*Edit 9-3-08*
Ok, the guide is up...
It's wiki style, so if you see anything that is a mistake, or a typo - just fix it, or let me know and I can update it. I tried to make it so anyone (experienced or not) could follow along and do this.
Just a few quick things... this assumes:
- you have Vista Ultimate, it can't be done on Premium (if there is a way to do it please let me know & update the guide, but as far as I know you can't do it using this method).
- Vista is already installed
![Smile [:)]](/emoticons/emotion-1.gif)
It might seem kind of long, I was just trying to be thorough - and there are lots of screen shots. Please follow the directions carefully (unless you know what you're doing).
This is a new wiki style site - please feel free to add your own guides for anything Media Center related to this site.
http://www.mediacenterguides.com/shell_replacement
Link was updated to reflect new Media Center Guides site.
*end edit*
I have put together a group policy with the goal of making a Media Center machine as appliance like as possible. I'm pretty sure group policies can only be used with Vista Ultimate. I did this for a computer that is used by a lot of different people so I was trying to lock it down as much as possible while keeping Media Center fully functional.
How it works on my setup: I have a normal admin account on the computer, and made another account (as a standard user) called "Media Center". I then used "control userpasswords2" to set the computer to automattically log in to the "Media Center" account.
Summary of settings used:
- Replaces the standard shell ("explorer.exe") with "ehshell.exe"
- Disables all windows shortcuts (Windows Key + Btn)
- Disables access to control panel
- Disables taskbar notifications
- Disables autorun installations
- Disables screensaver during playback
- Disables active desktop
- Disables desktop icons
- Disables task manager
- Doesn't save settings on reboot
- Sets screen saver to 2 hours (you can change this if needed)
- Disables changing wallpaper
- Limits Recycle Bin to 2% of HD
- Other various security/stability enhancements (I don't remember them all)
I have been using this setup on one of my computers for about a week now and have been pretty happy with it so far. It was my first time really diving into group policies, so it's probably not perfect yet. I welcome any suggestions.
*back up anything important first - just in case*
*Edit 5-2-07* Well, like I said, this was my first time diving into the group policy - apparently you can't transfer a .msc file from one computer to another properly (at least for group policies). Sorry. I am not sure how to properly do templates for this, so I have been working on a step by step guide of how to implement this. It will be posted soon.
Just my $0.02.