Locking Down a Windows 7 Computer

Phatty

New member
Local time
3:01 PM
Messages
3
First off, forgive me. I've done some digging, but I'm a Windows 7 newb and I have a lot to learn. I have a production computer meant for factory users to use and I want to have it locked down. I've been using Windows XP and the "Policy Editor" (poledit.exe) to remove access to the control panel, remove lock workstation, block the task manager, and all kinds of stuff like that.

Now, our company is rolling out Windows 7 computers and Poledit doesn't seem to work with that. I keep getting an error "Cannot connect to Registry" when I click on the user to use it.

What is the best way I can lock down ONE user on a Windows 7 stand-alone machine? I don't want to restrict EVERY user on the machine like when I log in as "administrator". I tried the "Group Policy" editor that comes with it, but it wants to change every user. Is there something else I can use? Is there a way to get Poledit to work?

Also, another problem I'm having is getting auto-logon to work. The check box to require the user to logon is unchecked but I can't check it or uncheck it and I have administrative privileges, so I don't know why I can't click there and autologon isn't working.

Any help would be appreciated.
 

My Computer

OS
Windows 7 64 bit
I did some more digging and am inching my way forward. To start, poledit will work if I'm logged on as administrator. Group Policy will work for just one user if you run the User settings while logged in as that user.

I'm still working on a few more problems, though. I've disabled just about everthing I can think of and find, BUT when you click on the Start menu, it still shows programs they can select. I don't want ANYTHING to be visible there when they press the start menu. Any ideas for that?

Also, I'm trying to put start-up items in my locked down user when I'm logged in as Administrator and I keep getting "Access Denied" errors when I try to navigate to some folders. If I'm administrator, why would there be any "Access Denied" errors? What's up with that? :)
 

My Computer

OS
Windows 7 64 bit
Also, I'm trying to put start-up items in my locked down user when I'm logged in as Administrator and I keep getting "Access Denied" errors when I try to navigate to some folders. If I'm administrator, why would there be any "Access Denied" errors? What's up with that? :)

Those folders that deny access are junction points. You need the leave them alone. See the links in my signature.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware Aurora ALX R4
OS
Windows 10 Pro (x64)
CPU
Intel Core i7-3930K (3.2GHz - 4.5GHz)
Motherboard
Alienware Aurora-R4 x79
Memory
4x Samsung 4GB PC3-12800 DDR3 (16GB 1600MHz)
Graphics Card(s)
Nvidia Geforce GTX 690
Sound Card
SteelSeries Siberia Elite
Monitor(s) Displays
Dell UltraSharp U3011
Screen Resolution
2560x1600
Hard Drives
Samsung 850 Pro 256 GB, Seagate 1TB Desktop Hybrid HDD, 2x Western Digital 4TB Green HDD
PSU
875W Some Dell PSU <.<
Case
Alienware Aurora ALX
Cooling
Custom Liquid Cooling (EK CPU & GPU blocks) dual EK 480RAD
Keyboard
Logitech G710+ Mechanical
Mouse
Logitech G700s
Internet Speed
Verizon Fios (50 mbps average)
Other Info
Server: Intel NUC D54250WYK: i5-4250U, 16GB, 256 GB mSATA, Windows Server 2012 R2
So, no one has any ideas on how to lock down the Start menu so it's either not accessible or bare when the user clicks on it? I'm pretty close to getting this finished, but that's a big one for me.
 

My Computer

OS
Windows 7 64 bit
Wonder if i should let the cat out of the bag? ...... You can lock down a single user with Group Policy..... From what I have found out it is only a new feature in Windows 7.
Here's the instructions to apply Group Policies to a single user.

http://www.sevenforums.com/tutorials/151415-group-policy-apply-specific-user-group.html

Open mmc.exe -> File -> Add/Remove Snap-in
Select Group Policy Object Editor -> Click Add..... Now here comes the kicker
A new window appears -> Select Browse -> Now Select the User Tab -> Select the user you wish to apply local Group Policies too -> Ok -> Finish -> Ok
Now underneath Console Root you should have

Console Root
L Local Computer\*Useraccount* Policy

Expand this and you can now edit this Users policy.... This only affects That user!

There you have it. I have not been able to find these instructions anywhere on the web.... you have seen it here FIRST!
 
Last edited by a moderator:

My Computer

OS
Windows 7 Ultimate x64
Excellent. Should prove useful to those who have multiple user accounts, and want to apply different policies depending on the user.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dwarf Dwf/11/2012 r09/2013
OS
Windows 8.1 Pro RTM x64
CPU
Intel Core-i5-3570K 4-core @ 3.4GHz (Ivy Bridge) (OC 4.4GHz)
Motherboard
ASRock Z77 Extreme4-M
Memory
4 x 4GB DDR3-1600 Corsair Vengeance CMZ8GX3M2A1600C9B (16GB)
Graphics Card(s)
MSI GeForce GTX770 Gaming OC 2GB
Sound Card
Realtek High Definition on board solution (ALC 898)
Monitor(s) Displays
ViewSonic VA1912w Widescreen (VGA)
Screen Resolution
1440x900
Hard Drives
OCZ Agility 3 SSD 120GB SATA III x2 (RAID 0)
Samsung HD501LJ 500GB SATA II x2
Hitachi HDS721010CLA332 1TB SATA II
Iomega 1.5TB Ext USB 2.0
WD 2.0TB Ext USB 3.0
PSU
XFX Pro Series 850W Semi-Modular
Case
Gigabyte IF233
Cooling
1 x 120mm Front Inlet 1 x 120mm Rear Exhaust
Keyboard
Microsoft Comfort Curve Keyboard 3000 (USB)
Mouse
Microsoft Comfort Mouse 3000 for Business (USB)
Internet Speed
NetGear DG834Gv3 ADSL Modem/Router (Ethernet) ~4.0 Mb/s (O2)
Antivirus
Avast! 8.0.1497
Browser
IE 11
Other Info
Optical Drive: HL-DT-ST BD-RE BH10LS30 SATA Bluray
Lexmark S305 Printer/Scanner/Copier (USB)
WEI Score: 8.1/8.1/8.5/8.5/8.25
Asus Eee PC 1011PX Netbook (Windows 7 x86 Starter)
Hey Dwarf; let us know if TrigZ post works.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
A simpler method that may not be restrictive enough is to password your Admin-level account, then enable the Guest account or a Standard User account which will restrict most changes to the OS.

This is what I do when I have guests or let someone use my computer, and I've never had anything added I didn't want.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dwarf Dwf/11/2012 r09/2013
OS
Windows 8.1 Pro RTM x64
CPU
Intel Core-i5-3570K 4-core @ 3.4GHz (Ivy Bridge) (OC 4.4GHz)
Motherboard
ASRock Z77 Extreme4-M
Memory
4 x 4GB DDR3-1600 Corsair Vengeance CMZ8GX3M2A1600C9B (16GB)
Graphics Card(s)
MSI GeForce GTX770 Gaming OC 2GB
Sound Card
Realtek High Definition on board solution (ALC 898)
Monitor(s) Displays
ViewSonic VA1912w Widescreen (VGA)
Screen Resolution
1440x900
Hard Drives
OCZ Agility 3 SSD 120GB SATA III x2 (RAID 0)
Samsung HD501LJ 500GB SATA II x2
Hitachi HDS721010CLA332 1TB SATA II
Iomega 1.5TB Ext USB 2.0
WD 2.0TB Ext USB 3.0
PSU
XFX Pro Series 850W Semi-Modular
Case
Gigabyte IF233
Cooling
1 x 120mm Front Inlet 1 x 120mm Rear Exhaust
Keyboard
Microsoft Comfort Curve Keyboard 3000 (USB)
Mouse
Microsoft Comfort Mouse 3000 for Business (USB)
Internet Speed
NetGear DG834Gv3 ADSL Modem/Router (Ethernet) ~4.0 Mb/s (O2)
Antivirus
Avast! 8.0.1497
Browser
IE 11
Other Info
Optical Drive: HL-DT-ST BD-RE BH10LS30 SATA Bluray
Lexmark S305 Printer/Scanner/Copier (USB)
WEI Score: 8.1/8.1/8.5/8.5/8.25
Asus Eee PC 1011PX Netbook (Windows 7 x86 Starter)
We are using Inteset Secure Lockdown software. It's the simplest way we've found to lock down Windows and allows us to have different configurations per user.
 

My Computer

OS
Windows 7 Home Premium 64bit

My Computer

Computer type
PC/Desktop
OS
Windows 10 x64
CPU
Intel i5-3570K
Motherboard
Asus Maximus V Gene
Memory
Crucial 16GB
Graphics Card(s)
nVidia Geforce 660 GTX
Sound Card
onboard
Monitor(s) Displays
NEC 2490WUXi2
Screen Resolution
1920x1200
Hard Drives
Crucial M4 256GB
PSU
Corsair 650TX
Case
Fractal Design - Define Mini
Keyboard
Filco Majestouch Tenkeyless Black MX
Mouse
Logitech MBJ58
Back
Top