Local admin right

Local admin right

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Local admin right Tu Nguyen 09-27-2005
Posted by =?Utf-8?B?VHUgTmd1eWVu?= on September 27, 2005, 9:39 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi to all,

I have a question. I need your help. We granted some employees’ network
account to local admin group to run some applications. However, they have
used this permission to grant someone else to access that box too. Are There
any ways to restrict them to use local admin right to grant someone
permission to box? I did test at OU but no luck. Any ideas should be
appreciated. Thanks.

Tu Nguyen



Posted by Steven L Umbach on September 27, 2005, 7:35 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Not really. Local administrators are all powerful on that computer within
what they know how to do with the operating system. Depending on their
knowledge you could use Group Policy user configuration/administrative
templates -- various settings to disable their access to the local user and
groups Management Console, hide Control Panel, command prompt, etc. If you
configure such settings at the domain/OU level they will not apply if the
user logs onto the "local" computer not using a domain account. You can also
use Group Policy Restricted Groups to enforce membership of local computer
groups if you use RG at the OU level which would remove unauthorized members
at the next GP computer configuration refresh on the domain computer. The
links below explains more on how to use RG. --- Steve

http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/611.mspx
http://www.windowsecurity.com/articles/Using-Restricted-Groups.html


> Hi to all,
>
> I have a question. I need your help. We granted some employees' network
> account to local admin group to run some applications. However, they have
> used this permission to grant someone else to access that box too. Are
> There
> any ways to restrict them to use local admin right to grant someone
> permission to box? I did test at OU but no luck. Any ideas should be
> appreciated. Thanks.
>
> Tu Nguyen
>
>



Similar ThreadsPosted
server local admin group June 29, 2005, 12:49 pm
Re: cracking local admin account September 4, 2005, 11:56 am
Users and local admin rights?? November 17, 2005, 9:18 am
Re: Installing Software without being Local Admin? July 25, 2007, 3:45 am
Re: Installing Software without being Local Admin? July 25, 2007, 5:21 am
RE: cracking local admin account September 15, 2007, 10:36 pm
Installing Software without being Local Admin? July 24, 2007, 5:38 am
How do I manage local admin accounts without a domain or ADS? November 16, 2005, 6:22 pm
Local Admin access through Active Directory April 6, 2006, 7:43 pm
Desk Local Admin - via restriced group April 13, 2006, 11:15 am

The site map in XML format XML site map

Contact Us | Privacy Policy