Re: Local Admin Rights

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



On Oct 13, 6:44 am, PSULionRP <PSULio...@xxxxxxxxxxxxxxxxxxxxxxxxx>
wrote:
What is the general concensus on local admin rights to client machines?


My concensus is that you should add the (I assume domain user?) to the
local administrators group for the PC/Notebook they do their work on.
This is going to cause less problems than messing with registry keys.
A lot of old (and new) applications "out there" write to HKLM and
write DATA to the "Program Files" directory as a birthright during
their normal operation. They ignore all the rules. However, these apps
will keep working and your users can get back to work if their domain
account also is included in the local PC or notebook "Administrators"
group.

But, NO, new applications today should assume only user group rights!
It is bad pactice to grant any administrative privileges to users
"these days". Especially on Vista, which will enfore registry and file
virtualization and generally make a non-future proof mess of your
registry if you install "yesterdays applications" for ordinary users.
But that's a whole other story - the technology and security of
Vista / Server 2008 is excellent. MS did not explain it too well -
_that_ is the UAC problem - lack of documentation in 2006 - not bad
technology.

Be sure to take good daily backups of your servers and network shared
programs/data. Imaging the desktops and servers is somthing I do to be
sure.

CreateWindow

http://mymessagetaker.com
The while-you-were-out message taking program you have been looking
for!


.



Relevant Pages

  • Re: Domain User Privileges on Client Computer
    ... If they are not added to the local administrators group with a specified group or the account itself, ... Are the domain user accounts you are taking about addded there? ...
    (microsoft.public.windows.server.setup)
  • Add domain account to local administrators
    ... A Script that will add a logged in domain user to local administrators group ...
    (microsoft.public.scripting.vbscript)
  • Re: Admin accounts for Run As purposes only
    ... Administrators group of each server that needs to be managed. ... is this just as strong as a Domain Admin or is it more limited / ... > don't have enough servers to achieve a separation. ... >> I know we can delegate alot of tasks now such as user account ...
    (microsoft.public.windows.server.active_directory)
  • Re: User type
    ... This does help Mike - thanks ... > If the computer is member of domain then you should use domain user ... > After you have this account and group created you can write a short script ... > administrator and make your users local administrators. ...
    (microsoft.public.windows.server.setup)
  • Re: Delegation dilemma
    ... That will spread the security control over a group of people ... your SMS and MOM servers are going to be member servers. ... SMSAdmins in the local administrators group of the SMS Primary and Secondary ...
    (microsoft.public.windows.server.active_directory)