banner



How to Keep Your Employees Happy With Their Company PCs (Without Losing Control of Your IT) - daviescritaiment1967

How to Keep Your Employees Happy With Their Company PCs (Without Losing Control of Your IT)

If you're a typical small-business owner, you don't have a centralized provisioning system that can easy and mechanically deploy each desktop or laptop organisation. You might not flat give a dedicated employee, not to mention a whole department, to manage your Information technology resources. And you belik give each user their own local login, instead of using a concentrated authentication server. In new row, your employees have the keys to their topical computer kingdoms. And that means they can do near anything on their machines: Set up new applications, install undesirable applications, change settings, and perhaps symmetric accidentally unlawful the Registry Beaver State download malware.

Giving your employees the freedom to try inexperienced tools, listen to music while they bring up, or visit social media sites in their off time volition improve their morale and enhance their productivity. Only that flexibility can quickly run along to disaster if they steer up ruining their computers, bogging them down with garbage apps, or worse.

So how do you balance keeping your employees happy with maintaining control of your company's assets?

The Decision

One strategy is to traverse your employees all administrative control over their computers. Much a limitation would reduce the take a chanc of your computers existence waylaid past buggy apps and malware, because no one would be able to install anything. The drawback is that you–or your designee–would wealthy person to do totally of the instalmen for them. That ass equal a long serve, especially if you'Re deploying a newfangled application to your entire workforce–fifty-fifty if it's just a handful of employees. Past you have to consider periodic security patches, bug fixes, device driver updates, and upgrades. And Don River't forget the need to install drivers and software for new peripherals, such as printers and scanners.

Granting Administrator Access

How to Keep Your Employees Happy With Their Company PCs (Without Losing Control of Your IT)
Giving your employees admin check involves a tradeoff between master and convenience.

As an alternative of managing everything yourself, you can take a come of steps to bestow administrative rights to your employees without losing nail control over the computers you've provided.

Before you open upwards everyone's computer for unfettered use, ground a baseline software environment that will constitute standard for to each one staffer. Set a policy that allows employees to augment their computers with new applications but prohibits them from uninstalling or unhealthful the baseline programs–peculiarly the antivirus and antimalware tools, a secure Web web browser, an office rooms (unless you usance a cloud app, such as Google Docs), and whatever proprietary software your small business of necessity to function.

Then, use an application such A DriveImage XML (exempt for private use; a five-user commercial message license costs $100) to ringer the system drive on each class of information processing system you'll deploy. Your goal is to create an image of each type of desktop system in your office, from standard administrative machines to function-limited desktops (video-editing workstations, for instance). If disaster strikes or an employee renders their computer unusable, you can cursorily restore it to its underived configuration.

Practice DriveImage XML to make over a clone of each of your PC environments.

You should also establish policies and procedures that employees must follow to minimize the chances that they'll break up median business trading operations. For starters, establish a insurance that every employee must create a Windows user bill, additionally to their executive account, and that they must check in under that user business relationship at all times unless they're performing functions that call for administrator credentials. This policy will help oneself prevent scalawag applications from gaining privileged access to the operating system. You should also dictate that each employees hive away their work-related files on a joint network drive (located on a server or NAS box seat), and that they suppress personal files in their personal defile storage (Dropbox, SkyDrive, and the like). Inform them that the personal data will not be included in the mandatory scheduled backups.

The Office of Group Policy Editor

Local administrator privileges seem unbeatable, but there is a means past which you can exert fine control over the Windows operating system. The surreptitious is to utilisation Windows 7's Group Policy Editor. Log connected with the user's admin credentials, and type gpedit.msc in the Windows search boxful (you'll find it in the Start menu) and then press the Enter distinguish. From here, you canful invalid access to critical Windows elements exclusively–including the Panel–operating theater you can choose which components you wish to allow your employees to modify. For example, you power give them the ability to switch screensavers, but not to change printers or uninstall programs.

Don River't discount the power of the Group Policy Editor. If you'Ra the slightest bit hesitant active letting employees run wild on their systems, this handy Windows feature offers the apothecaries' ounce of keep in line you need to keep your systems running smoothly. You'll find entirely of the settings Charles Frederick Worth browsing and editing under Group Policy Editor's 'Administrative Templates' folder in the User Configuration bill of fare.

The Group Policy Editor in Windows 7 is a knock-down administrative tool.

You can also block access to specific programs installed on a Windows simple machine; just wide-eyed the Grouping Policy Editor and navigate to the Arrangement booklet low-level Administrative Templates in the Substance abuser Configuration place setting. Bivalent-click the Don't run specified Windows applications option, enable the policy, click the Show push button (it's near 'List of Disallowed Applications'), and then case in the names of workable application files (such as uTorrent.exe) atomic number 3 values.

You can use Group Policy Editor to block particularized programs from launching.

This method won't prevent industrious employees from renaming their favorite peer-to-equal programs to, say, "hatemyboss.exe" and spouting them, which is why you might want to combine your Aggroup Policy edits with some extra changes at the network hardware even out. You could, for example, go into the configuration panel of your primary router and change the firewall settings to block access to all ports for your employees' systems, save for those necessary for the computers to actually work–much as traffic on ports 110, 53, 25, and 80, to name a hardly a. This is a nuclear option to forbid employees from turning your small-business environment into downloading central, but it is worth considering if peer-to-peer misbehavior is an military issue at your work.

Finer Administrative Keep in line

How to Keep Your Employees Happy With Their Company PCs (Without Losing Control of Your IT)
AppLocker, a Windows 7 tool, delivers precision control.

If your systems are running either Windows 7 Ultimate operating theatre Windows 7 Enterprise, you can make use of the in operation system's built-in AppLocker feature. Accessible via the Group Policy Editor, AppLocker provides even better control ended the items that system users can scarper on their machines. For example, instead of just blocking apps by executable name, you give the sack go in and block apps by publisher, file way, or file hash. The file-path option is especially useful if you need to cylinder block altogether access to a digital download service–so much As Steam–that puts all downloaded programs into a specific directory.

Get along you require a third-party application to control your users' activity along their systems? Not rattling. However, if you discover that recalcitrant employees with administrator privileges are circumventing your Windows-based access controls, you might want to look for into stronger solutions. For example, if you establis Faronics' Deep Freeze ($35.50 per yr) on employee machines, the broadcast will touch on each system to an identical snapshot all time the PC restarts. Or you could provide staffers with a realistic desktop that would give them the freedom to install their personal programs in a sandboxed environment.

As long as you're willing to invest a bit of time scope up the right configurations, granting your employees administrator privileges on their half-size-business PCs won't necessarily lead to chaos. You tin can even control admins without devising your employees feel as though they'atomic number 75 working under parental controls from nine to five.

Source: https://www.pcworld.com/article/465244/how_to_keep_your_employees_happy_with_their_company_pcs_without_losing_control_of_your_it_.html

Posted by: daviescritaiment1967.blogspot.com

0 Response to "How to Keep Your Employees Happy With Their Company PCs (Without Losing Control of Your IT) - daviescritaiment1967"

Post a Comment

Iklan Atas Artikel

Iklan Tengah Artikel 1

Iklan Tengah Artikel 2

Iklan Bawah Artikel