WinSecWiki
Windows Security Settings
Articles
WinSecWiki
»
Windows Security Settings
»
Local Policies
»
Security Options
»
Devices: Restrict CD-ROM access to locally logged-on user only
Devices: Restrict CD-ROM access to locally logged-on user only
Devices: Restrict CD-ROM access to locally logged-on user only
Like other “Devices:” settings this one has pretty narrow application and value. It’s designed to protect a user who mounts a CD-ROM containing sensitive information from having that information accessed by other users logged on to the computer from over the network. By default Windows does not share CD-ROMs anyway so it’s fairly unlikely this would happen anyway.
It is unclear whether this setting prevents Terminal Services users from access CD-ROMs when someone is logged on interactively.
Also interesting is the fact that should a user forget to remove the CD and logs off, network users will then be able to access the CD since no one is currently logged on locally (aka Interactive logon).
Enabling this setting can break certain applications. In particular it causes a problem for NTBackup and any other backup application that uses the Volume Shadow Copy service.
Bottom line
I recommend not enabling this policy because for most environments because of the low probability of risk and the problems it can cause.
Add Your Comments
Name:
*
Email Address:
Web Address:
Verification Code:
*
Details
Article not rated yet.
Article has been viewed 1,524 times.
Options
Bookmark Article
Social Bookmarks
Comments RSS
Upcoming Webinars
Additional Resources
Security Log Quick Reference Chart
Security Log Resource Kit
Learn about the SharePoint Audit Log
Patch Tuesday Analysis
Workstation Configuration Management
Home
>
Windows
>
WinSecWiki
User name:
Password:
/
Forgot?
Register
Home