How to place restrictions on standard user accounts beyond parentals

Page 1 of 2 12 LastLast

  1. Posts : 2
    Windows 7 64 bit
       #1

    How to place restrictions on standard user accounts beyond parentals


    I am trying to deny permission on standard user accounts to download files from email and such, as well ensure they cannot execute files. I cannot find this option available under parental controls, or even in additional parental controls software. Could someone please advise me how to gain greater control over standard user permissions?

    Thank you,
    Nick
      My Computer

  2.    #2

    You want to operate as passworded Administrator, then create standard User account for others to use.

    Test this standard account on the operations you want to restrict first and make a list of the ones which aren't restrictive enough, then post back or Google how to restrict each.

    Title your post the exact function you want to restrict to get catch the attention of someone who knows the specific answer. Google probably already knows if you ask succinctly enough.

    I believe this still applies with WIn7 to restrict file access: How to Deny Access to Files or Folders in Windows Vista - How-To Geek
    Last edited by gregrocker; 05 Jul 2010 at 18:35.
      My Computer


  3. Posts : 2
    Windows 7 64 bit
    Thread Starter
       #3

    I think i understand that process, however I am unable to set myself as owner privileged. I am signed in on admin account, but it will not allow me to take ownership over the local disk, even though there is no account set as the owner.
      My Computer


  4. Posts : 565
    Windows 7 Home Premium x64
       #4

    gregrocker said:
    You want to operate as passworded Administrator, then create standard User account for others to use.

    Test this standard account on the operations/files you want to restrict first and make a list of the ones which aren't restrictive enough, then post back or Google how to restrict each.

    Title your post the exact function you want to restrict to get catch the attention of someone who knows the specific answer. Google probably already knows if you ask succinctly enough.

    I believe this still applies with WIn7 to restrict file access: How to Deny Access to Files or Folders in Windows Vista - How-To Geek
    That is actually VERY bad advice, even for HTG (which I am a member of). Never use the "Deny" setting on NTFS permissions. It is the worst practice you can ever make.

    You can actually use Group Policy, which is MUCH safer. Given, you will need at least Windows 7 Pro or better as Group Policy is not available on any Home edition.

    With the Parental Controls you can restrict that they can only execute certain applications. They will be prevented from executing anything else.
      My Computer

  5.    #5

    Please explain how restricting file access using the OS's own permissions utility is a "worst practice."

    Was all of my post "VERY bad advice" or just using the permissions which are placed on each folder and file for the specific purpose of being able to restrict their access?

    Since Group policy is not available on lesser versions than Pro and there is about an 80% chance they have Home Premium, how would you have OP restrict access to folders they don't want shared?
      My Computer


  6. Posts : 565
    Windows 7 Home Premium x64
       #6

    gregrocker said:
    Please explain how restricting file access using the OS's own permissions utility is a "worst practice."

    Was all of my post "VERY bad advice" or just using the permissions which are placed on each folder and file for the specific purpose of being able to restrict their access?

    Since Group policy is not available on lesser versions than Pro and there is an 80% chance they have Home Premium, how would you have OP restrict access to folders they don't want shared?
    There are good practices and bad ones with setting NTFS permissions. It is better to remove a group and restrict a folder to a user than to ever use "Deny". If you make that user with "Deny" NTFS permission on their own user folder they will not be able to log in.

    Besides, the OP merely wants to prevent someone from downloading a file and executing it. As far as executing the file, you can do that by making that person a separate account and making it a Standard user. They won't be able to install anything at that point. You can then use Parental Controls to restrict them to only execute certain applications.

    Regarding downloading files, that can only be done through Group Policy or the registry.
      My Computer

  7.    #7

    JonM33 said:
    Besides, the OP merely wants to prevent someone from downloading a file and executing it. As far as executing the file, you can do that by making that person a separate account and making it a Standard user. They won't be able to install anything at that point. .
    From my original post:

    gregrocker said:
    You want to operate as passworded Administrator, then create standard User account for others to use.

    Test this standard account on the operations you want to restrict first and make a list of the ones which aren't restrictive enough, then post back or Google how to restrict each.

    Title your post the exact function you want to restrict to get catch the attention of someone who knows the specific answer. Google probably already knows if you ask succinctly enough.
    So I guess my entire post wasn't "VERY bad advice"?

    nicholas8814 said:
    I think i understand that process, however I am unable to set myself as owner privileged. I am signed in on admin account, but it will not allow me to take ownership over the local disk, even though there is no account set as the owner.
    Try this:
    Take Ownership Shortcut
      My Computer


  8. Posts : 8,870
    Windows 7 Ult, Windows 8.1 Pro,
       #8

    I'm still wondering what the OP meant about "standard" User accounts. Are these Users on different machines? Or are these User accounts on the same machine?

    If the User accounts are on seperate machines then using the Group Policy Editor is the way to go for this assuming that the Op has Windows 7 pro or above.
    http://blogs.techrepublic.com.com/10things/?p=1014

    If the User account is on the same machine then there are more options for restricting access. Big difference between the two as far as restricting things go.

    The OP needs to be more precise when asking these sorts of questions or it can get very confusing for everyone.

    And no Greg, I don't think your answer was very bad advice at all, considering that you linked to a post from the "How to Guy" that pretty much said that same thing. I believe that Jon could have easily reworded his advice to be more polite. But lets not waste more time arguing this point...

    If they are on the same machine then using the Guest mode will put the account back to square one everytime they sign out. You can read about using Guest mode in the link below. It seems to be what the Op was asking about.
    http://www.winsupersite.com/win7/ff_pcsafeguard.asp
      My Computer


  9. Posts : 2,072
    Windows 7 x64 Professional SP1
       #9

    @chev65 It seems like Guest Mode has been removed from Windows 7 RTM 7600 after MS deemed it caused many bugs in its implementation.. The option does not appear in the Manage another account box... Here's to hoping it comes back in a Service Pack.
      My Computer


  10. Posts : 565
    Windows 7 Home Premium x64
       #10

    gregrocker said:
    So I guess my entire post wasn't "VERY bad advice"?
    Well, I said it was very bad advice even for HTG. That was indicative of the link regarding using "Deny" NTFS permissions.

    I apologize if you felt it was referencing your entire post.

    Bottom line with NTFS, never use "Deny". Best practice is to create a local security group, add whatever users to that group that you want to have access, add that group to the folder's NTFS permissions with read only or write permission and then remove the remaining groups (such as Everyone) from that folder. Administrators will have "Full Control" by default.
      My Computer


 
Page 1 of 2 12 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 07:16.
Find Us