PDA

View Full Version : XP security


David Wenham
December 14th 03, 02:41 AM
My boss has new laptop, and needs access to NT domain
resources mostly a mapped network drive, but his is
security paranoid and wants no one to access his computer,
either remotely or infront of it.

I have 2 means of resolving this problem.

1. Attached the computer to the domain. The doman
administrator can access his computer and therefore access
all his information. Any solutions here ?

2. Attached to the the workgroup of same name of the
domain and map the drive. This work fine until he steps
outside the office connects to a ISP. When connects to
outside network ie at home dials into the internet, when
he reconnects to the netwrok the next day he loses the
workgroup connection and cannot see the the rest of the
network, and therefore loses the network drive. Any
solutions here ?

Thanks

David

Roger Abell [MVP]
December 14th 03, 02:41 AM
"David Wenham" > wrote in message
...
> My boss has new laptop, and needs access to NT domain
> resources mostly a mapped network drive, but his is
> security paranoid and wants no one to access his computer,
> either remotely or infront of it.
>
> I have 2 means of resolving this problem.
>
You missed one (at least)

> 1. Attached the computer to the domain. The doman
> administrator can access his computer and therefore access
> all his information. Any solutions here ?
>
remove Domain users from Users, and also remove
from Users Authenticated Users and INTERACTIVE
and then add his domain account to Users
remove Domain Admins from Administrators and have
his issue a memo that any Domain Admin that changes
that is out the door.

> 2. Attached to the the workgroup of same name of the
> domain and map the drive. This work fine until he steps
> outside the office connects to a ISP. When connects to
> outside network ie at home dials into the internet, when
> he reconnects to the netwrok the next day he loses the
> workgroup connection and cannot see the the rest of the
> network, and therefore loses the network drive. Any
> solutions here ?
>
Get a different ISP that does not dictate what must be
the workgroup name ! They have no business doing that.
or
Use a login script with some intelligence to reestablish
his environment, or get an app like NetSwitcher

> Thanks
>
> David
>

Google