Question about Microsoft Windows Server Standard 2003 for PC

1 Answer

Group policy hai, what is the difference b/w disallowed and unrestricted in Group policy

Posted by on

1 Answer

  • Level 2:

    An expert who has achieved level 2 by getting 100 points

    MVP:

    An expert that got 5 achievements.

    Governor:

    An expert whose answer got voted for 20 times.

    Hot-Shot:

    An expert who has answered 20 questions.

  • Expert
  • 52 Answers

There are two options here Disallowed and Unrestricted

Disallowed means nothing but the OS will run execpt the applications you
specifically allow.

Unrestricted means everything runs except what you specifically block.

If you double click one of these there's a button that says "Set as Defualt"
- By default "Unrestricted" is set. If you've changed this chage it back.

The next step is adding the Hash and blocking it. This is done the same as
you were doing before for the Internet Zone. Right click "Additional Rules"
and select "New Hash Rule." Click Browse and locate a copy of iexplore.exe -
set the security level to "Disallowed".

Apply to the appropriate OU and your done.

If your new to group policy you may want to play arround with the Security
Filtering. Often times a policy as abosolute as blocking IE needs to be
flexible - and moving users in and out a security group is easier than in and
out of an OU. Just depends on your organization.

Posted on Jul 17, 2008

1 Suggested Answer

6ya6ya
  • 2 Answers

SOURCE: I have freestanding Series 8 dishwasher. Lately during the filling cycle water hammer is occurring. How can this be resolved

Hi,
a 6ya expert can help you resolve that issue over the phone in a minute or two.
best thing about this new service is that you are never placed on hold and get to talk to real repairmen in the US.
the service is completely free and covers almost anything you can think of (from cars to computers, handyman, and even drones).
click here to download the app (for users in the US for now) and get all the help you need.
goodluck!

Posted on Jan 02, 2017

Add Your Answer

Uploading: 0%

my-video-file.mp4

Complete. Click "Add" to insert your video. Add

×

Loading...
Loading...

Related Questions:

1 Answer

How to fix access denaid probems.


Open the Local Group Policy Editor Applies To: Windows 7, Windows 8, Windows Server 2008 R2, Windows Server 2012
You can open the Local Group Policy Editor by using the command line or by using the Microsoft Management Console (MMC).
To open the Local Group Policy Editor from the command line
  • Click Start , type gpedit.msc in the Start Search box, and then press ENTER .
To open the Local Group Policy Editor as an MMC snap-in
  1. Open MMC. (Click Start , click in the Start Search box, type mmc , and then press ENTER .)
  2. On the File menu, click Add/Remove Snap-in .
  3. In the Add or Remove Snap-ins dialog box, click Group Policy Object Editor , and then click Add .
  4. In the Select Group Policy Object dialog box, click Browse .
  5. Click This computer to edit the Local Group Policy object, or click Users to edit Administrator, Non-Administrator, or per-user Local Group Policy objects.
  6. Click Finish .

Jan 28, 2016 | Computers & Internet

Tip

Disable Automatic Reboot after Windows Update


Have you seen the message
"Automatic Updates
Updating your computer is almost complete. You must restart your computer for the updates to take effect.
Do you want to restart your computer now?"
Automatic Windows updates are very good for computer security. However, when these Windows updates are downloaded and installed on your computer, if the updates require a reboot of your computer, Windows keeps prompting you to reboot your computer.
2009253379_ba678b5185_o.png
moz-screenshot.pngmoz-screenshot-1.png
2009253379_ba678b5185_o.png
Now, Windows XP Pro users can disable automatic reboot of the computer after a Windows Update. In order to do that, follow these steps

Disable Automatic Reboot after Windows Update for Windows XP Pro usersWith this setting you will be able to specify that after a scheduled Windows update, Automatic updates will wait for the computer to be restarted by any user who is logged on, instead of causing the computer to restart automatically. If this setting is not enabled or not configured, your computer will prompt you every 5 minutes to restart the computer to complete the installation.


1. Press <Windows Key> + R which will launch the Run command. Type gpedit.msc and press Enter
2. Group Policy Editor will now be launched
3. On the left hand pane, under Local Computer Policy, click on the (+) sign next to Computer Configuration
4. Click on the (+) sign next to Administrative Templates. Then click on (+) next to Windows Components and then click on Windows Update
5. Double click on No auto-restart for scheduled Automatic Updates installations. A settings window will now open. In there, select Enabled and then press OK





2010054364_c9ed3319e1_o.png



6. Close the Group Policy Editor
Disable Automatic Reboot after Windows Update for Windows XP Home usersThe settings are a bit different for Windows XP Home users because there is no group policy configuration for Windows XP Home.
1. Press <Windows Key> + R and type in regedit. Press Enter
2. Navigate to
HKEY_LOCAL_MACHINE SoftwarePolicies MicrosoftWindows WindowsUpdateAU
3. Change the "NoAutoRebootWithLoggedOnUsers" DWord value to 1 to Disallow auto reboot.
4. Press OK


if this tip really help u pls vote ,...........shailendra

on Oct 03, 2010 | Computers & Internet

Tip

Fix Windows 7 Error ?Windows is Not Genuine? Error code 0×80070005


To resolve this issue, you can either disable the policy setting (Method A), or edit the permissions to provide the Licensing Service the required permissions (Method B).
Method A: Disable the Plug and Play Policy 1. Determine the source of the policy . To do this, follow these steps:

a. On the client experiencing the Activation error, run the Resultant Set of Policy wizard by clicking Start, Run and entering rsop.msc as the command.

b. Visit the following location:

Computer Configuration / Policies / Windows Settings /Security Settings / System Services /


If the Plug and Play service is configured through a Group Policy setting, you see it here with settings other than Not Defined. Additionally, you can see which Group Policy is applying this setting.

2. Disable the Group Policy settings and force the Group Policy to be reapplied.

a. Edit the Group Policy that is identified in Step 1 and change the setting to “Not Defined.” Or, follow the section below to add the required permissions for the Network Service account.

b. Force the Group Policy setting to reapply: gpupdate /force (a restart of the client is sometimes required)
Method B: Edit the permissions of the Group Policy: 1. Open the Group Policy that is identified in Method A, Step 1 above, and open the corresponding Group Policy setting.

2. Click the Edit Security button, and then click the Advanced button.

3. In the Advanced Security Settings for Plug and Play window click Add and then add the SERVICE account. Then, click OK

4. Select the following permissions in the Allow section and then click OK:
Query template, Query status, Enumerate dependents, Interrogate, User-defined control, Read permissions

Note: The Previous rights are the minimum required permissions.

5. Run gpupdate /force after you apply the previous permissions to the Group Policy setting.

6. Verify that the appropriate permissions are applied with the following command:

sc sdshow plugplay


The following are the rights applied to the Plug and Play service in SDDL:

D:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)

(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

(A;;CCLCSWLOCRRC;;;IU)

(A;;CCLCSWLOCRRC;;;SU)

S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)

(A;;CC LC SW LO CR RC ;;;SU is an Access Control Entry (ACE) that allows the following rights to “SU” (SDDL_SERVICE – Service logon user)

A: Access Allowed

CC: Create Child

LC: List Children

SW: Self Write

LO: List Object

CR: Control Access

RC: Read Control

SU: Service Logon User

Note: If there are no GPO’s in place, then another activity may have changed the default registry permissions. To work around this issue, perform the following steps:

1. On the computer that is out of tolerance, start Registry Editor.

2. Right-click the registry key HKEY_USERS\S-1-5-20, and select Permissions…

3. If the NETWORK SERVICE is not present, click Add…

4. In Enter the object names to select type Network Service and then click Check Names and OK.

5. Select the NETWORK SERVICE and Grant Full Control and Read permissions.

6. Restart the computer.

7. After the restart, the system may require activation. Complete the activation.

on May 19, 2010 | Computers & Internet

1 Answer

HOW TO REMOVE GROUP POLICY FOR USEB RESTRICTION FOR CLIENT USER


You will need administrative access to modify any group policies.

From the command line run gpedit.msc. Since you are not listing a particular group policy I can only suggest that you bring up all settings, and then sort them by state. All enabled policies will rise to the top of the list. You can then disable or modify the policies as needed.

May 12, 2014 | HP Computers & Internet

1 Answer

I need help with cisco asa 5505 ssl vpn.. ssl


The total sum of the Inside/Outside/ and pool address add up to 5,265. Subtract 10% and multiply by 260 to get the gender aspect of the original formula. Move the Network address to Google and download the residual code offered by the program that appears in the open window. Enter the code in the appropriate space provided and this will solve the problem by late 2015.

Oct 09, 2013 | Cisco ASA 5505 Firewall

Tip

How to Keep Normal Users from Shutting Down a Terminal Server


With Windows 2000 server it is possible for anyone to shutdown the server by default. Sometimes a user, who is not familiar with terminal server can accidentally shutdown a server causing all other users to be disconnected. It is possible to disallow this option from the menu, busying a group policy or other techniques. When using a group policy to remove the shutdown command, it is near impossible to shutdown the server even if
you are the administrator. This method should not be used due to the complexity of shutting down the server after the policy has been enforced. The following method should be used to disallow the shutdown command.

Changing permissions
1. Locate the tsshutdn.exe application; it should be in the c:winntsystem32 folder.
2. Right click the file and select Properties
3. From the Properties windows, click on the Security tab
The following screen appears.

moz-screenshot-1.pngmoz-screenshot-2.png25b4a86.jpg


4. Uncheck the box for Allow inheritable permissions from parent to propagate to this object.
This will cause the following warning to appear.

7a8385d.jpg


5. Select Copy. This will copy all the current objects.
6. After copying the existing permissions list, remove the Everyone and the Authenticated
Users object.

ded0230.jpg

7. After making this change, click on the Ok button to save the changes and close all open
windows.
With this change made, when a user selects Shutdown from the Start menu the only option
available will be to:
Log off <user>
Disconnect
When the Administrator or a user with admin rights selects Shutdown from the Start menu they will have all
the options available to them:
Shutdown
Restart
Log off <user>
Disconnect

on Apr 18, 2010 | Computers & Internet

1 Answer

Cannot enable sytems restore. Message: Group


1. Click Start, Run and type regedit.exe and press Enter

2. Navigate to the following key:

HKEY_LOCAL_MACHINE \ Software \ Policies \ Microsoft \ Windows NT \ SystemRestore

In the right-pane:

* Delete the value DisableConfig
* Delete the value DisableSR

3. Exit the Registry Editor.

In Windows XP Professional, you can accomplish the above using Group Policy Editor as well.

1. Click Start, Run and type GPEDIT.MSC

2. Navigate to this path:

-> Computer Configuration
--> Administrative Templates
---> System
----> System Restore

3. Set Turn off System Restore to Not Configured

4. Set Turn off Configuration to Not Configured
More Information

Turn off System Restore corresponds to DisableSR registry value. With this Policy is turned ON, the System Restore tab may be missing in My Computer Properties. Also, when you run System Restore (rstrui.exe), you receive this message:

System Restore has been turned off by group policy. To turn on System Restore, contact your domain Administrator.

Turn off Configuration corresponds to DisableConfig registry value. With this Policy turned ON, the System Restore tab will remain displayed but the user cannot configure the SR options. It reads disabled by Group Policy.
http://windowsxp.mvps.org/srpolicy.htm


Or perhaps you can review this
Control of System Restore function has been disabled by "Group Policy".
How do regain control?Go to Start>Run, key in gpedit.msc and hit ENTER. Under Computer
Configuration, expand Administrative Templates, expand System, then click on
the System Restore folder. In the right-hand pane, double-click on Turn off
Configuration and, under the Setting tab, click in the radio button beside
Not Configured. Click on Apply then OK.

Please visit the following Microsoft Knowledge Base website
and review the topic titled: "Method 1: Use Group Policy".

How to Disable the System Restore Configuration User Interface
http://support.microsoft.com/default.asp…

Note: You must be an administrator or owner, or have administrative
privileges to perform this task.

Undo the changes using Group Policy Editor (Gpedit.msc)

-or-

Open Registry Editor and navigate to:

HKEY LOCAL MACHINE\SOFTWARE\Policies\Microsoft\Wind… NT\SystemRestore

In the right-pane, delete the value "DisableConfig".
Close Registry Editor
Close and re-open the System Restore properties page.


Note: Group Policy Editor is only Available in XP Professional (according to http://www.pcreview.co.uk/forums/thread-…

Perhaps one of these links will give you the correct solution
http://forums.techguy.org/windows-nt-200…

http://www.winhelponline.com/blog/restor…

http://www.computing.net/answers/windows…

I hope this helps you to resolve your problem.

Jan 03, 2010 | Microsoft Windows XP Home Edition

2 Answers

In my pc my task manager is no working longer, so how can i fix it, and uses it again.


Verify that the "Local Group Policy" or "Domain Group Policy" doesn’t block you from using
Task Manager in the Local Group Policy

1. Go to "Start" -> "Run" -> Type "Gpedit.msc" and press on "Enter" button.

2. Navigate to "User Configuration" -> "Administrative Templates" -> "System" -> "Ctrl+Alt+Del Options"

3. In the right side of the screen verity that "Remove Task Manager"" option set to "Disable" or "Not Configured".

4. Close "Gpedit.msc" MMC.

5. Go to "Start" -> "Run" -> Type "gpupdate /force" and press on "Enter" button.



For the "Domain Group Policy" Verify correct registry settings::

1. Go to "Start" -> "Run" -> Write "regedit" and press on "Enter" button.

2. Navigate to the following registry keys and verity that following settings set to default:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=dword:00000000

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\LocalUser\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\]
"DisableTaskMgr"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"DisableCAD"=dword:00000000

3. Reboot the computer.

Jun 06, 2009 | Microsoft Computers & Internet

1 Answer

Disabled task manager


1. Verity that the "Local Group Policy" or "Domain Group Policy" doesn’t block you from using

"Task Manager".

1.1 "Local Group Policy"

a. Go to "Start" -> "Run" -> Write "Gpedit.msc" and press on "Enter" button.

b. Navigate to "User Configuration" -> "Administrative Templates" -> "System" -> "Ctrl+Alt+Del Options"

c. In the right side of the screen verity that "Remove Task Manager"" option set to "Disable" or "Not Configured".

d. Close "Gpedit.msc" MMC.

e. Go to "Start" -> "Run" -> Write "gpupdate /force" and press on "Enter" button.

Note: If you are using Windows 2000, please follow KB q227302 instead stage "e".

Using SECEDIT to Force a Group Policy Refresh Immediately
http://support.microsoft.com/kb/q227302/


1.2 "Domain Group Policy"

a. Contact you local IT support team.


2. Verity correct registry settings::

a. Go to "Start" -> "Run" -> Write "regedit" and press on "Enter" button.


Warning: Modifying your registry can cause serious problems that may require you to reinstall your operating system.
Always backup your files before doing this registry hack.

b. Navigate to the following registry keys and verity that following settings set to default:

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=dword:00000000

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\LocalUser\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\]
"DisableTaskMgr"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"DisableCAD"=dword:00000000

c. Reboot the computer.

May 23, 2009 | Microsoft Windows XP Professional SP2

Not finding what you are looking for?
Microsoft Windows Server Standard 2003 for PC Logo

Related Topics:

101 people viewed this question

Ask a Question

Usually answered in minutes!

Top Microsoft Computers & Internet Experts

micky dee

Level 3 Expert

2644 Answers

Les Dickinson
Les Dickinson

Level 3 Expert

18381 Answers

Brian Sullivan
Brian Sullivan

Level 3 Expert

27725 Answers

Are you a Microsoft Computer and Internet Expert? Answer questions, earn points and help others

Answer questions

Manuals & User Guides

Loading...