| Windows 7: Limited account, restrict apps, but has install rights |
20 Aug 2011
|
#1 | | Windows 7 Professional x64 |
Limited account, restrict apps, but has install rights Dear Seven members,
I am running Windows 7 Prof x64 and I want to add a limited user account. I will be leaving home for about 6 months and a friend will be using my computer in the meantime. this means I won't be able to access the computer in that time.
I want to create an account for him, which allows him to install apps and do everything he wants, but I want to prevent him from using certain programs. Also I would like to block some folders that have private stuff.
Is it possible to do this using Group Policy in Windows?
Thanks in advance,
Nick | My System Specs |
| OS Windows 7 Professional x64 |
20 Aug 2011
|
#2 | | Windows 7 Ultimate x64 + x86 + Windows 8 x64 Newport, South Wales, UK |
You could protect the private data with some form of encryption, [Bitlocker, Truecrypt], but the program use may be more of an issue, As they will have permissions to install programs they can install anything you try to block.
Personally I would create a full image backup of the system, and a data backup, then remove the Current user info, programs and data completely.
When you return you can then reset the system to the way it is now and remove any changes | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Real World Computing (Me + a little help from Acer) OS Windows 7 Ultimate x64 + x86 + Windows 8 x64 CPU AMD Phenom II X6 1035T 2.6 GHz Motherboard Aspire M3400 Memory 4Gb PC10600 DDR3 1333 MHz Graphics Card NVIDIA GeForce 315 512MB Sound Card OnBoard - Realtek High Definition Audio Monitor(s) Displays Philips 32" HDTV, (HDMI) + 26" TV (VGA) Screen Resolution 1920 x 1080 @60Hz + 1360 x 768 @60Hz Keyboard Microsoft Wireless 800 or Stock Acer, (depends where I sit) Mouse Microsoft Wireless 800 or Stock Acer, (depends where I sit) PSU Stock (400W) Case Acer M3400 Cooling Stock Hard Drives 500 GB Seagate ST3500418AS SATA II
1 TB Hitachi HDS5C1010CLA382 SATAII
1 TB Samsung Spinpoint F1 HD103SI SATA II (external)
Plus various other (client ) HDDs as needed Internet Speed Temporaray 3G Dongle Antivirus Avast Browser Chrome Other Info USB Capture + Webcam(s) Bamboo Digitizer tablet
Also run Acer AspireOne 530h Netbook, Dual Core Atom + 1GB (Win7 Ult x86) Plus various test systems for new projects |
20 Aug 2011
|
#3 | | Windows 7 Professional x64 |
Hm hadn't thought of encryption software. Good point! Do you have any recommendations regarding them? I will need to encrypt some folders, but not complete hard drives or partitions.
The problem I have with a system back-up, is that it takes forever to do. When I do my weekly back-up it takes about 4 hours to completely back-up my system and my data.
Subsequently removing most applications is also not an option, because that also takes a long time. I have several large apps from my university. A 3D-CAD system, a finite-element analysis tool and a host of other programs. Removing them takes a long time.
If this could be done in advance, it's not a problem. However, I will be using the computer up to the moment I am leaving (save for a few hours or a day). I don't have time do all that the day before I leave.
So if you've got some other tips, I'd be very happy. Is it possible to restrict certain apps on an account with admin rights using group policy? I saw in the group policy editor, that you can restrict some apps, but I have no idea what it does or how it works. | My System Specs | | OS Windows 7 Professional x64 |
20 Aug 2011
|
#4 | | Windows 7 Professional x64 |
Oh btw, I don't need high-security encryption. A password will do. After all he is a friend not a cyber criminal. | My System Specs | | OS Windows 7 Professional x64 |
20 Aug 2011
|
#5 | | W7 X-64 RTM,SUSE 11.1, XP PRO SP3 as a VM, VMware ESXi Hafnarfjörður IS |
Hi there
the best 9and easiest) solution IMO is to do as a previous poster said
1) Image the system (i.e full backup)
2) Uninstall any app you don't want the user to access
3) delete ALL your private data (ensure its backed up first)
4) delete email account / email data and user data of your own account.
When you return just wipe the computer clean and re-install the image you made before you left. Use something like Acronis or Macrium as you can create a bootable restore -- you start the program via booting from a USB / DVD / external HDD. You don't have to worry about leaving an administrator account on the PC.
Much easier than mucking about with encryption / data access etc etc and the whole restore will only take around 20 mins anyway.
Cheers
jimbo | My System Specs | | System Manufacturer/Model Number Custom built OS W7 X-64 RTM,SUSE 11.1, XP PRO SP3 as a VM, VMware ESXi CPU Q9400 QUAD Motherboard P5QL-CM Memory 8GB Graphics Card On Motherborad Sound Card Realtek HD audio Monitor(s) Displays Apple Cinema display Mouse Toshiba wireless laser Hard Drives 4 X 1TB SATA Internet Speed > 20MB up |
20 Aug 2011
|
#6 | | Windows 7 Ultimate x64 + x86 + Windows 8 x64 Newport, South Wales, UK |
Have a look at Truecrypt, which is capable of encrypting entire operating systems.
It may be possible to create an encrypted partition and re-install your sensitive apps to this, (prior to leaving  ), and it is also useful for data protection of course. | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Real World Computing (Me + a little help from Acer) OS Windows 7 Ultimate x64 + x86 + Windows 8 x64 CPU AMD Phenom II X6 1035T 2.6 GHz Motherboard Aspire M3400 Memory 4Gb PC10600 DDR3 1333 MHz Graphics Card NVIDIA GeForce 315 512MB Sound Card OnBoard - Realtek High Definition Audio Monitor(s) Displays Philips 32" HDTV, (HDMI) + 26" TV (VGA) Screen Resolution 1920 x 1080 @60Hz + 1360 x 768 @60Hz Keyboard Microsoft Wireless 800 or Stock Acer, (depends where I sit) Mouse Microsoft Wireless 800 or Stock Acer, (depends where I sit) PSU Stock (400W) Case Acer M3400 Cooling Stock Hard Drives 500 GB Seagate ST3500418AS SATA II
1 TB Hitachi HDS5C1010CLA382 SATAII
1 TB Samsung Spinpoint F1 HD103SI SATA II (external)
Plus various other (client ) HDDs as needed Internet Speed Temporaray 3G Dongle Antivirus Avast Browser Chrome Other Info USB Capture + Webcam(s) Bamboo Digitizer tablet
Also run Acer AspireOne 530h Netbook, Dual Core Atom + 1GB (Win7 Ult x86) Plus various test systems for new projects |
21 Aug 2011
|
#8 | | Windows 7 Ultimate x64 + x86 + Windows 8 x64 Newport, South Wales, UK |

Quote: Originally Posted by szoltan What about blocking those programs with SRP (Software Restriction Policies)? ....pretty simple. For the folders problem: How To Lock And Password Protect Folder In Windows 7/Vista I would try to block the user with permissions (security tab of the folder) first. The user will have administrator access so any blocking needs to be done with a 3rd party solution, with password protection | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Real World Computing (Me + a little help from Acer) OS Windows 7 Ultimate x64 + x86 + Windows 8 x64 CPU AMD Phenom II X6 1035T 2.6 GHz Motherboard Aspire M3400 Memory 4Gb PC10600 DDR3 1333 MHz Graphics Card NVIDIA GeForce 315 512MB Sound Card OnBoard - Realtek High Definition Audio Monitor(s) Displays Philips 32" HDTV, (HDMI) + 26" TV (VGA) Screen Resolution 1920 x 1080 @60Hz + 1360 x 768 @60Hz Keyboard Microsoft Wireless 800 or Stock Acer, (depends where I sit) Mouse Microsoft Wireless 800 or Stock Acer, (depends where I sit) PSU Stock (400W) Case Acer M3400 Cooling Stock Hard Drives 500 GB Seagate ST3500418AS SATA II
1 TB Hitachi HDS5C1010CLA382 SATAII
1 TB Samsung Spinpoint F1 HD103SI SATA II (external)
Plus various other (client ) HDDs as needed Internet Speed Temporaray 3G Dongle Antivirus Avast Browser Chrome Other Info USB Capture + Webcam(s) Bamboo Digitizer tablet
Also run Acer AspireOne 530h Netbook, Dual Core Atom + 1GB (Win7 Ult x86) Plus various test systems for new projects |
21 Aug 2011
|
#9 | | Windows 7 Home 64, Vista Ultimate 64 Washington |
If a user is an admin he will have access to the whole system. The only way to protect the data is to encrypt it or remove it. I think your best bet is to back up your personal data (not a bad idea if you are going to be leaving your PC for 6 months), and then delete it.
As for disabling some applications - how about deleting key files from those apps? Probably simply deleting the main exe will do. Just make sure you back it up in a secure place. This will be much faster than uninstalling everything. | My System Specs | | System Manufacturer/Model Number Me :) I build all my PCs OS Windows 7 Home 64, Vista Ultimate 64 Limited account, restrict apps, but has install rights problems? All times are GMT -5. The time now is 04:52 AM. | |