How to Lock down Windows 7 as much as possible?

soccastar001

New member
Local time
2:28 PM
Messages
11
Hello, I was wondering if anybody can tell if it is possible and if so to point me to resources that would tell me how to lock down Windows 7 as much as possible.

We have a need at work to lock down a system so a user cannot ping, use nslookup, network discovery, or even tell if someone else is out there. We would like to lock down access to the C drive and OS as much as possible while still allowing the user to use the system and access a single IIS web instance.

Is this level of exclusion possible, even if through many different processes? If so can someone get me started on how to do all this?
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
I'm sure specifically to your situation, but check your "local security policy" in the Administrative tools section. You can tweak all kinds of security in Windows there. I believe you can make custom policies too, but definitely do some homework as you can cause all kinds of problems with access if you input the wrong thing.
 

My Computer My Computer

At a glance

Windows 7 Pro 64bit build 7601 SP1Intel Core I5 3570K 3.4Ghz w/ Zalman CNPS9900...G.Skill F3-12800CL9D-8GbXL ; 4Gx2EVGA Geforce GTX 770 Superclocked
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Pro 64bit build 7601 SP1
CPU
Intel Core I5 3570K 3.4Ghz w/ Zalman CNPS9900NT RT
Motherboard
MSI Z77A-G45 Gaming
Memory
G.Skill F3-12800CL9D-8GbXL ; 4Gx2
Graphics Card(s)
EVGA Geforce GTX 770 Superclocked
Sound Card
Creative Sound Blaster Z
Monitor(s) Displays
Dual ViewSonic VX2770Smh-LED Black 27"IPS-Panel
Screen Resolution
1920x1080
Hard Drives
Kingston Hyper X 240GB SSD Win8 Pro 64bit 6GB/s Sata III
Intel 335 Series SSD 240GB Win8 Storage 6GB/s Sata III
Intel 320 Series SSD 600GB Storage 3GB/s Sata II
Western Digital Scorpio Black 1TB - Docked via Esata
PSU
Coolermaster GX 750W
Case
Corsair Vengence C70
Cooling
Coolermaster 120mm and Enermax 140mm
Keyboard
Corsair Vengence K70
Mouse
Logitech G500
Internet Speed
22mbps+
Browser
Firefox, Chrome, IE
Other Info
Swan M50W 2.1 speakers
APC UPS
Thermaltake BlacX HDD Dock
Samsung BD Optical Drive
Netgear WNDR4500
Use Group Policy to lock down your system. You need at least Windows 7 Professional in order to access these settings.

There are a whole bunch of policies you can edit, and this is what IT administrators use to lock down a system. I myself used this to lockdown a system in an office my uncle had. You can use it to restrict anything from chaning the wallpaper, to opening the run menu, to opening the task manager, to right clicking the desktop, to preventing any logging off or shut down.
 

My Computer My Computer

At a glance

Windows 2000 5.0 Build 2195Intel Core i7-2630QM@2GHz(2.9GHz Turbo Boost)...Kingston DDR3 1333 16GB (4GBx4)nVidia GTX 460m 1.5GB
Computer Manufacturer/Model Number
Asus G73SW-XN2
OS
Windows 2000 5.0 Build 2195
CPU
Intel Core i7-2630QM@2GHz(2.9GHz Turbo Boost) [Sandy Bridge]
Motherboard
Asus G73SW (Intel HM65 Chipset)
Memory
Kingston DDR3 1333 16GB (4GBx4)
Graphics Card(s)
nVidia GTX 460m 1.5GB
Sound Card
EAX Advanced HD 5.0, THX TruStudio
Monitor(s) Displays
17.3 in. primary & 23 in. secondary
Screen Resolution
1920x1080
Hard Drives
Seagate Momentus XT (SATA II) 500 GB @ 7200 RPM
Hitachi (SATA II) 500GB @ 7200 RPM

Non Raid because ASUS was crappy to choose an HM65 Chipset
Keyboard
Built-in 102-Key Backlit Keyboard
Other Info
It's a Laptop.
Parental controls is another option -- although somewhat limited.
 

My Computer My Computer

At a glance

Windows XP - Now Windows 7 Home Premium (64-b...
OS
Windows XP - Now Windows 7 Home Premium (64-bit).
Or if you have a bit of dosh, think its $40ish, Windows 7 Manager.

Download here

This is very easy to use and you can pretty much lock everything down with this program and all options are explianed when you hover over them
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64 RTM + SP1Intel Core i7 950 3.06GHZ (OC'd to 3.99Ghz)6GB OCZ Reaper HPC Edition PC3-16000 (set 160...EVGA Nvidia Geforce GTX 570
Computer Manufacturer/Model Number
The HAFmeister (Custom)
OS
Windows 7 Ultimate x64 RTM + SP1
CPU
Intel Core i7 950 3.06GHZ (OC'd to 3.99Ghz)
Motherboard
Asus Rampage III Extreme x58 SATA 6GB & USB 3.0
Memory
6GB OCZ Reaper HPC Edition PC3-16000 (set 1606Mhz 8-8-8-26)
Graphics Card(s)
EVGA Nvidia Geforce GTX 570
Sound Card
Creative SB X-Fi Titanium Fatal1ty Professional Series
Monitor(s) Displays
Samsung SM2433BW 24" Widescreen Monitor
Screen Resolution
1920x1200
Hard Drives
Western Digital Caviar Black 500GB 32Mb Buffer SATA II
Western Digital Caviar Black 750GB 32Mb Buffer SATA II
Western Digital Caviar Blue 500GB 16Mb Buffer SATA II
Western Digital My Book Essential Edition 750GB USB
Samsung Spinpoint 2TB SATA II
PSU
Thermaltake Toughpower 1200w (Modular)
Case
CoolerMaster HAF-932
Cooling
Zalman Reserator XT and ZM-WB5 Plus - GPU uses Stock coolers
Keyboard
Logitech G510
Mouse
Logitech G9 Gaming Mouse
Internet Speed
3MB Profile - 350-400kbs (Real-Speed)
Other Info
IcyBox Hot-Swap Bay,
Logitech G27 Steering Wheel,
Xbox 360 Wirless Elite Controller with Microsoft Reciever and
Play & Charge Kit,
Belkin USB Wireless Adaptor,
GAME Generic Controller (Playstation Looky-Likey),
Epson SX125 All-in-One.

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Get to know Group Policy Editor.
The only issue is there are so many settings for so many things if you "oops" one of them, you just gotta remember where/what you checked and/or enabled.

Network Administrators use Group Policy for domains to lock down computers...as said.
 

My Computer My Computer

At a glance

7 Pro 64 Bit8300 Quad 2.53Ghz4GB DDR CrucialIntel
Computer Manufacturer/Model Number
Sytemax
OS
7 Pro 64 Bit
CPU
8300 Quad 2.53Ghz
Motherboard
Asus
Memory
4GB DDR Crucial
Graphics Card(s)
Intel
Get to know Group Policy Editor.
The only issue is there are so many settings for so many things if you "oops" one of them, you just gotta remember where/what you checked and/or enabled.

Network Administrators use Group Policy for domains to lock down computers...as said.

Make a log of each change you make to Group Policy. That makes it easy to go back without guessing and without leaving something out.
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32 bitIntel(R) Pentium(R) 4 CPU 3.00GHz2.50 GB RAMNVIDIA GeForce 7600 GS
Computer Manufacturer/Model Number
Home built
OS
Windows 7 Ultimate 32 bit
CPU
Intel(R) Pentium(R) 4 CPU 3.00GHz
Motherboard
ASUS P4P800-VM Motherboard Chipset: Intel 865G + ICH5
Memory
2.50 GB RAM
Graphics Card(s)
NVIDIA GeForce 7600 GS
Sound Card
SoundMax Integrated Digital Audio (Chip)
Monitor(s) Displays
ViewSonic VX 1962 wm
Screen Resolution
1680 X 1050
Hard Drives
Seagate Barracuda 7200.10 80 GB
ST380215A ATA Device 18.6 GB
Western Digital "My Book" external hard drive 750 GB
Cooling
Fan based
Keyboard
Microsoft Comfort Curve Keyboard 2000 v10 USB
Mouse
Logitec optic USB
Internet Speed
3.01 Mb/s download 0.64 Mb/s upload
Make a log of each change you make to Group Policy. That makes it easy to go back without guessing and without leaving something out.

Great advice, as these can quickly get out of control and forgotten. What I like to do is before making a change, clone the policy you want to change, name it accordingly, apply it to a test PC/account. That way you can verify that your desired results are reached. For logging, you can run gpresult /v with an /x to tell it to write to file on the account/PC before and after. You can name the output files with the dates or changes. That way if you need to track down changes you can use a program to compare the files, like windiff.
 

My Computer My Computer

At a glance

Windows 7i5-7504GB DDR3 1600GT220
OS
Windows 7
CPU
i5-750
Motherboard
Asus
Memory
4GB DDR3 1600
Graphics Card(s)
GT220
We use Secure Lockdown which is a pretty inexpensive product ($20) from Inteset. It's for Windows 7.
 

My Computer My Computer

At a glance

Windows 7 64bit
OS
Windows 7 64bit
Get to know Group Policy Editor.
The only issue is there are so many settings for so many things if you "oops" one of them, you just gotta remember where/what you checked and/or enabled.

Network Administrators use Group Policy for domains to lock down computers...as said.

Make a log of each change you make to Group Policy. That makes it easy to go back without guessing and without leaving something out.
You can also use the filter toolbarbutton option of Group Policy which will show you only the changes you have made
 

My Computer My Computer

At a glance

Windows 7 Professional 32-bit (6.1, Build 7600)Intel(R) Pentium(R) 4 3.00 GHz HT2.0 GBATI Mobility Radeon 9600 64MB
Computer Manufacturer/Model Number
Averatec 6130HS-20
OS
Windows 7 Professional 32-bit (6.1, Build 7600)
CPU
Intel(R) Pentium(R) 4 3.00 GHz HT
Memory
2.0 GB
Graphics Card(s)
ATI Mobility Radeon 9600 64MB
Sound Card
Realtek AC'97 Audio
Screen Resolution
1280 x 800
Hard Drives
Seagate 96023A 60GB 7200RPM -
Seagate FreeAgentDesktop 250GB
Cooling
20 Inch Box Fan
Mouse
Targus PAWM10 Wireless Optical Laptop Mouse
Back
Top