Questions

Stop window explorer's access to the internet

+
0 Votes
Locked

Stop window explorer's access to the internet

l.ossorio
I have a Windows XP Pro sp2 computer with 3 users. 2users are administrators and 1 user is a limited user. I have setup a security profile for the limited user but I have not been able to stop the user when he is in Windows Explorer from accessing the Internet. I have stopped the user?s ability to use Internet Explorer. I want them to be able to use Windows Explorer but not have access to the Internet by typing an internet address.

The 2 administrator users I want to have access to the internet so I do not want to block the IP address of the computer.
  • +
    0 Votes
    dpotter555

    One way to stop internet activity for a user would be to configure the firewall to deny access to tcp port 80 for the specific user's ip address.

    +
    0 Votes
    l.ossorio

    Thanks
    But I want other users on this machine to access the internet so I can not block the ip.

    +
    0 Votes
    bkinsey

    Setting a non-existent proxy address is the best way to do what you want, and you can do that with Group Policy (or with Local Policy if you're not in an AD domain).

    User Configuration->Windows Settings->Internet Explorer Maintenance->Connection/Proxy Settings and setting 0.0.0.0 for a server will do it. You can exempt local addresses, too, to allow intranet access.

    If you have domain-wide group policies with AD, add that setting to a policy which you link to the AD container housing the user account(s) you want this to effect. If you don't do AD, you can use gpedit.msc locally, as long as the user's not a local admin and thus able to change it back. . .

  • +
    0 Votes
    dpotter555

    One way to stop internet activity for a user would be to configure the firewall to deny access to tcp port 80 for the specific user's ip address.

    +
    0 Votes
    l.ossorio

    Thanks
    But I want other users on this machine to access the internet so I can not block the ip.

    +
    0 Votes
    bkinsey

    Setting a non-existent proxy address is the best way to do what you want, and you can do that with Group Policy (or with Local Policy if you're not in an AD domain).

    User Configuration->Windows Settings->Internet Explorer Maintenance->Connection/Proxy Settings and setting 0.0.0.0 for a server will do it. You can exempt local addresses, too, to allow intranet access.

    If you have domain-wide group policies with AD, add that setting to a policy which you link to the AD container housing the user account(s) you want this to effect. If you don't do AD, you can use gpedit.msc locally, as long as the user's not a local admin and thus able to change it back. . .