Re: Easy question on the local admin passwords




boomboom...@xxxxxxxxx wrote:
Steven L Umbach wrote:
With a Group Policy "startup" script users do not need read access to the
script in sysvol. You can remove authenticated users and add domain
computers with read/list/execute instead. You will also have a potential
problem in that the startup script will not be run until the computer is
restarted on the domain. You might want to use different local administrator
password on the laptops than the workstations. --- Steve

Thanks Steve,

That seems to be a more secure solution.
But I think it is still trivial to circumvent.
Any user that manages to run a script under LocalSystem (for any
reason) can acces the administrator password in clear text. As I can
trust totally all the workstations (there are some of them that are
operated by knowledgeable users with administrative rights) I would
prefer do not offer the password in that manner.

Sorry, there is a typo in the last phrase

As I can NOT trust totally all the workstations (there are some of them
that are
operated by knowledgeable users with administrative rights) I would
prefer do not offer the password in that manner.

.



Relevant Pages

  • Re: Easy question on the local admin passwords
    ... computers with read/list/execute instead. ... problem in that the startup script will not be run until the computer is ... password on the laptops than the workstations. ... operated by knowledgeable users with administrative rights) I would ...
    (microsoft.public.win2000.security)
  • Re: Moving workstations/servers OU to OU
    ... Check at Technet script center, they have many sample scripts that do similar process, you just need to adapt them to your needs. ... that would look to see if there is any new workstations in the ... Computers OU and if there is, look at the first two letters of the ...
    (microsoft.public.windows.server.active_directory)
  • RE: Auto shutdown of workstations
    ... The script would read a text file (which contained computer ... to you stating which computers where left on. ... > I have a Windows SBS 2003 server. ... I have about fifty workstations - most are ...
    (microsoft.public.windows.server.scripting)
  • Re: Easy question on the local admin passwords
    ... computers with read/list/execute instead. ... problem in that the startup script will not be run until the computer is ... password on the laptops than the workstations. ... reason) can acces the administrator password in clear text. ...
    (microsoft.public.win2000.security)
  • RE: Run as Admin - XP worksation updates
    ... script center. ... > I have 200 XP Pro workstations that I need to add entries in the ... > user can run a logon script with administrative rights or possibly a ...
    (microsoft.public.windowsxp.general)