Home
        3. DeviceLock Group Policy Manager
         Contents
1.    1997 2004 SmartLine Inc  All rights reserved  DeviceLock is a registered trademark of SmartLine Inc    5  Right click Software installation  point to New  and then click Package           gt Group Policy       Sg  CJ Window  qr  g8 SmartLine DeviceLock  Administrative Template  User Configuration  Software Settings  Windows Settings  H E Administrative Template                         6  In the Open dialog box  type the full Universal Naming Convention  UNC   path to the shared folder that contains the DeviceLock Service MSI package   For example    file server share DeviceLock Service msi     IMPORTANT  Do not browse to the location  Ensure that you use the UNC path  to the shared folder     7  Click Open     8  Click Assigned  and then click OK  The package is listed in the right pane of  the Group Policy window        Deploy Software    iS  Poblished   fe      e          Copyright   1997 2004 SmartLine Inc  All rights reserved  DeviceLock is a registered trademark of SmartLine Inc 9    9  Close the Group Policy snap in  click OK  and then quit the Active Directory  Users and Computers snap in  When the client computer starts  DeviceLock  Service is automatically installed     gf Group Policy     OF x     Action view     lt    gt   lm  amp  oB e   Name     Version   Deployment state       ne    Computer Configuration      Software Settings   iad Software installation   G Windows Settings   a    SmartLine DeviceLock   CI Administrative Templates  User Configuration     So
2.   Service distribution      and then press ENTER                         Up    DET        Bance Spy          5  Click Properties  and then click the Security tab     Copyright   1997 2004 SmartLine Inc  All rights reserved  DeviceLock is a registered trademark of SmartLine Inc    6  Click on the Deny check box next to Apply Group Policy for the security  groups that you want to prevent from having this policy applied  Click on the  Allow check box for the groups to which you want to apply this policy  When  you are finished  click OK     DeviceLock Service distribution Properties    General   Links Security          Name   m  P4RUSLAN NT4  SL2 P4RUSLAN NT 4     a P4RUSLAN W2K  SL2 P4RUSLAN W2K     m P4SUPPORT   SL2 P4SUPPORT      m P4SUPPORT_NT  SL2 P4SUPPORT_NT     m P4SUPPORT_W2K  S aaezan  b       di  lo  a       Remove         mm wre i sme rmi mi er er te eed    Permissions  Allow Deny       Full Control  Read    Create All Child Objects  Delete All Child Objects  Apply Group Policy M     L1  L1  Write oO  L1  L1    OoOoooo    Advanced            Cancel   Apply           Assign a Package    To assign DeviceLock Service to computers running Windows 2000 or later     1  Start the Active Directory Users and Computers snap in   2  In the console tree  right click your domain  and then click Properties     3  Click the Group Policy tab  select the group policy object that you want  and  then click Edit     4  Under Computer Configuration  expand Software Settings     Copyright
3.  steps     Create a Distribution Point  To install DeviceLock Service  you must create a distribution point on the server   1  Log on to the server computer as an administrator   2  Create a shared network folder in which to place the MSI package   3  Set permissions on the share to allow access to the distribution package   4  Copy the MSI package  DeviceLock Service msi  to the distribution point     Create a Group Policy Object  To create a Group Policy object  GPO  with which to distribute DeviceLock Service     1  Start the Active Directory Users and Computers snap in     2  In the console tree  right click your domain  and then click Properties          E Active Directory Users and Computers    lt  Console Window Help    Tree     sl2 com 5 objects    3 Active Directory Users and Computer  Name i y Type                                                            nem  FA Ruiltin builtinDomain  z Delegate Control    ters Container  Find    Controllers Organizational Unit  Connect to Domain    SecurityPrincipals Container  Connect to Domain Controller    Container  Operations Masters                   New  gt   All Tasks  gt        View  gt   New Window from Here    Refresh  Export List          Opens prope       Properties       Copyright   1997 2004 SmartLine Inc  All rights reserved  DeviceLock is a registered trademark of SmartLine Inc 6    3  Click the Group Policy tab  and then click New     4  Type the name that you want to call this policy  for example     DeviceLock
4. Corporation  Inso   a IP Security Monitor Microsoft Corporation   EJ IP Security Policy Management Microsoft Corporation   S  Link to Web Address Microsoft E    lt     ii  gt                  Description  Description  This snap in allows you to edit Group Policy Objects which can be linked  to a Site  Domain  or Organizational Unit in the Active Directory or stored  on 4 computer     Rem Ov       m    Copyright   1997 2004 SmartLine Inc  All rights reserved  DeviceLock is a registered trademark of SmartLine Inc       18    5  Select a Group Policy Object either from the Active Directory or a local  computer  and then click Finish     Select Group Policy Object    Welcome to the Group Policy Wizard a  eet    Group Policy Objects can be stored in the Active Directory    b  a or on a local computer            Use the Browse button to select a Group Policy Object     Group Policy Object   Remote computer  s  server2    i Browse             Allow the focus of the Group Policy Snap in to be  changed when launching from the command line  This  only applies if you save the console        6  Click Close to close the Add Standalone Snap in window     7  Click OK to add the snap in     Copyright   1997 2004 SmartLine Inc  All rights reserved  DeviceLock is a registered trademark of SmartLine Inc       19    8  Expand the Computer Configuration container  and then select SmartLine  DeviceLock     qm Group Policy    Console Root Local Computer Policy Compu    DEOX     in File Action View 
5. Favorites Window Help    m  ES  CI Console Root      Ey Local Computer Policy Floppy      e Computer Configuration Removable      9 Software Settings Hard disk        J Windows Settings Network drive     Administrative Templates    c SCD ROM  SmartLine DeviceLock  a d RAM disk      User Configuration   amp  F Serial port      j Infrared port   amp g IEEE 1394 port  Bluetooth   Y WiFi             There is no difference between the procedure for defining DeviceLock s permissions  and audit rules in DeviceLock Manager and in DeviceLock Group Policy Manager  Just  select a device type and set permissions and or audit rules for it as described in the  DeviceLock Manual pdf document     If you want to disallow changing permissions and audit rues for individual computers   without the GPO editor   select Override Local Policy from the Options context menu  It  enables the Group Policy mode for all the computers in GPO  such that the Local Policy  mode can t be enabled for these computers     NOTE  In order to change DeviceLock s permissions and settings via Group Policy   DeviceLock Service must be installed and started on all the computers belonging to the  GPO  For more information about service installation  please read the DeviceLock  Service Deployment section of this document     Also  don t forget that Group Policy is reapplied on a periodic basis  by default  every 90  minutes  so your changes do not take effect immediately  For more information  read the    Applying Group P
6. SmartLine Inc  All rights reserved  DeviceLock is a registered trademark of SmartLine Inc 13    Please keep in mind     Deployment occurs only when the computer starts up  not on a periodic basis  This  prevents undesirable results  such as uninstalling or upgrading an application that is  in use     DeviceLock Service will be copied to the Windows system directory  e g   c  winnt system32  if this service doesn t exist on the system  If the service exists on  this system but is too old  DeviceLock Service will be copied to the directory of the  old version and the old version will be replaced     If DeviceLock Service is installed on an NTFS partition  an installation routine  protects the service s file by allowing only members of the Administrators group or  the SYSTEM account to access this file     An installation routine also protects DeviceLock Service by allowing only members of  the Administrators group or the SYSTEM account to start  stop  or delete the  service     Copyright   1997 2004 SmartLine Inc  All rights reserved  DeviceLock is a registered trademark of SmartLine Inc 14       3  DeviceLock Group Policy Manager    You can use DeviceLock Group Policy Manager to control DeviceLock s permissions  and settings via Group Policy in an Active Directory domain  DeviceLock Group Policy    Manager integrates into the Group Policy Object  GPO  editor     To open DeviceLock Group Policy Manager     1  Start the Active Directory Users and Computers snap in     2  In the 
7. User Manual    DeviceLock   Management via Group Policy       SmartLine Inc    Copyright   1997 2004 SmartLine Inc  All rights reserved  DeviceLock is a registered trademark of SmartLine Inc 1    Contents    Using tnis Mahal      2  rato decd acmenancteussenoccsastumesseaseauenczesaeavsee 3  1  General Information                 roit nne 4  TAA  Overviews oria ipae rout tie ftt eheu rites 4  1 2 Applying Group Policy   doeet eet te exito ode mte 5  2  DeviceLock Service Deployment                                            6  3  DeviceLock Group Policy Manager                                      15    Copyright   1997 2004 SmartLine Inc  All rights reserved  DeviceLock is a registered trademark of SmartLine Inc 2    Using this Manual    This manual assumes you re familiar with basic functions like click  right click  and  double click  and that you re familiar with the basics of the operating system you re  using  This manual also assumes that you have basic network knowledge as well as the  ability to install a Local Area Network  LAN   We strongly recommend reading this  manual very carefully and thoroughly     This manual uses the following conventions     a Italics for file names  paths  buttons  menus  and menu items     a Bold Italics for notes and comments        Keyboard keys with a plus sign separating keys that you press simultaneously   For example  press Ctrl Alt Del to restart your computer     Copyright   1997 2004 SmartLine Inc  All rights reserved  DeviceLoc
8. atively  you can start MMC and add the Group Policy snap in manually     1  Run mmc from the command line or use the Run menu to execute this  command     2  Open the File menu  and then click Add Remove snap in     qm Console       Console Root       Action View Favorites Window Help       New Ctrl h  Open    Ctr O  Save Ctrl s  Save As    There are no items to show in this view     Add Remove Snap in    Ctrl M    Options                1 C  downloads Group Policy msc  2 CWINDOWSA     compmamt  mse  3 DeviceLock Management msc   4 DeviceLock Management msc       Exit  Adds or removes individual snap ins     3  Click the Standalone tab  and then click Add        Add Remove Snap in    Standalone   Extensions         Use this page to add or remove a standalone Snap in from the console        Snap ins added to   y Console Root v          Description    Remove About                Copyright   1997 2004 SmartLine Inc  All rights reserved  DeviceLock is a registered trademark of SmartLine Inc       17    4  Select Group Policy from the list  then click Add        im Console    Console Root     p  DoE Add Remove Snap in    Use this page to add or remo Hd C e T T STI TA    Shap ins added to  Available Standalone Snap ins   r Snap in Vendor           S Disk Defragmenter Microsoft Corp  Executive e   E Disk Management Microsoft and VERITAS Sc   dalJEvent Viewer Microsoft Corporation   J Folder Microsoft Corporation    Group Policy Microsoft Corporation       Indexing Service Microsoft 
9. computer or user belongs  By default  the system processes the GPOs in the  following order  local  site  domain  then organizational unit  Therefore  the computer  receives the policy settings of the last Active Directory container processed     When processing the GPO  the system checks the access control list  ACL  associated  with the GPO  If an access control entry  ACE  denies the computer access to the GPO   the system does not apply the policy settings specified by the GPO  If the ACE allows  access to the GPO  the system applies the policy settings specified by the GPO     Note that application deployment occurs only during startup  not on a periodic basis   This prevents undesirable results  such as uninstalling or upgrading an application that  is in use  However  DeviceLock s policy settings are applied periodically     Copyright   1997 2004 SmartLine Inc  All rights reserved  DeviceLock is a registered trademark of SmartLine Inc 5       2  DeviceLock Service Deployment    This step by step instruction describes how to use Group Policy to automatically  distribute DeviceLock Service to client computers  DeviceLock Service can be deployed  in an Active Directory domain using the Microsoft Software Installer  MSI  package   DeviceLock Service msi      NOTE  Microsoft Windows Group Policy automated program installation requires client  computers that are running Windows 2000 or later     You can use Group Policy to distribute DeviceLock Service by using the following
10. console tree  right click your domain  and then click Properties         amp  Active Directory Users and Computers           Tree                                                                             Opens prope      lt  Console Window Help    Active Directory Users and Computer              sl2 com 5 objects   Name sds ype  FR Ruiiltin  builtinDomain  Delegate Control    ters Container       Find    Controllers Organizational Unit    Connect to Domain    SecurityPrincipals Container  Connect to Domain Controller    Container    Operations Masters                 New  gt   All Tasks  gt             View  gt   New Window from Here    Refresh  Export List          Properties       Copyright   1997 2004 SmartLine Inc  All rights reserved  DeviceLock is a registered trademark of SmartLine Inc 15    3  Click the Group Policy tab  select the group policy object that you want  and  then click Edit  If you wish to create the new group policy object  click Add        ForeignSecurit   Users                     Up     DV          1  amp  Floppy  E A  Computer Configuration Removable  i B Software Settings  amp 3 Hard disk  Windows Settings E   Network drive  SmartLine D    i Administrative Templates  a 2 User Configuration    g Software Settings  E Windows Settings  H E Administrative Templates     amp  IEEE 1394 port    3 Bluetooth  Y wiri                   Copyright   1997 2004 SmartLine Inc  All rights reserved  DeviceLock is a registered trademark of SmartLine Inc 16    Altern
11. ftware Settings     Windows Settings    G Administrative Templates                                    Upgrade a Package    If the previous version of DeviceLock Service was already deployed and you want to  upgrade it to the new one     1  Start the Active Directory Users and Computers snap in   2  In the console tree  right click your domain  and then click Properties     3  Click the Group Policy tab  select the group policy object that contains the old  DeviceLock Service package  and then click Edit     4  Under Computer Configuration  expand Software Settings     5  Right click Software installation  point to New  and then click Package     Tree      New Group Policy Object  sl ser a E DeviceLock Service  old  5 62 Assigned    e Computer Configuration      Software Settings       E Windows Setting  a    SmartLine Devic  Administrative Te  User Configuration  E Software Setting  Export List      E Windows Setting                         Properties     Adds a package  Help    Copyright   1997 2004 SmartLine Inc  All rights reserved  DeviceLock is a registered trademark of SmartLine Inc 10       6  In the Open dialog box  type the full Universal Naming Convention  UNC   path to the shared folder that contains the new DeviceLock Service MSI  package  For example    file server share DeviceLock Service msi     7  Click Open     8  Click Assigned  and then click OK  The new package is listed in the right pane    of the Group Policy window        gE Group Policy    Administrati
12. k is a registered trademark of SmartLine Inc 3       1  General Information    1 1 Overview    In addition to the standard way of managing permissions via DeviceLock Manager   DeviceLock also provides you with a more powerful mechanism     permissions and  settings can be changed and deployed via Group Policy in an Active Directory domain     Group Policy enables policy based administration that uses Active Directory  Group  Policy uses directory services and security group membership to provide flexibility and  support extensive configuration information  Policy settings are created using the  Microsoft Management Console  MMC  snap in for Group Policy     System administrators can use system policies to control user and computer  configurations from a single location on a network  System policies propagate registry  settings to a large number of computers without requiring the administrator to have  detailed knowledge of the registry     Tighter integration into the Active Directory is a very important function of DeviceLock  It  makes DeviceLock   s permissions management and deployment easier for large  networks and more convenient for system administrators     Integration into the Active Directory eliminates the need to install more third party  applications for centralized management and deployment  DeviceLock does not need to  have its own server based version to control the entire network  instead it uses standard  functions provided by the Active Directory     Via Gr
13. olicy section     Copyright   1997 2004 SmartLine Inc  All rights reserved  DeviceLock is a registered trademark of SmartLine Inc 20    
14. oup Policy it is possible to      Install DeviceLock Service on all the computers in a network       Change DeviceLock   s settings on every computer     Control user access to devices and change permissions for an entire domain     Please note that to manage DeviceLock via Group Policy  you must have Active Directory  properly installed and configured  For more information about installing and configuring  Active Directory  please refer to the related Microsoft documentation     Copyright   1997 2004 SmartLine Inc  All rights reserved  DeviceLock is a registered trademark of SmartLine Inc 4    1 2 Applying Group Policy    Policy is applied when the computer starts up  When a user turns on the computer  the  system applies DeviceLock   s policy     Policy can be optionally reapplied on a periodic basis  By default  policy is reapplied  every 90 minutes  To set the interval at which policy will be reapplied  use the Group  Policy Object Editor  Policy can also be reapplied on demand     To refresh the current policy settings immediately on Windows XP and later   administrators can call the goupdate exe  force command line utility provided by  Microsoft  On Windows 2000  administrators can call another command line utility  provided by Microsoft  secedit  refreshpolicy machine_policy  enforce     When applying policy  the system queries the directory service for a list of Group Policy  Objects  GPOs  to process  Each GPO is linked to an Active Directory container in  which the 
15. package  and then click Edit     Expand the Software Settings container that contains the Software installation  item with which you deployed the package     Click the Software installation container that contains the package    In the right pane of the Group Policy window  right click the program  point to  All Tasks  and then click Redeploy application  The following message is  displayed   Redeploying this application will reinstall the application  everywhere it is already installed  Do you want to continue     Click Yes     Quit the Group Policy snap in  click OK  and then quit the Active Directory  Users and Computers snap in       Remove a Package    To remove DeviceLock Service     T     2     Start the Active Directory Users and Computers snap in   In the console tree  right click your domain  and then click Properties     Click the Group Policy tab  click the group policy object with which you  deployed the package  and then click Edit     Expand the Software Settings container that contains the Software installation  item with which you deployed the package     Click the Software installation container that contains the package     In the right pane of the Group Policy window  right click the program  Point to  All Tasks  and then click Remove     Click Immediately uninstall the software from users and computers  and then  click OK     Quit the Group Policy snap in  click OK  and then quit the Active Directory  Users and Computers snap in     Copyright   1997 2004 
16. ve Templates  User Configuration                      9  Right click the new package  click Properties  and then click the Upgrades  tab        DeviceLock Service Properties                 THETTIBVE     v Irure UDO ace  oT existing packages                      Copyright   1997 2004 SmartLine Inc  All rights reserved  DeviceLock is a registered trademark of SmartLine Inc    11    10  Click Add  select the old DeviceLock Service package you want to upgrade   click Uninstall the existing package  then install the upgrade package  and  then click OK        Add Upgrade Package    ol  2             11 Click OK to close the Properties window  close the Group Policy snap in  click  OK  and then quit the Active Directory Users and Computers snap in  When  the client computer starts  DeviceLock Service is automatically upgraded         amp f Group Policy    EH Computer Configuration     Software Settings    Windows Settings    Administrative Templal   User Configuration  Software Settings  Windows Settings    Metu                   Copyright   1997 2004 SmartLine Inc  All rights reserved  DeviceLock is a registered trademark of SmartLine Inc 12      Redeploy a Package    In some cases you may want to redeploy DeviceLock Service  To redeploy a  package     1     2     Start the Active Directory Users and Computers snap in   In the console tree  right click your domain  and then click Properties     Click the Group Policy tab  click the group policy object with which you  deployed the 
    
Download Pdf Manuals
 
 
    
Related Search
    
Related Contents
Samsung YH-925GS 用户手册  Oracle® Financial Services Analytical Applications Infrastructure  Powermate P024-0104SP User's Manual  Bedienungsanleitung  DYNACO M2  Mode d`emploi tensiomètre OMRON RS6    Copyright © All rights reserved. 
   Failed to retrieve file