Keeping Users In Check

xyber

New member
Local time
7:20 PM
Messages
1
Hi All,

I'm trying to find out if there is a way we can prevent users from creating/storing/copying/pasting files onto the root directory. This is because i want to prevent anything from writing itself there other than the system itself. Because most of the autorun viruses etc copies itself there. There are numerous viruses out there which does this. And at this present time, although majority of the anti-viruses can track them, we might never know if another way to circumvent anti-viruses watch and defenses can be formulated. This is the basis i'm looking for this specific way to block users from storing files on root drives. And yes i am aware that natively UAC does watch over these places which means without elevated privs, nothing can be stored there. But what good is security if the home owners welcome thieves in disguises?

Thank you for all inputs on this.

-Xyber.
 

My Computer

OS
Windows 7 Home Premium 32bit.
Hi xyber, and welcome. :geek:

You control user activity via limiting user accounts and permissions. Here are some links that should help you get started. Lots of reading:

Good link:

http://technet.microsoft.com/en-us/library/dd835546(WS.10).aspx

Good also:

Configuring Windows 7 for a Limited User Account

And a good, basic well written tutorial:

http://www.sevenforums.com/tutorials/122666-permissions-allow-deny-users-groups.html

Some links specific to requirements you may have:

group policy - How can I prevent users from installing software? - Server Fault

Prevent users moving folders

And finally, some searches:

windows 7 prevent users from creating/storing/copying/pasting files onto the root directory - Google Search

windows 7 limiting user accounts - Google Search

http://www.google.com/search?q=wind...-us&ie=UTF-8&oe=UTF-8&startIndex=&startPage=1

And a final link, which is only applicable to The Professional and above versions of windows, but an excellent read about the use of GPedit:

http://www.thewindowsclub.com/tag/group-policy

James
 

My Computer

OS
Win7U 64 RTM
CPU
Q9550
Motherboard
GA-EP45-UD3R
Memory
8GB Gskill
Graphics Card(s)
ASUS|EAH4850/HTDI/1GD3/A
Sound Card
xfi Plat
Monitor(s) Displays
Dell 2405fpw
Screen Resolution
1920x1200
Hard Drives
Seagate & WD sata Drives
PSU
Antec
Case
Antec
Keyboard
MS Natural Ergonomic 4000
Mouse
Logitech MX610 USB Cordless
The root drive is basically the PC, itself. Denying a user account the ability to create/store/copy/paste files would literally render the account useless. UAC is already set up to protect the computer and works great if set up properly. In other words, if the Administrator account is password protected and logged off, and a standard user account is being used by someone other than you, they would still need your password to run anything malicious, even non-threatening invitations.
 

My Computer

Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Pro/32 Academic. Build 7600
CPU
Intel 2.3 Duo core
Motherboard
EliteGroup G31T-M
Memory
4 GB DDR
Graphics Card(s)
Nvidia GeForce 9500 GT
Sound Card
Built in
Monitor(s) Displays
Viewsonic 15" 4:3
Screen Resolution
1280 x 1024
Hard Drives
WD Caviar Black 750 GB
WD 250 GB External
PSU
Antec 450w
Keyboard
Standard windows
Mouse
Logitech USB
Internet Speed
Bellsouth DSL 6.0
Back
Top