General discussion

Locked

Prevent Software Installation

By rspencer@kingfishermarine ·
I am running a WIN2k network, servers and workstations. Is there a way through group policy to prevent users from being able to install apps. I know you can prevent some by adding them to the users local group instead of admin but i would like to beable to do this on a domain level instead of individual pc's.

This conversation is currently closed to new comments.

5 total posts (Page 1 of 1)  
| Thread display: Collapse - | Expand +

All Comments

Collapse -

Prevent Software Installation

by maxwell edison In reply to Prevent Software Installa ...

You can assign software distribution policies to either users or computers with Control distribution through the MMC. Here is an article written by Brian Posey describing the process. (I like this guy. He writes good articles and seems to know his stuff.)

http://asia.cnet.com/itmanager/tech/0,39006407,39078824,00.htm

REMOVE SPACES from the pasted URL.

This is done at the server level. If you assign the group policies at the server instead of locally, these policies would apply. Therefore, the users would have to log into a network domain, and not log into the local computer.

Collapse -

Prevent Software Installation

This article talks about software distribution from the server level and not so much a policy on preventing users from installing their own apps from the web, cd, etc.

Collapse -

Prevent Software Installation

by dec33162 In reply to Prevent Software Installa ...

You don't give anyone, other than your system (domain) administrators, workgroup administrators, or Power Users, (as necessary), accounts on the local machines.

All personnel log ONLY, into your domain.

On your domain controllers, when user accounts are created, you specify the Groups these users are assigned to. In your case, the "Domain" USER Group. As domain "Users", individuals do not have privileges to install apps on the local machine.

Depending upon the size of your organization, the Domain/System Administrators are the only ones with local accounts and the privileges on them to perform allowed tasks. Create additional Groups, as necessary, on your domain controllers to set Group policies to provide a different level of authority from the default Groups.

Collapse -

Prevent Software Installation

Poster rated this answer

Collapse -

Prevent Software Installation

by kshemary2 In reply to Prevent Software Installa ...

I am running a WIN2k network, servers and workstations. Is there a way through group policy to prevent users from being able to install apps. I know you can prevent some by adding them to the users local group instead of admin but i would like to beable to do this on a domain level instead of individual pc's.

Back to IT Employment Forum
5 total posts (Page 1 of 1)  

Related Discussions

Related Forums