Re: Preventing Users from removing their PC from the Domain
- From: "rndinit9@xxxxxxxxx" <rndinit9@xxxxxxxxx>
- Date: 24 Jun 2006 22:11:24 -0700
thank you Steven, however I logged on as a non local administrator. To
be more specific a user.
The user does not have any privlidges what so ever. They cannot install
or uninstall software, but im willing to bet that even the guest
account (disabled by default) would be able to remove the PC from the
domain.
The funny thing is, when it prompts the user for a user name or
password, if you leave those fields blank and hit ok, it will work. And
the PC is removed from the domain. Would appreciate more replies.
Steven L Umbach wrote:
A user needs to be a local administrator in order to remove their computer
from the domain. So the obvious answer is to not allow the user to be a
local administrator and look at ways for the user to function as needed
without being a local administrator. I know that may not always be possible.
There is no magic bullet to prevent local administrators from removing their
computer from the domain as local administrators by definition and design
are all powerful on their computer. About the best you can do is to have a
strict user policy that users sign and understand and that removing
computers from the domain is prohibited. You can also use Group Policy to
try and hide access to ways a user would use to remove their computer from
the domain if it does not interfere with their needed access to the
operating system. Group Policy can be used to hide or remove access to
Control Panel applets such as System which is probably what most users use.
That will not work however for skilled and determined users. --- Steve
<rndinit9@xxxxxxxxx> wrote in message
news:1151146580.725415.255000@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
rndinit9@xxxxxxxxx wrote:
Currently users are able to remove their PC's from the domain w/o being
prompted for a DomainAdmin username/pass. This is becomming a problem.
How can I set it that in order for a PC to be removed from the domain,
that a domain admin username & password must be entered.
Your help is appreciated.
To add some info: The DC is Windows 2000
.
- Follow-Ups:
- Re: Preventing Users from removing their PC from the Domain
- From: Steven L Umbach
- Re: Preventing Users from removing their PC from the Domain
- References:
- Preventing Users from removing their PC from the Domain
- From: rndinit9
- Re: Preventing Users from removing their PC from the Domain
- From: rndinit9@xxxxxxxxx
- Re: Preventing Users from removing their PC from the Domain
- From: Steven L Umbach
- Preventing Users from removing their PC from the Domain
- Prev by Date: Re: Tracking access to folder
- Next by Date: Re: Preventing Users from removing their PC from the Domain
- Previous by thread: Re: Preventing Users from removing their PC from the Domain
- Next by thread: Re: Preventing Users from removing their PC from the Domain
- Index(es):
Relevant Pages
|
|