Synchronizing domain membership via VPN

o_jay83_at_hotmail.com
Date: 10/27/05

  • Next message: Joe Richards [MVP]: "Re: Network Services accessed after account disabled"
    Date: 26 Oct 2005 17:51:55 -0700
    
    

    Company policy has dictated no-one is allowed to be a local
    administrator on their computer. Sometimes we need to allow select
    users to be administrators temporarily to install some software on
    their computers or to work with a program that will not function
    without admin rights.

    When they are on the network this is achieved by putting them into a
    temp admin group (the temp admin group is in their local administrators
    group). Once they log off and on again they have their admin rights.
    After a predetermined amount of time they are removed from the temp
    admin group.

    The problem occurs however when they are not in the office. We can add
    them to the group but even if they connect to VPN their membership in
    the temp admin group is not recognized. Is there a way to force
    synchronize security information such as this after logon if they are
    connected to VPN... or for that matter if they are connected to the
    network so they don't have to log off and on?


  • Next message: Joe Richards [MVP]: "Re: Network Services accessed after account disabled"