Microsoft Windows NT 4.0 manual Tem Policy Editor

Page 51

tem Policy Editor.

2.From the File menu, click New Policy.

3.The Default Computer and Default User icons will be displayed. Click the user, computer, or group to be modified.

NOTES:

If you need to add a user, group, or computer, you can copy and paste the settings without having to manually go through each of the entries and make selections. For example, if you have made modifica- tions to User1 and want to create a similar profile for another user (User2), select User1, then from the Edit menu, click Copy. Select User2, then from the Edit menu, click Paste. Make any changes specific to User2 and save your changes. You will be prompted to verify your changes, and then the settings will be ap- plied.

When you add users or computers to the policy file, they automatically assume the properties of the icons Default User or Default Computer respectively.

4.Make changes to the options desired. For more information on each op- tion, see the portion of this guide titled “Registry Keys Modified by the System Policy Editor Default Templates.”

5.From the File menu, click Save As and save the policy file with the appro- priate name:

If workstations will be set to Automatic mode, use the file name NTconfig.pol.

If workstations will be set to Manual mode, use the name of your choice.

6.If workstations will be set to Automatic mode, place the file in the NETLOGON share of each of the domain controllers that will be perform- ing authentication. To simplify this process, you can use directory replication from Windows NT to replicate the file to the other domain con- trollers. If you use replication and later make changes to the file, the modified file will be duplicated across validating machines automatically.

Windows NT-based workstations, by default, are set to download the policy file in Automatic mode. If you modify the setting to specify manual update and to point to a specific machine, you must inform the workstation about this location change. There are two ways to do this:

Place the policy file in the location specified for manual updates, but maintain a policy file in the NETLOGON share that points to the man- ual path. Then, leave the Windows NT-based workstation in the default Automatic mode. When the policy file is first downloaded this change will be made, and at next logon and every logon thereafter, Windows NT will go to the new location for policy file updates.

Visit each Windows NT-based workstation either remotely or locally and make the required registry change to point to the new location. (Depending on the number of workstations affected, this could be very time consuming.)

7.Log on to the Windows NT-based workstation to download and enact the policy.

Microsoft Windows NT Server White Paper

43

Image 51
Contents Server Operating System Page Abstract User environment than they have ever had beforeWindows NT 4.0 documentation and Resource Kits Page Contents System Policy Editor System Policy An IntroductionPage Appendix C Usage Notes For More Information Appendix a -FlowchartsUser Profile Flowcharts System Policy Flowchart Autorun Start BannerProfiles, Policies, and the Zero Administration Kit IntroductionTCO and the User Before You Begin What are User Profiles and System Policies?Key Terminology 32-bit version of the Registry EditorComputer Technical NotesCreating and Administering User Profiles Establishing User Profiles AN OverviewUser Profile Structure Configuration Preferences Stored in Profile Directories Configuration Preferences Stored in the Registry HiveEquivalent Windows 95 file Windows NT 4.0 and Windows User Profile DifferencesWindows NT 4.0 file List, is checked for an existing entry for that userUser Profile Planning and Implementation Setting Permissions for User ProfilesSelecting a Location to Save User Profiles Encoding Permissions in the User ProfileSetting Persistent Connections Working Around Slow Network Links Delete the network connection and reconnectCreating and Maintaining User Profiles Creating a New Roaming User Profile for Windows NTTo create a new roaming user profile Microsoft Windows NT Server White Paper Copy the profile appropriate to your implementation ∙ To copy an existing user’s profile to another user∙ To copy a template profile manually to a number of users To create a new mandatory User Profile Creating a New Mandatory User Profile for Windows NTCalled TemplateUser Changing the User’s Ability to Modify a Profile Making a Roaming Profile Mandatory Windows NTEnforcing the Use of the Server-based Profile To create a roaming user profile for a Windows 95 user Creating a New Roaming User Profile for a Windows 95 UserTo create a mandatory user profile for a Windows 95 user Creating a New Mandatory User Profile for WindowsDeleting Profiles Ddays \\computernameDetermining Which Profile Is Displayed Copying Profiles Microsoft Windows NT Server White Paper All Users Shared Profile Log Files Used by ProfilesProfile Names and Storage in the Registry Default User Template ProfilesTo manually customize a User Profile Manually Administering a User Profile through the RegistryModifying the Default User Profile Microsoft Windows NT Server White Paper To create the profile from an existing template profile To create a mandatory profile from the old profileTo change the profile Creating Profiles Without User-Specific ConnectionsTroubleshooting User Profiles with the UserEnv.log File To enable loggingStart REGEDT32 and locate the following path ========================================================= Sample LogSystem Policy Files System Policy AN IntroductionPolicy Replication How Policies Are AppliedThis change must be made individually to each workstation Additional Implementation Considerations Microsoft Windows NT Server White Paper System Policy Editor Installing the System Policy Editor on a Windows 95 ComputerSystem Policy Editor Template .Adm Files Updating the Registry with the System Policy EditorYour Own Custom .Adm File,later in this document Configuring Policy SettingsTo create a new System Policy Setting Folder Paths Back to DefaultsTo restore the defaults Creating a System PolicyTem Policy Editor To resolve links correctly Setting Up Shortcuts for Server-based ProfilesCreating Alternate Folder Paths To create shared folders and alternate folder pathsTo retrieve the policy file from a specific location Deploying Policies for Windows NT 4.0 MachinesUpdate mode box, select Manual use specific path Deploying Policies for Windows 95 MachinesTo deploy policies for a Windows 95-based computer Modifying Policy Settings on Stand-Alone Workstations To change policy settings remotelyTo create a policy file for stand-alone workstations To change policy settings locally Creating a Custom .Adm FileTo create a custom .adm file Would use These can be nested to create sub-categories as followsRemember that the Valuename needs to be within a Part if END Part Type REGEXPANDSZ, for example ∙ MAXLEN- Specifies the maximum length of text, for exampleSave and test your file Each time the System Policy Editor starts Configuring System Policies Based on Geographic LocationBuilding Fault Tolerance for Custom Shared Folders Clearing the Documents Available ListMicrosoft Windows NT Server White Paper Default User Settings Selection Color scheme Key Selection Remove Run command from Start menu DescriptionSelection Remove Find command from Start menu Description Selection Hide drives in My Computer Description Selection Hide Network Neighborhood DescriptionSelection No Entire Network in Network Neighborhood Key Selection Hide all items on desktop Description Selection No workgroup contents in Network Neighborhood KeyCategory System Selection Disable Shut Down command DescriptionSelection Dont save settings at Exit Description SelectionDisable registry editing toolsSelection Run only allowed Windows applications Description Selection Custom desktop icons Description Selection Custom Program folder DescriptionSelection Hide Start menu subfolders Description Selection Custom Startup folder DescriptionSelection Custom Network Neighborhood Description Selection Only use approved shell extensions Key \CurrentVersion \Explorer \User Shell FoldersSelection Custom Start menu Description As part of the Start menuSelection Disable context menus for the Taskbar Description Selection Remove File menu from Explorer DescriptionSelection Work Drive options Selection Run logon scripts synchronously Description Selection Disable link file tracking DescriptionSelection Show welcome tips at logon Description Selection Disable Task Manager Description\Tips Default Computer SettingsSelection Remote update Description \ExplorerSelection Permitted managers Key Selection Run Description Selection Scheduler priority Key Selection Create hidden drive shares server DescriptionSelectionMax number of unsuccessful authentication retries Selection Beep for error enabled DescriptionError occurs on a print server CategoryWindows NT Remote AccessRAS Auto-disconnect SelectionWait interval for callbackSelectionAuto disconnect RAS Call-back IntervalSelection Custom shared desktop icons Description Custom shared foldersSelection Custom shared Programs folder Description Start menuSelection Custom shared Start menu Description Selection Custom shared Startup folder DescriptionSelection Logon banner Logon dialog is displayed Enables or disables display of the last logged on userWith text Dialog windowSelection Allow extended characters in 8.3 file names Tion, this value takes precedenceFile system \System \CurrentControlSet \Control \FileSystemSelectionDelete cached copies of roaming profiles Last access time. This increases the file system’sPerformance CategoryWindows NT User ProfilesSelectionSlow network connection timeout SelectionTimeout for dialog boxesSelectionAutomatically detect slow network connections Registry Value Registry Data Description Registry Entries not Included in the System Policy Editor Registry Value Registry Data Description NoStartBanner For More Information User Profile Flowcharts Appendix a FlowchartsWill the user be mandated to receive the profile for logon? Available? See Apply System Policy Save settings to Registry Call made to check Check for .man extension Server profile Do Group Policies System Policy FlowchartExisting Windows NT 3.5x Roaming Profile Appendix B Implementing User ProfilesCreating a New Windows NT 4.0 Mandatory Profile Creating a New Windows NT 4.0 Roaming ProfileChanging a Roaming Profile to a Mandatory Profile Appendix C Usage Notes Recent Updates to Profiles Since Retail ReleaseRecent Updates to Policies Since Retail Release Appendix D Related Knowledge Base Articles ProfilesPolicies Q156432

Windows NT 4.0 specifications

Microsoft Windows NT 4.0, released on July 29, 1996, marked a significant milestone in the evolution of Microsoft's operating systems. As the successor to Windows NT 3.51, this version brought a range of enhancements and features that appealed to both enterprise users and consumers.

One of the standout characteristics of Windows NT 4.0 was its introduction of the Windows 95 user interface, which significantly improved user experience and accessibility. This graphical interface made it easier for users to navigate the operating system, transitioning from the more complex interfaces of previous NT versions. The integration of familiar elements such as the Start menu and taskbar helped bridge the gap between professional and personal computing environments.

Windows NT 4.0 was built on a robust and secure architecture. It utilized the NT kernel, which provided improved multitasking and stability compared to its predecessors. This operating system was designed to handle multiple user sessions simultaneously, making it suitable for servers as well as workstations. The inherent stability of NT 4.0 made it a favorite in enterprise environments, particularly for critical applications and systems.

Another defining feature of NT 4.0 was its support for a wide range of hardware, making it versatile across various machine configurations. It included compatibility with numerous devices and peripherals, which facilitated its adoption in diverse settings.

In addition to user interface enhancements and hardware compatibility, Windows NT 4.0 introduced powerful networking capabilities. The operating system supported TCP/IP natively, alongside NetBEUI and IPX/SPX protocols. This meant that it could seamlessly integrate into existing network environments, providing essential services for file and printer sharing, domain management, and remote access through features like Remote Access Service (RAS).

Security was another key focus area for Windows NT 4.0. Built around security principles, it employed a discretionary access control system, allowing administrators to define user permissions and manage access to resources effectively. This was particularly appealing to businesses that needed to enforce strict security policies.

Windows NT 4.0 also included improved support for backup and recovery, through the inclusion of the NT Backup utility. The operating system allowed for the creation of scheduled backups and simplified data recovery processes, enhancing data integrity and reliability.

As NT 4.0 entered its later years, it laid the groundwork for future Windows operating systems, influencing the design of later versions, particularly Windows 2000. It combined user-friendly features with enterprise-level robustness, ultimately shaping expectations for modern operating systems across various industries.