Active Directory PC Lock down

From: Reto Barandun (reto.barandun@hofmann.ch)
Date: 06/19/02


From: "Reto Barandun" <reto.barandun@hofmann.ch>
Date: Wed, 19 Jun 2002 02:28:02 -0700


Hi

I see your problem. At the point, where you activate
Active Directory in your Company, you can use the Powers
of Group Policy Objects. (You can use GPO's only, if you
have Win2K or higher as Client OS, if not, forget it for
now).

With GPO's, you can enable the Windows Installer Service
to use elevated Privileges (LocalSystem), to install MSI
Packages, which require Admin Rights, even the user has
ordinary User right.

To configure this feature, open the GPO, Naviagte to:
Computer Configuration
 +Administrative Templates
  +Windows components
   +Windows Installer

You have to enable the same policy (Always install with
elevated privileges), in the User Configuration. Be sure,
that you have enabled both Policies (Computer and User
Policy).

As a reminder, you have to use Win2K or higher as OS. For
NT4, i don't know, if there is a equal function available,
maybe you have to edit the registry manually.

Regards
Reto Barandun
IT Systems Engineer

>-----Original Message-----
>Hi All,
>
>We are going to implement Active directory model in our
>company. Right now every user is having the priveleges of
>Local Admin to thier respective Pc's. But after
>implementing Active directory Model, We are going to
>restrict the users of their respective Pc's from becoming
>thier local Admins.
>
>But now we are having concerns. As we are developing MSI
>packages for application installation using wise Package
>studio 3.12, We are going to publish these packages on
our
>GE-Medical website. In this type of setup, If any user
>want to install any application(package), he need to
visit
>to our package list page of our website & need to double
>click on that particular package to install that
>application on his box.
>
>But as now the user is not having the local admin rights
>of his Pc, How he is going to install that package in his
>PC.
>
>SMS 2.0 is having by default a service Account, which is
>by default taking care of such type of deployments. But
we
>have SMS that is covering only 60% pc's. So for remaining
>40% pc's we want to use this webpage of our site to
deploy
>packages on thier boxes.
>
>Hope u understand my concern.
>
>
>Thanks
>
>Dinesh
>.
>



Relevant Pages

  • Re: SMS Installer
    ... credentials to install. ... > installing software packages on computers used by standard ... > power user or local admin' then there isn't a problem. ... > using SMS. ...
    (microsoft.public.sms.admin)
  • FS: Complete Linux Recording Package Ready To Roll.
    ... How to install Rehmudi-2.0 ... if you don't have any sound, ... dependencies of Agnula Packages ... ... from the new kernel. ...
    (comp.os.linux.misc)
  • Re: Complete Linux Recording Package Ready To Roll.
    ... How to install Rehmudi-2.0 ... if you don't have any sound, ... dependencies of Agnula Packages ... ... from the new kernel. ...
    (comp.os.linux.misc)
  • Which debian sources to use to install to Knoppix 4.0.2?
    ... running into a problem when I install software to version 4.0.2 that I ... Check out the list of extra packages to be installed, ... akregator ark cupsys cupsys-bsd cupsys-client gcc-4.0-base gs-common ... kdepim-kfile-plugins kdepim-kio-plugins kdeprint kdesktop kdessh kdf ...
    (comp.os.linux.misc)
  • Apt Gone Mad?-Or Is It Me?-Expert Help Needed
    ... So tried to upgrade OO to 2.0 but Apt refused to do so. ... Aptitude doesn't show anything but Wajig shows unmet dependency for kdelibs-data. ... The following packages are unused and will be REMOVED: agsync arson barcode brahms cdda2wav cddb digikam digikamimageplugins gmessage guarddog guidedog hotswap-gui hotswap-text i2e id3v2 kbarcode kbear kbiff kdebase-dev kdirstat kile kimdaba klog klogic kmymoney2 knetfilter knutclient komba2 kover kprof kpsk krusader ksimus ksimus-boolean ksimus-datarecorder ksimus-floatingpoint ksocrat ksocrat-data kvdr kvirc kvirc-data kvirc-doc kwavecontrol kxmleditor lesstif2 libdynamite libimlib2-dev libkonq4-dev libmimedir liborange ... ChatagnierL-Home:/temp# wajig install openoffice.org Reading Package Lists... ...
    (Debian-User)

Loading