Sign in with
Sign up | Sign in
Your question

GPO Computer Install Permissions

Last response: in Windows 2000/NT
Share
Anonymous
a b 8 Security
November 18, 2004 2:08:05 PM

Archived from groups: microsoft.public.win2000.security (More info?)

Currently our enironment install applications VIA GPO from a UNC path that is
replaicted with DFS. I want to restrict user access to the share and only
allow computer or domain computer access. Will this screw up the GPO and or
repair feature within the MSI's. I want to prevent users from being able to
go to the share and run any of the applications...mainly those users with
local admin rights... I want to set the security permissions to Domain
COmputer Access not Everyone or Athenticated User
Anonymous
a b 8 Security
November 19, 2004 12:06:25 AM

Archived from groups: microsoft.public.win2000.security (More info?)

Adding "domain computers":R to the share and removing "everyone" or
"authenticated users" should be all that's necessary. GPO software
installation and the MSI stuff that does the installation and repairs runs
under the security context of the computer, not the user.

Hope this helps

Oli


"Joe Flynn" <JoeFlynn@discussions.microsoft.com> wrote in message
news:0641E4DC-F1EB-497B-BBB1-B8142F83ACA1@microsoft.com...
> Currently our enironment install applications VIA GPO from a UNC path that
> is
> replaicted with DFS. I want to restrict user access to the share and only
> allow computer or domain computer access. Will this screw up the GPO and
> or
> repair feature within the MSI's. I want to prevent users from being able
> to
> go to the share and run any of the applications...mainly those users with
> local admin rights... I want to set the security permissions to Domain
> COmputer Access not Everyone or Athenticated User
!