Re: Local Admin Rights -> but no right to change the System Time?

From: Steven L Umbach (n9rou_at_no-spam.ameritech.net)
Date: 03/25/04


Date: Wed, 24 Mar 2004 22:05:42 -0600

It is difficult to impossible to restict a local administrator who knows the
power of the acount. The setting you are configuring is a machine policy, so
be sure that the computer is in the scope of influence of the GPO and look
at effective settings in the Local Security Policy to see if the policy is
being propagated to be what you expect. --- Steve

"Reinhard Mader" <edv-guru@no-spam-gmx.at> wrote in message
news:eCF08FeEEHA.2408@TK2MSFTNGP10.phx.gbl...
> Is this possible?
>
> I addes in my domain a user to the Local Administrator Group; because
there
> is some software running that needs administrator rights. But it should
not
> be possible for the User to change the System Time.
>
> In the Default Domain Policy i gave the Rights for Changing System Time
only
> Domain Admins. But the User(s) can still change the System time (because
> they're in the Local Admin Group).
>
> Is there a reason for my Problem?
>
> Many Thanks for Help
>
> Reinhard
>
>



Relevant Pages

  • Re: Remove Administrator Account from Administrators Group
    ... "Mathieu CHATEAU" wrote in message ... that there might be a policy for it somewhere. ... Our security officer would like us to either remove the local Administrator account from the group policy, or push it down under a different name. ...
    (microsoft.public.windows.group_policy)
  • Re: Remove Administrator Account from Administrators Group
    ... As for the LAN man hash, is this the policy that you are referring to: ... Currently, the local Administrator ... the local Administrator account from the group policy, or push it down ... would not see the local Administrator account listed as a member, ...
    (microsoft.public.windows.group_policy)
  • Re: Remove Administrator Account from Administrators Group
    ... that there might be a policy for it somewhere. ... "Mathieu CHATEAU" wrote in message ... Our security officer would like us to either remove the local Administrator account from the group policy, or push it down under a different name. ...
    (microsoft.public.windows.group_policy)
  • Re: Software Restriction Hash
    ... Since it is a machine policy, ... Of course restricting any local administrator is extremely difficult as ... > The hash was created, in this case AOL V9, in the machine GP policy. ... > The path rule could be used, and I have not tried that yet. ...
    (microsoft.public.win2000.security)
  • Re: >>Cant run gpedit.msc from user account<<
    ... control panel inaccessible, things of that nature. ... can't run gpedit.msc nor group policy within the mmc. ... >User Right Assignments / Change System Time. ... >> specify the accounts that I want restricted? ...
    (microsoft.public.win2000.general)