Re: Limit access to Active Directory Users and Computers
- From: APD189 <APD189@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Tue, 16 Dec 2008 07:16:04 -0800
Does anyone know how to limit the users access who have downloaded the Admin
Pack. We would like only to allow certian users and other users not to have
access.
"APD189" wrote:
They downloaded the Admin Pack onto their own computer and installed the.
admin pack on their local machine. I need to block what they see in it.
Thanks!!
"Florian Frommherz [MVP]" wrote:
Howdie!
APD189 wrote:
What I need to do is restrict users from using the Admin Pack and using
Active Directory Users and Computers. When I disabled a single user, he was
not able to remote to a server he had access to in the past. I think when I
denied "read" permissions, he was not able to log in because when I removed
his name, he was able to log back in.
How do they access those tools? Are they installed locally on the users'
machines or do they use an rdp (termanial services) connection to the DC
and make their changes there? From your description it sounds like that.
Disabling the user in ADUC is not a way to go as that "disable"
mechanism blocks his user account he needs to authenticate to the whole
network. How do they access the AdminPak? Can't you just tweak NTFS
permissions on the .msc files?
cheers,
Florian
--
Microsoft MVP - Group Policy
eMail: prename [at] frickelsoft [dot] net.
blog: http://www.frickelsoft.net/blog.
Maillist (german): http://frickelsoft.net/cms/index.php?page=mailingliste
- Follow-Ups:
- Re: Limit access to Active Directory Users and Computers
- From: Paul Bergson
- Re: Limit access to Active Directory Users and Computers
- From: Jorge de Almeida Pinto [MVP - DS]
- Re: Limit access to Active Directory Users and Computers
- Prev by Date: Remove programs
- Next by Date: Re: Looking for detailed GPO refresh process details
- Previous by thread: Remove programs
- Next by thread: Re: Limit access to Active Directory Users and Computers
- Index(es):
Relevant Pages
|
Loading