RE: What is the best way to lock a local box on a network?



Hi Martin,

Because AD will elevate the user's rights during installation for
assigned and published apps, you can:
1. remove the user from the local admins group, leaving them as a user
2. assign or publish the apps through AD
3. use WSUS to deliver approved (and vetted) patches

Kind Regards,
Scott Ramsdell

-----Original Message-----
From: listbounce@xxxxxxxxxxxxxxxxx [mailto:listbounce@xxxxxxxxxxxxxxxxx]
On Behalf Of Martin Tran
Sent: Wednesday, August 29, 2007 10:15 AM
To: security-basics@xxxxxxxxxxxxxxxxx
Subject: What is the best way to lock a local box on a network?

Hi guys, I was wondering the best way to lock a local box. Things such
as,
1. Can't install unauthorized programs.
2. But can install programs/softwares on a list that is acceptable.

I went to gpedit.msc and gone through the options, but everything
seems really cut and dry. For example, If I was to enable an option
to stop users from installing unwanted software and user tries to do
windows update, it wasn't allowed to proceed with the process saying
they needed administration rights to the box.

If you guys can shine some light as I continue to do some trial and
error on this test box, any suggestions would be great and
appreciated!

--
Martin Tran



Relevant Pages

  • RE: Office tries to repair/reinstall
    ... Giving admin rights to everyone is not the solution. ... The file association issue should be also related to the Office 2007 installation. ... I will check the registry and install windows installer. ...
    (microsoft.public.office.setup)
  • Re: Windows 2003 Users vs Software
    ... to which limited user do not and should not have write granted. ... The users do not have rights to install programs. ...
    (microsoft.public.security)
  • RE: Office tries to repair/reinstall
    ... This posting is provided "AS IS" with no warranties, and confers no rights. ... Download and install the Windows Installer Cleanup Utility. ... Giving admin rights to everyone is not the solution. ... The file association issue should be also related to the Office 2007 installation. ...
    (microsoft.public.office.setup)
  • Re: Granting all users Admin Rights
    ... I am a Network Admin for Cuesta College and we are dealing with the same ... Techs to go to install every little piece of software on users computers. ... I believe that giving users Power Users rights is the best way ...
    (microsoft.public.win2000.security)
  • Re: Granting all users Admin Rights
    ... Giving users in an environment that big Admin rights is asking for trouble. ... Even worse any closet hacker wanabee would install Lophtcrack and pull up ... > I am a Network Admin for Cuesta College and we are dealing with the same ...
    (microsoft.public.win2000.security)