Ik zoek een functie in Windows XP die ik wel eens gezien hem, alleen ik weet niet meer hoe die heet of hoe ik er moet komen. Het is net zoiets als gpedit.msc, maar net iets anders. Aan de linker kant heb je allerlei opties en instellingen die je kan wijzigen en aan de rechterkant kan je dan bepalen op wie die instellingen van toepassing zijn. (bv. --> Links staan dan: "Toestaan om datum/tijd te veranderen." En rechts kan je dan kiezen tussen: "Administrators, Hoofdgebruikers, Gebruikers, Iedereen, etc." of links staat: "Toestaan om de pc uit te schakelen" en rechts staat dan weer "Administrator, Hoofdgebruiker, etc.") De indeling is globaal hetzelfde als die van de group policy editor. Wie weet over welke functie ik het heb??
Staat in Group Policy Editor hoor, gpedit.msc dus.
Computer policy, Windows Settings, Security Settings, Local Security Policy
Computer policy, Windows Settings, Security Settings, Local Security Policy
9000Wp o/w SolarEdge SE6K - Panasonic 5kW bi-bloc - gasloos sinds 17-7-2023
Verwijderd
Even hierover - als ik dan bij de volgende map kijk:maspro schreef op 27 september 2002 @ 16:26:
Thx very much.
Nu weet ik het weer, eigenlijks best wel suf dat ik het daar zelf niet gevonden heb.
- Computerconfiguratie
-- Beheersjablonen
--- Windows-onderdelen
---- Windows Installer,
en dan bij de volgende instelling: Installaties door gebruiker verbieden,
wat moet ik me hier dan bij voorstellen? Kan dan alleen de administrator nog software installeren en dat alle andere (hoofd)gebruikers dan een melding krijgen in de trend van: error - geen toegang of zoiets? En geldt dit voor alle software?
Verwijderd
Niet voor niets is er de mogelijkheid om op die sleutel te dubbelklikken > Uitleg. Hierin staat precies uitgelegd wat de gevolgen zijn.
Verwijderd
Ja , maar daar staat niet bij of dat voor admins ook geldt of voor de (hoofd)gebruikers. En het is ook maar een vraag. Als je het weet kun je die toch ook gewoon beantwoorden? Ik heb er toch niet speciaal een topic voor geopend ofzo?
En dan wil ik nog steeds graag weten of dit alleen voor msi bestanden geldt of voor alle .exe(/.bat/.com?) setup bestanden.
En dan wil ik nog steeds graag weten of dit alleen voor msi bestanden geldt of voor alle .exe(/.bat/.com?) setup bestanden.
Verwijderd
WinXP kent (default) alleen local policies, dus het geldt ook voor Administrators. Daar is wel een mouw aan te passen door voor de Administrator de Read rechten voor de System32/GroupPolicy map op Deny te zetten. Voor hun worden dan geen policies uitgevoerd. Dit geldt voor alle programma's die geïnstalleerd moeten worden om te functioneren. Een exe die niet gebruikt maakt van de installer kun je gewoon uitvoeren.
Verwijderd
Oke, het gaat mij er ook om dat ik als admin spellen etc kan installeren en dat gebruikers die alleen kunnen starten. Bedankt voor je reactieVerwijderd schreef op 28 september 2002 @ 16:45:
WinXP kent (default) alleen local policies, dus het geldt ook voor Administrators. Daar is wel een mouw aan te passen door voor de Administrator de Read rechten voor de System32/GroupPolicy map op Deny te zetten. Voor hun worden dan geen policies uitgevoerd. Dit geldt voor alle programma's die geïnstalleerd moeten worden om te functioneren. Een exe die niet gebruikt maakt van de installer kun je gewoon uitvoeren.
Weet je misschien ook, waar ik kan aan/uit vinken dat een gebruiker Uberhaupt iets kan installeren - ook al is het een .exe bestandje?
Verwijderd
Het probleem is natuurlijk dat een exe niet beslist hoeft te worden geïnstalleerd. Je kun wel in de Gebruikersconfiguratie > Beheersjablonen > Menu Start & Taakbalk een hele reeks opties uitschakelen, waardoor bv hetRun commando niet meer kan worden gebruikt. Maar het juist configureren van Policies is behoorlijk ingewikkeld, dus dat is niet zomaar even uit te leggen. Start anders ook even secpol.msc en kijk wat je daarmee kunt. Via Actie > Beleid importeren zou je ook standaard sjablonen kunnen gebruiken.
Verwijderd
Ja , daar heb ik al naar zitten kijken - zal er eens een beetje mee stoeien. Maar over dat GroupPolicy op Read zetten? Ik heb de NL-versie en ik zou zo snel niet weten waar en hoe ik dat kan doen. Heb je misschien een simpele oplossing?Verwijderd schreef op 28 september 2002 @ 17:02:
Het probleem is natuurlijk dat een exe niet beslist hoeft te worden geïnstalleerd. Je kun wel in de Gebruikersconfiguratie > Beheersjablonen > Menu Start & Taakbalk een hele reeks opties uitschakelen, waardoor bv hetRun commando niet meer kan worden gebruikt. Maar het juist configureren van Policies is behoorlijk ingewikkeld, dus dat is niet zomaar even uit te leggen. Start anders ook even secpol.msc en kijk wat je daarmee kunt. Via Actie > Beleid importeren zou je ook standaard sjablonen kunnen gebruiken.
Zoals hij al zei:
c:\windows\System32\GroupPolicy
op deze map de admin geen lees rechten geven.
(Kan alleen als je NTFS filesystem draaid)
c:\windows\System32\GroupPolicy
op deze map de admin geen lees rechten geven.
(Kan alleen als je NTFS filesystem draaid)
Verwijderd
In Mapopties eerst "eenvoudige bestandsdeling" uitvinken. En "Verborgen bestanden en mappen weergeven" aanzetten. Rechtsklik dan op een map > Eigenschappen > Beveiliging. [EDIT: inderdaad alleen met NTFS[/EDIT]. Voor rest dit lezen:
Making Different Settings for Different Users
Centrally managed Group Policy settings—that is, those that are stored in Active Directory in Windows .NET Server or Windows 2000 Server—can be applied to individual users, computers, or groups of either. You can have multiple sets of Active Directory–based Group Policy objects, allowing you to create an entirely different collection of settings for different users or computers.
Such is not the case with local Group Policy. Local Group Policy settings apply to all users who log on to the computer. (If the computer is joined to a domain, however, the local settings might be overridden by Active Directory–based settings. For details, see "How Local Group Policy Settings Interact with Active Directory–Based Group Policy Settings.") You can’t have multiple sets of local Group Policy objects.
Although you can’t have customized settings for each of several different groups, you can effectively have two groups of users: those who are affected by local Group Policy settings and those who are not. This duality affects only the User Configuration settings; Computer Configuration settings are applied before anyone logs on.
You can do this because local Group Policy depends on users having Read access to the local Group Policy object, which is stored in the %SystemRoot%\System32\ GroupPolicy folder. Policies are not applied to users who do not have Read access; therefore, by denying Read access to administrators or others whom you don’t want to restrict, you free those users from control by group policies. To use this method, follow these steps:
Make the Group Policy setting changes that you want.
In Windows Explorer, right-click the %SystemRoot%\System32\GroupPolicy folder and choose Properties. (GroupPolicy is a hidden folder; if you can’t find it in System32, choose Tools, Folder Options, View, Show Hidden Files And Folders.)
On the Security tab of the GroupPolicy Properties dialog box, select the Administrators group and select the Deny check box for the Read permission. (If you want to exclude any other users or groups from Group Policy control, add them to the Group Or User Names list and then deny their Read permission.)
note
--------------------------------------------------------------------------------
You must deny the Read permission rather than simply clear the Allow check box. Otherwise, all users would continue to inherit Read permission because of their automatic membership in the Authenticated Users group.
At your next logon using one of the Read-disabled user accounts, you’ll find that you’re no longer encumbered by Group Policy settings. Without Read permission, however, you’ll find that you’re also unable to run Group Policy—so you can’t view or modify Group Policy settings. To regain that power, you need to revisit the Group Policy Properties dialog box and grant yourself Full Control permission.
Keep in mind that, even without the aforementioned security shenanigans, the default security settings effectively produce two groups of users. Although the local Group Policy settings apply to all users (clarification: all users who have Read access to the local Group Policy object), only members of the local Administrators group can view or change these settings.
If customizing the effects of Group Policy settings based on group membership is important to you, you should install Windows .NET Server or Windows 2000 Server and set up Active Directory. But the methods described in this section can provide an easy compromise solution.
-
Ik ga nu weekend vieren
Making Different Settings for Different Users
Centrally managed Group Policy settings—that is, those that are stored in Active Directory in Windows .NET Server or Windows 2000 Server—can be applied to individual users, computers, or groups of either. You can have multiple sets of Active Directory–based Group Policy objects, allowing you to create an entirely different collection of settings for different users or computers.
Such is not the case with local Group Policy. Local Group Policy settings apply to all users who log on to the computer. (If the computer is joined to a domain, however, the local settings might be overridden by Active Directory–based settings. For details, see "How Local Group Policy Settings Interact with Active Directory–Based Group Policy Settings.") You can’t have multiple sets of local Group Policy objects.
Although you can’t have customized settings for each of several different groups, you can effectively have two groups of users: those who are affected by local Group Policy settings and those who are not. This duality affects only the User Configuration settings; Computer Configuration settings are applied before anyone logs on.
You can do this because local Group Policy depends on users having Read access to the local Group Policy object, which is stored in the %SystemRoot%\System32\ GroupPolicy folder. Policies are not applied to users who do not have Read access; therefore, by denying Read access to administrators or others whom you don’t want to restrict, you free those users from control by group policies. To use this method, follow these steps:
Make the Group Policy setting changes that you want.
In Windows Explorer, right-click the %SystemRoot%\System32\GroupPolicy folder and choose Properties. (GroupPolicy is a hidden folder; if you can’t find it in System32, choose Tools, Folder Options, View, Show Hidden Files And Folders.)
On the Security tab of the GroupPolicy Properties dialog box, select the Administrators group and select the Deny check box for the Read permission. (If you want to exclude any other users or groups from Group Policy control, add them to the Group Or User Names list and then deny their Read permission.)
note
--------------------------------------------------------------------------------
You must deny the Read permission rather than simply clear the Allow check box. Otherwise, all users would continue to inherit Read permission because of their automatic membership in the Authenticated Users group.
At your next logon using one of the Read-disabled user accounts, you’ll find that you’re no longer encumbered by Group Policy settings. Without Read permission, however, you’ll find that you’re also unable to run Group Policy—so you can’t view or modify Group Policy settings. To regain that power, you need to revisit the Group Policy Properties dialog box and grant yourself Full Control permission.
Keep in mind that, even without the aforementioned security shenanigans, the default security settings effectively produce two groups of users. Although the local Group Policy settings apply to all users (clarification: all users who have Read access to the local Group Policy object), only members of the local Administrators group can view or change these settings.
If customizing the effects of Group Policy settings based on group membership is important to you, you should install Windows .NET Server or Windows 2000 Server and set up Active Directory. But the methods described in this section can provide an easy compromise solution.
-
Ik ga nu weekend vieren
Dit zijn allemaal wel zeer nuttig reacties, zo leert men nog eens wat.
Ik ga hier wel ff uitgebreid mee stoeien.
Ik ga hier wel ff uitgebreid mee stoeien.
Verwijderd
Zeker wel - ik wilde ook dat xp wel eens uitgebreid teste - en dit was dus een aangewezen mogelijk heidmaspro schreef op 28 september 2002 @ 17:26:
Dit zijn allemaal wel zeer nuttig reacties, zo leert men nog eens wat.
Ik ga hier wel ff uitgebreid mee stoeien.
[editmode]
En binary10 nog bedankt voor zijn uitgebreid antwoord
[/editmode]
Pagina: 1