Removing Local Admin Rights...
From: Jay Lopez (jlopez_si86_at_hotmail.com)
Date: 05/25/04
- Previous message: Kalpin Erlangga Silaen: "Re: possibly compromised redhat 7.2 box"
- Next in thread: KEN MORRIS: "RE: Removing Local Admin Rights..."
- Maybe reply: KEN MORRIS: "RE: Removing Local Admin Rights..."
- Maybe reply: Tom Stowell: "Re: Removing Local Admin Rights..."
- Maybe reply: Craig, Jason: "RE: Removing Local Admin Rights..."
- Maybe reply: Robinson, Sonja: "RE: Removing Local Admin Rights..."
- Reply: Murad Talukdar: "Re: Removing Local Admin Rights..."
- Maybe reply: Daszczyszak, Roman L. SPC (1AD 501 MI BN ACE IMO): "RE: Removing Local Admin Rights..."
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: security-basics@lists.securityfocus.com Date: Tue, 25 May 2004 08:48:04 -0500
I currently work for an organization with approximately 25,000 Windows
XP/2000 desktops in an Active Directory (AD) environment. Security from an
OS and individual application component (i.e., Outlook 2003, MS Office, IE,
etc.) perspective is being managed via group policy objects (GPO's).
Currently, we are pushing to remove local administrator access rights to
individual machines to prevent users from randomly installing unapproved
applications, prevent malware from being silently installed within the local
administrator context, etc. Prior to our move to AD and GPO's, we received
push-back on removing local admin rights for reasons such as the logon
scripts would not work, etc.
By chance, have any of you implemented any of the above--especially the
removal of local administrator rights? If so, what support issues did you
experience? What impact did removing local admin rights have?
I'd like to provide as many pros and cons back to our team based on your
feedback.
Thanks in advance,
Jay Lopez
_________________________________________________________________
FREE pop-up blocking with the new MSN Toolbar – get it now!
http://toolbar.msn.click-url.com/go/onm00200415ave/direct/01/
---------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
any course! All of our class sizes are guaranteed to be 10 students or less
to facilitate one-on-one interaction with one of our expert instructors.
Attend a course taught by an expert instructor with years of in-the-field
pen testing experience in our state of the art hacking lab. Master the skills
of an Ethical Hacker to better assess the security of your organization.
Visit us at:
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------
- Previous message: Kalpin Erlangga Silaen: "Re: possibly compromised redhat 7.2 box"
- Next in thread: KEN MORRIS: "RE: Removing Local Admin Rights..."
- Maybe reply: KEN MORRIS: "RE: Removing Local Admin Rights..."
- Maybe reply: Tom Stowell: "Re: Removing Local Admin Rights..."
- Maybe reply: Craig, Jason: "RE: Removing Local Admin Rights..."
- Maybe reply: Robinson, Sonja: "RE: Removing Local Admin Rights..."
- Reply: Murad Talukdar: "Re: Removing Local Admin Rights..."
- Maybe reply: Daszczyszak, Roman L. SPC (1AD 501 MI BN ACE IMO): "RE: Removing Local Admin Rights..."
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]