大橙子网站建设,新征程启航
为企业提供网站建设、域名注册、服务器等服务
Read-Only USB custom Policy for Windows XP using Domain GPO.By pdhewjau Active Directory, Blog 0 Comments
HI, back again to the blog. This time I have been doing research for the ‘GROUP POLICY EDITOR’ for server 2008 R2 and Server 2012. During my research I found that ‘GPMC’ is a quite vast tool and can control almost everything of the system on AD. Here I have created a custom group policy to block the USB drive.
创新互联长期为1000多家客户提供的网站建设服务,团队从业经验10年,关注不同地域、不同群体,并针对不同对象提供差异化的产品和服务;打造开放共赢平台,与合作伙伴共同营造健康的互联网生态环境。为黄骅企业提供专业的成都网站设计、做网站,黄骅网站改版等技术服务。拥有十多年丰富建站经验和众多成功案例,为您定制开发。
Some of you may ask why I need to create USB drive although I do have already a policy on the server to block USB. But if you read this policy carefully you will find out that this policy is for only the OS which are higher version than Windows Vista (i.e. Windows Vista, Windows 7 and Windows 8). But if someone ask you for Windows XP than??? What will you do?? If someone ask you for make a read-only policy for USB on windows XP. What will you do again?? So Simply I have created a custom Policy that can be compatible with windows XP or any other Windows Platform OS. Copy this code, Paste on notepad and save it in the extension of ‘.adm’.
CLASS MACHINE
CATEGORY !!category1
POLICY !!policyname
EXPLAIN !!DefaultSharesExplain
KEYNAME “SystemCurrentControlSetControlStorageDevicePolicies”
VALUENAME “WriteProtect”
VALUEON NUMERIC 1
VALUEOFF NUMERIC 0
END POLICY
END CATEGORY
[strings]
category1=”Storage Device Read-Only”
policyname=”Storage Device Read-Only Policy”
DefaultSharesExplain=”If Enable is selected, USB will be write Protected and only work on Read-only mode. if Disbale is selected it will work on both Read and Write mode. This policy basically works for windows XP sp3.–>Creator Aerrow”
Once you have created the adm file. Open GPMC, Create a new policy and edit it. After that go to the Computer ConfigurationàPoliciesà Administrative Template.
Right click on Administrative template and select Add/Remove Template.
Click on Add and select the .adm file you have just created and click on close.
This will import your custom policy on you Group policy editior in ADMX. Where you can enable this policy.