Hi Michael, thanks so much for the reply.
We haven't actually tried that, we usually create a local admin account, but quite possibly that would be a much easy way to go. That can go down on the stuff to do today.
With local policy, I have created a configuration setup see attached PDF below, but there's 2 problems with that. When I log into the admin account, the local policy is still applied. Will also work with any other accounts that logon to the system (student accounts etc). I would like to be able to login to the admin account and modify the system if needed without to much alteration, getting into the system. I will be trying this out today --> Local Group Policies - Apply to All Users Except Administrators - Windows 7 Forums..
PDF: http://non-stop-tech.com/ftp/Local%20GPO%20Configuration%20of%20Windows%207%20Student%20Systems.pdf
The other thing is I would like to use local GPO to block other programs as well, but not sure if I'm going to have to use local polilcies as well as something else. I am looking at using AppLocker but I have never used it before and not sure how effective it is.
Also I am trying to work out, can this be applied to blocking games from being run? Always copies of HALO, and counter strike (just to name a few) on these machines, usually always taking up space and instead of saving their school work, they cant because they don't have any more room left out of 160GB hdd! The other common one is the SWF flash files. We do need to run swf for some classes here so not sure if I can even tackle that one.
If there was software which was going to take the place of local group policy (like winselect) I wouldn't want it to be network deployable. This was such a pain when we used faronics sever management tool to deploy the software out over the machines. When I was creating the initial image at the end of last year, I wanted to have this installed during no sys prep, but for some reason as soon as it came time to capture, the image would corrupt itself each time, then I took out the software and it captured fine. Finally it came to being installed after the final sys prep image. So every time I have to do a re-format on a system, that software has to be installed and setup every time!! Its not too good when you do that nearly 20 times a week. The other thing is, even with a fresh install of the OS, the software doesn't always deploy even though it see the machine in the server..
So when I make an image, usually I create two accounts, one for the local admin, and the other is called user. User account is basically used to build up what I want the student to use program wise, start menu etc etc. Eventually we make two copies of the 'default' account in the users folder on C:, one called default_(with date create), and the user account gets renamed to the new default account. Than from their sys prep is captured and the setup I have made in the user account gets used as a standard setup for all student accounts. The admin account is mostly used just as a diag account, or if I need to install additional software I can go into this and install with full admin rights. Both these account are created as Administrator accounts when the system is first setup.
Should I create the user account as a standard account to prevent tools from sys32 being used?
Thanks again for your suggestions and help,will be trying them out today and seeing how it goes.
Kind regards, Kieren