We build logging in to the domain into our basic image so we don't apply an edit for it, but here is the edit.

********************************
REGEDIT4

[HKEY_LOCAL_MACHINE\Network\Logon]
"MustBeValidated"=dword:00000001
"NoDomainPwdCaching"=dword:00000001
*************************************

If a domain controller is not available, the lock down will not work. Thus if a student pulls out the LAN cable they can still get to the desktop by hitting "ESC". We get around this by applying very tight restrictions that are applied through the autoxec.bat file. Thus they need to logon to open the system up. You should also note we color code our desktops so we can spot students doing this type of activity. You should also note there is a some write ups in Technet about the 2 above edits conflicting & being unstable when used in combination if you don't have all the lates "DLLs". We don't have a problem but you might.

As to the MSDOS file you need to disable the bootup menu & the function keys during bootup. If you also disable booting from a floppy in the BIOS, it is very hard for a student to break in during bootup. Go to the NONAGS site to get a freeware package to edit the MSDOS.SYS file.

As a point of interest, Windows 95 ships with all security disabled while NT ships with most security enabled. When you enable all of Windows 95 security options, the difference between Windows 95 & NT security is not significant in the context of a school environment.

Hope you find that helpful.

Jack Lothian
for Hadley Junior High School,
Hull, Québec, Canada

_________________________
Jack