User/Account management in Win2k Profressional????

The Wildcard

Platinum Member
Oct 31, 1999
2,743
0
0
Hello, this is bascially what i want to do. I am running Win2k Professional on A SINGLE COMPUTER. I have two accounts set up. An administrator and a guest. I'd like to be able publish/assign or set which applications the GUEST account can use. Furthermore, I'd like to be able configure the guest account so that they can't, for example, install any new software.

So far I am able to access the GROUP POLICY in the microsoft management console (mmc). BUT, under the SOFTWARE SETTINGS branch/folder, there is nothing but a blank. So what do i do?

Furthermore, every setting i change in user rights branch/folder affects BOTH my administrator AND guest account.
I want however, to only thos changes to affect my GUEST account.


NOW, i have done alot of reading on the web, including at microsoft's website and at other sites and i have just been getting lost.

Any help would be appreciated.

Note: I have installed the administration tools pak from the Win2k Server Cd ( adminpak.msi ). But i have no idea how to use it.
 

Twilling

Senior member
Oct 9, 1999
221
0
0
I think a better way to set up the guest accout would be to have the person change password after logging on as guest, then assighning him/her as a user account with "specific priviledges." The guest account was not intended to be managed. The user account can be adjusted in a variety of ways to accomadate your taste...
 

AC

Senior member
Nov 2, 1999
616
0
0
You can manage a USER account called "Guest", whereas a GUEST account is established on login with DEFAULT USER settings and terminated on logout.

I am still trying to figure out the policy settings myself (had asked for help in this forum, but received none; probably going to read the Win2K Pro Resource Kit).

A USER account has a lot of things disabled such as software installation, but due to registry (? i think) restrictions (that I have yet to figure out how to control) some programs will not work.

I would add a USER account, set up directory restrictions (you can make the entire drive read-only if you want to), log on as that USER, make any other changes.

Until I figure out how to modify policy settings myself, this is all the advice I have to give.
 

The Wildcard

Platinum Member
Oct 31, 1999
2,743
0
0
How do i setup directory restrictions for that user account??

From what i understand, to partially solve my problem, i need to create a domain. Since i am just one computer at home, i currently don't have one since i am not on a network. If i did have a domain, then i could run active directory and create organizational units or OU. In each OU, i can create user accounts and group policies for each OU.

Then i can use group policy editor to edit THAT SPECIFIC OU'S GROUP POLICY and then only those changes would affect those users.

Problem is, i can't run active directory without a domain AND i still can't figure out how to limit specific software.

Apprently, i need the SOFTWARE INSTALLATION SNAP-IN but i can't find it at all. I don't know where i can install it from.
 

Deceiver

Senior member
Mar 4, 2000
385
0
0
can't you just set the security of certain directories to administrators only? for like program files, you could set it to read/exectue, while others you could just disable for them.
 

shiner

Lifer
Jul 18, 2000
17,112
1
0
Buy a good book on Win2k. QUE publishes a good one named Using Windows 2000 Professional to be honest that book had more helpful stuff in it than the Microsoft courseware book for the 2000 MCSE.

Oh yeah...1 test to go to get that Win2k MCSE!!! WOO HOO!!!