Windows SteadyState includes a Group Policy template called SCTSettings.adm in the ADM folder commonly located in %systemdrive%\Program Files\Windows SteadyState. This template reproduces most of the settings included in Windows SteadyState Feature Restrictions tab of the User Settings dialog box and can be used to deploy restrictions to users who are members of an Active Directory domain.
Group Policy for a domain can be configured either with the Group Policy Management Console, or by using the Group Policy Editor built into Active Directory Users and Computers. For Windows XP, the Group Policy Management Console is an add-in tool available for download from Microsoft. Group Policy Management Console is integrated into Windows Vista. By adding the SCTSettings.adm template into these tools, you gain access to account restrictions and settings that are appropriate for user accounts on shared computers.
The SCTSettings.adm Group Policy template included with Windows SteadyState also includes the capability to set idle and mandatory logoff timers, if Windows SteadyState is installed on your computers.
It is important that you apply these settings only to specific user accounts, so as not to restrict legitimate administrative user accounts on any computers.
To use Active Directory Users and Computers to manage Windows SteadyState restrictions
-
Start Active Directory Users and Computers on a computer running Microsoft Windows Server 2003 by clicking Start, and then clicking All Programs.
-
Click Administrative Tools. In Active Directory Users and Computers, right-click the organizational unit (OU) for which you want to configure policy, and then click Properties.
-
On the Group Policy tab, select the policy you want to modify, and then click Edit.
-
Expand User Configuration, right-click the Administrative Templates folder, and then click Add/Remove Templates.
-
In the Add/Remove Templates dialog box, click Add and then browse to the location of the SCTSettings.adm template, commonly located in %systemdrive%\Program Files\Windows SteadyState\ADM.
-
Browse the settings in the All Windows SteadyState Restrictions folder and note their similarity to the program and user restrictions settings in Windows SteadyState. Descriptions are given for each setting.
-
Make any restrictions changes that you want and then exit Group Policy Editor.
Note: |
---|
We recommend that you create an OU that stores the shared user accounts in your environment, and that you apply the SCTSettings.adm template to the User Configuration portion of a Group Policy Object linked to this dedicated OU. |