Disable Fast User Switching on domain clients
This commit is contained in:
@@ -36,6 +36,10 @@ contrario, el contenedor de equipos configurado en AD. Los parámetros
|
|||||||
explícitamente. Para otra cuenta, editar el usuario sugerido como
|
explícitamente. Para otra cuenta, editar el usuario sugerido como
|
||||||
`DOMINIO\usuario` o `usuario@dominio`. No se guardan contraseñas.
|
`DOMINIO\usuario` o `usuario@dominio`. No se guardan contraseñas.
|
||||||
|
|
||||||
|
El enrolamiento también oculta las entradas de Cambio rápido de usuario mediante
|
||||||
|
una política de equipo. Docentes, administrativos y alumnos conservan la opción
|
||||||
|
de cerrar sesión, pero no pueden dejar una sesión abierta para cambiar a otra.
|
||||||
|
|
||||||
Si la IPv4 proporcionada es pública, el mismo flujo configura automáticamente
|
Si la IPv4 proporcionada es pública, el mismo flujo configura automáticamente
|
||||||
la conectividad directa. Después de autenticar WinRM, el servidor crea o reutiliza
|
la conectividad directa. Después de autenticar WinRM, el servidor crea o reutiliza
|
||||||
un certificado DoH, publica DNS cifrado en TCP 443 y devuelve únicamente su
|
un certificado DoH, publica DNS cifrado en TCP 443 y devuelve únicamente su
|
||||||
|
|||||||
@@ -314,6 +314,11 @@ if ($PSCmdlet.ShouldProcess($installPath, 'Install and register the SGU Credenti
|
|||||||
-Value 1 `
|
-Value 1 `
|
||||||
-PropertyType DWord `
|
-PropertyType DWord `
|
||||||
-Force | Out-Null
|
-Force | Out-Null
|
||||||
|
New-ItemProperty -Path $interactiveLogonPolicyPath `
|
||||||
|
-Name HideFastUserSwitching `
|
||||||
|
-Value 1 `
|
||||||
|
-PropertyType DWord `
|
||||||
|
-Force | Out-Null
|
||||||
if (-not (Test-Path -LiteralPath $defaultProviderPolicyPath)) {
|
if (-not (Test-Path -LiteralPath $defaultProviderPolicyPath)) {
|
||||||
New-Item -Path $defaultProviderPolicyPath -Force | Out-Null
|
New-Item -Path $defaultProviderPolicyPath -Force | Out-Null
|
||||||
}
|
}
|
||||||
@@ -344,6 +349,9 @@ catch {
|
|||||||
LastSignedInUserHidden = (Get-ItemPropertyValue `
|
LastSignedInUserHidden = (Get-ItemPropertyValue `
|
||||||
-LiteralPath $interactiveLogonPolicyPath `
|
-LiteralPath $interactiveLogonPolicyPath `
|
||||||
-Name DontDisplayLastUserName) -eq 1
|
-Name DontDisplayLastUserName) -eq 1
|
||||||
|
FastUserSwitchingHidden = (Get-ItemPropertyValue `
|
||||||
|
-LiteralPath $interactiveLogonPolicyPath `
|
||||||
|
-Name HideFastUserSwitching) -eq 1
|
||||||
LocalUserEnumerationDisabled = (Get-ItemPropertyValue `
|
LocalUserEnumerationDisabled = (Get-ItemPropertyValue `
|
||||||
-LiteralPath $defaultProviderPolicyPath `
|
-LiteralPath $defaultProviderPolicyPath `
|
||||||
-Name EnumerateLocalUsers) -eq 0
|
-Name EnumerateLocalUsers) -eq 0
|
||||||
|
|||||||
@@ -99,6 +99,7 @@ $policies = @(
|
|||||||
@{ Key = $credentialProviderPolicyKey; Name = 'DefaultCredentialProvider'; Type = 'String'; Value = $providerClassId },
|
@{ Key = $credentialProviderPolicyKey; Name = 'DefaultCredentialProvider'; Type = 'String'; Value = $providerClassId },
|
||||||
@{ Key = $credentialProviderPolicyKey; Name = 'EnumerateLocalUsers'; Type = 'DWord'; Value = 0 },
|
@{ Key = $credentialProviderPolicyKey; Name = 'EnumerateLocalUsers'; Type = 'DWord'; Value = 0 },
|
||||||
@{ Key = $interactiveLogonPolicyKey; Name = 'DontDisplayLastUserName'; Type = 'DWord'; Value = 1 },
|
@{ Key = $interactiveLogonPolicyKey; Name = 'DontDisplayLastUserName'; Type = 'DWord'; Value = 1 },
|
||||||
|
@{ Key = $interactiveLogonPolicyKey; Name = 'HideFastUserSwitching'; Type = 'DWord'; Value = 1 },
|
||||||
|
|
||||||
# Use Windows' native default account image for named user tiles. LogonUI
|
# Use Windows' native default account image for named user tiles. LogonUI
|
||||||
# retains ownership of the anonymous Other user tile and its circular mask.
|
# retains ownership of the anonymous Other user tile and its circular mask.
|
||||||
|
|||||||
@@ -92,6 +92,20 @@ if (-not $lastSignedInUserHidden) {
|
|||||||
$issues.Add('The last signed-in user is not hidden from LogonUI.')
|
$issues.Add('The last signed-in user is not hidden from LogonUI.')
|
||||||
}
|
}
|
||||||
|
|
||||||
|
$fastUserSwitchingHidden = $false
|
||||||
|
try {
|
||||||
|
$fastUserSwitchingHidden = (Get-ItemPropertyValue `
|
||||||
|
-LiteralPath $interactiveLogonPolicyPath `
|
||||||
|
-Name HideFastUserSwitching `
|
||||||
|
-ErrorAction Stop) -eq 1
|
||||||
|
}
|
||||||
|
catch {
|
||||||
|
# Report the missing or unreadable policy as a failed enrollment check.
|
||||||
|
}
|
||||||
|
if (-not $fastUserSwitchingHidden) {
|
||||||
|
$issues.Add('Fast User Switching entry points are not hidden.')
|
||||||
|
}
|
||||||
|
|
||||||
$localUserEnumerationDisabled = $false
|
$localUserEnumerationDisabled = $false
|
||||||
try {
|
try {
|
||||||
$localUserEnumerationDisabled = (Get-ItemPropertyValue `
|
$localUserEnumerationDisabled = (Get-ItemPropertyValue `
|
||||||
@@ -279,6 +293,7 @@ $result = [pscustomobject]@{
|
|||||||
ProviderBinaryPresent = [bool]$providerBinaryPresent
|
ProviderBinaryPresent = [bool]$providerBinaryPresent
|
||||||
DefaultProviderConfigured = $defaultProviderConfigured
|
DefaultProviderConfigured = $defaultProviderConfigured
|
||||||
LastSignedInUserHidden = $lastSignedInUserHidden
|
LastSignedInUserHidden = $lastSignedInUserHidden
|
||||||
|
FastUserSwitchingHidden = $fastUserSwitchingHidden
|
||||||
LocalUserEnumerationDisabled = $localUserEnumerationDisabled
|
LocalUserEnumerationDisabled = $localUserEnumerationDisabled
|
||||||
PasswordProviderPreserved = $passwordProviderPreserved
|
PasswordProviderPreserved = $passwordProviderPreserved
|
||||||
StandardLocalUserPresent = $standardLocalUserPresent
|
StandardLocalUserPresent = $standardLocalUserPresent
|
||||||
|
|||||||
@@ -4,6 +4,8 @@ $enrollmentTestScriptPath = Join-Path $repositoryRoot 'scripts\Test-SguClientEnr
|
|||||||
$packageScriptPath = Join-Path $repositoryRoot 'scripts\New-SguBootstrapPackages.ps1'
|
$packageScriptPath = Join-Path $repositoryRoot 'scripts\New-SguBootstrapPackages.ps1'
|
||||||
$releaseScriptPath = Join-Path $repositoryRoot 'scripts\Publish-GiteaRelease.ps1'
|
$releaseScriptPath = Join-Path $repositoryRoot 'scripts\Publish-GiteaRelease.ps1'
|
||||||
$azureLauncherPath = Join-Path $repositoryRoot 'scripts\Start-SguAzureClientEnrollment.cmd'
|
$azureLauncherPath = Join-Path $repositoryRoot 'scripts\Start-SguAzureClientEnrollment.cmd'
|
||||||
|
$credentialProviderInstallerPath = Join-Path $repositoryRoot 'scripts\Install-CredentialProvider.ps1'
|
||||||
|
$computerPolicyScriptPath = Join-Path $repositoryRoot 'scripts\Set-SguDomainComputerPolicies.ps1'
|
||||||
|
|
||||||
$tokens = $null
|
$tokens = $null
|
||||||
$parseErrors = $null
|
$parseErrors = $null
|
||||||
@@ -72,4 +74,13 @@ Describe 'SGU Windows client enrollment scripts' {
|
|||||||
Should Be $true
|
Should Be $true
|
||||||
$azureLauncher | Should Match '-PauseOnError'
|
$azureLauncher | Should Match '-PauseOnError'
|
||||||
}
|
}
|
||||||
|
|
||||||
|
It 'hides Fast User Switching during enrollment and through computer policy' {
|
||||||
|
(Get-Content -LiteralPath $credentialProviderInstallerPath -Raw) |
|
||||||
|
Should Match 'HideFastUserSwitching'
|
||||||
|
(Get-Content -LiteralPath $enrollmentTestScriptPath -Raw) |
|
||||||
|
Should Match 'FastUserSwitchingHidden'
|
||||||
|
(Get-Content -LiteralPath $computerPolicyScriptPath -Raw) |
|
||||||
|
Should Match "Name = 'HideFastUserSwitching'; Type = 'DWord'; Value = 1"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user