Jump to content

Recommended Posts

Posted

Hi All,

 

Just wondered how (if you do) restrict the little bliters from installing anything on the PC's?

 

We already restrict anything from being downloaded of the web but we have had a small group of kids bringing stuff in on Pen Drives and installing from there.

 

Any pointers would be apreciated.

Posted

you could use group policy to restrict all applications except the ones you specify from running.

 

you could also use the prevent installers from removable media to also help.

 

 

Alan

Posted

Using software restriction policies is the way to go but due to the number of legitimate programs installed it would take some time to work out and test the policies to ensure that other programs are "Not Blocked".

 

What I am after is just a way to stop them installing anything at all as a quick fix untill I can fully test the software policies

Posted
Just prevent them using the Windows installer and disallow any install media in GPOs'. There are plenty of options in AD to prevent any kind of software installation.
Posted

I agree with geoff with regards to stopping the ppl using usb pens and such like to install things off of them @ disable usb.

 

With regards to using the gpo to only allow software you have on there, all they would have to do to get around that is rename the setup file(s) to something that is allowed to run on the machine like winword or calc etc.

 

Not sure if this is feasable option but deep freeze is used quite a lot from what I have heard and that is pretty good :)

Posted

If you are XP and Server 2003 only then you have the option of Software Restriction Policies.

 

These will allow you to take a snapshot of applications that are allowed to run (and associated files / .dlls) and use only these.

 

http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/ServerHelp/90b75a83-bca7-4871-a661-d67eafcfd86c.mspx

 

I have only seen this in action properly once .. in a business that only ran Office and 3 other apps ... I have never heard of a school with it fully implemented ... but theoretically it is possible.

 

And thank you for reminding me about the changing of name of apps Shane ... that use to be a right pain in the ar$e when you lot did that on the W9x machines.

Posted

we do by fact that we run rm here...

 

what they have done is allowed programs to run from program files with out a problem but students cant access program files dir etc...

 

then also if want to run exe outside of that addem to list of allowed files and paths..

 

russ

Posted

How about a GPO ADM template? Per Machine but meh..

 

1.) Take the following text, copy it, and paste it into a text document. Then, save it as USBSTOR.ADM.

 

CLASS MACHINE
CATEGORY "Custom Policies"
KEYNAME "SYSTEM\CurrentControlSet\Services\UsbStor"
 POLICY "USB Mass Storage Installation"
  EXPLAIN "When this policy is enabled, USB mass storage device permissions can be changed by using the drop down box.

Selecting 'Grant Permission' will allow USB mass storage devices to be installed.  Selecting 'Deny Permission' will prohibit
the installation of USB mass storage devices.

IF REMOVING THIS POLICY: Reset to original setting and let policy propegate before deleting policy."
    PART "Change Settings:" DROPDOWNLIST REQUIRED
      VALUENAME "Start"
      ITEMLIST
       NAME "Grant Permission" VALUE NUMERIC 3 DEFAULT
       NAME "Deny Permission" VALUE NUMERIC 4
      END ITEMLIST
    END PART
  END POLICY
END CATEGORY

 

2.) Open a group policy management console, and right click on "administrative templates" under "Computer Configuration". Select "Add/Remove Templates".

 

3.) Browse to the text document you just saved and click OK. You'll now see "Custom Policies" under "Administrative Templates". Right click on it, select "View", then select "Filtering". Uncheck the bottom box, labeled "Only show policy settings that can be fully managed".

 

4.) Click ok. Now you'll see the USB policy available for use under the custom policy heading. From there, you can enable or disable it just like any other policy.

Posted

Thanks for the feedback guys,

 

I am taking GrumbleDook's option to use Software Restriction Policies and flip things on thier head bt denying everything and only allow the apps I want them to use.

 

I have set up a 3 machince testing network to try it out, once I am happy with it I'll rollout across the school.

  • 2 months later...
Posted

I also (in the past) have experienced problems users installing software. Of course restricting applications from the web is one method, but the other is to restrict the available drive letters. This does involve editing a group policy, but it isn't too hard to do. If you'd like to know how, I'll locate the exact policy you need to edit to achieve such a result.

 

The end result, is that the network drive(s) are accessible, but even if someone plugs in a USB drive, explorer won't do anything as it has no letter to allocate the drive. Simple, but it works!

Posted
Software restriction policies can be applied to specific drives so you can make an educated guess at what drive letters will be assigned to usb drives, based on the spec of your machines. You can then have 'no executable' policy on these drive letters.
  • 4 weeks later...
Posted

With regards to using the gpo to only allow software you have on there, all they would have to do to get around that is rename the setup file(s) to something that is allowed to run on the machine like winword or calc etc.

 

Not true if you specify the full path to the file eg "C:\windows\system32\calc.exe" will only run calc in that directory, i fyou just specify "Calc.exe" then any pogram called calc will run

 

Only know this cos im working on setting this feature up in my school and tested that exact scenario.

Posted

This could be a bit of a long post, but bear with me.

 

I don't know about you, but most of the unsolicited mail that appears in my pigeon-hole or inbox goes straight in the bin, but a few years ago I read one flyer that literally changed my life as a Network Manager.

 

The blurb read something like - "How would you like to protect your PCs from any unauthorised deletions or installations, viruses or anything else that could harm it?" Yeah!!

 

Out of curiosity I got a guy in to demonstrate his product. He set up a PC and challenged me to b*gger it up. OK - delete Windows folder, that should do it! Wrong!! Format C: Nope! He just switched the machine off and turned it on again. It was exactly as it was before I played with it. I was gob-smacked!

 

What he was selling was then called a Teachers Smart Card, which has been variously named since then a PCCure Card, a Safekey Card and the latest a Reborn Card.

 

We now have this device on all PCs with student access. Believe me, it works. For the last 7 years I've challenged students to crack it and so far only one has managed it (with a Linux bootable USB drive and a couple of Linux command line instructions).

 

It means that we don't have to have any restrictions on the workstations whatsoever. We don't even need to run Anti-Virus software, as when you restart the machines any viruses are wiped. We do run McAfee Enterprise on the servers!

 

It's a Realtek LAN card with a custom boot ROM. When the machine is set up a hidden, very non-standard partition is created on the hard-drive that somehow logs any changes to the machine. When the machine is restarted all the changes are reversed. It doesn't create a complete image, just remembers the changes, so it's really quick - no more long waits while the image is restored from the server.

 

Setting up machines is easy - just create a master and clone the rest from that. Machine names and static IP addresses are created automatically if you want.

 

One slight draw-back is that if you actually want to do any changes or updates you have to start each machine in Supervisor Mode, so that the changes aren't reversed. On the later incarnations you can do this remotely.

 

Amazingly the company that originally imported these cards couldn't sell enough to make a profit and folded. I then managed to import them from Denmark for a while, but now they are available again in UK. I can't understand why more people don't use them.

 

The latest version comes with facilities like remote shut-down or reboot, remote control etc. etc.

 

So no more use for DriveImage or Ghost or any other time-consuming software restore solutions - just turn it off and turn it back on again!

 

I'm happy to supply more details.

 

RoyG

Posted
Were they not at BETT? I know there was at least one firm demonstrating that kind of thing near the AVG stand area?

 

Didn't notice anything yesterday.

 

RoyG

Posted
I am sure it was near the AVG stand, but its so big I may be wrong as these stands merge into one. I have not got the info here, but they were very pushy
Posted
I am sure it was near the AVG stand, but its so big I may be wrong as these stands merge into one. I have not got the info here, but they were very pushy

The company I buy from definitely wasn't there.

 

RoyG

Posted
we have an issue where policies are in place but they use word's webtools to allow them access to command.com to have access to the system drive and install software

 

You can use one of the security policies to change the permissions on this file, thats what I did.

Posted

The problem with software solutions & policy restrictions is that you're for ever chasing your tail! Put restrictions on kids and they'll do their damndest to get round them, so you have to add more restrictions, which they see as a new challenge..........

We are a grammar school, not full of goody-goodies, just brighter villains, and when we used policy restrictions before we started using the Reborn cards they took up the challenge to mess up the workstations and frequently succeeded.

So take away the challenge, let 'em wipe the Windows folder, or run FDisk, see if I care! Restart the machine, problem solved. The point is that they don't bother trying any more.

Invest £30 - buy one & try it

 

RoyG

 

P.S. No, I'm not on commission!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...