|
Preventing the Logon Screensaver from Launching (Windows NT/2000/XP)
Windows has a default screen saver called login.scr, which runs even if no screen saver has been selected. This can present a security risk, as it can allow a local user to replace login.scr with another program and have it launched with system privileges.
Enable Shutdown from Authentication Dialog Box (Windows NT/2000/XP)
When this setting is enabled a [Shutdown] button is displayed in authentication dialog box when the system first starts. This allows you to shutdown a system without logging in. The button is shown by default on a workstation and removed on a server installation.
Force the Use of Automatic Logon (Windows 2000/XP) Popular
Normally when a Windows machine is configured to automatically logon to a specified account users can bypass this and enter alternate account information. This tweak forces the machine to auto logon and to ignore any bypass attempts.
Disable Password Caching (All Versions)
Normally Windows caches a copy of the users password on the local system to allow for additional automation, this leads to a possible security threat on some systems. Disabling caching means the users passwords are not cached locally. This setting also removes the second Windows password screen and also remove the possibility of networks passwords to get out of sync.
Require Alphanumeric Windows Password (All Versions)
Windows by default will accept anything as a password, including nothing. This setting controls whether Windows will require a alphanumeric password, i.e. a password made from a combination of alpha (A, B, C...) and numeric (1, 2 ,3 ...) characters.
Disable the Change Password Button (Windows NT/2000)
This setting disables the 'Change Password' button on the Windows Security dialog box. Enabling this setting stops casual users from being able to change the password.
Disable the Lock Workstation Button (Windows NT/2000/XP)
Add this setting to the registry to stop unauthorized users from locking machines from the Windows Security dialog box.
Disable the Auto Logon Shift Override Feature (Windows NT/2000/XP)
When using the automatic login feature it is possible for a user to hold the Shift key to bypass the login sequence and enter a username and password. This feature disables the ability to override the function.
Require Users to Press Ctrl+Alt+Delete Before Logon (Windows 2000/XP)
This setting controls whether users are required to press Ctrl + Alt + Delete as a security precaution before logging into the system.
Customize the Windows Logon and Security Dialog Title (Windows NT/2000/XP) Popular
This setting allows you to add addition text to the title of the standard Windows Logon and Windows Security dialog boxes.
Restrict Showing the Last Username (Windows 2000/XP)
This restriction removes the ability to view which user was last logged onto a computer by clearing the username box on the login screen.
Limit the Number of Automatic Logins (Windows NT/2000/XP)
This setting is used to limit the number of automatic logins, once the limit has been reached the auto logon feature will be disabled and the system will display the standard authentication box.
Modify the Number of Cached Logins (Windows NT/2000/XP)
This value controls the number of allowable cached login attempts when the network domain controller is unavailable.
Use Active Authentication for Unlock and Screen Saver (Windows NT/2000/XP)
This setting controls whether a full login should be performed when a workstation is unlocked or a password is used with the screen saver. Normally Windows will not check some settings such as whether the account has been locked out.
Legal Notice Dialog Box Before Logon (All Versions) Popular
Use these fields to create a dialog box that will be presented to any user before logging onto the system. This is useful where you are required by law to warn people that it is illegal to attempt to logon without being an authorized user.
Change the Message Shown on the Logon Box (Windows NT/2000/XP) Popular
You can personalize (or legalize) the message displayed on the logon box above the user name and password.
Automatic Logon without Name or Password (Windows 95/98/Me) Popular
This setting allows Windows clients to logon without entering a user name or password, therefore bypassing the logon box.
Allow Portables to Undock Before Logon (Windows XP)
This setting controls whether users with portable computers have the option to undock the system before they have logged onto the computer.
Automatic Logon to a Windows Machine (Windows NT/2000/XP) Popular
Windows includes a feature that allows you to configure the computer to automatically logon to the network, bypassing the Winlogon dialog box.
Start Windows Without Prompting for a Password (Windows 95/98/Me) Popular
Does Windows prompt you for a password every time you boot up even though you're the only one using the PC? Follow these instructions to make Windows automatically start up without prompting you for a password.
Force Users to Logon to Windows (Windows 95/98/Me) Popular
Usually users can simply press 'Cancel' at the Windows logon box to bypass the login process and gain access to the local computer. This tweak will logout the user if the authentication fails or the user clicks Cancel.
Specify a Minimum Password Length (All Versions)
You can force Windows to reject passwords that do not meet a minimum password length. Useful to help stop people from using trivial passwords where security is an issue.
|