Windows7 new system protection features

  

In Windows 7 M3 Build 7*** we can see a new feature - PC Safeguard, a new PC protection feature. With PC Sageguard, we can create a Sandbox users in the system. When Sandbox users log in to the system, they are actually in a read-only environment. All operations, such as delete, write, and modify, will be in the system. The account disappears after being logged out.

PC Safeguard is designed for use in a multi-person computer environment, such as computer classrooms, libraries, corporate public areas, and more. Suppose we may encounter a situation where we have to let someone else use our personal computer, or when a child at home needs to use a computer. In these scenarios, we know what happens after the computer is used publicly!!

Below, we use PC Safeguard to solve our worries. First go to "User Accounts and Family Safety" through the control panel and navigate to "Change an Account", click "Set up PC Safeguard". (Figure 1)



Select "Turn on PC Safeguard" to enable this feature on the "Set Up PC Safeguard" configuration page. In addition, you can click on "Local Hard disk drives (advanced)" for advanced configuration of local disks. (Figure 2)



"Local Disk Drives" Configuration page We configure which disks to lock. When the disk is set to release, the user can modify the disk. In order to make screenshots in subsequent tests, I configured (D:) to unlock the state. (Figures 3, 4)





When I log in to the system using Sandbox users, a warning pops up automatically Prompt to tell that data made in the current environment should be saved to other storage. (Figure 5)



In order to test the specific capabilities of PC Safeguard, I performed in-depth testing. When we want to perform some modifications to the system itself, a UAC prompt will pop up, let me enter the administrator password for the authorization operation. The actions performed after the authorization is recorded are stored and stored. This feature is very flexible when used in the PC Safeguard environment. (Figure 6)



PC Safeguard is similar to the previous Windows SteadyState (early name: Shared Computer Toolkit), but it is easier to use, and the system is also Closer and more user-friendly.

Performed the relevant test operations in the PC Safeguard environment and found that when deleting the system's own files, the system mentioned above mentioned the lifting operation, type the prompt "quotan" in the above figure After the password of the account, the file is successfully deleted, and then use the "sufan" account to log in and find that the deleted file appears in the recycle bin under the account. Very interesting!

In addition, I found a more interesting question! I mentioned before that in the PC Safeguard environment, the operations done by Sandbox users will not be saved (except for the escalation operation), but Only the information in the recycle bin under Sandbox uers will be saved. In other words, let's say we created a folder on the desktop and created a file in it. By default, the directory and files will be cleaned up after we log out. But when we delete the directory, the directory will be placed in the recycle bin. After we log out and log back in, we will find that the directory and the files still exist. We only need to restore the directory to retrieve the previous files.

Whether the emergence of this problem belongs to the Bug remains to be verified. Interested friends can do further testing. Finally, you need to be reminded that PC Safeguard only supports standard users, and PC Safeguard cannot be enabled if the user belongs to the administrator group.

Copyright © Windows knowledge All Rights Reserved