RE: Allowing Non admin users to install approved software



I have to agree with that assessment. While there are tools out there that
will allow your non-privileged users to install programs, your policy should
not allow it. If they need a program installed, they can contact you. If
it's a program that is not used on other workstations, evaluate the program
and decide whether it should be allowed or not. In every case that does not
relate directly to a user's job, I deny such requests. Strict permissions
must remain strict, or you're just wasting your time.


Isaac Van Name
Systems Administrator
Southerland, Inc.
ivanname@xxxxxxxxxxxxxxxxxxxx

"What good would you do with an ignorant employee? Ignorance is grounds for
dismissal..." - Mario Spinthiras

Open Source developing at its finest:
"Written in vim, W3C valid and UTF-8 encoded, for her pleasure."

Disclaimer: This email is intended only to be used to feign intellectual
mastery of a subject or superhuman command of the English language, when
profanity is involved. By reading this email, you are agreeing to cease all
correspondence with the sender upon realizing your own ignorance, and
furthermore to refrain from taking legal action against said sender when
your compounding ignorance crushes your inadequate self-esteem. Have a nice
day.

Original> -----Original Message-----
Original> From: listbounce@xxxxxxxxxxxxxxxxx
[mailto:listbounce@xxxxxxxxxxxxxxxxx]
Original> On Behalf Of Laundrup, Jens
Original> Sent: Tuesday, October 17, 2006 5:24 PM
Original> To: Gary Collis; security-basics@xxxxxxxxxxxxxxxxx
Original> Subject: RE: Allowing Non admin users to install approved software
Original>
Original> Do not! If they would like a program installed, have them send
you an
Original> e-mail. Then you publish the program to the user. They log out
and
Original> then back in and the program will install. This way you retain
control
Original> whilst they get the program they wish. Since you are only
allowing them
Original> programs that are on your "approved" list, then just make sure you
have
Original> a valid msi for each and make very sure that you are covering the
Original> programs in your patch management tool.
Original>
Original> Jens
Original>
Original> -----Original Message-----
Original> From: listbounce@xxxxxxxxxxxxxxxxx
[mailto:listbounce@xxxxxxxxxxxxxxxxx]
Original> On Behalf Of Gary Collis
Original> Sent: Tuesday, October 17, 2006 1:30 PM
Original> To: security-basics@xxxxxxxxxxxxxxxxx
Original> Subject: Allowing Non admin users to install approved software
Original>
Original> List,
Original>
Original> How can I allow non admin/power users in a w2k domain, using XP
Original> machines
Original>
Original> to install software that is approved by IT, whilist maintaining
some
Original> degree of security and control over what is installed?
Original>
Original> Any suggestions would be greatly appreciated,
Original>
Original> Thanks
Original>
Original>
------------------------------------------------------------------------
Original> ---
Original> This list is sponsored by: Norwich University
Original>
Original> EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
Original> The NSA has designated Norwich University a center of Academic
Original> Excellence
Original> in Information Security. Our program offers unparalleled Infosec
Original> management
Original> education and the case study affords you unmatched consulting
Original> experience.
Original> Using interactive e-Learning technology, you can earn this
esteemed
Original> degree,
Original> without disrupting your career or home life.
Original>
Original> http://www.msia.norwich.edu/secfocus
Original>
------------------------------------------------------------------------
Original> ---
Original>
Original>
Original>
Original>
---------------------------------------------------------------------------
Original> This list is sponsored by: Norwich University
Original>
Original> EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
Original> The NSA has designated Norwich University a center of Academic
Original> Excellence
Original> in Information Security. Our program offers unparalleled Infosec
Original> management
Original> education and the case study affords you unmatched consulting
Original> experience.
Original> Using interactive e-Learning technology, you can earn this
esteemed
Original> degree,
Original> without disrupting your career or home life.
Original>
Original> http://www.msia.norwich.edu/secfocus
Original>
---------------------------------------------------------------------------
Original>



---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence
in Information Security. Our program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------



Relevant Pages

  • RE: Rights
    ... Yes the user can install applications and use the application if the ... After a reboot the virtual disk containing the changes ... EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE ... The NSA has designated Norwich University a center of Academic ...
    (Security-Basics)
  • RE: Allowing Non admin users to install approved software
    ... Allowing Non admin users to install approved software ... EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE ... The NSA has designated Norwich University a center of Academic ... in Information Security. ...
    (Security-Basics)
  • Re: Trojan horse bypassing any firewall and antivirus SW
    ... > nowadays really possible to install such a piece of SW to any arbitray PC ... EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE ... The NSA has designated Norwich University a center of Academic Excellence in Information Security. ...
    (Security-Basics)
  • RE: Allowing Non admin users to install approved software
    ... users who aren't admins can receive and install software from AD. ... EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE ... The NSA has designated Norwich University a center of Academic ... in Information Security. ...
    (Security-Basics)
  • RE: Verifying E-Mail Addresses
    ... correspondence with the sender upon realizing your own ignorance, ... Original> EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE ... Original> The NSA has designated Norwich University a center of Academic ... Original> in Information Security. ...
    (Security-Basics)