Re: Local user privileges



Hi,

Angel Massa schrieb:
> When I looked at an user account both local and domain accounts where set as
> administrator for the local machine. I think this is not good as a user
> should not have administrator privileges ever his local machine.

This is not the default behavior.

If you look at the user object in AD, which security groups
is the user member of?

Lock in as administrator and remove the dom-user from the local
administrator group. Lock in as user, if he is admin again, then
there is something that takes efect on the default behavior.
In a GPO you can manipulate this via restricted groups.
You mus configure this manually to change the default behavior,
thats why I think, taht there is no entry.

Mark-
--
Mark Heitbrink - MVP Windows Server
Homepage: www.gruppenrichtlinien.de
W2K FAQ : http://w2k-faq.ebend.de
PM: Vorname@Homepage, Versende-Adresse wird nicht abgerufen.
.



Relevant Pages

  • Re: Spying in a corporate environment
    ... while being logged into the local machine instead of the domain ... domain policies are not re-applied. ... An administrator can now manually ... getting the settings re-applied by GPO the next time it runs ...
    (Security-Basics)
  • Re: Camera Plug and Play
    ... > I have a test computer thta works fine with the camera. ... On the Client:>> In the Computer Admin area, the user id is administrator. ... >> I just find it odd that when logged into the local machine it all works>> fine. ...
    (microsoft.public.backoffice.smallbiz)
  • RE: Local Accounts
    ... domain user accounts administrators on the local machine. ... This will give them admin rights on the local machine ... though I can do this for the Administrator account as well. ...
    (microsoft.public.windows.server.sbs)
  • Re: Password Protection - Locking Computer Windows 2000 Prof
    ... Administrator had the password ... then "Lock Computer" ... >> accounts, select your user account, and then click ... >> Administrators so I cant create a password. ...
    (microsoft.public.win2000.security)
  • Re: sbs installation and clients not opening encrypted files
    ... How do I log onto the local machine without getting on the sbs2003 domain? ... > Usually the local administrator is the EFS recovery Agent on local ... >> Administrator may not be sufficient. ... >> You have to logon as the original User who encrypted the ...
    (microsoft.public.windows.server.sbs)