Re: Must loosen security screws for vendor



I can't help you with your question though I can certainly empathize with
you! It's quite ridiculous for apps to require that users have local admin
rights but requiring that they be able to logon on to the server is
bordering on stupidity.

My question for you: How are you able to restrict users to ONLY logon to
their own workstations? I've been wanting to do that for some time but my
research has not borne fruit.

John

"Roger" <Roger@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:FF61EFDE-2B4A-45FE-9A26-66CA1D6A416F@xxxxxxxxxxxxxxxx
> I've had it with application developers creating half assed software!!!
> Sorry... just a little venting.
>
> So here's what's happening. I'm running SBS2K3 Prem. with ISA 2K4
> configured. I've restricted the users so they can ONLY logon to their own
> workstations thru the properties of their user profile. And also, no user
> can
> log onto the server directly (except the admin account)
>
> In walks Mr. New Server Application. Turns out, in order for us to use it,
> the users must have the ability to logon to the server. So, in my mind,
> these
> guys are waltzing into my shop, telling me to relax my security, just so I
> can have the privilage to do business with them.
>
> Maybe I'm a little possesive... bitter maybe... paranoid - definately!
>
> Should I make the change and not worry about it?
> How can I safely allow users to logon to the server?
> Can I give them access to it, then take away all of their rights?
> How am I gonna do this?
>
> TIA
> -R.


.



Relevant Pages

  • Re: Permissions issue with users in Domain Users not able to see p
    ... A user always has to have local logon rights on a computer, ... is delete the user profile on the computer when logged ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: IIS 5 Authentication problem- solved
    ... In Local Security Policies/User Rights Assignment I had ... Can you log in using an administrator account, ... >> case there is no group, it is just the one server, ... >> interactive logon or using basic authentication. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Must loosen security screws for vendor
    ... I'm sorry but if they loosen your rights have them sign a form saying that they are now responsible. ... I've restricted the users so they can ONLY logon to their own workstations thru the properties of their user profile. ... New Server Application. ... An open letter to the Security Community:: http://msmvps.com/bradley/archive/2004/12/12/23540.aspx ...
    (microsoft.public.windows.server.sbs)
  • Re: Users no longer authenticate on W2k-svr
    ... the user rights setting in the Local ... Security Policy did it. ... establishing the connection from the RAS server, ... >auditing of logon events on that server and then view the ...
    (microsoft.public.win2000.networking)
  • Re: Developer accounts
    ... Is your question "Can I give them specific rights to do only this without ... except as a local admin" or "What is best practice for developers installing ... SQL Server can be fully managed as a SQL admin ... with giving them administrators rights. ...
    (microsoft.public.windows.server.security)