Jump to content

Recommended Posts

Posted

Hi all, apologies if this has been covered in another thread.

 

I'm working at a secondary school on an RM CC4 network. Our staff laptops are stand alone win7 machines and we're having an increasing problem of staff not thinking "Does this sound legit?" before installing everything under the sun.

 

We want to try and lock down these stand-alone laptops so staff can't install new software but they can update software that is already installed. Also so that we don't have to run around all day every day inputting an admin password. Is this possible using group policy?

Also, if anyone has any better solutions I'm all ears... we already want to move to cc4 desktops in every classroom but at present our budget is virtually non-existent.

 

Thanks

Posted

In a standalone environment, you can only set up users as either 'Users' or 'Administrators'. I know there are other groups, but I don't think it'll have the desired affect.

 

Why not create a separate OU within Active Directory and properly join devices to the domain? You can still do this, even within RM CC networks.

 

To be honest, I think end users not updating any software at all should be the policy. If everything is performed centrally, then you'll know exactly what's on your devices when diagnosing issues.

Posted

As Michael said, it's still possible to control them just outside of CC4, but kind of defeats the point of paying all that money for it!

 

If funds are tight, would it not be cheaper to move away from CC4 and go Vanilla?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...