Re: how can I stop user deleting important files



What he said...

And Remove the Keyboard and Mouse..
(That should slow them down) LOL ;)

--
Russ Grover
Small Business IT Support
SBS Rocks!
Portland/Beaverton OR
Email: Sales at SmallBusinessITSupport.com
Website: http://www.SmallBusinessITSupport.com


"MCSEGURU" <mcseguruhere@xxxxxxx> wrote in message
news:OmRxs$cvFHA.4032@xxxxxxxxxxxxxxxxxxxxxxx
> Unless your default NTFS Permissions on your PC are jacked, Domain Users
> shouldn't have access to modify or local system files on their PC. Are
> you sure they aren't members of their PC's Administrators group. Even
> though you have given them de-elivated permissions from the SBS Domain
> Directory, that doesn't necessarily override their permissions on their
> local PC's.
>
> If it may be that they are elevated on the local PC's as a result of
> Administrator group memberships, try enforcing restricted "Administrators"
> to the Local PC's using Group Policies.
>
> In Server Manager, Advanced Management, Group Policy Management, Your
> Forest, Your Domain, Your Domain.local, Default Domain Policy (right click
> and select Edit), Computer Settings, Windows Settings, Security Settings,
> Restricted Groups, Add Group, Administrators, Add Users... etc...
>
> Make sense? This will propagate specific users to be members of the
> Administrators Group on your domain member computers.
>
>
>
> "Bharat" <bharat@xxxxxxxxxxxx> wrote in message
> news:utTDrtcvFHA.252@xxxxxxxxxxxxxxxxxxxxxxx
>> Setting up user as USER - still allows them to delete
>>
>> NTLDR
>> BOOT.INI
>> etc.....
>>
>>
>
>


.



Relevant Pages

  • Re: SQL Domain Group Permissions
    ... Most settings can be retrieved by any authenticated user. ... the group "Domain Admins" is added to the local ... Administrators group with the computer is joined to the domain. ... members of Domain Admins to retrieve more information on the computers. ...
    (microsoft.public.sqlserver.security)
  • Re: Rid AD of Circular Group Membership
    ... and have use on members if it is used there. ... Administrators group is still intact), nor do they have empowerments over ... Admins is being used for by the 30+ can be delegated I(ex. ... The quess is each has an account and uses it, ...
    (microsoft.public.windows.group_policy)
  • Re: Adding User ID in Local Admin Group using Group Policy
    ... If you want to add and RESTRICT ... one would not use the Members list, ... The effect is that ClientAdm is added to the Administrators group ... Another useful one -- reset the local admin password while you're at it, ...
    (microsoft.public.windows.group_policy)
  • Re: Adding User ID in Local Admin Group using Group Policy
    ... If you want to add and RESTRICT ... one would not use the Members list, ... The effect is that ClientAdm is added to the Administrators group ... Another useful one -- reset the local admin password while you're at it, ...
    (microsoft.public.windows.group_policy)
  • Local Administrators & Active Directory
    ... I'm working on some Win XP laptops and am new to Active Directory so ... I check the members list in Administrators... ... Any idea why the Administrators group members constantly are being ...
    (microsoft.public.windows.server.active_directory)