Christine,
Glad to hear it went well. I didn't see any mention of performing Windows Updates though, so I hope you've done that or can get it done before anyone uses that PC on the Internet, since that's a core requirement for a secure system.
I understand why you've chosen to install the most popular browsers, since in an open environment like yours it's likely your users might do this if you hadn't, but you now understand the additional risk this creates and that keeping these maintained and
secure is an additional requirement and burden. It sounds like you've got enough people involved that this shouldn't be a problem though.
I note that you mentioned installing Office 2007, which if that's included on all machines will cause a significant issue for you later this year when it goes End of Life on October 10, 2017.
This Office 2007 End of Life roadmap - Office 365 article covers this extensively, but the basic issue will be the need to replace all of those copies at once, since this can get expensive and even the subscription model becomes expensive over time. As Carol
mentioned earlier, there are third-party options, but as I also discussed, this brings it's own support costs including separate maintenance and vulnerabilities, so there's a big decision to make.
What I'd try to determine first is whether these applications, likely just Word and possibly Excel are actually receiving much use to create new documents or are simply being used to display an occasional file received via email. If the latter is true,
you might look into the option I mentioned regarding the use of personal Microsoft Outlook.com email accounts for such occasional viewing, since that's completely free and requires no local maintenance whatsoever, as the applications are basically Office 365
operating through the email accounts.
If you truly need the Office apps installed locally, if it's only a handful of users which is likely, this may require only a few machines supporting these apps. I know that since I stopped working regularly, my own use of Office has dropped off drastically,
since most documents today are distributed in PDF or other publishing formats rather than the Office documents more commonly used in the business world.
As for the Hosts file, I realized something about that after having time to think about it since those earlier discussions. It's been so long since I'd used the earlier forms of these back in roughly 2001 to 2005 that I'd also forgotten why I'd dropped
using them at that point. The reason was that along with being a fairly static set of IP addresses needing separate maintenance and also causing performance issues for browsing at the time, their purpose was basically replaced by the SmartScreen Filter (now
Windows Defender SmartScreen in Win10).
What happened is that Microsoft saw the need initially for something to block phishing websites, so as this
IE7 - Introducing the Phishing Filter article discusses, this functionality was first added in 2007. As the threats evolved, Microsoft improved this and added Anti-Malware support, creating the
Internet Explorer 8 SmartScreen® Filter. In IE9 Microsoft added SmartScreen® Application Reputation and had begun using the more broad social-engineering attack terminology to describe the types of attacks which SmartScreen was helping to protect against.
As time has gone on, the integration between SmartScreen and both the Windows 8 & 10 operating systems, as well as Windows Defender has become much greater, allowing SmartScreen to better protect all applications that access the Internet and a cleaner interaction
between it and Defender to provide less confusing notifications for the PC user.
So all of these much more targeted protections within SmartScreen and Defender now more specifically detect and block the true threats from malicious websites, without needing to block entire IP addresses, since in some cases these may contain additional
domains that are otherwise innocent. SmartScreen's design allows it to block either individual domains pages or a specific URL path, so it has better granularity.
It also has a much larger database than can be maintained locally on a PC, so since any PC accessing the Internet can inherently reach the SmartScreen servers as well, this provides a continuously maintained and updated set of block lists. SmartScreen has
also always had a small subset of its list, obviously the more static items that don't change often similar to the hosts file entries, stored in a local cache on the PC. This means that not only does it provide basically the same protection as the hosts file,
but also a much more dynamic list of changes that any PC using it can access as needed, with no manual updating of any sort required.
I think from this you can see why though I originally dropped using the hosts file method due to performance issues caused by its having grown too large, I never returned to using it since its purpose is now functionally entirely gone. I only forgot about
this because I haven't taken the time to think about these hosts files in over a decade, but sorry for not thinking of it sooner.
Rob