Re: Installing Software without being Local Admin?

Re: Installing Software without being Local Admin?

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Re: Installing Software without being Local Admin? Ben 07-25-2007
Posted by Ben on July 25, 2007, 3:45 am
If you were  Registered and logged in, you could reply and use other advanced thread options
<snip>
>
> Hi, Ben - I remember you. Congratulations on a job well done for your
> company's security. I'm sure one of the security experts will have a more
> elegant idea for you, but here's mine:
>
> How many business modeler machines are we talking about? If just a few,
> why not purchase laptops just for that purpose and not join them to the
> domain? Keep them off the network, too or give them their own subnet if
> the program needs an Internet connection. Let them run the buggy software
> and nothing else. If those machines are never joined to your network, you
> don't really need to worry about what the business modeler users do. Tell
> the users that they are not to use the machines for anything else, no
> documents, etc. If they need to backup or transfer any data from that
> program, you can have them upload it to a folder or via thumb drive or to
> an NAS just for them. Since I don't know anything about how that software
> works and whether you need to back up stuff from it, those are just WAGs.
>
> In this scenario, you would set up a business modeler machine perfectly -
> exactly the way you want it. Image it. Then have those machines in for
> maintenance at some regular interval that makes sense to you and simply
> restore the image. Voila! Clean machines again.
>

Hi Malke,

That's an interesting approach, I'll have to run it past the business
modeler guys, (we have 2 spare thinkpads at the moment, so it might be a use
for them).

I can think of one reason why they might reject this approach down, and
that's weight/luggage - These guys travel a fair bit, and also carry a small
projector for presentations with them, they may not be open to the idea of
having to carry another laptop around with them.

However this all comes down to whether they actually need to have their
standard company laptop with them, maybe they can use that at home/in the
office for emails, VPN etc, then use the second laptop for modeler
development & onsite presentations.....Hmmm an interesting idea, will have
to give this serious thought - thanks!

Many thanks

Ben



Posted by Malke on July 25, 2007, 10:11 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Ben wrote:

> Hi Malke,
>
> That's an interesting approach, I'll have to run it past the business
> modeler guys, (we have 2 spare thinkpads at the moment, so it might be a use
> for them).
>
> I can think of one reason why they might reject this approach down, and
> that's weight/luggage - These guys travel a fair bit, and also carry a small
> projector for presentations with them, they may not be open to the idea of
> having to carry another laptop around with them.
>
> However this all comes down to whether they actually need to have their
> standard company laptop with them, maybe they can use that at home/in the
> office for emails, VPN etc, then use the second laptop for modeler
> development & onsite presentations.....Hmmm an interesting idea, will have
> to give this serious thought - thanks!

I think your idea expanding on mine is the way to go. Load up the spare
Thinkpads with whatever these guys need when they travel, including the
buggy software. Image them. Make those the "travel laptops" and have
them leave their "work laptops" behind. Problem solved.

Oh, and I think I'd just present the new method as a fait accompli and
not discuss it with them first. ;-)


Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User

Similar ThreadsPosted
Re: Installing Software without being Local Admin? July 25, 2007, 5:21 am
Installing Software without being Local Admin? July 24, 2007, 5:38 am
Local admin right September 27, 2005, 9:39 am
server local admin group June 29, 2005, 12:49 pm
Re: cracking local admin account September 4, 2005, 11:56 am
Users and local admin rights?? November 17, 2005, 9:18 am
RE: cracking local admin account September 15, 2007, 10:36 pm
How do I manage local admin accounts without a domain or ADS? November 16, 2005, 6:22 pm
Local Admin access through Active Directory April 6, 2006, 7:43 pm
Desk Local Admin - via restriced group April 13, 2006, 11:15 am

The site map in XML format XML site map

Contact Us | Privacy Policy