Eklablog Tous les blogs
Editer l'article Suivre ce blog Administration + Créer mon blog
MENU

Publicité

Open Local Group Policy Editor Vista

Windows 7 using the Local Group Policy Editor. In Windows 7, you can perform some pretty amazing things by using a tool that's about as hidden as any Windows power tool can be: the Local Group Policy Editor.

If you would like to read the other parts in this article series please go to: Managing Windows Vista Group Policy (Part 2) Managing Windows Vista Group Policy (Part 3). This download package contains the Microsoft Lync 2010 administrative template file (Communicator.adm) and a spreadsheet that lists the Group Policy settings for the. Open the Group Policy Management Console from a Vista computer by. There are typically three different tasks that you need to perform to secure the Local Administrators group. Windows Server 2008 and Windows Vista SP1 (with the RSAT. In case of stand-alone computer, the USB-port usage restriction policy can be edited using a Local Group Policy Editor – gpedit.msc.

That Microsoft has buried this program in a mostly untraveled section of the Windows landscape isn't the least bit surprising, because in the wrong hands, the Local Group Policy Editor can wreak all kinds of havoc on a system. It's a kind of electronic Pandora's box that, if opened by careless or inexperienced hands, can loose all kinds of evil upon the Windows world. Of course, none of this doom- and- gloom applies to you, dear reader, because you're a cautious and prudent wielder of all the Windows power tools. This means that you'll use the Local Group Policy Editor in a safe, prudent manner, and that you'll create a system restore point if you plan to make any major changes.

Open Local Group Policy Editor Vista

I knew I could count on you. Put simply, group policies are settings that control how Windows works.

You can use them to customize the Windows 7 interface, restrict access to certain areas, specify security settings, and much more. You make changes to group policies using the Local Group Policy Editor, a Microsoft Management Console snap- in.

Open Local Group Policy Editor Vista

I'll show you how to perform the same tweak using the Registry if you're using those versions.) To start the Local Group Policy Editor, follow these steps: Click Start. Type gpedit. msc. Press Enter. Figure A shows the Local Group Policy Editor window that appears. You can also download the sample chapter . If this extra step bugs you, you can turn it off by right- clicking the desktop's Recycle Bin icon, clicking Properties, and then deactivating the Display Delete Confirmation Dialog check box.

Now let's consider this from the opposite point of view. The reason Windows displays the delete confirmation dialog box by default is to prevent you from accidentally deleting a file. You and I are savvy, knowledgeable users, so we know when we want to delete something, but not everyone falls into this boat.

If you have young kids or old parents who use Windows, you know that the delete confirmation dialog box is an excellent safeguard for these and other inexperienced users. In that case, you might be wondering if there's a way to ensure that a novice user can't turn off the delete confirmation dialog box. Yes, there is. In fact, are two ways to prevent a user from turning off delete confirmations: Disable the Display Delete Confirmation Dialog check box that appears in the Recycle Bin's property sheet.

Disable the Recycle Bin's Properties command so that the user can't display the Recycle Bin's property sheet. Follow these steps to implement one of these policies: In the Local Group Policy Editor, open the User Configuration branch. Open the Administrative Templates branch. Display the property sheet of the policy you want to use, as follows: If you want to disable the Display Delete Confirmation Dialog check box, open the Windows Components branch and then click Windows Explorer. Double- click the policy named Display Confirmation Dialog When Deleting Files.

Open Local Group Policy Editor VistaOpen Local Group Policy Editor Vista

How to use Group Policy to black/white list wireless networks in Vista & Windows 7 http://bit.ly/9hx05I.

Open Local Group Policy Editor Vista

If you don't have access to the Group Policy Editor, open the Registry Editor and create a DWORD setting named Confirm. File. Delete with the value 1 in the following key: HKCU\Software\Microsoft\Windows\Current. Version\Policies\Explorer If you want to disable the Recycle Bin's Properties command, click Desktop and then double- click the Remove Properties From The Recycle Bin Context Menu policy. If you don't have access to the Group Policy Editor, open the Registry Editor and create a DWORD setting named No. Properties. Recycle. Bin with the value 1 in the following key: HKCU\Software\Microsoft\Windows\Current.

Version\Policies\Explorer. Click the Enabled option. Click OK to put the policy into effect. Disabling the notification area. If you have zero use for the taskbar's notification area, you can disable it entirely by following these steps: In the Local Group Policy Editor, open the User Configuration branch. Open the Administrative Templates branch.

Click the Start Menu And Taskbar branch. Double- click the Hide The Notification Area policy, click Enabled, and then click OK.

Double- click the Remove Clock From The System Notification Area policy, click Enabled, and then click OK. Log off and then log back on to put the policy into effect.

If you prefer (or need) to implement this policy via the Registry, first open the Registry Editor (click Start, type regedit, press Enter, and enter your UAC credentials). Then, navigate to the following key: HKCU\Software\Microsoft\Windows\Current. Version\Policies\Explorer(If you don't see the Explorer key, click the Policies key, select Edit . Windows 7 puts the policy into effect. To perform the same tweak in the Registry, open the following key: HKCU\Software\Microsoft\Windows\Current.

Version\Policies\Explorer. Add a DWORD value named Disallow. Cpl and set it equal to 1. Also create a new key named Disallow. Cpl, and within that key create a new String value for each Control Panel icon you want to disable. Give the settings the names 1, 2, 3, and so on, and for each one set the value to the name of the Control Panel icon you want to disable. Showing only specified Control Panel icons.

Disabling a few Control Panel icons is useful because it reduces a bit of the clutter in the All Control Panel Items window. However, what if you want to set up a computer for a novice user and you'd like that person to have access to just a few relatively harmless icons, such as Personalization and Getting Started? In that case, it's way too much work to disable most of the icons one at a time. A much easier approach is to specify just those few Control Panel icons you want the user to see. Here's how: In the Local Group Policy Editor, select the User Configuration . Windows 7 puts the policy into effect.

To perform the same tweak in the Registry, open the following key: HKCU\Software\Microsoft\Windows\Current. Version\Policies\Explorer. Add a DWORD value named Restrict.

Cpl and set it equal to 1. Also create a new key named Restrict. Cpl, and within that key create a new String value for each Control Panel icon you want to show. Give the settings the names 1, 2, 3, and so on, and for each one set the value to the name of the Control Panel icon you want to show. Preventing other folks from messing with the Registry. Do you share your computer with other people?

In that case, there's a pretty good chance that you don't want them to have access to the Registry Editor. In Windows 7, User Account Control automatically blocks Standard users unless they know an administrator's password. For other administrators, you can prevent any user from using the Registry Editor by setting a group policy: In the Local Group Policy Editor, open the User Configuration ? However, you can overcome that by temporarily disabling the policy prior to running the Registry Editor. Yes, you could perform this tweak in Windows 7 Home and Home Premium using the Registry Editor, but then you wouldn't be able to reverse it because the Registry Editor would be disabled! In my book Windows 7 Unleashed, I provide a script that toggles the corresponding Registry setting on and off; see that book for more info.

Disabling Internet Explorer's Security and Privacy tabs. If you want to prevent a novice user from mucking around in Security and Privacy tabs in the Internet Options dialog box, you can hide them: In the Local Group Policy Editor, select the User Configuration . Of these five commands, all but Switch User are customizable using group policies.

So if you find that you never use one or more of those commands, or (more likely) if you want to prevent a user from accessing one or more of the commands, you can use group policies to remove them from the Windows Security window. Here are the steps to follow: In the Local Group Policy Editor, open the User Configuration . Remove Lock This Computer — You can use this policy to disable the Lock Computer button in the Windows Security window. Remove Task Manager — You can use this policy to disable the Start Task Manager button in the Windows Security window. Remove Logoff — You can use this policy to disable the Log Off button in the Windows Security window. In the policy dialog box that appears, click Enabled and then click OK. Repeat steps 2 and 3 to disable all the buttons you don't need.

Figure B shows the Windows Security window with only the Switch User button displayed. If you have two or more folders that you use regularly (for example, you might have several folders for various projects that you have on the go), switching between them can be a hassle. To make this chore easier, you can customize the Places bar to include icons for each of these folders. That way, no matter which location you have displayed in the Save As or Open dialog box, you can switch to one of these regular folders with a single click of the mouse.

The easiest way to do this is via the Local Group Policy Editor, as shown in the following steps: In the Local Group Policy Editor, open the following branch: User Configuration . Open the Registry Editor and navigate to the following key: HKCU\Software\Microsoft\Windows\Current. Version\Policies\Now follow these steps: Select Edit . That's usually a good thing, but you might want to keep track of why you shut down or restart Windows 7, or why the system itself initiates a shutdown or restart.

To do that, you can enable a feature called Shutdown Event Tracker. With this feature, you can document the shutdown event by specifying whether it is planned or unplanned, selecting a reason for the shutdown, and adding a comment that describes the shutdown. To use a group policy to enable the Shutdown Event Tracker feature, follow these steps: In the Local Group Policy Editor, navigate to the Computer Configuration . He is the author of more than 6.

How to use Group Policy to black/white list wireless networks in Vista & Windows 7. I have seen an number of posts form IT Administrators on the Microsoft Group Policy forums asking how prevent their users from connecting to a wireless network. Maybe it is because they have an open WIFI network on the floor above that users keep connecting to so they can by pass the proxy server URL restrictions or they don’t want their users from accessing the internet from well known WIFI hot spots. In the tutorial below I am going to show you how to block your laptops from connecting to specific wireless networks with the example SSID of “dlink”. This black list method is useful when you want to prevent users from connecting to networks such as “Free Public Wi. Fi” which is nothing more than a trap set by hacker to steal people’s passwords. Then I will go through the way will to block all wireless networks except for one called “private.

This is very useful if you only want your users to connect to wireless network you know are safe to use. Lastly I will then quickly show you how to totally disable your wireless adapter from being able to connect to any networks. The instructions below are specific to Vista and Windows 7 as there were a whole heap of new group policy settings that were introduced back when Vista was released. How to Black List/White List Wireless Networks using Group Policy. Note: Steps 1 to 5 are common for setting up both black and white lists. Then the process branches and describes how to setup a black list then white list in steps 6 & 7. Step 1. This is a computer based setting so edit a Group Policy Object (GPO) that is targeted to all the laptops in your network.

Step 2. Navigate to Computer Configuration > Policies > Windows Settings > Security Settings > Wireless Network (IEEE 8. Policies. Step 3.

Click on “Action” in the menu and then click on “Create A New Wireless Network Policy for Windows Vista and Later Releases”. Note: You can only create one Windows Vista and later and one Windows XP wireless setting within each GPO.

Step 4. Now give the give the setting a Policy Name and Description. Ensure that the “Use Windows WLAN Auto. COnfig service for clients” is ticked so that Windows does not allow third- party software to control the wireless network adapter (e. Intel Wireless LAN configuration Tool). Now click on the Network Permission Tab and click “Add.

Type in the name of the SSID you want to black list (e. Infrastructure) and select . Click “OK”Now the user views all the wireless network the will no longer be able to connect the network that has been configured as Deny. Type in the name of the SSID you want to white list (e. Infrastructure) and select . Tick “Prevent connections to ad- hoc networks” and tick “Prevent connections to infrastructure networks” then click “OK”Now you will ONLY be able to connect to the wireless network called “private. How to disable your wireless networks access via Group Policy.

Now if you want to totally deny you users from connecting to any network profile just skip step 6. You users will no longer be able to connect to any wireless networks and when they click on the network in they will receive the message “Your network administrator has blocked you from connecting to this network”. Note: Any network profile you have configured in the General tab will be automatically added as an allowed network having the two “Prevent connections” options tick will ensure that the user will not be able to connect to anything but your corporate wireless network.

Publicité
Retour à l'accueil
Partager cet article
Repost0
Pour être informé des derniers articles, inscrivez vous :
Commenter cet article