to be done.
However, if you did use the Guest account, running the with software
elevated privileges and assigning a certain folder for saved data might
work. You can always set up the default user with the environment you want
for guests. It might be worth testing that configuration to avoid the
shortcomings of using the local group policy object editor and configuring a
special user.

--
David Dickinson
eveningstar at die-spammer-die dash mvps dot org
Please reply only to the newsgroup, not by email.

 




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 09:19 AM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.Search Engine Optimization by vBSEO 3.0.0 RC6
Copyright ©2004-2024 Vista Banter.
The comments are property of their posters.