Re: How to force a user to logon to the domain ?
From: Robert Moir (bofh_at_mvps.org)
Date: 10/02/03
- Next message: Robert Moir: "Re: Backing up an entire windows server 2003?"
- Previous message: Henri Feinberg: "Getting messages non stop,of type: Microsoft Technical Assistance [qlrlipu_rczpk@news.com]"
- In reply to: Branislav: "How to force a user to logon to the domain ?"
- Next in thread: Branislav: "Re: How to force a user to logon to the domain ?"
- Reply: Branislav: "Re: How to force a user to logon to the domain ?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Thu, 2 Oct 2003 20:20:57 +0100
Branislav wrote:
> Hello,
> We would like to force users to logon to the domain so all the
> scripts and patches could be applied.
>
> The situation is this: there are no local accounts on workstations,
> users have only a domain account. It is an NT4 domain, on
> workstations we have Win2000Pro and WinXP. Now, my boss wants every
> user to be a local administrator on his/her computer so we put their
> domain account to be a member of the local Administrators group. This
> gives them possibility to logon locally on their computers.
Well you have to realise that when you make someone a local administrator
they can do what they like on the local machine. Thats what "local
administrator" means. Your first stop should be to go to your boss and
explain that you've got a problem here as you've been asked to perform two
tasks that won't sit comfortably with each other. You can setup various
things to stop them getting a foot through the door but a determined person
with local administrator access *will* beat them all in the end.
My vote is for greating a modified GINA without the option to select the
login context (e.g. the drop down menu that has your domain and computer
names in it). Removing this option will stop damn near most people i should
think.
-- -- Rob Microsoft MVP Windows Servers and Security http://www.robertmoir.co.uk
- Next message: Robert Moir: "Re: Backing up an entire windows server 2003?"
- Previous message: Henri Feinberg: "Getting messages non stop,of type: Microsoft Technical Assistance [qlrlipu_rczpk@news.com]"
- In reply to: Branislav: "How to force a user to logon to the domain ?"
- Next in thread: Branislav: "Re: How to force a user to logon to the domain ?"
- Reply: Branislav: "Re: How to force a user to logon to the domain ?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|