A Windows XP help forum. PCbanter

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Go Back   Home » PCbanter forum » Microsoft Windows XP » Security and Administration with Windows XP
Site Map Home Register Authors List Search Today's Posts Mark Forums Read Web Partners

A policy to stop Internet usage



 
 
Thread Tools Display Modes
  #1  
Old October 10th 09, 02:23 AM posted to microsoft.public.windowsxp.security_admin
Terry
external usenet poster
 
Posts: 187
Default A policy to stop Internet usage

Using Windows XP Professional on a Windows 2000 Server Domain; how can I best
prohibit users from using the Internet (except for one weather web site)?

There is a problem the users need admin rights to use a business specific
software. I could if needed take the machine off the domain setting it to a
work group.

Is there a control or a policy I can use?

Looking for an idea - thanks

Ads
  #2  
Old October 10th 09, 12:38 PM posted to microsoft.public.windowsxp.security_admin
John John - MVP[_2_]
external usenet poster
 
Posts: 1,637
Default A policy to stop Internet usage

Terry wrote:
Using Windows XP Professional on a Windows 2000 Server Domain; how can I best
prohibit users from using the Internet (except for one weather web site)?

There is a problem the users need admin rights to use a business specific
software. I could if needed take the machine off the domain setting it to a
work group.

Is there a control or a policy I can use?

Looking for an idea - thanks


How are the machines connecting to the internet? You may be able to use
domain group policies or a proxy server but in my opinion the easiest
way would probably be to lock them out or restrict sites at the router.
Putting the machines in a workgroup will only exacerbate things, you
will lose all control on the machines, it would be a free for all...or
at least a free for all for users with administrative privileges.

John
  #3  
Old October 10th 09, 12:59 PM posted to microsoft.public.windowsxp.security_admin
Terry
external usenet poster
 
Posts: 187
Default A policy to stop Internet usage

John, thanks

Internet is a DSL from ATT and they control the router. If I use a Domain
Group Policy for certain users, would that policy aply even if the users have
admin rights on the local machine? And what is the process to write or change
a group polocy?

"John John - MVP" wrote:

Terry wrote:
Using Windows XP Professional on a Windows 2000 Server Domain; how can I best
prohibit users from using the Internet (except for one weather web site)?

There is a problem the users need admin rights to use a business specific
software. I could if needed take the machine off the domain setting it to a
work group.

Is there a control or a policy I can use?

Looking for an idea - thanks


How are the machines connecting to the internet? You may be able to use
domain group policies or a proxy server but in my opinion the easiest
way would probably be to lock them out or restrict sites at the router.
Putting the machines in a workgroup will only exacerbate things, you
will lose all control on the machines, it would be a free for all...or
at least a free for all for users with administrative privileges.

John

  #4  
Old October 10th 09, 02:15 PM posted to microsoft.public.windowsxp.security_admin
Leythos[_2_]
external usenet poster
 
Posts: 976
Default A policy to stop Internet usage

In article ,
says...

Using Windows XP Professional on a Windows 2000 Server Domain; how can I best
prohibit users from using the Internet (except for one weather web site)?

There is a problem the users need admin rights to use a business specific
software. I could if needed take the machine off the domain setting it to a
work group.

Is there a control or a policy I can use?

Looking for an idea - thanks


Why not just use a Global Blocking policy with exceptions for
*.Microsoft.com and *.Symantec.com (if you use Symantec) and others that
you approve of.

Try looking at
http://www.opendns.com/

It will let you give them SOME access and you can block most of the
others.

One warning, if you block Web Mail, it will also block your SMTP server,
if you have one, from sending to those providers, so you have to white-
list the MX records - this lets you send email, but blocks them from
accessing the websites that provide access to it.


--
You can't trust your best friends, your five senses, only the little
voice inside you that most civilians don't even hear -- Listen to that.
Trust yourself.
(remove 999 for proper email address)
  #5  
Old October 10th 09, 02:51 PM posted to microsoft.public.windowsxp.security_admin
John John - MVP[_2_]
external usenet poster
 
Posts: 1,637
Default A policy to stop Internet usage

You would create a Group Policy and apply it to the proper
Organizational Unit (OU). Domain Policies cannot be overridden by local
administrators. See here for typical instructions:

http://www.chrisse.se/MAQB.asp?ID=17
How to restrict internet access Domain wide or for a single Site or OU
with Group Policies

The ATT DSL Router. I don't know which router(s) ATT supplies or
how they set up their customers but I kind of doubt that they control
the router. I'm quite sure that you can configure the router to suit
your needs, if you have the manual for the router you should be able to
find your way around and set it to your liking. That being said, ISP
supplied routers are usually basic (cheap) routers with very limited
features. For most parts you can usually disable all the routing
functions on these cheap routers and simply have the modem part of the
device enabled and then pass it through a decent business class
router/firewall appliance that can control internet access by IP or MAC
address. This in my opinion is about as safe and easy as it gets, only
users with the router password can make changes to the setup.

John


Terry wrote:
John, thanks

Internet is a DSL from ATT and they control the router. If I use a Domain
Group Policy for certain users, would that policy aply even if the users have
admin rights on the local machine? And what is the process to write or change
a group polocy?

"John John - MVP" wrote:

Terry wrote:
Using Windows XP Professional on a Windows 2000 Server Domain; how can I best
prohibit users from using the Internet (except for one weather web site)?

There is a problem the users need admin rights to use a business specific
software. I could if needed take the machine off the domain setting it to a
work group.

Is there a control or a policy I can use?

Looking for an idea - thanks

How are the machines connecting to the internet? You may be able to use
domain group policies or a proxy server but in my opinion the easiest
way would probably be to lock them out or restrict sites at the router.
Putting the machines in a workgroup will only exacerbate things, you
will lose all control on the machines, it would be a free for all...or
at least a free for all for users with administrative privileges.

John

  #6  
Old October 10th 09, 03:17 PM posted to microsoft.public.windowsxp.security_admin
David H. Lipman
external usenet poster
 
Posts: 4,185
Default A policy to stop Internet usage

From: "Terry"

| Using Windows XP Professional on a Windows 2000 Server Domain; how can I best
| prohibit users from using the Internet (except for one weather web site)?

| There is a problem the users need admin rights to use a business specific
| software. I could if needed take the machine off the domain setting it to a
| work group.

| Is there a control or a policy I can use?

| Looking for an idea - thanks


This is what a FireWall Appliance is all about.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


 




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off






All times are GMT +1. The time now is 12:06 PM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright ©2004-2024 PCbanter.
The comments are property of their posters.