Windows registry security suggestions Whenever I bring up registry security, the inevitable query is generally how to prevent customers from accessing the registry. You can't. Keep in mind that the registry contains settings that the user should be able to read for Windows to perform adequately.
Customers also should have complete manage of their profile hives for the operating program and applications to save their preferences. You can not stop access-nor do you desire to prevent it. The ideal you ought to hope for is limiting users' capacity to edit the registry employing Regedit or other registry editors.Probably the most elegant way to avert access to Regedit is by enabling the Prevent access to registry editing tools policy. When customers start Regedit, all they see is an error message that says "Registry editing has been disabled by your administrator." The problem with this policy is that not all registry editors honor this policy.
As an example, in Active Directory, you might develop an administrators group for each organizational unit and choose to give it the capacity to edit computers' registries if they belong to the organizational unit. To enable that group to remotely edit a computer's registry, add that group towards the ACL of your crucial HKLM\SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg. The problem you're going to run into is that although adding a group to winreg will allow remote access, every key's ACL nonetheless determines which keys the group can change. So to let a remote user or group to alter a setting on the laptop, add that user or group to the nearby Customers, Power Users, or Administrators group.
Due to the fact the Domain Admins group is a member of each computer's nearby Administrators group, all domain windows 7 anytime upgrade home premium to professional administrators can connect the registry of any personal computer that is joined for the domain. Also, Windows now limits remote access for the registry more than earlier versions of Windows.There might be limited scenarios in which you would like to open remote access to computers' registries