Optimization Methods for Windows 7 (hereinafter referred to as Windows 7) are also emerging. Users often have no clue about how they work together. These methods are even more difficult to identify and how they work. In fact, using the system group policy function of Win7, we can achieve system optimization of Win7. This article explains how to use group policies to make Win7 safer.
Group Policy topic recommendation:Windows Group policy management tool in the hands of System Administrators
Note: The group policy function is only available in Win7 Professional Edition, Enterprise Edition, and Enterprise Edition.
Keep files confidential and put on your drive.
The drive mainly includes hard disks, optical drives, and mobile devices, and is mainly used to store data. Therefore, it is necessary to restrict the use of the drive to effectively prevent leakage of important and confidential information, and block the invasion of viruses and Trojans. Different drives have different limits, and the same drive has different levels of limits. There are two levels of hard disks: hiding and forbidding access. The hidden level is relatively Elementary, but the drive is invisible. It is generally used to prevent children and primary users. Access prohibited can completely block access to the drive. For mobile devices, you can set read, write, and execution permissions. However, viruses and Trojans are generally transmitted by executing malicious programs. Therefore, the most effective way is to disable execution permissions.
Basic defense is invisible to common users
There are some important files on the hard drive of the home computer, and the simplest way is to hide the drive where the file is located. Click Start and enter gpedit in the search box. msc. After confirmation, the Group Policy Editor is opened. Expand "user configuration> management template> Windows Components> Windows Resource Manager" in sequence. In the settings window on the right, go to "hide the specified drives in my computer", select "enabled", select the drive to be hidden from the drop-down list below, and then confirm. Go to "computer" and the drive icon you just selected will disappear.
Tip: This method only hides the drive icon. You can still use other methods to access the drive content, for example, directly type the directory path on the drive in the address bar. In addition, this setting does not prevent users from using programs to access these drives or their content.
Advanced protection for privileged users
The system disk contains important system files and cannot be modified or moved by others. In particular, when some partitions have important files, if you only hide the drive, others can still access it. Of course this is not the case! The safest way is to protect the drive and prohibit unauthorized access.
Similarly, in the Group Policy Manager, expand "user configuration> management template> Windows Components> Windows Resource Manager" to "prevent access to the drive from my computer ", select "enabled", and select the drive to be inaccessible from the drop-down list below. After confirming, the drive will take effect (1 ). When someone else wants to access the relevant drive, the "restriction" Prompt window will appear! When you need to view the information, you only need to change the related policy settings from "enabled" to "not configured.
Tip: how to prevent others from using group policy editing? It is easy to create users with different permissions, so that others can use normal User accounts (do not have the right to enable the Group Policy Editor.