T
techie9
We are attempting to lock down USB storage in Windows XP. I have read
several articles about doing this but have managed to work around every
potential fix. By imposing multi-layer set of restrictions I think
that I have effectively restricted USB storage. The last thing I need
to do is to prevent the USBSTOR.inf and USBSTOR.pnf from being deleted.
I have tried everything that I can think of to stop this from
happening. Turns out that if the user is a local admin (I know in the
perfect world user's shouldn' be local admins unless we can trust them
with our lives but as the saying goes..."we don't live anywhere near
perfect") they can still delete these files regardless of security
settings applied to them. My final hope is to create a File System
Group Policy in AD specifically restricting access to these two files.
My questions are these?
First, how would I create that so that it would apply to my
workstation? (the files exist in the same location in Windows 2003
Server as they do on Windows XP Pro, c:\windows\inf\)
Second, does anybody out there see any adverse effects for the Domain
Controller by applying policy? (Since it is a group policy and we are
only applying to a set of workstations I can't see any illeffect on the
DC but it is always good to double check)
Thank you in advance for your time...
several articles about doing this but have managed to work around every
potential fix. By imposing multi-layer set of restrictions I think
that I have effectively restricted USB storage. The last thing I need
to do is to prevent the USBSTOR.inf and USBSTOR.pnf from being deleted.
I have tried everything that I can think of to stop this from
happening. Turns out that if the user is a local admin (I know in the
perfect world user's shouldn' be local admins unless we can trust them
with our lives but as the saying goes..."we don't live anywhere near
perfect") they can still delete these files regardless of security
settings applied to them. My final hope is to create a File System
Group Policy in AD specifically restricting access to these two files.
My questions are these?
First, how would I create that so that it would apply to my
workstation? (the files exist in the same location in Windows 2003
Server as they do on Windows XP Pro, c:\windows\inf\)
Second, does anybody out there see any adverse effects for the Domain
Controller by applying policy? (Since it is a group policy and we are
only applying to a set of workstations I can't see any illeffect on the
DC but it is always good to double check)
Thank you in advance for your time...