Windows Security Documentation
This article provides information about the Windows security system and the restrictions that you can use to limit functionality.
Original Author: John M. Hall
Code
Windows Security
Documentation
color=#000000>Written by John Hall
style="FONT-SIZE: 16pt" face=Arial color=#000000>Documentation
Notes
format that was a little odd/wild, so, as requested, I've cleaned it up and
added more notes about using it. Hopefully this new organization and these
notes will help you better understand how to use this information and its
limitations. I, however, have not added any additional information to this
documentation because of the limited amount of security information that is
redily available for the newer operating systems.
use. Those are mentioned below:
work with Microsoft Windows XP or Millennium Edition. It's not been tested,
so I don't recommend trying it. It's known that a lot of this doesn't work
with Microsoft Windows NT 4.0 and below, so I also don't recommend its
application there. If you do decide to try to use it, remember, I'm not
responsible for your actions and you are doing this on your own accord.
known to override other settings on certain operating systems. This is most
likely because Microsoft didn't spend the required amount of time making the
Windows 98 security system(probably the most vulnerable to this problem) a
high-performance or very reliable work. If you find that some of these
settings have "holes" or something and it bothers you, I suggest you switch
to a more securified operating system in the Windows class, such as
Microsoft Windows 2000 Professional or greater.
on the original copy of this documentation and this section is here to answer
some of the questions that I noticed.
are shown in this documentation, simply reverse your process. Just delete
anything that you added to lock or disable a feature or you can make the
value the inverse. If it's a DWORD value, make it "00000000" instead of
"00000001", or a string value "yes" instead of "no" or vice versa.
internet access, I suggest you download any free firewall available. A
firewall will monitor what information is sent and recieved to your computer
through any network connection and filter it according to rules. The most
popular, free firewall that is available is onmouseover="self.status=title;return 0"
title="Click here to view the ZoneAlarm free edition homepage"
onmouseout="self.status='';return 0"
href="http://www.zonealarm.com/products/za/freedownload2.html"
target=_zonelabs>ZoneAlarm, by ZoneLabs, Inc. It's actually the
most secure when it comes to application internet access prevention.
to reverse the application locking method. You might want to experiment with
it by making a seperate user account on your computer and applying the
settings to that user only. Basically, that's what I did throughout the
period that I wrote this documentation and it doesn't harm any of your stuff
and it helps you uncover the truth. Don't afraid to be creative with this
information, just remember my disclaimer about it from
above.
Windows System
Security Settings
color=#000000>All the information that is included in this section affects the
main Windows system. These alter actual system functions and/or settings that it
uses to display certain items.
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesActiveDesktop color=#c00000>NoChangingWallPaper
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer color=#c00000>NoActiveDesktopChanges
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer color=#c00000>NoDesktop
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer color=#c00000>NoActiveDesktop
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesActiveDesktop color=#c00000>NoHTMLWallPaper
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesActiveDesktop color=#c00000>NoClosingComponents
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesActiveDesktop color=#c00000>NoDeletingComponents
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesActiveDesktop color=#c00000>NoEditingComponents
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesActiveDesktop color=#c00000>NoAddingComponents
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer color=#c00000>NoInternetIcon
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer color=#c00000>NoNetHood
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer color=#c00000>NoDriveTypeAutoRun
DWORD (set value of 0xb5000000)
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer color=#c00000>NoDispAppearancePage
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer color=#c00000>NoDispBackgroundPage
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer color=#c00000>NoDispCPL
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer color=#c00000>NoDispScrSavPage
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer color=#c00000>RestrictRun
DWORD (set value of 0x00000001)
list of programs that you want to allow to run. You can do this by creating
a Key inside the Explorer Key and calling it RestrictRun and adding string
values as demonstrated below:
Name "1"
Value "mspaint.exe"
color=#008000>This will allow any program named mspaint.exe to run on the
system
Name "2"
Value "iexplore.exe"
color=#008000>This will allow any program named iexplore.exe to run on the
system
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem color=#c00000>DisableRegistryTools
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPolicies color=#c00000>NoClose
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPolicies color=#c00000>NoLogoff
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPolicies color=#c00000>NoFind
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPolicies color=#c00000>NoRecentDocsMenu
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPolicies color=#c00000>NoFavoritesMenu
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPolicies color=#c00000>NoFolderOptions
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPolicies color=#c00000>NoDesktopUpdate
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPolicies color=#c00000>NoSetActiveDesktop
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPolicies color=#c00000>NoSetFolders
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPolicies color=#c00000>NoSetTaskbar
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPolicies color=#c00000>NoSaveSettings
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPolicies color=#c00000>NoTrayContextMenu
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPolicies color=#c00000>NoViewContextMenu
DWORD (set value of 0x00000001)
This
only applies to Microsoft Office 2000
HKEY_LOCAL_MACHINESoftwareMicrosoftOffice9.0CommonTuneUp color=#c00000>Disabled
DWORD (set value of 0x00000001)
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerAutoComplete color=#c00000>Use
String (set value of
"no")
Internet
Explorer System Settings
color=#000000>All the information that is included in this section affects the
operation of Internet Explorer. Please note that these only affect
Internet Explorer's operation and will not work with any other browsers that may
be installed on your computer.
HKEY_CURRENT_USERSoftwareMicrosoftInternet
ExplorerRestrictionsNoBrowserClose
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftInternet
ExplorerRestrictionsNoBrowserContextMenu
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftInternet
ExplorerRestrictionsNoBrowserOptions
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftInternet
ExplorerRestrictionsNoBrowserSaveAs
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftInternet
ExplorerRestrictionsNoFavorites
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftInternet
ExplorerRestrictionsNoFileNew
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftInternet
ExplorerRestrictionsNoFileOpen
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftInternet
ExplorerRestrictionsNoFindFiles
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftInternet
ExplorerRestrictionsNoOpenInNewWnd
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftInternet
ExplorerRestrictionsNoSelectDownloadDir
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftInternet
ExplorerRestrictionsNoTheaterMode
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftInternet
ExplorerRestrictionsNoViewSource
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftInternet
ExplorerInfodeliveryRestrictions color=#c00000>NoAddingChannels
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftInternet
ExplorerInfodeliveryRestrictions color=#c00000>NoAddingSubscriptions
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftInternet
ExplorerInfodeliveryRestrictions color=#c00000>NoRemovingChannels
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftInternet
ExplorerInfodeliveryRestrictions color=#c00000>NoRemovingSubscriptions
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftInternet
ExplorerInfodeliveryRestrictions color=#c00000>NoSearchCustomization
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftInternet
ExplorerControl PanelRestrictionsConnwiz Admin
Lock
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftInternet
ExplorerDisableImportExportFavorites
DWORD (set value of 0x00000001)
HKEY_CURRENT_USERSoftwareMicrosoftInternet
ExplorerMainDisable Script Debugger
String (set value of "yes")
HKEY_CURRENT_USERSoftwareMicrosoftInternet
ExplorerMainUse FormSuggest
String (set value of "no")
HKEY_CURRENT_USERSoftwareMicrosoftInternet
ExplorerMainFormSuggest Passwords
String (set value of "no")
HKEY_CURRENT_USERSoftwareMicrosoftInternet
ExplorerMainNotifyDownloadComplete
String (set value of "no")
HKEY_CURRENT_USERSoftwareMicrosoftInternet
ExplorerMainErr Dlg Displayed On Every Error
String (set value of "no")
HKEY_CURRENT_USERSoftwareMicrosoftInternet
ExplorerMainShowGoButton
String (set value of "no")
HKEY_CURRENT_USERSoftwareMicrosoftInternet
ExplorerMainUse Custom Search URL
DWORD (set value of 0x00000000)
HKEY_CURRENT_USERSoftwareMicrosoftInternet
ExplorerMainWindow Title
String (set value of "custom title
text")
Explorer
This only applies to Internet
Explorer 5.0 and up
HKEY_LOCAL_MACHINESoftwareMicrosoftInternet
Connection WizardCanInstallISPKit5
String (set value of
"no")
Windows Media
Player System Settings
color=#000000>All the information that is included in this section affects the
operation of Windows Media Player and components. Please note that these
only affect Windows Media Player's operation and will not work with any
other players that may be installed on your computer.
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsMediaPlayer color=#c00000>NoFindNewStations
DWORD (set value of 0x00000001)
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsMediaPlayer color=#c00000>NoMediaFavorites
DWORD (set value of 0x00000001)
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsMediaPlayer color=#c00000>NoRadioBar
DWORD (set value of 0x00000001)
HKEY_LOCAL_MACHINESoftwareMicrosoftMediaPlayerPlayerUpgrade color=#c00000>AskMeAgain
String (set value of "no")
Loading Comments ...
Comments
No comments have been added for this post.
You must be logged in to make a comment.