
GFI EndPointSecurity 2 Installing GFI EndPointSecurity | 30
Note
If the deployment of the agent on to the local computer is not up-to-date, then
manually deploy the agent on to it. For more information, refer to the GFI -
Administration and Configuration Manual.
Ensure that the user account with no administrative privileges is not set as a power user in the
General Control protection policy (shipping default protection policy).
Note
If the user account is set as a power user, then manually remove it from the power
users group of the General Control protection policy (shipping default protection policy).
For more information, refer to the GFI EndPointSecurityAdministration and
Configuration Manual.
2.6.2 Test case
Accessing a CD/DVD disc
Upon compliance with the previously outlined test pre-conditions, non-administrative users are no
longer allowed access to any devices or ports connected to the local computer.
To verify that both the device and media are inaccessible to the non-administrative user:
1. Log in to the local computer as the user with no administrative privileges.
2. Insert the CD/DVD disc in the CD/DVD drive.
3. From Windows Explorer locate the CD/DVD drive and confirm that you are unable to view and
open the contents stored on the CD/DVD disc.
Assign permissions to user with no administrative privileges
To assign CD/DVD device access permissions to the user with no administrative privileges:
1. Log in to the local computer as the user with administrative privileges.
2. Launch GFI EndPointSecurity.
3. Click on the Configuration tab.
4. Click on the Protection Policies sub-tab.
5. From the left pane, select the General Control protection policy.
6. Click on the Security sub-node.
7. From the left pane, click the Add permission(s)… hyperlink in the Common tasks section.
Komentáře k této Příručce