Re: Local Logon To Domain Controller

Tech-Archive recommends: Speed Up your PC by fixing your registry

From: Lanwench [MVP - Exchange] (lanwench_at_heybuddy.donotsendme.unsolicitedmail.atyahoo.com)
Date: 03/08/04


Date: Mon, 8 Mar 2004 12:06:31 -0500

anonymous@discussions.microsoft.com wrote:
<snip>
>> Not quite as simple as that. I have guys in place who
> need admin rights on the client pc's, but I don't want
> them to be able to logon to the server. These guys are
> members of the "powerful groups though" and need to be.

Create a "LocalAdministrator" group in AD. Add it to all the local
workstation Administrators groups. Add the appropriate parties to the
"LocalAdministrator" group, and make sure they don't have any domain admin
rights, etc etc etc. Voila - local admin rights, no monkeying around
elsewhere.



Relevant Pages

  • Re: a way to set source for capinst.exe?
    ... for local admin rights and if the user has them it runs ccmsetup (with the ... images have the adv client installed already. ... when we setup a new PC is a tech with admin rights. ... > a logon script? ...
    (microsoft.public.sms.admin)
  • Re: Visual Studio 2005 Web Site <-> Visual Source Safe Problems...
    ... Local Admin rights are very bad! ... RISK of being infected by trojans and SpyWare. ... existing website" from source safe. ...
    (microsoft.public.vsnet.general)
  • Re: getting me ducks in a row - concepts
    ... Don't create local login accounts for users, ... > the user has local admin rights and you will want to tweak this using RegMon ... keys on the server? ...
    (microsoft.public.windows.server.sbs)
  • Re: Visual Studio 2005 Web Site <-> Visual Source Safe Problems...
    ... you log on locally with Admin rights because their browser is part of the o/s and has an ActiveX instantiation layer. ... Browsing to ANY internet site while logged in with local Admin rights puts you machine at HIGH RISK of being infected by trojans and SpyWare. ... Still, when switching between websites, it gets to be a bit of a pain to have to create a new website and then add from source safe every time we switch. ... I can't test this fully, because I only have one client machine left with IIS on it, we changed our main .NET 2.0 dev team over to using Cassini which has solved the complications of trying to manage local IIS servers and their security across multiple machines, but the built-in server does have some limitations - if you want to use ISAPI etc. ...
    (microsoft.public.vsnet.general)
  • Re: Does anyone truly use Restricted User Accounts?
    ... > workstations and network. ... > user to have local Admin rights. ... > Has anyone truly and successfully implelmented Restricted User Accounts on ...
    (microsoft.public.windows.server.sbs)