Re: AD - permissions on the network



1) Change the local Administrator password to something difficult and never
use it
2) Use Group Policy Restricted Groups to add your IT Support guys to the
local Administrators group with their normal account
3) Do not give users Power User rights either. The IT Support guys should be
able to do most things remotely
4) Find out what the users think they need admin rights for, and work out
how to get round it
Anthony

"RC" <RichChristy@xxxxxxxxx> wrote in message
news:1157029565.309341.139120@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
is it possible to configure a script, gpo, or push something through
AD, ldap, that will remove all permissions from the local
administrators group of the machine and replace it with ones I want on
there.



Basically we do not allow users to have local admin rights for obvious
reasons. Instead we give them power users. "Somehow" I am seeing
more and more that either the domain users group or the actual user is
being applied to the local admin group of the computer.



Im sure it happens over there but some morons who work here have our
admin password and their way of solving permissions/problems is just
giving the users local admin rights! Frustrating!



.



Relevant Pages

  • RE: Impact of removing administrative rights in an enterprise running XP
    ... The most isseus are with installing applications. ... I tought that Microsoft and with them many other people almost ordered everybody to get rid of those admin rights. ... Onderwerp: RE: Impact of removing administrative rights in an enterprise running XP ... would likely require changes to the entire support model. ...
    (Focus-Microsoft)
  • RE: Removing Local Admin Rights...
    ... For those special cases where the user believes they need admin rights, ... > Subject: Removing Local Admin Rights... ... we are pushing to remove local administrator ... Attend a course taught by an expert instructor with years of in-the-field ...
    (Security-Basics)
  • Re: How do I prevent local administrator from logging on in safe mode
    ... You do have the option to set the local administrator password to encrypted in your sif file since Windows XP. ... forgotten value so that no one could log in in safe mode. ... Prior to XP it was not possible to disable the built-in account, ...
    (microsoft.public.windows.group_policy)
  • Re: Removing Local Admin Accounts - What do you think?
    ... people the necessary admin rights on the workstations, ... The local admin account poses a high risk in terms of workstations ... Does this pose a security risk to have a local administrator account on ... Is this a general best practice, from a security point of view? ...
    (Security-Basics)
  • RE: One of the "Unable to start debugging on the web server" issue
    ... What exectly you mean by "use a local Administrator to create and debug your ... and debug your web site, or use the File System mode instead of local IIS ... Microsoft Online Community Support ... where an initial response from the community or a Microsoft Support ...
    (microsoft.public.vsnet.debugging)