4 ms·
I don't know what the best practice for doing this would be but I would change the default shell from explorer to mstsc (the terminal services/remote desktop cl
by Avery3R 6y ago
I don't know what the best practice for doing this would be but I would change the default shell from explorer to mstsc (the terminal services/remote desktop client) and disable task manager and internet explorer. I don't think that would perfectly lock it down, but it would do the job for ~90% of use cases.
- geofft 6y agoRight, the goal is not to prevent a malicious user from running things, it's to make a usable environment for non-malicious users (via giving them Remote Desktop) so they don't feel the need to install anything that someone else could later attack.