MSFN Forum: Security Rights for using Client Installation Wizard (CIW) - MSFN Forum

Jump to content



Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Security Rights for using Client Installation Wizard (CIW) Rate Topic: -----

#1 User is offline   xponard 

  • Group: Members
  • Posts: 7
  • Joined: 14-November 04

Posted 13 December 2005 - 02:59 AM

Hello,

I am trying to implement a RIS server to deploy unattended installation of Windows XP.
But I am asking few question about security.
Especially with the Client Installation Wizard,
in fact, as I can see, a user with a working computer with PXE-boot enable and no admins rights could easily launch the RIS startup, logon himself with its own account to completely reinstall its own computer (and then loosing all local data...)

I want to know if there is a way to allow only a special group/user account (even admin) to be able to complete/launch the Client Installation Wizard process.

Or showing me how to increase the security process with RIS.

ps : I also try to create a special delegation control on a group for joining computer, and changing GPO to allow only a special group to join a computer to the domain but unsuccessfully...

Thanks in advance.

This post has been edited by xponard: 13 December 2005 - 05:06 AM



#2 User is offline   cluberti 

  • Gustatus similis pullus
  • Group: Supervisor
  • Posts: 11,001
  • Joined: 09-September 01
  • OS:Windows 7 x64
  • Country: Country Flag

Posted 14 December 2005 - 12:23 PM

If you change NTFS permissions on the image folder, a user without permissions cannot access that image (as the user won't be able to enumerate the .sif files).

#3 User is offline   xponard 

  • Group: Members
  • Posts: 7
  • Joined: 14-November 04

Posted 15 December 2005 - 03:33 AM

That's It !

I have changed the NTFS permissions of the RemoteInstall folder on the RIS server.
>Replacing "Authenticated Users" group with my dedicated group for deploying (Read/Execute+List Contend+Read)

Thanks.
:hello:

#4 User is offline   cluberti 

  • Gustatus similis pullus
  • Group: Supervisor
  • Posts: 11,001
  • Joined: 09-September 01
  • OS:Windows 7 x64
  • Country: Country Flag

Posted 15 December 2005 - 06:54 PM

Not a problem.

#5 User is offline   RogueSpear 

  • OS: SimplyMEPIS
  • Group: Supreme Sponsor
  • Posts: 1,529
  • Joined: 18-September 04

Posted 16 December 2005 - 07:17 AM

By default all users are allowed to install up to ten (10) computers via RIS. At least in a 2000 domain.

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users



All trademarks mentioned on this page are the property of their respective owners
Copyright © 2001 - 2011 msfn.org
Privacy Policy