take a look at microsofts best practice for locking down workstations http://technet2.microsoft.com/windowsserver/en/library/73907fc3-0390-4264-911e-2b374d90b6041033.mspx?mfr=true and download the commonscenarios.msi file
Hi, I was wondering if anyone out there could shed some light or a workaround for an issue we are having.
We are a large organisation of 1000 users with Windows 2000/2003 DC's. We have a helpdesk user (account operator and server operator) who creates folders and shares them. Our standard being...
I think I have sussed this, enter location under the appropriate subnet within sites & services..then use the "prepopulate" option within a GPO and it works fine.
Only issue I now have is getting enterprise admin rights for our forest ! I only have domain admin rights for our domain..ho hum
Hi All,
First of all, apologies for the long(ish) post.
We have a mixture of Windows 2000/2003 Print servers (which are also DCs) spread across 12 countries.. I have been experimenting with the GPO functionality to help users locate printers easily.
I have configured the "computer location"...
Hi there,thanks for your responses.
The updates are pushed out via GPO and I have been testing with the Deadline utility, problem is that it forces a reboot of the workstation which could be a problem. What we want is a situation where the updates are "pulled" from the WSUS server by the...
Hi there, I was wondering if you can help me. We are running WSUS 2.0 SP1 on a Windows 2003 Server. Our workstations are a mix of XP and 2000 Pro. When workstations pickup the wsus updates, the yellow shield appears as expected. But the problem is, a lot of users dont click on the shield to...
Hi there,
In Group Policies: User -> Admin Templates -> System there is a policy titled "Don't Run Specified Windows Applications." Link that to an OU and specify "msmsgs.exe" as an executable to prevent.
The users will then get a popup message when they try to run MSN.
This policy can of...
Create an OU, and move the user accounts for the users concerned. Create a GPO and enter a proxy address as 127.0.0.1 There are plenty of posts on the subject in these forums, so do a search for further info.
Can you not install the DHCP snap in on a server/workstation then right click on it and look at "authorised servers". This will tell you which servers have been authorised in AD.
Mike,
To add the helpdesk global group to the local admin groups on client pc's, take a look at restricted groups via GPO.
Open up a GPO, drill down to computer settings--windows settings---Security setting----restricted groups.
Add a group called administrators, then add the global group as...
I know its obvious but I presume you have also put http://servername for both entries under the "specify intranet microsoft update service location" ??
From memory, at the point where you add the logon scripts to the GPO there is an option for "show files"...I think it is, this is a folder within the GPO itself.
Cut/paste the logon scripts to this folder then add the scripts to the GPO from this location as opposed to the netlogon share...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.