installing2003服务器系统
2003服务器系统 时间:2021-02-28 阅读:(
)
LockingDownWindowsServer2003TerminalServerSessionsMicrosoftCorporationPublished:July,2003AbstractThisarticledemonstratestheabilityofActiveDirectorytorestrictMicrosoftWindowsServer2003TerminalServersessionstothefunctionalityallowedbyanadministrator.
Highlightingimportantgrouppolicies,considerationsareoutlinedforconfiguringuserinteractionswiththeoperatingsystemforawidevarietyofdeployments.
MicrosoftWindowsServer2003WhitePaperThisisapreliminarydocumentandmaybechangedsubstantiallypriortofinalcommercialreleaseofthesoftwaredescribedhereinTheinformationcontainedinthisdocumentrepresentsthecurrentviewofMicrosoftCorporationontheissuesdiscussedasofthedateofpublication.
BecauseMicrosoftmustrespondtochangingmarketconditions,itshouldnotbeinterpretedtobeacommitmentonthepartofMicrosoft,andMicrosoftcannotguaranteetheaccuracyofanyinformationpresentedafterthedateofpublication.
Thisdocumentisforinformationalpurposesonly.
MICROSOFTMAKESNOWARRANTIES,EXPRESSORIMPLIED,ASTOTHEINFORMATIONINTHISDOCUMENT.
Complyingwithallapplicablecopyrightlawsistheresponsibilityoftheuser.
Withoutlimitingtherightsundercopyright,nopartofthisdocumentmaybereproduced,storedinorintroducedintoaretrievalsystem,ortransmittedinanyformorbyanymeans(electronic,mechanical,photocopying,recording,orotherwise),orforanypurpose,withouttheexpresswrittenpermissionofMicrosoftCorporation.
Microsoftmayhavepatents,patentapplications,trademarks,copyrights,orotherintellectualpropertyrightscoveringsubjectmatterinthisdocument.
ExceptasexpresslyprovidedinanywrittenlicenseagreementfromMicrosoft,thefurnishingofthisdocumentdoesnotgiveyouanylicensetothesepatents,trademarks,copyrights,orotherintellectualproperty.
Theexamplecompanies,organizations,products,peopleandeventsdepictedhereinarefictitious.
Noassociationwithanyrealcompany,organization,product,personoreventisintendedorshouldbeinferred.
2003MicrosoftCorporation.
Allrightsreserved.
Microsoft,Windows,theWindowslog,andWindowsServerareeitherregisteredtrademarksortrademarksofMicrosoftCorporationintheUnitedStatesand/orothercountries.
Thenamesofactualcompaniesandproductsmentionedhereinmaybethetrademarksoftheirrespectiveowners.
MicrosoftWindowsServer2003WhitePaperContentsIntroduction.
1Howcanthisbeimplemented1Planning2InstallingTerminalServer.
3RestrictiveComputerPolicies.
4RestrictiveUserPolicies.
7Non-PolicySettings.
20DisableInternetExplorerSearchCompanion20RemovePrintersandFaxesfromNewStartMenu.
20DisabletheFullPathinWindowsExplorer.
21RemoveInternetExplorerandWindowsExplorerfromtheQuickLaunchBar21DisableHelp.
21NetworkBrowsingbyUsingtheCommonOpen/SaveFileDialogBox.
21AdditionalRestrictions.
23SoftwareRestrictionPolicies23InternetExplorerinKioskMode.
23Summary.
24RelatedLinks.
25MicrosoftWindowsServer2003WhitePaperLockingDownWindowsServer2003TerminalServerSessions1IntroductionUsingTerminalServerinWindowsServer2003,youcanoperate32-bitapplications,suchasMicrosoftWordandMicrosoftExcel,anytimeandanywhere.
TerminalServerprovidescentralizedapplicationprocessing,management,andmaintenance.
Withthisflexibility,TerminalServercanbeusedinawidevarietyofapplicationsandenvironments.
Aterminalcanresideinanoffice,kiosk,classroom,laboratory,onafactoryfloor,oracrosstheinternetinanothercountrywhiletheserverisinasecureserverroom.
Forexample;TerminalServercanbeusedbyApplicationServiceProviderstoprovideaccessformultipleapplicationstocustomersovertheInternet.
Incertaindeployments,itmightbenecessarytorestrictuseractivitytoapredefinedsetofapplicationsorWindowsoperatingsystemfunctionality.
HowcanthisbeimplementedThiswhitepaperisintendedforadministratorswhoarealreadyfamiliarwithTerminalServerandtheActiveDirectory.
ItexplainshowyoucanusethefeaturesofActiveDirectorytorestrictusersessionsontheTerminalServertoonlytheapplicationsanddesktopfunctionalitythattheadministratordeemsnecessary.
Certaingrouppoliciesarehighlightedherewithbriefexplanationsoftheirbenefits.
Notallofthesettingsarenecessarybecausetheycancreateahighlyrestricteduserinterface.
UsethispaperasaguidetoconfigureTerminalServerforyourenvironment.
Foradetailedexplanationofeachpolicymentioned,seetheExplaintabintheGroupPolicyObjectEditor.
IfActiveDirectoryisnotavailable,administratorscanuseNTFSpermissionsorthelocalpolicyeditortorestrictapplicationaccess.
AlthoughmanypoliciescanbeappliedwithoutActiveDirectorybymeansofthelocalpolicyeditor,thatmethodisnotrecommended.
EnablingthesepoliciesinthelocalpolicyeditorrestrictsallaccountsontheTerminalServer,includingtheadministratoraccount.
Usingthelocalpolicyeditorcanalsobecumbersomeandisoutsidethescopeofthispaper.
UsingActiveDirectorytorestrictfunctionalityistherecommendedmeanstorestrictTerminalServersessionsinWindowsServer2003.
NoteThisarticledoesnotaddressmethodstosecuretheTerminalServeragainstmaliciousattacks.
Itdoesnotprovideaguaranteeagainsthackers,creativeusers,applications,ordriversthatcircumventtherestrictionsmentionedinthispaper.
FormoreinformationaboutsecuringTerminalServicesinMicrosoftWindows2000,seeSecuringWindows2000TerminalServicesat:http://go.
microsoft.
com/fwlink/LinkId=18404.
MicrosoftWindowsServer2003WhitePaperLockingDownWindowsServer2003TerminalServerSessions2PlanningThepolicieshighlightedinthearticlearebasicrestrictionsfortheuserinterfacefortheoperatingsystem.
Notallofthepoliciesarerequired,andsomemightnotbeappropriateincertainenvironments.
Testyourimplementationbeforedeployment.
Inadditiontodeterminingwhichrestrictionsaresuitableforyourenvironment,decidehowthesepolicieswillbeimplemented.
Thepoliciesmentionedinthisarticlecanseverelyrestrictfunctionalityforeventheadministratoraccount.
Itishighlyrecommendedthataneworganizationalunit(OU)andGroupPolicyobject(GPO)becreated.
Ifsystem-widerestrictionsmustbeappliedtotheTerminalServer,placetheTerminalServercomputerobjectintothelockeddownOU.
Doingsoenforcescomputer-basedrestrictionsontheTerminalServer.
Administratorshavetheoptiontoapplyuser-basedrestrictionstoallusers,includingadministratorswhologontotheTerminalServer.
Theserestrictionscanbeinadditionto,orinplaceofpoliciestheusertypicallyhaswhenloggingontothedomain.
Refertothecomputerloopbackpolicyforadditionalinformation.
Ifper-userrestrictionsneedtobeapplied,placetheuseraccountobjectintothelockeddownOU.
Doingso,however,enforcesuser-basedrestrictionsforthatuseraccountregardlessofwhichcomputertheuserusestologontothedomain.
Herearetworecommendationsforimplementationofgrouppolicies:1.
UseraccountsareplacedintothelockeddownOU.
CreateTerminal-Server-onlyuseraccountsandplacetheminthelockeddownOU.
AllowuserlogonstotheTerminalServerforonlytheseusersbyusingtheTerminalServerConfigurationMMCsnap-in.
InstructtheuserstoonlyusetheseaccountsontheTerminalServer.
Ifsomecomputerrestrictionsarenecessary,disableloopbackprocessingandplacetheTerminalServercomputerobjectintotheOU.
Asidefromtherestrictivecomputerpolicies,userscanhavedifferentlevelsofrestrictionsonthesameTerminalServer.
ThisimplementationallowsAdministratorstoperformsomeoperationsontheTerminalServerwhileusersareactive.
2.
OnlytheTerminalServercomputerobjectisplacedintothelockeddownOU.
AfterinstallingandconfiguringallapplicationsontheTerminalServer,placetheTerminalServercomputerobjectintothelockeddownOU.
Enableloopbackprocessing.
AlluserswhologontotheTerminalServerarethenrestrictedbyuser-basedpoliciesasdefinedbythelockeddownGPO,regardlessoftheOUtheuserislocatedin.
ThiscanpreventmanylocalchangesfrombeingappliedtotheTerminalServer;however,theservercanstillberemotelymaintained.
IfadministratorsneedaccesstotheTerminalServer,logoffallusersandtemporarilyrestricttheirlogonstotheTerminalServer.
MovetheTerminalServercomputerobjectoutofthelockeddownOU,thenlogon.
ReturntheTerminalServercomputerobjecttothelockeddownOU,andre-enableuserloginsaftermaintenanceiscomplete.
Thisimplementationdoesnotrequireuserstohavemultipleuseraccounts.
ItcanalsopreventconfigurationchangestotheTerminalServerwhileitisinproduction.
MicrosoftWindowsServer2003WhitePaperLockingDownWindowsServer2003TerminalServerSessions3Formoreinformationonconfiguringsecuritysettings,see"ToeditasecuritysettingonaGroupPolicyobject"at:http://go.
microsoft.
com/fwlink/linkid=18541.
InstallingTerminalServerWheninstallingTerminalServeronaWindowsServer2003computer,youareaskedtoselectapermissionscompatibilitysettingforeitherFullSecurityorRelaxedSecurity.
ThissettingcanbechangedlaterbyusingtheTerminalServerConfigurationMMCsnap-in.
ItisrecommendedthatyouselecttheFullSecurityoption.
DoingsorestrictspermissionsforTerminalServeruserstothe-Usersgroup.
TheFullSecuritysetting,however,mighthavecompatibilityissueswithsomelegacyapplications.
Ifthisisthecase,selecttheRelaxedSecuritysetting.
TheRelaxedSecuritysettingprovidesTerminalServeruserswithnearlyPowerUserlevelaccesstocertainsystemfoldersandregistrykeys.
IftheRelaxedSecuritysettingisselected,considerenablingpoliciestorestrictaccesstoregistryeditorsandfilebrowsers.
MicrosoftWindowsServer2003WhitePaperLockingDownWindowsServer2003TerminalServerSessions4RestrictiveComputerPoliciesThesepoliciesareonlyappliedtocomputerobjectsthatareplacedintothelockeddownOU.
Thesesettingsaresystemwide,affectingallusers.
[ComputerConfiguration\WindowsSettings\SecuritySettings\LocalPolicies\SecurityOptions]Devices:RestrictCD-ROMaccesstolocallylogged-onuseronlyRecommendedsetting:EnabledThispolicyallowsonlyuserswhologontotheconsoleoftheTerminalServeraccesstotheCD-ROMdrive.
ItisrecommendedthatyouenablethispolicytopreventusersandadministratorsfromremotelyaccessingprogramsordataonaCD-ROM.
Devices:Restrictfloppyaccesstolocallylogged-onuseronlyRecommendedsetting:EnabledThispolicyallowsonlyuserswhologontotheconsoleoftheTerminalServeraccesstothefloppydiskdrive.
Itisrecommendedthatyoutoenablethispolicytopreventusersandadministratorsfromremotelyaccessingprogramsordataonafloppydisk.
Interactivelogon:DonotdisplaylastusernameThispolicydoesnotdisplaythelastloggedonuseraccountattheWindowslogonpromptontheconsoleoftheTerminalServer.
ThispolicydoesnotaffectTerminalServerclientsthatlocallycachethelogonusername.
[ComputerConfiguration\WindowsSettings\SecuritySettings\SystemServices]HelpandSupportRecommendedsetting:DisabledThispolicydisablesHelpandSupportCenterservice.
ItpreventsusersfromstartingthenewWindowsHelpandSupportCenterapplication.
Thispolicydoesnotdisabletheoldhelpfiles(suchasthe*.
chm)orHelpinotherapplications.
Disablingthisservicemightcauseissueswithotherprogramsandservicesthatdependonthisservice.
ItisrecommendedthatyoudisablethisservicetopreventusersfromstartingotherapplicationsorviewingsysteminformationabouttheTerminalServer.
[ComputerConfiguration\AdministrativeTemplates\WindowsComponents\TerminalServices]RestrictTerminalServicesuserstoasingleremotesessionThispolicycanpreventasingleuserfromcreatingmultiplesessionsontheTerminalServerusingasingleuseraccount.
RemoveDisconnectoptionfromShutDowndialogboxMicrosoftWindowsServer2003WhitePaperLockingDownWindowsServer2003TerminalServerSessions5ThispolicyremovesthedisconnectoptionfromtheShutDownWindowsdialogbox.
ItdoesnotpreventusersfromdisconnectingsessiontotheTerminalServer.
UsethispolicyifyoudonotwantuserstoeasilydisconnectfromtheirsessionandyouhavenotremovedtheShutDownWindowsdialogbox.
[ComputerConfiguration\AdministrativeTemplates\WindowsComponents\TerminalServices\Client/Serverdataredirection]DonotallowdriveredirectionRecommendedsetting:EnabledBydefault,TerminalServermapsclientdrivesautomaticallyuponconnection.
Itisrecommendedthatyouenablethispolicytopreventusersfromhavingeasyaccesstoapplicationsontheirlocalcomputer.
[ComputerConfiguration\AdministrativeTemplates\WindowsComponents\TerminalServices\Sessions]SettimelimitfordisconnectedsessionsBydefault,TerminalServerallowsuserstodisconnectfromasessionandkeepalloftheirapplicationsactiveforanunlimitedamountoftime.
ThispolicyspecifiesatimelimitfordisconnectedTerminalServersessionstoremainactive.
UsethispolicyifyoudonotwantdisconnectedsessionstoremainactiveforalongtimeontheTerminalServer.
[ComputerConfiguration\AdministrativeTemplates\WindowsComponents\WindowsInstaller]DisableMicrosoftWindowsInstallerRecommendedsetting:Enabled-AlwaysIfthisissetfornon-managedapplicationsonly,theWindowsInstallerstillfunctionsforapplicationsthatarepublishedorassignedbymeansofgrouppolicies.
IfthisissettoAlways,WindowsInstalleriscompletelydisabled.
ThismaybebeneficialifsomepublishedorassignedapplicationsarenotwantedonTerminalServer.
DisablingWindowsInstallerdoesnotpreventinstallationofapplicationsbymeansofothersetupprogramsormethods.
Itisrecommendedthatapplicationsbeinstalledandconfiguredpriortoenablingthispolicy.
Afterthepolicyisenabled,administratorscannotinstallapplicationsthatuseWindowsInstaller.
[ComputerConfiguration\AdministrativeTemplates\System\GroupPolicy]UserGroupPolicyloopbackprocessingmodeIftheTerminalServercomputerobjectisplacedinthelockeddownOU,andtheuseraccountisnot,loopbackprocessingappliestherestrictiveuserconfigurationpoliciestoallusersontheTerminalServer.
Ifthispolicyisenabled,allusers,includingadministrators,loggingontotheTerminalServerareaffectedbytherestrictiveuserconfigurationpolicies,regardlessofwheretheuseraccountislocated.
Twomodesareavailable.
Mergemodefirstappliestotheuser'sownGPO,thentothelockeddownpolicy.
Thelockdownpolicytakesprecedenceovertheuser'sGPO.
ReplacemodejustusestheMicrosoftWindowsServer2003WhitePaperLockingDownWindowsServer2003TerminalServerSessions6lockeddownpolicyandnottheuser'sownGPO.
Thispolicyisintendedforrestrictionsbasedoncomputersinsteadoftheuseraccount.
Ifthispolicyisdisabled,andtheTerminalServercomputerobjectisplacedinthelockeddownOU,onlythecomputerconfigurationpoliciesisappliedtotheTerminalServer.
EachuseraccountmustbeplacedintotheOUtohaveuserconfigurationrestrictionplacedonthatuser.
MicrosoftWindowsServer2003WhitePaperLockingDownWindowsServer2003TerminalServerSessions7RestrictiveUserPoliciesThesepoliciesareappliedtouseraccountsthatareinthelockeddownOU.
Ifloopbackprocessingisused,alluseraccountsthatlogontocomputersthatareinthelockeddownOUalsohavetheserestrictionapplied.
[UserConfiguration\WindowsSettings\FolderRedirection]ApplicationDataRecommendedsetting:Basicredirectionandcreateafolderforeachuserundertherootpath.
OntheSettingstab,enablegranttheuserexclusiverights.
Enablemovecontentsoffoldertonewlocation.
Setthepolicyremovaltoredirectthefolderbacktothelocaluserprofilelocationwhenpolicyisremoved.
DesktopRecommendedsetting:Basicredirectionandcreateafolderforeachuserundertherootpath.
OntheSettingstab,enablegranttheuserexclusiverights.
Enablemovecontentsoffoldertonewlocation.
Setthepolicyremovaltoredirectthefolderbacktothelocaluserprofilelocationwhenpolicyisremoved.
MyDocumentsRecommendedsetting:Basicredirectionandcreateafolderforeachuserundertherootpath.
OntheSettingstab,enablegranttheuserexclusiverights.
Enablemovecontentsoffoldertonewlocation.
Setthepolicyremovaltoredirectthefolderbacktothelocaluserprofilelocationwhenpolicyisremoved.
StartMenuRecommendedsetting:Basicredirectionandredirecttothefollowinglocation.
OntheSettingstab,setthepolicyremovaltoredirectthefolderbacktothelocaluserprofilelocationwhenthepolicyisremoved.
Createa\Programs\Startupfolderunderthissharedfolder.
Enablingthesepoliciescanprovideacentralpointforbackingupuserdata.
Additionally,ifthepolicytorestrictaccesstolocaldrivesisenabled(below),theusersneedfolderredirectioniftheydonotwanttoseemessagessayingthattheyhaverestrictedaccess.
Ifaroamingprofileserverisnotavailable,localsharescanbeused.
Createamasterfolderforalloftheuserdata(suchasC:\userdata).
Createfoursubfolders,oneforeachfoldertype(suchasAppData,Desktop,MyDocs,andStart).
Shareeachofthesubfoldersandsetthesharepermissionsforthe"everyone"groupto"change".
Seteachpathtoitscorrespondingshare.
TheStartMenucanbeconfigureddifferently.
Itcanbesharedacrossallusers.
Placelinkstoapplicationsinhere.
Changethesharepermissionsforthe"everyone"groupto"read".
Youshouldmanuallycreatethe"Programs\Startup"folderunderthesharedStartupfolder(C:\userdata\Start\Programs\Startup).
MicrosoftWindowsServer2003WhitePaperLockingDownWindowsServer2003TerminalServerSessions8[UserConfiguration\AdministrativeTemplates\WindowsComponents\InternetExplorer]Search:DisableFindFilesviaF3withinthebrowserRecommendedsetting:EnabledThispolicydisablestheuseoftheF3keytosearchinMicrosoftInternetExplorerandWindowsExplorer.
UserscannotpressF3tosearchtheInternet(fromInternetExplorer)ortosearchtheharddisk(fromWindowsExplorer).
IftheuserpressesF3,apromptappearsthatinformstheuserthatthisfeaturehasbeendisabled.
Thispolicycanpreventauserformeasilysearchingforapplicationsontheharddisk.
ItisrecommendedthatyouenablethispolicytopreventusersfromsearchingforapplicationsonharddriveorbrowsingtheInternet.
[UserConfiguration\AdministrativeTemplates\WindowsComponents\InternetExplorer\Browsermenus]DisableContextmenuRecommendedsetting:EnabledThispolicypreventstheshortcutmenufromappearingwhenusersclicktherightmousebuttonwhileusingthebrowser.
Itisrecommendedthatyouenablethispolicytopreventusersfromusingtheshortcutmenuasanalternatemethodofrunningcommands.
HideFavoritesmenuThispolicypreventsusersfromadding,removing,oreditingthelistofFavoritelinks.
Ifyouenablethispolicy,theFavoritesmenuisremovedfromtheinterfaceandtheFavoritesbuttononthebrowsertoolbarappearsdimmed.
UsethispolicyifyouwanttoremovetheFavoritesmenufromWindowsExploreranddonotwanttogiveuserseasyaccesstoInternetExplorer.
[UserConfiguration\AdministrativeTemplates\WindowsComponents\ApplicationCompatibility]Preventaccessto16-bitapplicationsRecommendedsetting:EnabledThispolicypreventstheMS-DOSsubsystem(ntvdm.
exe)fromrunningfortheuser.
Thissettingaffectsthestartingofall16-bitapplicationsintheoperatingsystem.
Bydefault,theMS-DOSsubsystemrunsforallusers.
ManyMS-DOSapplicationsarenotTerminalServerfriendlyandcancausehighCPUutilizationduetoconstantpollingofthekeyboard.
Itisrecommendedthatyouenablethispolicytopreventthe16-bitcommandinterpreter,Command.
com,fromexecuting.
NoteThe"Preventaccessto16-bitapplications"policycanbeconfiguredinbothComputerConfiguration(system-wide)andUserConfiguration(userspecific).
MicrosoftWindowsServer2003WhitePaperLockingDownWindowsServer2003TerminalServerSessions9[UserConfiguration\AdministrativeTemplates\WindowsComponents\WindowsExplorer]RemovestheFolderOptionsmenuitemfromtheToolsmenuRecommendedsetting:EnabledRemovestheFolderOptionsitemfromallWindowsExplorermenusandremovestheFolderOptionsitemfromControlPanel.
Asaresult,userscannotusetheFolderOptionsdialogbox.
ItisrecommendedthatyouenablethispolicytopreventusersfromconfiguringmanypropertiesofWindowsExplorer,suchasActiveDesktop,Webview,OfflineFiles,hiddensystemfiles,andfiletypes.
RemoveFilemenufromWindowsExplorerRecommendedsetting:EnabledThispolicyremovestheFilemenufromMyComputerandWindowsExplorer.
ItdoesnotpreventusersfromusingothermethodstoperformtasksavailableontheFilemenu.
Itisrecommendedthatyouenablethispolicytoremoveeasyaccesstotaskssuchas"New,""OpenWith,"andshellextensionsforsomeapplications.
Enablingthispolicyalsopreventseasycreationofshortcutstoexecutables.
RemoveMapNetworkDriveandDisconnectNetworkDriveRecommendedsetting:EnabledThispolicypreventsusersfromconnectinganddisconnecttoshareswithWindowsExplorer.
Itdoesnotpreventmappinganddisconnectingdrivesfromotherapplicationsortheruncommand.
ItisrecommendedthatyouenablethispolicytoremoveeasyaccesstobrowsingthedomainfromWindowsExplorer.
Ifmappeddrivesarenecessary,theycanbemappedfromalogonscript.
RemoveSearchbuttonfromWindowsExplorerRecommendedsetting:EnabledItisrecommendedthatyouenablethispolicytopreventusersfromsearchingforapplicationsfromWindowsExplorer.
ThispolicydoesnotpreventsearchroutinesinotherapplicationsortheStartMenu.
RemoveSecurityTabRecommendedsetting:EnabledThispolicyremovestheSecuritytabfromWindowsExplorer.
IfuserscanopenthePropertiesdialogboxforfilesystemobjects,includingfolders,files,shortcuts,anddrives,theycannotaccesstheSecuritytab.
Itisrecommendedthatyouenablethispolicytopreventusersfromchangingthesecuritysettingsorviewingalistofalluserswhohaveaccesstotheobject.
RemoveWindowsExplorer'sdefaultcontextmenuRecommendedsetting:EnabledThissettingremovestheshortcutmenufromWindowsExplorer.
ItisrecommendedthatyouenablethispolicytopreventeasyaccesstoapplicationsthatplacehooksintotheshortcutMicrosoftWindowsServer2003WhitePaperLockingDownWindowsServer2003TerminalServerSessions10menu.
Thispolicydoesnotremoveothermethodsofaccessingapplicationsontheshortcutmenu,suchasusingshortcuthotkeys.
HidestheManageitemontheWindowsExplorershortcutmenuRecommendedsetting:EnabledThispolicyremovestheManageoptionfromWindowsExplorerorMyComputer.
TheManageoptionopenstheComputerManagementMMCsnap-in(compmgmt.
msc).
ItemslikeEventViewer,SystemInformation,andDiskAdministratorcanbeaccessedfromComputerManagement.
ThispolicydoesnotrestrictaccesstothesetasksfromothermethodssuchasControlPanelandtheruncommand.
ItisrecommendedthatyouenablethispolicytoremoveeasyaccesstosysteminformationabouttheTerminalServer.
HidethesespecifieddrivesinMyComputerRecommendedsetting:Enabled–RestrictA,B,C,andDdrivesonlyThispolicyonlyremovestheiconsfromMyComputer,WindowsExplorer,andthestandardfiledialogbox.
Itdoesnotpreventusersfromaccessthesedrivesbyusingothermeanssuchasthecommandprompt.
ThepolicyonlyallowsyoutohidedrivesAthroughD.
Itisrecommendedthatyouenablethispolicytohidethefloppydiskdrive,theCD-ROMdrive,andtheoperatingsystempartition.
Apartitionforpublicdatacanbeconfiguredtobetheonlydriveviewabletotheusers.
Ifrequired,NTFSpermissionscanbeusedtorestrictaccesstothispartition.
PreventaccesstodrivesfromMyComputerRecommendedsetting:Enabled–A,B,C,andDdrivesonlyThispolicypreventsaccesstodrivesAthroughDwithMyComputer,WindowsExplorerandthestandardfiledialogbox.
Thispolicydoesnotpreventaccessfromprogramsthatdonotusethecommondialogboxes.
Theuserscanstillstartapplicationsthatresideontherestricteddrives.
Itisrecommendedthatyouenablethispolicytorestrictfilebrowsingofsystempartitions.
RemoveHardwaretabRecommendedsetting:EnabledThispolicyremovestheHardwaretabfromMouse,Keyboard,andSoundsandAudioDevicesinControlPanel.
ItalsoremovestheHardwaretabfromthePropertiesdialogboxforalllocaldrives,includingharddrives,floppydiskdrives,andCD-ROMdrives.
ItisrecommendedthatyouenablethispolicytopreventusersfromusingtheHardwaretabtoviewthedevicelistordeviceproperties.
RemoveOrderPrintsfromPictureTasksRecommendedsetting:EnabledItisrecommendedthatyouenablethispolicytoremovethe"OrderPrintsOnlinefromPictureTasks"linkintheMyPicturesfolder.
RemovePublishtoWebfromFileandFoldersTasksRecommendedsetting:EnabledMicrosoftWindowsServer2003WhitePaperLockingDownWindowsServer2003TerminalServerSessions11ThispolicysettingremovesPublishthisfiletotheWeb,PublishthisfoldertotheWeb,andPublishtheselecteditemstotheWebfromFileandFoldertasksinWindowExplorer.
ItisrecommendedthatyouenablethispolicytopreventusersfrompublishingfilesorfolderstoaWebpage.
No"ComputersNearMe"inMyNetworkPlacesRecommendedsetting:EnabledThispolicyremovescomputersintheuser'sdomainfromlistsofnetworkresourcesinWindowsExplorerandMyNetworkPlaces.
Itdoesnotpreventusersfromconnectingtoothercomputersbyothermethods,suchasthecommandpromptortheMapNetworkDrivedialogbox.
Itisrecommendedthatyouenablethispolicytoremoveeasyaccesstobrowsingthedomain.
No"EntireNetwork"inMyNetworkPlacesRecommendedsetting:EnabledThispolicyremovesallcomputersoutsideoftheuser'slocaldomainfromlistsofnetworkresourcesinWindowsExplorerandMyNetworkPlaces.
Itdoesnotpreventusersfromconnectingtoothercomputersbyothermethods,suchascommandpromptortheMapNetworkDrivedialogbox.
Itisrecommendedthatyouenablethispolicytoremoveeasyaccesstobrowsingthenetwork.
TurnoffWindows+XhotkeysRecommendedsetting:EnabledThispolicyturnsoffWindows+Xhotkeys.
KeyboardswithaWindowslogokeyprovideuserswithshortcutstocommonshellfeatures.
Forexample,pressingthekeyboardsequenceWindows+RopenstheRundialogbox;pressingtheWindows+EstartsWindowsExplorer.
ItisrecommendedthatyouenablethispolicytopreventusersfromstartingapplicationswiththeWindowslogohotkey.
TurnonClassicShellRecommendedsetting:EnabledThispolicyallowsyoutoremovetheActiveDesktopandWebviewfeatures.
Ifyouenablethissetting,itdisablestheActiveDesktopandWebview.
Also,userscannotconfiguretheirsystemtoopenitemsbysingle-clicking(suchasinMouseinControlPanel).
Asaresult,theuserinterfacelooksandoperatesliketheinterfaceforWindowsNT4.
0,anduserscannotrestorethenewfeatures.
ItisrecommendedthatyouenablethispolicytoremoveFolderTasks.
SomeFolderTask,suchasfortheMyMusicfoldercanstartInternetExplorer.
[UserConfiguration\AdministrativeTemplates\WindowsComponents\WindowsExplorer\CommonOpenFileDialog]HidethecommondialogplacesbarRecommendedsetting:EnabledThispolicyremovestheshortcutbarfromtheCommonOpenFiledialogbox.
ThisfeaturewasoriginallyaddedinWindows2000,sodisablingitmakesitlookasitdidinWindowsNT4.
0andMicrosoftWindowsServer2003WhitePaperLockingDownWindowsServer2003TerminalServerSessions12earlier.
Thesepoliciesaffectonlyprogramsthatusethecommondialogbox.
Itisrecommendedthatyouenablethispolicytoremoveeasyaccesstobrowsingthenetworkorthelocalcomputer.
ItemsdisplayedinPlacesBarThispolicyallowsyoutoreplacethePlaceBaritemsintheCommonOpenFiledialogboxwithpredefinedentries.
Toviewthisbar,startNotepad,selectFile,andthenclickOpen.
[UserConfiguration\AdministrativeTemplates\WindowsComponents\TaskScheduler]HidePropertyPagesRecommendedsetting:EnabledItisrecommendedthatyouenablethispolicytopreventusersfromviewingandchangingthepropertiesofanexistingtask.
ProhibitTaskDeletionThispolicypreventsadministratorsfromdeletingtasksfromtheScheduledTasksfolder.
ThisdoesnotpreventadministratorsfromdeletingtaskswiththeATcommand,orfromaremotecomputer.
PreventTaskRunorEndThispolicypreventsadministratorsfromstartingandstoppingtasks.
ProhibitNewTaskCreationRecommendedsetting:EnabledItisrecommendedthatyouenablethispolicytopreventusersfromcreatingnewscheduledtasksandbrowsingforapplications.
ThisdoesnotpreventadministratorsfromcreatingnewtaskswiththeATcommand,orfromaremotecomputer.
[UserConfiguration\AdministrativeTemplates\WindowsComponents\WindowsMessenger]DonotallowWindowsMessengertoberunRecommendedsetting:EnabledThispolicydisablesWindowsMessengerfortheuser.
ItisrecommendedthatyouenablethispolicytopreventusersfromreceivinglinksorfilesfromotherWindowsMessengerusers.
[UserConfiguration\AdministrativeTemplates\WindowsComponents\WindowsUpdate]RemoveaccesstouseallWindowsUpdatefeaturesThispolicyremovesaccesstoWindowsUpdate.
Ifyouenablethissetting,allWindowsUpdatefeaturesareremoved.
ThisincludesblockingaccesstotheMicrosoftWindowsUpdateWebsiteathttp://go.
microsoft.
com/fwlink/LinkId=18539,fromtheWindowsUpdatehyperlinkontheStartmenu,andalsoontheToolsmenuinInternetExplorer.
WindowsautomaticupdatingisMicrosoftWindowsServer2003WhitePaperLockingDownWindowsServer2003TerminalServerSessions13alsodisabled;youareneithernotifiedaboutcriticalupdatesnordoyoureceivecriticalupdatesfromWindowsUpdate.
ThissettingalsopreventsDeviceManagerfromautomaticallyinstallingdriverupdatesfromtheWindowsUpdateWebsite.
ThispolicycanbeusedtopreventchangestotheTerminalServerwhileitisproduction.
IfyoudisableWindowsUpdate,youshouldscheduleperiodiccheckstoensureWindowshaslatestcriticalupdates.
[UserConfiguration\AdministrativeTemplates\StartMenu&Taskbar]RemovelinksandaccesstoWindowsUpdateRecommendedsetting:EnabledThispolicyremoveslinksandaccesstotheWindowsUpdateWebsite.
TheWindowsUpdateWebsiteisonlyavailableforadministrators.
ItisrecommendedthatyouenablethispolicytoremoveeasyaccesstoInternetExplorerforusers.
RemovecommonprogramgroupsfromStartMenuRecommendedsetting:EnabledThispolicyremovesshortcutstoprogramsfromtheallusers'profile.
OnlytheStartMenuintheuser'sprofileortheredirectedStartMenuisavailable.
Itisrecommendedthatyouenablethispolicytoremoveeasyaccesstobuilt-inapplicationslikegames,calculator,andmediaplayer.
RemovepinnedprogramslistfromStartMenuThispolicyremovesthePinnedProgramslistfromthenewStartMenu.
ItalsoremovesthedefaultlinkstoInternetExplorerandOutlookExpressiftheyarepinned,anditpreventsusersfrompinninganynewprogramstotheStartMenu.
TheFrequentlyUsedProgramslistisnotaffected.
RemoveprogramsonSettingsmenuRecommendedsetting:EnabledThispolicyremovesControlPanel,Printers,andNetworkConnectionsfromSettingsontheClassicStartmenu,MyComputerandWindowsExplorer.
Italsopreventstheprogramsrepresentedbythesefolders(suchasControl.
exe)fromrunning.
However,userscanstillstartControlPanelitemsbyusingothermethods,suchasright-clickingthedesktoptoopenDisplayPropertiesorright-clickingMyComputertoopenSystemProperties.
Itisrecommendedthatyouenablethispolicytopreventeasyaccesstoviewingorchangingsystemsettings.
RemoveNetworkConnectionsfromStartMenuRecommendedsetting:EnabledThispolicypreventstheNetworkConnectionsfolderfromopening.
ThepolicyalsoremovesNetworkConnectionsfromSettingsonStartMenu.
NetworkConnectionsstillappearsinControlPanelandinWindowsExplorer,butifuserstrytostartit,amessageappearsexplainingthatasettingpreventstheaction.
ItisrecommendedthatyouenablethispolicytopreventusersfromcreatingnewconnectionssuchasVPNorDial-up.
MicrosoftWindowsServer2003WhitePaperLockingDownWindowsServer2003TerminalServerSessions14RemovetheSearchmenufromStartMenuRecommendedsetting:EnabledThispolicyremovesthesearchfunctionfromtheStartmenu.
ThissettingremovesSearchfromtheStartmenuandfromtheshortcutmenuthatappearswhenyouright-clickStartMenu.
Also,thesystemdoesnotrespondwhenuserspressWindows+FortheF3key.
InWindowsExplorer,thesearchitemstillappearsontheStandardbuttonstoolbar,butthesystemdoesnotrespondwhentheuserpressesCTRL+F.
Also,Searchdoesnotappearintheshortcutmenuwhenyouright-clickaniconrepresentingadriveorafolder.
Thissettingaffectsthespecifieduserinterfaceelementsonly.
ItdoesnotaffectInternetExploreranddoesnotpreventtheuserfromusingothermethodstosearch.
Itisrecommendedthatyouenablethispolicytopreventusersfromeasilysearchingforapplicationsthattheyarenotassignedtothem.
RemoveDrag-and-DropshortcutmenusonStartMenuRecommendedsetting:EnabledThispolicypreventsusersfromusingthedrag-and-dropmethodtoreorderorremoveitemsontheStartmenu.
ThissettingdoesnotpreventusersfromusingothermethodsofcustomizingtheStartmenuorperformingthetasksavailablefromtheshortcutmenus.
ItisrecommendedthatyouenablethispolicytoremoveshortcutmenusfromtheStartmenu,includingtaskssuchascreatinganewshortcut.
RemoveFavoritesmenufromStartMenuThispolicypreventsusersfromaddingtheFavoritesmenutotheStartmenuortheClassicStartmenu.
UsethispolicyifyoudonotwantuserstoexecuteInternetExplorer.
NoteTheFavoritesmenudoesnotappearontheStartmenubydefault,butthispolicydisablestheFavoriteslink.
ThissettingonlyaffectstheStartmenu.
TheFavoritesmenustillexistsinWindowsExplorerandInternetExplorer.
RemoveHelpmenufromStartMenuRecommendedsetting:EnabledThispolicyremovestheHelplinkfromtheStartmenu.
ThissettingonlyaffectstheStartmenu.
TodisablethenewHelpandSupportapplicationdisabletheserviceinComputerConfiguration(SeeRestrictedComputerPolicies).
ItisrecommendedthatyouenablethispolicytopreventusersfromeasilyviewingSystemInformationabouttheTerminalServer.
MicrosoftWindowsServer2003WhitePaperLockingDownWindowsServer2003TerminalServerSessions15RemoveRunmenufromStartMenuRecommendedsetting:EnabledItishighlyrecommendedthatyouenablethispolicytopreventusersfromattemptingtoexecuteanyapplication.
ThisisverycriticalforlockingdowntheTerminalServer.
EnablingthisremovestheRuncommandfromtheStartmenu,NewTaskfromTaskManager,andusersareblockedfromenteringaUNCpath,localdrive,andlocalfoldersintotheInternetExploreraddressbar.
Also,userswithextendedkeyboardscannolongerdisplaytheRundialogboxbypressingWindows+R.
NoteThe"RemoveRunmenufromStartMenu"settingaffectsthespecifiedinterfaceonly.
Itdoesnotpreventusersfromusingothermethodstorunprograms.
RemoveMyNetworkPlaceiconfromStartMenuRecommendedsetting:EnabledThispolicyremovestheMyNetworkPlacesiconfromtheStartmenu.
Itisrecommendedthatyouenablethispolicytopreventeasyaccesstobrowsingthenetwork.
AddLogofftoStartMenuRecommendedsetting:EnabledItisrecommendedthatyouenablethispolicytomakeiteasyforuserstologoffoftheirTerminalServersessions.
Thispolicyaddsthe"LogOff"itemtotheStartmenuandpreventsusersfromremovingit.
ThissettingaffectstheStartmenuonly.
ItdoesnotaffecttheLogOffitemontheWindowsSecuritydialogboxthatappearswhenyoupressCTRL+ALT+DELorCTRL+ALT+ENDfromaTerminalServerclient.
RemoveandpreventaccesstoShutDowncommandRecommendedsetting:EnabledThispolicyremovestheabilityfortheusertoopentheShutdowndialogboxfromtheStartmenuandfromtheWindowsSecuritydialogbox(CTRL+ALT+DEL).
ThispolicydoesnotpreventusersfromrunningprogramstoshutdownWindows.
Itisrecommendedthatyouenablethispolicyhelpremoveconfusionfromtheusersandpreventadministratorsfromshuttingdownthesystemwhileitisinproduction.
PreventchangestoTaskbarandStartMenusettingsRecommendedsetting:EnabledThispolicypreventscustomizationofthetaskbarandtheStartmenu.
Itcansimplifythedesktopbyadheringtotheconfigurationsetbytheadministrator.
Itisrecommendedthatyouenablethispolicytorestricttheabilitytoaddotherapplicationstothestartmenubybrowsingortypingthelocationofanapplication.
MicrosoftWindowsServer2003WhitePaperLockingDownWindowsServer2003TerminalServerSessions16RemoveaccesstotheshortcutmenusforthetaskbarRecommendedsetting:EnabledThispolicyremovestheright-clickmenuonthetaskbar.
Thissettingdoesnotpreventusersfromusingothermethodstoissuethecommandsthatappearonthismenu.
ItisrecommendedthatyouenablethispolicytopreventpotentialaccesstofilesandapplicationsbystartingWindowsExplorerorSearch.
ForceClassicStartMenuThispolicyeffectsthepresentationoftheStartmenu.
TheClassicStartmenuinWindows2000allowsuserstobegincommontasks,whilethenewStartmenuconsolidatescommonitemsontoonemenu.
WhentheClassicStartmenuisused,thefollowingiconsareplacedonthedesktop:MyDocuments,MyPictures,MyMusic,MyComputer,andMyNetworkPlaces.
ThenewStartmenustartsthemdirectly.
DisablingthenewStartmenuremovesPrintersandFaxes.
FromPrintersandFaxes,userscanviewServerPropertiestoseewheretheSpoolfolderisinstalled.
[UserConfiguration\AdministrativeTemplates\Desktop]RemovePropertiesfromMyDocumentsshortcutmenuRecommendedsetting:EnabledThissettinghidesPropertiesfortheshortcutmenuonMyDocuments.
ItisrecommendedthatyouenablethispolicyifshortcutmenusarenotdisabledandyoudonotwanttheuserstoeasilyvieworeditthelocationoftheirMyDocumentfolder.
RemovePropertiesfromMyComputershortcutmenuRecommendedsetting:EnabledThissettinghidesPropertiesontheshortcutmenuforMyComputer.
ItisrecommendedthatyouenablethispolicyifshortcutmenusarenotdisabledandyoudonotwanttheuserstoeasilyviewconfigurationinformationabouttheTerminalServer.
RemovePropertiesfromRecycleBinshortcutmenuRecommendedsetting:EnabledThispolicyremovesthePropertiesoptionfromtheRecycleBinshortcutmenu.
ItisrecommendedthatyouenablethispolicyifshortcutmenusarenotdisabledandyoudonotwanttheuserstoeasilyvieworchangeRecycleBinsettings.
HideMyNetworkPlacesiconondesktopRecommendedsetting:EnabledItisrecommendedthatyouenablethispolicytoremoveeasyaccesstobrowsingthenetworkforapplications.
Thissettingonlyaffectsthedesktopicon.
Itdoesnotpreventusersfromconnectingtothenetworkorbrowsingforsharedcomputersonthenetworkwithothermethods.
MicrosoftWindowsServer2003WhitePaperLockingDownWindowsServer2003TerminalServerSessions17HideInternetExplorerIcononthedesktopThispolicyremovestheInternetExplorericonfromthedesktop.
ThissettingdoesnotpreventtheuserfromstartingInternetExplorerbyusingothermethods.
ProhibituserfromchangingMyDocumentspathRecommendedsetting:EnabledThispolicyrestrictstheMyDocumentslocationtothedesignatedlocation.
Itisrecommendedthatyouenablethispolicytopreventbrowsingforapplications.
HideanddisableallitemsonthedesktopThispolicyremovesicons,shortcuts,andotherdefaultanduser-defineditemsfromthedesktop,includingBriefcase,RecycleBin,MyComputer,andMyNetworkPlaces.
Removingiconsandshortcutsdoesnotpreventtheuserfromusinganothermethodtostarttheprogramsoropeningtheitemstheyrepresent.
UsercanstillsaveandopenitemsonthedesktopbyusingtheCommonFiledialogboxorWindowsExplorer.
Theitems;however,arenotdisplayedonthedesktop.
RemoveMyDocumentsicononthedesktopThispolicyremovesmostoccurrencesoftheMyDocumentsicon.
ItdoesnotpreventtheuserfromusingothermethodstogainaccesstothecontentsoftheMyDocumentsfolder.
RemoveMyComputericononthedesktopRecommendedsetting:EnabledThispolicyhidesMyComputerfromthedesktopandfromthenewStartmenu.
ItalsohideslinkstoMyComputerintheWebviewofallExplorerwindows,andithidesMyComputerintheExplorerfoldertreepane.
IftheusernavigatesintoMyComputerbyusingtheUpiconwhilethissettingisenabled,theyviewanemptyMyComputerfolder.
ItisrecommendedthatyouenablethispolicytopresentuserswithasimplerdesktopenvironmentandremoveeasyaccesstoComputerManagementandSystemPropertiesbynolongerallowingright-clickingoftheicon.
NoteHidingMyComputeranditscontentsdoesnothidethecontentsofthechildfoldersofMyComputer.
Forexample,iftheusersnavigateintooneoftheirharddrives,theyseealloftheirfoldersandfilesthereevenifthissettingisenabled.
[UserConfiguration\AdministrativeTemplates\ControlPanel]ProhibitaccesstotheControlPanelRecommendedsetting:EnabledThispolicyremovesaccesstoControlPanelanddisablesallControlPanelprograms.
ItalsopreventsControl.
exe,theprogramfileforControlPanel,fromstarting.
ItisrecommendedthatyouenablethissettingtopreventusersfromviewingconfigurationinformationabouttheTerminalServer.
MicrosoftWindowsServer2003WhitePaperLockingDownWindowsServer2003TerminalServerSessions18[UserConfiguration\AdministrativeTemplates\ControlPanel\AddorRemovePrograms]RemoveAddorRemoveProgramsRecommendedsetting:EnabledThispolicyremovesAddorRemoveProgramsfromControlPanelandremovestheAddorRemoveProgramsitemfrommenus.
IfaccesstoControlPanelisprohibited,thispolicycanbeusedtoremovethelinkstoAddorRemoveProgramsfromplaceslikeMyComputer.
Thelinkthendisplaysanaccessdeniedmessageifclicked.
Thissettingdoesnotpreventusersfromusingothertoolsandmethodstoinstalloruninstallprograms.
ItisrecommendedthatyouenablethispolicytopreventuserstoviewingTerminalServerconfigurationinformation.
[UserConfiguration\AdministrativeTemplates\ControlPanel\Printers]PreventadditionofprintersRecommendedsetting:EnabledThispolicypreventsusersfromusingfamiliarmethodstoaddlocalandnetworkprinters.
Itisrecommendedthatyouenablethispolicytopreventusersfrombrowsingthenetworkorsearchingtheactivedirectoryforprinters.
Thispolicydoesnotpreventtheauto-creationofTerminalServerredirectedprinters,nordoesitpreventusersfromrunningotherprogramstoaddprinters.
[UserConfiguration\AdministrativeTemplates\System]PreventaccesstothecommandpromptRecommendedsetting:Enabled–Set"Disablethecommandpromptscriptprocessingalso"toNo.
ThispolicypreventsusersfromrunningtheinteractivecommandpromptCmd.
exe.
Fromthecommandpromptuserscanstartapplications.
Thissettingalsodetermineswhetherbatchfiles(.
cmdand.
bat)canrunonthecomputer.
NoteDonotpreventthecomputerfromrunningbatchfilesonaTerminalServer.
ThispolicydoesnotpreventaccesstoCommand.
com(16-bitcommandinterpreter).
TodisabletheCommand.
com,youcanrestrictaccesswithNTFSpermission,ordisableall16-bitapplicationswiththe"Preventaccessto16-bitapplication"policy.
Itisrecommendedthatyouenablethe"Preventaccesstothecommandprompt"policytopreventusersfrombypassingotherpoliciesbyusingthecommandpromptinsteadofWindowsExplorerastheshell.
MicrosoftWindowsServer2003WhitePaperLockingDownWindowsServer2003TerminalServerSessions19PreventaccesstoregistryeditingtoolsRecommendedsetting:EnabledThispolicyrestrictsusersfromchangingregistrysettingsbydisablingRegedit.
exe.
Itisrecommendedthatyouenablethispolicytopreventusersfromchangingtheirshelltothecommandpromptorbypassingseveralotherpolicies.
Thispolicydoesnotpreventotherapplicationsforeditingtheregistry.
RunonlyallowedWindowsapplicationsRecommendedsetting:Enabled–DefinelistofauthorizedapplicationsItisrecommendedthatyouenablethispolicytorestrictuserstoonlyrunprogramsthatareaddedtotheListofAllowedApplications.
ThissettingonlypreventsusersfromrunningprogramsthatarestartedbyWindowsExplorer.
ItdoesnotpreventusersfromrunningprogramssuchasTaskManager,whichcanbestartedbyasystemprocess.
Also,ifusershaveaccesstothecommandprompt,Cmd.
exe,thissettingdoesnotpreventthemfromstartingprogramsfromthecommandwindowthattheyarenotpermittedtostartbyusingWindowsExplorer.
[UserConfiguration\AdministrativeTemplates\System\CTRL+ALT+DELOptions]RemoveTaskManagerRecommendedsetting:EnabledThispolicypreventsusersfromstartingTaskManager.
Itisrecommendedthatyouenablethispolicytopreventusersfromusingtaskmanagertostartandstopprograms;monitortheperformanceoftheTerminalServer;andfindtheexecutablenamesforapplications.
RemoveLockComputerThispolicypreventsusersfromlockingtheirsessions.
Userscanstilldisconnectandlogoff.
Whilelocked,thedesktopcannotbeused.
Onlytheuserwholockedthesystemorthesystemadministratorcanunlockit.
[UserConfiguration\AdministrativeTemplates\System\Scripts]RunlegacylogonscriptshiddenRecommendedsetting:EnabledThispolicyhidestheinstructionsinlogonscriptswrittenforWindowsNT4.
0andearlier.
ItisrecommendedthatyouenablethispolicytopreventusersfromviewingorinterruptinglogonscriptswrittenforWindowsNT4.
0andearlier.
MicrosoftWindowsServer2003WhitePaperLockingDownWindowsServer2003TerminalServerSessions20Non-PolicySettingsDisableInternetExplorerSearchCompanionUserscanaccesstheInternetExplorerSearchCompanionbyclickingSearchonthetoolbar,orpressingCTRL-EinInternetExplorer.
WiththeInternetExplorerSearchCompanion,userscanbrowseorsearchforfilesandfolders.
ThereisnopolicytodisabletheInternetExplorerSearchCompanion.
Thisoperationneedstobepreformedmanually.
1.
Createatextfileonthelocalpartition,(c:\windows\nosearch.
txt)2.
Thecontentofthetextfilecanbe"Searchisdisabled.
"3.
SettheNTFSpermissionsofthefileto"Everyone–ReadandExecute".
4.
Thenmodifythefollowingregistryvalues:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\InternetExplorer\Search"SearchAssistant"=REG_SZ:c:\windows\nosearch.
txt"CustomizeSearch"=REG_SZ:c:\windows\nosearch.
txtWhentheusersopentheSearchCompanion,thecontentsofthetextfilearedisplayed.
ItispossibletouseaHypertext(Html)fileinsteadofatextfile.
RemovePrintersandFaxesfromNewStartMenuThenewStartMenuoffersalinktothePrintersandFaxesfolder.
FromthisfolderuserscanviewServerPropertiesfortheprintspooler.
OntheAdvancedtab,userscanview,notedit,thelocationofthespoolfolder.
TodisableeasyaccesstotheServerPropertiesdialogbox,dooneofthefollowing:1.
Enablethe"TurnonClassicShell"and"RemoveFilemenufromWindowsExplorer"policies.
2.
Setthefollowingregvalue:[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]"Start_ShowPrinters"=REG_DWORD:0x000000003.
Enablethe"PreventchangestoTaskbarandStartMenuSettings"policy.
(Theregistrysettingcanbedeployedbymeansoflogonscripts(executingregedit/shideprinters.
reg)orbyusingacustomADMfile.
)4.
Right-clicktheStartbutton,selectProperties,selecttheStartMenutab,andthenclickCustomize.
5.
SelecttheAdvancedtab,clearthePrintersandFaxescheckbox,andthenenablethe"PreventchangestoTaskbarandStartMenuSettings"policy.
(ItisrecommendedthatyouremovetheStartMenushortcutmenus,andthendisableaccesstoControlPanel.
6.
DisablethenewStartMenubyenablingthe"ForceClassicStartMenu"policy,andthenenablethe"RemoveFilemenufromWindowsExplorer"policy.
MicrosoftWindowsServer2003WhitePaperLockingDownWindowsServer2003TerminalServerSessions21DisabletheFullPathinWindowsExplorerBydefaultthefullpathtothecurrentfolderinWindowsExplorerisdisplayed.
IfFolderRedirectionisusedandusersnavigatebeyondtheMyDocumentsfolder,theaddressbardisplaysthefullpathtothefolder.
ThisisaconfigurableFolderOptionthatcannotbesetbygrouppolicies.
Todisablethefullpath,dooneofthefollowing:1.
InWindowsExplorer,clickToolsontheToolbar,thenselectFolderOptions.
2.
ClicktheViewtab,andthencleartheDisplaythefullpathintheaddressbarandDisplaythefullpathinthetitlebarcheckboxes.
3.
Enablethe"RemoveFolderOptionsmenuitemfromToolsmenu"policy.
4.
Setthefollowingregvalues:[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CabinetState]"FullPathAddress"=REG_DWORD:0x00000000"FullPath"=REG_DWORD:0x00000000Theregistrysettingcanbedeployedbymeansoflogonscripts(executingregedit/saddressbar.
reg)orbyusingacustomADMfile.
RemoveInternetExplorerandWindowsExplorerfromtheQuickLaunchBarBydefaultlinkstoInternetExplorerandWindowsExplorerareaddedtotheQuickLaunchbar.
Theselinkscanberemovedfromalogonscriptbyaddingthefollowinglines:del"%userprofile%\ApplicationData\Microsoft\InternetExplorer\QuickLaunch\explorer.
exe.
lnk"del"%userprofile%\ApplicationData\Microsoft\InternetExplorer\QuickLaunch\LaunchInternetExplorerBrowser.
lnk"DisableHelpHelpfilescanbeopenedfrommanyapplicationsbypressingF1.
ManyofthesehelpfilescanprovideuserswithlinkstootherapplicationsandWebsitesthattheywouldnormallynothaveaccessto.
GroupPolicydoesnotexisttorestrictaccesstohelpinapplications.
ItisnecessarytorestrictNTFSaccessto.
chmand.
hlpfiles.
ThemajorityofWindowshelpfilesresideinthe%SystemRoot%\Helpfolder—typically,c:\windows\help.
Simplyremovetheusergroupsfromtheaccesscontrollisttothefolder.
Thenselecttheoptiontoreplacepermissionentriesonallchildobjects.
DoingsopreventsHelpfilesfromopeningforusers.
NetworkBrowsingbyUsingtheCommonOpen/SaveFileDialogBoxTheCommonOpen/SaveFiledialogboxisusedbymanyapplicationstoopenorsavefiles.
ItcanbeseenbyselectingOpenorSaveontheFilemenufromapplicationssuchasNotepad.
Fromthepathentrybox,userscanbrowsethenetwork.
FromtheOpen/SaveFiledialogbox,userscanenterUNCpaths,suchas\\localhost,andthenbrowsethesharesforthelocalserver.
ByusingtheUPARROWtogettotheparentobject,theusercanbrowseeitherthedomainorthenetwork.
Althoughusersmightbeabletoseeserverandsharenames,theyarestillrestrictedbyshare-levelandNTFS-levelpermissions.
Ifyouneedtopreventusersfromviewingserverorsharenames,thefollowingoptionsareavailable:MicrosoftWindowsServer2003WhitePaperLockingDownWindowsServer2003TerminalServerSessions221.
UsetheRestrictAnonymousregistryvalueinconjunctionwithshareandNTFSpermissionstorestrictaccess.
Formoreinformation,seeKnowledgeBasearticle246261,"HowtoUsetheRestrictAnonymousRegistryValueinWindows2000"athttp://go.
microsoft.
com/fwlink/LinkId=18396.
2.
Hideasharenamebyaddingatrailing"$"totheendofthesharename.
Formoreinformation,KnowledgeBasearticle90929,"ShareNamesWitha"$"CharacterattheEndAreHidden"athttp://go.
microsoft.
com/fwlink/LinkId=18403.
3.
Configurecomputerstonotsendannouncementstobrowsersonthedomain.
Thiscanbeaccomplishedbyaddingthefollowingregistryvalueorexecutingthefollowingcommand:Fromtheregistry:HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanServer\ParametersValuename:HiddenDatatype:REG_DWORDValuedata:1Theregistrysettingcanbedeployedbymeansoflogonscripts(executingregedit/saddressbar.
reg)orbyusingacustomADMfile.
Fromthecommandline:"netconfigserver/hidden:yes"Formoreinformation,seeKnowledgeBasearticle321710,"HOWTO:HideaWindows2000-BasedComputerfromtheBrowserList"athttp://go.
microsoft.
com/fwlink/LinkId=18397MicrosoftWindowsServer2003WhitePaperLockingDownWindowsServer2003TerminalServerSessions23AdditionalRestrictionsSoftwareRestrictionPoliciesSoftwarerestrictionpoliciesareanewfeatureinMicrosoftWindowsXPandWindowsServer2003.
Thisimportantfeatureprovidesadministratorswithapolicy-drivenmechanismforidentifyingsoftwareprogramsrunningoncomputersinadomain,anditcontrolstheabilityofthoseprogramstoexecute.
Policiescanbeusedtoblockmaliciousscripts,helplockdownacomputer,orpreventunwantedapplicationsfromrunning.
ForadditionalinformationaboutSoftwareRestrictionPolicies,seethewhitepaper,"UsingSoftwareRestrictionPoliciestoProtectAgainstUnauthorizedSoftware,"athttp://go.
microsoft.
com/fwlink/LinkId=17299andKnowledgeBasearticle324036,"HOWTO:UseSoftwareRestrictionPoliciesinWindowsServer2003,"athttp://go.
microsoft.
com/fwlink/LinkId=18400.
InternetExplorerinKioskModeAdministratorscanreplacethestandardWindowsExploreruserinterfacewithInternetExplorerinKioskmode.
WhenyourunInternetExplorerinKioskmode,theInternetExplorertitlebar,menus,toolbars,andstatusbararenotdisplayed,andInternetExplorerrunsinFullScreenmode.
OnlyWebpagesaredisplayed.
InternetExplorerinKioskmodecanbeenabledbyenablingthefollowingpolicy:[UserConfiguration\AdministrativeTemplates\System]CustomuserinterfaceRecommendedsetting:EnabledInterfacefilename:"%ProgramFiles%\InternetExplorer\IExplore.
exe"–KIfInternetExplorerinKioskmodeisusedastheuserinterface,itisstronglyrecommendreviewingandenablingInternetExplorerrestrictivepoliciesunderthefollowingsections:[ComputerConfiguration\AdministrativeTemplates\WindowsComponents\InternetExplorer][UserConfiguration\AdministrativeTemplates\WindowsComponents\InternetExplorer]MicrosoftWindowsServer2003WhitePaperLockingDownWindowsServer2003TerminalServerSessions24SummaryWindowsServer2003isafeature-richplatformthatcanprovidethefunctionalityofTerminalServertoawidevarietyofenvironments.
Thesedeploymentsrequirevariousdegreesofcontrolandmanageability.
UsingActiveDirectory,youcanquicklyandeasilyconfigureTerminalServertointegratewithdiverseenvironments,providingcontrolleddesktopfunctionalityandmanagedaccesstoapplications.
MicrosoftWindowsServer2003WhitePaperLockingDownWindowsServer2003TerminalServerSessions25RelatedLinksSeethefollowingresourcesforfurtherinformation:MicrosoftWindowsServer2003TerminalServerOverviewathttp://go.
microsoft.
com/fwlink/LinkId=17300MicrosoftWindowsServer2003ActiveDirectoryOverviewathttp://go.
microsoft.
com/fwlink/LinkId=18540SecuringWindows2000TerminalServicesathttp://go.
microsoft.
com/fwlink/LinkId=18404.
HowtoUsetheRestrictAnonymousRegistryValueinWindows2000athttp://go.
microsoft.
com/fwlink/LinkId=18396KnowledgeBasearticle90929"ShareNamesWitha"$"CharacterattheEndAreHidden"athttp://go.
microsoft.
com/fwlink/LinkId=18403.
KnowledgeBasearticle321710,"HOWTO:HideaWindows2000-BasedComputerfromtheBrowserList"athttp://go.
microsoft.
com/fwlink/LinkId=18397UsingSoftwareRestrictionPoliciestoProtectAgainstUnauthorizedSoftwareathttp://go.
microsoft.
com/fwlink/LinkId=17299KnowledgeBasearticle324036"HOWTO:UseSoftwareRestrictionPoliciesinWindowsServer2003,"athttp://go.
microsoft.
com/fwlink/LinkId=18400Windows2003ServerWebsiteathttp://go.
microsoft.
com/fwlink/LinkId=18405
NameCheap商家如今发布促销活动也是有不小套路的,比如会在提前一周+的时间告诉你他们未来的活,比如这次2021年的首次活动就有在一周之前看到,但是这不等到他们中午一点左右的时候才有正式开始,而且我确实是有需要注册域名,等着看看是否有真的折扣,但是实际上.COM域名力度也就一般需要51元左右,其他地方也就55元左右。当然,这次新年的首次活动不管如何肯定是比平时便宜一点点的。有新注册域名、企业域...
数脉科技怎么样?数脉科技品牌创办于2019,由一家从2012年开始从事idc行业的商家创办,目前主营产品是香港服务器,线路有阿里云线路和自营CN2线路,均为中国大陆直连带宽,适合建站及运行各种负载较高的项目,同时支持人民币、台币、美元等结算,提供支付宝、微信、PayPal付款方式。本次数脉科技给发来了新的7月促销活动,CN2+BGP线路的香港服务器,带宽10m起,配置E3-16G-30M-3IP,...
hostkvm在2021年3月新上线洛杉矶新VPS业务,强制三网接入中国联通优化线路,是当前中美之间性价比最高、最火热的线路之一,性价比高、速度非常好,接近联通AS9929和电信AS4809的效果,带宽充裕,晚高峰也不爆炸。 官方网站:https://hostkvm.com 全场优惠码:2021(全场通用八折,终身码,长期) 美国 US-Plan0【三网联通优化线路】 内存:1G CPU:...
2003服务器系统为你推荐
拂晓雅阁我对电脑操作不熟悉,想买一本自学的电脑书籍,是电脑入门那一类的,最好还有办公软件应用那一类的伪静态静态与伪静态的区别?唱吧电脑版官方下载唱吧有没有电脑版的啊?怎么点亮qq空间图标如何点亮QQ空间图标qq空间打扮QQ空间打扮商标注册查询官网如何在网上查询商标是否注册?iphone6上市时间苹果六什么时候出的iphone6上市时间苹果6什么时候出?网页打开很慢如何解决网速正常 网页打开很慢问题网络虚拟机虚拟机网络设置
香港vps 日本动态vps 什么是二级域名 淘宝抢红包攻略 lamp安装 网络星期一 mobaxterm 国外免费空间 主机合租 好看qq空间 免费网站申请 vip购优汇 谁的qq空间最好看 流量计费 域名和空间 河南移动网 超级服务器 域名dns 联通网站 香港ip 更多