2、在组策略中的推荐设置:
1)Computer Configuration → Windows Settings → Security Settings → Local Policies → Security Options:
Devices: Restrict CD-ROM access to locally logged-on user only = Enabled
Devices: Restrict floppy access to locally logged-on user only = Enabled
Interactive logon: Do not display last user name = Enabled
2)Computer Configuration → Windows Settings → Security Settings → System Services:
Help and Support = Disabled
3)Computer Configuration → Administrative Templates → Windows Components → Terminal Services:
Restrict Terminal Services users to a single remote session = Enabled
Remove Disconnect option from Shut Down dialog box = Enabled
4)Computer Configuration → Administrative Templates → Windows Components → Terminal Services → Client/Server data redirection:
Do not allow drive redirection = Enabled
5)Computer Configuration → Administrative Templates → Windows Components → Terminal Services → Sessions:
Set time limit for disconnected sessions = Enabled
6)Computer Configuration → Administrative Templates → Windows Components → Windows Installer:
Disable Microsoft Windows Installer = Enabled – Always
7)Computer Configuration → Administrative Templates → System → Group Policy:
User Group Policy loopback processing mode = Enabled
8)User Configuration → Windows Settings → Folder Redirection: