Re: Domain Users in Local Machine Administrators Group



What apps don't like not running in local admin?

www.threatcode.com

You may need to hack up registries to get all of the line of business software to work.

The reality is that about 80% of corporations still run with admin rights...

MikeD wrote:
Okay I know its probably been asked before but here it is again. I'm working on a SBS hosted GP deployment that incorporates a mix of 'highly-,' lightly-' and un-managed machine & user OU's. These configurations include everything from completely unmanaged run-of-the-network accounts to a couple of locked-down, public 'kiosk' machines. Everything works great, roaming profiles, folder redirections, mandatory desktops etc.. One catch... it works as long as Domain Users have administrator privileges on the local machines.

Two questions:

1) Am I doing something wrong or is this really a legit requirement? 2) Can't this be set in GP?

If anyone has an answer to either question it would be greatly appreciated. I've (obviously) been all over GP and haven't found one. If thats the way it is, fine. It just doesn't seem right that the domain must have complete run of the local machine.

Thanks!
Mike

.



Relevant Pages

  • Re: Accessing Shares of Users that shouldnt be possible! :(
    ... | would someone who is a basic user be able to access someones c$ with no ... The local machines have the user account deleted and ... The local admin also is added ... If you have administrative rights on that computer, ...
    (microsoft.public.windowsxp.security_admin)
  • Lock out Local administrator
    ... I'm creating an app on local machines. ... What I want to do is secure the AS that I can only connect with our ... Big problem is off course the local admin account. ... I've deleten the OLAP Admin group of the machine. ...
    (microsoft.public.sqlserver.olap)
  • Re: nis : how to avoid user1 becoming user2 using local root ?
    ... > All developpers can become root on their local machines. ... > For me it's a huge problem (windows don't have this prob, local admin ...
    (Focus-Linux)
  • Accessing Shares of Users that shouldnt be possible! :(
    ... another local admin have both the same setup on our machines however I ... would someone who is a basic user be able to access someones c$ with no ... The local machines have the user account deleted and ... the admin account setup with a password. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Changing Local Group Membership
    ... >I have a group of domain users who are setup as administrators for their ... >local machines. ... How do I create a global group, so that it is a member of the local administrators group on all workstations and member servers, by using group policy restricted groups? ...
    (microsoft.public.win2000.group_policy)