Answer the question
In order to leave comments, you need to log in
Peer-to-peer control?
Hello, I'm a beginner admin, please tell me how to control the operation of a peer-to-peer network on windows, there is a park of 50 computers and all switches are connected to one router, tell me the program or methods of various restrictions for users (prohibition of program installations, access to the Internet, etc.) preferably some kind of software product , you can of course apply group policies, but it’s a chore for me to do it and run, I want a program on my computer that controls everything, such as a gateway or something ....
PS windows server is excluded because they don’t plan to buy yet ...
Answer the question
In order to leave comments, you need to log in
It won't work the way you want. In any case, you will need to tie the infrastructure with servers in order to control it.
Also, the cases you described are not related to network control, they are closer to user control.
The simplest thing is to deploy Ldap and use group policies to distribute rights to users.
Moreover, all users are on Windows.
To access the Internet - proxy. To control network connectivity, you can throw in poppy filters if your switches are managed. To control the installation and actions of users, I don’t know honestly free solutions, but it’s very easy to google, here’s a list for an example.
https://info-comp.ru/top-5-programs-for-employee-m...
In a peer-to-peer network - most of the Wishlist is unrealizable.
Tyrnet access is usually controlled by a proxy and port blocking on the router.
If you do not want AD, then do not expect easy ways. AD is the easy way out.
First you need on all computers in the network:
1. Get one user (with the same password) with administrator rights. On computers of administrators the same it is necessary to get the same user.
2. Set up remote access via RDP on all computers, at least for the administrator
3. Give clear names to computers so that you can easily identify the problem computer by the name / surname of the employee (phone number or something else). You can display the IP address and other information as a wallpaper, there is an appropriate software for this.
4. Enable "access to files and printers"
5. Remove administrator rights from users
6. Starting from Windows Vista and beyond, you need to turn off UAC to run programs remotely. This is done by editing the registry:
reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v LocalAccountTokenFilterPolicy /t REG_DWORD /d 1 /f
0) it will be hard without AD
1) take away the rights
2) If there is no AD and will not be - automate by other means, ala ManageEngine DesktopCentral
at first I did this
1. I took away the rights on all machines, left only the necessary set of programs, the rest was already coordinated separately
2. I installed TightVNC for everyone - there was a problem - I wrote to the cart - I gave ip (it will be displayed in the user's tray) - you connected with admin rights and did everything
3. If there are no servers at all - but you need a general file washer - any old beech will do - you deploy freenas on it
4. On networks, if there is no control, you most likely have a router, most likely mikrotik - there you can cut speed by poppy addresses (IpScanner will help to compile their table)
In a peer-to-peer network - run around computers and configure.
You can run with your feet, or you can connect remotely or even use software like Ansible.
If there is a simpler domain there, all settings are made in one place, no third-party software is needed.
I want to have a program on my computer that controls everythingAh, I saw this one.
windows server is excluded because they do not plan purchases yet ...Correctly!
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question