This is Vista Home Basic, btw, which probably doesn't make too much difference. I believe anything you can do with Group Policy you can do with the registry for individual accounts.
So far I've disabled Control Panel, the system tray and run command will be next, but I'm looking for suggestions and things I might miss. The aim is to lock down the machine as close to 100% as possible.
I considered replacing explorer.exe as the default shell but I'm not sure what I'd replace it with, exactly...
I will probably also remove all traverse/view contents permissions for the C: drive; hopefully this will be good enough to allow desktop shortcuts to run but not allow him to find new .exe files to mess around with
As for the internet I thought my best option was the filters provided by OpenDNS. I've tested it a bit; seems they caught most pr0n sites but you can always find a couple if you dig a little.
Anyone have any ideas?
So far I've disabled Control Panel, the system tray and run command will be next, but I'm looking for suggestions and things I might miss. The aim is to lock down the machine as close to 100% as possible.
I considered replacing explorer.exe as the default shell but I'm not sure what I'd replace it with, exactly...
I will probably also remove all traverse/view contents permissions for the C: drive; hopefully this will be good enough to allow desktop shortcuts to run but not allow him to find new .exe files to mess around with

As for the internet I thought my best option was the filters provided by OpenDNS. I've tested it a bit; seems they caught most pr0n sites but you can always find a couple if you dig a little.
Anyone have any ideas?