Software Restrictions versus Revoke Local Admin Rights




I am in the process of installing and configuring SBS 2003 for our
small network. I am looking for the best way to stop employees from
downloading and/or installing software without consent (basically
attempting to stop malware/badware/spyware). I know one option is to
use Software Restrictions. My two choices for Software Restrictions
seem to be a) Blacklist software I don't want or b) Whitelist the
software that is allowed to run. While these would work, it seems
Blacklisting software would be next to impossible, because who knows
how many apps are out there that I don't want installed. Whitelisting
would work, but it seems difficult to get a handle on all the apps that
must run in order for employees to do their jobs correctly (all the
Windows components, etc).

I read somewhere that you could revoke the Local Admin Rights that the
user had. I wasn't aware this was an option. A couple of questions...


1) Is there a way to change SBS configuration so that when
computers/users are configured, the users aren't given Local Admin
privileges when they certainly shouldn't be Admins to the machine (big
security breach in my mind)?

2) Is simply making them a User versus an Admin of the machine going to
stop the installation of software (spyware, etc)?

Thanks,
Sean

.



Relevant Pages

  • RE: How to block users from installing other apps
    ... How to block users from installing other apps ... and add their domain account to the local admin group. ...
    (Focus-Microsoft)
  • Re: Clip Art Error 0x8007000E Not enough memory
    ... I added them to the local admin group. ... > downloading these two files and installing them onto ... > I am able to insert Clip Art when I login to the TS ...
    (microsoft.public.windows.server.sbs)
  • Re: F11: Samsung laser printer no longer works: " client-error-document-format-not&#
    ... On Thu, 18 Jun 2009, Colin Brace wrote: ... For anyone else installing this printer under Fedora; ... i've been following this thread and i still have no luck configuring ... and smart panel app, why should i be doing any config by hand instead ...
    (Fedora)
  • Re: Clip Art Error 0x8007000E Not enough memory
    ... I added them to the local admin group. ... >> downloading these two files and installing them onto ... >> I am able to insert Clip Art when I login to the TS ... >> the Administrator account, ...
    (microsoft.public.windows.server.sbs)
  • RE: Removing Local Admin Rights...
    ... Some software will run only under local admin user accounts. ... individual machines to prevent users from randomly installing unapproved ... What impact did removing local admin rights have? ... to facilitate one-on-one interaction with one of our expert instructors. ...
    (Security-Basics)